is-auditing10 min read

Developing an IS Audit Plan: Step by Step

Follow a structured approach to developing an IS audit plan. Covers each step from understanding the environment to final plan approval for the CISA exam.

CISAPractice|

Overview of IS Audit Planning

Developing an IS audit plan is one of the most important responsibilities of the IS audit function. A well-constructed plan ensures that audit resources are directed toward the areas of greatest risk and value to the organization. This step-by-step guide covers the process from start to finish, as expected on the CISA exam.

Step 1: Understand the Business and IT Environment

Before developing the audit plan, auditors must gain a thorough understanding of the organization:

  • Review the business strategy, objectives, and key initiatives.
  • Understand the IT architecture, including applications, infrastructure, and network topology.
  • Identify key business processes and the IT systems that support them.
  • Review prior audit reports and management responses.
  • Assess the regulatory and compliance landscape.

Step 2: Define the Audit Universe

The audit universe is a comprehensive list of all auditable entities within the organization. For IS auditing, this typically includes:

  • Business applications and supporting infrastructure
  • IT processes (change management, incident management, access administration)
  • Data centers and physical IT assets
  • Third-party service providers and outsourced functions
  • IT projects and development initiatives
  • Compliance-related areas (data privacy, financial reporting controls)

Step 3: Perform Risk Assessment

Each item in the audit universe should be assessed for risk using a consistent methodology. Common risk factors include:

  • Financial impact and materiality
  • Regulatory or legal requirements
  • Complexity of the technology environment
  • History of control weaknesses or incidents
  • Degree of change since the last audit
  • Criticality to business operations

Assign risk scores to each auditable entity and rank them from highest to lowest risk.

Step 4: Determine Audit Resources

Assess the available audit resources, including:

  • Number and skills of audit staff
  • Budget for external specialists or co-sourced support
  • Time available during the audit period
  • Technology tools and CAATs available to the team

Step 5: Develop the Audit Plan

Based on the risk assessment and available resources, create the audit plan:

  • Schedule high-risk areas for audit first and more frequently.
  • Distribute medium-risk areas across the planning cycle.
  • Address low-risk areas through alternative means such as self-assessments or rotational audits.
  • Include time for ad hoc requests, investigations, and follow-up activities.
  • Build in contingency time for unexpected events.

Step 6: Obtain Approval

Present the audit plan to senior management and the audit committee (or board of directors) for review and approval. The plan should clearly communicate the rationale for audit priorities, the resources required, and any areas that cannot be covered within the planning period along with the associated risk acceptance.

Step 7: Monitor and Update

The audit plan is a living document. Monitor the risk environment throughout the year and update the plan when significant changes occur, such as major system implementations, mergers, regulatory changes, or security incidents.

CISA Exam Focus

The CISA exam emphasizes that the audit plan should be risk-based, approved by appropriate authority, and flexible enough to accommodate changes. Know that the Chief Audit Executive is responsible for developing the plan, the audit committee approves it, and the plan should be updated whenever the risk environment changes significantly.

Related Tags

IS AuditingCISA ExamAudit PlanningRisk AssessmentAudit Management

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free