# Draft Internal Audit Work Plan

> Agents produce a work plan that lists audit topics without a structured audit universe with risk ratings and cycle frequencies, fail to reconcile available hours against the co-sourcing cap, omit engagement-specific rationales for each planned area, and miss supervisory guidance thresholds that justify concentration-area audit priorities.

- Skill: `finchipaiorg/draft-internal-audit-work-plan` (Agent Skill)
- Install (CLI): `npx skillmds@latest add finchipaiorg/draft-internal-audit-work-plan`
- Raw SKILL.md: https://api.skillmd.com/api/skills/finchipaiorg/draft-internal-audit-work-plan/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: FinchipAIOrg (https://skillmd.com/u/finchipaiorg)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/finchipaiorg/draft-internal-audit-work-plan

---


# Skill: Risk-Based Internal Audit Work Plan for a Bank Holding Company

## 1. Subject-matter triage
- Treat the task as a planning-and-prioritization exercise, not a narrative memo.
- Start by identifying the audit perimeter: consolidated holding company, bank subsidiary, and any in-scope support functions or outsourced activities.
- If the source set contains multiple candidate audit universes, enumerate them first and then build the plan once per auditable area; do not merge distinct lines of business, entities, or regulatory themes into one generic bucket.

## 2. Failure modes the skill is correcting
- Drafts often list audit topics without a risk-ranked audit universe, which weakens the basis for board or audit committee approval.
- Drafts often omit a cycle-frequency view, so the plan does not show when high-risk areas were last reviewed or when the next review is due.
- Drafts often fail to tie each planned engagement to a concrete driver such as a prior issue, metric outlier, new product, vendor change, regulatory expectation, or strategic initiative.
- Drafts often ignore the staffing math: internal hours, management overhead, training, leave, and co-sourced capacity must be reconciled to the plan.
- Drafts often omit explicit coverage for concentration areas, consumer compliance themes, third-party oversight, or reporting-control coordination when those topics appear in the source documents.
- Drafts often present activities without making clear whether each engagement is at the holding-company level, bank level, or both.
- Drafts often state conclusions about coverage or resourcing without citing the governing policy, supervisory guidance, or source-document authority supporting the conclusion.
- Drafts often omit an action-oriented close, leaving no clear next-step ownership for the audit committee, management, or internal audit leadership.

## 3. Legal frameworks / domain conventions that apply
- **Risk-based internal audit:** The work plan should reflect a documented risk assessment, with higher-risk areas receiving more frequent coverage and stronger rationale than lower-risk areas.
- **Audit universe discipline:** A defensible plan begins with a complete inventory of auditable entities, processes, and governance areas, each labeled with risk level, cycle frequency, and last-audit timing.
- **Supervisory concentration guidance:** Real estate and other concentration-heavy exposures should be evaluated against the applicable supervisory framework cited in the source set or standard banking guidance, and the plan should explain why the area is prioritized.
- **BSA/AML and sanctions:** Compliance reviews should be anchored in the specific control weakness, monitoring issue, filing timeliness concern, or training gap that justified inclusion.
- **Consumer compliance and mortgage servicing:** If the source documents reference mortgage servicing, fair lending, CRA, deposit, lending, or complaints, the plan should map testing to the implicated regulatory regime and the operational driver.
- **Third-party risk management:** New, critical, or changed vendors should receive planned coverage aligned to the supervisory expectation for oversight, due diligence, contract management, and ongoing monitoring.
- **Capital, liquidity, and financial reporting controls:** If the company is subject to reporting-control or external-audit reliance considerations, the plan should identify which work supports those needs and when it must be completed.
- **Holding company governance:** Work should distinguish between board-level governance, holding-company control functions, and subsidiary operational testing where the source documents require that separation.

## 4. Analytical scaffolds
- **Audit universe table:** For each auditable area, capture entity/scope, risk rating, planned cycle frequency, last audit date, and the reason it is in scope now.
- **Engagement justification row:** For each planned engagement, state the risk driver, the testing objective, and the coverage level required to address the driver.
- **Resourcing model:** Reconcile total planned audit hours to available internal capacity after normal deductions, then allocate any co-sourced support by engagement and confirm the allocation stays within the stated cap or agreement limit.
- **Coverage mapping:** Make sure every high-risk or recurring supervisory theme has a scheduled response, either as a standalone audit, thematic review, follow-up testing, or coordinated coverage through another engagement.
- **Remediation linkage:** If the source documents identify prior findings, write the current engagement so it tests whether remediation changed the underlying control, not just whether a document was updated.
- **Timing logic:** Place time-sensitive work early enough to support board reporting, management action plans, or external-auditor reliance where applicable.
- **Assumption control:** State staffing, turnover, expertise, and source-document assumptions that could alter the plan, and flag any dependency that would require reprioritization.
- **Authority support:** When the plan relies on a particular supervisory or policy rationale, cite the controlling source by name and section, part, or guidance title as provided in the documents or standard practice.

## 5. Vertical / structural / temporal relationships
- **Holding company vs. bank subsidiary:** Specify whether each engagement covers the parent, the insured bank, shared services, or a combined population.
- **Enterprise vs. line-level scope:** Separate governance-level coverage from transaction-level testing so the reader can see where oversight ends and operations begin.
- **Current year vs. prior year:** Show what is new this cycle, what is follow-up testing, and what repeats on a recurring cadence.
- **Quarterly sequencing:** If timing matters for board reporting, remediation follow-up, or external reliance, anchor the work to the relevant quarter or milestone rather than using vague “during the year” language.
- **Coverage gap logic:** If a high-risk area is deferred, explain what alternative coverage exists and why the deferral remains acceptable under the stated risk framework.

## 6. Output structure conventions
- Use a clean planning format with an executive overview, an audit universe inventory, a scheduled engagement plan, resourcing detail, coordination items, and assumptions/risks.
- Present the audit universe in table form with risk ratings and cycle frequencies.
- Present each planned engagement in a way that shows scope, risk driver, timing, hours, and internal/co-sourced split.
- Include a resource summary that reconciles aggregate planned hours to available hours and any co-sourcing constraint.
- Include a short coordination section for any work that depends on management remediation, external-auditor reliance, or board/audit committee timing.
- End with explicit next steps or recommended actions tied to the relevant internal audit leader, officer, or management owner and a timing anchor.
- Keep the plan self-contained, operational, and ready to be saved as the requested `.docx` deliverable.

