ACC 645 Module 8 Internal Audit Assignment Example

Reviewed by Portia Lambrick, MBA

This ACC 645 Module 8 Internal Audit Assignment sample builds a risk-based annual plan for an internal audit function. Prepared for SNHU ACC 645 (ACC-645), the advanced auditing course in the MS Accounting program, it answers Module Eight's assignment on internal auditing and its relationship with the external audit. A composite Nasdaq-listed payroll software company near Pittsburgh has a six-person internal audit team reporting to the audit committee. The assignment defines the audit universe, scores risks by impact and likelihood, allocates 7,200 hours to the highest risks, from client fund custody to sales contract integrity, confirms the function's independence under the IIA's 2024 standards and explains how the external auditor may use its work.

CourseACC 645 Advanced Auditing
ModuleModule 8
Paper typegraduate assignment building a risk-based internal audit plan
LengthAbout 1,010 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Accounting
UpdatedOctober 2026

Free sample paper for ACC 645 Module 8

1

Risk-Based Internal Audit Plan for 2026

[Student Name]

Southern New Hampshire University

ACC 645: Advanced Auditing

Module Eight Assignment

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title names the plan and year.
2

Risk-Based Internal Audit Plan for 2026

Introduction

The company's internal audit function has a chief audit executive, four auditors and one IT auditor, giving about 7,200 available audit hours a year after training and leave. It reports functionally to the audit committee and administratively to the CFO. This assignment builds the 2026 plan under the Institute of Internal Auditors' current global standards, in force since January 2025, which require a plan based on a documented assessment of the organization's strategies, objectives and risks (Institute of Internal Auditors, 2024).

What this page is doingThe function and its capacity are introduced.
3

The Audit Universe

The universe has 28 auditable areas, grouped by the company's value chain: sales and contracting, customer onboarding, payroll processing, tax filing and remittance, client fund custody, treasury, the Canadian operations, product development, information security, data privacy, human resources, procurement, financial close and reporting, and regulatory compliance, among others. Each area was assessed with management and the audit committee in November, and the backdating case and the Canadian acquisition were treated as new information.

What this page is doingAuditable areas are defined.
4

Risk Scoring

Each area was scored from 1 to 5 for impact, considering financial, regulatory, reputational and customer effects, and for likelihood, considering complexity, change, past findings and control maturity. The product gives a score out of 25.

Highest-scoring risks

AreaImpactLikelihoodScoreReason
Client fund custody and reconciliation5315About $2.1 billion held for customers; any shortfall is existential
Payroll tax filing and remittance5315Penalties and customer losses if filings are late or wrong
Data privacy and cybersecurity5315Employee pay and bank data for 9,000 employers
Sales contracting and commissions4416Backdating case showed control gaps and incentive pressure
Canadian integration and migration4416New systems, new regulators, customer migration under way
Financial close and reporting428Mature controls, covered by SOX testing
What this page is doingImpact and likelihood are combined.
5

Allocating the Hours

2026 plan hours

ActivityHours
SOX testing for management's assessment2,200
Client fund custody and reconciliation audit700
Payroll tax filing and remittance audit650
Sales contracting and commission audit600
Canadian integration review550
Data privacy and cybersecurity, with outside specialists600
Follow-up of prior findings300
Reserve for unplanned work and investigations600
Advisory work on the new deal desk controls400
Planning, reporting and quality assurance600
Total7,200

The plan concentrates on the five highest risks and does not audit lower-scoring areas this year; the audit committee was told which areas will not be covered, as the standards expect. Cybersecurity uses an outside firm under internal audit's direction because the team has only one IT auditor.

What this page is doingThe plan fits the team.
6

Scoping the Top Engagements

Each major engagement has a written objective approved by the chief audit executive. The client fund audit will test whether every customer's funds are received, held in segregated trust accounts, invested only as policy allows and disbursed on time, with daily reconciliations of the trust accounts to customer obligations reviewed by someone outside treasury. The tax filing audit will select 60 employers across 15 states and the Canadian provinces and trace filings and payments to agency confirmations, focusing on jurisdictions where rates changed during the year. The sales contracting audit will test the new deal desk controls, the commission plan's accelerators and a sample of contracts against signature metadata, building on the investigation's findings. The Canadian review will cover data migration controls, the source deduction remittance calendar and access to the Toronto systems.

What this page is doingObjectives are set for the highest risks.
7

Quality and Reporting

The standards require a quality assurance and improvement program, including ongoing monitoring, periodic self-assessment and an external assessment at least every five years. The function's last external assessment was in 2021, so one is scheduled for 2026, performed by a firm with no other relationship to the company. Each engagement ends with a written report rating findings as high, medium or low, with management's response and a due date; the committee receives a quarterly summary of open findings by age, and any high-rated finding open past its due date is discussed in executive session.

What this page is doingThe function's own quality is managed.
8

Independence and Objectivity

The chief audit executive meets the audit committee in executive session each quarter and the committee approves the plan, budget and the chief audit executive's appointment and pay. The administrative line to the CFO is limited to budget and logistics. The advisory work on deal desk controls creates a potential objectivity threat for the later audit of sales contracting, so different staff will perform the two engagements and the advisory role will stop at recommending controls, not designing or operating them.

What this page is doingThe function's position is confirmed.
9

Coordination With the External Auditor

Under AS 2605, the external auditor may use internal audit's work after assessing the function's competence and objectivity (Public Company Accounting Oversight Board, 2016). The external auditor plans to use about half of the SOX testing hours, mainly for lower-risk processes such as payroll for the company's own staff, procurement and fixed assets, and will reperform a sample. It will not use internal audit's work for significant risks, such as revenue recognition and client funds, where it must perform its own tests. Prawitt et al. (2009) found that higher-quality internal audit functions are associated with less earnings management, which supports investing in the function's quality as well as its size.

What this page is doingReliance is planned.
10

Areas Left Uncovered

Concentrating hours means some areas go unaudited in 2026. Procurement, facilities, the company's own payroll and travel expenses scored below 8 and will rely on management's monitoring and the SOX work that touches them. Product development scored 12 because of the pace of releases, but the external SOC 2 work covers change management on the platforms, so internal audit will not duplicate it. Human resources compliance scored 10 and is scheduled for 2027. If the reserve is not needed by the third quarter, the chief audit executive will propose using it for product development, giving the committee a choice rather than a fixed answer.

What this page is doingThe trade-offs are stated.
11

Conclusion

The 2026 plan puts most discretionary hours on custody of client funds, tax filing, sales contracting and the Canadian integration, reserves time for the unexpected and keeps SOX work efficient by coordinating with the external auditor. The committee will review progress quarterly and can redirect the reserve if new risks emerge.

What this page is doingThe plan's logic is summarized.
12

References

Institute of Internal Auditors. (2024). Global internal audit standards. Author.

Prawitt, D. F., Smith, J. L., & Wood, D. A. (2009). Internal audit quality and earnings management. The Accounting Review, 84(4), 1255-1280. https://doi.org/10.2308/accr.2009.84.4.1255

Public Company Accounting Oversight Board. (2016). Consideration of the internal audit function (AS 2605). Author.

What the ACC 645 Module 8 instructions ask for

The Module Eight assignment in ACC 645 usually asks you to plan or evaluate an internal audit function: its independence and reporting lines, its risk assessment and annual plan, and its relationship with the external auditor. Plan to define the audit universe, assess risks using impact and likelihood, rank them and allocate available hours, while reserving time for required work such as SOX testing and for unplanned requests. Cite the IIA's Global Internal Audit Standards, which took effect in 2025, and, for coordination with external auditors, PCAOB AS 2605. Explain how the plan responds to recent events at the company, since a plan that ignores them looks generic, and state which areas will go unaudited this year.

How this ACC 645 Module 8 internal audit assignment example is built

The paper builds a plan for 7,200 available hours. Risks are scored on five-point impact and likelihood scales. The highest are custody of about $2.1 billion of client funds, payroll tax filing accuracy for 9,000 employers, data privacy and cybersecurity, sales contract integrity after the backdating case, and the Canadian integration. SOX testing for management's assessment takes 2,200 hours, of which the external auditor plans to use about half. The chief audit executive reports functionally to the audit committee. The paper reserves 600 hours for unplanned work and explains the competence and objectivity factors the external auditor will weigh, along with the quality program that supports them.

Where the ACC 645 Module 8 rubric puts the points

Rubrics for the internal audit assignment typically score the audit universe and risk assessment, the ranking method, allocation of resources, independence and reporting lines, coordination with the external auditor and use of the IIA and PCAOB standards. Top papers use a transparent scoring method, connect the highest risks to the company's business and recent events, reserve capacity for the unexpected and explain how the function's work can be relied on by the external auditor. Graders also reward recognizing limits on reliance for high-risk areas. Common deductions include listing every process as a high risk, ignoring available hours, omitting independence and assuming the external auditor will rely on internal audit for significant risks.

ACC 645 Module 8 help: the mistakes that cost points

Internal audit plans most often slip by covering everything thinly: a plan that gives each of 30 areas a few days provides little assurance anywhere. A second weak spot is coordination, where students overlook that the external auditor's use of internal audit's work depends on competence and objectivity and is limited for areas of high risk or judgment. If your assignment evaluates an existing function instead, the same elements, independence, risk basis and quality, structure the evaluation. Show the hours table before the narrative; it proves the plan fits the team's capacity. Then explain the two or three areas you chose not to cover, because the committee will ask.

Get ACC 645 Module 8 written to your instructions

Send the ACC 645 Module 8 assignment and the company facts. The paper will define the audit universe, score and rank risks, allocate resources to a plan, address independence and coordinate with the external auditor under the standards. Turnaround is two days, and the first is on us. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More ACC 645 papers and related MS Accounting samples

ACC 645 Module 8 questions, answered

Where can I find a free ACC 645 Module 8 Internal Audit sample?

This page includes a full ACC 645 Module 8 risk-based internal audit plan with coordination with the external auditor.

What are the IIA's Global Internal Audit Standards?

The Institute of Internal Auditors' standards, effective in 2025, organized around domains of purpose, ethics, governance of the function, management of the function and performance of services.

How is a risk-based internal audit plan built?

By defining the audit universe, assessing risks by impact and likelihood, ranking them, considering assurance from other sources and allocating available resources to the highest risks, with time reserved for unplanned work.

Can an external auditor use internal audit's work?

Yes, under AS 2605, after evaluating the function's competence and objectivity; reliance is limited in areas of significant risk or judgment.

Why should internal audit report to the audit committee?

A functional reporting line to the audit committee supports the chief audit executive's independence from the management whose activities are audited.