StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 1: Information system auditing process

Risk-based audit planning: audit universe, risk assessment, annual plan and engagement scope

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

No audit function can review everything every year. Risk-based audit planning is how you decide where limited audit hours will do the most good. ISACA's standards require the IS auditor to use an appropriate risk assessment approach when planning, and the exam consistently rewards answers that start with understanding the business and its risks before choosing tests or tools.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan