Audit and Assurance · Assessing audit risks
Audit Strategy and Audit Plan: ISA 300 Explained
Updated 11 October 2026 · Fact-checked
Audit planning (ISA 300) means setting the overall audit strategy, which fixes scope, timing and direction, then writing a detailed audit plan of procedures. Risk assessment drives both. Higher assessed risk means more extensive and more reliable procedures, more testing at or after the year end unless interim work can be rolled forward, and more senior staff. Planning is continuous and documented.
Understand Audit Planning, Strategy and Engagement Acceptance
Audit planning is the work the auditor does before and during the audit to make sure it is done effectively and efficiently. ISA 300 requires the engagement partner and key team members to be involved. It is not a one-off step. You update the plan as you learn more.
There are two layers. The overall audit strategy is the big picture. It sets the scope, timing and direction of the audit and guides the detailed plan. The audit plan is more detailed. It sets out the nature, timing and extent of risk assessment procedures and of further audit procedures at assertion level, plus other procedures needed to comply with ISAs.
The strategy covers things like the financial reporting framework, deadlines and reporting dates, key areas of focus, the significant risks, materiality, the team and their skills, use of experts or internal audit, and the need for specialist or other auditors. The plan turns this into specific tests, sample sizes and timing.
Risk assessment shapes the approach. Where risk of material misstatement is higher, you do more extensive procedures, use more reliable evidence (external, obtained directly), tend to perform more testing at or after the year end rather than at an interim date (unless rolling forward interim work is adequate), and use more experienced staff with closer supervision. Where controls are reliable, you may rely on tests of controls and reduce substantive testing. Where they are weak, you rely on substantive procedures.
At the start of the audit you also carry out preliminary engagement activities: client acceptance or continuance, ethics and independence checks, and agreeing the engagement letter. These are separate from developing the strategy and plan, and they come first. For a first-year audit you also plan for opening balances. Planning is documented in the audit file, including the strategy, the plan and any significant changes made.
Key rules to remember
- Audit strategy (ISA 300)
- Strategy = scope + timing + direction of the audit
- Overall and high level. Guides development of the detailed plan.
- Audit plan (ISA 300)
- Plan = nature + timing + extent of procedures
- Covers risk assessment procedures and further audit procedures at assertion level.
- Audit risk
- Audit risk = risk of material misstatement (inherent risk × control risk) × detection risk
- Audit risk is the risk the auditor accepts of giving an inappropriate opinion, and it is set at an acceptably low level. The multiplicative form is a conceptual model, not a precise calculation. Use it to see the relationship: higher assessed risk of material misstatement means lower acceptable detection risk and more audit work.
- Risk response
- Higher risk → more extensive, more reliable, more testing at or after year end, more senior staff
- Use this as the checklist when asked how risk affects the approach. Year-end testing is a tendency, not a rule: interim work can be used if it is adequately rolled forward.
How to solve Audit Planning, Strategy and Engagement Acceptance questions
Use this method for any question on planning, strategy or the effect of risk on the approach.
- 1Read the requirement. Decide whether it asks for the strategy, the plan, planning steps or the response to specific risks.
- 2Pick out the scenario facts: new client, growth, new systems, weak controls, tight deadline, overseas locations, estimates.
- 3Link each fact to a risk and to an assertion or account area. State why it is a risk.
- 4For each risk, state the response in terms of nature, timing and extent.
- 5Add resourcing: senior staff, supervision, experts, other auditors, internal audit use.
- 6Mention documentation and that the plan is updated as new information arises.
- 7Check you have used the scenario, not a generic list, and that each point earns a mark on its own.
Quickest way: Fact – risk – response
When to use it: For Section C planning questions and any OT asking how a risk changes the audit approach.
- Underline each fact in the scenario.
- Write: fact, risk, response (nature, timing, extent).
- Add team and timing points last.
- Stop when you have one clear point per mark.
Common mistakes in Audit Planning, Strategy and Engagement Acceptance
Treating the audit strategy and audit plan as the same document.
Both sound like planning and the terms are used loosely.
Fix: Strategy is high level: scope, timing, direction. Plan is detailed procedures: nature, timing, extent.
Listing generic audit procedures with no link to the scenario.
Students recall a standard list instead of reading the facts.
Fix: Use fact – risk – response. Name the specific balance and assertion affected.
Saying planning is done once at the start.
Planning is taught as the first stage of the audit.
Fix: State that planning is continuous and the strategy and plan are updated as conditions change.
Responding to higher risk only with 'more testing'.
It sounds right but earns no mark.
Fix: Be specific: larger samples, external evidence, year-end testing, senior staff, unpredictable procedures.
Confusing audit planning with client acceptance.
Both occur early in the engagement.
Fix: Acceptance, ethics and the engagement letter are preliminary engagement activities carried out at the start of the audit. They are distinct from developing the strategy and plan, which follow them.
Worked examples
Example 1
State the difference between the overall audit strategy and the audit plan, and give two items you would include in each.
Show the solution
- The strategy sets the scope, timing and direction of the audit at a high level.
- The plan sets out the detailed procedures to carry out, in line with the strategy.
- Strategy items: reporting deadlines and key dates; significant risk areas and materiality.
- Plan items: nature, timing and extent of tests on a specific balance, such as sample sizes for receivables; the risk assessment procedures to perform.
Answer: The strategy is the overall approach (scope, timing, direction). The plan is the detailed set of procedures that implements it. Strategy: deadlines, significant risks. Plan: specific tests and sample sizes.
Example 2
A client has launched a new inventory system during the year and opened two new warehouses. Explain how this affects your audit approach.
Show the solution
- New system: risk of errors in data migration and weak controls, affecting the existence, completeness and valuation of inventory.
- Response: first understand and test the controls over the new system and the data transfer, using IT specialists if needed. If the controls prove effective, you can reduce substantive work. If they are unreliable, rely on more extensive substantive procedures, such as larger samples and reconciling migrated balances to the old system.
- New warehouses: inventory may be missed, double-counted or counted wrongly, affecting existence and completeness.
- Response: attend the counts at both new locations, at or near the year end. Count attendance is the response to the existence and completeness risks.
- Transfers between warehouses: inventory in transit may be counted twice or in neither location, and goods received and despatched around the year end may be recorded in the wrong period (cut-off).
- Response: at the count, record the last goods movement documents for each warehouse. Then test transfer and despatch documentation either side of the year end and trace in-transit items to receipt.
- The new system and new sites raise the risk of material misstatement, so assign experienced staff to these areas with closer supervision.
- Update the strategy and plan, and document the changes and reasons.
Answer: The new system and locations raise the risk of material misstatement in inventory. Test the system controls first and set substantive work according to the result. Attend counts at each site to address existence and completeness. Test cut-off and inter-warehouse transfers. Use specialist IT help and closer supervision, and update the plan.
Exam tips
- Always give responses in terms of nature, timing and extent. Examiners mark these words.
- Tie every point to a scenario fact. Generic planning lists score poorly in Section C.
- In OT questions, watch the wording: 'strategy' means high-level, 'plan' means detailed procedures.
- Mention that planning is continuous and documented when you have a spare mark.
Audit Planning, Strategy and Engagement Acceptance in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Audit Planning, Strategy and Engagement Acceptance: frequently asked questions
What is the difference between an audit strategy and an audit plan?
The strategy is the overall approach: scope, timing and direction of the audit. The plan is more detailed and sets out the nature, timing and extent of the procedures. The strategy guides the plan.
What are the main steps in audit planning?
Carry out preliminary activities such as acceptance and the engagement letter, understand the entity and assess risks, set materiality, develop the overall strategy, then write the detailed plan. Document it and update it as needed.
How does risk assessment affect the audit approach?
Higher assessed risk leads to more extensive procedures, more reliable evidence, more testing at or after the year end (unless interim work can be adequately rolled forward) and more experienced staff. Lower risk, with effective controls, allows less substantive work.
Can the plan change during the audit?
Yes. Planning is continuous. If you find new risks or controls fail, you revise the strategy and plan and document the changes.