Risk-based internal audit planning in banking: A multi-period assignment model


YILMAZ E., AYYILDIZ E.

EDPACS, 2026 (Scopus) identifier

  • Yayın Türü: Makale / Tam Makale
  • Basım Tarihi: 2026
  • Doi Numarası: 10.1080/07366981.2026.2656368
  • Dergi Adı: EDPACS
  • Derginin Tarandığı İndeksler: Scopus, ABI/INFORM, Geobase
  • Karadeniz Teknik Üniversitesi Adresli: Evet

Özet

Risk-based internal audit planning has become increasingly important for banking institutions seeking to improve audit effectiveness and resource allocation. This study develops a deterministic mathematical model for risk-based internal auditor assignment in a large-scale banking network. The proposed framework models the assignment of 133 internal auditors with heterogeneous seniority and experience levels to 1,754 branches classified by risk level over a medium-term planning horizon of 20 periods. An efficiency function is incorporated into the objective function to evaluate each auditor-branch-period assignment. In addition to strengthening audit effectiveness and establishing a more systematic planning process, the model explicitly integrates fair workload distribution constraints alongside risk-based assignment requirements. Results from the real data application show that the baseline policy setting, where the minimum workload requirement is fixed at 5 periods, generates an efficient and balanced assignment schedule. Sensitivity analysis further indicates that RHS = 8 yields the highest objective value as an alternative scenario under the tested conditions. Overall, the findings suggest that combining risk prioritization with workload fairness can significantly improve the effectiveness, transparency, and consistency of internal audit planning in banking institutions.