Dimov Audit
An internal audit team planning the year's schedule

Internal audit schedule and how often audits should run

You need a schedule you can defend when someone asks why one cycle waited and another did not. Rate the risk in each cycle, size the work it takes, and set the interval from both.

  • 500+

    audit and attestation engagements

  • AICPA

    peer-reviewed firm

  • 16+

    years auditing experience

How often are internal audits conducted

At least once a year for the assessment behind the plan. Under Standard 9.4 of the Global Internal Audit Standards, the chief audit executive must base the internal audit plan on a documented assessment of the organization's strategies, objectives and risks, and must perform that assessment at least annually.

Set each cycle, meaning the process, system or business area you audit, to an interval based on its risk rating. A regulator can set a different interval for you.

You take the internal audit frequency for each cycle from the documented assessment and the supervisory rules you answer to. Update the rolling internal audit schedule whenever you change your business, systems or controls.

If your team cannot cover the plan, take the cycles you rated highest first. Under the same standard, the chief audit executive must tell the board and senior management the impact of any resource limitations on coverage, and the rationale for leaving an area of high risk out of the plan.

How often to audit each cycle by risk level

We start each cycle at the interval for its risk level. Where a regulator sets a different interval, we follow the regulator.

Risk levelInterval we setCycles we rate at this level
High

Once a year, with a retest inside the year after a failed control or a system change

Cash, payroll, revenue, a new system, a finding still open from the last visit
Medium

Once every two years

Settled processes with moderate volume and no open findings
Low

Once every three years, on rotation

Low-volume processes with no findings in the last two visits

How to set internal audit frequency for each cycle

  • Risk rating

    Revisit the cycles you rated higher more often than settled ones.

  • Change

    After a new system, a new location or a migration, bring the cycle forward.

  • Prior findings

    If the auditors identified an issue last time, retest it before the next scheduled visit.

Your team adjusts the audit frequency for each of these:

  • Supervisory rules

    Where a supervisor sets the cadence, follow the supervisor's cadence.

  • Resourcing

    Match the plan to the people, budget and technology you have.

  • Materiality

    Spend the hours on areas where the organization could miss an important objective.

How to set audit cadence under supervisory rules

Banks answer to their examiner as well as their board. The FDIC tells institutions to run an internal audit program appropriate to their size and to the nature and scope of their activities, so an examiner has a view on your cadence alongside your audit committee. Insurers, healthcare providers and companies handling cardholder data each answer to their own rule set.

Management at a public company performs the annual Section 404(a) assessment of internal control over financial reporting as of fiscal year end, and evaluates material changes each quarter. Internal auditors can use that SOX work to shape the internal audit schedule without treating each quarter as a separate control testing requirement. We cover the split between management's assessment and the auditor's opinion in SOX and internal audit.

We can run the plan or the cycles inside it

Some clients hand us the whole function and others hand us selected cycles. Dimov Audit provides internal audit services for either model and defines the work around the risk.

How to build an internal audit schedule

Start from the risk rating of each cycle and finish with an internal audit calendar your board or owners can approve:

  1. 1

    Rate the cycles

    Score each one for risk and for the changes you made to it since you last looked at it.

  2. 2

    Set the coverage

    Decide which cycles you cover this year and which ones you defer.

  3. 3

    Space the work

    Spread the audits across the year and keep the weeks before year end clear.

  4. 4

    Leave room

    Hold capacity back for requests your board or owners make after approving the plan.

  5. 5

    Revisit it

    Reopen the schedule when you change a cycle, when management leaves a finding unfixed, or when your supervisor asks a question you cannot answer from last year's work.

Write down the cycle, timing, owner and hours for each entry before the team approves the schedule.

An internal audit calendar, worked example

Illustrative only. Assumes seven cycles, 400 audit hours for the year, a December year end, and the intervals in the risk level table.

  1. Q1

    110

    Hours

    Cycles audited

    Cash and treasury (high), payroll (high)

    Why then

    After the year-end close, before the audit committee meets

  2. Q2

    90

    Hours

    Cycles audited

    Revenue and receivables (high)

    Why then

    Before the mid-year board meeting

  3. Q3

    110

    Hours

    Cycles audited

    Purchasing and payables (medium), IT access (medium)

    Why then

    Both due this year on the two-year interval

  4. Q4

    50

    Hours

    Cycles audited

    Fixed assets (low)

    Why then

    Rotation year; kept light before year end

  5. Held back

    40

    Hours

    Cycles audited

    Board and owner requests

    Why then

    Any quarter

Inventory (medium) is not on this year's calendar; we audit it next year on its two-year interval. Hours total 400.

What happens if you audit too rarely or too often

Audit a cycle too rarely and your team finds the failed control at the next visit, after the company has carried the loss for the whole gap. Audit a settled cycle too often and you take hours away from the cycles you rated higher. If your own people cannot cover the plan, we take the cycles you rate highest and your team keeps the rest.

How internal audit frequency differs from IRS audit frequency

You control the frequency of internal audit through your own plan. How often do companies get audited by the IRS? The IRS decides that, and your plan has no bearing on it. If you hold an IRS notice, ask our audit defense team to handle it.

Related services

Treat the information as general, not advice for your circumstances. Ask a CPA to review your own risk profile and any supervisory rules before you fix a schedule.

How we set the cost of the internal audit cycles we run

We set the fee on four things:

  • Cycles in scope

    We charge less for one cycle than for the whole plan.

  • Transactions per cycle

    We size samples to the volume you run through each control.

  • Systems and locations

    We add hours for each system or site we pull evidence from.

  • Plan or cycles

    We charge more to build the schedule and run the cycles than to run cycles on a schedule you set.

Tell us what your plan has to cover

Send us four things: the cycles you want examined this year, the findings still open from your last audits, the rules you answer to, and the hours your own team can give. We come back with a schedule, a plan and a price.

Contact

Connect with Dimov Audit

Our dedicated team is ready to assist you on your path to financial success.

New York Office

24 Mercer St, 2nd Floor, Suite 214
New York, NY 10013
United States

Reviewed by George Dimov, CPA. Dimov Audit plans and runs internal audit cycles for boards and owners across all 50 states. George brings 20+ years of accounting and consulting experience. Profile