Objectives Identify business risks and controls (operational, financial reporting, and
compliance)
Measure and prioritize the identified risks
Obtain management consensus
Process Focused interviews with multiple levels of management
Review of business plan
Analysis of financial and operational reports and other company information
Review of audit reports, management letters, industry information and other
Items
Results Risk profile: A profile of key business risks by business unit, key business
Objectives, and core business processes – ranked
Risk Treatments: An initial set of recommendations for management
Consideration arising from the risk assessment process
Internal Audit Plan: A proposed set of audits for the coming year, focusing
On areas of risk most appropriate for internal audit to address and key
Controls that should be tested