Instiq
Chapter 2 · Audit planning·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

2.2Formulating the audit plan

Key points

Covers the three-tier hierarchy of the audit plan—the medium-to-long-term plan that sets multi-year audit policy, the annual audit plan that sets that year's audit targets and resource allocation, and the individual audit plan that sets the concrete procedures and schedule for each engagement—and the judgment of how risk-assessment results cascade from higher to lower plans.

Systems auditing is conducted systematically based on a plan that surveys the whole organization's risks and audit resources, not by picking targets on a whim. That plan comprises three layers of differing granularity: the medium-to-long-term plan that looks several years ahead, the annual audit plan that is that year's execution plan, and the engagement-level individual audit plan. This section covers what each layer decides and how the risk-assessment results of a higher plan feed into a lower one, framed as the judgments of an audit-department head or an assigned auditor.

2.2.1The three tiers of the audit plan

  • The medium-to-long-term plan sets, over roughly three to five years, the policy and rotation of audit target areas so that the organization's high-risk areas are all brought into scope. Since not all areas can be audited in a single year, it is drafted from the viewpoint of ensuring coverage across multiple years.
  • The annual audit plan, informed by the medium-to-long-term plan, sets the concrete audit themes, target systems, timing, and allocation of audit resources (staff, effort) to be carried out that year. It is revised to reflect new risks that arise during the year (a new system going live, a serious incident, and so on).
  • The individual audit plan sets, for each engagement chosen in the annual plan, the audit objective, scope, concrete audit procedures, schedule, assignments, and the audit evidence required. From this plan, the audit program (procedure schedule) covered later is prepared.
Exam point

Most-tested: the three-tier division of roles—"medium-to-long-term = multi-year rotation policy ensuring coverage", "annual = that year's targets, timing, and resource allocation", and "individual = per-engagement objective, scope, procedures, and schedule". Watch for confusing the layers, such as "the individual audit plan decides the organization-wide rotation of audit targets." The higher the tier, the more it is about policy and coverage; the lower, the finer the granularity of concrete procedures.

An organization's internal-audit department head is drafting next year's annual audit plan. The medium-to-long-term plan sets a rotation policy that brings the core-business, information-systems, and outsourcing areas into scope once over three years. During the year, a new cloud platform handling customer information goes live, and a minor access-management incident occurs at an outsourcing vendor. Rather than mechanically following the original annual plan, the head judges to reflect the newly surfaced risks (the immature controls of the new cloud platform, the vendor's weak access management) in the annual audit plan and revise the audit targets and resource allocation. Concretely, because risk assessment expects inherent and control risk to be high in these areas, the head concentrates that year's audit resources on them, and conversely reduces the audit depth (or defers to the following year) for a stably operating area that had no problems the prior year. Next, for the selected "audit of the new cloud platform" engagement, the assigned auditor cascades it into an individual audit plan. What is decided here is not annual-level resource allocation but this engagement's specific audit objective (e.g., evaluating the design and operating effectiveness of access controls over customer information), audit scope (target systems, period), the concrete audit procedures to perform, the required audit evidence, and the schedule. From this individual audit plan, the audit program covered in later sections is prepared. Risk-assessment results are thus progressively made concrete from higher to lower plans—medium-to-long-term to annual to individual—with each layer handling decisions at a different granularity.

Plan tierMainly decidesHorizon/granularity
Medium-to-long-termRotation of audit areas; coverage policyMulti-year (about 3-5 years)
Annual audit planThat year's targets, timing, resource allocationSingle year
Individual audit planPer-engagement objective, scope, procedures, schedule, evidenceEach engagement
Warning

Trap: "Once the annual audit plan is drafted it should not be changed within the year and should be executed as originally set" is wrong—when new risks surface during the year (a new system going live, a serious incident), reassessing risk and flexibly revising audit targets and resource allocation is the operation consistent with the risk-based approach. Also wrong: "the individual audit plan sets the organization-wide multi-year rotation"—rotation policy is the role of the medium-to-long-term plan, while the individual audit plan handles per-engagement concrete procedures and schedule.

Long-term, annual, individual plans.
From the big picture to each audit

2.2.2Section summary

  • The audit plan has three tiers—medium-to-long-term, annual, individual—with higher tiers about policy/coverage and lower tiers at the granularity of concrete procedures
  • The medium-to-long-term plan ensures coverage via multi-year rotation; the annual audit plan sets that year's targets, timing, and resource allocation
  • When new risks surface during the year, reassess risk and flexibly revise audit targets and resource allocation

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Midway through the year, a new cloud platform handling customer information goes live, and an access-management incident occurs at an outsourcing vendor. What is the most appropriate response by the audit-department head to the original annual audit plan?

Q2. Which statement most accurately describes the division of roles among the medium-to-long-term plan, the annual audit plan, and the individual audit plan in systems auditing?

Q3. Which is most appropriately an item to be set in the individual audit plan?

Check your understandingPractice questions for Chapter 2: Audit planning