{"id":7599,"date":"2026-08-21T10:03:17","date_gmt":"2026-08-21T04:33:17","guid":{"rendered":"https:\/\/www.akgvg.com\/blog\/?p=7599"},"modified":"2026-08-24T10:13:15","modified_gmt":"2026-08-24T04:43:15","slug":"audit-planning-how-audit-procedures-are-decided","status":"publish","type":"post","link":"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/","title":{"rendered":"Audit Planning: How Audit Procedures Are Decided"},"content":{"rendered":"<p>The first step to a successful internal audit is to develop an audit plan. If not planned properly, auditors could miss crucial threats to the business, use precious resources, or not give relevant feedback to management. The foundation of the audit plan is the areas to audit, procedures to conduct, and evidence to gather to assess the effectiveness of controls.<\/p>\n<p>The audit plan is carefully designed to enable the audit to concentrate on the areas that are important to the organization. The information contained in this document outlines how audit procedures are determined at the planning phase of the audit.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_83 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Understanding_the_Organizations_Objectives\" >Understanding the Organization&#8217;s Objectives<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Running_a_Risk_Assessment\" >Running a Risk Assessment<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Determining_the_Audit_Scope\" >Determining the Audit Scope<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Selecting_Appropriate_Audit_Procedures\" >Selecting Appropriate Audit Procedures<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Allocation_of_Resources_and_Scheduling\" >Allocation of Resources and Scheduling<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Continuous_Review_in_the_Audit\" >Continuous Review in the Audit<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Conclusion\" >Conclusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.akgvg.com\/blog\/audit-planning-how-audit-procedures-are-decided\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Understanding_the_Organizations_Objectives\"><\/span><strong><b>Understanding the Organization&#8217;s Objectives<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Clarifying the organization&#8217;s business model, objectives, operations, and regulatory environment is the first step in planning the audit. Policies, prior audit reports, financial data and the way operational processes are carried out are assessed by auditors to determine if there are areas that could contain increased risks.<\/p>\n<p>The knowledge of organization goals will assist auditors to be knowledgeable of the business objectives and not just check compliance for an internal audit.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Running_a_Risk_Assessment\"><\/span><strong><b>Running a Risk Assessment<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Risk assessment is one of the most important aspects of audit planning. Auditors assess the risk and impact of different risks that may arise for business operations, financial reporting and regulatory compliance.<\/p>\n<p>Low-risk functions may receive limited review, while medium- and high-risk functions may be reviewed in greater detail. The following are factors that will be taken into consideration when assessing a risk:<\/p>\n<ul>\n<li>Changes in company processes.<\/li>\n<li>New rules or standards that must be met<\/li>\n<li>Previous audit findings<\/li>\n<li>Financial significance<\/li>\n<li>Technology and cyber security threats.<\/li>\n<li>Fraud vulnerability<\/li>\n<\/ul>\n<p>Organizations can concentrate resources on areas where they will be most effective with a risk-based internal audit.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Determining_the_Audit_Scope\"><\/span><strong><b>Determining the Audit Scope<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>After identifying the risks, the scope of the audit is decided by auditors. This is what will be reviewed, the departments involved, the time period reviewed and what objectives will be achieved.<\/p>\n<p>A good scope means no wasted time and all essential processes can be given a good shot. It also sets the ground rules for management prior to the audit.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Selecting_Appropriate_Audit_Procedures\"><\/span><strong><b>Selecting Appropriate Audit Procedures<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Audit procedures are selected based on the risk(s) and audit objective(s). These procedures enable the auditor to collect sufficient and reliable evidence to support the auditor&#8217;s conclusions.<\/p>\n<p>Below are standard audit procedures:<\/p>\n<ul>\n<li>Policy and documentation review<\/li>\n<li>Data analysis<\/li>\n<li>Testing of internal controls<\/li>\n<li>Conducting interviews of employees<\/li>\n<li>Business process observation<\/li>\n<li>Sampling transactions<\/li>\n<li>Verification of regulatory compliance<\/li>\n<\/ul>\n<p>Procedures conducted during <strong><a href=\"https:\/\/www.akgvg.com\/internal-audit\">internal audit<\/a><\/strong> engagements may differ depending on the risk exposure of the organization.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Allocation_of_Resources_and_Scheduling\"><\/span><strong><b>Allocation of Resources and Scheduling<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Another important aspect of planning is ensuring the appropriate personnel are assigned to conduct the audit within realistic timelines.<\/p>\n<p>Resource allocation takes into account audit complexity, the availability of people, special knowledge needs, and reporting deadlines. Such planning helps to avoid disruption to the business as well as ensuring that the audit can be carried out in an efficient manner.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Continuous_Review_in_the_Audit\"><\/span><strong><b>Continuous Review in the Audit<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The process of audit planning is an ongoing process. Risks and issues may be identified by auditors during their fieldwork. As a result, the audit plan may need to be amended in order to perform further tests and\/or modify audit techniques.<\/p>\n<p>This flexibility ensures that the internal auditing function is able to respond appropriately to differing circumstances.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span><strong><b>Conclusion<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The key components of an audit are understanding the organization, risk assessment, scope, testing methods and resource allocation, with all these contributing to well-planned audit procedures. A risk-based Planning approach ensures audits are not done on every process equally, but on those with the highest impact on the business.<\/p>\n<p>An effective internal audit has the potential to highlight control weaknesses and improve governance, operational efficiency and risk management within an organization. Audits that take the time to carefully plan will ultimately deliver better audit results and stakeholders will have more confidence in the final outcomes.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span><strong><b>Frequently Asked Questions<\/b><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong><b>Q: What is a risk-based internal audit?<\/b><\/strong><\/p>\n<p>A risk-based internal audit gives greater attention to areas with higher potential financial, operational, compliance, technology, or fraud-related impact.<\/p>\n<p><strong><b>Q: What audit procedures are commonly used in an internal audit?<\/b><\/strong><\/p>\n<p>Common procedures include reviewing policies and records, testing controls, analyzing data, interviewing employees, observing processes, sampling transactions, and checking compliance requirements.<\/p>\n<p><strong><b>Q: <\/b><\/strong><strong><b>What is the difference between internal audit and statutory audit?<\/b><\/strong><\/p>\n<p>Internal audit focuses on improving controls, risk management, and operations throughout the year. A statutory audit examines financial statements to meet legal requirements.<\/p>\n<p><strong><b>Q: Does internal audit only focus on financial matters?<\/b><\/strong><\/p>\n<p>No. It also reviews operational efficiency, compliance, IT controls, cybersecurity, governance, fraud risk, and business processes.<\/p>\n<p><strong><b>Q: What documents are reviewed during an internal audit?<\/b><\/strong><\/p>\n<p>Auditors may review invoices, financial records, policies, contracts, bank statements, approval documents, system reports, and transaction samples.<\/p>\n<blockquote><p><strong>Also Read:<\/strong> <a href=\"https:\/\/www.akgvg.com\/blog\/data-driven-internal-audits-why-analytics-is-becoming-essential\/\">Data-Driven Internal Audits: Why Analytics Is Becoming Essential<\/a><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>The first step to a successful internal audit is to develop an audit plan. If not planned properly, auditors could miss crucial threats to the business, use precious resources, or not give relevant feedback to management. The foundation of the audit plan is the areas to audit, procedures to conduct, and evidence to gather to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":7600,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2107,510],"tags":[],"class_list":["post-7599","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-audit-and-assurance","category-internal-audit"],"_links":{"self":[{"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/posts\/7599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/comments?post=7599"}],"version-history":[{"count":1,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/posts\/7599\/revisions"}],"predecessor-version":[{"id":7601,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/posts\/7599\/revisions\/7601"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/media\/7600"}],"wp:attachment":[{"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/media?parent=7599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/categories?post=7599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.akgvg.com\/blog\/wp-json\/wp\/v2\/tags?post=7599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}