Module 15 · Intermediate · ⏱ 55 min · 🏆 +275 XP

IT Audit Execution: Planning & Scoping

Every great audit starts with a great plan. Risk-based audit planning is both art and science — knowing which systems deserve the most scrutiny, how to define the right scope, and how to design tests that actually reveal the truth.

Risk-Based PlanningAudit Programs Sampling MethodsIPPF Standards ScopingAudit Universe

Learning Objectives

  • Build a risk-based audit plan using the audit universe and risk assessment.
  • Define audit scope, objectives, and approach for a specific IT system.
  • Design an audit program with specific test procedures for key controls.
  • Apply statistical and judgmental sampling methods appropriately.
  • Explain the IIA IPPF Standard 2010 (Planning) requirements.
  • Scope an audit when time and resources are constrained.

Lecture

1 · The Audit Universe

The audit universe is the complete inventory of all auditable entities — systems, processes, departments, controls — that the internal audit function could potentially audit. A mature internal audit function maintains and updates its audit universe annually, using it as the starting point for risk-based audit plan development.

2 · Risk-Based Audit Planning

Not everything in the audit universe gets audited every year. Risk-based planning selects which areas to audit based on: inherent risk level, time since last audit, recent changes (new system, new vendor, new regulation), management concerns, and regulator expectations. High-risk areas with no recent audit get priority. Low-risk stable areas may go 2–3 years between audits.

3 · Audit Scope and Objectives

Scope defines what is in and what is out of the audit. Scope creep — gradually expanding the audit beyond its defined boundaries — is one of the most common audit execution failures. A well-defined scope includes: system/process name, time period, locations, and specific controls or assertions to be tested. Objectives state what the audit will conclude about.

4 · The Audit Program

An audit program is the detailed playbook for executing the audit. For each control to be tested, the program specifies: the control objective, the specific test procedure, evidence to be gathered, population size, sample methodology, and the test of design vs operating effectiveness.

Planning principle: 80% of audit quality is determined before fieldwork starts. A weak plan produces weak findings regardless of how hard the auditor works during execution.

Theory Deep Dive — Audit Planning Science

📋 IIA Standard 2010 — Planning Requirements

IIA Standard 2010 (Engagement Planning) requires the Chief Audit Executive to establish risk-based plans to determine the priorities of the internal audit activity. Key requirements:

Risk-Based Prioritization

Audit plans must be based on a documented risk assessment. Plans driven by management request or historical rotation (without risk justification) do not meet IIA standards.

Consideration of Management Goals

Plans must consider management's goals, strategic initiatives, and concerns. Audit that ignores business context is less valuable and less likely to receive cooperation.

Annual Plan Approval

The annual audit plan must be reviewed and approved by the audit committee. This ensures appropriate governance oversight of internal audit activity.

Plan Flexibility

Plans should be responsive to significant risk changes during the year. Emerging risks (new breach type, regulatory change, acquisition) may require unplanned audits. A rigid plan cannot adapt.

🎯 Audit Sampling Methods — Statistical vs Judgmental

When a population is too large to test 100%, auditors use sampling. Choosing the right sampling method is critical to drawing valid conclusions:

MethodBasisConclusionBest For
Random SamplingEvery item has equal probability of selectionStatistically defensible conclusion about the whole populationLarge homogeneous populations (all access provisioning tickets)
Stratified SamplingPopulation divided into groups (strata); samples from eachProportional conclusions about different segmentsPopulations with distinct risk groups (admin accounts vs regular users)
Systematic SamplingEvery nth item selected (e.g., every 10th)Statistically valid if no pattern in the nth intervalOrdered populations (transaction logs, change tickets)
Judgmental SamplingAuditor selects items based on knowledge and riskNot statistically generalizable — conclusions limited to tested itemsTargeted testing of high-risk specific items
Attribute SamplingTests whether an attribute is present/absent in a binary wayEstimated deviation rate for the population within confidence boundsTesting whether controls were applied consistently

For compliance auditing (SOX, PCI-DSS), statistical sampling with documented confidence levels and error rates provides the most defensible conclusions. For risk-focused internal auditing, judgmental sampling can efficiently target the highest-risk items.

📊 Scoping Under Resource Constraints

Real audits rarely have unlimited time. Scoping under constraints requires professional judgment:

1
Risk-Tiered Scoping

Identify the top-risk controls within the area. Scope the audit to fully test those. Use inquiry and walkthrough for medium-risk controls. Exclude low-risk controls from testing (document the exclusion rationale).

2
Reliance on Prior Period Testing

If a control was tested last year with no exceptions, and nothing has changed, the auditor may be able to reduce the current year sample. Document the reliance rationale and prior findings.

3
Scope Limitation Disclosure

When scope is limited due to resource constraints, the audit report must disclose the limitation. Recipients need to understand what was and was not tested to properly interpret the findings.

4
Issue-Driven Scoping

If during planning you identify a high-risk issue, scope should be expanded to cover it — even at the expense of lower-risk planned areas. Issue-driven scope adjustments should be documented and approved.

📝 Audit Program Design — Writing Effective Test Procedures

An audit program is only as good as its test procedures. Effective test procedures are:

Specific and Reproducible

"Verify that user access is reviewed quarterly" is weak. "Select 25 random user accounts from the Active Directory export as of [date]. For each, verify: (1) An access review approval email exists in the ticketing system, (2) dated within the prior 90 days, (3) signed by the resource owner."

Linked to Control Objective

Every test procedure must trace back to the specific control objective it tests. Orphaned test procedures (testing something with no clear objective) waste resources and produce unusable results.

Evidence-Specified

The program should specify what evidence will be collected for each test. "Screenshot of configuration setting," "Signed access review form," "System-generated user list" — defining evidence type in advance avoids fieldwork inefficiency.

Pass/Fail Criteria

Define what constitutes a pass and what constitutes an exception before testing begins. If pass/fail is defined after seeing results, the auditor's judgment may be unconsciously influenced by expectations.

🧪 Lab — Build an Audit Plan: Payroll System

You are leading the internal audit of a payroll system that processes $48M in annual payroll for 1,800 employees. Build a complete, professional-grade audit plan using the risk-based audit planning methodology — from objective through sampling through reporting.

Scenario — Scoping 200 Systems in Limited Time

Mission Quiz

Mission Complete

← Module 14 Next: Module 16 →