Audit planning is more than preparing a checklist before fieldwork begins. Under SA 300, Planning an Audit of Financial Statements, the auditor establishes an overall audit strategy, develops a more detailed audit plan, decides how the engagement team will be directed and reviewed, and updates those decisions when the audit reveals new information. The objective is practical: plan the audit so that it is performed in an effective manner.
ICAI lists SA 300 in its current Engagement and Quality Control Standards repository. The detailed requirements are available in the official SA 300, Planning an Audit of Financial Statements.
Overall audit strategy and audit plan are not the same thing
SA 300 requires an overall audit strategy that sets the scope, timing and direction of the audit and guides development of the audit plan. The audit plan is more detailed: it describes the nature, timing and extent of risk assessment procedures, further audit procedures at the assertion level, and other procedures needed to comply with the Standards on Auditing.
A useful distinction is that the strategy answers how the engagement will be organised and directed, while the plan answers what audit work will be performed, when and to what extent. They are closely related rather than rigidly sequential, so a change in one may require a change in the other.
Step 1: complete preliminary engagement activities
At the beginning of the current audit engagement, SA 300 requires preliminary activities relating to client continuance under SA 220, compliance with ethical requirements including independence, and an understanding of the engagement terms under SA 210. The standard also notes that continuance and ethical considerations continue throughout the engagement as circumstances change.
For an initial audit, additional considerations before starting include acceptance procedures under SA 220 and, where there has been a change of auditors, communication with the predecessor auditor in accordance with relevant ethical requirements.
Step 2: build the overall audit strategy
The strategy should make the major planning decisions visible. SA 300 requires consideration of the characteristics defining engagement scope, reporting objectives and communications, significant factors directing team effort, results of preliminary engagement activities, relevant knowledge from other engagements where applicable, and the resources needed.
In practice, this means deciding matters such as which locations or areas require attention, where experienced team members or experts are needed, when work should occur, how resources should be allocated to higher-risk areas, and how the engagement will be directed, supervised and reviewed.
Step 3: convert the strategy into the audit plan
SA 300 requires the audit plan to describe three broad categories of work:
- Risk assessment procedures: planned nature, timing and extent under SA 315.
- Further audit procedures: planned nature, timing and extent at the assertion level under SA 330.
- Other required procedures: work needed so the engagement complies with applicable SAs.
A vague instruction such as “test revenue” is weak planning. A stronger plan identifies the relevant assertions and risks, the intended control or substantive response, timing, the population or period to be covered where relevant, and how the work responds to the risk assessment.
Worked example: planning revenue in a multi-location business
Assume a company has three branches, centralised accounting, significant year-end sales and one branch that introduced a new billing system. The overall strategy may identify revenue as a key area, allocate an experienced team member to the new-system branch, schedule work around year-end cut-off, and require manager review of significant revenue judgments.
The detailed plan then turns those decisions into procedures: understand and assess the new billing process, perform relevant risk assessment work, decide whether controls will be tested, design assertion-level work for occurrence and cut-off, and address unusual manual entries or exceptions. If testing shows unexpected system errors, the strategy and plan should be revised rather than mechanically completed as originally drafted.
Planning is continuous, not a one-time exercise
SA 300 describes planning as a continual and iterative process that may begin shortly after completion of the previous audit and continue until the current engagement is complete. The auditor must update and change the overall strategy and audit plan as necessary during the audit.
Audit evidence can contradict planning assumptions. Unexpected transactions, control failures, changed business conditions or results of substantive procedures may require a revised risk assessment and different procedures. Good documentation therefore records significant changes and why they were made.
Do not make the audit unnecessarily predictable
The auditor may discuss elements of planning with management to coordinate the engagement, but the strategy and plan remain the auditor's responsibility. SA 300 cautions that discussing detailed nature and timing of procedures may compromise effectiveness by making the audit too predictable.
Plan direction, supervision and review
SA 300 requires planning the nature, timing and extent of direction and supervision of engagement team members and review of their work. The appropriate level depends on factors including entity size and complexity, audit area, assessed risks and the competence of team members. Higher assessed risk ordinarily calls for more timely and extensive direction, supervision and review.
What must be documented?
The auditor must document the overall audit strategy, the audit plan, and significant changes made during the engagement together with the reasons for those changes. ICAI notes that a strategy memorandum can record key decisions on scope, timing and conduct, while audit programs or checklists may support the detailed plan if they are tailored to the engagement.
For a smaller entity, planning need not become a large document merely for appearance. SA 300 recognises that a brief memorandum may serve as the documented strategy if it covers the required considerations.
Practical SA 300 planning checklist
- Complete continuance, ethics and engagement-terms activities before major audit work.
- Define scope, reporting objectives and key communications.
- Identify significant factors that should direct team effort.
- Decide what resources, expertise and review levels are needed.
- Develop risk assessment procedures under SA 315.
- Plan assertion-level responses under SA 330.
- Include other procedures required to comply with the SAs.
- Plan team direction, supervision and review.
- Update the strategy and plan when evidence or circumstances change.
- Document significant changes and the reasons for them.
Practical takeaway
A strong SA 300 file shows a clear chain from engagement facts to audit decisions. Establish the strategy to define scope, timing, direction and resources; translate it into specific risk assessment and further audit procedures; plan supervision and review; and revise the approach when evidence changes the risk picture. Planning is effective when it actively shapes the audit, not when it simply reproduces last year's programme.