Dynamic risk assessment in internal audit means refreshing the risk view during the year when new signals show that the approved annual plan is no longer enough. The point is not constant churn; it is controlled plan change with evidence, capacity impact and Audit Committee visibility.
Use this pack when cyber incidents, AI deployments, vendor failures, compliance notices, ERP changes, fraud indicators or dashboard exceptions should change what internal audit covers next.
Download the Excel/PDF pack for risk signals, trigger thresholds, movement scoring, plan-change decisions, committee approval, capacity impact and product-reuse fields.
Privilege changes, ransomware attempt, data leak, failed backup, third-party breach or repeat access exception.
New AI system, model change, chatbot deployment, automated approval, OCR workflow or exception engine goes live.
New geography, channel, product, acquisition, outsourcing model, shared service centre or ERP migration.
Notice, inspection, audit qualification, enforcement update, tax position change or licence condition.
Margin drop, working-capital stress, covenant pressure, inventory ageing, write-off spike or unusual journal pattern.
Repeat finding, overdue ATR, weak closure evidence, monitoring exception spike or management override indicator.
Review incidents, dashboards, monitoring exceptions, regulator updates, business changes and management requests.
Re-score moved risks, add/defer reviews, test capacity and document committee rationale.
Trigger outside the quarterly cycle for cyber events, fraud indicators, acquisitions, ERP changes or major control failures.
Roll unresolved movements into the next audit universe, annual plan, assurance map and capacity model.
Risk movement is high, assurance gap exists, timing is urgent and capacity can be created or co-sourced.
Planned audit exists but risk timing changed; move quarter, revise scope and update evidence request list.
Original scope misses the moved risk, system change, location, vendor, data feed or compliance exposure.
Risk reduced or better assurance exists elsewhere; document residual risk and approval for material changes or as required by the approved methodology.
Risk needs recurring exception testing instead of one-time fieldwork.
Signal indicates fraud, override, data breach or regulatory exposure outside normal internal audit timing.
This public resource can become specification input for the separate Internal Audit product build: risk signals, movement scores, plan-change decisions, capacity impact, committee approvals and monitoring handoffs.
Risk sensing: Signal type, source, owner, date, severity, affected auditable unit and evidence link.
Audit universe: Previous score, current score, movement reason, trigger threshold and reviewer override.
Annual planning: Add, accelerate, expand, defer, convert-to-monitoring or investigate decision with committee rationale.
Resource planner: Hours added, hours released, quarter impact, specialist need, co-source action and buffer usage.
Reporting: Moved risks, decision rationale, limitations, open actions and approval status.
Continuous monitoring: Exception rule candidate, source data readiness, threshold owner and false-positive route.
Dynamic risk assessment is the process of refreshing the internal audit risk view during the year when incidents, dashboards, business changes, regulatory signals or control failures show that the approved plan no longer matches current risk.
No universal monthly statutory refresh requirement applies. For Section 138 companies, Rule 13 links internal audit scope, functioning, periodicity and methodology with Board or Audit Committee consultation. A documented refresh cadence is a governance control, not a fixed legal calendar; material plan changes should follow the approved methodology and governance route.
Change the plan when a risk moves materially, assurance coverage is weak, timing is urgent, and capacity can be created without leaving higher-risk areas uncovered. Document additions, accelerations, scope expansions, deferrals and conversions to monitoring; take material changes through the approval route set in the internal audit methodology.
Keep the trigger evidence, before/after risk score, affected audit universe item, proposed response, capacity impact, assurance-map impact, management input, CAE conclusion and Audit Committee or Board approval trail.