The Assurance Gap: The Board Decision Most Audit Plans Leave Unsaid

Insights
Every internal audit plan is a risk decision in two parts. The first part, the subjects that get audited, is visible. The second part, the subjects that are deliberately not audited, is missing entirely from most plans. That is not an innocent omission. It is an implicit promise that internal audit cannot keep and that the board cannot evaluate. This essay explains how you move from a universe to a net plan, why depth and coverage are two different things, how GIAS turns the assurance gap into a literal planning requirement, and why risk appetite is a board decision rather than a technical optimization. Along the way: fourteen pitfalls, a worked calculation example, a sample universe, and a concrete three-meeting cycle for the audit committee.
A farmer brings in the hay before the rain arrives and deliberately leaves the rest of the field standing
The farmer works the field methodically, bringing in what needs doing now, the hay before the rain, and deliberately leaves the rest standing. That is how an audit plan works too.

I. From universe to annual plan: the process and the instruments

Every year, sometime in the autumn, a head of internal audit sits down to build the annual plan. Conversations are held with management, a risk list gets reviewed, and after some deliberation an overview appears of fifteen, twenty, sometimes thirty subjects to be audited in the coming year. The plan goes to the audit committee, gets approved, and then reality sets in: there is capacity for twelve, maybe fourteen.

That gap, between what the plan says and what actually gets executed, is the assurance gap. And in the large majority of audit plans I have seen, that gap is not stated explicitly. It simply is not there. The seven subjects dropped from the candidate list for lack of capacity, the processes that have sat on the list for three years and keep getting pushed off, the new legislation nobody has given any assurance on: they have vanished. The plan shows only what gets done, and by doing so conceals what does not.

That is a fundamental problem. It is not just a communication problem, it is a governance problem. An audit committee that approves a plan without knowing which objects were deliberately left uncovered cannot judge whether the coverage is adequate. It does not know what it is approving. Worse: it does not know what it has or has not explicitly accepted. If an incident later occurs in an area that sat on the candidate list for two years but kept getting dropped, the question is fair: did the audit committee knowingly accept that this area stayed uncovered? In most cases the answer is no, it did not even know. That is the problem this essay addresses.

An audit plan is a risk decision, and by definition that decision also covers the risks on which no assurance is deliberately given. Leaving out that second part means presenting half an account. But before we reach that conclusion, we need to understand how the plan gets built.

The annual plan does not start with a spreadsheet. It starts with understanding.

What GIAS Standard 9.1 asks for is not bureaucratic, it is substantive: the head of the audit function must genuinely know the organization, its strategy, its risk profile, and its control environment. That requires regular conversations with the board and senior management, access to the second line's risk registers, knowledge of the strategic agenda, and insight into projects and changes underway. An organization that was stable last year may absorb a major acquisition this year, roll out new IT infrastructure, or face shifting supervisory expectations. All of those movements are potential new risk-introducing objects.

Term: Auditable object (the fruit basket)
An auditable object is a risk-introducing object: anything that brings risk into the organization. Processes, laws and regulations, activities, departments, systems, chains, strategic themes. The best comparison is a fruit basket: apples, pears, grapes, all mixed together. The goal is completeness, not model purity. Anyone who tries to order the fruit basket along a single conceptual axis always loses something. A complete but conceptually mixed collection beats a tidy model with gaps.

From that understanding you build the audit universe as a multi-layered, complete collection of auditable objects. Not just the known processes, but also the chains with external parties, the systems underlying critical decision-making, the laws and regulations that create obligations, and the strategic themes that cut across the whole organization. You order that collection along several structures at once, switching lenses until you are confident no categories are missing.

Term: Audit universe
The audit universe is the ordered collection of all those objects, as a planning aid. GIAS names the universe as one possible approach, not a requirement. That is exactly the right status: the universe is a means, not an end. Anyone who spends months perfecting the universe spreadsheet while the substantive prioritization stays weak is confusing the map with the terrain. The universe is also multi-layered: the same fruit basket can be ordered along several structures, by organizational structure, by process, by product and service, by theme. You switch lenses to spot gaps that stay invisible in one ordering but show up in another.
Screenshot of the audit universe in the Audirium Audit app, ordered along the structures Organization, Process, and Product/Service, with an impact badge and complexity indicator per object
The audit universe in practice: the same objects are visible along the structures Organization, Process, and Product/Service. Each object carries an impact badge (Top/Big/Moderate/Low) and a complexity rating (H/M/L). Switching lenses reveals gaps that stay invisible in a single ordering.

A sample universe for a fictional logistics company

To make the abstract concrete, below is a schematic universe for a mid-sized Dutch logistics provider with roughly 800 employees, five warehouses, and an international road transport division. The objects are spread across five lenses. This is not exhaustive; it illustrates the breadth a full universe covers.

Audit object Lens / category Impact External assurance available
Order processing (WMS)ProcessTopPartial (ISAE 3402, supplier)
Transport planning and executionProcessTopNo
Procurement and supplier selectionProcessBigNo
Financial reporting processProcessTopYes (external accountant)
HR and payroll administrationProcessBigNo
ERP system (SAP S/4)SystemTopPartial (third-party penetration test)
Telematics and onboard computersSystemModerateNo
Cybersecurity and access managementSystemTopPartial (ISO 27001 certification)
GDPR / data protectionLegislation / regulationBigPartial (DPO activities)
Health and safety legislationLegislation / regulationTopPartial (external risk assessment)
Customs and excise legislationLegislation / regulationBigNo
Subcontractors (owner-operators)Chain / third partyTopNo
IT outsourcing partner (hosting)Chain / third partyBigYes (ISAE 3402 type II)
Strategic acquisition (integration)Strategic themeTopNo
Sustainability / CSRD reportingStrategic themeBigPartial (external assurance, EY)
Fraud and integrity managementStrategic themeBigNo

Sixteen objects, five lenses, and a pattern already emerges: four Top-impact risks have no external assurance available at all (transport planning, subcontractors, the strategic acquisition, health and safety legislation only partially covered). Those objects are the core candidates for the internal audit plan. The others deserve a reliance assessment: does the IT outsourcing partner's ISAE 3402 lean sufficiently on the right control objectives, or does it cover only the general IT environment and not the transport-specific processes?

Model purity is a second-order concern here. Completeness comes first. Anyone who takes the universe seriously quickly notices that combining lenses surfaces things that stay invisible in a single process breakdown: the customs obligation does not sit in an internal process but does sit in the chain with the owner-operators, so it shows up in the chain lens and stays invisible in the process lens.

A second observation about the sample universe: the "external assurance available" column is critical, but it hides a trap in how it gets filled in. Marking "Partial (ISAE 3402, supplier)" for the order processing process has not made a reliance decision. It has only established that a report exists. The reliance decision, the conclusion that the report is adequate to lean on for your own assurance need, requires the active testing described in the ISAE 3402 box below. That step gets skipped frequently in practice. The result is an assurance map that looks complete but is hollow inside: the "partial" fields are filled with the existence of a report, not with substantive reliance.

Next comes the assurance mapping. For each object, you map out what assurance already exists from elsewhere. ISO certifications that external parties validate periodically. Regulators examining specific domains. The external accountant, who produces findings on relevant control measures through the management letter. ISAE 3402 and SOC 2 reports from service providers running critical processes. Compliance activities and GDPR work by the data protection officer. And second-line monitoring, to the extent it is mature enough to rely on.

Term: Assurance mapping
Assurance mapping is the step where, for each object, you map what assurance already exists from outside internal audit. That includes ISO certifications, regulator audits, the management letter and the external accountant's scope, third-party reports (ISAE 3402, SOC 2), compliance activities and GDPR audits, and second-line monitoring. This is not just a record of your own audits; it is a map of all the assurance circulating in the organization. GIAS Standard 9.5 requires this explicitly: the head of the internal audit function coordinates with other assurance providers to optimize coverage and minimize duplication, and documents the basis for the reliance placed on their work. Undocumented reliance is not reliance in the GIAS sense.

After the mapping comes prioritization. And here sits a methodological trap that is widespread in practice: the pseudo risk score. Audit functions that rank their universe on "inherent risk" or "residual risk" using a model are doing something odd. You only know an object's actual residual risk after auditing it: only then do you know whether the control measures actually work, and what risk remains after that. A risk score for the audit is by definition an estimate, and in most cases that estimate simply reflects the line manager's judgment. You are using the outcome of a measurement you have not yet taken as the selection criterion for that same measurement.

The better approach is an impact analysis or relevance analysis as the selection basis. Gross exposures play a role there: the inherent size of the risk, not yet shaped by controls, because you do know that in advance. Strategic relevance counts, current themes count, and recent developments count. And so does time since the last audit: for subjects that have gone untouched for a long time, that can be reason to prioritize them higher, even if their gross risk is not at the top.

The GIAS implementation guidance to 9.4 lists the factors the CAE must weigh when building the plan: mandatory assignments required by law or regulation, assignments critical to the organization's mission or strategy, domains with a significant risk level, whether all significant risks are adequately covered by assurance providers, ad hoc requests from the board and management, the time and resources per potential assignment, and each assignment's potential to improve governance, risk management, and control processes. That last one is underrated: an audit on a subject where findings drive structural improvement delivers more value than an audit on a stable subject where the findings are predictably nil. Factoring that into selection optimizes for impact, not completeness.

When scheduling assignments, operational priorities come into play: when is the object available for review, how does the timing relate to the external accountant, are the right auditors available with the required competencies? The GIAS implementation guidance names this explicitly: "schedule of external audit engagements and regulatory reviews, competencies and availability of internal auditors, ability to access the activity under review." That last point, access to the object, is a practical constraint rarely made explicit during planning but that regularly causes delays during execution. An audit scheduled for the second quarter that can only start in the third quarter because the object is not available until then has quietly created a capacity trap that crowds out other assignments.

Then comes the funnel. From the universe with all objects, you build a gross list, scoring each object on impact, complexity, and available assurance from others. Objects with abundant, adequate, documented external coverage move down; objects with no assurance from anyone and a large inherent weight move up.

From audit universe to annual plan The funnel. What falls out is the assurance gap. AUDIT UNIVERSE all auditable objects, the fruit basket GROSS LIST scored on impact, complexity, assurance elsewhere AUDIT CANDIDATES above the relevance threshold NET LIST = ANNUAL PLAN fits within capacity ASSURANCE GAP candidates dropped, deliberately not audited. Belongs on the AC agenda every year. Selection on impact and relevance, not on a residual risk you only know after the audit.
From the full universe to the net annual plan. What falls out between the candidates and the net list is the assurance gap: deliberately not audited this year, and therefore a risk the board needs to accept.

Next, the candidates get selected: the objects above a chosen threshold that qualify for this year. And finally, the net list gets determined: what actually fits within capacity?

Capacity is a hard constraint, not a planning tool. For each auditor: FTE multiplied by gross working hours per year, corrected for leave and other absence and for the productivity factor, yields direct net hours. The sum across all auditors is total capacity. That must also reserve a contingency buffer for unexpected work: follow-up on earlier findings, ad hoc investigations on request, stepping in on incidents. Skip that buffer and you have implicitly planned away your room for unexpected work, and you will deliver a plan that falls structurally behind by year end.

Calculation example: from FTE to net audit capacity

Let's make this concrete with a worked calculation, because the abstract argument about "capacity shortage" loses its edge unless it is anchored in numbers an audit committee can actually assess.

Calculation: 3 FTE to net audit hours

Gross hours per FTE: 52 weeks x 36 hours = 1,872 hours. Minus 25 vacation days (200 hours), minus an average of 8 sick days (64 hours), minus 12 training days (96 hours) = 1,512 gross available hours.

Productivity factor: Of those 1,512 hours, part goes to overhead: team meetings, planning discussions, administration, quality review, performance reviews, and internal communication. In a professional audit function, the billable factor sits around 60 percent. That yields 1,512 x 0.60 = 907 direct audit hours per FTE.

Three FTE: 3 x 907 = 2,721 direct gross hours.

Contingency buffer (15%): GIAS 9.4 explicitly requires reserving a percentage of hours for contingencies and ad hoc requests. At 15 percent that is 408 hours, going toward follow-up on findings, urgent investigations, and ad hoc board questions.

Net plannable hours: 2,721 - 408 = 2,313 direct hours for planned assignments.

Converting to audits: An average design-and-existence audit takes 3 weeks (110 direct hours). An operating-effectiveness audit with sampling takes 6-8 weeks (220-290 direct hours). At a mix of 60 percent design/existence and 40 percent operating-effectiveness audits, the weighted average comes out to roughly 170 direct hours per assignment.

Feasible number of assignments: 2,313 / 170 = roughly 13 to 14 assignments per year.

The gap in numbers: If the candidate list holds 22 objects above the relevance threshold, then 8 to 9 objects fall outside the plan. Those are the objects that go into the gap appendix: deliberately not audited, with the reason stated and any alternative coverage noted.
Screenshot of the capacity calculation in the Audirium Audit app: 1.5 FTE x 1,700 hours, indirect 30%, resulting in 1,785 direct hours; set against an optimal need of 5,080 hours, showing a shortfall with a staffing proposal in euros
The capacity calculation in the app: direct hours after correcting for indirect work, weighed against the optimal budget for the candidate list. The shortfall is translated into euros as a staffing proposal for the audit committee, turning the gap into a concrete investment question.

What this calculation shows is not that a capacity shortage is bad. Everyone already knew that. What it shows is that it is a quantitative fact that belongs in the plan: not as a complaint, but as a building block for the conversation with the audit committee about resources. GIAS 8.2 requires the board to assess the adequacy of resources at least annually. That is only possible if resources are specified in hours and objects and the gap is named.

The gap appendix: the second half of the pair, on paper

The funnel makes the gap visible. The question is what you do with it. My answer is simple: write it down. Not as an appendix nobody reads, but as a formal second part of the audit plan, treated with the same seriousness as the net list.

Screenshot of the funnel with the expanded gap list in the Audirium Audit app: universe 50 objects, gross candidates 42 (3,280 hours), net/annual plan 1,785 hours, assurance gap 40 objects each flagged as GENUINE GAP with impact TOP or BIG and reason Capacity shortage
The funnel with the gap list expanded: from 50 universe objects to 42 gross candidates (3,280 hours needed) to 1,785 direct hours available. Two large Top-risk assignments take up nearly the entire 1,785 hours, so the remaining forty candidates, each smaller in scope but together accounting for the remaining 1,495 hours, fall outside the net plan and are each explicitly flagged "GENUINE GAP" with impact and reason.

Below is an example of what that gap appendix looks like for the fictional logistics company. The objects are not picked at random: they are the highest-impact candidates that still fall outside the net plan, either because of a capacity shortage or because enough external assurance is available to lean on this year.

Audit object Impact Reason out of scope Alternative coverage
Subcontractors (owner-operators)TopCapacity shortage; requires site visits plus legal analysisNone
Customs and excise legislationBigCapacity shortage; specialist knowledge missing in-houseNone (planned next year via specialist hire)
Fraud and integrity managementBigLower priority than the selected Top risksConfidential counselor reports annually; no formal audit
Telematics and onboard computersModerateDeliberately low priority; technically stable, little changeVendor's internal management reports; no external audit
HR and payroll administrationBigCapacity shortage; audited 2 years ago with no material findingsNo external assurance; scheduled for year 3 of the three-year cycle
Procurement and supplier selectionBigCapacity shortage; competes with higher prioritiesNone; possible candidate for Q3 supplementary budget
Sustainability / CSRD reportingBigExternal assurance (EY) sufficient this year; reliance documentedYes (EY limited assurance on CSRD data)

Seven objects, seven explicit board decisions. The audit committee that receives this overview knows exactly where it is getting no independent assurance, and can decide whether to live with that or invest in additional capacity. That is the conversation GIAS 9.4 is aiming for.

The plan is submitted for approval to the board and the audit committee (GIAS 9.4), and updated whenever circumstances require it. Not as an annual ritual settled in October and left untouched until the next October, but as a rolling document with agreed revision criteria. A major acquisition closing in March, an incident in June that makes a new subject urgent, a regulator announcing new priorities in September: all of those are potential triggers for an interim revision. GIAS 9.4 explicitly allows this, and GIAS 8.1 requires the board to be informed immediately when risks make a plan change necessary before a formal board meeting can be scheduled.

The frequency dimension deserves separate attention. A multi-year cycle prevents the annual plan from becoming a yearly repeat of the same selection. Objects audited last year need not return to this year's list; objects unassessed for three years while their impact stays high deserve an explicit reason for being skipped again.

Screenshot of the frequency heatmap in the Audirium Audit app: for each audit object, the years 2024 through 2029 with color codes for Completed, Planned, and Not planned
The frequency heatmap shows the multi-year cycle at a glance: which objects were audited recently (green), which are scheduled (blue), and which have gone untouched for several years (grey). It makes the conversation about cycle times concrete and traceable.

II. What GIAS and the Corporate Governance Code require

The Global Internal Audit Standards structure the obligations around the annual audit plan across five standards in Principle 9, supported by the governance and resource standards in Principles 7 and 8.

GIAS Standard 9.1 requires the head of the audit function to have a thorough understanding of the organization's governance, risk management, and control processes, including its risk profile and strategic priorities. Standard 9.2 asks for a multi-year audit strategy showing how the audit function fulfills its mandate. Standard 9.3 is critical and covers methodology: the procedures, techniques, and tools used to carry out audit assignments in line with the standards. In the context of the annual plan, that means the selection and planning process itself must be methodologically sound, documented, and periodically reviewed.

GIAS 9.4: the "next set of engagements" as a literal gap requirement

Standard 9.4 (Internal audit plan) is the core of this chapter. The head of the audit function builds a risk-based audit plan, based on a documented risk assessment carried out at least annually, after consultation with senior management and the board, and submitted to the board for approval. The standard also explicitly requires that the plan make the available resources and their consequences for coverage explicit. But the most concrete element is what the standard says about the plan's content.

The GIAS implementation guidance to 9.4 spells out literally what the proposed plan must contain. Alongside available hours versus other activities, the list of proposed assignments with their rationale (significance of the risk, organizational theme, legal obligation, time since the last assignment), the general purpose and preliminary scope of each assignment, and the percentage of hours for contingencies, it states this: "The next set of engagements that would have been performed if additional resources were available. Discussion regarding these engagements may help the board assess the adequacy of resources available to the internal audit function."

GIAS 9.4: the literal gap requirement
The gap appendix is not an invention of a diligent audit function, or a best practice recommended in a handful of professional publications. It is a literal element of what the proposed internal audit plan must contain under the GIAS implementation guidance. "The next set of engagements that would have been performed if additional resources were available." The gap list is therefore not a free choice but the worked-out practice the implementation guidance to 9.4 prescribes. More important still is the binding requirement itself. Standard 9.4 (Internal audit plan) explicitly requires the plan to make the available resources and their consequences for coverage visible: a plan without the gap list leaves out exactly that element.

That clause obliges the audit function to document the assurance gap. The board must be able to assess whether the available resources are adequate; that requires the unplanned objects to be visible. Discussion of those next assignments, the guidance says, helps the board assess the adequacy of resources. That is exactly the function of the gap appendix: not to complain about a lack of resources, but to let the audit committee make an informed choice.

Standard 9.5, on coordination and reliance, requires assurance mapping. Not only to avoid duplication, but also to document the basis for relying on others' work. Undocumented reliance is not reliance in the GIAS sense. The GIAS guidance to 9.5 is concrete on this point: a reliance decision requires assessing the other provider's qualifications and independence, the quality of the work delivered, and whether that work covers the control objectives relevant to your own assurance need. The head of the audit function then keeps monitoring the quality of that work for as long as it is relied upon. An ISAE 3402 report that vanishes into the archive on arrival does not meet that requirement.

Principles 7 and 8 flank this on the governance side: Standard 7.1 requires organizational independence and functional reporting to the board. An audit function that does work outside the audit core, gives advice, or contributes to risk management must put safeguards in place for objectivity. Standard 8.1 requires direct, regular communication with the board, including on the adequacy of resources. Standard 8.2 states that the board assesses the adequacy of resources at least annually and oversees budget decisions.

A board that discusses this without an explicit gap appendix has not been able to judge anything. In most organizations, the CAE brings in the plan and asks for agreement. But Standard 8.2 explicitly pulls that responsibility toward the board: the board oversees budget decisions. That is only possible if the consequences of the budget, including what does not get audited, are visible at board level. A board that never puts 8.2 on the agenda has effectively left the resource assessment to the CAE, while the standard explicitly places that responsibility with the board.

Alongside Standard 9.4, Standard 10.2 also deserves attention in the context of capacity planning. Standard 10.2 requires the head of the audit function to carry out formal capacity planning to establish staffing needs. That capacity planning is not just an internal HR tool; it is the empirical basis for the budget requested from the board. A CAE who says "we need more people" without a documented capacity calculation is asking the board to make a decision it cannot substantiate. A CAE who does present the calculation, in the form of the worked example above, gives the board the material to genuinely weigh "more budget versus a bigger gap."

At the assignment level, Standard 13.2 works out the risk assessment further: for each individual assignment, internal auditors carry out a risk assessment to inform the assignment's objectives and develop the work program. This is the second layer: the organization-level risk assessment drives selection, the assignment-level risk assessment drives depth.

The Statement on Risk Control and the Dutch Corporate Governance Code

Alongside the GIAS obligations, an external anchor has now been added. The Verklaring Omtrent Risicobeheersing (Statement on Risk Control, VOR) is part of the updated Dutch Corporate Governance Code. The Code works through a comply-or-explain mechanism: a listed company applies the provisions or accounts for why it does not. That is legally different from a direct statutory duty in the strict sense, but the practical effect for the audit function is, in many respects, identical: the board accounts for the level of assurance it has, and that account rests on what the assurance chain actually covered that year. The precise effective date and first reporting years can be found in the published Code; anyone who needs certainty on exact timing for legal purposes should consult the Code itself or the monitoring information from the Dutch Corporate Governance Code Monitoring Committee.

Best-practice provision 1.4.3 requires the board to explicitly account for the level of assurance its systems give that operational and compliance risks are being effectively controlled. Provision 1.4.2 asks for an account of the design, operation, and effectiveness of the risk control and control systems. Under provision 1.5.3(iv), the audit committee reports to the supervisory board on the substantiation of that statement.

That turns the assurance gap (see section I) from an internal planning category into the gap the board accounts for externally. For non-listed organizations, healthcare institutions, pension funds, housing associations, and semi-public bodies, the Code does not apply, but the logic spreads as best practice through sector governance codes. The underlying reasoning is sector-independent: board members who claim assurance over risks on which no assurance has been delivered are making an unsubstantiated statement.

In conversations with audit committees, I notice the VOR is initially treated as a legal formality when it first comes up: an extra paragraph in the annual report. But it slowly sinks in that the substantiation of that statement runs through the annual audit plan as its central input. The moment a supervisory board member asks, "On what basis do we state that operational risks are effectively controlled?", the answer depends heavily on what the audit function did that year. And on what it did not do.
Screenshot of the audit committee dashboard in the Audirium Audit app: KPIs, the audit plan, an Assurance and Gap section with combined coverage, the number of gap objects, required versus available capacity, and a draft card for the Statement on Risk Control
The audit committee dashboard: KPIs, the net audit plan, and the assurance/gap section side by side. Combined coverage, the number of gap objects, and the capacity ratio are readable at a glance. The VOR draft card shows how coverage translates into the board statement.

Combined assurance and the ISAE 3402 boundary

Assurance mapping is more than an administrative exercise; it is the basis for what GIAS 9.5 calls "reliance." The question is concrete: whose work can you lean on, and up to what limit? And what do you need to request from an ISAE 3402 to be able to make that judgment?

With an ISAE 3402 type II report, the most common form of external IT assurance from service providers, the first question is which control objectives were described and tested. An ISAE 3402 from an IT outsourcing partner typically tests general IT controls: access security, change management, backup and recovery. If your assurance need concerns the accuracy and completeness of transaction processing for specific processes, the ISAE 3402 may not cover those control objectives. The report then says something about the infrastructure, but nothing about the processing running on top of it inside your organization.

Term: Combined assurance and reliance boundaries (GIAS 9.5)
Combined assurance is the practice of internal audit relying on other assurance providers' work to optimize coverage and avoid duplication. GIAS sets three requirements for this: (1) the other provider's qualifications and independence have been assessed; (2) the quality of the work has been found adequate; (3) the reliance decision is documented, including the basis for the reliance. For an ISAE 3402 report, the relevant questions are: which control objectives are described, do the transaction flows relevant to you fall under those objectives, did the auditor test operating effectiveness (type II) or only assess the description (type I), and does the audit period cover the year you need assurance on? If a type II report only tests the description of the control measures but not their effectiveness for your specific control objectives, that is not an adequate basis for reliance. Undocumented reliance, or reliance based on a superficial reading of the report, is not reliance in the GIAS sense.

The second question concerns the audit period. An ISAE 3402 type II typically covers a period of six to twelve months. If your organization reports annually on fiscal year X, and the report runs from October X-1 to September X, you have a three-month gap. That gap deserves an explicit position in the assurance map.

The third question concerns the adequacy of the assurance level. An ISAE 3402 gives limited assurance on the design and operation of the described controls. If the board needs reasonable assurance on the effectiveness of specific control measures, an ISAE 3402 may not be sufficient, even if the report exists.

Combined assurance is a tool for efficiency, not a tool for papering over coverage gaps. GIAS 9.5 makes that explicit: the head of the audit function keeps monitoring the quality of the work used as a reliance basis. That is an active, judgment-based task, not passively filing third-party reports.

A practical checklist for assessing an ISAE 3402 type II report: are the described control objectives specified and do they align with your assurance need? Does the audit period cover the fiscal year you need assurance on, or is there a gap of several months? Did the auditor perform type II work (testing operating effectiveness over the period) or type I (only assessing the description and design)? Were exceptions reported in the test results, and if so, of what nature? If any of these questions gets an unsatisfactory answer, the reliance decision is not straightforward. It then requires additional work of your own, targeted additional testing, or explicit documentation of the remaining uncertainty in the assurance map.


III. Depth, coverage, and risk appetite

One of the most dangerous illusions in the annual audit plan is the impression of broad coverage that is actually thin coverage.

Say an audit function includes twenty subjects in this year's plan. All get executed. Coverage, measured by number of objects, is one hundred percent. But if all twenty audits were quick scans, checking only whether control measures exist on paper, the assurance level obtained is low. The question of whether those measures actually worked consistently over the past year was never asked, let alone answered.

An honest assurance map therefore records, for each object, not just whether there is coverage but to what depth. A DORA audit that fully tested the Regulatory Technical Standards, including a year of operating-effectiveness testing, means something fundamentally different from a high-level DORA quick scan.

Term: Depth
Depth is a separate dimension that does not replace coverage. An audit can "cover" an object by assessing only the design of the control measures: are they adequately designed? That is a different question from existence: are they actually implemented and present? And a different one again from operation: do they demonstrably function over a period? Operating-effectiveness testing requires sampling over time and is therefore considerably heavier than a design-and-existence check. The level of detail in the standards framework also matters: an audit testing a high-level framework produces a fundamentally different outcome than an audit testing the detailed Regulatory Technical Standards required under DORA. Treating those two as equivalent in the assurance map presents a distorted picture of actual coverage.

The three depth levels, side by side

To make the conversation with the audit committee concrete, it helps to lay the three levels side by side. Not as an abstract taxonomy, but as a decision framework with practical consequences for the plan.

Level Question answered Typical duration Sampling required Assurance level
Design Are the control measures adequately designed to mitigate the risks? 2-3 weeks No (document review plus interviews) Limited: assurance on design, not on execution
Existence Are the designed measures actually present and implemented? 3-5 weeks Limited (a few spot checks on presence) Limited to moderate: assurance that measures exist, not that they work consistently
Operation Have the measures demonstrably worked over the assessment period? 6-12 weeks Yes (statistical or risk-based sampling over the period) Moderate to reasonable: basis for a board statement on effectiveness

What this table reveals is that the ambition to audit fifteen subjects this year looks very different depending on whether all fifteen are examined at the operation level or are quick scans. The plan must state the intended depth per object, because only then can the audit committee judge what assurance level the result actually delivers.

The example I find most telling: an audit function that has kept "DORA" on the candidate list for five years running, but always executes it as a quick scan for lack of time. The formal coverage exists; the material assurance does not. If the external accountant and the regulator also do nothing in depth in this domain, the board has spent years assuming things were fine while nobody actually looked closely.

The gap therefore has two dimensions. The first is the objects gap: subjects that do not get audited at all. The second is the depth gap: subjects formally assessed but at a level insufficient to give the required assurance. Both dimensions belong in the plan and in the conversation with the audit committee.

GIAS 9.4 backs this directly: the proposal must include "the rationale for selecting each proposed engagement," including the "general purpose and preliminary scope of each proposed engagement." Scope and depth are by definition part of the plan; a plan without that specification does not meet the board's information need that 9.4 aims to serve.

Risk appetite: the board chooses the gap

Reversing the decision order in the annual planning process confuses the governance. The common mistake is that the CAE builds a plan and then asks whether the board agrees. The correct order is: the board first approves the audit landscape (the universe, the mapping, the impact ratings), then chooses an explicit risk appetite, and the CAE derives the plan and the associated budget from that.

Term: Risk appetite
Risk appetite is the level of risk acceptance the board deliberately chooses. In the context of the annual audit plan: choosing a risk appetite means choosing the assurance gap (see section I). A higher risk appetite means deliberately accepting bigger coverage gaps. A lower appetite means investing in more and deeper audit work. That is a board decision, not a technical optimization. If the board approves the plan without first setting the landscape and the risk appetite, it is effectively approving choices the CAE already made quietly beforehand. Board responsibility for the assurance gap has then, in effect, been delegated to the audit function, even though that gap is a board decision.

A risk appetite in the context of the annual plan looks concrete in practice: the board decides which impact levels get independent assurance within the planning period. Only catastrophic risks, with everything below that threshold as an accepted gap? Catastrophic and critical risks, with major risks as a deliberately uncovered zone? Or a full multi-year cycle that also covers significant risks over a longer horizon? Each choice carries its own budget size and depth, and therefore its own gap.

In practice, this conversation rarely runs so cleanly. What I see more often is a board that approves the plan after the fact and assumes the CAE made the right trade-offs. That is trust in the professional, and that trust is warranted, but it is not board oversight in the sense of GIAS 8.2. Board oversight means the board understands the capacity trade-off, knows the consequences of the chosen prioritization, and has explicitly accepted which objects go without independent assurance this year. A board that cannot confirm that after approving the plan has completed a ritual, not made a board decision.

A CAE who wants to change this has a concrete tool: always present three variants. Variant A: what can we do with current capacity, and what falls outside it? Variant B: what would we add with 20 percent extra budget, and which gap closes as a result? Variant C: what does it cost to audit all Top risks at the operation level, and how big is that investment jump? Three variants make the trade-off concrete and give the board a real choice. Presenting one variant "for approval" is asking the board to stamp a proposal whose alternatives are unknown.

The audit universe as a funnel: from many risk objects to a small assessed set, the rest dimmed as the assurance gap

The three-meeting cycle for the audit committee

The decision order only works if it is embedded in a concrete meeting cycle. In most organizations, the audit plan is presented for approval in a single audit committee meeting. That is too narrow: the board cannot assess the universe, choose the risk appetite, and approve the net plan in one sitting. That requires at least three meeting moments with clearly distinct agenda items.

The three-meeting cycle (an operational decision model)

Meeting 1 (for example, May/June): universe and assurance mapping for information
The CAE presents the updated audit universe, the assurance mapping results per object, and the impact assessment. The board takes note and gives feedback on completeness: are any categories missing, are there new strategic themes that belong in the universe? This is an information meeting, not a decision meeting. Outcome: a shared picture of the audit landscape.

Meeting 2 (September): risk appetite as the decision point
Based on the universe and the impact ratings, the CAE presents the range of possible plans: from a minimal variant (Top risks only, limited depth) through a middle variant (Top and Big, mixed depth) to an ambitious variant (a full three-year cycle, operation-level audits for all Top risks). For each variant, the required capacity, the associated gap, and the indicative budget. The board chooses a variant. This is a decision meeting, not an information moment. Outcome: a chosen risk appetite and a mandate for the CAE to finalize the plan.

Meeting 3 (November): net plan, gap appendix, and budget for approval
The CAE presents the finalized annual plan based on the chosen risk appetite: the net list with the rationale, scope, and intended depth per assignment, the capacity calculation including the contingency buffer, and the gap appendix as a formal second part. The board approves the plan. Outcome: an approved plan compliant with GIAS 9.4, including the gap list GIAS requires.

Difference from common practice: In common practice, the plan is presented and approved in a single meeting, and the board effectively endorses choices the CAE has already made. The three-meeting cycle reverses the order: the board sets the framework before the plan gets built. This is not more work; it is a rearrangement of the same information across three conversations, each with its own decision function.

The IIA's Three Lines Model from 2020 is the relevant framework here: the governing body provides oversight, management runs the first and second lines, and internal audit delivers independent assurance to the board as the third line. The organizational independence of the third line (GIAS 7.1) is exactly what makes that assurance valuable. That model only works if the three lines genuinely play three distinct roles. An audit function that takes on second-line tasks because that line is not mature enough helps the organization in the short term but undermines its own independence over the longer term. It is better to state explicitly in the audit plan that the second line's immaturity makes it impossible to rely on its work, which in turn implies extra capacity for the audit function itself.

Within the selected coverage, combined assurance can offer efficiency: objects where external parties deliver adequate, documented assurance need less depth or less frequency from internal audit. But combined assurance is not a license to skip coverage: the documentation must show that the external assurance answers the right questions, at sufficient depth, and over the right period.

Then there are the external accountant and the regulator. These sometimes get labeled as extra assurance lines. That framing misleads if it leads the board to lean on their judgment for timely board assurance. The external accountant judges only after the fiscal year closes, typically not until February or March of the following year. Moreover, the external accountant's scope is primarily the financial statements. Operational risk control and compliance, the subject of the board's VOR statement, largely fall outside the accountant's primary mandate. And the regulator stands even further removed: external, focused on sector compliance, not intended as a source of board assurance during the year.

I have seen board members genuinely surprised when I explained that the external accountant does not substantiate the VOR statement. "But we get audited every year, don't we?" Yes, the financial statements. Not whether operational risks are effectively controlled. The accountant does not say that either; the accountant's opinion covers the fairness of the financial reporting. A board that misses that gap is living in false comfort.

IV. The pitfalls and the mature audit function

The methodology is clear, but practice is stubborn. The pitfalls in the annual planning process are recognizable and recurring. I walk through fourteen of them, not to offer a catalog of mistakes, but because each one has caused damage I have seen firsthand, damage that could have been prevented.

A note on how this list is built: I am not presenting these pitfalls as a ranking, with the last one being the worst. Severity depends on context. But if I have to single out the one I see most often and that does the most damage in practice, it is the fourteenth: the deliberate choice not to name the gap. All the other pitfalls are methodological shortcomings; the fourteenth is a communication failure toward the board.

1. The universe as an end rather than a means. Some audit functions spend months refining the universe spreadsheet, adding subcategories, attaching risk tags. That is "spreadsheet theater": activity that contributes little on its own to better selection. GIAS does not demand a perfect universe; GIAS demands a risk-based plan. The universe is a means to make that basis visible, and once that basis is visible, the universe is good enough.

2. The static universe. Copying last year's list every year and removing only the completed items misses the dynamics of a changing organization. New legislation such as DORA and CSRD, reorganizations, new IT systems, incidents at comparable organizations: all of this creates new auditable objects that need to appear in the universe. A universe last fundamentally revised three years ago is no longer a universe, it is a historical document.

3. The wish-list plan. Including more audits than capacity allows is tempting, because it suggests ambition. But a plan that is structurally unachievable produces a silent gap: audits that get pushed to next year without anyone explicitly deciding that. Skip the contingency buffer and you have implicitly planned it away, and you will miss it later.

4. No combined assurance. Skip the assurance mapping and you fall into two traps at once. On one side, you audit domains already amply covered by others, burning capacity better spent elsewhere. On the other, you lean on the assumption that "someone else handles it" without ever verifying that, which creates coverage gaps nobody wanted but nobody saw either.

5. Leaning on management risk without validation. Management's assessments are a useful input for organization-level risk assessment, but they are not a substitute for an independent one. If the second line's risk management has not been found effective, its risk assessment output is unreliable as a basis for audit selection. GIAS 9.5 requires the basis for reliance on others to be explicitly documented, and an immature second line does not meet that basis. An audit function that bases its selection on a risk register whose quality has never been assessed is building on sand. The GIAS implementation guidance to 9.4 puts it clearly: "The internal audit function should only rely on management's information about risks if it has concluded that the organization's risk management processes are effective." That is an active conclusion requiring documentation, not a passive assumption.

6. The annual ritual. A plan built in the autumn and not reassessed until the following autumn misses the flexibility the environment requires. Changing circumstances that surface mid-year, incidents, new legislation, strategic pivots, should trigger an interim revision against agreed revision criteria. The GIAS implementation guidance to 9.4 is explicit here: in a dynamic organizational environment, the audit plan may need adjustment as often as every quarter, or even every month. Without that mechanism, you are always behind events.

7. Handing management the pen. Management is a useful conversation partner when building the plan, but input is not control. GIAS Standard 7.1 is clear on the audit function's organizational independence: it is independent of the activities it assesses. Auditing what is comfortable for the organization, rather than what matters to the board, means abandoning the mandate.

8. Gross or net blindness. Selecting purely on net risk misses the inherently dangerous objects whose controls simply have not been tested yet. Selecting purely on gross risk misses control effectiveness as a co-selection criterion. The selection basis is impact combined with an assessment of control effectiveness, to the extent that can be judged before the audit.

9. Frequency as habit. The three-year cycle for medium-sized risks is a rule of thumb, not a law. An object audited last year and fundamentally changed since deserves renewed attention. An object sitting in the cycle for five years without anything material ever surfacing in a stable environment might move to a longer cycle. Event-driven triggers, an incident, a new partner, a major investment, always override the calendar rhythm.

10. Coverage without depth. A quick scan on design does not count when the board's need is reasonable assurance on operation. A plan naming twenty objects without specifying the intended depth per object gives the board no basis to judge the assurance level. This is the depth gap: not a missing assignment, but an assignment executed at a level that does not meet the board's need. The depth gap is, in a sense, more treacherous than the objects gap: it stays invisible in the plan, since every planned object is listed, but becomes visible in the reporting afterward when the board discovers that "audited" meant something fundamentally different from what it expected. The best moment to calibrate that expectation is before execution, not after.

11. Leaning on the external accountant for timely assurance. The external accountant and the regulator arrive too late, cover too narrowly, and sit too far away to serve as timely board assurance. They earn a place in the assurance map, but they do not replace the third line as a source of targeted board assurance during the year.

12. A work mix that erodes independence. An audit function taking on significant advisory roles, contributing to setting up the second line, or actively helping with risk management can no longer audit those domains independently (GIAS 7.1). Every hour spent on non-assurance work is an hour not spent on coverage. Fail to steer the work mix deliberately, and coverage shrinks without that ever being a conscious decision.

13. Treating an ISAE 3402 as a blanket license. The existence of an ISAE 3402 report at a service provider is not, on its own, a reason to automatically drop that object from scope. Only after an active reliance assessment, testing the control objectives, the audit period, and the assurance level against your own assurance need, is there a documented reliance basis. An unopened report in the archive is not reliance.

14. Not putting the gap in the plan as a list. This is the overarching pitfall. Every other pitfall can produce a hidden gap, but this one is the deliberate choice not to make the gap visible at all. A plan showing only the net list, without the deliberately-unassessed list, never confronts the board with the gap it should be weighing in on. GIAS 9.4 explicitly requires that list, as "the next set of engagements that would have been performed if additional resources were available." A plan without that list is non-compliant with Standard 9.4, which explicitly prescribes this element as part of the proposed audit plan.

I have seen it too often: an audit committee caught by surprise at year end. Not by what was audited, but by what was not. An incident suddenly reveals that a certain process has sat outside scope for years. Nobody decided it, nobody said it out loud, nobody put the gap on the table. The CAE had treated the plan's "implicit" as reality, and the board had assumed the plan was fully comprehensive. That misunderstanding does real damage.

The mature audit function dares to name what it does not cover

Many annual audit plans get built out of an understandable but misplaced desire for completeness. The plan has to look impressive, project ambition, show the audit function active across every relevant area. The trap is that this desire produces a plan promising more than it can deliver, creating a gap that goes undiscussed.

The mature audit function does the opposite. It establishes what it can genuinely do, with the people and hours available, at the assurance level the organization needs. It maps the universe fully, does the assurance mapping carefully, selects on impact and relevance, and sets the net list based on capacity and depth. What is left over, it names explicitly as this year's assurance gap (see section I). It puts that gap on the table with the audit committee, asking whether the board accepts it or is willing to invest in more capacity or a different prioritization.

That transparency has a curious side effect I recognize from practice: the audit function that names its limits becomes more credible, not less. A board that knows the CAE says what she does and does not do trusts that CAE's reports more than the reports of an audit function that always suggests full coverage but delivers the surprise afterward. Precision builds trust; broad claims breed distrust the moment reality tells a different story.

The instruments supporting this conversation, universe, assurance map, capacity calculation, gap appendix, and multi-year frequency, are not complicated in themselves. What matters is bringing them together into one coherent planning document that lets the board ask the questions it needs to ask. "Why isn't the owner-operator fleet being audited this year?" is a good question from an audit committee member. "We simply did not have the capacity" is an unsatisfying answer. "We did not have the capacity, we have no alternative assurance, and the impact is Top; the question for the board is whether you are willing to fund €40,000 in outside help to close this gap this year" is the answer the board deserves, and it lets the audit function take its advisory role seriously.

That conversation is uncomfortable, and it should be: it confronts the board with the financial consequences of the risk appetite it chose.

Under the Dutch Corporate Governance Code and the VOR, that conversation is no longer optional for listed companies. The statement the board signs rests, in substance, on the coverage the audit function actually delivered that year. Anyone who has not explicitly discussed and formally accepted the gap is signing a statement without adequate substantiation.

The best annual audit plan is not the plan with the most audits. It is the plan that puts the available assurance to maximum use on the most relevant risks, that names the gap without dancing around it, and that lets the board make an informed choice about what it accepts and what it does not. A plan that tells the board everything internal audit will do, but hides what it will not, is not a governance instrument. It is a work agenda.

The audit function that says every year: "These are the twelve subjects we are auditing, and these are the six we are deliberately leaving uncovered, and here is why, and here is the risk that stays uncovered as a result," delivers real value. Not by doing more than others, but by being more precise about what it does and does not do, and letting that precision drive a board conversation worthy of the name.

That is also the core of what GIAS aims for. The standards are not a compliance checklist; they are a professionalization agenda for a function that deepens its value through transparency, methodological discipline, and honest communication about its limits. An audit function that meets GIAS 9.4 in the literal sense, with the gap list in the plan, is already a step ahead of most peers. An audit function that does that and also runs the three-meeting cycle, presents the board three variants, documents the reliance basis per object, and specifies the depth ambition per assignment, builds a governance position that serves the board for years, regardless of who sits on the audit committee or how senior management changes.

Time to hold your annual plan up to the light?
Do you recognize the pitfalls in this essay in your own audit function: a gap that is nowhere stated explicitly, a universe not fundamentally revised in years, a capacity plan without a buffer? Walking through the process methodically helps. Audirium offers an audit planning module that brings the universe, assurance mapping, prioritization, and capacity calculation together into one transparent decision document for the audit committee. Feel free to reach out via [email protected] to explore what that could mean for your function.
Back to Insights