
Audit Scope Builder Tool
Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free
Good audits are decided at the planning stage. Before a single test is performed, the auditor has to understand the business objectives, identify the risks that could prevent them, and agree an objective and scope that can realistically be concluded in the time available. When planning is rushed, the consequences show up later: testing that misses the real issues, scope disputes at the closing meeting, and reports that management sees as irrelevant.
In this area auditors typically review business objectives and strategy documents, prior audit results, risk registers, process documentation, key systems and data sources, and the expectations of senior stakeholders. They also make practical decisions on locations, time budgets, team skills and the information they will need from management.
Common planning risks include objectives that cannot be tested, scope that is too broad for the budget, exclusions that are never stated, stakeholders who are consulted too late, and data that turns out to be unavailable halfway through fieldwork. For annual planning, the main risk is a plan that rotates through the same audits every year instead of following the organization's changing risk profile.
The resources below follow the planning journey from start to finish. The tools help you build objectives, scope and time budgets; the guides explain risk-based planning and work program design step by step; the checklists confirm nothing important has been missed; and the templates give you ready-made planning documents, from the engagement plan to the annual internal audit plan. All are free to download, with no registration.
21 free resources · No registration

Turn a broad request such as “audit procurement” into a clear, risk-based scope linking objectives, risks, processes, locations, systems and exclusions.
PDF • 6 Pages • Free

Reduce a long risk list to the few risks that deserve audit attention, scoring impact, likelihood, velocity, control weakness and sensitivity.
PDF • 6 Pages • Free

Document how a process really works during walkthroughs — steps, roles, systems, approvals, evidence, exceptions and manual workarounds.
PDF • 6 Pages • Free

Identify who can block, support, inform or approve an audit and plan how to engage them — preventing late surprises on sensitive or cross-border engagements.
PDF • 6 Pages • Free

Turn a vague request such as “review procurement” into clear, testable, outcome-focused audit objectives linked to a specific risk and clear criteria.
PDF • 6 Pages • Free

Plan focused interviews and walkthrough meetings that separate what people say from the evidence that still needs corroboration.
PDF • 6 Pages • Free

Turn an engagement scope into a realistic time budget, allocating hours by risk, complexity, data effort and review needs rather than equally.
PDF • 6 Pages • Free

A six-step approach for moving from business objectives and risks to a focused, defensible audit plan — with clear objectives, scope, evidence and agreed boundaries.
PDF • 6 Pages • Free

How to follow a real transaction from start to finish, see the process rather than hear the policy, and close with a confirmed process map and evidence list.
PDF • 6 Pages • Free

Plan and run interviews that produce evidence, not just answers — open questions, “show me” demonstrations, probing exceptions, and notes that separate facts from opinions.
PDF • 6 Pages • Free

Convert audit objectives into focused, evidence-producing procedures — linking each objective to its risk, evidence source, coverage and sampling logic, owner and expected workpaper output.
PDF • 6 Pages • Free

Check that an engagement is ready for fieldwork: purpose linked to business risk, prior issues reviewed, risks and scope explicit, out-of-scope areas justified, and resources and timing realistic.
PDF • 6 Pages • Free

Start an audit with clear expectations: prepare scope and information requests, confirm roles and escalation points in the meeting, and document agreed dates, owners and scope changes afterwards.
PDF • 6 Pages • Free

Confirm how a process actually works before testing: trace a real transaction, watch each system step and hand-off, capture workarounds and overrides, then compare practice with policy.
PDF • 6 Pages • Free

Turn an audit request into a focused, risk-based engagement plan, documenting purpose, objectives, in- and out-of-scope areas, walkthroughs, data needs and milestones in one reviewable record.
PDF • 6 Pages • Free

Define exactly what the audit will cover and what it will not, recording included processes, locations and systems, documented exclusions with reasons, and how scope changes are approved.
PDF • 6 Pages • Free

Convert audit objectives and risks into clear, reviewable procedures, recording the expected control, procedure steps, population or sample, evidence expected, results and reviewer clearance.
PDF • 6 Pages • Free

Issue clear PBC and information requests that state the item, period, population, required fields and format, track owner and status, and check completeness against the source system.
PDF • 6 Pages • Free

Capture how a process actually works during a walkthrough, documenting triggers, hand-offs, systems, key controls, override rights, urgent exceptions, evidence captured and open questions.
PDF • 6 Pages • Free

Record audit interviews in a structured way, separating key facts from stated judgments, flagging potential contradictions, and tracking the evidence promised, owners and any further interviews.
PDF • 6 Pages • Free

Build a risk-based annual audit plan from the risk universe: risk scores and trends, last assurance coverage, proposed engagements with rationale, quarters and days, resource allocation and contingency.
PDF • 6 Pages • Free