Structure the audit universe before you plan a single audit.
Every defensible audit plan starts with a clear picture of what could be audited in the first place.

In brief. An audit universe is the complete population of auditable entities, processes and functions an internal audit function could examine — the basis on which a risk-based audit plan is built.
The business problem
Without a structured audit universe, audit scope tends to live in someone's head or an out-of-date spreadsheet. Entities get missed, ownership is unclear, and the annual plan is hard to defend because there's no complete picture of what exists to audit.
How the platform solves it
The Audit & Risk Platform models your organization as a structured hierarchy — organizations, departments, business units and auditable entities — so the full audit universe is explicit, current and shared across the team.
Capabilities
Organizations & business units
Represent your organizational structure, including departments and business units, as it actually operates.
Auditable entities
Define the specific entities, processes or units that fall within audit scope, each traceable back to the org structure.
Centralized ownership
Keep entity ownership and structure current in one place instead of a spreadsheet nobody updates.
Workflow
- 1Model the organization into departments and business units.
- 2Define auditable entities within that structure.
- 3Use the universe as the foundation for risk assessment and planning.
Business benefits
- A complete, current view of everything in audit scope
- No entity forgotten because it lived in someone's notes
- A defensible starting point for risk assessment and planning
Related capabilities
Audit Universe is where the audit lifecycle begins, leading into Risk Assessment. See the full platform overview or compare packages.
See the Audit & Risk Platform in action.
Watch the demo or talk to the team to see how the platform fits your audit function.
Prefer a live walkthrough? Book a demo