Risk Based Internal Audit: Process, Approach & Key Considerations
Table of Contents:-
Risk Based Internal Audit (RBIA) is an internal audit approach that focuses audit resources on the areas and risks that have the greatest potential to affect an organisation’s ability to achieve its objectives.
Instead of giving equal audit attention to every process or transaction, a risk-based approach identifies significant risks, evaluates their likelihood and impact, considers the effectiveness of existing controls and prioritises internal audit activities accordingly.
This enables internal audit to focus on matters that are most important to the organisation, its management and those charged with governance.
The Institute of Chartered Accountants of India (ICAI) has published guidance on Risk-Based Internal Audit, while The Institute of Internal Auditors (IIA) also requires internal audit planning to be aligned with organisational strategies, objectives and risks.
Companies looking to implement or outsource a risk-focused internal audit function may also refer to our Internal Audit Services in India.
What Is Risk Based Internal Audit?
Risk Based Internal Audit is an approach under which internal audit activities are planned and performed after considering the significant risks affecting the achievement of organisational objectives.
The process ordinarily involves:
- understanding organisational objectives;
- identifying significant risks;
- understanding management’s risk appetite;
- evaluating inherent risks;
- assessing existing controls;
- determining residual risks;
- prioritising auditable areas;
- developing a risk-based internal audit plan;
- conducting individual audit engagements;
- reporting significant findings; and
- monitoring corrective actions.
ICAI’s Technical Guide explains RBIA as an approach that focuses on organisational objectives and the management of risks rather than merely examining controls and individual transactions.
For professional guidance, refer to the ICAI Generic Internal Audit Guides.
Why Is Risk Based Internal Audit Important?
Traditional internal audit programmes can sometimes become heavily checklist-driven.
For example, an auditor may review:
- 20 purchase transactions;
- 20 sales transactions;
- 10 employee reimbursements;
- 10 fixed assets; and
- 10 vendor payments
simply because these areas were examined in previous years.
Risk-based internal audit asks a different question:
What could prevent the organisation from achieving its objectives, and which of those risks require the greatest audit attention?
This allows internal audit resources to be directed toward matters with potentially greater impact.
The IIA’s current guidance on developing a risk-based internal audit plan emphasises aligning limited internal audit resources with an organisation’s most significant risks.
Objectives of Risk Based Internal Audit
The principal objectives of RBIA may include:
- identifying significant business risks;
- evaluating whether management has appropriately identified risks;
- assessing the adequacy of risk responses;
- evaluating internal controls over significant risks;
- determining whether residual risks remain within acceptable levels;
- providing assurance regarding governance, risk management and controls;
- identifying emerging risks;
- improving allocation of internal audit resources; and
- providing useful information to management and the Board.
RBIA therefore extends beyond transaction checking and focuses on matters affecting achievement of business objectives.
Traditional Internal Audit vs Risk Based Internal Audit
A traditional or checklist-based audit may focus primarily on whether prescribed procedures and controls have been followed.
Risk-based internal audit starts with the organisation’s objectives and risks.
For example:
Traditional approach:
Were purchase orders properly approved?
Risk-based approach:
What procurement risks could materially affect cost, supply continuity, fraud exposure or operational performance, and are those risks appropriately controlled?
Similarly:
Traditional approach:
Were customer credit limits approved?
Risk-based approach:
Could inadequate credit management lead to significant bad debts or cash-flow problems, and are controls sufficient to manage that risk?
A checklist remains useful, but it should support—not determine—the entire audit strategy.
For a detailed operational checklist, see our Internal Audit Checklist for Companies in India.
Risk Based Internal Audit Process
A structured RBIA process may broadly involve the following stages.
1. Understand the Business and Its Objectives
The first step is developing a proper understanding of the organisation.
The internal auditor should understand matters such as:
- business model;
- products and services;
- organisational structure;
- strategic objectives;
- revenue model;
- customers;
- suppliers;
- geographical operations;
- regulatory environment;
- information systems;
- financial structure;
- major contracts;
- competitive environment; and
- significant changes in the business.
Without understanding the organisation’s objectives, it is difficult to identify risks that could prevent those objectives from being achieved.
2. Understand the Industry and External Environment
Risk does not arise only from internal processes.
The auditor should consider external factors such as:
- economic conditions;
- regulatory changes;
- technological developments;
- cybersecurity threats;
- competition;
- supply-chain disruption;
- foreign exchange movements;
- geopolitical developments;
- changes in customer behaviour;
- environmental risks; and
- industry-specific developments.
For example, a company heavily dependent on imported raw materials may have significant foreign exchange and supply-chain risks even where its internal procurement controls are strong.
3. Identify the Audit Universe
The audit universe represents the collection of auditable areas, processes, entities, systems or activities that could potentially be reviewed by internal audit.
Depending upon the organisation, the audit universe may include:
- procurement;
- sales;
- receivables;
- inventory;
- manufacturing;
- payroll;
- human resources;
- treasury;
- taxation;
- legal and compliance;
- information technology;
- cybersecurity;
- fixed assets;
- projects;
- branch operations;
- regulatory compliance;
- related-party transactions;
- financial reporting; and
- corporate governance.
Defining the audit universe helps ensure that important business areas are considered during risk assessment.
4. Identify Risks
The next step is identifying risks associated with the organisation’s objectives and auditable areas.
Risks may include:
Strategic Risks
- failure of business strategy;
- loss of key customers;
- competitive disruption;
- expansion failure; and
- adverse market developments.
Financial Risks
- liquidity problems;
- credit losses;
- foreign exchange exposure;
- incorrect financial reporting;
- fraud; and
- treasury risks.
Operational Risks
- supply-chain disruption;
- production failure;
- inventory loss;
- process inefficiencies;
- dependence on key employees; and
- inadequate business continuity.
Compliance Risks
- Companies Act non-compliance;
- GST and income-tax non-compliance;
- FEMA violations;
- labour-law violations;
- licensing failures; and
- industry-specific regulatory breaches.
Technology Risks
- cybersecurity incidents;
- unauthorised system access;
- data loss;
- system downtime;
- inadequate backups; and
- weak change-management controls.
Fraud Risks
- vendor fraud;
- employee fraud;
- management override;
- fictitious transactions;
- duplicate payments;
- inventory theft; and
- manipulation of financial information.
5. Determine Risk Appetite and Risk Tolerance
An important consideration in RBIA is understanding the organisation’s risk appetite.
Risk appetite represents the amount and type of risk an organisation is prepared to accept while pursuing its objectives.
Risk tolerance represents acceptable variation or thresholds around particular objectives or risks.
For example, management may accept:
- a small level of inventory loss;
- a specified customer credit exposure;
- limited foreign exchange exposure; or
- certain operational downtime.
However, management may have extremely low tolerance for:
- regulatory violations;
- fraud;
- data breaches;
- employee safety failures; or
- significant financial misstatement.
Understanding these thresholds helps internal audit determine which risk exposures require greater attention.
6. Assess Inherent Risk
Inherent risk is the level of risk existing before considering the effect of controls.
The auditor may assess inherent risk considering factors such as:
- financial impact;
- transaction volume;
- complexity;
- regulatory exposure;
- fraud susceptibility;
- management judgement;
- system dependency;
- geographical spread;
- historical issues; and
- rate of change.
A process involving high-value transactions and significant regulatory exposure may have high inherent risk even if strong controls currently exist.
7. Assess Likelihood and Impact
Risks are commonly evaluated based on:
Likelihood – probability that the risk may occur.
Impact – severity of consequences if the risk occurs.
A simple rating system may be:
Likelihood: Low / Medium / High
Impact: Low / Medium / High
or numerical scores such as:
1 = Low
2 = Moderate
3 = High
4 = Very High
5 = Critical
A risk matrix can then be used to prioritise significant risks.
8. Evaluate Existing Controls
After identifying inherent risks, the auditor should understand controls implemented by management.
Controls may include:
- segregation of duties;
- approval matrices;
- maker-checker controls;
- reconciliations;
- system validations;
- exception reports;
- physical safeguards;
- access controls;
- management reviews;
- policies and SOPs;
- monitoring controls; and
- automated controls.
The internal auditor should consider both control design and operating effectiveness.
A control may be well designed but ineffective if employees do not actually follow it.
9. Determine Residual Risk
Residual risk is the risk remaining after considering management’s controls and risk responses.
For example:
Inherent Risk: High
Control Effectiveness: Strong
Residual Risk: Medium
Alternatively:
Inherent Risk: High
Control Effectiveness: Weak
Residual Risk: High
High residual-risk areas generally warrant greater internal audit attention.
10. Prepare a Risk Register
A risk register can provide a structured record of identified risks.
Typical information may include:
- business objective;
- process;
- risk description;
- risk category;
- risk owner;
- likelihood;
- impact;
- inherent risk rating;
- existing controls;
- control effectiveness;
- residual risk;
- risk response; and
- proposed audit coverage.
The risk register should be periodically updated because business risks change over time.
11. Develop a Risk Based Internal Audit Plan
Once risks have been assessed and prioritised, the internal audit plan can be developed.
Higher-risk areas may receive:
- more frequent audits;
- broader scope;
- larger samples;
- specialist resources;
- data analytics;
- surprise reviews; or
- continuous monitoring.
Lower-risk areas may receive less frequent or narrower reviews.
The IIA’s current guidance describes risk-based planning as a systematic process designed to align internal audit resources with the organisation’s most pressing issues.
Refer to the IIA Guide on Developing a Risk-Based Internal Audit Plan.
12. Obtain Management and Board Input
Risk assessment should not be performed in isolation.
Internal audit should appropriately interact with:
- senior management;
- process owners;
- risk-management teams;
- compliance personnel;
- finance leadership;
- information technology teams; and
- the Board or Audit Committee, where applicable.
Management owns and manages business risks.
Internal audit independently evaluates whether risk-management and control processes are adequate and effective.
Management input helps internal audit understand:
- strategic priorities;
- emerging risks;
- operational concerns;
- major changes;
- planned investments;
- known control weaknesses; and
- areas requiring assurance.
However, management involvement should not compromise internal audit independence.
13. Define Individual Audit Objectives and Scope
Each internal audit engagement should have clearly defined objectives.
For example:
Instead of defining the scope simply as:
“Purchase Audit”
a risk-based objective could be:
“Evaluate whether procurement controls adequately mitigate risks relating to unauthorised purchases, vendor concentration, conflicts of interest, excessive pricing and supply disruption.”
This creates a much more focused audit.
The IIA’s 2026 guidance on engagement planning similarly emphasises defining objectives and scope based on the risks relevant to the activity being reviewed.
14. Design Risk-Based Audit Procedures
Audit procedures should respond to identified risks.
These may include:
- interviews;
- walkthroughs;
- document inspection;
- transaction testing;
- control testing;
- analytical procedures;
- data analytics;
- observation;
- confirmations;
- system access reviews;
- surprise checks; and
- physical verification.
Sampling should also be aligned with risk.
Higher-risk transactions may require larger samples or 100% testing.
For detailed guidance, see Sampling in Internal Audit.
15. Evaluate Findings Based on Risk
Internal audit observations should be evaluated according to their potential impact rather than merely counting exceptions.
For example:
Observation A: 10 minor documentation errors with negligible financial impact.
Observation B: One administrator has unrestricted ability to create vendors and process payments.
Although Observation B involves only one control weakness, its potential fraud exposure may make it significantly more important.
Risk-based reporting therefore focuses on significance, not merely the number of exceptions.
16. Determine Root Cause
An effective risk-based audit should identify why a control failure occurred.
Possible root causes include:
- inadequate policy;
- unclear responsibility;
- system limitation;
- inadequate training;
- lack of supervision;
- poor segregation of duties;
- insufficient resources;
- management override; or
- ineffective monitoring.
Recommendations addressing root causes are generally more effective than recommendations dealing only with symptoms.
17. Report Significant Risks
The internal audit report should communicate:
- audit objective;
- scope;
- significant risks;
- observations;
- risk implications;
- root causes;
- recommendations;
- management responses;
- responsible persons; and
- target completion dates.
Findings may be classified as:
- Critical;
- High;
- Medium; or
- Low
depending upon the organisation’s methodology.
The rating system should be consistently applied and linked to clearly defined criteria.
18. Monitor Corrective Actions
RBIA does not end when the audit report is issued.
Internal audit should monitor whether management has implemented agreed corrective actions.
Follow-up may consider:
- outstanding observations;
- risk rating;
- responsible person;
- agreed action;
- due date;
- implementation status;
- evidence of closure; and
- revised residual risk.
Unresolved high-risk observations should be appropriately escalated.
19. Continuously Update the Risk Assessment
Risk-based internal audit should be dynamic.
The internal audit plan may require modification when significant developments occur, such as:
- acquisition or merger;
- new business line;
- major system implementation;
- cybersecurity incident;
- regulatory change;
- significant fraud;
- senior management changes;
- business restructuring;
- rapid growth;
- new geographical market; or
- major economic disruption.
The IIA’s guidance specifically recognises that risk-based internal audit plans should respond to changes in business, risks, operations, systems and controls.
Key Considerations in Risk Based Internal Audit
The following considerations are particularly important when implementing RBIA.
Understand Business Objectives
The auditor should understand what the organisation is trying to achieve before determining which risks matter most.
Involve Management Appropriately
Management should provide information about business objectives, risk ownership, emerging concerns and risk responses.
Maintain Internal Audit Independence
Management participation in risk assessment should not allow management to restrict legitimate audit scope or suppress significant findings.
Understand Risk Appetite
Audit priorities should consider whether residual risks are consistent with the organisation’s risk appetite and tolerance.
Focus on Significant Risks
Internal audit resources are limited. They should be allocated according to risk significance rather than historical audit routines.
Consider Emerging Risks
The audit plan should consider future-facing risks, not merely problems identified in previous years.
Use Data and Analytics
Data analytics can help identify:
- unusual transactions;
- control overrides;
- duplicate payments;
- transactions on holidays;
- payments just below approval limits;
- unusual journal entries; and
- emerging patterns.
Consider Fraud Risk
Fraud risk should form part of risk assessment rather than being treated as a completely separate exercise.
Review Risk Assessment Periodically
An annual risk assessment alone may be insufficient for rapidly changing businesses. Significant changes may require interim reassessment.
Example of Risk Based Internal Audit
Assume a manufacturing company has the following processes:
- procurement;
- inventory;
- payroll;
- sales;
- treasury; and
- IT.
After risk assessment, the internal auditor identifies:
Cybersecurity – Critical Risk
Procurement fraud – High Risk
Inventory loss – High Risk
Customer credit – Medium Risk
Payroll – Low Risk
Instead of giving every process equal audit time, the annual plan may allocate:
- extensive audit coverage to cybersecurity;
- detailed procurement testing;
- inventory controls and physical verification;
- limited credit-control review; and
- periodic payroll review.
This is the core principle of RBIA: audit effort follows risk.
Risk Matrix Example
A simple risk matrix may evaluate:
Impact: Low / Medium / High
against:
Likelihood: Low / Medium / High
For example:
High Impact + High Likelihood = Critical/High Risk
High Impact + Low Likelihood = Significant Risk requiring judgement
Low Impact + Low Likelihood = Lower Priority
The precise methodology should be customised according to the organisation.
Benefits of Risk Based Internal Audit
RBIA can provide several benefits:
- better alignment with business objectives;
- greater focus on significant risks;
- improved allocation of audit resources;
- stronger risk management;
- better Board and management insights;
- identification of emerging risks;
- improved internal controls;
- more meaningful audit findings;
- reduced unnecessary transaction checking; and
- greater value from the internal audit function.
Challenges in Implementing RBIA
Risk-based internal audit can also present challenges.
These may include:
- inadequate risk-management framework;
- incomplete risk registers;
- unclear organisational objectives;
- insufficient management involvement;
- weak risk ownership;
- lack of reliable data;
- rapidly changing risks;
- inadequate internal audit resources;
- insufficient industry knowledge; and
- difficulty assessing emerging risks.
Where the organisation’s risk-management maturity is low, internal audit may need to adapt its approach while maintaining appropriate independence.
Risk Based Internal Audit for Foreign-Owned Companies in India
RBIA can be particularly useful for Indian subsidiaries of foreign companies because they often operate within both Indian regulatory requirements and global group policies.
Potential risk areas may include:
- FEMA compliance;
- transfer pricing;
- inter-company transactions;
- GST;
- withholding taxes;
- overseas payments;
- related-party transactions;
- group reporting;
- information security;
- delegation of authority;
- procurement;
- local statutory compliance; and
- alignment with global policies.
A risk-based audit programme can help overseas headquarters obtain greater assurance over Indian operations without relying only on financial transaction testing.
Risk Based Internal Audit and Internal Audit Checklist
RBIA does not mean that audit checklists should be abandoned.
The two tools serve different purposes.
Risk-Based Internal Audit: Determines where internal audit should focus.
Internal Audit Checklist: Helps determine what procedures should be performed within the selected area.
A strong internal audit function can therefore use both.
See our detailed Internal Audit Checklist for Companies in India.
Risk Based Internal Audit and Audit Sampling
Risk assessment can also influence sampling.
For example:
High-risk process: larger sample or 100% testing of specific transactions.
Medium-risk process: moderate sample.
Low-risk process: smaller sample where appropriate.
However, sample size should not be determined solely by a simple risk rating. Population characteristics, expected errors, audit objectives and other relevant factors must also be considered.
Read our detailed guide on Sampling in Internal Audit.
Frequently Asked Questions
What is Risk Based Internal Audit?
Risk Based Internal Audit is an internal audit approach that identifies and prioritises significant organisational risks and focuses audit resources on evaluating how those risks are being managed.
What is the main objective of RBIA?
The main objective is to provide assurance regarding whether significant risks affecting organisational objectives are appropriately identified, managed and controlled.
What is the difference between traditional internal audit and RBIA?
Traditional internal audit may focus heavily on transaction checking and compliance with existing procedures. RBIA begins with business objectives and risks and directs audit effort toward areas of greatest significance.
What is a risk-based internal audit plan?
It is an internal audit plan developed after assessing and prioritising organisational risks. Higher-risk areas generally receive greater or more frequent audit coverage.
What is inherent risk?
Inherent risk is the level of risk existing before considering the effectiveness of controls or risk responses.
What is residual risk?
Residual risk is the level of risk remaining after considering the controls and other risk responses implemented by management.
What is risk appetite?
Risk appetite is the amount and type of risk an organisation is willing to accept in pursuit of its objectives.
Is management involved in Risk Based Internal Audit?
Management input is important because management owns and manages business risks. However, internal audit should maintain its independence and independently evaluate risk-management and control processes.
Is RBIA applicable only to large companies?
No. The principles can be adapted according to the size, complexity, risk profile and resources of an organisation.
Does RBIA eliminate transaction testing?
No. Transaction testing remains important where relevant. RBIA helps determine which areas and risks deserve greater attention and how audit procedures should be designed.
How often should risk assessment be updated?
Risk assessment should be reviewed periodically and when significant changes occur in the business, regulatory environment, systems, operations or risk profile.
Risk Based Internal Audit Services in India
EzyBiz India Consulting LLP assists Indian and foreign-owned companies with internal audit, risk assessment, internal control reviews, process audits and compliance reviews.
Our approach focuses on understanding business objectives, identifying significant risks, evaluating controls and providing practical recommendations to management.
For professional assistance, visit our Internal Audit Services in India or explore our broader Audit and Assurance Services in India.
Related Services
- Internal Audit Services in India
- Internal Audit Checklist for Companies in India
- Sampling in Internal Audit
- Internal Audit Activity Charter
- Audit and Assurance Services in India
Authoritative References
- ICAI – Technical Guide on Risk Based Internal Audit
- ICAI – Internal Audit Standards Board
- The Institute of Internal Auditors – Global Internal Audit Standards
- The IIA – Developing a Risk-Based Internal Audit Plan
Prepared By: EzyBiz India Consulting LLP
Reviewed By: Anil Agrawal, Chartered Accountant
Last Updated: August 2026
Disclaimer
The information provided on this page is for general informational and educational purposes only and should not be construed as audit, legal, accounting, risk-management or regulatory advice. The scope and methodology of a Risk Based Internal Audit depend upon the organisation’s objectives, industry, size, risk profile, internal controls, regulatory environment and specific circumstances. Professional judgement should be applied while designing and conducting internal audit engagements, and appropriate professional advice should be obtained based on the facts and circumstances of each organisation.