, ,

The Engagement Planning Memo Template (Annotated): Eight Sections Mapped to GIAS 13.1–13.6

The planning memo is the contract for an engagement — between the team and its manager about what will be done, between the function and the auditee about what will be examined, and between this audit and the plan that authorized it. When it is good, fieldwork runs on rails: everyone knows the objective, the scope is a sentence someone can defend, and the criteria were agreed before a single test ran. When it is bad — boilerplate objectives, a scope that means whatever the senior decides in week three, no criteria at all — the engagement spends its last two weeks arguing about things the memo should have settled in its first two pages.

This guide was rewritten in September 2026 to map every section of the memo to the Global Internal Audit Standards’ engagement-planning requirements (13.1 to 13.6), to add variants for advisory, SOX and technology engagements, and to add the review checklist a manager uses before signing. The template itself is unchanged in substance, because it has held up in review: it is the memo that a first-year senior can complete and a director can sign, and every section answers a question the Standards now ask in so many words.

This is the memo in full: eight sections with model language in the shaded blocks, drafting guidance under each, and a worked example that continues the Templates Suite’s thread — MidState Beverage’s route cash-handling audit, engagement #1 from the annual plan template, which goes on to the walkthrough, the report, and the issue log. The memo’s eight sections map almost one-to-one onto the six planning standards in Domain V — which is not a coincidence, and is noted where it helps.

In this guide

What the memo has to settle — and who signs it

Five things get settled in a planning memo, and each has a reader who will hold you to it. The objective — the question the audit answers — is the sentence the final report must close against (Standard 14.5), so it is written for the manager who will review that report. The scope and its exclusions are written for the auditee, who otherwise learns the boundaries in the exit meeting. The risk assessment and criteria are written for the team, because they are what make the work program derivable rather than inherited — and criteria agreed with management in planning (13.4) are what stop findings from dying in draft review. The approach and milestones are written for everyone’s calendar. And the budget and approvals make it a governance document: the manager’s sign-off means the function has committed resources to a specific question with a specific boundary. Two signatures at the bottom — engagement lead and audit manager — are the minimum; the strongest functions also send the objective and scope sections to the auditee executive in advance, so the first meeting is a confirmation rather than a negotiation.

What the Standards require the memo to show: 13.1 to 13.6, section by section

The Global Internal Audit Standards, effective January 2025, turned the planning memo from good practice into evidence. Principle 13, Plan Engagements Effectively, has six standards, and an external quality assessor reading an engagement file will look for each of them in the planning documentation, because the Standards’ own examples of evidence of conformance are the memo’s sections. The table maps each standard to the section of the template that evidences it and to the question the assessor asks; the detailed treatment of the engagement standards is in GIAS Domain V, and the quality program that checks conformance in the QAIP playbook.

StandardWhat it requiresTemplate section that evidences itThe assessor’s question
13.1 Engagement CommunicationCommunication with management about the engagement’s objectives, scope, timing and expectations, before and during the workSection 1 (background and context), Section 7 (milestones, communication and deliverables), the approval block in Section 8When did the auditee learn the objectives and scope, and how is that evidenced?
13.2 Engagement Risk AssessmentAn assessment of the risks relevant to the activity under review, drawing on the organisation’s own assessment and the auditor’s understanding, to inform objectives and scopeSection 4 (engagement risk assessment: the table of risks with inherent ratings and expected controls)Which risks drove the scope, and where did they come from?
13.3 Engagement Objectives and ScopeObjectives that state what the engagement will conclude on, and a scope that states what is included and excluded, with the reasonsSections 2 (objectives) and 3 (scope and exclusions)Can the objectives be answered yes or no, and is every exclusion justified?
13.4 Evaluation CriteriaCriteria against which the activity will be evaluated, agreed with management where appropriate; for advisory engagements the criteria may be developed with managementSection 5 (criteria: policies, standards, regulations, management’s own targets)What is “good”, and did management agree it before testing began?
13.5 Engagement ResourcesResources appropriate to the objectives: hours, skills, specialists, toolsSection 8 (team, budget and approvals: hours by phase, specialists, tools)Were the skills and hours matched to the risks, and what was the basis?
13.6 Work ProgramA documented program of procedures to achieve the objectives, approved before fieldwork and updated as the engagement proceedsSection 6 (approach and test summary, cross-referenced to the work program) and the approval blockWas the program approved before fieldwork, and does each test trace to an objective and a risk?

Two practical consequences. The memo must be signed before fieldwork starts, by the manager or the CAE as the methodology provides, and the signature date is the evidence; a memo signed after the closing meeting fails 13.6 however good it is. And the memo must be re-issued when the scope changes materially, because the Standards’ requirement is that the documented plan reflects the engagement as performed; the section on re-issue below covers how, and the work program it points to is set out in the audit work program guide.

The template, annotated: eight sections

Section 1 — Background and context

1. Background. This engagement is [plan item #] in the approved [year] internal audit plan, addressing [risk theme]. [Process/area] is [two or three sentences: what it is, its scale in the organization’s terms — volume, value, headcount — who owns it, and the systems it runs on]. Relevant recent history: [prior audit and date, open findings, known incidents, changes in the period — system, leadership, structure]. Management contacts: [executive sponsor; process owner; day-to-day contact].

Drafting guidance. Three short paragraphs, not three pages: the plan reference (traceability back to the risk that authorized this), the process in numbers (an auditor who cannot state the volume and value of what they are auditing has not started), and the history that shapes the approach — open findings from last time belong here because they shape scope (Section 3) and follow-up procedures. Name the contacts; a memo without named people is a memo nobody has talked to yet. This section is the written form of Standard 13.1’s engagement communication — it should read as though the conversation with management has already happened, because it should have.

Section 2 — Objectives

2. Objectives. The objective of this engagement is to assess whether [the process] [achieves a specific outcome — e.g., is designed and operating to ensure that X is complete, accurate, and timely / that risk Y is managed within appetite]. Specifically, the engagement will conclude on: (a) [sub-objective one, phrased as a question the work will answer]; (b) [sub-objective two]; (c) [sub-objective three]. The engagement will not conclude on [adjacent matters deliberately out of objective].

Drafting guidance. One primary objective, written as something you can conclude on, plus two to four sub-objectives phrased as questions — because the final report’s conclusion section (14.5) is literally the answers to these questions in order, and a memo that lists activities (“review controls over cash”) instead of questions (“is cash collected on routes completely deposited within one business day?”) produces reports that list activities too. The negative sentence is not optional: stating what you will not conclude on is the single cheapest scope defense available, and it forces the team to decide it now.

Section 3 — Scope and exclusions

3. Scope. The engagement covers [organizational scope: entities, locations, business units], [process scope: from step A through step B], [system scope], for the period [start] to [end]. Sampling will draw from the full period unless stated in Section 6. Exclusions: [item] — [reason: covered by another engagement / other assurance provider / outside the risk that drove the plan item / to be addressed after a pending change]; [item] — [reason]. Scope changes during fieldwork will be documented as an addendum to this memo and approved by [audit manager]; changes affecting the objectives or timeline will be communicated to [sponsor].

Drafting guidance. Scope is four dimensions — organizational, process (name the start and end steps), system, and period — and memos that specify only two are the ones that get renegotiated mid-fieldwork. Every exclusion carries a reason, and the reasons are drawn from a short legitimate list; “out of scope” with no reason is a decision nobody made. The change-control sentence is the memo’s own governance: scope creep and scope shrink both leave a paper trail, which is exactly what you want when the auditee asks in week six why you’re looking at the acquisitions. This section and the next are where the scope-out log discipline from ITGC scoping applies at engagement level.

Section 4 — Engagement risk assessment

4. Risk assessment. The following risks were identified for the process in scope, from [walkthrough / management discussion / prior findings / data profiling], and drive the approach in Section 6:

#Risk (what could go wrong)Inherent ratingExpected controlsAddressed by (Section 6 ref.)
[R1][Specific, in the process’s own terms][H/M/L][The controls that should mitigate it][Procedure #]
[R2][…][…][…][…]

Drafting guidance. This table is the engine of the memo — Standard 13.2 made it mandatory, and the work program (13.6) is derived from it row by row. Write risks as events in the process’s language (“cash collected on a route is not deposited”), not as control absences (“lack of reconciliation”), because the risk is what you are protecting against and the control is one of several ways to do it. The “addressed by” column is the traceability that lets a reviewer see every risk has a procedure and every procedure has a reason; a risk with no procedure is a scope decision that needs a sentence in Section 3. Keep it to the six to ten risks that matter — a twenty-row table is a sign nobody prioritized.

Section 5 — Evaluation criteria

5. Evaluation criteria. Controls and outcomes will be evaluated against: [internal policy — name, version, date]; [procedure or SLA — name]; [regulatory or contractual requirement, if any]; and, where internal criteria are silent, [recognized framework or practice — named]. Management [confirmed the criteria as appropriate on [date] / has been asked to confirm the criteria by [date]]. Where management and internal audit disagree on criteria, the disagreement will be documented here and resolved by [audit manager and sponsor] before fieldwork.

Drafting guidance. The most-skipped section and, since Standard 13.4, the most-tested one. Criteria are what “good” means for this engagement — and a finding written against criteria management confirmed in planning has nowhere to hide in the exit meeting, while a finding written against criteria the auditor invented in week four is a negotiation. Name documents with versions; “the policy” is not a criterion. Where the organization has no policy, say which external practice you’ll use and get management’s nod on it — the nod is the point.

Section 6 — Approach and key procedures

6. Approach. The engagement will [walk through the process end-to-end to confirm design (Section 4 risks R1–Rn), then test operating effectiveness over the period]. Key procedures: (1) [procedure — addresses R#; nature: inquiry/observation/inspection/re-performance/analytics; extent: sample size or full population]; (2) […]; (3) […]. Data required: [extracts, sources, and the completeness step for each]. Analytics: [tests to be run on the full population, with the tool]. Reliance: [any work of others relied upon and the basis]. The detailed work program is at Appendix A and will be approved before fieldwork begins.

Drafting guidance. The memo carries the approach at summary level — five to eight key procedures, each tagged to a Section 4 risk with its nature and extent — and points to the work program for the detail. Two disciplines separate strong approach sections: the data paragraph names the completeness step for every extract (the IPE obligation written into the plan, not discovered in review), and the analytics sentence commits to full-population tests where the data allows, so “we sampled 25” is a choice rather than a default.

Section 7 — Milestones, communication, and deliverables

7. Timeline and communication. Kickoff with management: [date]. Fieldwork: [start]–[end]. Status updates to [contact] [weekly / at milestones]; potential findings communicated as identified, no later than [end of fieldwork]. Draft report to management: [date]; management response due: [date]; exit meeting: [date]; final report issued: [date] to [distribution]. Deliverables: [final report per the house template; management action plans; follow-up validation scheduled for [quarter]].

Drafting guidance. Dates, not durations — a memo that says “four weeks of fieldwork” has not been scheduled. The no-surprises commitment (“potential findings communicated as identified”) belongs in writing here because it is the promise that makes exit meetings civil, and putting it in the memo means the auditee agreed to it before the first finding existed. Name the report format and the follow-up quarter: the report template and the issue log are downstream of this sentence.

Section 8 — Team, budget, and approvals

8. Resources and approval. Engagement lead: [name]. Team: [names and roles]; specialist support: [co-source / guest auditor, scope of their work]. Independence: [each team member has confirmed no impairment for this engagement / the following safeguard applies: …]. Budget: [H] hours ([plan allocation] / [variance and reason]), by phase: planning [H], fieldwork [H], reporting [H], follow-up [H]. Prepared by: [lead, date]. Approved by: [audit manager, date]. Objective and scope shared with [sponsor] on [date].

Drafting guidance. The independence line is the Domain II per-engagement declaration, and it should be a real sentence per person, not a checkbox — the auditor who came from the process being audited gets a named safeguard here. Budget by phase exposes the classic optimism (reporting and follow-up under-allocated) before it becomes an overrun. Two signatures and the date the sponsor saw the scope: that last item is the one that changes exit-meeting dynamics most.

Worked example: MidState’s route cash-handling audit

1. Background. Plan item 1 of the FY27 plan, addressing risk theme 1 (cash custody at the route level). MidState’s 300 delivery routes serve roughly 4,200 smaller customers who pay by cash or check on delivery — about $31 million annually, 14% of revenue — collected by drivers, turned in at twelve depots, and deposited by depot clerks. Route settlement runs in the 2013 ERP’s route-accounting module with a spreadsheet reconciliation at each depot. Last audited FY23 (two moderate findings, closed); a driver theft at the Dayton depot in FY26 ($18,400, detected by a customer complaint) prompted management’s request to accelerate this audit. Sponsor: VP Operations. Process owner: Director of Route Accounting.

2. Objectives. To assess whether cash and checks collected on delivery routes are completely and timely deposited, and whether the controls over route settlement would detect and prevent skimming and lapping. Specifically: (a) is every collection recorded to the customer account and settled to the depot the same day? (b) are depot deposits complete against settlements, and reconciled by someone other than the depot clerk? (c) would the monitoring in place detect a driver skimming or lapping within one billing cycle? The engagement will not conclude on pricing, credit, or fleet matters.

3. Scope. All twelve depots and 300 routes; process from customer collection through depot settlement and bank deposit to customer-account application; the route-accounting module, depot reconciliation spreadsheets, and bank feeds; the period 1 January–31 December FY26 for testing, with observation of current-state procedures at three depots (Dayton, Toledo, Fort Wayne) in Q1 FY27. Exclusions: customers on credit terms (no collection at delivery — covered in the FY28 revenue audit); the two acquired entities’ routes (separate integration engagement, plan item 2).

4. Risks (abbreviated). R1 — collection taken but not recorded to the customer account (skimming); R2 — collection recorded but deposit short (depot-level theft); R3 — collections applied to the wrong customer to cover earlier theft (lapping); R4 — deposits delayed beyond one business day; R5 — depot reconciliation performed by the clerk who deposits (no segregation). 5. Criteria. Route Cash Handling Policy v4 (Jan FY25); Depot Settlement Procedure (rev. FY26); same-day settlement and next-day deposit SLAs — confirmed with the Director of Route Accounting on 12 January. 6. Approach (key procedures). (1) Walkthrough at Dayton, settlement to deposit (design, R1–R5); (2) full-population analytics: settlement-to-deposit matching for all depots, all year, with timing gaps and shortfalls flagged (R2, R4); (3) customer-account analytics: unapplied cash aging and payment-application sequences by route (R1, R3); (4) sample of 40 route settlements traced to customer payment evidence (R1); (5) surprise cash counts at three depots (R2); (6) segregation review of depot roles in the ERP (R5). Data: route settlement file, deposit file, bank feed, customer application log — each reconciled to the GL cash-receipts total for completeness.

Sections 7 and 8 carried dates from 12 January to a 21 March final report, a 520-hour budget split 60/320/100/40 across phases, a three-person team with one independence safeguard (a senior who had transferred from route accounting two years earlier was assigned to the acquisition engagement instead), and the sponsor’s confirmation of objectives and scope on 15 January. What this memo does that weak ones don’t: the objectives are questions the report will answer; every risk has a procedure; the criteria are named documents management confirmed; and the analytics commit to the full population, which is what let the team find what the sample never would. The engagement’s walkthrough is the next artifact in the suite.

Adapting the memo: advisory, SOX, technology and investigation engagements

The eight sections are written for an assurance engagement over a business process, which is most of what a function does. Four other engagement types use the same skeleton with predictable changes, and the changes are where reviewers find the gaps: an advisory memo with assurance objectives, a SOX memo with no link to the scoping decision, a technology memo with a scope defined by systems rather than risks, an investigation memo that reads like an audit. The table sets out what changes in each.

Engagement typeWhat changes in the memoSections most affectedThe gap reviewers find
Advisory (consulting)Objectives describe the advice to be given, not the conclusion to be reached; criteria are developed with management under Standard 13.4; the deliverable is a report of observations and options rather than findings with ratings; independence safeguards for any later assurance over the same area are stated2, 5, 7Assurance language in an advisory memo, which later lets management treat the advice as an opinion, or the reverse
SOX and ICFR supportBackground cites the scoping memo and the key-control population; objectives are stated per control or process; criteria are the control descriptions and the deficiency framework; approach states the reliance the external auditor will place and the timing of interim and roll-forward testing; see SOX scoping1, 2, 5, 6, 7No traceability from the memo to the scoping decision, so nobody can say why these controls and not others
Technology (ITGC, application, cyber)Scope is defined by systems and control layers and reconciled to the technology universe; the risk assessment names the systems and their dependence; criteria cite the frameworks (the organisation’s standards, ISO/IEC 27001, NIST, COBIT) and the version; the approach states the test-of-one logic for automated controls and the sampling for manual ones, as in the IT audit plan guide and testing automated controls3, 4, 5, 6A scope written as a list of systems with no risk behind the list, and criteria cited without a version
Investigation or special reviewBackground states the allegation or trigger and the authority under which the review is conducted; objectives are questions of fact; scope is the period, the population and the parties; criteria include the policy breached and the legal standard; approach covers evidence preservation, confidentiality and counsel’s involvement; distribution is restricted; the protocol in the CFE guide applies1, 2, 3, 6, 7, 8An investigation memo circulated like an audit memo, to the people under review
Follow-up and validationBackground lists the findings and actions in scope; objectives are whether each action was implemented and is effective; criteria are the agreed action plans; approach states the evidence standard for closure, as in the issue validation guide1, 2, 5, 6Validation planned as a re-audit, or as a conversation

The manager’s review checklist: fifteen questions before signing

A memo is signed by someone who did not write it, and the signature means the signer would defend the plan to the audit committee. The checklist below is what a manager or CAE works through before signing; it takes twenty minutes on a good memo and produces most of the questions a senior needs to answer on a weak one. Each question traces to a section and, through the mapping above, to a standard.

1. Does the background say why this engagement is in the plan now, with a reference to the risk assessment or the request that put it there? 2. Can each objective be answered with a conclusion, and is the number of objectives three or fewer? 3. Does the scope state the period, the units, the processes and the systems, in one paragraph a non-auditor could read? 4. Is every exclusion justified in a sentence, and is any exclusion one the committee would question? 5. Does the risk assessment list the risks that drove the scope, with inherent ratings, and does every High risk appear in the approach? 6. Are the criteria specific documents, standards or targets with versions and dates, and has management agreed the ones that are theirs? 7. Does the approach state, for each objective, the procedures, the populations and the sampling basis, cross-referenced to the work program? 8. Are the analytics and any specialist work identified, with the data requests already issued? 9. Do the milestones include the opening meeting, the fieldwork window, the closing meeting and the report date, and do they fit the budget? 10. Is the communication plan specific about who is told what and when, including escalation? 11. Are the hours built up by phase and by person, and do they reconcile to the plan’s allocation? 12. Are the team’s skills matched to the risks, with any gap covered by a specialist or a co-source hour? 13. Is independence confirmed for everyone on the team against the auditee? 14. Are the deliverables and the rating scale stated, so that the report’s form is not a surprise? 15. Is the memo dated before fieldwork, and is the approval block complete?

The three memo failures that sink reviews

FailureHow it readsWhat it costs laterThe template’s fix
Objectives as activities“Review the controls over route cash”A report that lists what was done and never concludes; a manager who can’t tell if the audit answered anythingSection 2’s question form and the negative sentence
Criteria omittedNo Section 5 — or “company policy” with no name or versionEvery finding becomes a debate about what “should” means; the exit meeting relitigates standards instead of factsNamed documents, management confirmation, dated
Risks without procedures (or vice versa)A risk table and a procedure list that don’t reference each otherUntested risks nobody noticed; procedures performed out of habit; a work program that can’t explain itselfThe “addressed by” column in Section 4 and the risk tags in Section 6

Length, format, and when to re-issue

Three to five pages for a standard engagement, with the risk table and the key procedures doing most of the work; a memo longer than eight pages is a work program wearing a memo’s clothes. Keep it as a document in the workpapers (it is Standard 13’s evidence in one file) and send Sections 1–3 and 7 to the auditee as the engagement letter — the same text, so the promise made to management and the plan the team follows are literally identical. Re-issue as an addendum, not a rewrite, whenever scope or objectives change: the original stays, the addendum records what moved and why, and a reviewer can reconstruct the engagement’s decisions in order. For advisory engagements, the same eight sections apply with Section 2 phrased as the question management asked and Section 5 stating whose criteria (usually management’s) the advice will be judged against — the memo is what keeps advisory work from drifting into unasked assurance.

Where the memo goes next

Every hard moment in an engagement — the scope fight, the criteria argument, the finding that surprises the sponsor — is a planning memo sentence that was never written. Eight sections, model language, and the discipline of questions-for-objectives, named criteria, and risks tied to procedures: that is the whole difference between an audit that runs on rails and one that runs on nerve. Write it before fieldwork, sign it, send the auditee their half, and the rest of the engagement inherits its clarity.

The Templates Suite — one company, one cycle: the annual audit plan · the walkthrough document · the audit report set · the finding and issue log. The standards behind each section: Domain V, Principle 13.

The planning memo sits between the annual plan and the work program, so the guides below are the ones you will reach for immediately before and after it. Start with the two on either side of the memo, then use the risk and testing guides when Sections 4 to 6 need more depth.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading