AP AuditPro Africa
AUDIT · RISK · COMPLIANCE
Planning · South Africa

Building a risk-based audit plan that satisfies both the Standards and the Act

Last reviewed August 2026

A plan can be genuinely risk-based and still fail an assessment, because the reasoning that produced it was never written down. The requirement is not only that the plan be risk-based, but that the linkage be demonstrable.

The two obligations you are meeting at once

The Standards require the plan to be informed by an understanding of the organisation's governance, risk management and control processes, and to be reviewed with the board. The PFMA for public entities and the MFMA for municipalities impose their own internal audit obligations. Building for one and hoping the other follows produces gaps in both.

What documented linkage looks like

The mistake to avoid

A plan built by carrying forward last year's engagements and adding one or two new areas is a schedule, not a risk-based plan. The test is whether the risk assessment could have produced a materially different plan. If it could not, it did not drive anything.

Common questions

How far ahead should the internal audit plan run?

Practice varies. Many functions maintain a rolling multi-year view of the audit universe alongside a detailed annual plan, with the annual plan revisited when the risk profile changes materially.

Should the plan change during the year?

Yes, where risk changes materially. Amendments should be documented and taken to the audit committee rather than made informally.

Where does your function actually stand?

A free 26-question self-assessment against the four assessable domains of the Global Internal Audit Standards 2024. No sign-up, results in six minutes.

TAKE THE FREE READINESS CHECK →

Related guides