Instiq
Chapter 2 · Audit planning·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

2.3Materiality, audit scope & objectives

Key points

Covers the core planning judgments of materiality (how much a problem or deficiency affects decision-making and reliability), the setting of the audit scope that allocates audit resources on that basis, and the setting of the audit objective that defines "what to evaluate and what to establish." The key link is that the higher the materiality of an area, the wider the audit scope and the greater the depth.

Deciding where and how much of the limited audit resources to invest requires a yardstick for "how serious an impact a problem in that area could have." That yardstick is materiality. Based on materiality, the auditor sets the audit scope (how far to include as a target) and, within that scope, clarifies the audit objective (what to evaluate and what to establish). This section covers how these three are interlinked—the higher an area's materiality, the wider the audit scope and the more specifically the audit objective is narrowed—framed as the judgment of an auditor designing the audit plan.

2.3.1The concept of materiality

  • Materiality is the degree to which a problem, deficiency, or error could affect the reliability of the information system and the management decisions or stakeholder decisions that rely on it. It is judged not only by monetary magnitude but also by nature (legal violation, personal-data breach, core-business stoppage, and so on).
  • Materiality is the yardstick for allocating audit resources. The higher an area's materiality, the wider the audit scope and the deeper the procedures allocated to it, while a low-materiality area is treated in a limited way. This is two sides of the same coin as the risk-based approach, reconciling the efficiency and effectiveness of the audit plan.

2.3.2Setting audit scope and audit objective

  • The audit scope is the boundary of the organizations, processes, systems, and periods subject to the audit. It is set based on the materiality judgment, and by placing low-materiality areas out of scope, the finite resources are concentrated on the material areas. Without a clear scope, the audit loses focus and resources are dispersed.
  • The audit objective is the target of what the audit evaluates and establishes (e.g., "confirm that the design and operating effectiveness of access controls over customer information are effective"). Only once the audit objective is set concretely can the required procedures and evidence be determined. If procedures are laid out while the objective stays vague, the evidence does not correspond to the objective and no conclusion can be drawn.
Exam point

Most-tested: "materiality judges impact by nature (legal violation, personal-data breach, etc.), not only by amount", "the higher the materiality, the wider the scope and the greater the depth", and "only once the audit objective is made concrete are the required procedures and evidence determined". Watch for reversing the order ("fix a broad scope first, then consider materiality") and the misconception that "materiality is determined solely by monetary magnitude."

A systems auditor is designing the audit scope and objective for an engagement on a core-business system. The system comprises three subsystems: (A) billing processing involving large-volume monetary calculations, (B) a customer-management function handling personal data (names, contact details, purchase history), and (C) an internal bulletin-board function. The auditor first judges materiality. (A) has high materiality because an error leads directly to mis-billed amounts, with large impact on both management and customers; (B) does not move money, but a leak would cause a legal violation (personal-data protection law) and serious loss of trust, so it is highly material in a dimension separate from amount; (C) has low materiality because even a failure has limited impact on operations, law, or customers. Based on this materiality judgment, the auditor sets the audit scope to "concentrate on (A) billing processing and (B) the customer-management function, placing (C) the bulletin board out of scope this time." The key point here is that placing (B) out of scope solely on the grounds that "no money moves" would be a materiality-judgment error—materiality must be judged comprehensively, including the nature of the impact (the seriousness of a legal violation or personal-data breach), not just the size of the amount. Next, the auditor makes the audit objective concrete for each in-scope area: for (A), "confirm that controls over the accuracy and completeness of billing-amount calculation are effectively designed and operating"; for (B), "confirm that the design and operating effectiveness of controls over granting, changing, and revoking access rights to customer information are effective." Only once the audit objective is made concrete to this granularity do the required procedures and evidence become uniquely determined—for (A), a full reconciliation of calculation results using generalized audit software; for (B), reconciling the access-rights register with system settings and checking the approval trail for rights grants. Materiality, audit scope, audit objective, and audit procedures are thus connected by a single line of logic, and an error in the upstream materiality judgment makes all the downstream procedures miss their mark.

ElementWhat it decidesDownstream effect
MaterialityImpact of a problem (amount + nature)Governs resource allocation, scope breadth, depth
Audit scopeTarget organizations, processes, systems, periodsBasis for setting the audit objective within scope
Audit objectiveWhat to evaluate and establishUniquely determines required procedures and evidence
Warning

Trap: "Materiality is determined solely by monetary magnitude" is wrong—there are areas, such as a personal-data breach or a legal violation, that should be judged highly material by the nature of the impact even when no money directly moves, so an area must not be mechanically ruled out of scope by amount alone. Also wrong: "even with a vague audit objective, laying out many procedures will yield a conclusion"—only once the objective is made concrete are the required procedures and evidence determined; a list of procedures without an objective produces no evidence corresponding to the objective and cannot reach a conclusion.

From materiality to objectives.
Deciding where to focus

2.3.3Section summary

  • Materiality judges impact by nature (legal violation, personal-data breach, etc.), not only by amount
  • The audit scope is set based on materiality; the higher the materiality, the wider the scope and the greater the depth
  • Only once the audit objective is made concrete are the required audit procedures and evidence uniquely determined

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. The system under audit includes a customer-management function that handles personal data. This subsystem does not directly involve monetary calculation. Which is the most appropriate materiality judgment and scope decision?

Q2. Which statement most accurately describes the relationship among materiality, audit scope, audit objective, and audit procedures in an audit plan?

Q3. Which is the most appropriate treatment in the audit plan for an area judged to have high materiality?

Check your understandingPractice questions for Chapter 2: Audit planning