,

GIAS Domain V: Performing Engagements From Planning to Closure

Domain V is where the Global Internal Audit Standards meet the engagement file. Performing Internal Audit Services covers three principles and fourteen standards that run from the first communication with the auditee to the confirmation that management did what it said it would, and every one of them corresponds to a document a reviewer can open: the notification, the engagement risk assessment, the objectives and scope, the criteria, the resource plan, the work program, the evidence, the analyses, the findings, the recommendations and action plans, the conclusion, the documentation, the final communication and the follow-up. This guide takes the domain standard by standard, with what each requires, the workpaper that evidences it and the gap a quality assessor usually finds, then adds the conformance mapping, an engagement conformance checklist, and a worked example that traces one engagement, a distributor’s route cash audit, through all fourteen standards.

This guide was rewritten in September 2026 from a shorter version published in August 2026. Standard titles and numbering follow the Global Internal Audit Standards as published by The IIA on 9 January 2024 and effective from 9 January 2025; requirement summaries are paraphrases for orientation.

In this guide

The domain at a glance: three principles, fourteen standards, fourteen workpapers

PrincipleStandardThe workpaper that evidences it
13. Plan Engagements Effectively13.1 Engagement CommunicationNotification and kickoff record; communication plan for the engagement
13.2 Engagement Risk AssessmentEngagement-level risk assessment
13.3 Engagement Objectives and ScopePlanning memo: objectives, scope, exclusions
13.4 Evaluation CriteriaCriteria stated and agreed with management
13.5 Engagement ResourcesBudget, staffing and skills for the engagement
13.6 Work ProgramThe work program with procedures linked to objectives
14. Conduct Engagement Work14.1 Gathering Information for Analyses and EvaluationEvidence: relevant, reliable, sufficient; population records; samples
14.2 Analyses and Potential Engagement FindingsAnalyses; potential findings with condition and criteria
14.3 Evaluation of FindingsFindings evaluated for significance; ratings
14.4 Recommendations and Action PlansRecommendations; management action plans with owners and dates
14.5 Engagement ConclusionsThe conclusion or opinion and its basis
14.6 Engagement DocumentationThe file: complete, reviewed, retained
15. Communicate Engagement Results and Monitor Action Plans15.1 Final Engagement CommunicationThe report: contents, distribution, conformance statement
15.2 Confirming the Implementation of Recommendations or Action PlansFollow-up process and the validation record

Principle 13: Plan Engagements Effectively

Standard 13.1, Engagement Communication, requires internal auditors to communicate with management of the activity under review throughout the engagement, starting with a notification of the engagement’s objectives, scope, timing and the people involved, and continuing with progress, potential findings and the results; the artifact is the notification and kickoff record, and the audit notification letter and kickoff template is its form. Standard 13.2, Engagement Risk Assessment, requires an assessment of the risks relevant to the activity under review, using the function’s understanding from Standard 9.1 and information gathered during planning, to determine the objectives, scope and the procedures that matter; it is the engagement-level counterpart of the plan’s risk assessment and the standard most often missing from files that otherwise conform, because functions assume the annual risk assessment covers it. Standard 13.3, Engagement Objectives and Scope, requires objectives that state what the engagement will conclude on and a scope that states what is included, what is excluded and why, including the period and the locations, with limitations disclosed; the artifact is the planning memo, which the planning memo template lays out.

Standard 13.5, Engagement Resources, requires the engagement to be staffed with people who collectively have the competencies it needs, in the time it needs, with external expertise obtained where the function lacks it; the artifact is the resource allocation in the planning memo and the co-source arrangement where there is one. Standard 13.6, Work Program, requires a work program that specifies the procedures for gathering evidence sufficient to achieve the objectives, approved before fieldwork begins and amended with approval when the engagement changes; the audit work program guide covers the structure and the walkthrough versus test of controls guide the procedure choice that most work programs get wrong.

Standard 13.1 in depth: communication as a thread, not an event

The engagement communication standard is written as a thread that runs the length of the engagement, and files that conform show four moments on it. The notification, which states the objectives, scope, timing, the auditors and what is requested of management, and which is sent early enough that management can prepare and object; the kickoff, at which the objectives and criteria are discussed, the process owner’s concerns heard and the logistics agreed, with a record kept; the progress communications, at a cadence agreed at kickoff, at which potential findings are discussed as they arise so that the facts are confirmed under Standard 14.2 and nothing in the draft report is a surprise; and the closing meeting, at which the findings, ratings and proposed actions are walked through with management before the draft is issued, with disagreements recorded. The Standards add a consideration that is easy to miss: communication runs to the board where the engagement’s results warrant it, and the CAE decides, during the engagement rather than after, whether a finding is one the audit committee should hear about before the report is final. The notification and kickoff template covers the first two moments, the auditee’s guide is what the auditee should have been told about all four, and the verbal communication guides cover the meetings themselves.

Two practices make the thread hold. The engagement keeps a communication log, a dozen lines in the planning memo, with the date, the parties and the substance of each significant exchange, so that the assessment can see the thread without reconstructing it from email. And the closing meeting’s record states what management agreed with, what it disputed and on what basis, so that the report’s management responses are the second statement of a position the file already holds rather than the first.

Standard 13.4 in depth: evaluation criteria

Standard 13.4 requires internal auditors to identify the criteria against which the activity will be evaluated: the policies, procedures, laws, regulations, contracts, standards and expectations that define what “should be”, agreed with management where possible, and, where management has not established criteria, the criteria the auditor selects and the basis for them, communicated to management. The standard exists because a finding is a difference between a condition and a criterion, and a finding with no stated criterion is an opinion. The artifact is a criteria statement in the planning memo listing, for each objective, the source of the criteria (the organization’s own policy, an external standard, a regulatory requirement, a benchmark, or the auditor’s professional judgment with its rationale) and the record of management’s agreement or disagreement. Three practices make the standard work. Where the organization’s own policy is the criterion and the policy is weak, the auditor evaluates the policy against an external standard as well and says so, so that conformance with a bad policy is not reported as good practice. Where the criteria are the auditor’s, they are stated before fieldwork, not constructed to fit the findings. And where management disagrees with the criteria, the disagreement is recorded and the report presents both positions, which is the honest form of a finding management does not accept. The CSF 2.0 assessment method is an extended example of turning an external framework into agreed criteria, and the Topical Requirement workbook shows the criteria a Topical Requirement imposes.

Principle 14: Conduct Engagement Work

Standard 14.1, Gathering Information for Analyses and Evaluation, requires internal auditors to gather information that is relevant, reliable and sufficient to achieve the engagement objectives: relevant in that it supports the objectives and the potential findings, reliable in that it comes from a source and by a method the auditor can trust, and sufficient in that a prudent, informed person would reach the same conclusion from it. The artifacts are the evidence itself, the population records that show where samples came from, and the notes that show how reliability was assessed, which the audit evidence guide, the IPE testing guide and the sampling memo template cover. Standard 14.5, Engagement Conclusions, requires a conclusion at the engagement level, on the objectives, that considers the findings’ significance in aggregate and is supported by them; where the function issues an opinion or rating, the rating methodology is applied and stated. Standard 14.6, Engagement Documentation, requires documentation that is sufficient to support the conclusions and the findings, allows an experienced reviewer to understand the work, is reviewed and retained under the function’s policy, with access controlled; the workpaper best practices guide and the workpaper example set the standard, and the walkthrough documentation template is the most-used single workpaper. The assessment of Principle 14 reads sampled files for the chain from objective to procedure to evidence to finding to conclusion, and breaks in the chain, a finding with no procedure behind it or a conclusion the findings do not support, are the observations it makes.

Documentation under 14.6 has one more requirement that files built on shared drives fail without noticing: access control. The standard expects the CAE to control access to engagement documentation, to have a retention policy consistent with the organization’s requirements and the law, and to obtain approval from the CAE, and where required legal counsel, before releasing documentation to parties outside the organization. The evidence is the audit management system’s access model or, for a function without one, a restricted evidence store with an access list and a log, together with the retention schedule and the record of any external release; the workpaper best practices guide covers the practical arrangements, and the confidentiality standards in the Domain II guide are the reason the requirement exists.

Standards 14.2 to 14.4 in depth: from analysis to action plan

The three middle standards of Principle 14 describe the arc of a finding. Standard 14.2, Analyses and Potential Engagement Findings, requires the auditor to analyze the information gathered to identify potential findings, described as a difference between the condition and the criteria, with the cause and effect where determinable, and to discuss potential findings with management to confirm the facts. Standard 14.3, Evaluation of Findings, requires each finding’s significance to be evaluated, considering its impact, likelihood and the organization’s risk appetite, and rated on the function’s scale, with root cause identified where the finding’s remediation depends on it; the 5 Cs of audit findings guide gives the finding its structure (condition, criteria, cause, consequence, corrective action), the root cause analysis guide the cause, and the finding severity ratings guide the scale. Standard 14.4, Recommendations and Action Plans, requires the auditor to develop recommendations, or to obtain management’s action plans, that address the root cause, with management’s response, the owner and the target date recorded, and, where management declines to act, the acceptance of risk documented and handled under Domain IV’s Standard 11.5.

The arc has two discipline points a reviewer checks. The first is that the potential finding was confirmed with management before it became a finding: the standard requires the facts to be discussed, and a file that shows the finding appearing in the draft report with no record of the conversation has skipped a step that later becomes an argument. The second is that the action plan addresses the cause the finding names, not the symptom: a finding whose cause is an undesigned delegation rule and whose action plan is “retrain the approvers” will recur, and the follow-up under 15.2 will record it as implemented and ineffective, which is the worst outcome for everyone.

Standard 14.5 in depth: conclusions, opinions and the rating rule

The conclusion is the sentence the engagement exists to produce, and Standard 14.5 requires it to be stated at the engagement level, on the objectives, and to be supported by the findings taken together. Where the function issues an engagement rating or opinion (Satisfactory, Needs Improvement, Unsatisfactory, or whatever scale the function uses), the standard’s consideration is that the methodology for reaching it be documented and applied consistently, which in practice means a rule that connects the findings’ ratings to the engagement rating and that the audit committee has seen. The rule matters because it takes the engagement rating out of negotiation: MidState’s rule, agreed with its committee, is that an engagement is Unsatisfactory when a High finding shows a key control not operating across a material part of the scope, and Needs Improvement when High findings exist but the control layer as a whole still functions, which is what turned five findings into the Unsatisfactory opinion in the worked example and what allowed the cybersecurity program audit, with six High findings, to be rated Needs Improvement, as the cybersecurity program audit guide explains. The conclusion also has to answer the objectives as written: an engagement whose objective was to conclude on the design and operation of controls over route cash concludes on exactly that, and a report that concludes on something broader, or narrower, has changed the scope without saying so. The finding severity ratings guide covers the finding scale and the aggregation rule, and the report writing guide the placement of the conclusion at the top of the report where the reader will see it.

Principle 15: Communicate Engagement Results and Monitor Action Plans

Standard 15.1, Final Engagement Communication, requires a final communication that includes the objectives, scope and conclusions, the findings with their significance, the recommendations or action plans, and management’s responses; that is accurate, objective, clear, concise, constructive, complete and timely under Standard 11.2; that is distributed to the parties who can ensure the results receive due consideration; and that states whether the engagement was conducted in conformance with the Standards, with any nonconformance disclosed. Where an engagement covered a Topical Requirement, the conformance statement includes it. The internal audit report template and the report writing guide carry the form, and the report examples show finished ones. Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, requires the CAE to establish a process to monitor and confirm implementation, with confirmation proportionate to the significance of the finding (inquiry for low, validation testing for high), results reported to senior management and the board, and unimplemented actions escalated, with the acceptance of risk handled under 11.5 where management decides not to act; the issue validation guide covers the confirmation and the issue log template the tracking. The assessment of 15.2 is the one that most often finds partial conformance, because functions track actions and rarely confirm them, and because the escalation of overdue actions to the board happens in a footnote or not at all.

Supervision and review inside the engagement

Domain V does not have a supervision standard of its own; supervision lives in Domain IV’s Standard 12.3 and in the documentation standard’s requirement that the file be reviewed, and the assessment tests it in the engagement file. The pattern that conforms has three levels: the in-charge auditor reviews every workpaper prepared by others before it supports a finding; the engagement manager reviews the planning memo before fieldwork, the findings before the closing meeting and the file before the report; and the CAE reviews the report and, on a risk basis, the file. Each review leaves evidence, which is not a signature but review notes: the questions asked, the answers, the changes made and the date cleared. A file with sign-offs and no notes has evidence that someone was present, not that anyone reviewed. Timing is the second test: review that happens after the report is issued has not supervised the engagement, and the assessment compares review dates to the report date. The third test is that review notes were cleared rather than deleted, because a cleared note shows what the reviewer challenged and how it was resolved, which is the evidence of professional skepticism the Domain II guide describes. Small functions where the CAE is also the in-charge auditor conform by having the manager or a peer review the CAE’s own workpapers, and by saying so in the manual.

Standard 15.2 in depth: confirming, not tracking

The follow-up standard is the one most functions partially conform with, and the reason is a single word: confirm. Tracking an action means recording that management said it was done. Confirming it means the function established that it was done and that it addressed the finding, with the method proportionate to the finding’s significance: inquiry and a document for a Low, inspection of the changed control for a Medium, and re-testing for a High, on a sample sized to the control’s frequency as the sample sizes guide sets out. The process the standard requires has five parts: a register of every action with owner, date and significance; a validation approach set when the action is agreed, not when it falls due; the validation performed at or after the due date, with its evidence in a workpaper; reporting to senior management and the board of the status of actions, including those past due; and escalation of overdue or ineffective actions, with management’s decision not to act treated as an acceptance of risk under Standard 11.5. Three failure patterns recur. Actions closed on management’s confirmation alone, which the assessment finds by asking for the validation workpaper. Due dates extended repeatedly without the extensions reaching the board, so that an action three years old shows as “in progress”. And actions validated as implemented that did not fix the finding, because the action addressed the symptom, which the issue validation guide treats as the central test: was the control now operating, and would it have prevented the condition the finding described? The issue log template carries the fields that make the five parts visible, and a function that reports the past-due list to its audit committee every meeting, by name, rarely has one.

Evidence of conformance and the common gaps

StandardEvidence in a conforming fileWhere files usually fall short
13.1 CommunicationNotification with objectives, scope, timing, people; kickoff record; progress communications; closing meeting recordNotification sent; nothing recorded between kickoff and draft report
13.2 Engagement risk assessmentDocumented assessment of the activity’s risks driving objectives and proceduresAbsent; the annual risk assessment assumed to cover it
13.3 Objectives and scopePlanning memo with objectives, scope, exclusions with reasons, period, locations, limitationsScope stated as a process name; exclusions unstated
13.4 CriteriaCriteria per objective with sources; management’s agreement or disagreement recordedCriteria implied by the findings rather than stated before fieldwork
13.5 ResourcesBudget, staffing and skills; external expertise arrangedStaffing by availability; skills gaps unaddressed
13.6 Work programProcedures linked to objectives and risks; approved before fieldwork; amendments approvedLast year’s program reused; amendments unrecorded
14.1 Gathering informationPopulation records with completeness checks; sampling design; reliability assessed; evidence retainedSamples from unreconciled populations; management assertions as evidence
14.2 Analyses and potential findingsAnalyses; condition and criteria for each potential finding; management discussion recordedFindings appearing first in the draft report
14.3 Evaluation of findingsSignificance evaluated; rating on the scale with rationale; root causeRatings without rationale; cause stated as the condition restated
14.4 Recommendations and action plansRecommendations addressing cause; management responses with owners and dates; accepted risks recordedAction plans that treat symptoms; no owner or date
14.5 ConclusionsEngagement conclusion on the objectives; rating methodology appliedReport with findings and no conclusion, or a conclusion the findings do not support
14.6 DocumentationComplete file; review evidence; retention; access controlEvidence in mailboxes; reviews unsigned; files never closed
15.1 Final communicationReport with all required elements; distribution record; conformance statementNo conformance statement; distribution decided by management
15.2 Confirming implementationFollow-up process; validation proportionate to significance; reporting to board; escalation of overdue actionsTracking without validation; overdue actions not escalated

Advisory engagements and the Topical Requirements

Domain V applies to advisory engagements with the adjustments the Standards describe: the objectives and scope are agreed with the party requesting the service, the criteria may be the requester’s own goals, the communication is to the requester, and the conclusion may be advice rather than an opinion, but the risk assessment, the work program, the evidence standard and the documentation requirements apply. A function that treats advisory work as exempt from the domain produces files that cannot show what was done, and an advisory engagement in an area the function later audits raises the objectivity questions the Domain II guide covers. The Topical Requirements add a layer to assurance engagements on their subjects: mandatory for assurance and recommended for advisory, each requirement assessed or documented as not applicable, with conformance documented under 14.6 and stated under 15.1; the Topical Requirements guide covers the family, and the cybersecurity requirement is the one most functions meet first.

The engagement conformance checklist

One checklist per engagement, completed by the reviewer at file close and used by the QAIP’s ongoing monitoring under Standard 12.1. It is deliberately short; the detail sits in the workpapers it references.

Engagement conformance checklist (Domain V)

Planning. 13.1 Notification issued with objectives, scope, timing and people; kickoff and closing meetings recorded. 13.2 Engagement risk assessment documented and used. 13.3 Objectives, scope, exclusions, period, locations and limitations in the planning memo. 13.4 Criteria stated per objective with sources; management agreement recorded. 13.5 Resources and skills assigned; external expertise arranged where needed. 13.6 Work program approved before fieldwork; amendments approved.

Fieldwork. 14.1 Populations reconciled; sampling designed and documented; evidence relevant, reliable and sufficient; IPE tested. 14.2 Analyses documented; potential findings with condition and criteria; facts confirmed with management. 14.3 Findings rated with rationale; root cause identified. 14.4 Recommendations address cause; action plans with owner and date; accepted risks recorded. 14.5 Engagement conclusion stated and supported; rating methodology applied. 14.6 File complete, reviewed with evidence of review, retained, access controlled.

Reporting and follow-up. 15.1 Final communication with objectives, scope, conclusion, findings, action plans, responses; quality criteria met; distribution recorded; conformance statement included (Standards and any Topical Requirement). 15.2 Actions entered in the follow-up process with validation approach set by significance.

Topical Requirement (if applicable). Requirements assessed or documented as not applicable; conformance record filed.

Sign-off. Reviewer; date; observations for the QAIP.

Worked example: MidState Beverage’s route cash audit through fourteen standards

MidState Beverage, the illustrative three-state drinks distributor used across this site, runs 300 routes from 12 depots and collects about $31 million a year in cash and checks. Its FY27 route cash audit, reported as FY27-01 and shown in full in the report examples guide, was the first engagement the function’s new quality program assessed against Domain V, and the assessment traced the file through all fourteen standards. The table is the trace.

StandardWhat the file showedAssessment
13.1Notification to the operations director and depot managers with objectives, scope, timing and the team; kickoff at three depots; weekly progress notes; closing meeting with the COO recordedConforms
13.2Engagement risk assessment identifying driver-collected cash, depot reconciliation independence, override approvals and customer statements as the risks; used to set objectivesConforms
13.3Planning memo with four objectives, scope of all 12 depots and 300 routes for the fiscal year, exclusion of the two acquired distributors’ routes with the reason (separate systems, covered in the integration engagement)Conforms
13.4Criteria stated: the cash handling policy, the depot procedure, the delegation of authority for overrides, and, for statement practice, the auditor’s criterion with rationale; management agreed except on the statement criterion, recordedConforms; the disagreement recorded is cited as good practice
13.5520 hours budgeted, 548 used; one senior reassigned for objectivity (see the Domain II guide); analytics auditor assigned for the override population workConforms
13.6Work program approved before fieldwork; amended once to add the override routing test after the walkthrough, with approvalConforms
14.1Populations reconciled (37,400 overrides; 4,200 customers; ~3,000 reconciliations); 60 reconciliations stratified five per depot; 70 monetary-unit selections at a $134,600 interval on $9,421,880 plus 20 targeted confirmations; IPE testedConforms
14.2Analyses documented; five potential findings with condition and criteria; facts confirmed with depot managers and the operations director before the draftConforms
14.3Findings rated (two High, three Medium) with rationale; root causes stated (a workflow routing rule; a depot administrator role designed for one person)Conforms
14.4Eleven actions with owners and dates addressing causes; the COO’s acceptance of residual risk on part of F5 recorded and escalated under 11.5Conforms
14.5Unsatisfactory opinion under the rating methodology agreed with the audit committee; basis statedConforms
14.6File complete in the audit management system; review notes cleared; two walkthrough workpapers missing the reviewer’s sign-off at closeConforms with an observation
15.1Report with all elements; distributed to the COO, CFO, CEO and the committee; conformance statement includedConforms
15.2Actions in the issue log; validation approach set (testing for the two High findings); at the assessment date, 3 of the function’s 14 open actions across engagements were past due without escalation to the committeePartially conforms (function-level); escalation rule added, past-due actions reported at the next meeting

The engagement conformed on thirteen standards, with an observation on documentation and a partial conformance on follow-up that was a function-level gap rather than this engagement’s: the tracking existed, the validation approach existed, and the escalation of overdue actions to the audit committee did not. That result, one of the three partial conformances the QAIP playbook records for MidState’s first assessment, is typical, and the fix, an escalation rule in the manual and a standing agenda line for past-due actions, took an afternoon. The file’s strength was the chain: every finding traced back through a procedure in the approved work program to an objective in the planning memo and forward to a rated finding, an action plan with an owner, and a conclusion the findings supported, which is what Domain V asks for in fourteen different ways.

Common mistakes

Skipping the engagement risk assessment because the annual one exists. Stating scope as a process name with no exclusions. Discovering the criteria after the findings. Reusing last year’s work program without approval of the changes. Sampling from populations nobody reconciled. Putting findings in the draft report before discussing the facts. Rating without rationale and naming the condition as the cause. Writing action plans that treat symptoms. Issuing reports with findings and no conclusion. Leaving the conformance statement out, or including it when the file cannot support it. Tracking actions without validating them. Never escalating overdue actions. And treating advisory engagements as outside the domain. The Domain IV guide covers the methodologies these standards are implemented through, the IPPF-to-GIAS mapping the old 2200 to 2600 series standards this domain descends from, and the QAIP self-assessment template the annual review in which the engagement checklists are aggregated.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading