
The Audit plan can be perfect and still fail the business
The last two weeks of July 2026 have been remarkable as I successfully delivered projects for two leading companies, one in Nigeria and another in Ethiopia. My career began in internal audit, working under Aguma Mpairwe, one of the most direct, ethical and disciplined professionals I know. He taught me two lessons that have stayed with me throughout my career: pay attention to detail, and focus on outcomes, not activity. That training early in my career, shaped how I approached a recent presentation to the Audit Committee of a prospective client in Ethiopia.

The panel included the Audit Committee Chair, the Chief Audit Executive and members of the internal audit team. I opened with one question: “Which audit has protected this business from its biggest threat?” Then I added the kicker: “An audit plan can be perfectly executed and strategically useless.”
The first impression had been made. More importantly, the discussion moved beyond routine audits, compliance checklists and the familiar language of value addition and consulting. I focused instead on internal audit’s strategic assurance mandate. Internal audit should not merely confirm that controls exist. It should help leaders understand whether the strategy is working, where execution is drifting and which risks could destroy value before management sees them. I won the project. But the bigger lesson was not about winning work, it was about positioning.
I am a governance expert, but my core focus is strategy and execution. Everything an organisation does must connect to its strategy. When that connection is missing, even well-executed activity becomes wasted effort. This is why I enjoy connecting the dots. Internal audit must evolve from being a reviewer of past transactions into an intelligence engine for the business. It must anticipate strategic threats, challenge management assumptions, identify weak signals and provide assurance while decisions can still be changed. The audit function of the next decade will not be judged by how many audits it completed, but by the failures it helped the organisation avoid, the decisions it improved and the value it protected.
A full audit plan may impress the committee, while a strategically relevant audit plan can save the business. The common practice holding internal audit back is the annual risk-based audit plan. I do not reject planning, but the illusion that an annual document can remain relevant while strategy, technology, regulation, customers and competitors keep moving. Too many audit functions confuse activity with value. They celebrate reports and closed actions while the organisation’s decisions pass without challenge.
I have seen teams audit petty cash while a major acquisition collapsed, auditors review leave records while a digital platform exposed customer data, and boards receive clean assurance over old processes while management invested millions in untested growth assumptions. To me, that is administrative comfort, not auditing. I believe internal audit creates raw value when it improves a decision before value is destroyed. The question is not, “Did we complete the plan?” but, “Did we help the organisation make better strategic choices, protect critical value and act earlier?”
My first counter-strategy is to audit strategy, not merely departments. What I am told to do is build an audit universe around functions: finance, procurement, human resources, operations and information technology. This is neat, familiar and dangerously incomplete. What I actually must do is map every proposed audit to a strategic objective, a material risk and an executive decision. I use a Strategy-to-Audit Alignment Map. If an engagement cannot show which objective it protects, which risk it tests and which decision it informs, I challenge its place on the plan. This discipline exposes vanity audits immediately. It also changes my conversation with management. I stop asking, “Which department should I audit?” but rather, “Where could the strategy fail, and what evidence would tell us early?”
My second counter-strategy is to replace calendar loyalty with risk responsiveness. What I am told to do is preserve the approved annual plan because changing it may suggest poor planning. That belief is absurd. Refusing to change an obsolete plan is not discipline, it is stubbornness dressed as governance. What I actually must do is run quarterly risk-sensing sessions with executives, operational leaders and the board. I track changes in customer behaviour, regulation, technology, liquidity, talent, suppliers and strategic projects. I define triggers that force reconsideration of the plan.
I learned this painfully during a transformation programme. My team continued testing routine controls while implementation delays, vendor dependence and weak adoption grew into the real threat. We were busy but late. Now I reserve audit capacity for emerging work. A plan without contingency is not controlled but trapped.
My third counter-strategy is to measure impact, not output. What I am told to do is report audits completed, findings raised, and actions closed. These measures are convenient because they are easy to count but also weak evidence of value. What I actually must do is measure decisions improved, losses prevented, revenue protected, control costs removed, risks reduced and management actions accelerated. I call this the Audit Impact Scorecard.
During a bank transformation, I sat with the CAE, and we recommended the removal of a complicated approval chain that management believed was a strong control. It delayed customer service, encouraged workarounds and added no real protection. The team redesigned the control around clear authority limits and automated evidence. Processing time fell, accountability improved, and risk reduced.
That was more valuable than another long report. The establishment will resist this approach as some audit committees prefer predictable plans, some executives dislike auditors entering strategic discussions, and some auditors feel safer testing transactions than challenging assumptions. The profession has trained good people to seek certainty in a world that rewards relevance.
I overcome that resistance with evidence. I show where strategy is exposed, where assurance is missing and where the current plan spends time. I do not ask for unlimited freedom. I ask for disciplined flexibility, clear triggers and transparent reporting.
The board must understand the choice. A busy audit plan can protect internal audit’s reputation while the business fails. A relevant plan may create tension, force difficult changes and expose uncertainty. That tension is not failure, it is evidence that internal audit is finally working where value is at risk.
I no longer want applause for completing the wrong work. I want internal audit present before the decision, alert during execution and honest when strategy begins to drift. The greater professional risk is not changing the plan but completing it perfectly while the organisation walks toward a failure I should have seen.
Copyright Institute of Forensics & ICT Security, 2026. All rights reserved.


