Risk Based Auditing – Establishing a Methodology

The Institute of Internal Auditors defines risk based internal auditing (RBIA) as a methodology that links internal auditing to an organization's overall risk management framework. RBIA allows internal audit to provide assurance to the board that risk management processes are managing risks effectively, in relation to the risk appetite.

RBIA is at the cutting edge of internal audit practice. It is an area that is evolving rapidly and where there is still little consensus about the best way to implement it.  Executing on true risk based internal auditing requires more than an annual risk assessment for the internal audit plan.  It requires a pre-established methodology that includes defining the organization's risk appetite and risk tolerance utilizing measurements that include aspects of financial, compliance and operational metrics.  In addition, internal audit must be ready to put aside their typical checklists and standard work programs.  True risk based internal auditing goes far beyond setting the annual audit plan.  It incorporates cascading the process through to each individual audit as well as the audit reporting process.

This course is the second of three risk based auditing courses.  This course focuses on the establishment of a framework or methodology for risk based auditing and examining how to utilize risk based questions within the process steps.  

Course Series

This course is included in the following series:

3 CoursesRisk Based Auditing

  1. Understanding Risk-Based Auditing
  2. Risk Based Auditing – Establishing a Methodology
  3. Risk Based Auditing – Applying the Methodology
Learning Objectives
  • Identify some of the various challenges internal audit may face when attempting to execute upon risk based auditing.
  • Explore alternatives to identifying risk appetite and risk tolerance to utilize within risk based auditing.
  • Evaluate the development and usage of a variety of risk management characteristics when identifying risk tolerance.
  • Explore sample scoring techniques to apply to risk based auditing.
  • Learn how to conclude your assessment for risk based auditing.
Last updated/reviewed: March 27, 2024

Included In Certifications

This course is included in the following Certification Programs:

32 CoursesInternal Controls and Internal Audit Certification

  1. Internal Audit Standards Overview
  2. Managing the Internal Audit Function in Line with GIAS - Part 1
  3. Managing the Internal Audit Function in Line with GIAS – Part 2
  4. Managing the Internal Audit Function in Line with GIAS – Part 3
  5. Executing the Internal Audit Engagement in Line with GIAS – Part 1
  6. Executing the Internal Audit Engagement in Line with GIAS – Part 2
  7. Identifying and Implementing the Proper Balance of Internal Controls
  8. Documentation Methods For Internal Control Processes
  9. Segregation of Duties for Core Business Processes
  10. Foundations for a Strong Internal Audit Department
  11. Internal Audit Management - Top Skills
  12. Internal Audit: Keys to Managing an Effective Function
  13. Understanding Risk-Based Auditing
  14. Risk Based Auditing – Establishing a Methodology
  15. Risk Based Auditing – Applying the Methodology
  16. Cyber Risk Frameworks And Concepts
  17. Information Technology (IT) Controls in Emerging Business Environments
  18. Fraud Risk Assessments
  19. Professional Skepticism - Keys to Maintaining
  20. Introduction to Forensic Accounting
  21. The Fraud Triangle
  22. Internal Audit Effective Relations with the Audit Committee
  23. COSO 2013 Overview
  24. COSO 2013 - Operational Execution
  25. Internal Audit Emerging Risks for 2021 and Beyond - Part 1
  26. Internal Audit Emerging Risks for 2021 and Beyond - Part 2
  27. Internal Audit Emerging Risks for 2021 and Beyond - Part 3
  28. Internal Audit Emerging Risks for 2021 and Beyond - Part 4
  29. Internal Audit Challenges During Times of COVID
  30. Global Internal Audit Standards (GIAS) - Overview and Contrast to 2017 International Professional Practices Framework
  31. Tools for Internal Control Certificate
  32. Lessons of an Auditor- Tools for Internal Control Certificate
92 Reviews (403 ratings)

Reviews

5
Member's Profile
Lynn, The RBA doen internally certainly has its challenges and you have discussed them here in great detail. The human element underlies the success or lack thereof in the process. This course was a little more difficult then the previous RBA courses in the series and I only got an 80%. Still an amazingly informative course. As always, your courses are the best on Illumeo :) Larry

5
Anonymous Author
The course material was well-presented. The emphasis on the need for management's buy-in conveys the presenter's real-world knowledge: if the organization doesn't measure risk or understand the importance of thresholds, it is difficult to measure/classify the impact of control failures. Great course for thos interested in learning about RBA.

5
Member's Profile
This course details the Risk Based Auditing process in a simple and easy way to remember. The presenter provides relevant examples from real world situations which an Internal Auditor would have faced in his or her organisation. This course is a must for IA department that plans to start RBIA exercise in their organisation.

5
Member's Profile
This is my second course in Risk-Based Auditing with Lynn Fountain and I'm really enjoying this type of auditing. I'm not very excited about traditional auditing as a profession but would consider risk-based auditing because it attacks potential problem areas within an organization.

5
Member's Profile
GREAT CLASS - A LOT OF VALUE IN UNDERSTANDING VALUE OF ADOPTION

5
Member's Profile
This was a great training! I really liked the way Lynn frames risk impact versus risk likelihood. And the way she discusses risk appetite versus risk tolerance. Wonderful walkthrough of methodology and communicating with leadership. Highly recommend.

5
Anonymous Author
Thank you very much for another great course. A lot of real life examples make this course very valuable. The course would be useful for IA's but, as Lynn mentioned, a full day training with discussions is a must.

5
Anonymous Author
Overall, the course does a good job of breaking the material down into something someone unfamiliar with RBIA could understand and gives perspective of how others may struggle with the concept outside of IA.

5
Anonymous Author
Valuable course for educating auditors and management about the value of RBIA that provides a step by step methodology which can be utilized as a starting place for organizations to begin to establish RBIA.

5
Anonymous Author
The course provides an overview and comprehensive knowledge of risk based auditing methodology for internal audit department. The instructor also gives a lot of practical examples that applied to real world

4
Anonymous Author
This course does a good job at diving into the importance of Risk Based Internal Auditing. It explains the keys to implementing this within your own department. Presentation was neat and easy to follow.

5
Anonymous Author
Very informative, refresher course on the importance of a Risk Based Audit Methodology, its challenges and opportunities for the IA Department. The instructor is clear and the course is easy to follow.

5
Anonymous Author
This course is a great introduction to risk-based auditing methodology. Each of the methodology steps were clearly explained which made it easy to apply to my own organization.

4
Anonymous Author
This is a great course. The examples provided are helpful and the speaker is very knowledgeable. The time spent in the course is sufficient and the topics are well organized.

5
Member's Profile
This is a great course. The tools and concepts discussed in this course will definitely help in establishing a methodology tailor fit to any organization interested in RBA.

5
Member's Profile
Good overview of methodology for employing risked based internal auditing. i look forward to the final section of the 3 part series to learn how to apply the methodologies.

4
Anonymous Author
This course provides a good understanding of what Risk Based Auditing is and how to establish the correct understanding, focus, and steps in performing risk based audits.

4
Anonymous Author
The instructor clearly explains risk based auditing and makes easy to understand all steps of RBIA methodology. Unfortunately slides have several grammatical errors

5
Anonymous Author
This course was impactful and helpful to my understanding of risk based internal audit assessment. The instructor was effective in presenting the course materials.

5
Anonymous Author
Emphasis on the appropriate level of buy in and what considerations go into determining if buy in exists at the appropriate level was most helpful in this course.

5
Anonymous Author
Great course on risk based auditing!! I gained a lot of value from learning more about charting risks on a risk matrix to support the basis for audit testing.

5
Anonymous Author
This course was helpful and covered a wide variety of information, while also digging into the practical guidance and steps for implementation.

5
Member's Profile
The risk based auditing course to establish a methodology provides a helpful overview with clear and actionable approaches for the audit team.

5
Member's Profile
Instructor provided valuable information that would not be normally considered. Every internal auditor should enroll in this course.

5
Anonymous Author
Good course. Easy to follow. Would recommend for organizations who are trying to define risk tolerance, risk appetite, and RBA.

4
Member's Profile
It is a interesting training specially for beginners or the ones who need some refresh about IA Risk Based approach.

4
Member's Profile
The training is refreshing. I think everyone will learn from this irrespective of experience. Nothing surprised me.

5
Member's Profile
Lynn's presentations are always very easy to follow, well presented and provide excellent information and guidance.

5
Anonymous Author
The content shared was very straight forward. The exam questions were a little tricky but it was great practice.

5
Member's Profile
Good coverage on risk based internal auditing and the preparedness towards that....Well covered in the course!!!

4
Anonymous Author
This course covers addressing risk based auditing approach for an internal audit team within an organization.

5
Anonymous Author
Relevant and informative. The presenter was clear and concise and provided additional context to the material

5
Anonymous Author
Instructor provides clear and comprehensive steps for implementing risk based auditing in an organization.

5
Anonymous Author
Good concept for Audit departments and Management to consider as the internal controls continue to mature.

5
Anonymous Author
Excellent review on establishing Risk Based Internal auditing. Very thorough and relevant. Great examples.

5
Member's Profile
I like how the flow of ho each topics were presented in stages so that I could get a solid understanding.

5
Anonymous Author
Very good presentation on benefits and challenges IA faces when trying to implement risk based auditing.

4
Member's Profile
Interesting course. Concepts are clearly laid out. Good to do it after completing the course 1 on RBIA.

3
Anonymous Author
I liked the breakdown of all of the methodology steps. I believe they are explained well and in-depth.

5
Anonymous Author
I think the instructor did a great job at explaining the course information and giving great examples.

5
Anonymous Author
Enjoyed the clear explanation of RBA. Straightforward and easily explainable to exec team peers.

4
Anonymous Author
Very informative discussions on Risk Based Audit, and how the organization will benefit from such.

5
Member's Profile
Overall a good course on the methodology. Enforces the risk based auditing concepts and practices.

5
Member's Profile
This was very informative and I will recommend this to my colleague and friends of similar field.

5
Member's Profile
Program materials were relevant and contributed to the achievement of the learning objectives.

5
Anonymous Author
I really liked this course. It was put together well and I appreciate the numbering. Thank you

5
Anonymous Author
This course, establishing a RBIA methodology was full of useful information for my IA team.

5
Anonymous Author
Clear and concise - great examples provided. A great course for any experienced auditor.

5
Member's Profile
Excellent and informative course! My understanding of risked based auditing has improved.

5
Member's Profile
It proposes a very well structure about how to establish a Risk Based Audit methodology.

5
Member's Profile
interesting subject, well distributed , good instructor, waitng to see the next topic

4
Anonymous Author
Great course of risk based auditing - establishing a methodology that add value for me.

5
Member's Profile
Good outline and guidance toward developing RBIA methodology for your organization.

5
Member's Profile
Good application of risk management principles to the whole internal audit process.

5
Anonymous Author
Very useful and meaningful course. Highly recommended to be taken by professionals.

4
Member's Profile
instructor is very monotone and hard to listen to for a prolonged period of time

5
Anonymous Author
Very good. Good steps. Would recommend you need CPE for CIA. Nice Refresher.

5
Member's Profile
Risk based auditing establishing a methodology is an excellent course.

5
Member's Profile
Excellent job! Love, Love, Loved this course. So relevant, spot on!

4
Anonymous Author
Well done on a good course. Have a nice day. The instructor is good.

5
Member's Profile
Simple and straight to the point. Really well executed and useful.

5
Anonymous Author
Good course, provides a full understanding of Risk Based Auditing.

5
Member's Profile
This course reflects what I see in my organization. Good summary.

4
Member's Profile
Enables a good understanding of a risk based audit methodology

4
Member's Profile
great class, very informative and easy to follow along with.

3
Anonymous Author
good for me and served my needs as a continuing cpa and cia

4
Member's Profile
A great refresher and review for internal audit executives.

5
Anonymous Author
Great topic put in understandable and easy to follow way.

4
Anonymous Author
Steps involved in developing a RBIA and the challenges

5
Member's Profile
Informative. Focused contents on RBIA methodology.

5
Anonymous Author
Good explanation of the risk-based methodology.

5
Anonymous Author
helpful and straight forward - easy to follow

4
Member's Profile
New way of thinking of this topic for me

4
Member's Profile
Good explanation of risk based auditing

5
Member's Profile
Easy to understand, and very practical.

5
Member's Profile
I enjoy all of this instructors classes

4
Anonymous Author
Good pace and emphasis on key aspects.

5
Member's Profile
Nice course, gives a good perspective.

4
Member's Profile
good content and easy to understand

5
Member's Profile
I loved exam questions the most!

4
Member's Profile
Great, new information for me

5
Anonymous Author
Good, informative course.

4
Anonymous Author
It was a very good course

5
Member's Profile
Very helpful fr CAE's

4
Member's Profile
informative content.

4
Anonymous Author
Good review on RBIA

5
Anonymous Author
Clear and concise

5
Member's Profile
great course

4
Member's Profile
Great course!

5
Member's Profile
Great course

4
Member's Profile
none

4
Anonymous Author
.

Prerequisites
Course Complexity: Intermediate

No Advanced Preparation or Prerequisites are needed for this course. However, it is recommended to take the other courses in the series prior to completing this one.

Education Provider Information
Company: Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA 95113
Contact: For more information regarding this course, including complaint and cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to .
Instructor for this course
Course Syllabus
INTRODUCTION AND OVERVIEW
  Institute of Internal Auditors Update 20243:22
  Introduction to Risk Based Auditing Establishing The Methodology8:53
Establishing a Methodology
  Methodology Steps 1 and 29:56
  Methodology Step 38:10
  Ex: Risk Tolerance 10:50
  Methodology Steps 4 - 610:39
  Methodology Steps 7 - 107:08
  Applying RB Questions within Methodology10:40
  Questions Steps 3 and 411:35
  Utilizing Management in Developing RBIA Approach 9:39
CONCLUSION
  Using Experts and Course Summary7:29
Continuous Play
  Risk Based Auditing: Establishing The Methodology1:35:00
SUPPORTING MATERIALS
  Slides: Risk Based Auditing – Establishing a MethodologyPDF
  Risk Based Auditing – Establishing a Methodology Glossary/ IndexPDF
REVIEW and TEST
  REVIEW QUESTIONSquiz
 FINAL EXAMexam