Enterprise Risk Management (ERM) Integration
Definition
The practice of aligning audit planning with the organisation's ERM risk register so that audit coverage tracks actual risk. When the risk register changes, the audit plan changes accordingly, keeping the programme risk-driven rather than compliance-driven.
- Aligns
- Audit plan with the organisation's risk register
- Effect
- Coverage tracks actual risk, not just compliance items
- Trigger for change
- Any update to the risk register
Common questions
How does ERM integration change the annual audit plan?+
Instead of a fixed rotation of areas, the plan is redrawn whenever the risk register shifts, so a newly elevated risk (a new market, a system migration, a fraud incident) can pull audit resources toward it ahead of schedule.
What is the risk of an audit programme that stays compliance-driven instead?+
It tends to keep testing the same checklist areas regardless of where the organisation's actual exposure has moved, leaving emerging risks unaudited until they surface as losses rather than being caught proactively.
Related terms
- Audit Programme Maturity
- The degree to which an organisation's audit activities are systematically planned, resourced, executed, measured, and improved. Maturity is usually described on a...
- CMMC (Cybersecurity Maturity Model Certification)
- A United States Department of Defense framework that certifies defence contractors at one of five tiers of cybersecurity capability. Each tier requires...
- Lessons-Learned Review
- A structured post-cycle review that identifies what worked, what failed, and what should change in the next audit cycle. The output is...
- Mean Time to Close (MTTC)
- The average elapsed time between the date a finding is formally reported and the date remediation is verified as complete. MTTC is...
- Repeat Finding Rate
- The percentage of findings in the current audit cycle that were also identified in the prior cycle. A high repeat finding rate...