Skip to content

Advanced Auditing, Assurance and Professional Ethics · Internal Audit

Internal Audit Standards and Engagement Planning (CA Final)

Updated 5 October 2026 · Fact-checked

Standards on Internal Audit (SIAs) are ICAI standards that set how internal auditors plan, perform, document and report their work. Planning starts with understanding the entity, assessing risks, and building an internal audit plan that ranks areas by risk. To answer, state the standard's requirement, apply it to the case facts, and conclude.

Understand Internal Audit Standards and Engagement Planning

An internal audit is an independent review of an entity's operations, controls, risk management and governance, carried out for management or those charged with governance. The Standards on Internal Audit (SIAs) are issued by the Internal Audit Standards Board of ICAI. They give the minimum expected quality of work. They are recommendatory at first and become mandatory as notified, for members performing internal audits.

The SIAs are grouped by theme. Some cover basic principles such as the nature of assurance, internal controls and risk management. Some cover general standards such as managing the internal audit function and overall planning. Others cover specific areas such as planning an assignment, evidence, documentation, communication and reporting. Students often confuse or misremember SIA numbers, so name standards by their titles unless you have checked the number against the current ICAI list. Commonly cited ones are the standards on Planning an Internal Audit, Sampling, Internal Audit Documentation and Enterprise Risk Management.

Planning works at two levels. The overall internal audit plan covers the whole entity, usually for a year or a cycle. It lists the areas to be audited, how often and with what resources. The assignment plan covers one engagement. It sets objectives, scope, timing, team, procedures and the approach to sampling.

Planning is risk based. You first understand the entity: its business, processes, systems, laws and past audit findings. Then you identify the risks in each area and rank them by their impact and likelihood. High-risk areas get more frequent and deeper audits. Low-risk areas get less. Management's own risk management process is an input, but the internal auditor forms an independent view of it.

Documentation is the proof that you followed the standards. Working papers record the plan, procedures, evidence, findings and conclusions. They should let an experienced reviewer with no prior link to the audit understand what you did and why. Sampling is used when testing every item is not practical. You pick a sample that represents the population and draw conclusions from it, with the size and method driven by risk.

Key rules to remember

Risk ranking score (common method)
Risk score = Impact × Likelihood
A practical way to rank auditable areas. It is a method, not a number prescribed by the SIAs. Use the same scale for every area.
Two levels of planning
Overall internal audit plan → Assignment plan
The overall plan decides which areas to audit and when. The assignment plan decides how to audit one area.
Sampling logic
Higher risk or lower reliance on controls → larger sample
Sample size moves with risk, the tolerable error and the population. Sampling risk cannot be removed, only controlled.
Documentation test
Working papers should let an experienced reviewer understand the work done, evidence obtained and conclusions reached
Use this test to say whether the documentation is adequate.
Plan contents to remember
Objectives, scope, timing, resources, risk assessment, procedures, sampling approach, reporting
A short checklist for any assignment planning answer.

How to solve Internal Audit Standards and Engagement Planning questions

Use this method for any question on SIAs, the internal audit plan or documentation. Keep the answer in provision, facts and conclusion form.

  1. 1Identify what is asked: a standard's requirement, a plan, a risk ranking, documentation or sampling.
  2. 2Name the relevant SIA or principle in plain words. Give the SIA number only if you are sure of it.
  3. 3State the requirement in one or two sentences.
  4. 4Pull the key facts from the case: the entity, its risks, past findings, systems and constraints.
  5. 5Apply the requirement to those facts. For a plan, rank areas by risk and link the depth of work to the rank.
  6. 6Cover the supporting points: resources, timing, documentation and sampling approach.
  7. 7Close with a clear conclusion or recommendation. Say what the internal auditor should do.

Quickest way: Four-line planning answer

When to use it: Use it when a written question asks you to prepare or evaluate an audit plan with little time left.

  1. Understand: write two lines on the business, process and past findings.
  2. Assess risk: list the areas, score each by impact and likelihood, and rank them.
  3. Plan: set objectives, scope, timing, team and sample approach for the top-ranked areas first.
  4. Record and conclude: mention working papers and the review by the engagement head, then state the plan.

Common mistakes in Internal Audit Standards and Engagement Planning

  • Treating the overall audit plan and the assignment plan as the same thing.

    Both use the word plan and both involve scope and timing.

    Fix: Say the overall plan decides what to audit and how often. The assignment plan decides how to audit a single area.

  • Ranking areas by size of balance instead of by risk.

    Students carry over the idea of materiality from statutory audit.

    Fix: Rank by impact and likelihood of the risk, including non-financial risks such as compliance, fraud and system failure.

  • Quoting SIA numbers from memory and getting them wrong.

    Many standards have similar-sounding titles, so numbers are easily mixed up.

    Fix: Use the numbers from your latest ICAI material. If unsure, describe the standard by its title, for example the standard on documentation.

  • Writing only the theory of documentation without tying it to the case.

    Students memorise the definition of working papers.

    Fix: Name what must be recorded in this case: plan, procedures, evidence, findings, reviews and conclusions.

  • Saying a sample proves the whole population is error free.

    Students overlook sampling risk.

    Fix: Say a sample gives a conclusion with some risk of being wrong. Extend testing if exceptions are found.

  • Confusing the internal auditor's risk view with management's risk register.

    Both deal with risk management.

    Fix: Say the auditor may use management's risk assessment but must form an independent view of whether it is reliable.

Worked examples

Example 1

Case: You are the internal auditor of a manufacturing company. You are preparing the annual plan. The areas and your scores on a 1 to 5 scale are: Procurement (impact 4, likelihood 4), Payroll (impact 5, likelihood 2), Petty cash (impact 1, likelihood 5) and IT access controls (impact 4, likelihood 3). Rank the areas and explain how this drives the plan.

Show the solution
  1. Method: a risk-based plan ranks areas by risk. The risk-based approach to planning is reflected in the standard on Planning an Internal Audit, while the standard on Enterprise Risk Management deals with the auditor's role regarding enterprise risk management. Impact × Likelihood is only a common scoring method, not one prescribed by any SIA. Score = impact × likelihood.
  2. Procurement = 4 × 4 = 16.
  3. Payroll = 5 × 2 = 10.
  4. Petty cash = 1 × 5 = 5.
  5. IT access controls = 4 × 3 = 12.
  6. Ranking from highest: Procurement (16), IT access controls (12), Payroll (10), Petty cash (5).
  7. Plan impact: audit procurement and IT access first and in depth, perhaps more than once a year. Cover payroll once with moderate testing. Cover petty cash with limited testing or in a rotation.
  8. Record the scores and reasons in the working papers, and get management's agreement on the plan.

Answer: Ranking: Procurement 16, IT access controls 12, Payroll 10, Petty cash 5. Allocate more time, senior staff and larger samples to procurement and IT access, and the least to petty cash.

Example 2

Case: During an assignment on the inventory process of a trading company, the junior team member tests 25 purchase invoices and finds 4 with missing approvals. Her working paper only says 'Tested invoices, found some exceptions.' The engagement head asks whether the documentation and sampling approach are adequate.

Show the solution
  1. Rule: working papers must let an experienced reviewer with no prior link to the audit understand the work, the evidence and the conclusion.
  2. Apply to the case: the note does not record the objective, the population, how the 25 were selected, the exceptions, or the conclusion. A reviewer cannot understand it.
  3. Sampling: 4 exceptions out of 25 is a high rate. It suggests the approval control may not be working. The sample alone should not be taken as showing the control works.
  4. Action: extend testing, record the selection method and population, and find the cause of the missing approvals.
  5. Document the exception details, management's response and the final conclusion, and have the work reviewed by the engagement head.

Answer: The documentation is inadequate because it does not record objective, population, selection, exceptions or conclusion. With 4 of 25 invoices lacking approval, the auditor should extend testing, document the details and report the control weakness.

Exam tips

  • Write the answer in provision, facts and conclusion form. Even a short answer scores better when the case facts are used.
  • In plan questions, always show a risk ranking and link it to depth and frequency of audit work.
  • Give an SIA number only when you are sure. Naming the standard by its subject is safe and still earns the marks.
  • For case-scenario MCQs, look for the key word: risk based, overall plan, assignment plan or working papers. It usually points to the answer.
  • Link planning, documentation and sampling in one answer when the case gives you exceptions or a new risk.

Practice questions from Internal Audit

Internal Audit Standards and Engagement Planning in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Audit Standards and Engagement Planning: frequently asked questions

What are the Standards on Internal Audit?

They are standards issued by the Internal Audit Standards Board of ICAI that set the expected quality of internal audit work. They cover basic principles, general matters such as planning and managing the function, and specific areas such as evidence, documentation and reporting. They are recommendatory at first and become mandatory as notified, for members performing internal audits.

How do I prepare an internal audit plan in the exam?

Understand the entity, identify risks, rank them by impact and likelihood, and then decide scope, timing, team and procedures. Put the highest-risk areas first. Mention that the plan is documented and reviewed.

What is risk based internal audit?

It is an approach where audit effort is directed to areas with higher risk. The auditor assesses risk, considers how well management manages it, and plans the depth and frequency of work from that assessment.

What should be in internal audit working papers?

They should record the plan, procedures performed, evidence obtained, findings, reviews and conclusions. The test is whether an experienced reviewer can understand the work without further explanation.