Skip to content

Audit Planning

Where to find it: Audit & Inspection, then Audit Management (/audit), then Plans.

An Audit Plan sets out what internal audit intends to examine over a planning period, and is approved by the audit committee or the Chief Audit Executive before work begins.


What a plan carries

FieldPurpose
TitleWhat the plan covers
Planning periodThe period it addresses
ObjectivesWhat the plan is intended to achieve
Scope summaryWhat is in and out
OwnerWho prepared it
StatusIts governance state
Approved by and atThe approval record
StatusMeaning
draftBeing prepared
in_reviewSubmitted for approval
approvedApproved and in force
rejectedReturned
archivedSuperseded or complete

The audit universe

OrviQ provides advisory risk-based planning signals across assets, business services and risks: explainable attention indicators drawn from the live platform.

Signals might include a business service with a high criticality tier and no audit coverage in three years, a risk rated Critical with degrading control assurance, or a third-party engagement classified as material with an overdue reassessment.

The audit universe is advisory only

It does not auto-create plans, auto-approve them, or determine coverage. It surfaces where attention may be warranted, with the reasoning visible, and leaves the planning judgement to the Chief Audit Executive.

Audit independence means the audit plan is the auditor's to set. A platform that generated the plan would be making a decision that is not its to make.


Governed plan approval

Plan approval consumes the organisational workflow layer:

Draft and submit plan, then audit review and approval, then approved or rejected.

The default is four-eye; six-eye and eight-eye chains are available through workflow template configuration where the audit committee requires a further stage.

Segregation of duties: the preparer cannot approve their own plan.

Requires audit.plan_manage to prepare and audit.plan_approve to approve.


From plan to engagement

Approved plans hold engagements. An engagement can also exist outside a plan — an unplanned or special engagement — and records that it did.


Permissions

ActionPermission
View plans and programmesaudit.plan_read
Create, update and manage plansaudit.plan_manage
Approve or reject plansaudit.plan_approve

All require the audit_management entitlement.


Example

Plan: FY2026 Internal Audit Plan.

ElementValue
PeriodFY2026
ObjectivesProvide assurance over the effectiveness of controls supporting the group's important business services and its regulatory obligations
Engagements14
OwnerChief Audit Executive
Approved byAudit Committee Chair

Universe signals that shaped it:

SignalEffect on the plan
Payments platform: critical tier, last audited 2023Engagement added, Q2
Third-party engagement classified material, reassessment overdueIncluded in the outsourcing engagement scope
Risk RSK-2026-0014 Critical inherent, degrading control assurancePrivileged access engagement added, Q1
Two business services with no BIAReferred to the resilience engagement rather than a separate audit

The last row is the interesting one: the CAE judged that two missing BIAs did not warrant a dedicated engagement and folded them into an existing scope. That judgement is exactly what the advisory universe leaves to a person.


Troubleshooting

"I cannot approve a plan I prepared." Segregation of duties. An independent approver is required.

"The audit universe shows a service we do not audit." It is advisory. Not everything it surfaces belongs in the plan; the plan is the auditor's judgement.

"Audit Management is not visible." Requires the audit_management entitlement and audit.engagement_read or audit.plan_read.


OrviQ Enterprise Governance, Risk & Compliance Platform