Almost no Internal Audit department has enough resources to review every auditable entity in the organization every year. The challenge is not to get more resources, but to design an audit universe that makes it possible to decide with confidence what to review first, how often, and what can be covered through alternative means. This article proposes a practical methodology for building and maintaining an up-to-date audit universe.
What the audit universe is and why it is the foundation of the entire plan
The audit universe is a comprehensive inventory of all entities that could potentially be the subject of an audit: processes, business units, systems, projects, or subsidiaries. It is the starting point for any planning exercise, because no audit plan can be coherent if the universe on which it is built is incomplete.
Difference between the audit universe and the audit plan
The audit universe is exhaustive: it includes everything that could be audited. The audit plan, on the other hand, is a selection from that universe, prioritized by risk and constrained by available resources. Confusing the two leads to planning only around what is already known, leaving out relevant areas that never make it onto the department's radar.
Consequences of an incomplete audit universe
If a business unit, a new process, or a recent subsidiary does not appear in the audit universe, it will simply never enter the planning conversation, regardless of how much its risk level has grown. This is one of the most frequent reasons why a significant risk remains without coverage for years.
How to build the audit universe from scratch
Step 1: identify the auditable entities
Gather information from multiple sources: the organizational chart, process maps, system inventory, corporate structure, and the catalog of strategic projects. Cross-referencing several sources helps identify entities that might be missed if only the traditional org chart is used.
Step 2: define the right level of granularity
A universe that is too aggregated (for example, "finance" as a single entity) makes precise prioritization difficult. One that is too granular (dozens of minor sub-processes) creates excessive maintenance overhead. The right level typically sits at processes or sub-processes that have their own distinct risk profile, neither so broad that they mix very different risks nor so narrow that they multiply management effort without adding real precision.
Step 3: assign a risk owner to each entity
Each entity in the universe should have an identified business owner. This not only facilitates the execution of future engagements, but helps detect more quickly when an entity has changed significantly and its risk level should be reassessed.
How to prioritize when resources do not cover everything
Weighted risk model
Assess each entity in the universe by combining several factors: potential financial impact, likelihood of an incident, regulatory exposure, and time elapsed since the last review. A weighted model, even if imperfect, provides an objective and defensible basis for decisions that would otherwise be purely subjective.
Differentiated coverage cycles by risk level
Not all entities need to be reviewed with the same frequency. The highest-risk ones might be audited every twelve to eighteen months, while lower-risk ones could be covered every three to four years, or through lighter reviews such as control self-assessments complemented by targeted analytical testing.
When to use co-sourcing or analytical tools
When the audit universe grows faster than the internal team, two common levers are co-sourcing with external specialists for very specific risks (such as cybersecurity or AI model auditing) and incorporating analytical tools that allow covering high-volume processes without needing to expand the team proportionally.
How to keep the audit universe up to date
An audit universe built once and never revisited becomes outdated quickly, particularly in organizations undergoing acquisitions, product launches, or continuous digital transformation. A formal review at least once a year is advisable, as well as a mechanism for ad-hoc updates whenever a significant organizational change occurs, such as the creation of a new business unit or the deployment of a critical system.
Common mistakes when designing the audit universe
- Building it solely from the organizational chart. This leaves out cross-functional processes or risks that do not fit neatly within a single organizational area.
- Not updating the universe when the organization changes. An acquisition or new product launch should automatically trigger an update to the audit universe.
- Prioritizing solely based on risk as perceived by the audit function itself. Incorporating the perspective of other control functions, such as risk management or compliance, often surfaces relevant entities that would otherwise go unnoticed.
- Applying the same review cycle to all entities regardless of risk level. Treating high-risk and low-risk processes with the same frequency dilutes available resources rather than concentrating them where they are most needed.
Key control point: if your audit universe has not been updated in the last twelve months, there are very likely processes, systems, or business units that have emerged in that period and are not yet reflected in it.
An audit management platform that centralizes the audit universe alongside the risk map allows keeping it current on an ongoing basis, linking each entity to its last review date, and generating alerts when a high-risk entity has gone too long without being audited.
Checklist for designing your audit universe
- Has the universe been built by cross-referencing multiple sources, not just the org chart?
- Does the granularity level allow precise prioritization without creating excessive maintenance overhead?
- Does each entity have an identified risk owner?
- Is there a prioritization model based on multiple risk factors, not just the team's intuition?
- Do higher-risk entities have a more frequent review cycle than lower-risk ones?
- Is there a mechanism for updating the universe when significant organizational changes occur?
Conclusion
Designing the audit universe well does not in itself solve the resource constraints that almost every department faces, but it does ensure that decisions about where to invest that limited time are made with sound judgment rather than by inertia or by defaulting to what is most convenient to audit. A complete, prioritized, and up-to-date universe is ultimately the difference between a defensible audit plan and one built in the dark.