A warehouse engagement that counts inventory but never asks whether the enterprise resource planning system's access controls let a clerk create a vendor is not a risk-based engagement. It is a stock count with a cover page.
Planning identifies what could stop the activity from achieving its objectives, then identifies the controls management relies on to prevent that. Everything below is a source of candidate risks. Your job in planning is to gather them, rank them, and map each significant one to a control you will test.
KEY: Risks are identified against the objectives of the activity under review, never against the audit's own convenience. No objective, no risk. That ordering is the most tested idea in this scope.
A topical requirement is a mandatory element issued by The IIA that prescribes minimum coverage when an assurance engagement addresses a named subject such as cybersecurity or third-party management. Applying topical requirements when planning means running three checks.
- Applicability. Does the engagement cover the governance, risk management, and control elements of the named topic? Partial coverage triggers the requirement for the covered portion.
- Floor coverage. Every prescribed element becomes a planned procedure, or an exclusion is documented and approved by the chief audit executive.
Common mistakes
- Identifying risks before objectives. A list of process risks with no link to what the activity is trying to achieve cannot be prioritized. Read the strategic objectives first.
- Testing application controls while ITGCs are unassessed. If access and change management fail, a passing three-way-match test proves nothing.
- Treating backup completion as recovery assurance. Nightly job success against a 1-hour RPO still leaves up to 23 hours of data loss unaddressed.
Bottom line
- Objectives first, then risks to those objectives, then the key controls that mitigate them, then procedures.
- Topical requirements set a mandatory floor for assurance engagements over the named topic; partial coverage still binds, and exclusions need documented chief audit executive approval.
- Performance management incentives create risk; pair every KPI in the plan with a forward-looking KRI.
- ITGC families: access to programs and data, change management, program development, computer operations. Application control reliance depends on them.
Exam shortcut
Read the stem for the objective before you read the risk. If no objective appears, the correct answer is usually the option that establishes one. Signal-to-answer mapping worth memorizing. "Backups completed successfully" means the gap is untested recovery, not backup failure. "Collected additional customer fields for possible future use" means data minimization, a privacy principle, not a security control.
The full lesson (about 2,568 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 3
Browse all free CIA Part 2 lessons or jump into free CIA Part 2 practice questions.