Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

Approaches To Risk-Based Method For Internal Audits

A Risk-Based Approach to Internal Audit Planning

An internal audit function that reviews every department on the same fixed rotation, regardless of how much risk that department actually carries, wastes hours on low-risk areas while high-risk areas go unchecked for years at a time. A risk-based approach flips that logic: audit frequency, depth, and staffing are driven by where the company is actually exposed, not by an alphabetical list of departments or a calendar habit inherited from the previous audit committee.

This article focuses on the practical mechanics of building that kind of plan: how to map a company’s risk universe, score and rank individual risks, construct an annual audit schedule around those scores, and avoid the mistakes that make risk-based programs fail in practice. It assumes the reader already understands what risk-based auditing is and how it differs from a traditional cyclical audit approach, and instead walks through how to actually build one.

Building the Risk Universe Before Setting Audit Priorities

Before any risk can be scored, it has to be identified and catalogued. The “risk universe” is the complete inventory of auditable entities, processes, and systems across the company, the raw list that risk scoring is later applied to. Skipping this step and jumping straight to scoring a handful of familiar risks is one of the most common reasons risk-based programs miss material exposures.

For most UAE companies, the risk universe should cover at least these categories:

  • Financial reporting integrity: revenue recognition under IFRS 15, lease accounting under IFRS 16, and financial instrument classification under IFRS 9, particularly where estimates or management judgment are involved.
  • Tax compliance: Corporate Tax registration and filing accuracy under Federal Decree-Law No. 47 of 2022, and VAT compliance under Federal Decree-Law No. 8 of 2017, including whether VAT return figures reconcile to the general ledger, a mismatch that is itself a known Federal Tax Authority audit trigger.
  • AML/CFT exposure: for designated non-financial businesses and professions, obligations under Federal Decree-Law No. 10 of 2025 and its implementing Cabinet Resolution No. 134 of 2025, including customer due diligence records and MLRO reporting.
  • Payroll and WPS compliance: salary transfer timing under the Wage Protection System, now tightened by Ministerial Resolution No. 340 of 2026, and gratuity calculation accuracy under Federal Decree-Law No. 33 of 2021.
  • IT and cybersecurity controls: access management, segregation of duties within financial systems, and change control over ERP configurations.
  • Operational and quality risk: for manufacturing, healthcare, and other regulated production environments, process controls tied to ISO and GMP standards.

A risk universe that only lists financial line items and ignores tax, AML, and payroll compliance risk will consistently underweight the areas most likely to trigger regulatory penalties, since those obligations sit outside the general ledger but carry some of the sharpest financial consequences when missed.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

Step-by-Step: Constructing a Risk-Based Internal Audit Plan

Once the risk universe is documented, building the actual audit plan follows a repeatable sequence.

Step 1: Confirm the audit universe is complete. Cross-check the list against the organizational chart, the entity structure (including free zone and mainland entities separately, since each may carry different QFZP or licensing obligations), and any process not owned by a single department, such as intercompany transactions.

Step 2: Score each risk by likelihood and impact. A simple 1-5 scale for likelihood and 1-5 for impact, multiplied together, produces a workable risk score without requiring a statistical model. The worked example below shows how six typical risk areas might score for a mid-sized UAE trading company with a designated non-financial business exposure.

Risk areaLikelihood (1-5)Impact (1-5)Risk scoreSuggested audit cycle
Corporate Tax compliance and filing4520Annual
VAT return reconciliation3412Annual
AML/CFT customer due diligence records2510Annual or semi-annual
IT access controls and segregation of duties3412Annual
Payroll and WPS transfer timing339Every 12-18 months
Vendor and procurement management224Every 24-36 months

A common banding treats a score of 15-25 as high priority (audited at least annually), 8-14 as medium priority (audited every 12-24 months), and below 8 as low priority (audited on a longer cycle or when a trigger event occurs, such as a system change or a new regulation). The exact thresholds should be set by the audit committee, but the logic stays the same: the highest scores get the most audit hours, not the departments that happen to be easiest to schedule.

Step 3: Rank and tier the results. Sort the scored risk universe from highest to lowest and group it into the priority bands above.

Step 4: Match staff and hours to each tier. High-scoring areas should get the most experienced auditors and the largest time allocation in the plan, not simply the most audits by count.

Step 5: Build the annual schedule. Convert the tiered list into a calendar that shows which areas are audited in which quarter, leaving room for at least one unscheduled review in case a new risk emerges mid-year.

Step 6: Get audit committee or board sign-off. Under Federal Law No. 32 of 2021 on Commercial Companies, public joint stock companies are required to maintain an audit committee with oversight of the internal audit function; other companies increasingly adopt the same governance layer voluntarily. The scoring methodology and the resulting plan should be presented and approved before execution begins, not after.

Step 7: Execute, then refresh the universe. Risk scores are not static. A new law, a new business line, an acquisition, or a system migration changes the risk profile and should trigger an update to the risk universe rather than waiting for the next annual cycle.

Applying Risk-Based Audits in ISO and GMP-Regulated Environments

For manufacturing, pharmaceutical, and healthcare companies operating under ISO or GMP quality systems, the same scoring logic applies with a few sector-specific inputs layered in:

  • Classify each department or process by how directly it affects product safety and quality, since a defect in a production-critical process carries a different consequence than a defect in an administrative process.
  • Review the history of recalls, nonconformances, and customer complaints; areas with a higher incident count should receive a higher likelihood score, not just a higher impact score.
  • Check prior audit findings and regulatory inspection reports for gaps that were flagged but never fully closed.
  • Factor in personnel and process changes since the last audit cycle; a department with significant staff turnover or a recent process change carries elevated risk even without a prior incident on record.

These inputs feed into the same risk universe and scoring table described above; they are simply the sector-specific detail that determines the likelihood and impact numbers for that category of risk.

Risk-Based Follow-Up: Turning Findings Into Prioritized Action

A risk-based approach does not end when fieldwork finishes. Each finding should be assigned its own risk level, separate from the risk score of the area it was found in, since a minor documentation gap and a control failure that could misstate Corporate Tax liability carry very different urgency even if they surface in the same audit.

High-risk findings should carry a shorter remediation deadline and go directly to the audit committee or board rather than being batched into a general management letter. Lower-risk findings can be tracked on a standard remediation log with periodic status updates. Reporting findings by risk level, rather than by department or by the order they were discovered, keeps the audit committee focused on what actually needs a decision rather than reading through a flat list of observations.

Common Mistakes When Adopting a Risk-Based Internal Audit Approach

Companies that move to a risk-based model tend to repeat a small set of avoidable mistakes:

  • Scoring risk once and never updating it. A risk universe built two years ago will not reflect a new Corporate Tax filing obligation, an AML law change, or a new business line added since then.
  • Letting each department score its own risk. Without a consistent methodology applied centrally, departments tend to under-score their own risk exposure, which quietly defeats the purpose of the exercise.
  • Treating a low score as zero coverage. Risk-based does not mean risk-only. Low-priority areas still need baseline, cyclical coverage, or they become blind spots precisely because no one is checking them.
  • Ignoring risks with no incident history. A newly introduced regulation has no track record of past failures to score against, but that does not make it low risk; it usually means the opposite, since the company has not yet had time to build compliant processes around it.
  • No board or audit committee visibility into the scoring rationale. If the audit committee cannot see why one area was prioritized over another, they cannot meaningfully challenge or approve the plan, which undermines the governance value the exercise is meant to provide.
  • Under-resourcing the highest-scored areas. Building a heat map and then allocating audit hours the same way as before defeats the entire purpose of scoring risk in the first place.

Also check: Internal Audit Services

Recent regulatory developments have added weight to getting this right. Ministerial Decision No. 84 of 2025 made external audit mandatory for all Qualifying Free Zone Persons, companies with revenue above AED 50 million, and all Tax Groups, effective for tax periods starting 1 January 2025. While that requirement covers statutory external audit rather than internal audit specifically, it has pushed many boards to formalize their internal risk and control oversight at the same time, since a mandatory external audit tends to surface control gaps that a well-scoped internal audit function should already be catching earlier and at lower cost.

Related: Corporate Tax Audit in UAE

Companies with AML/CFT obligations face a similar dynamic. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 extend personal liability to the Money Laundering Reporting Officer, which is itself a reason AML-related processes should score consistently high in the risk universe rather than being treated as a once-a-year compliance checkbox.

See also: AML Compliance Services in UAE

Frequently Asked Questions

What is a risk universe, and why does it matter for a risk-based internal audit plan?

A risk universe is the complete inventory of a company’s auditable entities, processes, and systems before any risk scoring is applied. It matters because a risk-based audit plan can only prioritize risks that have been identified in the first place; skipping the risk universe step and scoring only a handful of familiar areas is one of the main reasons risk-based programs leave material exposures unaudited.

Is a risk-based internal audit legally required for companies in the UAE?

Internal audit itself is not mandated for every UAE company. Federal Law No. 32 of 2021 on Commercial Companies requires public joint stock companies to maintain an audit committee with oversight of internal audit, and many other companies adopt a risk-based internal audit function voluntarily as a governance practice. This is separate from Ministerial Decision No. 84 of 2025, which makes external statutory audit mandatory for Qualifying Free Zone Persons, companies with revenue above AED 50 million, and all Tax Groups.

How often should a company reassess its risk register or heat map?

At minimum, once a year, before the next annual audit plan is built. The risk universe should also be updated outside that cycle whenever a material event occurs: a new regulation such as a Corporate Tax or AML law change, a new business line, an acquisition, or a significant system migration.

What happens if an internal audit team keeps auditing on a fixed rotation instead of by risk score?

High-risk areas can go years without meaningful review while low-risk areas are audited repeatedly out of habit. This increases the chance that a control failure in a high-exposure area, such as Corporate Tax filing accuracy or AML customer due diligence, goes undetected until it results in a regulatory penalty or a qualified external audit finding.

Can a risk-based approach mean some departments are never audited?

No. A properly built risk-based plan still assigns a baseline audit cycle to low-scoring areas, typically every 24-36 months, rather than removing them from coverage entirely. Treating a low risk score as zero coverage creates blind spots that eventually resurface as higher-risk items once enough time passes without any review.

How does Farahat & Co. support UAE companies in building a risk-based internal audit program?

Farahat & Co. supports companies in mapping their risk universe, scoring and prioritizing risk areas, and building an internal audit plan aligned to current UAE regulatory obligations, including Corporate Tax, VAT, and AML/CFT requirements, alongside operational and financial reporting risk.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. works with UAE companies to build and run risk-based internal audit programs, from mapping the risk universe and setting a scoring methodology through to executing the audit plan and reporting findings by priority to management and the audit committee.

Contact Farahat & Co. today to discuss your risk-based internal audit plan requirements.

×

Hold On!

Business decisions are easier with the right guidance.