CORAA
Resources · Risk-Based Planning

Audit universe taxonomy.

An internal audit universe is the full population of auditable areas before the annual plan is selected. A good universe includes processes, legal entities, locations, systems, outsourced activities, regulatory obligations, projects and new technology risks, then scores them with a consistent risk taxonomy.

Score the universeBuild annual plan
Downloads

Audit universe workbook workbook

Download the Excel/PDF pack for audit universe inventory, risk taxonomy, scoring model, coverage heatmap, annual-plan feed and product data dictionary.

Universe fields

What the audit universe should include include

Auditable unit

Name the process, legal entity, location, system, product line, project, outsourced activity or regulatory obligation that can be audited.

Risk category

Use consistent categories such as financial reporting, compliance, operational resilience, cyber, data privacy, fraud, third-party, ESG or AI governance.

Risk owner

Assign the executive or process owner accountable for controls, remediation and risk acceptance. Avoid unnamed department-level ownership.

Inherent risk

Score impact and likelihood before considering current control strength so high-exposure areas are visible.

Control confidence

Record management controls, second-line monitoring, prior audit results, incident history and known deficiencies.

Assurance coverage

Map last internal audit, planned audit, second-line work, external assurance and uncovered areas.

Plan decision

Translate the rating into audit frequency, review type, quarter, hours, specialist need and deferral rationale.

Risk taxonomy

Use consistent risk language language

The taxonomy should be specific enough to drive planning, RCM selection, monitoring rules and dashboard reporting. If every risk is called operational risk, the annual plan cannot explain why one area was selected and another was deferred.

Strategic and change

New products, restructuring, integrations, major projects, process redesign and business-model change.

Financial reporting

Close process, journals, reconciliations, estimates, provisions, intercompany, revenue recognition and reporting access.

Compliance and regulatory

Companies Act, GST, income tax, labour law, sector regulation, filings, notices and licence obligations.

Operations

P2P, O2C, inventory, fixed assets, manufacturing, logistics, service delivery, quality and customer commitments.

Technology and cyber

ITGC, privileged access, change management, backups, interfaces, cloud operations, incident response and audit logs.

Fraud and conduct

Override, conflicts, kickbacks, fabricated vendors, ghost employees, revenue leakage, expense abuse and whistleblower themes.

Third-party and outsourcing

Vendor criticality, data sharing, sub-outsourcing, SLA failure, BCP, exit rights and concentration risk.

Data, AI and automation

Data quality, AI use cases, model changes, human review, prompt leakage, automation errors and monitoring blind spots.

Scoring

How to rank the universe prioritise

Impact

Financial exposure, operational disruption, customer harm, regulatory consequence, reputational impact and management attention.

Likelihood

Transaction volume, complexity, change, manual intervention, system fragmentation, prior exceptions and incident frequency.

Control weakness

Known design gaps, failed testing, overdue actions, weak SoD, poor evidence, unreviewed reports or excessive overrides.

Change intensity

ERP migration, new locations, new products, reorganisation, new law, leadership change or process outsourcing.

Assurance gap

No recent audit, no reliable second-line work, unavailable evidence, limited specialist coverage or repeated deferral.

Audit priority

Use total score to decide annual plan inclusion, cadence, monitoring, advisory review, specialist review or deferral.

Quality checks

Mistakes that weaken risk-based planning avoid

Universe mirrors the org chart

Departments are listed, but systems, outsourced work, regulatory obligations and major projects are missing.

Every item has the same risk label

Generic labels like operational risk do not help prioritisation or plan explanation.

Scoring is not evidenced

Ratings are based on workshop opinion with no link to incidents, KRIs, losses, control failures or prior findings.

Coverage is confused with ownership

A second-line owner or dashboard is treated as assurance without testing scope and evidence review.

Plan excludes high-risk gaps silently

Budget or capacity constraints are real, but deferrals need rationale and committee visibility.

Taxonomy cannot feed tools

Free-text risk names prevent analytics, monitoring rules, dashboard metrics and product workflows from connecting.

Authority anchors

Sources to verify before issuing cite

IIA Global Internal Audit Standards

Use the 2024 Standards for risk-based planning, governance communication, board oversight and alignment of internal audit work with organisational risks.

IIA Developing a Risk-Based Internal Audit Plan

Use the IIA practice guide on developing a risk-based internal audit plan to connect the audit universe, risk assessment and limited internal-audit resources.

ICAI SIA 130, 140, 210, 220, 230 and 310

For Indian internal audit files, anchor risk management, governance, function management, overall planning, objectives and assignment planning to the ICAI SIA framework.

Companies Act Section 138 and Rule 13

For covered Indian companies, connect the audit universe to the approved scope, functioning, periodicity and methodology of internal audit.

Product reuse

Website resource now, product reference data later later

This public template can become reference data for the separate Internal Audit product build. The important part is stable field names: universe item, risk category, owner, score, coverage and plan decision should remain consistent across planning, RCM, testing, reporting and dashboards.

Audit universe master

Planning module: Unit ID, process, entity, location, system, owner, risk category, score and status.

Risk taxonomy

Risk library: Category, sub-risk, definition, related cycles, typical controls, monitoring candidates and issue themes.

Scoring model

Risk scorer: Impact, likelihood, control weakness, change intensity, assurance gap, override rationale and reviewer sign-off.

Coverage heatmap

Command centre: Last audit, next due date, second-line work, external input, current coverage and uncovered risk.

Plan feed

Annual plan builder: Priority, review type, quarter, estimated hours, specialist need, deferral reason and committee note.

Data dictionary

Product onboarding: Canonical field names that let RCM, PBC, testing, observations, monitoring and dashboards join cleanly.

Related resources

Use the universe through the full audit lifecycle next

Internal Audit Risk Scorer

Turn universe items into ranked priorities using impact, likelihood, control gaps, change and compliance sensitivity.

Internal Audit Annual Plan Generator

Convert ranked universe items into quarterly plan, hours, reviewers, cadence and committee summary.

Three Lines Assurance Map

Map assurance providers and reliance decisions against the same universe and risk taxonomy.

Internal Audit Control Repository

Use taxonomy categories to select RCM controls and tests for each cycle.

Continuous Monitoring Rules Repository

Convert high-frequency or high-risk universe items into recurring exception rules.

Internal Audit Dashboard KPIs

Report coverage, overdue high risks, assurance gaps and plan progress with consistent taxonomy labels.

FAQs

Audit universe questions answered

What is an internal audit universe?

An internal audit universe is the complete list of auditable areas that may need internal audit coverage: processes, entities, locations, systems, projects, outsourced activities, products and regulatory obligations.

How is an audit universe different from an annual audit plan?

The audit universe is the full population of possible audit areas. The annual audit plan is the selected subset for a period, based on risk score, assurance coverage, capacity and committee-approved priorities.

What should an internal audit risk taxonomy include?

A useful taxonomy defines risk categories, sub-risks, descriptions, related process cycles, typical controls, monitoring indicators and issue themes so planning, RCMs, observations and dashboards use the same language.

How often should the audit universe be refreshed?

Refresh the audit universe at least annually and whenever there is material change: new systems, acquisitions, regulatory changes, incidents, business restructuring, outsourcing, new AI use cases or major process redesign.