| Course | ACC 645 Advanced Auditing |
|---|---|
| Module | Module 8 |
| Paper type | graduate assignment building a risk-based internal audit plan |
| Length | About 1,010 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Accounting |
| Updated | October 2026 |
Free sample paper for ACC 645 Module 8
Risk-Based Internal Audit Plan for 2026
[Student Name]
Southern New Hampshire University
ACC 645: Advanced Auditing
Module Eight Assignment
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Risk-Based Internal Audit Plan for 2026
Introduction
The company's internal audit function has a chief audit executive, four auditors and one IT auditor, giving about 7,200 available audit hours a year after training and leave. It reports functionally to the audit committee and administratively to the CFO. This assignment builds the 2026 plan under the Institute of Internal Auditors' current global standards, in force since January 2025, which require a plan based on a documented assessment of the organization's strategies, objectives and risks (Institute of Internal Auditors, 2024).
The Audit Universe
The universe has 28 auditable areas, grouped by the company's value chain: sales and contracting, customer onboarding, payroll processing, tax filing and remittance, client fund custody, treasury, the Canadian operations, product development, information security, data privacy, human resources, procurement, financial close and reporting, and regulatory compliance, among others. Each area was assessed with management and the audit committee in November, and the backdating case and the Canadian acquisition were treated as new information.
Risk Scoring
Each area was scored from 1 to 5 for impact, considering financial, regulatory, reputational and customer effects, and for likelihood, considering complexity, change, past findings and control maturity. The product gives a score out of 25.
Highest-scoring risks
| Area | Impact | Likelihood | Score | Reason |
|---|---|---|---|---|
| Client fund custody and reconciliation | 5 | 3 | 15 | About $2.1 billion held for customers; any shortfall is existential |
| Payroll tax filing and remittance | 5 | 3 | 15 | Penalties and customer losses if filings are late or wrong |
| Data privacy and cybersecurity | 5 | 3 | 15 | Employee pay and bank data for 9,000 employers |
| Sales contracting and commissions | 4 | 4 | 16 | Backdating case showed control gaps and incentive pressure |
| Canadian integration and migration | 4 | 4 | 16 | New systems, new regulators, customer migration under way |
| Financial close and reporting | 4 | 2 | 8 | Mature controls, covered by SOX testing |
Allocating the Hours
2026 plan hours
| Activity | Hours |
|---|---|
| SOX testing for management's assessment | 2,200 |
| Client fund custody and reconciliation audit | 700 |
| Payroll tax filing and remittance audit | 650 |
| Sales contracting and commission audit | 600 |
| Canadian integration review | 550 |
| Data privacy and cybersecurity, with outside specialists | 600 |
| Follow-up of prior findings | 300 |
| Reserve for unplanned work and investigations | 600 |
| Advisory work on the new deal desk controls | 400 |
| Planning, reporting and quality assurance | 600 |
| Total | 7,200 |
The plan concentrates on the five highest risks and does not audit lower-scoring areas this year; the audit committee was told which areas will not be covered, as the standards expect. Cybersecurity uses an outside firm under internal audit's direction because the team has only one IT auditor.
Scoping the Top Engagements
Each major engagement has a written objective approved by the chief audit executive. The client fund audit will test whether every customer's funds are received, held in segregated trust accounts, invested only as policy allows and disbursed on time, with daily reconciliations of the trust accounts to customer obligations reviewed by someone outside treasury. The tax filing audit will select 60 employers across 15 states and the Canadian provinces and trace filings and payments to agency confirmations, focusing on jurisdictions where rates changed during the year. The sales contracting audit will test the new deal desk controls, the commission plan's accelerators and a sample of contracts against signature metadata, building on the investigation's findings. The Canadian review will cover data migration controls, the source deduction remittance calendar and access to the Toronto systems.
Quality and Reporting
The standards require a quality assurance and improvement program, including ongoing monitoring, periodic self-assessment and an external assessment at least every five years. The function's last external assessment was in 2021, so one is scheduled for 2026, performed by a firm with no other relationship to the company. Each engagement ends with a written report rating findings as high, medium or low, with management's response and a due date; the committee receives a quarterly summary of open findings by age, and any high-rated finding open past its due date is discussed in executive session.
Independence and Objectivity
The chief audit executive meets the audit committee in executive session each quarter and the committee approves the plan, budget and the chief audit executive's appointment and pay. The administrative line to the CFO is limited to budget and logistics. The advisory work on deal desk controls creates a potential objectivity threat for the later audit of sales contracting, so different staff will perform the two engagements and the advisory role will stop at recommending controls, not designing or operating them.
Coordination With the External Auditor
Under AS 2605, the external auditor may use internal audit's work after assessing the function's competence and objectivity (Public Company Accounting Oversight Board, 2016). The external auditor plans to use about half of the SOX testing hours, mainly for lower-risk processes such as payroll for the company's own staff, procurement and fixed assets, and will reperform a sample. It will not use internal audit's work for significant risks, such as revenue recognition and client funds, where it must perform its own tests. Prawitt et al. (2009) found that higher-quality internal audit functions are associated with less earnings management, which supports investing in the function's quality as well as its size.
Areas Left Uncovered
Concentrating hours means some areas go unaudited in 2026. Procurement, facilities, the company's own payroll and travel expenses scored below 8 and will rely on management's monitoring and the SOX work that touches them. Product development scored 12 because of the pace of releases, but the external SOC 2 work covers change management on the platforms, so internal audit will not duplicate it. Human resources compliance scored 10 and is scheduled for 2027. If the reserve is not needed by the third quarter, the chief audit executive will propose using it for product development, giving the committee a choice rather than a fixed answer.
Conclusion
The 2026 plan puts most discretionary hours on custody of client funds, tax filing, sales contracting and the Canadian integration, reserves time for the unexpected and keeps SOX work efficient by coordinating with the external auditor. The committee will review progress quarterly and can redirect the reserve if new risks emerge.
References
Institute of Internal Auditors. (2024). Global internal audit standards. Author.
Prawitt, D. F., Smith, J. L., & Wood, D. A. (2009). Internal audit quality and earnings management. The Accounting Review, 84(4), 1255-1280. https://doi.org/10.2308/accr.2009.84.4.1255
Public Company Accounting Oversight Board. (2016). Consideration of the internal audit function (AS 2605). Author.
What the ACC 645 Module 8 instructions ask for
The Module Eight assignment in ACC 645 usually asks you to plan or evaluate an internal audit function: its independence and reporting lines, its risk assessment and annual plan, and its relationship with the external auditor. Plan to define the audit universe, assess risks using impact and likelihood, rank them and allocate available hours, while reserving time for required work such as SOX testing and for unplanned requests. Cite the IIA's Global Internal Audit Standards, which took effect in 2025, and, for coordination with external auditors, PCAOB AS 2605. Explain how the plan responds to recent events at the company, since a plan that ignores them looks generic, and state which areas will go unaudited this year.
How this ACC 645 Module 8 internal audit assignment example is built
The paper builds a plan for 7,200 available hours. Risks are scored on five-point impact and likelihood scales. The highest are custody of about $2.1 billion of client funds, payroll tax filing accuracy for 9,000 employers, data privacy and cybersecurity, sales contract integrity after the backdating case, and the Canadian integration. SOX testing for management's assessment takes 2,200 hours, of which the external auditor plans to use about half. The chief audit executive reports functionally to the audit committee. The paper reserves 600 hours for unplanned work and explains the competence and objectivity factors the external auditor will weigh, along with the quality program that supports them.
Where the ACC 645 Module 8 rubric puts the points
Rubrics for the internal audit assignment typically score the audit universe and risk assessment, the ranking method, allocation of resources, independence and reporting lines, coordination with the external auditor and use of the IIA and PCAOB standards. Top papers use a transparent scoring method, connect the highest risks to the company's business and recent events, reserve capacity for the unexpected and explain how the function's work can be relied on by the external auditor. Graders also reward recognizing limits on reliance for high-risk areas. Common deductions include listing every process as a high risk, ignoring available hours, omitting independence and assuming the external auditor will rely on internal audit for significant risks.
ACC 645 Module 8 help: the mistakes that cost points
Internal audit plans most often slip by covering everything thinly: a plan that gives each of 30 areas a few days provides little assurance anywhere. A second weak spot is coordination, where students overlook that the external auditor's use of internal audit's work depends on competence and objectivity and is limited for areas of high risk or judgment. If your assignment evaluates an existing function instead, the same elements, independence, risk basis and quality, structure the evaluation. Show the hours table before the narrative; it proves the plan fits the team's capacity. Then explain the two or three areas you chose not to cover, because the committee will ask.
Get ACC 645 Module 8 written to your instructions
Send the ACC 645 Module 8 assignment and the company facts. The paper will define the audit universe, score and rank risks, allocate resources to a plan, address independence and coordinate with the external auditor under the standards. Turnaround is two days, and the first is on us. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More ACC 645 papers and related MS Accounting samples
- ACC 645 Module 1 Discussion: When Investors Sue the Auditor
- ACC 645 Module 2 SOC Report Assignment: A SOC 1 Type 2 Report on the Payroll Platform
- ACC 645 Module 3 Milestone One: A Group Audit With a Canadian Component
- ACC 645 Module 4 Discussion: Do Nonaudit Fees Threaten Independence?
- ACC 645 Module 5 Benefit Plan Audit Assignment: Auditing the Company's 401(k) Plan
- ACC 645 Module 6 Milestone Two: A Whistleblower and Backdated Contracts
- ACC 645 Module 7 Discussion: Assurance on Emissions Data
- ACC 550 Module 7 Milestone Three: A Flexible Budget for the Shelling Season
- MBA 540 Module 3 Global Market Assessment Assignment
- ACC 620 Module 1 Discussion: Why Leases Moved Onto the Balance Sheet
- MBA 580 Module 7 Stage-Gate Process Presentation
ACC 645 Module 8 questions, answered
Where can I find a free ACC 645 Module 8 Internal Audit sample?
This page includes a full ACC 645 Module 8 risk-based internal audit plan with coordination with the external auditor.
What are the IIA's Global Internal Audit Standards?
The Institute of Internal Auditors' standards, effective in 2025, organized around domains of purpose, ethics, governance of the function, management of the function and performance of services.
How is a risk-based internal audit plan built?
By defining the audit universe, assessing risks by impact and likelihood, ranking them, considering assurance from other sources and allocating available resources to the highest risks, with time reserved for unplanned work.
Can an external auditor use internal audit's work?
Yes, under AS 2605, after evaluating the function's competence and objectivity; reliance is limited in areas of significant risk or judgment.
Why should internal audit report to the audit committee?
A functional reporting line to the audit committee supports the chief audit executive's independence from the management whose activities are audited.