Internal audit plans: the programme for the year and the plan for a single audit, and why they are two documents

Internal audit plans are two different documents that share a name, and organisations that keep only one of them get a finding for the other. The audit programme covers the cycle: which processes will be audited, when, by whom, and why that coverage is the right coverage. The individual audit plan covers one visit: the scope, the criteria, the people to be interviewed, the records to be sampled and the timings for the day. An external auditor will ask for the programme to test whether your coverage is deliberate, and for a recent audit plan to test whether the audit was actually conducted the way the programme intended.

What the programme has to be able to explain

The programme is judged on its reasoning, not its layout. It has to say what is in scope across the cycle, so that nothing applicable is quietly left out. It has to say why the frequency of each area is what it is, which means referring to risk, to past findings and to change. It has to name auditors who are independent of the areas they audit. And it has to be a live document: an area that changed significantly in March should show up as a change in the programme, not as a surprise in November.

What a single audit plan contains

Scope, in one sentence that a process owner could not misread. Criteria, meaning the specific clauses, procedures or regulatory requirements the process will be judged against. Method, meaning who will be interviewed, which records will be sampled and how the sample will be chosen. Timing, including who needs to be available and for how long. Sending this to the area a week ahead is not softening the audit; it removes the excuse that the right person was not available, and it means the day is spent on evidence rather than on logistics.

Sizing the plan before you commit to dates

The commonest planning failure is agreeing dates and discovering the workload afterwards. The fieldwork is processes multiplied by requirements checked per process multiplied by records sampled per requirement, converted to minutes, plus interview time per process, plus write-up. Run those figures before the calendar, and either the plan fits the auditors you have or it does not. The free internal audit template on this site does that arithmetic and converts it into audit days per auditor, which is the number that decides whether the programme is real.

The parts of the plan that get audited themselves

Auditors check three things about your plans specifically. That the programme covers the applicable scope across the cycle. That the audits in it actually happened on something close to the planned dates, because a programme with half its audits deferred is a programme that was never resourced. And that findings from one audit fed the planning of the next, which is the part that shows the programme is a system rather than a calendar. An audit programme with no visible link to the previous cycle's findings is the most common structural finding of all.

Questions people ask about internal audit plans

Is an audit programme the same as an audit schedule?

A schedule is the dates. A programme is the dates plus the reasoning about coverage, frequency, auditor independence and how findings feed back. A schedule alone rarely satisfies an external auditor asking how you decided what to audit.

How far ahead should the programme be written?

Far enough to cover the applicable scope across a full cycle, usually a year for most schemes, with the near-term audits detailed and the later ones outlined. It should be revised when risk changes rather than kept fixed for the sake of looking stable.

Who approves internal audit plans?

Someone with the authority to resource them, which usually means the management representative or a director. Approval matters because an unresourced programme is the standard way audits get quietly dropped, and the approval record is what makes that visible.

What if an audit in the plan cannot happen?

Record why, reschedule it, and note the risk of the delay. A documented deferral with a reason is defensible. A missing audit that nobody recorded is a nonconformity against the programme, and it looks like the programme was never taken seriously.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder