Two auditors plan the same procurement review. One writes the objective as "review procurement." The other writes "determine whether purchase approvals above $50,000 were obtained before commitment during the year ended December 31." Only the second one can be reported against, and only the second one tells you when fieldwork stops.
Engagement objectives are the statements of what the engagement will accomplish, phrased so a conclusion can be drawn against them. Engagement scope is the boundary: which processes, locations, systems, and time periods the work covers, and which it deliberately excludes. Objectives answer "what question are we answering." Scope answers "over what."
The Global Internal Audit Standards place both in the planning domain, with Standard 13.2 (Engagement Objectives and Scope) as the anchor. The chief audit executive owns the framework; the engagement supervisor and team draft the specifics.
KEY: Objectives must be derived from the risk assessment for the auditable area, not from the request that triggered the engagement. A stakeholder asks for the work; the risk assessment determines what the work asks.
Common mistakes
- Writing objectives that cannot be concluded against. "Review procurement" produces no conclusion. Objectives must name the criteria, the population, and the period, as in approvals above $50,000 during a stated year.
- Letting the requester set assurance objectives. In assurance work, objectives derive from the risk assessment. Only in advisory work are objectives agreed with the client.
- Treating a topical requirement as optional because your risk assessment ranked the element low. The requirement is a floor. Exclusion requires a documented rationale and chief audit executive approval, not a low risk score.
Bottom line
- Objectives state what the engagement concludes on; scope states the processes, locations, systems, and period covered and excluded.
- Assurance objectives come from the risk assessment; advisory objectives are agreed with the client and documented in an engagement understanding.
- Topical requirements set a mandatory floor for assurance engagements over the named topic; excluding a prescribed element needs a documented rationale and chief audit executive approval.
- Objective inputs: regulatory requirements, strategy and objectives, governance, risk management and control processes, risk appetite and tolerance, internal policies, previous audit reports, and other assurance providers' work.
Exam shortcut
Classify before you answer. Scan the stem for a third party receiving a conclusion. Present means assurance, so objectives come from risk assessment and topical requirements bind. Absent means advisory, so client agreement governs. Stem signals worth memorizing: "denied access" or "records unavailable" means scope limitation, and the first correct action is assess whether objectives can still be met, not report immediately.
The full lesson (about 2,393 words, 16 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
Browse all free CIA Part 2 lessons or jump into free CIA Part 2 practice questions.