How to prepare an audit Programme

An audit program, also called an audit plan, is an action plan that documents what procedures an auditor will follow to validate that an organization is in conformance with compliance regulations.

The goal of an audit program is to create a framework that is detailed enough for any outside auditor to understand what official examinations have been completed, what conclusions have been reached and what the reasoning is behind each conclusion. The framework should explain the audit's objectives, its scope and its timeline. The audit program should also describe how working papers -- the documented evidence of the audit -- will be collected, reviewed and reported.

Objectives of audit programs

When developing an audit program, the internal auditor and its associated audit team should start with outlining the audit's objectives, goals and obligations.

Audit program objectives help direct planning of the audit report and are based onthe policies, procedures and guidelines unique to the company. These objectives may relate to and outline how the auditors will maintain efficiency, professionalism and a specific code of conduct during audit procedure.

In addition to relevant regulatory compliance mandates, objectives for audit programs should consider aspects such as management priorities, business intentions, system requirements, business structure, legal and contractual mandates, the expectations of customers and other interested parties, potential risk management vulnerabilities, and any corrective action taken based on previous audits.

Preparing an audit program

Audit program details are specific to individual organizations based on their unique needs, but audit plan preparation will consider the audit's relevant regulatory deadlines, staff requirements and reporting structure, and overall goals.In particular, these goals will consider how the company will maintain regulatory compliance via risk assessment and management procedures. The audit program should also include a timeline detailing when specific aspects of the audit program should take place and how they should be prioritized.

Audit program planning is usually a continual and iterative process. During audit planning and development, companies can build on lessons learned from previous audits by implementing newly learned best practices that alleviate risk and maintain compliance. Audit development guidelines and best practices vary by industry, but local and regional auditing certifications are available, as are internationally recognized audit certifications. These certifications include Certified Internal Auditor and Certified Information Systems Auditor, and membership in the International Register of Certificated Auditors.

Types of audit programs

Different types of audit programs include standardized audit programs, tailored audit programs and compliance audit programs. Standardized audit programs, which are available for many different industries, can be used proactively to help an organization create its own internal compliance framework and internal audit program. For example, the International Federation of Accountants publishes financial audit standards called the International Standards on Auditing. A standardized audit program is different than a fixed audit program, which is defined as an audit program that cannot be changed during the course of an audit.

Tailored audit programs are different from standardized audit programs in that they cater audit procedures to match specific needs of the auditing entity.These audit programs are "tailored" to reference specific areas such as business procedures, legal documents and assets. By targeting these specific requirements through tailored audit programs, the company can more quickly identify potential compliance lapses and develop internal controls to offset these vulnerabilities.

A compliance audit program outlines how an organization will adhere to regulatory guidelines. The details of compliance audit program will vary depending upon factors such as whether an organization is a public or private company, what kind of data it handles and if it transmits or stores sensitive financial data. For instance, Sarbanes-Oxley Act requirements state that electronic communication must be backed up and secured with disaster recovery infrastructure, while financial services companies that transmit credit card data are subject to Payment Card Industry Data Security Standard (PCI DSS) requirements. In the Unites States, publicly traded companies must report results of internal control audits to the Securities and Exchange Commission (SEC). In each case, an organization's audit program outlines how the company will maintain compliance with regulatory compliance rules.

This was last updated in April 2017

Continue Reading About audit program (audit plan)

  • Health law expert: HIPAA's audit program serious business
  • HIPAA audit program scrutinizes 167 healthcare organizations
  • Family physicians: Meaningful use audits expensive, unhelpful
  • PCAOB AS2101: Audit planning
  • ISACA audit program based on NIST Cybersecurity Framework

Dig Deeper on Risk management and governance

  • How to prepare an audit Programme
    Tips to prepare for a network disaster recovery audit

    How to prepare an audit Programme

    By: Paul Kirvan

  • How to prepare an audit Programme
    security audit

    How to prepare an audit Programme

    By: Alexander Gillis

  • How to prepare an audit Programme
    How can organizations prepare for a data storage audit?

    How to prepare an audit Programme

    By: Paul Kirvan

  • How to prepare an audit Programme
    Sarbanes-Oxley Act (SOX) Section 404

    How to prepare an audit Programme

    By: Katie Terrell Hanna

What is audit Programme how it is prepared?

An audit program is a set of directions that the auditor and its team members need to follow for the proper execution of the audit. After preparing an audit plan, the auditor allocates the work and prepares a program which contains steps that the audit team needs to follow while conducting an audit.

How do you write an audit Programme?

Audit Program for Cash/Bank.
Check posting and balancing of Cash book..
Check petty cash book if maintained..
Check cash receipt with cash book..
Check cash payment voucher with relevant support bills..
Authorization of cash payments..
Check accounting for cheques/demand draft received..

How do you prepare audit procedures?

The Best Way to Formulate and Execute Audit Procedures.
Assess the risks of the specific area to be reviewed..
Develop a written work program..
Agree on scope, locations, sample sizes and period under review..
Develop a report format that will be effective..

What is an audit Programme?

An audit program is a system of audit objectives, scope, timeline, and activities that will be carried out by auditors. An audit program, also known as an audit plan, functions as a guide for conducting various types of audits in a company.