An audit risk assessment is the step that decides where the audit effort goes, and it is the step small organisations skip. Without it, an internal audit programme drifts into auditing whatever is easiest to audit: the areas with tidy records, run by the people who enjoy being audited. The processes that would actually hurt the business if they failed get a light touch, because they are messy and their owners are busy. Ranking processes by risk before planning the audit turns the same number of audit hours into a different and much more useful result, and it is what an external auditor will ask to see when they ask how you chose your programme.
The two questions that rank a process
How badly would it hurt if this process failed, and how likely is it that it is failing right now without anyone noticing? The first question is about consequence: a lost customer, a recall, an injury, a regulatory notice, a system down for a day. The second is about visibility: a process with automated checks and daily output is one you would notice failing, while a process that runs quarterly by hand and produces a document nobody reads could have been broken for a year. Multiply the two, rank the list, and the top of it is where your audit hours belong.
What moves a process up the list
Change is the strongest signal. A process that gained a new supplier, a new system, a new manager or a new site in the last year is far more likely to have drifted from its written procedure than one that has run untouched. Past findings are the second signal: an area that produced a nonconformity last cycle earns a return visit, and a corrective action closed on paper without evidence of effectiveness earns two. Complaints, near misses, rework and any process where one person is the only one who knows how it works all move an area up.
Turning the ranking into a sampling plan
The ranking decides frequency and depth, not just order. A high-risk process might be audited twice in a cycle with a wide sample of records; a low-risk stable process might be audited once with a handful of samples, or covered by a documented review rather than a full audit. Write the reasoning down next to the ranking. The sentence an auditor wants to read is not that you audited everything, it is that you knew which areas mattered most and can say why. The free internal audit template on this site sizes the fieldwork once you have decided the processes, the checks per process and the samples per check.
Where a risk assessment audit is the thing being audited
The phrase also runs the other way. If your management system requires risk assessments, whether for safety, information security, environment or quality, then those assessments are themselves an audit subject, and the questions are the same each time. Is there an assessment for every activity in scope. Does it name an assessor and a date. Were the controls it chose actually implemented. Was it reviewed after the incidents, changes and new equipment that should have triggered a review. That last one is the most commonly failed, because reviews are event-driven and events are not diarised.
Questions people ask about audit risk assessment
Is audit risk assessment the same as the risk register?
They overlap but they answer different questions. The risk register is about threats to the business. An audit risk assessment is about which processes deserve audit attention, which is driven as much by how visible a failure would be as by how bad it would be.
Who should do the audit risk assessment?
Whoever owns the audit programme, using input from process owners rather than only their opinion. Owners systematically rate their own areas as lower risk, so a ranking built purely from self-assessment tends to invert the list you want.
How often should the ranking be redone?
Once a cycle as a minimum, and immediately after any significant change: a new site, a new product line, a system migration, a serious incident. The ranking is a live document, not an annual formality.
Does a small organisation really need this step?
It needs the thinking, not necessarily the matrix. Three lines of reasoning about where failure would hurt most, written down and dated, does the job and is defensible. What is not defensible is an audit programme that cannot explain its own coverage.