CPA AUDITING & ATTESTATION (AUD) • ASSESSING RISK AND DEVELOPING A PLANNED RESPONSE

Audit Planning — Prepare Detailed Audit Plan

Translating assessed risks into a comprehensive blueprint that guides every phase of the audit engagement.

Historical Context & Motivation

The notion that an auditor should methodically plan engagement work before examining evidence has evolved dramatically over the past century. In the early days of the accounting profession, audits were largely unstructured inspections—clerks reviewed ledger entries item by item with no overarching strategy to guide their efforts. As businesses grew more complex and capital markets demanded greater assurance, it became clear that an ad hoc approach generated inconsistent quality and left gaping holes in audit coverage. The development of formal audit planning standards was a direct response to high-profile corporate failures that exposed the consequences of inadequate preparation. Today, the detailed audit plan sits at the core of every engagement, connecting the auditor's understanding of the entity, the assessed risks of material misstatement, and the specific procedures designed to respond to those risks.

1939
McKesson & Robbins Scandal
A massive inventory fraud at McKesson & Robbins revealed that auditors had failed to physically verify assets. The fallout led the AICPA to formalize requirements for audit planning and physical observation procedures.
1972
SAS No. 1 Issued
The Auditing Standards Board codified the first Statement on Auditing Standards, establishing a baseline for planning, fieldwork, and reporting, and marking the transition from ad hoc guidance to authoritative standards.
2002
Sarbanes-Oxley Act
Following Enron and WorldCom, Congress created the PCAOB and mandated rigorous planning requirements for audits of public companies, including integrated audits of internal controls.
2010
Clarified Auditing Standards (ASB)
The AICPA's clarity project reorganized and refined AU-C Section 300 (Planning an Audit), aligning U.S. nonpublic audit standards with the ISAs issued by the IAASB, emphasizing risk-based planning.
2023–Present
Technology-Driven Audit Plans
Modern audit methodologies integrate data analytics, continuous auditing tools, and AI-driven risk assessment into the planning phase, enabling auditors to tailor procedures with greater precision.

The central question that the detailed audit plan answers is deceptively simple: Given everything we know about this entity, its environment, and its risks, what specific procedures must the engagement team perform, how extensively, and when? Answering this question rigorously is what separates a defensible audit from a perfunctory one, and it is precisely the skill tested in the AUD section of the CPA Exam.

Core Principles & Definitions

Before constructing a detailed audit plan, it is essential to ground yourself in the foundational principles that govern this phase of the engagement. Under AU-C Section 300 (for nonissuers) and AS 2101 (for issuers under PCAOB standards), the auditor is required to develop an overall audit strategy and a detailed audit plan. The overall audit strategy sets the scope, timing, and direction of the audit at a high level, while the detailed audit plan operationalizes that strategy into specific audit procedures. Think of the strategy as the architectural blueprint and the plan as the construction schedule—both are necessary, but the plan tells each worker exactly what to build, where, and when.

1

Risk Assessment Foundation

The detailed audit plan is anchored to the auditor's assessed risks of material misstatement at both the financial-statement level and the assertion level. Every procedure in the plan must be traceable to one or more identified risks.
2

Nature, Timing, and Extent (NTE)

For each planned procedure, the auditor specifies the nature (type of test), timing (interim vs. year-end), and extent (sample size or scope). These three dimensions form the core design parameters of every audit response.
3

Linkage to Assertions

Audit procedures must map to specific financial statement assertions—existence, completeness, valuation, rights and obligations, and presentation and disclosure—ensuring that no assertion is left untested for a significant account.
4

Dynamic & Iterative Process

Planning is not a one-time event. The plan is revised throughout the engagement as new evidence emerges, risk assessments change, or the entity's circumstances evolve. AU-C 300.A13 explicitly acknowledges this iterative nature.
5

Documentation Requirement

The plan must be documented in sufficient detail such that an experienced auditor with no prior connection to the engagement could understand the planned procedures. This supports supervisory review and regulatory inspection.
KEY TAKEAWAY
Think of the detailed audit plan like a surgical team's pre-operation checklist. A surgeon doesn't walk into the operating room and improvise—every incision, instrument, and contingency is mapped out in advance based on the patient's specific diagnosis. Similarly, the auditor tailors each procedure to the entity's unique risk profile. Just as skipping a step in surgery can be life-threatening, omitting a planned procedure can mean missing a material misstatement that investors rely upon.

Visual Explanation — The Audit Planning Flow

The flowchart above illustrates how the detailed audit plan (Step 4) sits between the overall strategy and execution. Notice the dashed feedback loop on the right—planning is iterative. As evidence is gathered in Step 5, the auditor may need to revisit and revise planned procedures.

As depicted in the diagram, the detailed audit plan is not created in isolation—it is the logical product of the auditor's cumulative knowledge gained during the first three stages. The plan disaggregates the overall audit strategy into specific audit procedures organized by account, assertion, or business process. Each procedure is classified as a test of controls, a substantive procedure (including substantive analytical procedures and tests of details), or a dual-purpose test that serves both objectives simultaneously. The dashed red feedback loop illustrates the iterative nature of planning: if, during execution, the auditor discovers that assessed risk was understated—perhaps because a key control has been overridden—the plan must be revised to increase the extent of substantive testing.

How the Detailed Audit Plan Works — Nature, Timing, and Extent

The operational heart of the detailed audit plan lies in the auditor's decisions about the nature, timing, and extent (NTE) of further audit procedures. These three dimensions interact to form the auditor's overall response to assessed risks at the assertion level. Understanding how each dimension shifts in response to higher or lower risk is fundamental to constructing an effective plan and is heavily tested on the CPA Exam.

Nature of Procedures

The nature of an audit procedure refers to its type and purpose. Procedures include inspection (of documents or physical assets), observation, external confirmation, recalculation, reperformance, analytical procedures, and inquiry. When assessed risk is higher, the auditor selects procedures that are more effective at detecting misstatements—for example, shifting from analytical procedures (less precise) to external confirmations (more persuasive) for an account balance assertion. The nature decision also determines whether the procedure is a test of controls or a substantive test. If the auditor plans to rely on the operating effectiveness of internal controls to reduce substantive testing, the plan must include tests of controls for those specific controls.

Timing of Procedures

The timing dimension specifies whether procedures are performed at an interim date or at (or near) the period end. Performing procedures at an interim date can improve engagement efficiency and allow earlier identification of issues, but it introduces the need for additional procedures to cover the roll-forward period between the interim date and year-end. When the risk of material misstatement is higher, auditors tend to perform substantive procedures closer to the period end to minimize the risk that misstatements arising after the interim date go undetected.

Extent of Procedures

The extent of a procedure refers to the quantity to be performed—commonly represented by sample size. The extent decision is influenced by the auditor's assessment of the risk of material misstatement, the tolerable misstatement assigned to the account, and the expected misstatement based on prior experience. Where controls are effective, the auditor can often justify a smaller sample size for substantive procedures, because the combined assurance from controls testing and substantive testing achieves the desired level of audit risk.

AUDIT RISK MODEL
AR = IR × CR × DR
Where AR = Audit Risk (the risk of issuing an inappropriate opinion), IR = Inherent Risk, CR = Control Risk, and DR = Detection Risk. The detailed audit plan directly manages DR by adjusting the nature, timing, and extent of substantive procedures.
DETECTION RISK (SOLVED)
DR = AR ÷ (IR × CR)
Rearranging the audit risk model isolates detection risk—the only component the auditor can directly control. A lower acceptable DR requires more persuasive procedures (stricter nature), testing closer to year-end (tighter timing), and larger samples (greater extent).
💡 CPA Exam Tip
The audit risk model is tested both conceptually and computationally on the AUD section. Remember that inherent risk and control risk are assessed (not controlled) by the auditor, while detection risk is managed through the detailed audit plan. When IR and CR are assessed as high, DR must be set low—meaning more extensive, more effective, and more timely procedures.

Detailed Breakdown — Components of the Audit Plan

A well-constructed detailed audit plan is typically organized around significant accounts and disclosures, with each section specifying the procedures designed to address the relevant assertions. Below is a visual representation of the key components that comprise a comprehensive audit plan, followed by a classification table breaking down each element.

This hierarchy diagram shows the four major procedure categories within a detailed audit plan, their sub-elements, and the cross-cutting elements (materiality, staffing, supervision, specialists, communications, IT) that apply across all categories.
Classification of Audit Plan Components
Plan ComponentPurposeKey Considerations
Risk Assessment ProceduresObtain an understanding of the entity and its environment, including internal control, to identify and assess risks of material misstatement.Required on every engagement regardless of assessed risk. Includes walk-throughs, inquiries, and preliminary analytics.
Tests of ControlsEvaluate the operating effectiveness of controls the auditor intends to rely upon to reduce the assessed level of control risk.Required when (a) the auditor's risk assessment assumes controls are operating effectively, or (b) substantive procedures alone are insufficient. Must be performed each year for significant risks.
Substantive Procedures — Tests of DetailsDetect material misstatements at the assertion level through direct examination of transactions, balances, or disclosures.Vouching (testing existence/occurrence) and tracing (testing completeness) are directional. Confirmations, recalculations, and physical inspection are common techniques.
Substantive Analytical ProceduresDevelop an expectation of a recorded amount using plausible relationships among financial and non-financial data, then investigate significant differences.More effective for high-volume, predictable transactions (e.g., payroll). Must define a threshold for investigating differences and use reliable data.
Wrap-Up & CompletionAddress remaining requirements before forming the audit opinion, including subsequent events, going concern, management representations, and the overall analytical review.These procedures are often planned in the engagement timeline but may need to be adjusted based on findings during fieldwork.

Worked Example — Building an Audit Plan for Revenue

Consider an engagement to audit TechBright Inc., a mid-size software company that recognizes revenue from multi-element arrangements (subscriptions, professional services, and hardware sales). Revenue is a significant account with a presumed fraud risk under AU-C 240. The following worked example walks through how an auditor would construct the detailed audit plan for revenue.

Preparing the Detailed Audit Plan for TechBright Inc. — Revenue
1
Step 1 — Identify Relevant Assertions and Assess RisksBegin by listing the financial statement assertions relevant to revenue: occurrence, completeness, accuracy, cutoff, and classification. Based on understanding the entity, the auditor assesses occurrence (risk of fictitious revenue) as significant risk due to management incentives tied to revenue targets. Cutoff is assessed as high risk because TechBright recognizes multi-element arrangements and has historically made errors near period end. Completeness is assessed as moderate risk, and accuracy/classification as moderate.
Risk mapping: Occurrence = Significant; Cutoff = High; Completeness = Moderate; Accuracy = Moderate
2
Step 2 — Determine Planned Reliance on ControlsTechBright has automated controls in its ERP system that match sales orders to shipping documents before posting revenue. The auditor plans to rely on these controls to reduce substantive testing for the occurrence and cutoff assertions. This decision means the plan must include tests of controls. For the occurrence assertion (significant risk), controls must be tested in the current period—prior-period evidence cannot be relied upon.
Plan includes tests of IT general controls (ITGCs) and application controls for revenue recognition. Controls reliance planned for occurrence and cutoff.
3
Step 3 — Design Nature, Timing, and Extent of Tests of ControlsNature: Reperformance of the automated three-way match (sales order, shipping document, invoice) and inspection of system configuration settings. Timing: Test throughout the period by selecting samples from Q1 through Q4, ensuring the controls operated consistently. Extent: Because TechBright's automated control is programmed and unchanged during the year, a smaller sample (25 items) is appropriate for the application control, supplemented by testing ITGCs over change management.
Nature = Reperformance + Inspection; Timing = Throughout the year; Extent = 25 application control items + ITGC testing
4
Step 4 — Design Nature, Timing, and Extent of Substantive ProceduresEven with control reliance, substantive procedures are required for every significant account. For occurrence (significant risk): Vouch a sample of recorded revenue transactions to signed contracts, delivery evidence, and cash receipts (external confirmation for the top 10 customers). Perform the test at year-end rather than interim to address the higher risk. For cutoff: Select transactions in a window of ±5 business days around December 31 and verify that revenue is recorded in the correct period. For completeness: Trace a sample of shipping documents to recorded revenue entries. For accuracy: Recalculate the allocation of the transaction price in multi-element arrangements using standalone selling prices.
Substantive plan includes: vouching (occurrence), cutoff testing (±5 days), tracing (completeness), recalculation (accuracy), and confirmations (top 10 customers)
5
Step 5 — Determine Materiality and Sample SizesOverall materiality for the engagement is set at $500,000 (based on 5% of pre-tax income). Performance materiality is set at $375,000 (75% of overall materiality) to provide a cushion for undetected misstatements. Tolerable misstatement for revenue is $375,000. Using the audit risk model, the auditor calculates the required detection risk: AR (0.05) ÷ (IR (0.90) × CR (0.40 after control reliance)) = DR ≈ 0.139, or approximately 14%. This low detection risk translates to a substantive sample of roughly 60 vouching items for occurrence and 40 items for the cutoff test.
Materiality = $500,000; Performance materiality = $375,000; Detection risk ≈ 14%; Vouching sample = 60 items; Cutoff sample = 40 items
6
Step 6 — Document the Plan and Assign ResourcesThe completed plan for revenue is documented in the engagement workpapers, linking each procedure to the specific assertion and assessed risk it addresses. The engagement partner assigns a senior associate with software industry experience to lead revenue testing, a staff associate to perform the cutoff test, and requests the firm's IT audit specialist to test ITGCs. The timeline allocates three weeks of fieldwork in January, with interim controls testing completed in October. The plan also specifies escalation procedures if any exceptions are found—specifically, if more than one control deviation is identified, the auditor will expand the substantive sample by 50%.
Fully documented plan with risk-procedure linkage, staffing assignments, timeline, and contingency escalation procedures.

Strengths and Limitations of Detailed Audit Planning

Like any structured methodology, the detailed audit plan offers significant advantages but also carries inherent limitations. Understanding both sides is important for auditors who must exercise professional judgment in applying the planning framework—and for CPA candidates who are expected to recognize when planning may fall short.

Strengths and Limitations of the Detailed Audit Plan
StrengthsLimitations
Ensures comprehensive coverage of all significant accounts and assertions, reducing the risk of overlooking material misstatements.Can lead to a "checklist mentality" if auditors follow the plan mechanically without exercising professional skepticism.
Provides a clear roadmap for engagement team members, improving coordination, efficiency, and consistency of execution.Time-intensive to prepare, particularly for first-year engagements where the auditor has limited institutional knowledge.
Creates an auditable trail that supports supervisory review, quality control inspections, and regulatory inquiries.May become outdated quickly if the entity's circumstances change materially between planning and fieldwork, requiring costly revisions.
Facilitates early identification of resource needs—specialists, IT auditors, or component auditors—allowing timely scheduling.Over-reliance on prior-year plans for recurring engagements can introduce anchoring bias and cause the team to miss emerging risks.
Enables the engagement partner to set appropriate materiality levels and detection risk thresholds before testing begins.The audit risk model underlying the plan involves inherently subjective assessments of inherent and control risk, which can introduce inconsistency.
KEY TAKEAWAY
A detailed audit plan is like a flight plan filed by an airline pilot before takeoff. It maps the route, anticipated turbulence, fuel requirements, and alternate airports—but the pilot must still respond to unexpected weather in real time. Similarly, the audit plan provides essential structure and direction, but it is only as effective as the auditor's willingness to adapt it when conditions on the ground diverge from expectations. Professional skepticism is the compass that keeps the plan on course.

Connection to Advanced Theory — Integrated Audits and Group Audits

The principles of detailed audit planning extend naturally into more complex engagement structures. Two areas where planning becomes significantly more involved are integrated audits (audits of financial statements combined with audits of internal control over financial reporting under PCAOB AS 2201) and group audits (engagements involving component auditors under AU-C 600 or PCAOB AS 1205). Understanding these extensions helps you see how the foundational NTE framework scales to address real-world complexity.

Scaling the Detailed Audit Plan: Standard vs. Integrated vs. Group Audits
DimensionStandard Audit PlanIntegrated Audit PlanGroup Audit Plan
Scope of Controls TestingOptional—only if the auditor plans to rely on controls to reduce substantive testing.Mandatory and comprehensive—must test the design and operating effectiveness of controls over all significant accounts and relevant assertions.Depends on the group engagement partner's instructions to component auditors regarding reliance on component-level controls.
MaterialitySet at the financial-statement level with tolerable misstatement for individual accounts.Same financial-statement level materiality, but the ICFR opinion may require lower thresholds for evaluating control deficiencies.Group materiality is established, then component materiality is allocated—which must be lower than group materiality.
Staffing ComplexitySingle engagement team with potential specialist involvement.Requires IT auditors to test ITGCs and application controls; may involve internal audit reliance under AS 2201.16–19.Multiple component auditors across jurisdictions requiring coordination, quality oversight, and communication protocols.
Plan DocumentationStandard workpaper documenting NTE for each significant account.Dual documentation: one set for the F/S audit procedures and a parallel set for ICFR testing procedures, cross-referenced.Group engagement instructions to components, aggregation plan, and inter-office communication logs must all be documented.

As you progress beyond the fundamentals of AU-C 300 and AS 2101, you will encounter planning challenges that demand not only technical knowledge but also managerial skills—coordinating geographically dispersed teams, reconciling differing regulatory frameworks across jurisdictions, and exercising judgment on how much reliance to place on another auditor's work. The detailed audit plan, in these contexts, becomes a critical communication tool that ensures every participant in the engagement understands their role, the risk landscape, and the expected deliverables. These advanced topics frequently appear in AUD simulation questions, making a strong foundation in planning principles essential.

Practice Problems

PROBLEM 1CONCEPTUAL
Distinguish between the overall audit strategy and the detailed audit plan. Why does professional auditing literature require both, and how do they relate to one another?
PROBLEM 2BASIC CALCULATION
An auditor sets audit risk at 5%. Based on the understanding of the entity, inherent risk for the inventory existence assertion is assessed at 80%, and control risk is assessed at 50% because the entity has moderately effective inventory controls. Calculate the maximum acceptable detection risk and explain how this result influences the detailed audit plan.
PROBLEM 3INTERMEDIATE
During the planning phase for a retail client, the auditor discovers that the client implemented a new point-of-sale (POS) system mid-year. Explain how this change should affect the detailed audit plan with respect to: (a) tests of controls, (b) timing of substantive procedures, and (c) the need for IT specialists.
PROBLEM 4APPLIED
You are the senior on an engagement for a manufacturing company. The engagement partner informs you that overall materiality is $200,000 and performance materiality is $150,000. Revenue ($15 million) and accounts receivable ($3.2 million) are significant accounts. The client's largest customer represents 40% of revenue and has been experiencing publicized financial difficulties. Prepare a summary outline of the detailed audit plan for accounts receivable, specifying the assertions at risk, the nature of procedures, timing decisions, and extent considerations.
PROBLEM 5CRITICAL THINKING
A recurring audit client has had no material misstatements found in the prior three years. The new engagement partner proposes reducing the extent of substantive testing across all significant accounts by 30% and performing most procedures at an interim date three months before year-end to improve engagement efficiency. Critically evaluate this proposal. What risks does it introduce, and how would you advise the partner while still supporting the goal of efficiency?

Summary — Preparing the Detailed Audit Plan

The detailed audit plan operationalizes the overall audit strategy by specifying the nature, timing, and extent of audit procedures for each significant account and relevant assertion. Grounded in the audit risk model (AR = IR × CR × DR), the plan translates assessed risks of material misstatement into actionable procedures—tests of controls where reliance is planned, substantive procedures (both tests of details and analytical procedures) for every significant account, and wrap-up procedures that address subsequent events, going concern, and the overall analytical review.

Key principles to remember: the plan must be linked to specific assertions so no assertion is left untested; it is dynamic and iterative, requiring revision as new evidence emerges during fieldwork; and it must be documented in sufficient detail for supervisory review and regulatory inspection. Whether you are constructing a plan for a single-entity audit or scaling the framework to an integrated audit or group audit, the core NTE framework and its connection to the audit risk model remain the auditor's most important planning tools.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Audit Planning — Prepare Detailed Audit Plan