Agents produce a work plan that lists audit topics without a structured audit universe with risk ratings and cycle frequencies, fail to reconcile available hours against the co-sourcing cap, omit engagement-specific rationales for each planned area, and miss supervisory guidance thresholds that justify concentration-area audit priorities.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-internal-audit-work-plan --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Internal Audit Work Plan?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-internal-audit-work-plan)More formats (shields.io, HTML) on the badges page.
---
name: draft-internal-audit-work-plan
task_id: corporate-governance/draft-internal-audit-work-plan
description: Agents produce a work plan that lists audit topics without a structured audit universe with risk ratings and cycle frequencies, fail to reconcile available hours against the co-sourcing cap, omit engagement-specific rationales for each planned area, and miss supervisory guidance thresholds that justify concentration-area audit priorities.
activates_for: [planner, solver, checker]
---
# Skill: Risk-Based Internal Audit Work Plan for a Bank Holding Company
## 1. Subject-matter triage
- Treat the task as a planning-and-prioritization exercise, not a narrative memo.
- Start by identifying the audit perimeter: consolidated holding company, bank subsidiary, and any in-scope support functions or outsourced activities.
- If the source set contains multiple candidate audit universes, enumerate them first and then build the plan once per auditable area; do not merge distinct lines of business, entities, or regulatory themes into one generic bucket.
## 2. Failure modes the skill is correcting
- Drafts often list audit topics without a risk-ranked audit universe, which weakens the basis for board or audit committee approval.
- Drafts often omit a cycle-frequency view, so the plan does not show when high-risk areas were last reviewed or when the next review is due.
- Drafts often fail to tie each planned engagement to a concrete driver such as a prior issue, metric outlier, new product, vendor change, regulatory expectation, or strategic initiative.
- Drafts often ignore the staffing math: internal hours, management overhead, training, leave, and co-sourced capacity must be reconciled to the plan.
- Drafts often omit explicit coverage for concentration areas, consumer compliance themes, third-party oversight, or reporting-control coordination when those topics appear in the source documents.
- Drafts often present activities without making clear whether each engagement is at the holding-company level, bank level, or both.
- Drafts often state conclusions about coverage or resourcing without citing the governing policy, supervisory guidance, or source-document authority supporting the conclusion.
- Drafts often omit an action-oriented close, leaving no clear next-step ownership for the audit committee, management, or internal audit leadership.
## 3. Legal frameworks / domain conventions that apply
- **Risk-based internal audit:** The work plan should reflect a documented risk assessment, with higher-risk areas receiving more frequent coverage and stronger rationale than lower-risk areas.
- **Audit universe discipline:** A defensible plan begins with a complete inventory of auditable entities, processes, and governance areas, each labeled with risk level, cycle frequency, and last-audit timing.
- **Supervisory concentration guidance:** Real estate and other concentration-heavy exposures should be evaluated against the applicable supervisory framework cited in the source set or standard banking guidance, and the plan should explain why the area is prioritized.
- **BSA/AML and sanctions:** Compliance reviews should be anchored in the specific control weakness, monitoring issue, filing timeliness concern, or training gap that justified inclusion.
- **Consumer compliance and mortgage servicing:** If the source documents reference mortgage servicing, fair lending, CRA, deposit, lending, or complaints, the plan should map testing to the implicated regulatory regime and the operational driver.
- **Third-party risk management:** New, critical, or changed vendors should receive planned coverage aligned to the supervisory expectation for oversight, due diligence, contract management, and ongoing monitoring.
- **Capital, liquidity, and financial reporting controls:** If the company is subject to reporting-control or external-audit reliance considerations, the plan should identify which work supports those needs and when it must be completed.
- **Holding company governance:** Work should distinguish between board-level governance, holding-company control functions, and subsidiary operational testing where the source documents require that separation.
## 4. Analytical scaffolds
- **Audit universe table:** For each auditable area, capture entity/scope, risk rating, planned cycle frequency, last audit date, and the reason it is in scope now.
- **Engagement justification row:** For each planned engagement, state the risk driver, the testing objective, and the coverage level required to address the driver.
- **Resourcing model:** Reconcile total planned audit hours to available internal capacity after normal deductions, then allocate any co-sourced support by engagement and confirm the allocation stays within the stated cap or agreement limit.
- **Coverage mapping:** Make sure every high-risk or recurring supervisory theme has a scheduled response, either as a standalone audit, thematic review, follow-up testing, or coordinated coverage through another engagement.
- **Remediation linkage:** If the source documents identify prior findings, write the current engagement so it tests whether remediation changed the underlying control, not just whether a document was updated.
- **Timing logic:** Place time-sensitive work early enough to support board reporting, management action plans, or external-auditor reliance where applicable.
- **Assumption control:** State staffing, turnover, expertise, and source-document assumptions that could alter the plan, and flag any dependency that would require reprioritization.
- **Authority support:** When the plan relies on a particular supervisory or policy rationale, cite the controlling source by name and section, part, or guidance title as provided in the documents or standard practice.
## 5. Vertical / structural / temporal relationships
- **Holding company vs. bank subsidiary:** Specify whether each engagement covers the parent, the insured bank, shared services, or a combined population.
- **Enterprise vs. line-level scope:** Separate governance-level coverage from transaction-level testing so the reader can see where oversight ends and operations begin.
- **Current year vs. prior year:** Show what is new this cycle, what is follow-up testing, and what repeats on a recurring cadence.
- **Quarterly sequencing:** If timing matters for board reporting, remediation follow-up, or external reliance, anchor the work to the relevant quarter or milestone rather than using vague “during the year” language.
- **Coverage gap logic:** If a high-risk area is deferred, explain what alternative coverage exists and why the deferral remains acceptable under the stated risk framework.
## 6. Output structure conventions
- Use a clean planning format with an executive overview, an audit universe inventory, a scheduled engagement plan, resourcing detail, coordination items, and assumptions/risks.
- Present the audit universe in table form with risk ratings and cycle frequencies.
- Present each planned engagement in a way that shows scope, risk driver, timing, hours, and internal/co-sourced split.
- Include a resource summary that reconciles aggregate planned hours to available hours and any co-sourcing constraint.
- Include a short coordination section for any work that depends on management remediation, external-auditor reliance, or board/audit committee timing.
- End with explicit next steps or recommended actions tied to the relevant internal audit leader, officer, or management owner and a timing anchor.
- Keep the plan self-contained, operational, and ready to be saved as the requested `.docx` deliverable.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!