Audit Planning Agent
Builds the risk-based audit plan and scopes engagements.
Synthesizes risk assessments, prior findings, incident data and regulatory focus into a defensible risk-based audit universe and annual plan, then drafts the scope for each engagement; the chief audit executive recommends the plan and the board audit committee approves it.
Authority
Act within policy
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Internal Audit
Desk workflow
Risk-based annual planning and scoping, then fieldwork (evidence gathering and control testing), then findings, reporting and issue follow-up, with conclusions re-checked by a reviewing audit agent and owned by the accountable audit executive.
Collaboration
Coordinates specialist contributions
Decision boundary
Acts only within an explicit policy, permission and escalation boundary.
Systems and capabilities involved
Audit management system
Risk assessments + incident data
Prior findings + issue register
Chief-audit oversight agent
re-checks the plan as QA
Handoffs
What this role gives and receives
Capabilities offered
The handoffs name the next owner or specialist and the work that moves between them.
Handoff to
Context
What the role needs to do the work
- Current work
- The audit universe + risk inputs under synthesis.
- Prior interactions
- Prior plans, findings and how risks rated out historically.
- Policies and reference
- The risk-assessment methodology and audit-universe taxonomy.
- Working method
- Not specified for this role.
Illustrative workflow
How the work moves
Starting point
Annual planning cycle opens; a new product line launched mid-year.
- 01
Refresh the audit universe with the new product and its control environment.
- 02
Synthesize risk ratings, incidents and regulatory focus into a heat map.
- 03
Propose engagement coverage and draft scopes for the high-risk areas.
Result
A risk-based annual plan with scoped engagements and a documented coverage rationale for every high-risk area.
Checks and boundaries
What must be tested or reviewed
- 01Coverage check: every high-inherent-risk area is addressed or explicitly deferred with rationale.
- 02Independence guardrail: a chief-audit oversight agent re-checks the plan, the chief audit executive recommends it, and the board audit committee approves it before it commits.
- 03Agent-as-judge review of scope completeness vs. the risk inputs.
Human authority
Acts only within an explicit policy, permission and escalation boundary.
Keep exploring