Internal Audit Planning: Process, Scope & SIA 220

Internal Audit Planning: Process, Scope and SIA 220 Guide

Table of Contents:-

Internal audit planning is one of the most important stages of an effective internal audit. A properly designed internal audit plan enables an organisation to identify its key risk areas, determine audit priorities, allocate resources and establish the scope and frequency of internal audit assignments.

Rather than treating internal audit as a routine checking exercise, effective planning aligns the audit function with the organisation’s business objectives, risk profile, regulatory environment and internal control framework.

Businesses looking to establish or strengthen their audit framework may also refer to our Internal Audit Services in India.

What is Internal Audit Planning?

Internal audit planning is the process of determining what should be audited, why it should be audited, when the audit should be conducted and what resources should be deployed.

It provides a structured roadmap for conducting internal audits across different business functions, locations, processes and risk areas.

Readers who require an introduction to the overall concept can first refer to our What Is Internal Audit guide.

Why is Internal Audit Planning Important?

Internal audit planning helps an organisation:

  • identify significant business and operational risks;
  • prioritise high-risk processes;
  • determine the appropriate audit coverage;
  • allocate internal audit resources efficiently;
  • avoid duplication of audit efforts;
  • establish audit timelines and periodicity;
  • improve coordination with management;
  • ensure important business functions are not overlooked; and
  • provide meaningful assurance to management and those charged with governance.

Planning therefore converts the internal audit function from a reactive activity into a structured and risk-focused assurance mechanism.

SIA 220 and Conducting Overall Internal Audit Planning

The ICAI framework on Standards on Internal Audit includes SIA 220 – Conducting Overall Internal Audit Planning, dealing with overall planning of the internal audit function.

The overall plan is broader than an individual audit assignment. It considers the organisation as a whole and establishes the direction and priorities for internal audit coverage.

For a broader understanding of the applicable internal audit standards, see our Standards on Internal Audit in India guide.

Companies Act Perspective

Section 138 of the Companies Act, 2013 read with the Companies (Accounts) Rules, 2014 provides the statutory framework for internal audit for prescribed classes of companies.

The Audit Committee or the Board, in consultation with the internal auditor, determines the scope, functioning, periodicity and methodology for conducting internal audit.

For current statutory provisions, readers should refer to the Ministry of Corporate Affairs and applicable rules.

Two Levels of Internal Audit Planning

Internal audit planning can broadly operate at two levels.

Overall Internal Audit Plan

The overall internal audit plan is prepared for the organisation as a whole, generally covering a defined period such as a financial year.

It establishes the broad areas to be audited based on factors such as business significance, risk exposure, regulatory requirements and management priorities.

Assignment-Level Audit Plan

A detailed audit plan is subsequently developed for individual assignments, departments, processes or locations.

For example, separate assignments may cover:

  • procurement;
  • sales and receivables;
  • inventory;
  • payroll;
  • taxation and statutory compliance;
  • information technology;
  • fixed assets;
  • treasury; or
  • related-party transactions.

This enables the overall plan to be converted into specific executable audit assignments.

Key Elements of Internal Audit Planning

An effective internal audit planning exercise involves several interconnected elements.

Understanding the Business and its Environment

Before developing the audit plan, the internal auditor should understand the organisation’s:

  • business model;
  • industry;
  • organisational structure;
  • operating locations;
  • products and services;
  • financial processes;
  • applicable laws and regulations;
  • technology environment;
  • major stakeholders; and
  • strategic objectives.

Without adequate knowledge of the business, it is difficult to identify areas carrying significant risk.

Discussion with Management and Key Stakeholders

Planning should include appropriate discussions with senior management, process owners and other relevant stakeholders.

Such discussions help identify:

  • emerging risks;
  • significant operational changes;
  • management concerns;
  • new projects;
  • regulatory developments;
  • previous audit findings; and
  • areas requiring special attention.

The internal auditor should nevertheless maintain the necessary independence and professional judgement while determining audit priorities.

Developing the Audit Universe

An important component of internal audit planning is identifying the audit universe.

The audit universe represents the complete population of potentially auditable entities, processes, departments, locations, systems and activities within the organisation.

What Can Form Part of the Audit Universe?

Depending upon the organisation, the audit universe may include:

  • business divisions;
  • branches and locations;
  • departments;
  • financial processes;
  • operational processes;
  • IT systems;
  • legal and regulatory compliance;
  • subsidiaries;
  • projects;
  • outsourced activities; and
  • significant business cycles.

A properly documented audit universe reduces the possibility that a significant auditable area is unintentionally excluded.

Risk Assessment in Internal Audit Planning

Risk assessment is at the heart of modern internal audit planning.

Each auditable area should be evaluated according to its potential risk and significance.

Factors Considered During Risk Assessment

The internal auditor may consider:

  • financial exposure;
  • operational complexity;
  • regulatory exposure;
  • history of control weaknesses;
  • fraud vulnerability;
  • management concerns;
  • changes in systems or personnel;
  • transaction volume;
  • previous audit findings;
  • information technology dependence; and
  • strategic importance.

Higher-risk areas generally require greater audit attention.

For further understanding, refer to our detailed guide on Risk Based Internal Audit.

Linking Risk Assessment with Audit Frequency

Not every process needs to be audited with the same frequency.

For example, a high-risk process may require annual or more frequent review, whereas a comparatively low-risk activity may be reviewed less frequently.

This allows internal audit resources to be directed towards areas where they can provide the greatest assurance and value.

Determining the Scope of Internal Audit

After identifying and assessing the audit universe, the auditor determines the proposed scope of internal audit coverage.

Scope May Include

The scope can cover areas such as:

  • internal financial controls;
  • operational controls;
  • statutory compliance;
  • fraud risk;
  • procurement;
  • inventory;
  • revenue;
  • receivables;
  • expenses;
  • payroll;
  • information systems;
  • cybersecurity;
  • asset management; and
  • management reporting.

A properly defined scope reduces ambiguity between management and the internal auditor regarding the expected audit coverage.

Technology in Internal Audit Planning

Technology has become an important consideration in internal audit planning.

Understanding the Company’s Technology Environment

The auditor should understand the extent to which the organisation relies on:

  • ERP systems;
  • accounting software;
  • automated workflows;
  • cloud applications;
  • databases;
  • e-commerce systems; and
  • other technology platforms.

Technology dependence may significantly influence the organisation’s risk profile.

Using Technology in the Audit

Internal auditors may themselves use technology for:

  • data analytics;
  • exception identification;
  • trend analysis;
  • transaction testing;
  • sampling;
  • continuous monitoring; and
  • identifying unusual transactions.

Technology therefore affects both what needs to be audited and how the audit is performed.

Resource Allocation for Internal Audit

An internal audit plan must be realistic in terms of available resources.

Assessing Resource Requirements

Resource planning should consider:

  • number of audit assignments;
  • complexity of each assignment;
  • estimated audit hours;
  • specialist skills required;
  • availability of audit personnel;
  • geographical spread; and
  • technology requirements.

Competence of the Internal Audit Team

The team assigned to an audit should possess appropriate knowledge and skills relevant to the area being reviewed.

Specialist assistance may be necessary for areas such as information technology, cybersecurity, taxation or complex regulatory matters.

Documentation of Internal Audit Planning

The internal audit planning process should be properly documented.

Good documentation establishes how the audit universe, risk assessment, priorities and scope were determined.

This also creates an audit trail demonstrating the basis on which the overall internal audit plan was developed.

For detailed guidance, see our Internal Audit Documentation guide.

Important Planning Documents

Depending upon the organisation and engagement, documentation may include:

  • understanding of the business;
  • audit universe;
  • risk assessment;
  • management discussions;
  • previous audit observations;
  • resource assessment;
  • proposed audit calendar;
  • scope of individual assignments;
  • audit frequency;
  • reporting responsibilities; and
  • approved overall internal audit plan.

Approval and Periodic Review of the Internal Audit Plan

The overall plan should be appropriately discussed with management and placed before the competent governance authority in accordance with the organisation’s framework.

However, an internal audit plan should not become a static document.

When Should the Audit Plan Be Revised?

Changes may become necessary because of:

  • new business activities;
  • acquisitions or restructuring;
  • significant control failures;
  • regulatory changes;
  • introduction of new IT systems;
  • fraud incidents;
  • significant management changes; or
  • newly identified risks.

Accordingly, internal audit planning should remain responsive to changes in the organisation’s risk environment.

Internal Audit Planning and Internal Audit Process

Planning forms an important part of the overall internal audit lifecycle.

A typical sequence may include:

Understanding the Business → Identifying Audit Universe → Risk Assessment → Audit Planning → Assignment Execution → Documentation → Reporting → Follow-up

Our detailed Internal Audit Process guide explains the wider process.

Internal Audit Planning for Foreign-Owned Companies in India

Foreign-owned Indian companies may require additional attention during internal audit planning because their operations often involve both Indian regulatory requirements and group-level controls.

The audit plan may therefore need to consider:

  • related-party transactions;
  • intercompany agreements;
  • transfer pricing processes;
  • FEMA-related transactions;
  • group reporting;
  • global accounting policies;
  • information security;
  • delegated authority matrices; and
  • reconciliation between Indian operations and overseas group reporting.

A properly designed internal audit plan can help management identify local control and compliance gaps before they become significant issues.

How EzyBiz India Can Assist

EzyBiz India Consulting LLP assists Indian and foreign-owned businesses in designing and executing risk-focused internal audit programmes.

Our approach may include understanding business processes, developing the audit universe, identifying key risks, determining audit priorities, conducting internal audit assignments and reporting observations with practical recommendations.

For professional assistance, visit our Internal Audit Services in India.

Frequently Asked Questions

What is internal audit planning?

Internal audit planning is the process of determining the areas to be audited, their relative risks, audit frequency, scope, resources and timing so that internal audit activities are conducted systematically.

What is an overall internal audit plan?

An overall internal audit plan establishes the broad audit coverage and priorities for an organisation over a defined period, generally based on its audit universe and risk assessment.

What is an audit universe?

An audit universe is the complete population of potentially auditable business units, processes, locations, systems and activities of an organisation.

Why is risk assessment important in internal audit planning?

Risk assessment helps prioritise areas that may have greater financial, operational, compliance or strategic significance so that limited audit resources can be deployed effectively.

Who determines the scope of internal audit under the Companies Act?

For companies covered by the applicable provisions, the Audit Committee or Board, in consultation with the internal auditor, determines the scope, functioning, periodicity and methodology of internal audit.

Can an internal audit plan be changed during the year?

Yes. The plan may need revision when significant new risks, regulatory changes, control failures, business restructuring or other important developments occur.

Is internal audit planning different from an internal audit checklist?

Yes. Internal audit planning determines what, when, why and how much to audit, whereas an Internal Audit Checklist helps organise specific procedures and control areas to be examined during audit execution.

Related Services & Guides

Prepared By
Anil Agrawal, Chartered Accountant
EzyBiz India Consulting LLP, New Delhi

Last Updated
August 2026

Disclaimer
This article is intended for general informational purposes and should not be considered professional or legal advice. Internal audit requirements and procedures should be evaluated based on the applicable law, standards and circumstances of each organisation.