Key takeaways

  • Connect each proposed review to an objective, a risk and a decision that assurance can inform.
  • Make coverage gaps and resource trade-offs visible to the people overseeing the plan.
  • Agree the signals that will prompt reassessment instead of waiting for the next planning cycle.
  • Keep management's action-completion claim separate from risk-based verification of implementation.

Start with decisions, not last year's list

A familiar list of reviews can be a useful starting point, but it is a poor substitute for understanding what the organisation is trying to achieve. Begin with the objectives leadership is pursuing and the decisions the board or management expects to make. Ask where uncertainty could change those decisions and what evidence would be useful before they are made.

For a business introducing a new operating system, the important question may be whether responsibilities, access and reporting remain dependable during the transition. Repeating a review of the old process can produce sound work that arrives after the decision it was supposed to support. Connect assurance timing with the actual change.

Make coverage and omissions visible

Build a short map of important objectives, the related risks, existing assurance and possible gaps. Other reviews may already answer part of the question. Distinguish what has been checked from what remains uncertain, and avoid treating a previous report as evidence that the current process still works in the same way.

The Institute of Internal Auditors (IIA) Global Internal Audit Standards provide the professional framework for managing and performing internal audit. The planning map below is an illustrative working aid. It does not replace the complete Standards, the internal audit charter or the judgements required for a specific engagement.

Illustrative planning map for a system transition
DecisionUncertaintyPossible review
Proceed with migrationAccess responsibilities are unclearReview role design and approval evidence
Rely on new reportingReconciliations are incompleteTest the reconciliation process
Close the transitionOpen issues have no ownersCheck ownership and follow-up

Connect a changing risk to a coverage decision

Use one row per distinct question. Describe the objective, what could prevent it and the decision that needs better evidence. A concern called system failure is broad; a concern that supplier-bank changes can reach a payment run without an independent check identifies a process and a question to investigate. Record the change that makes the question important now.

Before proposing more work, assess the age, scope and limitations of existing evidence. An earlier report may cover a previous system or population. A policy can show intended design without demonstrating operation. Explain the remaining uncertainty rather than treating the presence of a report as dependable coverage.

The IIA's 2024 Standards connect planning to documented risk assessment and appropriate board and senior-management involvement. Use the organisation's mandate, charter and methodology to decide scope and governance. This original worksheet is not a conformance assessment and does not establish a legal duty for every Maltese business to have an internal-audit function.

Original risk-to-coverage worksheet; complete one row per question
Objective / decisionRisk / change signalExisting evidence / gapProposed coverage / rationale
[objective; next decision; when evidence is needed][credible failure; process; change or incident][source; period; scope; reliability; remaining uncertainty][assurance/advisory purpose; criteria; priority reasoning; resources]

Explain the trade-offs

Make clear why particular work is proposed and what will not be covered within the available capacity. Record the knowledge, time and access needed for each review. Where a gap cannot be covered, explain its significance and the options available to those responsible for oversight.

Avoid giving every review the same priority. A decision that is difficult to reverse, depends on uncertain information or affects several objectives deserves a different discussion from a routine process with recent dependable assurance. Make the reasoning understandable rather than treating a numerical score as a guarantee.

Record the consequence of changing coverage

Urgent advisory work can displace planned assurance. Identify which question will wait and which decision may now lack evidence. Show access restrictions and specialist skills needed alongside capacity. Route the proposed change through the agreed governance rather than allowing a revised task list to stand in for a decision.

IIA Standard 9.4 addresses board approval of the plan and significant changes. Check applicable Topical Requirements when defining assurance scope: the IIA page checked on 7 October 2026 identifies effective cybersecurity and third-party requirements. Applicability depends on the engagement; this record does not cover their detailed requirements or certify compliance.

Original coverage decision record
Coverage choiceReason / consequenceDecision / next review
[add, defer, narrow or replace work; affected objective][risk rationale; capacity/access constraint; displaced coverage][appropriate decision maker; actual status/date; revisit trigger; unresolved concern]

Agree when the plan should change

Identify developments that would prompt reassessment: a major system change, an incident, a new operating location or repeated control failures. Assign responsibility for bringing those signals into the planning discussion. Record changes to the plan, including the work displaced and any resulting gap.

A regular discussion can ask three questions: what has changed, which decisions now need assurance and whether current work remains the best use of capacity. The appropriate rhythm depends on the organisation and its oversight arrangements. The aim is a plan that stays connected to the decisions it is meant to inform.

Carry a finding through to verifiable action

Explain the observed condition, criterion and risk before agreeing an action. Separate an evidenced cause from a hypothesis still needing investigation. Improve controls gives the owner little to implement and the reviewer little to verify. Describe the intended change, accountable management owner, dependency and evidence that would demonstrate implementation.

Keep management's completion claim separate from the follow-up result. Issuing a policy, installing a setting and demonstrating operation are different evidence. IIA Standard 15.2 addresses risk-based confirmation of implementation. Select follow-up proportionate to significance and preserve exceptions; delays or proposed risk acceptance should enter the agreed escalation route.

Fictional illustration: a business moving to a new purchasing system identifies a question about verification of supplier-bank changes. The planning row records the old policy and missing operating evidence from the new system. Any later action remains separate from its verification result. This is a planning scenario, not an actual finding, client result or fraud allegation.

Original finding-to-action and verification record
Finding / riskManagement actionImplementation claimVerification / remaining risk
[condition; criterion; evidence; significance; cause confirmed or hypothesis][specific change; accountable owner; agreed internal target; dependency][owner's status/date; evidence reference; exceptions][verifier; scope/period checked; result; remaining limit; next action]

Actions to consider

  • Identify the decisions leadership expects to make.
  • Map available assurance and the uncertainties it does not address.
  • Document the rationale, capacity requirements and omissions.
  • Agree reassessment signals and who will raise them.
  • Record management's actions and risk-based follow-up evidence separately.

Sources

Sources checked on . The check covered the primary-source material identified below for the claims used here; linked standards and handbooks were not comprehensively audited.

Prepared and source/editorial-reviewed with AI assistance under owner authorization. This is general, non-personal planning information with original worksheets, not an official form or professional engagement programme. No named human or licensed professional sign-off is recorded for this article. Entity-specific legal, tax, regulatory and engagement decisions require appropriate professional advice.

  1. The IIA: Global Internal Audit Standards, 2024 edition

    International professional framework, checked on 7 October 2026. It does not establish a universal Maltese internal-audit obligation; the original worksheets are not a conformance assessment.

  2. The IIA: Complete Global Internal Audit Standards, 2024

    Relevant sections of Standards 9.4 and 15.2 were checked for risk-led planning, plan/change approval and implementation follow-up. Not a comprehensive standards review or reproduction of an IIA template.

  3. The IIA: Topical Requirements

    Landing-page applicability and effective-topic information checked on 7 October 2026. Assess the actual assurance scope and operative requirements; individual topical documents were not exhaustively reviewed.

About KMFINCO

Perspectives on assurance, consulting, governance and financial operations, connecting specialist frameworks with practical questions for organisations and their owners.

This article provides general information, not advice tailored to your circumstances. Confirm applicable professional, legal, tax and regulatory requirements with the appropriate adviser.

Meet the people behind the firm

Explore Management Consulting or contact the firm to discuss your circumstances.