| Area | Entity | Owner | Inherent risk | Control gap | Prior findings | Change | Compliance | Quarter | Hours | Reviewer | Score | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
70 High | ||||||||||||
66 High | ||||||||||||
82 Critical | ||||||||||||
70 High | ||||||||||||
67 High | ||||||||||||
66 High | ||||||||||||
56 Medium | ||||||||||||
85 Critical | ||||||||||||
76 High | ||||||||||||
90 Critical |
Need the next workpaper? Use the SOW generator, then build the RCM and PBC list.
An internal audit annual plan converts the audit universe into a calendar of reviews. It should explain why certain cycles are reviewed early or frequently, how hours are allocated, who will review them and which high-risk areas need continuous monitoring.
This generator scores each auditable area using inherent risk, control gap, prior findings, business change and compliance sensitivity. The score does not create an audit conclusion; it creates a defensible planning priority for discussion with management and the Audit Committee or Board.
In CORAA, the annual plan can become live work: selected cycles flow into SOW, RCM, PBC, fieldwork, observations, action taken reporting and dashboard follow-up.
A company has a new ERP rollout, unresolved leaver-access observations and frequent GST/TDS reconciliation delays. Inventory and O2C are important, but ITGC and compliance have higher governance exposure.