ControlVista

—IIA 2024 · Domain IV

The audit universe under the IIA 2024 Standards.

The 2024 Standards don't require an audit universe. They require something more demanding: a documented assessment of the organization's strategies, objectives and risks, refreshed at least annually, behind a plan that stays dynamic. An audit universe is the most common way to deliver that — if it's built around risks rather than the org chart.

—What the Standards Require

The requirements, in plain terms.

  • Standard 9.4

    Internal Audit Plan

    The plan rests on a documented assessment of strategies, objectives and risks, performed at least annually; it stays dynamic, and the board approves it and significant changes.

  • Standard 9.4 · Considerations

    The audit universe as one approach

    The Considerations for Implementation describe grouping auditable units — business units, processes, programs, systems — and linking them to key risks. It's guidance, not a requirement.

  • Standard 9.1

    Understanding Governance, Risk Management, and Control Processes

    The CAE must understand these processes across key risk areas, including reporting integrity, operations, safeguarding of assets and compliance.

—In Practice

What it looks like when it's done well.

Start from risks, not departments

A universe that's simply a list of departments produces a plan that rotates through the org chart. Linking each auditable unit to the risks it carries is what lets you show the committee why the plan looks the way it does.

Treat "at least annually" as a floor

Standard 9.4 sets a minimum frequency and also asks for a plan that stays dynamic. Re-scoring entities when risks change — a new system, a regulatory change, an incident — keeps the universe from going stale before the plan is approved.

Keep the trail from risk to plan

When the universe, the scores and the plan live in different files, the reasoning between them is lost. Keeping them in one record lets an assessor follow a line of the plan back to the risk that put it there.

—Evidence of Conformance

What an assessor will ask to see.

  • A documented risk assessment dated within the last twelve months (9.4)

  • Auditable units mapped to the key risks they carry (9.4 Considerations)

  • A record of changes to the assessment and plan during the year (9.4)

  • Board approval of the plan and of significant changes (9.4)

How ControlVista Supports It

VistaPlan — Planning & Scheduling

VistaPlan keeps a risk-ranked audit universe with weighted risk factors and inherent/residual scoring, and builds the risk-based plan from it — so every line of the plan traces back to the risk that put it there.

—Frequently Asked

Questions audit leaders ask.

Is an audit universe mandatory under the IIA 2024 Standards?

No. Standard 9.4 requires a documented assessment of strategies, objectives and risks behind the plan. The audit universe appears in the Considerations for Implementation as one way to perform that assessment.

How often must the audit universe be updated?

The underlying risk assessment must be performed at least annually, and the plan must stay dynamic and be updated in a timely way as risks change.

Last reviewed October 2026. Standards references paraphrase The IIA's Global Internal Audit Standards (2024); they are not a substitute for the official text.

—Request a demo

See ControlVista run your audit lifecycle, end to end.

A 30-minute walkthrough with the team that built it — from the audit universe to the board-ready committee pack, in English and Arabic.

A product of Vantage Technologies.

We respond within one business day.