Compliance Management, Audit and Due Diligence · Audit Process and Documentation
Audit Planning, Audit Strategy and Audit Programme
Updated 11 October 2026 · Fact-checked
Audit planning means deciding in advance how the audit will be done. You set the overall audit strategy (scope, timing, direction), then build a detailed audit plan, then draw up an audit programme of procedures. Risk assessment under SA 315 drives all three, and you document them.
Understand Audit Planning and Strategy
An audit without planning wastes time and misses risk. Planning means you understand the entity first, decide where misstatement is most likely, and then allot team, time and procedures to those areas.
There are three layers. The overall audit strategy is the big picture: scope of the engagement, reporting objectives, timing, nature of communication, and the main areas of focus. The audit plan is more detailed. It sets out the risk assessment procedures, the further procedures planned and other work needed to comply with the standards. The audit programme is the lowest layer: a list of specific procedures for each area, who does them, and when.
A simple way to remember it: strategy says what and how broadly, plan says how in detail, programme says exactly which steps. The strategy guides the plan, and the plan guides the programme.
Risk assessment is the engine. Under SA 315, you obtain an understanding of the entity and its environment, including relevant internal control, to identify and assess risks of material misstatement. The depth needed is less than management's own understanding. You use judgment on how much is enough. Controls matter only where they are relevant to the audit, since not every operational or compliance control affects your risk assessment.
Planning is not a one-time act. You update the strategy and plan as the audit progresses. Documentation follows SA 230. The form and extent depend on the entity's size and complexity. For a small entity, strategy, plan, understanding, materiality and assessed risks may sit together in one document with cross references.
Key rules to remember
- Planning hierarchy
- Overall audit strategy → Audit plan → Audit programme
- Each layer is more detailed than the one before. The strategy guides the plan; the plan guides the programme.
- Depth of understanding (SA 315)
- Understanding needed < Understanding held by management
- The test is whether your understanding is enough to identify and assess risks of material misstatement. You use professional judgment.
- Relevant controls (SA 315)
- Not all controls relate to the audit
- Controls relate to financial reporting, operations and compliance, but only those relevant to your risk assessment matter.
- Documentation (SA 230)
- Document the plan and risk assessment; no separate checklist needed where the file itself shows compliance
- A well documented audit plan itself shows you planned the audit. A signed engagement letter shows agreed terms.
How to solve Audit Planning and Strategy questions
Use this method for any question on planning, strategy, plan or programme, whether it asks for steps, differences or a case-based plan.
- 1Identify what is asked: strategy, plan, programme, or the whole planning process.
- 2State the meaning in one line each, showing the hierarchy.
- 3Link to the facts: entity size, industry, internal control, internal audit function, prior-year issues.
- 4Apply risk assessment under SA 315: understand the entity, identify risks, decide focus areas.
- 5List the planning steps or procedures that fit the facts, such as engagement terms, team discussion, materiality, timing and staffing.
- 6Mention documentation under SA 230 and that the plan is updated as the audit proceeds.
- 7Conclude with a clear recommendation tied to the facts.
Quickest way: Strategy-Plan-Programme in four lines
When to use it: Use when time is short or the question asks only for a difference or a quick outline.
- Write the hierarchy: strategy, then plan, then programme.
- Give one point each on scope, detail and purpose.
- Add one fact-specific risk and the procedure for it.
- Close with documentation and updating during the audit.
Common mistakes in Audit Planning and Strategy
Using audit plan and audit programme as the same thing.
Both sound like a list of work to be done.
Fix: Say the plan is the detailed approach covering risk assessment and further procedures. The programme is the specific step-by-step procedures, with timing and responsibility.
Leaving out the overall audit strategy.
Students jump to the programme because it feels practical.
Fix: Always start with strategy: scope, timing, direction and focus areas.
Treating planning as a one-time step before fieldwork.
Textbooks list planning as the first stage.
Fix: State that strategy and plan are revised as new information arises during the audit.
Saying the auditor must understand the entity as deeply as management.
Overstating the 'understanding' requirement.
Fix: Say the depth needed is less than that of management; it need only be enough to assess risk.
Writing a generic answer that ignores the case facts.
Memorised notes are easier than analysis.
Fix: Pick two or three facts from the case and tie each to a planning decision.
Claiming every audit needs a separate checklist to prove compliance.
Confusing documentation with checklists.
Fix: Note that SA 230 says a documented audit plan itself demonstrates planning, so separate checklists are unnecessary where the file shows compliance.
Worked examples
Example 1
Distinguish between an audit plan and an audit programme. Why does an auditor prepare both?
Show the solution
- Start with the hierarchy: the overall audit strategy guides the audit plan, and the plan guides the programme.
- Audit plan: the auditor's detailed approach to the engagement, covering risk assessment procedures, further procedures and other work to comply with standards. It is built on understanding of the entity and risks.
- Audit programme: a list of specific procedures for each area, with who performs them and when. It turns the plan into actionable steps.
- Difference in level: the plan is broader and strategic; the programme is narrower and operational.
- Purpose: the plan ensures attention to risky areas and proper resourcing. The programme ensures consistent execution, supervision and a record of work done.
- Both are documented, and both are revised if risks change.
Answer: The audit plan is the detailed approach based on risk assessment; the audit programme is the set of specific procedures that implements it. Both are needed so that work is risk-focused, coordinated, supervised and documented.
Example 2
Sunrise Textiles Ltd, a Pune company, has a new ERP system and an active internal audit function. You are appointed auditor. Advise how you will plan the audit.
Show the solution
- Provision: SA 315 requires understanding the entity and its environment, including relevant internal control, to assess risks of material misstatement.
- Analysis of the ERP: a new system raises risk in data migration and controls. Test relevant IT controls and plan for greater focus on affected balances.
- Analysis of internal audit: inquire of appropriate internal audit staff about their responsibilities. If these relate to financial reporting, review their audit plan and discuss it. Read reports where findings may be relevant. Keep communication open throughout the audit.
- Overall strategy: fix scope, timing, staffing with IT-skilled members, and focus areas such as revenue and inventory.
- Plan and programme: set risk assessment procedures, then specific procedures for each risk area, with responsibility and timing.
- Team discussion with the engagement partner participating, which also evidences the partner's involvement.
- Document the strategy, plan, materiality and assessed risks under SA 230. Update as the audit progresses.
Answer: Plan the audit by understanding Sunrise Textiles and its ERP risks, using internal audit work and communication, setting strategy, plan and programme around the identified risks, and documenting and updating them throughout.
Exam tips
- Draw the hierarchy first in two lines; it frames every answer on planning.
- In case questions, name the facts and tie each to a planning step. This earns analysis marks.
- Remember the depth of understanding is less than management's, and only relevant controls matter.
- Mention documentation under SA 230 and updating of the plan; many students skip both.
- For small entities, note that strategy, plan, risks and materiality may be documented together with cross references.
Practice questions from Audit Process and Documentation
- Meera & Associates, a firm of Company Secretaries, is auditing a new client, Kaveri Textiles Ltd. The engagement partner asks what the audit…
- A small proprietor-run company, Ganga Traders Pvt Ltd, is audited by a team of two junior members under a partner. The partner asks how to d…
- A firm of auditors is auditing Kaveri Agro Ltd, where sales invoicing is highly automated with almost no manual intervention. The auditor co…
- An audit team for Himalaya Foods Pvt Ltd consists mostly of first-year audit assistants. The partner is deciding how detailed the planning d…
- A firm of practising company secretaries is auditing a small trading company. The partner asks whether the risk assessment must be documente…
Audit Planning and Strategy in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Audit Planning and Strategy: frequently asked questions
What is the difference between audit plan and audit programme?
The audit plan is the detailed approach to the audit, built on risk assessment. The audit programme lists the specific procedures, who does them and when. The programme implements the plan.
Is the overall audit strategy separate from the audit plan?
Yes. The strategy sets scope, timing and direction. The plan is more detailed and follows from it. In small audits they may be recorded together.
How much understanding of the entity must the auditor have?
Enough to identify and assess risks of material misstatement. It is less than the understanding management has, and the auditor uses professional judgment on the extent.
Can the auditor use internal audit reports in planning?
Yes. If inquiries show findings relevant to financial reporting, the auditor may read related internal audit reports, and may review the function's audit plan where its responsibilities relate to financial reporting.
How is audit planning documented?
Under SA 230, the form and extent are for the auditor's judgment. A well documented plan shows that planning happened, so a separate checklist is not needed.