Instiq

2Audit planning

Practice questions →Glossary →
  • 2.1Risk-based approach & audit risk

    Covers the risk-based approach, which concentrates limited audit resources on high-risk areas, and the relationship audit risk = inherent risk x control risk x detection risk. Inherent and control risk are givens the auditor assesses, while only detection risk is what the auditor controls through audit procedures; the section covers how to lower detection risk to hold audit risk to an acceptable level in areas of high inherent and control risk.

  • 2.2Formulating the audit plan

    Covers the three-tier hierarchy of the audit plan—the medium-to-long-term plan that sets multi-year audit policy, the annual audit plan that sets that year's audit targets and resource allocation, and the individual audit plan that sets the concrete procedures and schedule for each engagement—and the judgment of how risk-assessment results cascade from higher to lower plans.

  • 2.3Materiality, audit scope & objectives

    Covers the core planning judgments of materiality (how much a problem or deficiency affects decision-making and reliability), the setting of the audit scope that allocates audit resources on that basis, and the setting of the audit objective that defines "what to evaluate and what to establish." The key link is that the higher the materiality of an area, the wider the audit scope and the greater the depth.

  • 2.4Preparing the audit program

    Covers the role and preparation of the audit program, which concretely sets "who, when, what, by which audit technique, and what evidence to obtain" in order to achieve the audit objective, its mapping to the audit objective, and its significance in ensuring the uniformity, completeness, and reviewability of the audit. The key point is that the program is designed so one can logically trace from the audit objective to the evidence.