CORAA
CORAA University / Free planning tool

Internal audit risk scorer

Rank the audit universe across P2P, O2C, R2R, Cash & Bank, H2R, Inventory, Fixed Assets, Statutory Compliance, Treasury and ITGC before drafting the annual internal audit plan.

SIA 220 planningSIA 310 scopePDF + Excel exportRCM links
ResourcesSOW generator
Audit universe profile
Entity name
Planning period
Score each cycle
CycleImpactLikelihoodControl gapChange / complexityCompliance sensitivityScore
Procure to Pay
Vendor master, PO, GRN, invoice, MSME ageing and payments.
74
High
Order to Cash
Credit, dispatch, billing, collections, credit notes and receivables.
69
High
Record to Report
Close calendar, journals, reconciliations, provisions and reporting.
78
High
Cash and Bank
BRS, receipts, payments, bank mandates, stale items and petty cash.
71
High
H2R and Payroll
Hiring, onboarding, attendance, salary changes, PF, ESI, TDS and exits.
72
High
Inventory
Receipts, issues, stock counts, ageing, write-offs and valuation.
70
High
Fixed Assets
Capex, CWIP, FAR, tagging, depreciation, verification and disposal.
60
Medium
Statutory Compliance
GST, TDS/TCS, PF/ESI, ROC, MSME and compliance calendar.
85
Critical
Treasury
Borrowings, investments, covenants, bank guarantees and authority.
78
High
ITGC and Access
User access, change management, backups, privileged users and audit trail.
89
Critical
How CORAA uses this

From score to audit universe

Inside the Internal Audit module, this ranking becomes the planning layer: the audit universe drives cycle selection, the selected cycles seed the RCM repository, and high-risk cycles can be moved onto recurring monitoring rules.

Need the engagement boundary next? Draft the SOW or open the annual plan template.

How internal audit risk scoring works

An internal audit risk scorer ranks the audit universe before the annual plan is approved. It does not prove that a control failed; it decides where internal audit time should be spent first. The score should be revisited when business volume, ERP, management, regulations, prior findings or incidents change.

The model here weighs five planning dimensions: impact, likelihood, control gap, change and compliance sensitivity. High scores route a cycle to monthly or continuous monitoring; medium scores route to annual or rotational review. The result is a planning aid for the Board or Audit Committee, not an audit conclusion.

In CORAA, the same planning logic can seed the Internal Audit module: high-risk cycles become the first RCMs to confirm, test and monitor. Public templates show the structure; the module turns the chosen universe into assigned tests, evidence, observations, management responses and follow-up status.

Worked example — statutory compliance becomes the first review

A company has frequent GST/TDS reconciliation delays, new locations, and several prior compliance observations. P2P and inventory are important, but the compliance calendar is the most sensitive risk area this year.

Inputs
Impact5/5
Likelihood4/5
Control gap4/5
Change4/5
Compliance sensitivity5/5
Output
Risk bandCritical
Suggested frequencyMonthly or continuous monitoring
Planning responsePut statutory compliance early in the annual internal audit plan and design recurring exception rules.
The score is high because regulatory sensitivity, prior control gaps and business change combine. The correct use is prioritisation: define the scope, build the RCM, test evidence and track management action.

Common mistakes

Treating the score as an audit finding
A high score only says the cycle deserves audit attention. It does not prove a control failure until fieldwork, evidence review and management discussion support an observation.
Scoring every cycle the same
Audit-universe scoring is useful only if it reflects real differences: volume, system maturity, prior observations, compliance exposure, management change and fraud susceptibility.
Ignoring prior observations
Repeat findings and overdue ATR items should raise control-gap and likelihood scores. A clean-looking process with unresolved observations is not low risk.
Forgetting to update the universe mid-year
SIA planning is not a one-time spreadsheet. New ERP modules, acquisitions, fraud allegations, regulatory notices or management turnover should trigger a fresh risk review.

Frequently asked questions

What is an internal audit risk scorer?+
It is a planning tool that ranks processes or auditable areas in the audit universe using factors such as impact, likelihood, control maturity, business change and compliance sensitivity. The output helps decide what goes into the annual internal audit plan and how often it should be reviewed.
Is this the same as an RCM?+
No. The risk scorer ranks which cycles deserve attention. The RCM then documents risks, controls, control objectives, test procedures, evidence and results for the cycles selected for audit.
Which internal audit cycles should be scored?+
Common cycles include P2P, O2C, R2R, Cash and Bank, H2R/Payroll, Inventory, Fixed Assets, Statutory Compliance, Treasury and ITGC. Companies should add entity-specific areas such as production, projects, stores, logistics, capex, branches or shared services where relevant.
How often should the audit universe be updated?+
At least annually before the internal audit plan is approved, and again when there is a major business, ERP, regulatory, management or incident trigger. High-risk cycles may need quarterly, monthly or continuous monitoring.

Authoritative sources

MCA
Companies (Accounts) Rules, 2014 — Rule 13Rule 13(2) requires the Audit Committee or Board to formulate scope, functioning, periodicity and methodology in consultation with the internal auditor.
ICAI
ICAI IASB — Compendium of Standards on Internal AuditICAI lists the Compendium of Standards on Internal Audit as on February 2026 as applicable from 1 April 2026.
ICAI
ICAI IASB — Standards on Internal Audit publicationsCurrent SIA publications include overall planning, assignment planning, evidence, documentation, reporting and follow-up standards.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit resources hubInternal audit SOW generatorInternal audit annual plan templateRisk assessment matrix template
Share this tool
Last reviewed: 2026-08-27 · For informational purposes only — not professional advice.