Appearance
Audit Planning
Where to find it: Audit & Inspection, then Audit Management (/audit), then Plans.
An Audit Plan sets out what internal audit intends to examine over a planning period, and is approved by the audit committee or the Chief Audit Executive before work begins.
What a plan carries
| Field | Purpose |
|---|---|
| Title | What the plan covers |
| Planning period | The period it addresses |
| Objectives | What the plan is intended to achieve |
| Scope summary | What is in and out |
| Owner | Who prepared it |
| Status | Its governance state |
| Approved by and at | The approval record |
| Status | Meaning |
|---|---|
draft | Being prepared |
in_review | Submitted for approval |
approved | Approved and in force |
rejected | Returned |
archived | Superseded or complete |
The audit universe
OrviQ provides advisory risk-based planning signals across assets, business services and risks: explainable attention indicators drawn from the live platform.
Signals might include a business service with a high criticality tier and no audit coverage in three years, a risk rated Critical with degrading control assurance, or a third-party engagement classified as material with an overdue reassessment.
The audit universe is advisory only
It does not auto-create plans, auto-approve them, or determine coverage. It surfaces where attention may be warranted, with the reasoning visible, and leaves the planning judgement to the Chief Audit Executive.
Audit independence means the audit plan is the auditor's to set. A platform that generated the plan would be making a decision that is not its to make.
Governed plan approval
Plan approval consumes the organisational workflow layer:
Draft and submit plan, then audit review and approval, then approved or rejected.
The default is four-eye; six-eye and eight-eye chains are available through workflow template configuration where the audit committee requires a further stage.
Segregation of duties: the preparer cannot approve their own plan.
Requires audit.plan_manage to prepare and audit.plan_approve to approve.
From plan to engagement
Approved plans hold engagements. An engagement can also exist outside a plan — an unplanned or special engagement — and records that it did.
Permissions
| Action | Permission |
|---|---|
| View plans and programmes | audit.plan_read |
| Create, update and manage plans | audit.plan_manage |
| Approve or reject plans | audit.plan_approve |
All require the audit_management entitlement.
Example
Plan: FY2026 Internal Audit Plan.
| Element | Value |
|---|---|
| Period | FY2026 |
| Objectives | Provide assurance over the effectiveness of controls supporting the group's important business services and its regulatory obligations |
| Engagements | 14 |
| Owner | Chief Audit Executive |
| Approved by | Audit Committee Chair |
Universe signals that shaped it:
| Signal | Effect on the plan |
|---|---|
| Payments platform: critical tier, last audited 2023 | Engagement added, Q2 |
| Third-party engagement classified material, reassessment overdue | Included in the outsourcing engagement scope |
Risk RSK-2026-0014 Critical inherent, degrading control assurance | Privileged access engagement added, Q1 |
| Two business services with no BIA | Referred to the resilience engagement rather than a separate audit |
The last row is the interesting one: the CAE judged that two missing BIAs did not warrant a dedicated engagement and folded them into an existing scope. That judgement is exactly what the advisory universe leaves to a person.
Troubleshooting
"I cannot approve a plan I prepared." Segregation of duties. An independent approver is required.
"The audit universe shows a service we do not audit." It is advisory. Not everything it surfaces belongs in the plan; the plan is the auditor's judgement.
"Audit Management is not visible." Requires the audit_management entitlement and audit.engagement_read or audit.plan_read.