audit-risk-assessment

Builds an audit universe and scores entity-level risks for annual internal audit planning.

Updated Jul 2, 2026
One-click install
npx skills add https://github.com/tuanpa-nhg-eng/nhg-ipms --skill audit-risk-assessment-tuanpa-nhg-eng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-risk-assessment
Source: https://github.com/tuanpa-nhg-eng/nhg-ipms/tree/main/.claude/skills/audit-risk-assessment
Command: npx skills add https://github.com/tuanpa-nhg-eng/nhg-ipms --skill audit-risk-assessment-tuanpa-nhg-eng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Internal audit teams need a structured, defensible way to decide which units and processes to audit each year. This Skill builds the audit universe and scores every auditable entity on a mandatory 5×5 Likelihood × Impact scale, producing ranked risk assessments that feed directly into the annual audit plan. ## Core Features & Use Cases - Audit Universe Construction: Lists auditable entities by organizational unit or by process (admissions, tuition & receivables, procurement, HR & payroll, finance, IT, school safety), each with code, owner, last audit date, and related IT systems. - 5×5 Risk Scoring with Justification: Scores Likelihood × Impact per entity using a mandatory rating scale, requiring documented rationale for every score and considering factors like major changes, transaction volume, prior audit results, and whistleblower signals. - Ranking, Heatmap & Handoff: Produces a descending risk ranking, a 5×5 Markdown heatmap, and proposed audit frequency, then hands results off as input to the annual audit plan with assumptions and items needing leadership confirmation. - Use Case: An internal audit lead at an education group needs to prepare the annual risk assessment. The Skill inventories all OpCos and functional processes, scores each on the 5×5 scale, and outputs audit-universe.md and danh-gia-rui-ro-{year}.md ready for management review. ## Quick Start Ask the assistant to build the audit universe and perform this year's internal audit risk assessment for all units and key processes using the 5×5 scoring scale.

Frequently Asked Questions about audit-risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build an audit universe for internal audit?

List auditable entities along two dimensions: by organizational unit (subsidiaries, functional blocks) or by process (procurement, payroll, finance, IT). For each entity record a code, description, owner, last audit date, and related IT systems, using existing org charts and process dictionaries to avoid gaps.

How to perform an annual internal audit risk assessment?

Score each auditable entity on Likelihood × Impact using a 5×5 scale, documenting the rationale for every score. Consider major changes, transaction volume, prior audit results, time since last audit, automation level, and whistleblower signals, then rank entities and map them on a heatmap.

What risk factors should be considered when scoring audit entities?

Key factors include significant changes (new systems, restructuring, key personnel turnover), transaction and cash volume, results of previous audits, time elapsed since the last audit, degree of automation, and irregularities reported through whistleblowing or hotline channels.

Does the risk assessment replace the audit plan approval by leadership?

No. The assessment is an input to the annual audit plan, not a final decision. It explicitly records assumptions, missing information sources, and items requiring leadership confirmation, and does not conclude on behalf of the Head of Internal Audit.

When should the audit risk assessment be updated during the year?

Update it mid-year whenever material changes occur, such as restructuring, new systems, or emerging risks. Regulations like Decree 05/2019 (Article 14) permit adjusting the audit plan to reflect such significant developments.