Defining the Audit Universe
In CIA Part 3, defining the audit universe is the first step in building a risk-based internal audit plan. The audit universe is the complete inventory of auditable entities, meaning every area of the organization that internal audit could review. Under IIA guidance, the chief audit executive must … In CIA Part 3, defining the audit universe is the first step in building a risk-based internal audit plan. The audit universe is the complete inventory of auditable entities, meaning every area of the organization that internal audit could review. Under IIA guidance, the chief audit executive must base the plan on a documented assessment of the organization's strategies, objectives, and risks, and that assessment starts with a clearly defined universe. Auditable entities can be organized in several ways: by business unit or subsidiary, by geographic location, by core and support process (procurement, payroll, revenue, IT general controls), by information system, by major project or program, by legal or regulatory obligation, and by significant third-party relationship such as outsourced services. Many organizations combine these views into a matrix so that cross-functional risks are not missed. To build the universe, auditors review organizational charts, strategic plans, budgets, process maps, risk registers, regulatory requirements, and prior audit results. They also interview senior management and the board. The goal is completeness, because any area left out of the universe will never be considered for audit coverage. Entities should also be defined at a practical size: specific enough to be audited in one engagement, but broad enough to keep the list manageable. Once the universe is defined, each entity is risk-assessed using factors such as financial materiality, complexity, regulatory exposure, control environment, pace of change, fraud potential, and time since the last audit. The resulting risk ranking helps the chief audit executive decide which entities enter the annual or rolling plan. Coverage by other assurance providers, such as compliance or external audit, should be mapped to avoid duplication. The universe is not static. It must be updated at least annually, and whenever there are acquisitions, new products, new systems, restructurings, or emerging risks like cybersecurity or ESG issues. This keeps the audit plan aligned with the organization's current risk profile and supports communication with the board about audit coverage.
Defining the Audit Universe: A Complete CIA Part 3 Guide to Building the Foundation of the Internal Audit Plan
Introduction
The audit universe is the starting point of every risk-based internal audit plan. Before the Chief Audit Executive (CAE) can decide what to audit, when, and with what resources, the internal audit activity must first identify everything that could be audited. This guide explains what the audit universe is, why it matters, how it is built and kept current, and how to handle exam questions on the topic in CIA Part 3 (Business Knowledge for Internal Auditing) and related planning content.
1. What Is the Audit Universe?
The audit universe is a complete inventory of all auditable entities (also called auditable units) in an organization. An auditable entity is any part of the organization that can be defined, assessed for risk, and audited.
Auditable entities can be organized in several ways:
• Organizational units: divisions, departments, subsidiaries, branches, regions.
• Business processes: procure-to-pay, order-to-cash, payroll, treasury, inventory management.
• Functions: HR, IT, legal, compliance, marketing.
• Information systems and technology: ERP systems, cybersecurity, data centers, cloud services.
• Programs and projects: major capital projects, system implementations, mergers and acquisitions.
• Locations or geographic areas: plants, warehouses, foreign operations.
• Products, services, and customer segments.
• Regulatory and compliance areas: anti-bribery, data privacy, environmental, health and safety.
• Third parties: key vendors, outsourced service providers, joint ventures.
• Strategic and governance areas: ethics program, enterprise risk management, governance processes, culture.
Key idea: The audit universe is not the audit plan. The universe is the full population of potential audit areas. The audit plan is the risk-prioritized subset chosen for a given period.
2. Why Is the Audit Universe Important?
• Foundation for risk-based planning: The IIA Standards require the CAE to establish a risk-based plan (Standard 2010 under the IPPF; Standard 9.4 Internal Audit Plan under the 2024 Global Internal Audit Standards). A risk assessment can only cover what has been identified, so an incomplete universe means an incomplete risk assessment.
• Completeness and coverage: It shows that internal audit has considered the whole organization and helps reveal coverage gaps, areas never audited or not audited for many years.
• Alignment with strategy: Mapping auditable entities to strategic objectives and key risks keeps audit work relevant to what matters most to the board and senior management.
• Resource allocation: It provides the basis for estimating staffing, skills, budget, and co-sourcing needs.
• Communication with the board: The CAE can show the board what is and is not covered, which supports discussions about risk acceptance and resource limits.
• Coordination and reliance: It allows mapping of other assurance providers (risk management, compliance, external audit, quality assurance) to entities, supporting combined assurance and reducing duplication (Standard 2050 / GIAS 9.5).
• Multi-year planning: Many organizations use the universe to build a rotational or multi-year coverage plan alongside the annual plan.
3. How It Works: Building the Audit Universe
Step 1: Understand the organization.
Review the strategic plan, business objectives, organizational chart, financial statements, the ERM risk register, regulatory requirements, prior audit reports, board and committee minutes, and industry trends. Interview senior management and the board.
Step 2: Choose a structure (the organizing basis).
Decide how to segment the universe: by business unit, process, risk, location, system, or a hybrid/matrix approach (for example, processes within business units). The choice should reflect how the organization is managed and how risks are owned. Process-based universes often work well for cross-functional risks. Entity-based universes suit decentralized organizations.
Step 3: Identify and define auditable entities.
Each entity should be clearly bounded so that it can be audited within a reasonable engagement. Entities that are too broad are hard to audit. Entities that are too granular make the universe unmanageable. Document the entity name, owner, objectives, key processes, systems, size (revenue, assets, transactions, headcount), and last audit date.
Step 4: Link entities to objectives and risks.
Map each entity to strategic objectives and to risks in the organization's risk framework (strategic, operational, financial, compliance, IT, fraud, reputational).
Step 5: Assess risk for each entity.
Apply risk factors such as:
• Financial materiality and transaction volume
• Complexity of operations or systems
• Regulatory exposure
• Changes in management, systems, processes, or the business (new products, acquisitions)
• Results of prior audits and open issues
• Quality of the control environment
• Fraud susceptibility
• Time since last audit
• Management concerns and board requests
• Strategic significance and reputational impact
Score inherent and residual risk using likelihood and impact, then rank the entities.
Step 6: Prioritize and select for the plan.
High-risk entities are prioritized for the audit plan, considering resources, mandatory audits (regulatory requirements), management requests, and reliance on other assurance providers.
Step 7: Maintain and update.
The audit universe is a living document. It should be reviewed at least annually and updated when significant changes occur, such as new business lines, acquisitions, divestitures, new systems, reorganizations, new regulations, or emerging risks like cyber threats, AI, or ESG. The GIAS emphasize reviewing and adjusting the plan in response to changes in the business, risks, operations, programs, systems, and controls.
4. Key Related Concepts
• Risk assessment: the process applied to the universe to determine priorities.
• Audit cycle / rotation: lower-risk entities may be covered on a cyclical basis (for example, every 3 to 5 years). Modern practice favors risk over pure rotation.
• Assurance map: shows which assurance provider covers which entity or risk.
• Dynamic / continuous risk assessment: many organizations now update risk rankings quarterly or continuously rather than once a year.
• Entity-level vs. process-level risks: some risks, such as culture, tone at the top, and governance, cut across all entities and may be treated as separate auditable areas.
• Owner of the universe: the CAE is responsible for it, with input from senior management and the board.
5. Common Pitfalls
• Building the universe only around the organizational chart, which misses cross-functional processes and third-party risks.
• Treating the universe as static.
• Omitting IT, governance, ethics, or strategic risks because they are hard to audit.
• Defining entities inconsistently in size or scope, which distorts risk comparisons.
• Confusing the audit universe with the risk register (risks) or the audit plan (selected engagements).
• Excluding areas because management prefers they not be audited, which is an independence concern.
6. Exam Tips: Answering Questions on Defining the Audit Universe
Tip 1: Know the sequence. The usual order is: understand the organization and its strategy, define the audit universe, perform the risk assessment, prioritize, develop the risk-based plan, communicate it and get board approval, then execute. If a question asks for the first step in developing a risk-based plan, look for understanding the organization's strategies, objectives, and risks, or identifying the audit universe. The answer is not scheduling audits or assigning staff.
Tip 2: Distinguish universe, risk assessment, and plan. The universe means all auditable areas. The risk assessment ranks them. The plan is the selected engagements. Wrong answer choices often blur these.
Tip 3: Completeness is the key attribute. When asked about the primary purpose or most important characteristic of the audit universe, choose the answer about comprehensiveness/completeness and identifying all auditable entities. Avoid answers like "listing only high-risk areas."
Tip 4: The universe must be updated for change. Scenarios involving an acquisition, new ERP, new regulation, reorganization, or new product line call for updating the audit universe and reassessing risk. "Wait until next year's cycle" is usually wrong.
Tip 5: Strategy alignment wins. The best answer typically ties auditable entities to organizational objectives and key risks rather than to historical audit coverage alone.
Tip 6: Risk over rotation. If asked how to select from the universe, choose risk-based prioritization over fixed rotation, equal coverage, or auditing whatever was audited last year. Rotation is acceptable only as a supplement for lower-risk areas.
Tip 7: Input from stakeholders, ownership by the CAE. The CAE develops the universe and plan, considering input from senior management and the board. Management does not decide what is excluded. Board approval applies to the plan, and the CAE communicates resource limitations and their impact.
Tip 8: Recognize good risk factors. Be ready to identify appropriate risk factors: materiality, complexity, change, regulatory exposure, control environment, prior findings, fraud risk, and time since last audit. Distractors may include irrelevant factors such as auditor preference or the convenience of a location.
Tip 9: Think about appropriate granularity. If a question describes entities that are too broad ("the entire company") or too narrow ("each individual invoice"), recognize that auditable entities should be manageable, auditable units.
Tip 10: Include non-traditional areas. Correct answers often recognize that IT, cybersecurity, governance, ethics, culture, third parties, and ESG belong in the universe.
Tip 11: Use the elimination technique. Remove answers that compromise independence (management dictating scope), ignore risk, treat the universe as fixed, or confuse the universe with an engagement work program.
Tip 12: Watch the wording. Words such as most important, primary, first, and best signal that several options may be partly true. Choose the most comprehensive, risk-based, and standards-aligned option.
7. Sample Exam-Style Question
The chief audit executive is developing next year's internal audit plan. The organization recently acquired a foreign subsidiary and implemented a new cloud-based payroll system. What should the CAE do first?
A. Schedule an audit of the payroll system for the first quarter.
B. Update the audit universe to include the new subsidiary and system, then reassess risks.
C. Ask management which areas they would like audited.
D. Continue the existing rotation plan and add the new areas next cycle.
Answer: B. Significant changes require updating the audit universe and the risk assessment before audits are scheduled. Option A skips the risk assessment. Option C gives management inappropriate control over scope, although its input is valuable. Option D ignores the changes in risk.
8. Quick Summary
• The audit universe is the complete inventory of auditable entities.
• It is the foundation of the risk-based audit plan required by the IIA Standards.
• Build it from a thorough understanding of the organization's strategy, objectives, structure, processes, systems, and risks.
• Structure it logically (by unit, process, system, or a hybrid), with consistently defined, auditable-sized entities.
• Assess each entity's risk, then prioritize to form the audit plan.
• Keep it dynamic, updating it for organizational changes and emerging risks.
• On the exam, favor answers emphasizing completeness, risk-based prioritization, strategic alignment, CAE ownership, and continuous updating.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!