This document discusses risk based internal auditing and sampling techniques. It begins with an agenda and definitions of risk, risk management, and the three lines of defense model. It then covers topics like risk identification, evaluation, scoring, developing a risk based internal audit plan, criteria for rating observations, and tools used for auditing. Sampling techniques discussed include random selection, systematic selection, monetary unit sampling, haphazard selection and block selection. Guidelines are provided for determining appropriate sample sizes based on the frequency of control activities.