Course overview
The audit plan is the single document that decides what the audit function will look at, what it will ignore, and what it will discover too late. Most plans are built with good intentions and rebuilt in a hurry: last year's engagements are copied forward, a few requests from management are added, the hours are made to fit the headcount, and the risk assessment behind it is written up afterwards to justify the list. When the audit committee asks why a business unit that later blew up was never audited, that sequence becomes very hard to defend.
This course treats planning as the discipline it is. It covers building the audit universe, scoring risk in a way that can be challenged, allocating scarce audit hours, tracking delivery through the year, and reporting honestly when the plan changes. It draws on the IIA International Professional Practices Framework, the COSO frameworks for control and enterprise risk, and ISO 31000 for risk vocabulary.
Why the plan is the hardest document you write
Audit functions are almost always smaller than the risk they are asked to cover. A team of six may face an audit universe of two hundred entities, processes and systems, of which they can realistically visit thirty. Every plan is therefore an argument about what will not be covered, and that argument needs evidence behind it.
The pressure has increased as risk profiles change faster than annual cycles. Outsourced processes, third-party platforms, new markets and new regulatory obligations appear mid-year and do not wait for the next planning round. Functions that treat the plan as a living document, refreshed against a maintained risk assessment, keep pace. Functions that lock it in January spend the rest of the year auditing last year's risks.
Course objectives
By the end of the course, participants will be able to:
- Construct an audit universe covering entities, processes and systems.
- Renew the mandate and the plan the audit committee approves.
- Score auditable areas on financial exposure and control maturity.
- Budget audit days against leave, training and follow-up.
- Resource an actuarial or technology area the team cannot cover.
- Draft engagement scoping that holds a project inside its boundaries.
- Monitor plan delivery against the annual calendar.
- Translate coverage gaps into decisions the audit committee owns.
- Track cycle time and the metrics that distort audit behavior.
Course outline
Unit 1: Introduction to effective audit planning
- The audit charter and what it lets the function refuse.
- IIA framework expectations for a risk-based plan.
- Compiling an audit universe and keeping it current.
- Inputs from the enterprise risk register and prior findings.
Unit 2: Risk-based approaches to audit planning
- Risk criteria: regulatory sensitivity, complexity and change.
- Weighting and scoring without engineering the answer.
- Using the risk register without inheriting its blind spots.
- Naming risks nobody owns: third parties, technology change.
Unit 3: Resource allocation and scheduling
- Capacity modeling of audit days after leave and training.
- Sizing an engagement and the cost of one extra week.
- Skills mapping and co-sourcing for specialist assurance.
- Building contingency for the investigation nobody planned.
Unit 4: Executing and monitoring the audit plan
- Scope renegotiation against the audit approach memo.
- Showing percentage of plan delivered and reports in draft.
- Absorbing special requests without losing the plan.
- Re-planning mid-year, and who is allowed to approve it.
Unit 5: Reporting and continuous improvement
- Telling the audit committee what was dropped and why.
- Overdue management actions and the ageing analysis.
- Measuring cycle time and stakeholder feedback.
- Quality assessment of planning, tested by external review.
How the course is delivered
The course runs as guided discussion around documented material: real audit universes, risk scoring models, plan documents and committee papers that participants examine, pull apart and rebuild in conversation. Worked examples take a small audit function from an empty spreadsheet to an approved plan. Participants are welcome to bring their own planning problems into the room. The course is educational and does not certify participants or assess any organization's audit function. Those who want to strengthen the testing techniques the plan relies on will find Auditing Techniques for Effective Risk Management a natural next step.
Who should attend
- Heads of internal audit and audit managers responsible for the annual plan.
- Senior auditors moving into planning and resourcing responsibilities.
- Risk and compliance managers whose monitoring plans need to align with audit coverage.
- Audit committee members and executives who approve and challenge the plan.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, and we run courses through hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they cover.
Frequently asked questions
Is this course useful if my audit team is very small?
Yes, and arguably more so. A small function has to be far more explicit about what it will not cover, which makes a defensible risk assessment and a realistic capacity model essential instead of optional.
Do I need to bring my own audit plan with me?
It is not required, but participants who bring a current plan or risk model usually get more from the discussion, since they can test the ideas against something real.
Does the course include a live lab?
No. There is no software environment to work in. The sessions use documented case material, planning templates and worked examples that participants analyze and discuss.
Related courses
- Best Practices in Internal and External Auditing
- Developing Audit Reports with Impact
- Enterprise Risk Management Strategies
- Auditing Risk and Compliance Practices
Register for this course
Select a city and date from the schedule above and register online, or speak to the EuroQuest team about running the course in-house for an audit function planning its next cycle.
All Course Dates & Locations
30 dates · 15 cities · Sep 2026 – Jun 2027