Audit Plan
Definition
The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what timeline, using which evidence collection methods.
- Function
- Translates scope and objectives into a fieldwork programme
- Specifies
- What will be tested, how, and by whom
- Also specifies
- Timeline and evidence collection methods
Common questions
How does an audit plan differ from the audit objectives it is built on?+
Objectives state the questions to be answered, while the plan is the operational document translating those questions into concrete test steps, assigned staff, deadlines, and the specific evidence each step will collect, effectively the execution roadmap.
Why is an audit plan usually reviewed or approved before fieldwork starts?+
Review at this stage catches gaps, such as untested control areas or unrealistic timelines, before resources are committed, and gives management or the audit committee visibility into what the audit will and will not cover.
Related terms
- Audit Criteria
- The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
- Audit Objectives
- The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
- Audit Scope
- The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor...
- Auditee
- The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...