A Risk-Based Approach to Internal Audit Planning
An internal audit function that reviews every department on the same fixed rotation, regardless of how much risk that department actually carries, wastes hours on low-risk areas while high-risk areas go unchecked for years at a time. A risk-based approach flips that logic: audit frequency, depth, and staffing are driven by where the company is actually exposed, not by an alphabetical list of departments or a calendar habit inherited from the previous audit committee.
This article focuses on the practical mechanics of building that kind of plan: how to map a company’s risk universe, score and rank individual risks, construct an annual audit schedule around those scores, and avoid the mistakes that make risk-based programs fail in practice. It assumes the reader already understands what risk-based auditing is and how it differs from a traditional cyclical audit approach, and instead walks through how to actually build one.
Building the Risk Universe Before Setting Audit Priorities
Before any risk can be scored, it has to be identified and catalogued. The “risk universe” is the complete inventory of auditable entities, processes, and systems across the company, the raw list that risk scoring is later applied to. Skipping this step and jumping straight to scoring a handful of familiar risks is one of the most common reasons risk-based programs miss material exposures.
For most UAE companies, the risk universe should cover at least these categories:
- Financial reporting integrity: revenue recognition under IFRS 15, lease accounting under IFRS 16, and financial instrument classification under IFRS 9, particularly where estimates or management judgment are involved.
- Tax compliance: Corporate Tax registration and filing accuracy under Federal Decree-Law No. 47 of 2022, and VAT compliance under Federal Decree-Law No. 8 of 2017, including whether VAT return figures reconcile to the general ledger, a mismatch that is itself a known Federal Tax Authority audit trigger.
- AML/CFT exposure: for designated non-financial businesses and professions, obligations under Federal Decree-Law No. 10 of 2025 and its implementing Cabinet Resolution No. 134 of 2025, including customer due diligence records and MLRO reporting.
- Payroll and WPS compliance: salary transfer timing under the Wage Protection System, now tightened by Ministerial Resolution No. 340 of 2026, and gratuity calculation accuracy under Federal Decree-Law No. 33 of 2021.
- IT and cybersecurity controls: access management, segregation of duties within financial systems, and change control over ERP configurations.
- Operational and quality risk: for manufacturing, healthcare, and other regulated production environments, process controls tied to ISO and GMP standards.
A risk universe that only lists financial line items and ignores tax, AML, and payroll compliance risk will consistently underweight the areas most likely to trigger regulatory penalties, since those obligations sit outside the general ledger but carry some of the sharpest financial consequences when missed.
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
Step-by-Step: Constructing a Risk-Based Internal Audit Plan
Once the risk universe is documented, building the actual audit plan follows a repeatable sequence.
Step 1: Confirm the audit universe is complete. Cross-check the list against the organizational chart, the entity structure (including free zone and mainland entities separately, since each may carry different QFZP or licensing obligations), and any process not owned by a single department, such as intercompany transactions.
Step 2: Score each risk by likelihood and impact. A simple 1-5 scale for likelihood and 1-5 for impact, multiplied together, produces a workable risk score without requiring a statistical model. The worked example below shows how six typical risk areas might score for a mid-sized UAE trading company with a designated non-financial business exposure.
| Risk area | Likelihood (1-5) | Impact (1-5) | Risk score | Suggested audit cycle |
|---|---|---|---|---|
| Corporate Tax compliance and filing | 4 | 5 | 20 | Annual |
| VAT return reconciliation | 3 | 4 | 12 | Annual |
| AML/CFT customer due diligence records | 2 | 5 | 10 | Annual or semi-annual |
| IT access controls and segregation of duties | 3 | 4 | 12 | Annual |
| Payroll and WPS transfer timing | 3 | 3 | 9 | Every 12-18 months |
| Vendor and procurement management | 2 | 2 | 4 | Every 24-36 months |
A common banding treats a score of 15-25 as high priority (audited at least annually), 8-14 as medium priority (audited every 12-24 months), and below 8 as low priority (audited on a longer cycle or when a trigger event occurs, such as a system change or a new regulation). The exact thresholds should be set by the audit committee, but the logic stays the same: the highest scores get the most audit hours, not the departments that happen to be easiest to schedule.
Step 3: Rank and tier the results. Sort the scored risk universe from highest to lowest and group it into the priority bands above.
Step 4: Match staff and hours to each tier. High-scoring areas should get the most experienced auditors and the largest time allocation in the plan, not simply the most audits by count.
Step 5: Build the annual schedule. Convert the tiered list into a calendar that shows which areas are audited in which quarter, leaving room for at least one unscheduled review in case a new risk emerges mid-year.
Step 6: Get audit committee or board sign-off. Under Federal Law No. 32 of 2021 on Commercial Companies, public joint stock companies are required to maintain an audit committee with oversight of the internal audit function; other companies increasingly adopt the same governance layer voluntarily. The scoring methodology and the resulting plan should be presented and approved before execution begins, not after.
Step 7: Execute, then refresh the universe. Risk scores are not static. A new law, a new business line, an acquisition, or a system migration changes the risk profile and should trigger an update to the risk universe rather than waiting for the next annual cycle.
Applying Risk-Based Audits in ISO and GMP-Regulated Environments
For manufacturing, pharmaceutical, and healthcare companies operating under ISO or GMP quality systems, the same scoring logic applies with a few sector-specific inputs layered in:
- Classify each department or process by how directly it affects product safety and quality, since a defect in a production-critical process carries a different consequence than a defect in an administrative process.
- Review the history of recalls, nonconformances, and customer complaints; areas with a higher incident count should receive a higher likelihood score, not just a higher impact score.
- Check prior audit findings and regulatory inspection reports for gaps that were flagged but never fully closed.
- Factor in personnel and process changes since the last audit cycle; a department with significant staff turnover or a recent process change carries elevated risk even without a prior incident on record.
These inputs feed into the same risk universe and scoring table described above; they are simply the sector-specific detail that determines the likelihood and impact numbers for that category of risk.
Risk-Based Follow-Up: Turning Findings Into Prioritized Action
A risk-based approach does not end when fieldwork finishes. Each finding should be assigned its own risk level, separate from the risk score of the area it was found in, since a minor documentation gap and a control failure that could misstate Corporate Tax liability carry very different urgency even if they surface in the same audit.
High-risk findings should carry a shorter remediation deadline and go directly to the audit committee or board rather than being batched into a general management letter. Lower-risk findings can be tracked on a standard remediation log with periodic status updates. Reporting findings by risk level, rather than by department or by the order they were discovered, keeps the audit committee focused on what actually needs a decision rather than reading through a flat list of observations.
Common Mistakes When Adopting a Risk-Based Internal Audit Approach
Companies that move to a risk-based model tend to repeat a small set of avoidable mistakes:
- Scoring risk once and never updating it. A risk universe built two years ago will not reflect a new Corporate Tax filing obligation, an AML law change, or a new business line added since then.
- Letting each department score its own risk. Without a consistent methodology applied centrally, departments tend to under-score their own risk exposure, which quietly defeats the purpose of the exercise.
- Treating a low score as zero coverage. Risk-based does not mean risk-only. Low-priority areas still need baseline, cyclical coverage, or they become blind spots precisely because no one is checking them.
- Ignoring risks with no incident history. A newly introduced regulation has no track record of past failures to score against, but that does not make it low risk; it usually means the opposite, since the company has not yet had time to build compliant processes around it.
- No board or audit committee visibility into the scoring rationale. If the audit committee cannot see why one area was prioritized over another, they cannot meaningfully challenge or approve the plan, which undermines the governance value the exercise is meant to provide.
- Under-resourcing the highest-scored areas. Building a heat map and then allocating audit hours the same way as before defeats the entire purpose of scoring risk in the first place.
Also check: Internal Audit Services
Recent regulatory developments have added weight to getting this right. Ministerial Decision No. 84 of 2025 made external audit mandatory for all Qualifying Free Zone Persons, companies with revenue above AED 50 million, and all Tax Groups, effective for tax periods starting 1 January 2025. While that requirement covers statutory external audit rather than internal audit specifically, it has pushed many boards to formalize their internal risk and control oversight at the same time, since a mandatory external audit tends to surface control gaps that a well-scoped internal audit function should already be catching earlier and at lower cost.
Related: Corporate Tax Audit in UAE
Companies with AML/CFT obligations face a similar dynamic. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 extend personal liability to the Money Laundering Reporting Officer, which is itself a reason AML-related processes should score consistently high in the risk universe rather than being treated as a once-a-year compliance checkbox.
See also: AML Compliance Services in UAE
Frequently Asked Questions
What is a risk universe, and why does it matter for a risk-based internal audit plan?
Is a risk-based internal audit legally required for companies in the UAE?
How often should a company reassess its risk register or heat map?
What happens if an internal audit team keeps auditing on a fixed rotation instead of by risk score?
Can a risk-based approach mean some departments are never audited?
How does Farahat & Co. support UAE companies in building a risk-based internal audit program?
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Farahat & Co. works with UAE companies to build and run risk-based internal audit programs, from mapping the risk universe and setting a scoring methodology through to executing the audit plan and reporting findings by priority to management and the audit committee.
Contact Farahat & Co. today to discuss your risk-based internal audit plan requirements.
