Skip to main content
Category: Internal Audit and Assurance

Engagement Planning

Also known as: Audit Engagement Planning
Simply put

Engagement planning is the process an internal audit team follows to decide what a specific audit or review will cover and what it aims to achieve before the work begins. It involves setting clear objectives, defining the scope, and considering the relevant risks so the engagement stays focused and aligned with the organization's priorities. Good planning helps ensure the audit is efficient and produces useful results.

Formal definition

In an internal audit context, engagement planning is the preparatory phase in which the auditor establishes the objectives and scope of a specific engagement, typically informed by risk considerations and alignment with organizational priorities and the broader audit plan. It generally encompasses defined planning steps that translate the engagement's purpose into a documented set of objectives and boundaries, providing the basis for subsequent fieldwork and testing. The precise steps and requirements vary depending on the applicable professional guidance, the entity, and the auditor's judgment; the term is also used in adjacent, distinct senses (for example, stakeholder or community engagement planning) that fall outside the internal audit meaning described here. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Engagement planning is where an internal audit assignment is shaped before any testing begins. When objectives and scope are set clearly and informed by relevant risks, the engagement stays focused on what matters to the organization and avoids drifting into areas of limited value or missing significant exposures. Poorly planned engagements risk consuming resources on low-priority matters, producing findings that stakeholders cannot act on, or overlooking the risks that prompted the review in the first place.

Because engagement planning aligns individual audits with the broader audit plan and organizational priorities, it also supports the internal audit function's credibility and the assurance it provides to the audit committee and the board. A documented set of objectives and boundaries gives management and those charged with governance a shared understanding of what the engagement will and will not address, which helps manage expectations and clarifies the basis on which conclusions are later drawn.

The term is also used in adjacent, distinct senses, such as stakeholder engagement planning or community engagement planning, that are unrelated to the internal audit meaning. Confusing these can lead to misapplied methods, so it is worth being explicit that this entry concerns the internal audit engagement, not communication or outreach strategies.

Who it's relevant to

Internal Auditors
Internal auditors carry out engagement planning directly, setting objectives, defining scope, and considering relevant risks before fieldwork begins. Sound planning helps them keep the engagement focused, efficient, and capable of producing useful results.
Chief Audit Executives and Audit Leadership
Those responsible for the internal audit function rely on consistent engagement planning to ensure individual audits align with the broader audit plan and organizational priorities. They also help ensure planning approaches reflect applicable professional guidance and the entity's circumstances.
Audit Committees and the Board
In their oversight role, audit committee members and the board benefit when engagements are clearly scoped and aligned to risk, as this supports the quality and relevance of the assurance internal audit provides. Well-defined objectives help clarify the basis on which audit conclusions are reached.
Management of Audited Areas
Managers whose functions are subject to an engagement benefit from a documented set of objectives and boundaries, which sets a shared understanding of what the audit will and will not cover and helps manage expectations about its scope.

Inside Engagement Planning

Objectives and Scope Definition
The articulation of what the engagement is intended to achieve and the boundaries of what will and will not be examined, including the processes, locations, systems, and time periods covered. Scope is typically set by the assurance function (for example, internal audit) with input from stakeholders, and should be documented before fieldwork begins.
Preliminary Risk Assessment
An assessment conducted during planning to identify and prioritize the areas of greatest risk relevant to the engagement, generally informing where resources are concentrated. This is distinct from the enterprise-wide risk assessment owned by management or the risk function; it is an engagement-level exercise to focus assurance work.
Understanding the Area Under Review
Gathering background on the relevant objectives, processes, controls, applicable laws or standards, and prior findings. Under many internal audit standards, practitioners are generally expected to understand control design before testing operating effectiveness.
Engagement Work Program
A documented plan of the procedures to be performed, typically linking each procedure to identified risks and objectives. It supports consistency, review, and accountability, and is generally approved before fieldwork commences.
Resource and Timing Allocation
Determination of the staffing, skills, budget, and schedule needed to complete the engagement. This includes considering whether specialized competencies are required and how the timing fits within the broader assurance plan.
Stakeholder Communication and Coordination
Establishing how and when the engagement team will communicate with management of the area under review and other relevant parties, clarifying roles without transferring the assurance function's independence or the board's oversight responsibility to management.

Common questions

Answers to the questions practitioners most commonly ask about Engagement Planning.

Is engagement planning just a formality the internal audit team completes before starting fieldwork?
No. Engagement planning is a substantive process that generally shapes the scope, objectives, and approach of an assurance engagement, not a procedural checkbox. Under many internal audit frameworks, planning involves understanding the auditable area, assessing risks relevant to the engagement, and determining the resources and testing strategy. Treating it as a mere formality tends to undermine the quality and defensibility of the resulting work. The specific expectations depend on the applicable professional standards and the entity's own methodology, and this entry is educational rather than a substitute for those standards.
Does engagement planning mean management sets the scope and objectives of the audit?
Generally not. Engagement planning is typically owned by the assurance function conducting the engagement, and the responsibility for setting engagement objectives and scope usually rests with that function to preserve its independence and objectivity. Management input is commonly sought to understand the area, its risks, and relevant context, but allowing management to determine scope would blur the line between an operational function and an independent assurance activity. Where accountability sits can vary by the type of engagement and the applicable framework, so professional judgment and the relevant standards should govern.
How is the scope of an engagement typically determined during planning?
Scope is generally determined by relating the engagement objectives to the risks and controls within the area under review, then defining what will and will not be examined, including the period covered, locations, processes, and systems in scope. Under many methodologies, scope decisions are informed by a preliminary risk assessment and by resource and time constraints. Documenting what is out of scope is often as important as documenting what is in scope, so that stakeholders understand the boundaries and limitations of the resulting assurance. The right approach depends on the facts of the engagement and the applicable standards.
What role does risk assessment play in engagement planning?
Risk assessment at the engagement level typically helps focus effort on the areas that matter most, guiding where testing is concentrated and how much work is performed. This engagement-level assessment is generally distinct from enterprise risk management, which is owned by management, and from any organization-wide audit risk assessment used to build the audit plan. During planning, practitioners often consider factors relevant to the specific area, and may distinguish inherent from residual risk when deciding how much reliance to place on existing controls. This entry describes the concept generally and is not audit advice.
How should engagement planning be documented?
Planning is commonly documented in a written plan or program that records the objectives, scope, risks considered, the approach or procedures to be performed, resource allocation, and timing. Clear documentation supports supervision, review, and later demonstration that the work was appropriately directed. The level of detail generally varies with the complexity and risk of the engagement and with the requirements of the applicable professional standards and the function's own methodology. What is sufficient depends on the facts and on professional judgment.
How should changes that arise after planning is complete be handled?
When new information, emerging risks, or scope changes arise during an engagement, the plan is generally revisited and updated rather than treated as fixed. Many methodologies expect planning to be iterative, with significant changes to objectives, scope, or approach documented and, where appropriate, approved consistent with the function's protocols and reporting lines. Whether a change is significant enough to require formal re-approval depends on the applicable standards, the nature of the change, and professional judgment. This entry is educational and not a substitute for the relevant standards or methodology.

Common misconceptions

Engagement planning is a purely administrative formality that can be completed quickly before the real work begins.
Planning generally shapes the quality and focus of the entire engagement. The preliminary risk assessment, scoping, and understanding of controls typically drive where effort is directed, and inadequate planning can leave significant risks unexamined. It is a substantive, judgment-driven phase, not a checkbox exercise.
The engagement-level risk assessment performed during planning is the same as the organization's enterprise risk management process.
These are distinct activities owned by different functions. Enterprise risk management is typically a management responsibility supported by the risk function and overseen by the board or a committee. The engagement risk assessment is a narrower exercise performed by the assurance function to prioritize procedures within a specific engagement.
A fixed engagement plan should be locked in at the outset and followed without change.
Plans generally need to remain responsive. If information gathered during the engagement changes the understanding of risks or controls, practitioners typically revise scope, procedures, or resources. The plan is a living document subject to professional judgment, not an immutable contract.

Best practices

Document engagement objectives and scope explicitly before fieldwork, and confirm what is out of scope so expectations are clear to the assurance team and stakeholders.
Base the engagement work program on a documented preliminary risk assessment, linking each planned procedure to the risks and objectives it addresses.
Develop an understanding of control design during planning before testing operating effectiveness, keeping these two evaluations distinct.
Match resources, skills, and timing to the assessed risks, and identify early whether specialized competencies are needed for the engagement.
Agree communication protocols with management of the area under review while preserving the assurance function's independence and not shifting oversight responsibilities.
Treat the plan as revisable: update scope, procedures, or resources when information gathered during the engagement changes the risk picture, and document the rationale for changes.