In addition, almost all audits begin with the same process: a risk assessment. When conducting audits of various IT segments, this is true. To develop an effective IT audit program, the IT auditor needs to understand what objects present the highest risks. When applying COBIT® to audits, the Plan and Organize domain includes process PO9 Assess and manage IT risks, which should be considered. ISACA IT Audit and Assurance Standard S11, “Use of Risk Assessment in Audit Planning,” explains the role of and need for risk assessment in IT audits: