—IIA 2024 · Domains IV & V
Risk assessment at the plan and the engagement.
The Standards ask for risk assessment twice: once across the organization, to build the internal audit plan, and again inside each engagement, to set its objectives and scope. The two should connect — the engagement starts from what the plan-level assessment already knows.
—What the Standards Require
The requirements, in plain terms.
Standard 9.4
Internal Audit Plan
A documented assessment of the organization's strategies, objectives and risks, performed at least annually, underpins the plan.
Standard 13.2
Engagement Risk Assessment
Auditors understand the activity under review and identify, prioritise and assess its significant risks — including fraud risk.
Standard 9.1
Understanding Governance, Risk Management, and Control Processes
The CAE's understanding of governance, risk and control — across reporting, operations, assets and compliance — informs both assessments.
—In Practice
What it looks like when it's done well.
One scoring language
If the plan-level assessment and the engagement assessment use different scales, the link between "why we're auditing this" and "what we're testing" breaks. A consistent method across both keeps the story intact.
Fraud is named, not assumed
Standard 13.2 calls out fraud risk explicitly. Recording how fraud was considered in each engagement is simpler than explaining later why it wasn't.
Risk drives scope
The engagement risk assessment should visibly shape the objectives, scope and work program. If the scope could have been written without it, an assessor will notice.
—Evidence of Conformance
What an assessor will ask to see.
The annual, documented plan-level risk assessment (9.4)
An engagement risk assessment for each assurance engagement, including fraud consideration (13.2)
A visible link from assessed risks to engagement objectives and scope (13.2)
A consistent, documented risk-assessment methodology (9.3)
How ControlVista Supports It
VistaPlan & VistaField
VistaPlan scores the universe with weighted factors for the plan; VistaField carries that context into the engagement, where walkthroughs and the RACM drive what gets tested.
—Further Reading
From our resources.
—IIA 2024 Hub
More on the Standards.
—Frequently Asked
Questions audit leaders ask.
Is a documented engagement risk assessment always required?
For assurance engagements, Standard 13.2 expects auditors to identify and assess significant risks, including fraud. The Standards allow more flexibility on documenting it for advisory engagements.
How does the plan-level assessment relate to the engagement one?
The plan-level assessment (9.4) decides what to audit and when; the engagement assessment (13.2) decides what to focus on inside that engagement. The second should build on the first.
Last reviewed October 2026. Standards references paraphrase The IIA's Global Internal Audit Standards (2024); they are not a substitute for the official text.
—Request a demo
See ControlVista run your audit lifecycle, end to end.
A 30-minute walkthrough with the team that built it — from the audit universe to the board-ready committee pack, in English and Arabic.
A product of Vantage Technologies.
