10-audit Cycle
The 10-audit Cycle is a risk-based methodology for determining audit frequency, aligning audit efforts with the level of risk associated with business processes and controls.
What is 10-audit Cycle?
The 10-audit Cycle, also known as the continuous audit cycle or the audit frequency model, is a risk-based methodology for determining how often specific business processes or controls should be audited. It moves away from traditional, periodic audit schedules towards a more dynamic approach that aligns audit resources with the level of risk associated with an entity’s operations. This framework acknowledges that not all risks are static and that audit effort should be concentrated where it is most needed.
Implementing a 10-audit Cycle requires a thorough understanding of an organization’s risk landscape. This involves identifying key business processes, assessing the inherent and residual risks associated with each, and then assigning an appropriate audit frequency. The

