An internal audit universe is the full population of auditable areas before the annual plan is selected. A good universe includes processes, legal entities, locations, systems, outsourced activities, regulatory obligations, projects and new technology risks, then scores them with a consistent risk taxonomy.
Download the Excel/PDF pack for audit universe inventory, risk taxonomy, scoring model, coverage heatmap, annual-plan feed and product data dictionary.
Name the process, legal entity, location, system, product line, project, outsourced activity or regulatory obligation that can be audited.
Use consistent categories such as financial reporting, compliance, operational resilience, cyber, data privacy, fraud, third-party, ESG or AI governance.
Assign the executive or process owner accountable for controls, remediation and risk acceptance. Avoid unnamed department-level ownership.
Score impact and likelihood before considering current control strength so high-exposure areas are visible.
Record management controls, second-line monitoring, prior audit results, incident history and known deficiencies.
Map last internal audit, planned audit, second-line work, external assurance and uncovered areas.
Translate the rating into audit frequency, review type, quarter, hours, specialist need and deferral rationale.
The taxonomy should be specific enough to drive planning, RCM selection, monitoring rules and dashboard reporting. If every risk is called operational risk, the annual plan cannot explain why one area was selected and another was deferred.
New products, restructuring, integrations, major projects, process redesign and business-model change.
Close process, journals, reconciliations, estimates, provisions, intercompany, revenue recognition and reporting access.
Companies Act, GST, income tax, labour law, sector regulation, filings, notices and licence obligations.
P2P, O2C, inventory, fixed assets, manufacturing, logistics, service delivery, quality and customer commitments.
ITGC, privileged access, change management, backups, interfaces, cloud operations, incident response and audit logs.
Override, conflicts, kickbacks, fabricated vendors, ghost employees, revenue leakage, expense abuse and whistleblower themes.
Vendor criticality, data sharing, sub-outsourcing, SLA failure, BCP, exit rights and concentration risk.
Data quality, AI use cases, model changes, human review, prompt leakage, automation errors and monitoring blind spots.
Financial exposure, operational disruption, customer harm, regulatory consequence, reputational impact and management attention.
Transaction volume, complexity, change, manual intervention, system fragmentation, prior exceptions and incident frequency.
Known design gaps, failed testing, overdue actions, weak SoD, poor evidence, unreviewed reports or excessive overrides.
ERP migration, new locations, new products, reorganisation, new law, leadership change or process outsourcing.
No recent audit, no reliable second-line work, unavailable evidence, limited specialist coverage or repeated deferral.
Use total score to decide annual plan inclusion, cadence, monitoring, advisory review, specialist review or deferral.
Departments are listed, but systems, outsourced work, regulatory obligations and major projects are missing.
Generic labels like operational risk do not help prioritisation or plan explanation.
Ratings are based on workshop opinion with no link to incidents, KRIs, losses, control failures or prior findings.
A second-line owner or dashboard is treated as assurance without testing scope and evidence review.
Budget or capacity constraints are real, but deferrals need rationale and committee visibility.
Free-text risk names prevent analytics, monitoring rules, dashboard metrics and product workflows from connecting.
This public template can become reference data for the separate Internal Audit product build. The important part is stable field names: universe item, risk category, owner, score, coverage and plan decision should remain consistent across planning, RCM, testing, reporting and dashboards.
Planning module: Unit ID, process, entity, location, system, owner, risk category, score and status.
Risk library: Category, sub-risk, definition, related cycles, typical controls, monitoring candidates and issue themes.
Risk scorer: Impact, likelihood, control weakness, change intensity, assurance gap, override rationale and reviewer sign-off.
Command centre: Last audit, next due date, second-line work, external input, current coverage and uncovered risk.
Annual plan builder: Priority, review type, quarter, estimated hours, specialist need, deferral reason and committee note.
Product onboarding: Canonical field names that let RCM, PBC, testing, observations, monitoring and dashboards join cleanly.
An internal audit universe is the complete list of auditable areas that may need internal audit coverage: processes, entities, locations, systems, projects, outsourced activities, products and regulatory obligations.
The audit universe is the full population of possible audit areas. The annual audit plan is the selected subset for a period, based on risk score, assurance coverage, capacity and committee-approved priorities.
A useful taxonomy defines risk categories, sub-risks, descriptions, related process cycles, typical controls, monitoring indicators and issue themes so planning, RCMs, observations and dashboards use the same language.
Refresh the audit universe at least annually and whenever there is material change: new systems, acquisitions, regulatory changes, incidents, business restructuring, outsourcing, new AI use cases or major process redesign.