17/08/2026
10 THINGS EVERY AUDITOR SHOULD DO BEFORE REUSING LAST AUDIT’S RISK ASSESSMENT
If you are an auditor, there is one thing I want you to stop doing.
Do not take last year’s risk assessment, change the date and call it a new risk assessment.
I understand why it happens. You are under pressure. The previous risk assessment is already there. It looks good. The risks are already documented.
But here is the problem.
The business did not stop changing just because you completed last year’s audit.
So before you reuse that risk assessment, here are 10 things you should do.
1. Ask what has changed in the business.
Start with the bas
Has the organisation changed its structure, strategy, operations or business model?
A change in the business can create a completely different risk profile.
2. Check whether there are new systems or technology.
Maybe the organisation introduced a new accounting system, payroll system, payment platform or enterprise resource planning system.
Do not assume the controls around the new system are the same as the old one.
New systems can introduce new risks.
3. Check for changes in key personnel.
Did the head of the department leave?
Was a new manager appointed?
Did someone take over a sensitive role?
Changes in people can affect segregation of duties, approvals, knowledge transfer and accountability.
4. Review changes in vendors and third parties.
A new vendor may mean a new risk.
Ask yourself:
Who are the new vendors?
What services do they provide?
How were they selected?
Are there new third-party dependencies?
Sometimes the risk is not inside the organisation. It sits with the person or company the organisation depends on.
5. Look at changes in transaction volume.
A process handling 500 transactions last year may now be handling 5,000.
The control may have worked perfectly before but may no longer be strong enough for the current volume.
Risk can increase simply because the business has grown.
6. Check for regulatory or policy changes.
Have new laws, regulations, industry requirements or internal policies been introduced?
An area that was low risk last year could become high risk because the requirements have changed.
7. Review previous audit findings.
This one is very important.
Do not just look at the risk assessment.
Look at what you reported last time.
Which findings were resolved?
Which ones are still open?
Which recommendations were only partially implemented?
An unresolved high risk from last year should not magically disappear from this year's risk assessment.
8. Review incidents and unusual events.
Ask what went wrong during the period.
Were there fraud cases?
Customer complaints?
System failures?
Operational losses?
Stock shortages?
Payment issues?
Control breaches?
These events can tell you where the current risks are.
Sometimes the business itself has already shown you where the risk is.
9. Challenge the old risk ratings.
Do not automatically carry forward the same rating.
A risk rated low last year may now be high.
A high risk may have reduced because management implemented stronger controls.
Your job is not to protect last year's assessment.
Your job is to determine the current level of risk.
10. Speak to the people doing the work.
This is one of the most useful things you can do.
Talk to process owners.
Ask them:
“What has changed in this process since our last review?”
You may discover risks that are not visible in the previous risk assessment.
People working in the process every day often know where the real problems are.
And finally, remember this:
Your previous risk assessment is a useful reference, but it is not your answer.
Use it as your starting point.
Then update it based on what is happening today.
Because as an auditor, you are not auditing yesterday's business.
You are auditing the business as it exists now.
So before you change the date on last year's risk assessment, ask yourself:
“What has changed?”
That single question can completely change the quality of your audit planning.