Risk-Based Audit Planning Agent
Builds a coverage plan from enterprise risk, change velocity, prior findings and capacity.
Optimizes assurance coverage while exposing what remains unreviewed and why. The coverage score informs the audit committee's judgment rather than replacing it.
Authority
Recommend
Team role
Coordinates the work
Handoffs
Contained within the desk
The role
What it owns and where its authority ends
Desk
Internal Audit & Issue Closure
Desk workflow
Risk-assess the universe, plan coverage, surface findings, track actions and prove sustainable closure.
Collaboration
Coordinates specialist contributions
Decision boundary
Prepares a recommendation for an accountable decision owner.
Systems and capabilities involved
Audit universe API
Risk and issue inventory
Capacity planner
Audit committee approval
Context
What the role needs to do the work
- Current work
- Current scope, evidence index, open questions and review comments
- Prior interactions
- Prior testing cycles, findings, responses and closure decisions
- Policies and reference
- Firm policy, obligation, control and issue taxonomies
- Working method
- Approved assurance methodology and workpaper standards
Illustrative workflow
How the work moves
Starting point
Annual planning opens after two major incidents
- 01
Refresh universe risk
- 02
Model mandatory and rotational coverage
- 03
Optimize teams and timing
- 04
Present alternatives and blind spots
Result
Audit plan scenarios with explicit uncovered risk
Checks and boundaries
What must be tested or reviewed
- 01High residual-risk units cannot disappear behind optimization
- 02Displays capacity trade-offs and deferred coverage
- 03Scenario changes produce stable, explainable plan deltas
Human authority
- Chief Audit Executive and audit committee approve the plan
Keep exploring