Audit Universe and IT Risk Ranking
Learn how to build an IT audit universe and rank audit subjects by risk. Practical guidance for CISA exam candidates on prioritizing audit activities.
What Is the Audit Universe?
The audit universe is a comprehensive inventory of all areas, processes, systems, and entities that could be subject to audit within an organization. For IS auditing, it represents every IT-related area that the audit function could potentially examine. Building and maintaining an accurate audit universe is foundational to effective risk-based audit planning and a key concept for the CISA exam.
Building the IT Audit Universe
Constructing the audit universe requires a systematic approach:
Identify Auditable Entities
Auditable entities in an IT audit universe typically include:
- Applications: ERP systems, financial applications, customer-facing platforms, and custom-developed software.
- Infrastructure: Servers, network devices, databases, storage systems, and cloud environments.
- IT processes: Change management, incident management, problem management, capacity management, and IT service management.
- Security domains: Access management, vulnerability management, encryption, security monitoring, and physical security.
- Third parties: Outsourced IT services, cloud providers, managed security services, and software vendors.
- Projects: Major IT implementations, system migrations, and development initiatives.
- Compliance areas: Data privacy programs, regulatory reporting systems, and financial control frameworks.
Sources of Information
Auditors gather information from multiple sources to build the audit universe:
- IT asset inventories and configuration management databases
- Organization charts and business process documentation
- IT strategic plans and project portfolios
- Regulatory requirements and compliance obligations
- Prior audit reports and risk assessments
- Interviews with IT management and business stakeholders
IT Risk Ranking
Once the audit universe is defined, each entity must be ranked by risk to prioritize audit attention.
Risk Factors
Common risk factors used in IT risk ranking include:
- Business criticality: How essential is the system or process to core business operations?
- Data sensitivity: Does the entity process confidential, personal, or regulated data?
- Financial materiality: What is the financial exposure if the entity fails or is compromised?
- Regulatory exposure: Are there specific legal or compliance requirements?
- Complexity and change: Has the entity undergone significant changes recently?
- Control maturity: How mature and reliable are the existing controls?
- Incident history: Has the entity experienced recent incidents, breaches, or audit findings?
- Time since last audit: How long has it been since the area was last reviewed?
Scoring and Ranking
Each risk factor is typically scored on a scale (for example, 1 to 5), and scores are aggregated to produce an overall risk rating. Some organizations weight certain factors more heavily based on their risk appetite and industry context. The result is a prioritized list that directs audit resources to the highest-risk areas first.
Maintaining the Audit Universe
The audit universe is not static. It should be updated at least annually and whenever significant changes occur, such as new system implementations, organizational restructuring, regulatory changes, or major incidents. Regular updates ensure the audit plan remains aligned with the current risk landscape.
CISA Exam Tips
For the CISA exam, remember that the audit universe should be comprehensive but practical. The risk ranking methodology should be consistent, transparent, and documented. High-risk items should receive audit attention every year, while lower-risk items can be addressed on a rotational basis over a multi-year cycle.