CORAA
Resources · Dynamic Risk Assessment

Internal audit plan refresh.

Dynamic risk assessment in internal audit means refreshing the risk view during the year when new signals show that the approved annual plan is no longer enough. The point is not constant churn; it is controlled plan change with evidence, capacity impact and Audit Committee visibility.

Use this pack when cyber incidents, AI deployments, vendor failures, compliance notices, ERP changes, fraud indicators or dashboard exceptions should change what internal audit covers next.

Open 2026 risk mapRefresh annual plan
Downloads

Dynamic risk refresh workbook workbook

Download the Excel/PDF pack for risk signals, trigger thresholds, movement scoring, plan-change decisions, committee approval, capacity impact and product-reuse fields.

Risk signals

Signals that should reopen the plan move

Cyber or access incident

Privilege changes, ransomware attempt, data leak, failed backup, third-party breach or repeat access exception.

AI or automation rollout

New AI system, model change, chatbot deployment, automated approval, OCR workflow or exception engine goes live.

Business model change

New geography, channel, product, acquisition, outsourcing model, shared service centre or ERP migration.

Compliance or regulator signal

Notice, inspection, audit qualification, enforcement update, tax position change or licence condition.

Financial volatility

Margin drop, working-capital stress, covenant pressure, inventory ageing, write-off spike or unusual journal pattern.

Control failure trend

Repeat finding, overdue ATR, weak closure evidence, monitoring exception spike or management override indicator.

Cadence

A practical refresh cadence rhythm

Monthly signal scan

Review incidents, dashboards, monitoring exceptions, regulator updates, business changes and management requests.

Quarterly plan refresh

Re-score moved risks, add/defer reviews, test capacity and document committee rationale.

Event-driven refresh

Trigger outside the quarterly cycle for cyber events, fraud indicators, acquisitions, ERP changes or major control failures.

Annual reset

Roll unresolved movements into the next audit universe, annual plan, assurance map and capacity model.

Plan change log

How to respond when risk moves decide

Add review

Risk movement is high, assurance gap exists, timing is urgent and capacity can be created or co-sourced.

Accelerate review

Planned audit exists but risk timing changed; move quarter, revise scope and update evidence request list.

Expand scope

Original scope misses the moved risk, system change, location, vendor, data feed or compliance exposure.

Defer review

Risk reduced or better assurance exists elsewhere; document residual risk and approval for material changes or as required by the approved methodology.

Convert to monitoring

Risk needs recurring exception testing instead of one-time fieldwork.

Escalate to investigation

Signal indicates fraud, override, data breach or regulatory exposure outside normal internal audit timing.

Authority anchors

Sources to cite in the refresh memo document

IIA Global Internal Audit Standards

Use risk-based planning, communication with the board, quality and performance expectations when the plan changes during the year.

IIA Risk in Focus 2026

Use current risk themes such as cyber, digital disruption, AI, third-party dependency and geopolitical uncertainty as external scan inputs, not as a substitute for entity-specific risk assessment.

ICAI Standards on Internal Audit

Connect the refresh to SIA 120 internal controls, SIA 130 risk management, SIA 220 overall internal audit planning, SIA 310 assignment planning, SIA 320 evidence, SIA 330 documentation, SIA 350 review and supervision, SIA 360 communication, SIA 370 reporting, SIA 390 follow-up and expert/provider standards where relevant.

Companies Act Section 138 and Rule 13

For covered Indian companies, scope, functioning, periodicity and methodology should remain aligned with the Board or Audit Committee process; material interim changes should follow the approved governance route.

Product reuse

Website resource now, risk sensing workflow later workflow

This public resource can become specification input for the separate Internal Audit product build: risk signals, movement scores, plan-change decisions, capacity impact, committee approvals and monitoring handoffs.

Risk signal register

Risk sensing: Signal type, source, owner, date, severity, affected auditable unit and evidence link.

Movement score

Audit universe: Previous score, current score, movement reason, trigger threshold and reviewer override.

Plan change log

Annual planning: Add, accelerate, expand, defer, convert-to-monitoring or investigate decision with committee rationale.

Capacity impact

Resource planner: Hours added, hours released, quarter impact, specialist need, co-source action and buffer usage.

Committee pack

Reporting: Moved risks, decision rationale, limitations, open actions and approval status.

Monitoring handoff

Continuous monitoring: Exception rule candidate, source data readiness, threshold owner and false-positive route.

Related resources

Use this with planning, capacity and monitoring next

Internal Audit Priority Risk Areas 2026

Use the trend map to seed the external signal register.

Audit Universe & Risk Taxonomy

Attach every moved risk to a stable auditable unit and risk taxonomy.

Internal Audit Annual Plan Generator

Convert approved plan changes into quarter, hours, owner and committee-summary fields.

Resource Capacity Planner

Check whether accelerated or added reviews can actually be delivered.

Three Lines Assurance Map

Check whether second-line or external assurance already covers the moved risk.

Continuous Monitoring Rules

Turn recurring risk signals into reviewed exception rules.

FAQs

Dynamic risk assessment questions answered

What is dynamic risk assessment in internal audit?

Dynamic risk assessment is the process of refreshing the internal audit risk view during the year when incidents, dashboards, business changes, regulatory signals or control failures show that the approved plan no longer matches current risk.

Does Indian law require monthly internal audit plan refreshes?

No universal monthly statutory refresh requirement applies. For Section 138 companies, Rule 13 links internal audit scope, functioning, periodicity and methodology with Board or Audit Committee consultation. A documented refresh cadence is a governance control, not a fixed legal calendar; material plan changes should follow the approved methodology and governance route.

When should the internal audit plan be changed mid-year?

Change the plan when a risk moves materially, assurance coverage is weak, timing is urgent, and capacity can be created without leaving higher-risk areas uncovered. Document additions, accelerations, scope expansions, deferrals and conversions to monitoring; take material changes through the approval route set in the internal audit methodology.

How should internal audit document a plan refresh?

Keep the trigger evidence, before/after risk score, affected audit universe item, proposed response, capacity impact, assurance-map impact, management input, CAE conclusion and Audit Committee or Board approval trail.