Audit Scope
Definition
The documented boundaries of an audit: which systems, processes, organizational units, locations, and time periods are included. Scope is agreed between auditor and auditee before fieldwork and governs what the audit can conclude.
- Set by
- Auditor and auditee jointly
- Fixed
- Before fieldwork begins
- Covers
- Systems, processes, units, locations, time period
- Effect
- Limits which conclusions the audit can support
Common questions
What happens if an auditor finds something important outside the agreed scope?+
The finding is noted separately and often flagged as a recommendation to expand scope in a future audit, but it cannot be used to support formal conclusions in the current report.
How does audit scope differ from an audit objective?+
The objective is the question the audit is trying to answer, such as whether controls are adequate. Scope is the boundary of systems, time period and locations examined to answer that question.
Related terms
- Audit Criteria
- The standards, policies, or requirements against which audit evidence is compared. Common criteria include ISO/IEC 27001, NIST SP 800-53, PCI-DSS, and the...
- Audit Objectives
- The questions the audit is designed to answer, stated in terms of control criteria. For example: do access management controls satisfy the...
- Audit Plan
- The document that translates scope and objectives into a structured programme of fieldwork: what will be tested, how, by whom, on what...
- Auditee
- The organization or organizational unit being audited. In planning, the auditee provides key inputs: system inventory, risk register, previous audit findings, control...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...