The Global Internal Audit Standards, effective January 2025, made something explicit that good functions already believed: under Standard 9.4, the risk assessment that underpins the internal audit plan must be documented and reviewed at least annually.
It sounds modest. In practice, for a lot of functions, it is a quiet challenge to how the audit universe is actually maintained.
Most "risk-based" plans are built from the audit universe, not the risk universe
A common pattern: the audit universe is a list of departments, functions, or processes. The plan rotates through that list. It feels risk-based because each entity has a risk rating attached — but the starting point is the org chart, not the risks.
A genuinely risk-based approach inverts this. It starts from the risks and asks which entities are affected by them. The difference matters most exactly when the business is changing fastest, because new risks rarely respect last year's list of auditable units.
The data problem
The most common obstacle to an accurate universe is mundane: the information is incomplete or out of date. Risk perception is also subjective — two team members will rate the same exposure differently — and the business environment moves faster than an annual cycle can track.
When the universe is a spreadsheet refreshed once a year, by the time the plan is approved the picture it was based on has already shifted.
What "at least annually" really asks for
Standard 9.4 sets a floor, not a target. The intent is a living assessment:
- Documented — you can show how risk drove the plan, not just assert that it did.
- Refreshed at least annually — and updated immediately when a significant business change or major new risk emerges, rather than waiting for the next cycle.
- Traceable — the link from a risk, to an auditable entity, to a line in the plan, to an engagement, is visible and defensible to the audit committee.
The leading practice is closer to continuous reassessment than to a static annual planning event.
What this means in practice
If your universe lives in a workbook, meeting the spirit of 9.4 means somebody re-keys risk factors, re-scores entities, and re-versions the plan by hand — and hopes the committee never asks to see the trail.
A living universe does this differently:
- Auditable entities carry weighted risk factors with inherent and residual scoring that can be re-assessed continuously.
- The plan is generated from that scoring, with version history on every change.
- Coverage is reported against the universe and the multi-year rotation, so the board can judge whether the plan is reaching the right risks over time.
That is the job VistaPlan, the planning module in ControlVista, is built to do — keep the universe alive, turn it into a board-approved plan, and make the whole chain traceable.