audit-plan

Creates a risk-based annual internal audit plan with resource budgets and approval workflow.

Updated Jul 2, 2026
One-click install
npx skills add https://github.com/tuanpa-nhg-eng/nhg-ipms --skill audit-plan-tuanpa-nhg-eng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-plan
Source: https://github.com/tuanpa-nhg-eng/nhg-ipms/tree/main/.claude/skills/audit-plan
Command: npx skills add https://github.com/tuanpa-nhg-eng/nhg-ipms --skill audit-plan-tuanpa-nhg-eng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Internal audit teams must translate risk assessment results into an approved annual audit plan, selecting engagements, allocating auditor days, and documenting leadership sign-off. Doing this manually risks inconsistent coverage, over-allocated resources, and undocumented acceptance of unaddressed high risks. ## Core Features & Use Cases - Risk-Based Engagement Selection: Converts risk assessment scores into a prioritized engagement list with codes, audit universe references, risk ratings, engagement types, quarters, and team leads. - Resource Budgeting: Calculates available auditor days (headcount × working days minus training, admin, and a 15-20% contingency reserve) and validates planned days against capacity. - Explicit Risk Acceptance: Documents high-risk areas not audited this year with reasons and alternative monitoring measures for leadership sign-off. - Mid-Year Adjustments: Creates versioned amendment files instead of overwriting the approved plan, preserving the audit trail. - Use Case: After completing the annual risk assessment, generate the audit plan for the year, allocate 300 available auditor days across 12 engagements, and route it for approval before the fiscal year starts per Decree 05/2019. ## Quick Start Create the annual internal audit plan for this year based on the completed risk assessment, allocating auditor days and flagging any high-risk areas left unaudited.

Frequently Asked Questions about audit-plan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a risk-based annual internal audit plan?

Start from a completed risk assessment, then select engagements by risk rating: very high risks are mandatory, high risks are included unless a reason is documented, and medium or low risks follow rotation cycles. Allocate auditor days against available capacity and route the plan for approval.

How to allocate auditor days in an annual audit plan?

Calculate available days as number of auditors multiplied by working days, minus training, administration, and a 15-20% contingency reserve for unplanned work. Total planned engagement days must not exceed this available capacity.

What input is required before building the audit plan?

A completed annual risk assessment file is mandatory input, produced by the prior risk assessment step in the audit lifecycle. Without it, run the risk assessment first so engagement selection is grounded in scored risk ratings.

How do I handle high-risk areas not audited this year?

Document them explicitly in the plan with the reason for exclusion and alternative monitoring measures. This makes leadership's risk acceptance transparent and is a required section of the plan, not an optional note.

Can I modify an approved audit plan mid-year?

Do not overwrite the approved version. Create a versioned adjustment file recording each added, removed, or postponed engagement, the reasons, and the re-approval status, preserving the original approved plan for the audit trail.