Three Persistent Pain Points of Risk-Based Auditing — and How You Can Get Ahead of Them

Does your audit plan have the impact you want? Is it focused on the risks and priorities that matter most to your business?
We’re always aiming for a truly risk-based audit plan. But most audit plans ultimately fall short — often for reasons outside of Internal Audit’s control.
That doesn’t mean we should give up the control we do have. Small changes can help us move our audit plans closer to the mark.
Internal Audit’s work and role are changing. So are our businesses and their risk landscapes. But core skills like audit planning will always remain. These practices ARE in our control, and small changes to our mindset or approach can often have a big impact.
That’s the inspiration behind the Internal Audit Collective’s “Audit Skills Workshop” roundtable series led by Community Manager Toby DeRoche. Toby and other Internal Audit leaders use these sessions to explore essential questions about core audit skills and share practical ideas for changing the game.
Today’s article distills discussion and leading practices from two different roundtables focused on audit planning. Read on for three of the most common pain points of risk-based auditing and real-world strategies to help you get ahead of them.
1. Most “Risk-Based” Audit Plans Really Audit Processes — Not Risks
The holy grail of a risk-based audit approach is a systematic methodology that ensures that the audit plan focuses on the biggest risks to the company’s business objectives.
Most Internal Audit teams say they use a risk-based audit approach. After all, don’t we use a risk assessment to help us decide what to audit?
“When we look at what we do versus what we say we do, there’s a disconnect,” said Toby. Starting with a big audit universe, we ask questions to narrow the focus — but “we're talking about anything except risks and objectives.” Instead, we’re typically listing processes, departments, and applications. As a result, audit plans often focus more on auditing processes than actual risks.
At the same time, the roundtable participants agreed that a purely risk-based audit approach is unrealistic.
Most teams operate in a hybrid model balancing Internal Audit’s assessment of the organization’s top risks with compliance requirements (e.g., SOX, regulatory), management requests, and advisory work. Those audits aren’t going away. But our audit plans often end up lopsided, leaning away from “what matters most” to what matters in a given moment.
As one Internal Audit leader shared, “It becomes very subjective… there’s not a great framework, and it’s kind of bottom-up. I worry about blind spots, and I want a more top-down or from-the-side view to make sure we’re really thinking about risk from a complete perspective.”
Acknowledged Toby, “I don't know that there's a pure risk-based play for any of us. But I want to do more of it. I want to be able to look back on the audit work and say that it's directly impacting the organization as much as it possibly can.”
The goal of more risk-focused auditing is worth aiming for even though we’ll fall short.
If we improve our aim, we’ll at least get closer.
Recommendations
1. Build your audit universe around risks rather than processes where possible.
Start with business objectives, tying every risk back to those objectives. Make sure you’re using process audits only as a way to understand or test the risks you’ve identified.
2. Be explicit about what’s driving each audit.
Continually connect audit work back to why it matters. In both planning and reporting, specify where the project originated (e.g., management request, compliance requirement, advisory, risk assessment) and how it links back to enterprise risk. Share the rationale for any audits added, removed, or delayed.
After all, if you can’t clearly explain why an audit matters to the business, does it really belong on your audit plan?
3. Proactively pressure-test your plan.
Several roundtable participants described the frustrations of spending weeks auditing detailed processes — only to produce findings nobody cared about.
To increase audit impact, make sure as many audits as possible focus on risks that actually matter to management. During planning, ask management to identify their highest-priority issues — and ask follow-up questions to ensure that planned audits will actually address the problems they’re focused on.
Also, as Toby suggested, ask yourself: “If you look at that area, find an issue, and put it in a report, will anybody care?”
The Internal Audit Collective’s 2025–2026 benchmarking survey found that audit plans often miss key opportunities to address C-Suite and board priorities. For example, it’s worth considering how your audit plan can better support business objectives around talent management, product development, innovation, cost control, top-line growth, customer satisfaction, and other go-to-market activities.
4. Be more intentional about allocating across compliance, advisory, and risk-based activities.
While management and board priorities will always have an outsized impact and some audits are nonnegotiable, it is literally our job to provide them with our independent, objective perspective on overall risk management effectiveness.
That includes bringing a strong POV on how the audit plan balances risk-based, compliance, advisory, and management requests.
As one CAE said, “Let's get rid of all the stuff that just doesn't matter and focus on the stuff that does.”
2. Risk Assessments Are Often Too Generic to Drive Effective Planning
Internal Audit’s risk assessments often point to very high-level risk categories. Sure, financial, IT, cybersecurity, and compliance risks impact every part of your organization. But are such broad and far-reaching risk categories genuinely meaningful for directing audit planning?
As one Internal Audit leader put it, “The most important things are obvious. But they’re often nebulous and giant and unauditable in their totality.”
That’s why taking the time to drill down to a more specific and detailed risk listing is where, in Toby’s words, “We actually get more bang for our buck out of our risk assessment.”
As roundtable participants acknowledged, this type of risk assessment is harder and takes longer. But when you go into the audit, you’ll have a clearer picture of what you’re going to do. Instead of the more typical scenario of starting the audit with an end-to-end walkthrough to figure out where the audit needs to go, you arrive with a solid risk hit list.
The goal is making better use of risk assessment activities so that the assessment becomes a more robust planning activity — not just a compliance and prioritization exercise.
Recommendations
1. Get more granular in risk assessments and stakeholder interviews.
When scopes are too broad, risk assessments and audits are less relevant and valuable than they should be. For example, as David Malcom detailed, instead of auditing “cybersecurity,” a more granular risk assessment can help you hone in on more specific areas worth auditing (e.g., privileged access). With that in mind:
Capture at least two levels of risk. Toby recommended capturing (1) the ERM-level risks you’re mapping to and (2) the more granular risks you identify in stakeholder interviews (e.g., underlying operational risks) and then documenting those conversations in your assessment. “The good audits come from the conversations we’ve had. And those conversations mostly happen during the assessment,” said Toby.
Leverage additional risk assessments. For example, review any risk assessments done by ERM, Compliance, operational teams, or other second-line teams. Consider asking stakeholders to conduct self-assessments, helping you collect more detailed information.
2. Evaluate stakeholder insights and management requests through a risk lens.
Considering all of the risk information in Internal Audit’s arsenal (e.g., ongoing stakeholder conversations, business and emerging risk insights, formal risk assessments), what are the most relevant and impactful audits?
Follow up with stakeholders to ensure that audit focus areas align with what they actually care about.
3. Make audit plan language more specific.
Everyone on the team should understand how each process or control links back to the specific enterprise risk being audited.
This sounds obvious. But it’s not always the case.
For example, Business Process Auditors often review processes without understanding the risks in the supporting IT systems, and IT Auditors often do control work without a real understanding of the business processes the IT systems facilitate.
So, before fieldwork begins, document a detailed list of the specific risks and controls that will be evaluated and why. As mentioned, link each risk back to business objectives, process risks, supporting systems and IT controls. Review the combined risk universe as a team before scoping begins.
3. Audit Plans Quickly Become Outdated
Nowadays, most annual audit plans have a ridiculously short shelf life. That makes prioritization and sequencing tougher, and relevance and impact harder to guarantee.
Roundtable participants agreed: It’s hard to feel comfortable making an audit plan more than a quarter out. As one CAE shared, “Risk profiles change so rapidly that leadership can’t agree on what audits or risks we should focus on for the next 12 months.”
Sure, more granular risk assessments and audit planning documentation can help teams focus on the right risks and audits earlier in the process. But both practices also require greater flexibility and agility in the audit plan. “It’s a different way of approaching audit,” said Toby. “Because it means I'll be there until I'm done auditing these five risks I’ve identified. That could be three days. It could be six weeks. I don't really know yet. I have to be a lot more adaptive and agile to do it.”
In addition, as several roundtable participants observed, even the best-laid audit plans can end up subject to belated management or audit committee scrutiny: “Why didn’t you audit X, Y, or Z?”
Audit scoping is always a challenge. Auditors want to ensure that they’re auditing the risks, processes, and controls that matter — but stakeholders often assume that other risks, processes, and controls are in scope. It’s hard to fully and clearly convey in your scope paragraph what’s being audited, what isn’t, and why, and the belated second-guessing of Internal Audit’s choices can be incredibly frustrating.
We still have to make an audit plan. But we also have to more clearly set expectations that in a hypervolatile risk environment, audit plans can’t be static — and they can’t cover everything.
Recommendations
1. Expect audit plans to change — and give yourself space to pivot.
Build more flexibility into your audit plan. That way, you can punt planned audits if needed to focus on the emerging risks impacting your business.
Specifically, when sharing your audit plan with management and the audit committee, be clear: “This is what we plan to do, but it’s going to change.” Explain that as new risks emerge, some audits will drop off so that higher-risk areas can take their place.
Build up your buffer by ensuring audit scope language and reasoning is as clear as possible during kickoff and planning meetings. Essentially, you’re broadcasting, “This is what we’re doing and why, and this is what we’re not doing and why.” That way, if stakeholders want the scope bigger, they can say so during planning — not during the closing meeting.
Lastly, propose only 75% of the number of audits you did last year. This adds flexibility while ensuring your team has time to lean in on key initiatives (e.g., learning to use AI, doing an AI governance review, connected risk or SOX initiatives).
2. Retroactively report audit plan changes to audit committees and management.
During reporting, share what changed/why. You’re providing transparency while supporting accountability on all sides of the table.
One Internal Audit leader includes a slide near the end of his board deck outlining dropped audit projects and reasons why. He recommended including it at the presentation’s end rather than its beginning, helping keep the bulk of the discussion focused on the completed audits and their impact.
3. Meet with stakeholders regularly to keep a pulse on what’s changing.
Many Internal Audit leaders reported that they’re formalizing processes to enable more frequent interactions with stakeholders across the business. This is the single most impactful change you can make to ensure your audit plan stays relevant and provides value.
One IT Audit leader shared that his team meets quarterly with his organization’s CISO, CTO, and Chief AI Officer to talk about planned initiatives and what’s changing, helping them identify front-end opportunities to focus on risks or back-end opportunities to look at processes. For example, if the enterprise has deployed a new backup solution, IT Audit will ask, "When is this going to be complete? When can we come in and check, or can we participate somewhere along the line?”
The leader continued, “Those interactions specific to initiatives and changes have given us some of the best ROI for directing audit plan ideas or opportunities — with buy-in.”
THE LAST WORD: To Reduce the Pain, Consider Three Key Changes
It’s hard to feel like today’s audit plans have any hope of keeping up, but it’s also overwhelming to feel like keeping up requires making a whole slew of changes to our approach and thinking.
Why not start by keeping it simple?
Commit to three key changes that can help reduce all three pain points simultaneously:
- Have more frequent stakeholder conversations. These conversations are a critical ingredient to help Internal Audit improve its risk assessments and stay apprised of how risks are emerging and changing.
- Focus on balancing the audit plan to ensure better allocation across “required” audits and the risks that really matter. Your independent, objective, risk-based perspective is the biggest value Internal Audit brings to the table. Use it to assess and challenge board and management priorities to help them ensure more effective overall risk management.
- Make sure management, the audit committee, and your entire Internal Audit team understand why each audit is on the plan. Every audit should connect back to a risk that genuinely matters. Again, if you can’t explain why an audit project is on the plan (e.g., what specific risks and business objectives it ties back to), Internal Audit’s limited time and resources are likely better invested elsewhere.
If this article resonated with you, consider signing up for the Internal Audit Collective’s:
- SOX Base Camp course. This 16-CPE, 4-week course — FREE for members of the Internal Audit Collective — covers SOX compliance fundamentals with a strong focus on the evolving needs of modern Internal Audit teams. The next cohort (the last in 2026!) begins October 5, 2026. Register and learn more here.
- APEX conference. APEX is different from your average industry conference: It’s a bona fide leadership retreat, designed to bring together peak-performing Internal Audit leaders to build connections while sharing practical ideas for advancing the profession. APEX takes place October 20-21, 2026, at the beautiful Lodge at Spruce Peak in Stowe, Vermont. Not registered yet? A limited number of tickets are still available. Secure your spot today; the event is capped at 80 attendees.
Everything we do in the Collective focuses on helping each other and our profession move forward. How can we help you advance?

Recent Articles
Want to be updated as new blog posts are released? Subscribe to our newsletter.
Join 1K+ readers of The Enabling Positive Change Newsletter for tips, strategies, and resources to improve your approach to Internal Audit and SOX compliance.

