CORAA
CORAA University / Free planning tool

Internal audit annual plan generator

Turn an audit universe into a quarter-wise, risk-ranked annual plan with estimated hours, reviewers, continuous monitoring candidates and an audit committee summary.

Plan profile
Auditable areas
10
Critical/high
9
Estimated hours
656
Monitoring candidates
6
Audit universe and annual plan
AreaEntityOwnerInherent riskControl gapPrior findingsChangeComplianceQuarterHoursReviewerScore
70
High
66
High
82
Critical
70
High
67
High
66
High
56
Medium
85
Critical
76
High
90
Critical
Q1
304 hrs
ITGC and Access
Critical / 90
Statutory and Tax Compliance
Critical / 85
Record to Report
Critical / 82
Procure to Pay
High / 70
Q2
192 hrs
Cash and Bank
High / 67
Order to Cash
High / 66
Inventory
High / 66
Q3
104 hrs
Hire to Retire / Payroll
High / 70
Fixed Assets
Medium / 56
Q4
56 hrs
Treasury and Cash Management
High / 76
Where it fits

From universe to approved plan

The annual plan sits between the risk scorer and fieldwork. It converts the audit universe into a Board or Audit Committee approved calendar, then feeds the SOW, RCM builder, PBC request list, cycle programmes and monitoring rules.

Need the next workpaper? Use the SOW generator, then build the RCM and PBC list.

How a risk-based internal audit annual plan works

An internal audit annual plan converts the audit universe into a calendar of reviews. It should explain why certain cycles are reviewed early or frequently, how hours are allocated, who will review them and which high-risk areas need continuous monitoring.

This generator scores each auditable area using inherent risk, control gap, prior findings, business change and compliance sensitivity. The score does not create an audit conclusion; it creates a defensible planning priority for discussion with management and the Audit Committee or Board.

In CORAA, the annual plan can become live work: selected cycles flow into SOW, RCM, PBC, fieldwork, observations, action taken reporting and dashboard follow-up.

Worked example - ITGC and statutory compliance move into Q1

A company has a new ERP rollout, unresolved leaver-access observations and frequent GST/TDS reconciliation delays. Inventory and O2C are important, but ITGC and compliance have higher governance exposure.

Inputs
ITGC scoreHigh / Critical
Compliance scoreHigh / Critical
Plan responseQ1 review and recurring monitoring rules
Output
PDFCommittee-ready annual plan summary
ExcelAudit universe, quarterly plan and monitoring candidates
The plan prioritises the areas where system change, prior findings and statutory sensitivity combine. Fieldwork still needs an approved scope, RCM, evidence testing and management discussion.

Common mistakes

Treating the annual plan as a static calendar
The plan should change when ERP, business volume, management, acquisitions, incidents or regulations change. High-risk areas may need mid-year rescoping.
Ignoring available audit hours
A risk-ranked plan that exceeds team capacity will fail in execution. Show estimated hours and quarter loading before the plan is approved.
Scheduling everything annually
Low-risk areas can sit on rotation, while high-risk areas may need quarterly review or continuous monitoring. The frequency logic should be explicit.
Approving cycles without data availability
Before locking the plan, confirm source reports, system access, process owners and PBC timelines. Otherwise fieldwork starts with avoidable delays.

Frequently asked questions

What is an internal audit annual plan?+
It is a risk-based schedule of internal audit reviews for the year. It starts from the audit universe, ranks auditable areas by risk, assigns quarters and estimated hours, and sets out what management or the Audit Committee is being asked to approve.
What should an audit universe include?+
Common auditable areas include P2P, O2C, R2R, Cash and Bank, H2R/Payroll, Inventory, Fixed Assets, Statutory Compliance, Treasury and ITGC. Companies should add business-specific areas such as plants, branches, projects, stores, logistics, shared services or regulated activities.
Is this annual plan enough for Section 138 internal audit?+
No. It is a planning aid. The final scope, periodicity and methodology should be agreed through the company governance process, and each assignment still needs an SOW, RCM, evidence file, report and follow-up tracker.
How is this different from an internal audit risk scorer?+
The risk scorer ranks the audit universe. The annual plan generator turns that ranking into quarter-wise coverage, hours, reviewer allocation, monitoring candidates and audit committee summary wording.

Authoritative sources

MCA
Companies (Accounts) Rules, 2014 - Rule 13Rule 13(2) requires the Audit Committee or Board to formulate scope, functioning, periodicity and methodology in consultation with the internal auditor.
ICAI
ICAI IASB - Compendium of Standards on Internal AuditICAI lists Standards on Internal Audit including overall planning, assignment planning, risk management, documentation, reporting and follow-up.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit risk scorerAnnual plan Word templateInternal audit SOW generatorCycle-wise audit programmesInternal audit software for enterprise teams
Share this tool
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.