{"description":"Audit Engagement Planning runs ON an already-opened Audit item — the engagement record the annual audit plan created. The audit is an INPUT: this workflow enriches that item, it never creates a duplicate. In scope: producing the planning package — scope, the engagement risk assessment and mapped control population (Risk and Control items linked to the Audit; together the engagement Risk & Control Matrix, the RCM), the sampling plan, the planning memos, and the enriched audit record. Out of scope: fieldwork, findings, and reporting, which belong to the downstream Internal Audit Engagement Lifecycle workflow that consumes this workflow's handoff package (the RCM travels with it). There is no upstream workflow; planning starts from the audit-plan entry itself.","edges":[{"id":"e-lock-executable-workplan-build-the-sampling-plan","source":"lock-executable-workplan","target":"build-the-sampling-plan"},{"id":"e-build-the-sampling-plan-classify-disposition","source":"build-the-sampling-plan","target":"classify-disposition"},{"id":"e-classify-disposition-approve-or-revise-package","label":"Clear","source":"classify-disposition","target":"approve-or-revise-package","whenValue":"clean"},{"id":"e-classify-disposition-create-action-plan","label":"Action","source":"classify-disposition","target":"create-action-plan","whenValue":"remediate"},{"id":"e-classify-disposition-escalate-or-accept-risk","label":"Escalate","source":"classify-disposition","target":"escalate-or-accept-risk","whenValue":"escalate"},{"id":"e-create-action-plan-approve-or-revise-package","source":"create-action-plan","target":"approve-or-revise-package"},{"id":"e-escalate-or-accept-risk-approve-or-revise-package","source":"escalate-or-accept-risk","target":"approve-or-revise-package"},{"id":"e-approve-or-revise-package-handoff-to-related-workflow","label":"Approved","source":"approve-or-revise-package","target":"handoff-to-related-workflow","whenValue":"approved"},{"id":"e-approve-or-revise-package-resolve-approval-conditions","label":"Revise","source":"approve-or-revise-package","target":"resolve-approval-conditions","whenValue":"revise"},{"id":"e-resolve-approval-conditions-handoff-to-related-workflow","source":"resolve-approval-conditions","target":"handoff-to-related-workflow"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{"UC-AUDIT-07":"operates","UC-AUDIT-11":"operates","UC-AUDIT-12":"operates","UC-AUDIT-15":"operates"},"controls":["UC-AUDIT-11","UC-AUDIT-12","UC-AUDIT-15","UC-AUDIT-07"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-engagement-planning","contentDigest":"sha256:b6b8606898fa799c22cc7aaa3d1d036828b9ec97873cdb397ca4ce75e4f0089a","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:b6b8606898fa799c22cc7aaa3d1d036828b9ec97873cdb397ca4ce75e4f0089a","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-engagement-planning"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-engagement-planning","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit"]},"name":"Audit Engagement Planning","nodes":[{"data":{"description":"Resolve universe linkage, auditable scope, exclusions, evidence standards and the feasible planning schedule.","instructions":"**Objective** — Resolve universe linkage, auditable scope, exclusions, evidence standards and the feasible planning schedule.\n\n**Inputs**\nThe audit universe register: auditable entities with their boundaries, risk scores, and assigned audit cadence.\n- The engagement objective and boundary statement for this engagement.\n- Prior audits linked to the candidate universe entries.\n\nFrom the existing audit-plan entry, commissioning record and approved reporting calendar: the engagement title, objectives, in-scope processes, explicit exclusions, period covered, the request driver, the stakeholders to interview, and the audit-committee (or reporting) deadline that anchors the timeline.\n- The lead auditor; where the record needs them, the regions, portfolio, and legal entities in scope.\n- Prior workpapers and the issue history for this auditable area, for context.\n\nThe confirmed scope frame from scope-and-objectives gathering, including any scope expansion that step surfaced.\n- The engagement's decision owners and known constraints; team availability; the audit-committee or reporting deadline.\n- The function's audit methodology: evidence standards, review-hierarchy rules, documentation conventions.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Engagement lead owns the stated judgments and authorizations.*\n\n*Confirm audit universe linkage.* Tie the engagement to its audit-universe entry so coverage statistics, audit cadence, and prior history accrue to the right auditable entity before any planning effort is spent.\n\n1. Locate the auditable entity whose boundary contains the engagement's target processes. If the engagement spans entries (a process audit crossing two business units), link every touched entry and designate one primary for coverage reporting.\n2. Verify cadence: compare the entry's last-audited date plus its assigned cadence against today. If this engagement arrives earlier than cadence implies, record what pulled it forward (new risk, incident, regulator request) — that rationale feeds the risk assessment. If it arrives late, note the coverage gap the delay created.\n3. Check risk-score vintage: if the entity-level risk score predates the last annual universe refresh, flag it. The engagement risk assessment in a later step must not silently inherit a stale entity score.\n4. If no universe entry covers the target, stop and treat it as a universe gap: raise it to the CAE and propose the new entry as a suggested change. Planning an engagement against no entry breaks coverage reporting for the whole plan cycle.\n5. Confirm the entry's boundary matches the intended scope. Scope beyond the boundary needs either a documented scope expansion captured when the workplan is locked or a universe boundary correction — never an unrecorded stretch.\n\n*Gather scope and objectives.* Capture the engagement's scope so the risk assessment, control population, sampling plan, memos, and audit record all build on the same agreed frame (IIA Standard 13.3).\n\n6. Read the existing engagement record and commissioning material, then clarify only missing or conflicting facts with their source owner and capture the confirmed scope explicitly. Record what is deliberately out of scope alongside what is in — exclusions are stated, never implied.\n7. Pull prior-period workpapers, the issue history, and any standing scope for this auditable area, so the new engagement is set against what has run before rather than drafted in a vacuum.\n8. Where an existing scope field is missing or ambiguous, ask the requester to clarify before proceeding. Never invent the objective, the in-scope processes, the period, or the audit-committee date; surface unresolved items as open questions rather than guessing.\n9. Human checkpoint: the engagement lead judges whether the requested scope is auditable and proportionate — whether the objectives can be concluded on within the period and the deadline given — and confirms the scope and the audit-committee date before risk assessment begins. Where the requested frame is not auditable, negotiate it with the requester rather than accepting it.\n\n*Lock executable workplan.* Freeze scope, owners, dates, and evidence expectations into an executable workplan so the core planning chain — risk assessment through seeded record — works against a stable frame.\n\n10. Fix the scope statement: objectives, in-scope processes, entities and systems, and explicit exclusions, each exclusion with a one-line reason. From this point, scope changes go through a suggested change plus engagement-lead approval — no silent edits.\n11. Assign a named owner, due date, and reviewer to each planning phase: risk assessment, control population, sampling plan, memo drafting. Per IIA Standard 13.6 the work program must be approved before implementation — build that approval into the dates rather than after them.\n12. Sanity-check the calendar backward from the audit-committee deadline: planning sign-off, the fieldwork window, and reporting must fit around auditee blackout periods and team availability. The memo step computes exact tollgate dates; here you confirm feasibility, not final dates.\n13. Set evidence expectations per scope area before anyone collects anything: what counts as sufficient (source-system extracts over screenshots; screenshots carry URL and capture date; system-generated reports captured with their generation parameters), and that evidence attaches to the step that used it.\n14. Confirm review expectations: who reviews which workpapers, expected turnaround, and the sign-off order ending at the engagement lead.\n\n**Record in AssureSwarm**\nLink the engagement's Audit item to each universe entry (a Process item — the auditable-entity inventory), with the primary flagged.\n- Record the cadence-check result and the risk-score vintage on this step.\n- Raise a suggested change for any universe gap or boundary correction.\n\nRecord the confirmed objectives, processes, exclusions, period, reporting deadline, request driver and stakeholders in the native planning record. Reuse existing facts; the lead’s auditability judgment and negotiated changes go in the step result.\n- Field updates on the engagement's existing Audit item: the confirmed objectives and in-scope processes with explicit exclusions in scope, the period covered in period_start/period_end, and the lead in lead_auditor; the audit-committee deadline and stakeholders (plus regions, portfolio, entities where applicable) in the description.\n- Open questions awaiting an answer, recorded on this step rather than buried in notes.\n\nWrite the locked scope statement to the Audit item's scope field; per-phase owners, dates, and reviewers on this step (the workplan document, attached).\n- Capture the engagement lead's approval on this step — that approval is the lock.\n- Route any later scope change as a suggested change referencing this step.\n\n**Exit criteria**\nEngagement linked to at least one universe entry; cadence and risk-vintage checks recorded; any universe gap escalated rather than worked around.\n\nAn agreed, gap-flagged scope (objectives, in-scope processes, period, audit-committee deadline, lead, stakeholders) is recorded as the frame for the rest of planning; every scope field is either supported by the existing commissioning record or a documented clarification or flagged as an open question; no date or scope element is fabricated.\n\nScope frozen and approved; every planning phase has an owner, a date, and a reviewer; evidence and review expectations documented; the audit-committee deadline confirmed reachable.\n\n","label":"Lock executable workplan","performedBy":{"agent":"audit-artist","note":"captures the scope fields and audit-committee date, clarifying gaps rather than inventing them","primitives":["coach-item-create","coach-query-data"]}},"id":"lock-executable-workplan"},{"data":{"description":"Challenge inherent risk and fraud scenarios, select key-control coverage and authorize sample sizes, methods and departures before the draw.","instructions":"**Objective** — Challenge inherent risk and fraud scenarios, select key-control coverage and authorize sample sizes, methods and departures before the draw.\n\n**Inputs**\nThe confirmed scope frame: objectives, in-scope processes, period, entities, and reporting expectations.\n- Prior workpapers and the issue history: open and repeat findings, past ratings for this area.\n- Auditee inputs: planning interviews with the stakeholder list and auditee contacts, management's own risk register for the area, loss events and KRIs, and the change log for the period (systems, reorganizations, key-person departures).\n- The approved criteria the engagement will evaluate against — policies, frameworks, regulations (IIA Standard 13.4).\n\nThe proposed risk assessment: the top three to five key risks and their audit objectives, to be reviewed with control coverage and sampling.\n- Process narratives, SOPs, and any existing risk-and-control matrix for the area — including the SOX RCM where the scope overlaps ICFR.\n- Walkthrough conversations with control owners; system configuration for automated controls.\n\nThe prioritized control population, with each control's risk rating taken from this engagement's own risk assessment — read the risk column from this assessment, never a generic default.\n- Each control's operating frequency, and the population listing and its size per control.\n- Per control, the escalation flags: whether it is the sole control addressing a significant risk, any prior-period deficiency on it, whether it is newly implemented, and whether an external auditor intends to rely on the testing.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Engagement lead owns the stated judgments and authorizations.*\n\n*Assess risks.* Produce the engagement risk assessment (IIA Standard 13.2): inherent risk ratings over the in-scope processes and a prioritized set of audit objectives that tell the rest of planning where the effort goes.\n\n1. Build the risk inventory per in-scope process: what could keep the process from meeting its objectives? Seed it from management's register, prior findings, loss events, and the planning interviews — then add what management did not list; the auditor's inventory must not simply mirror the auditee's.\n2. Consider fraud explicitly, as Standard 13.2 requires: the schemes relevant to this area (asset misappropriation, fraudulent reporting, corruption), the incentive-opportunity-rationalization conditions present, and management-override scenarios. Absence of fraud history is not absence of fraud risk.\n3. Rate inherent risk — before considering controls — on the function's scale, typically impact times likelihood on 1-5 each. Drive the rating from stated factors, not gut feel: transaction volume and value, process complexity, degree of change in the period, manual versus automated operation, prior findings, time since last audit, regulatory attention.\n4. Prioritize: rank by inherent rating and select the top three to five key risks; convert each into an audit objective phrased as an assurable question (for example, \"Are user access grants approved and revoked timely?\"); confirm every engagement objective from scoping is covered by at least one key risk or expressly descoped.\n5. Human checkpoint: the inherent ratings and prioritized audit objectives are drafted for the engagement lead, who challenges the ratings together with the proposed control mapping and sampling plan. Resolve all changes before drawing the approved samples; the lead owns the ratings.\n\n*Identify control population.* Identify the controls management relies on against each prioritized risk, so testing effort lands on the controls that matter and control gaps surface now rather than mid-fieldwork. This step completes the control half of the engagement's Risk & Control Matrix (RCM) — the named deliverable fieldwork tests against.\n\n6. For each key risk, list the controls management asserts mitigate it, drawn from narratives, the RCM, and owner walkthroughs. Capture per control: description, owner, operating frequency, preventive or detective, manual / automated / IT-dependent manual, and the evidence it produces when it operates.\n7. Classify key versus non-key: a control is key if its failure would leave the risk unmitigated with no compensating coverage. Key controls are the testing scope; non-key controls are noted, not tested.\n8. Run the coverage check in both directions: every key risk maps to at least one key control, and every claimed key control maps to a risk. A risk with no control is a control gap — record it now as a finding candidate and plan substantive procedures for that risk instead of control testing. A control mapped to nothing is scope padding; drop it.\n9. Verify design currency with each control owner: does the control still operate as documented? Note controls changed mid-period — they will need split-period testing — and controls that are newly implemented, which carry an escalation factor in the sampling step.\n10. For automated controls, record the ITGC dependency (access, change management) that a test-of-one strategy will rely on. If the ITGCs for that system are known-weak, treat the control as manual for sampling purposes.\n\n*Build the sampling plan.* Size and select the test sample for each in-scope control so the selections are defensible and reproducible.\n\n11. Set the base sample size from control frequency by risk rating, using the standard frequency-by-risk table as the starting point: annual → about 1 selection; quarterly → 2; monthly → 2-3 (higher at higher risk); weekly → 5-15; daily → 20-40; and a transaction or many-per-day population of 250 or more → roughly 25 / 40 / 60 selections at low / moderate / high risk.\n12. Apply the escalation factors that raise the base size, and record which applied: the control is the sole control addressing a significant risk; a prior-period deficiency exists; the control is new; or an external auditor will rely on the work.\n13. Choose a selection method per control from four options and record the rationale: random — the default for transaction-level controls with large populations; targeted or judgmental — for small or high-variance populations, documenting the risk rationale for each individual selection; haphazard — only when no sequential population listing is available and the population is homogeneous; systematic — for a sequential population where even coverage across the period matters.\n14. Obtain engagement-lead approval of the risk ratings, mapped control coverage, sample sizes, methods and departures before any draw against live populations. Then run every random or systematic draw as a recorded, re-runnable computation: fix and log the random seed, and keep the selection script and its output alongside the sample so any reviewer can reproduce the exact selection. Never hand-pick items for a method that calls for a random or systematic draw.\n15. Retain the lead’s combined risk, control-coverage and sampling approval with the resulting reproducible selections; any changed approved basis requires re-approval before a new draw.\n\n**Record in AssureSwarm**\nCreate or update a Risk item per identified risk — category, likelihood, impact, inherent_rating, risk_owner, with the factor notes in its description; link each Risk to the engagement's Audit item and to the Process it sits on. These Risk items are the risk half of the engagement's Risk & Control Matrix (RCM).\n- Record the prioritized top-three-to-five list, the criteria linkage, and the lead's sign-off on this step.\n\nCreate or link a Control item per population entry — control_owner, frequency, control_type, automation, key_control, with the evidence notes in its description; link each Control to the Risk items it mitigates and to the engagement's Audit item. Together with the Risk items this is the engagement's Risk & Control Matrix (RCM).\n- Record each control gap as an Issue item (issue_type: deficiency or observation, source: internal_audit, severity per exposure), linked to the uncovered Risk and the Audit — gaps feed the disposition decision.\n\nPer control, on this step: the population size, the frequency and risk rating used, the base size, any escalation factor applied and the resulting size, and the selection method with its rationale.\n- For random or systematic draws: the seed and the script/output reference, attached with the sample.\n- Link the plan rows to their control items.\n\n**Exit criteria**\nEvery in-scope process has an assessed risk set with rated inherent risk traceable to stated factors; fraud scenarios documented even where rated low; the top three to five key risks and their audit objectives signed off by the engagement lead.\n\nEvery key risk has mapped key controls or a recorded gap; every control carries owner, frequency, type, and evidence notes; the RCM (Risk ↔ Control ↔ Audit links) is complete; mid-period changes, new controls, and ITGC dependencies flagged for the sampling plan.\n\nAn approved, reproducible sampling plan per control (sizes, methods, seeds, and selections) is recorded and ready to feed the planning memo's sampling-plan section; sizes trace to the frequency-by-risk basis and the stated escalation factors; the method fits each population; random and systematic selections reproduce from the recorded seed; every departure from the standard table is documented.\n\n> **⚡ Audit Artist accelerator:** `/sox-python` runs the seeded selection as a reproducible computation — the draw, its seed, and its output land in a re-runnable procedure any reviewer can replay.","label":"Build the sampling plan","performedBy":{"agent":"audit-artist","note":"drafts the inherent risk ratings and prioritised audit objectives for human lead sign-off sizes each sample from frequency-by-risk with escalation factors and runs the reproducible seeded selection","primitives":["coach-query-data","coach-item-create","sox-python"]}},"id":"build-the-sampling-plan"},{"data":{"decisionField":"disposition_path","description":"Review the complete memo set and enriched period record, then classify readiness, correctable gaps or authority-level escalation.","formData":{"fields":[{"key":"disposition_path","label":"Classify disposition","options":[{"label":"No reportable gap","value":"clean"},{"label":"Remediation required","value":"remediate"},{"label":"Escalate significant issue","value":"escalate"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Review the complete memo set and enriched period record, then classify readiness, correctable gaps or authority-level escalation.\n\n**Inputs**\nThe confirmed scope and objectives; the in-scope processes, regions, and entities plus explicit exclusions.\n- The risk assessment (its top three to five key risks) and the identified control population.\n- The approved sampling plan: sizes, methods, seeds.\n- The stakeholder and interview list, the required cooperation from the auditee, the lead auditor and team, the open questions, and the audit-committee deadline captured at scoping.\n- The firm's own AAM or APM template with its fixed legal wording, where one exists.\n- For a review pass: the existing memo document and the confirmed audit-universe entry the engagement is linked to.\n\nThe engagement's existing Audit item (already opened by the annual plan) — the anchor this workflow runs on.\n- The approved planning memo; the engagement objective and approved criteria.\n- The confirmed scope and any scope limitations; the assessed risks and identified control population (the RCM); the sampling plan.\n- The responsible lead and team; reporting expectations.\n- For a recurring engagement: the prior period's Audit item plus the workflow template it ran.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Engagement lead owns the stated judgments and authorizations.*\n\n*Draft the planning memo.* Render the approved scope, risk assessment, control population, and sampling plan into the engagement's planning-memo deliverables: the fieldwork-ready internal planning memo with a dated tollgate timeline, plus two distributable planning-phase memos drawn from the same structured data — the Audit Announcement Memo (AAM), which goes to the auditee two to three weeks before fieldwork starts, and the Audit Project Memo (APM), the fuller planning sign-off memo issued at the planning tollgate. The step also supports a review pass that QAs an already-drafted AAM or APM for completeness and consistency before it is issued.\n\n1. Compile the internal planning memo with the standard sections in order: Objectives; Scope and exclusions; Risk assessment; Control population; Sampling plan; Timeline; Stakeholders and interviews; Open questions.\n2. Build the Timeline as a tollgate schedule computed backward from the audit-committee date: planning sign-off at the audit-committee date minus 90 days, fieldwork start at minus 70, fieldwork end at minus 30, draft report at minus 14, and final report at minus 7. Compute each milestone from the confirmed audit-committee date; never invent a milestone date, and if the audit-committee date is unset, flag it as an open question instead of guessing.\n3. Draft the two distributable memos from the same structured audit data rather than reinventing structure: map each memo slot to the data and write one to three sentences per slot. AAM slots (announcement, issued two to three weeks before fieldwork): audit title and period, objectives, scope of in-scope processes and exclusions, period covered, tentative timeline of key milestones, lead auditor and team, and stakeholders. APM slots (planning sign-off): every AAM slot plus a risk-assessment summary of the top three to five key risks, the sampling approach, the required cooperation from the auditee, and the tollgate deadlines. The AAM contents are a strict subset of the APM, so draft both from the same fields.\n4. NEVER-INVENT GATE — load-bearing across all three memos: if an input is missing, do not fabricate a plausible value. In the internal memo, carry every unresolved item into the Open questions section; in the AAM and APM, write an explicit [NEEDS INFO: specific question] marker in the slot's place so the missing input stays visible and gets resolved before the memo is issued. Cite each risk and control reference back to its source record rather than copying records verbatim.\n5. Firm-template discipline: when a firm-specific AAM or APM template with legal disclaimers or fixed boilerplate is in use, fill only the structured slots the template defines and never edit, reword, or remove the boilerplate legal text.\n6. Render each completed memo as its distributable document and link it to the engagement record: the AAM to go out ahead of fieldwork, the APM to accompany the planning sign-off, and the internal planning memo to feed the audit record.\n7. Review pass — when QAing an existing AAM or APM instead of drafting: check internal consistency (the period is stated consistently throughout; the lead and team match the team section; the risks named in scope match the risk-assessment section; the sampling approach is feasible given the stated period and population), then check alignment to the linked audit-universe entry (the in-scope processes fall within the universe entity's coverage; the period aligns with that entry's audit cadence). Record each issue as kind, severity, location, and recommendation.\n8. Human checkpoint: the engagement lead resolves every open [NEEDS INFO] marker and open question, confirms the memo's scope, period, risks, sampling plan, and tollgate timeline are accurate, and approves the internal planning memo, the AAM for issue to the auditee, and the APM for the planning sign-off — all before the audit record is seeded.\n\n*Enrich the audit record.* Enrich the engagement's EXISTING Audit item — the record the annual audit plan already opened — with the approved planning outputs: fields, links to the RCM (Risk and Control items), authority citations, and the executable workplan, so fieldwork has a home and a reviewable trail. The audit is an input to this workflow, not something this step creates; creating a second record here duplicates the engagement. This step also handles the recurring case: when the engagement is a new period of an audit that has run before, create the NEW period's Audit item seeded from the prior one instead of building it from scratch.\n\n9. Enrich the existing Audit item: confirm and complete its identifying fields — title, audit_type, planning-stage status, period_start, period_end, lead_auditor — filling gaps rather than re-creating the record. Link it to its scope, cited authority or criteria sources, the assessed Risk items, and the identified Control items (the RCM); confirm the executable workplan is attached as this workflow's instance so every planned step has a place to collect evidence and sign-offs.\n10. Recurring rollover — create the new period's Audit item, copying forward from the prior period the scope, the audit_type, the authority or criteria citations, and the links to the same Risk and Control items. These are stable across periods and should not be re-derived.\n11. Recurring rollover — advance the period: set the new period_start and period_end, and swap the period suffix in the title so it names the new period (for example \"Q1\" becomes \"Q2\", \"FY2025\" becomes \"FY2026\").\n12. Recurring rollover — attach a fresh workflow instance built from the prior period's workflow template, so the step shape, the step instructions, and any pre-set step-to-control and step-to-risk links carry across while every step still starts empty.\n13. Recurring rollover — reset run state to planning: clear the team assignments so they are re-confirmed for the new period, and start every step with a blank assignee, no attached evidence, not-started status, and no sign-offs.\n14. LOAD-BEARING RULE — never carry forward the prior period's issues, findings, or prior evidence. The new period must surface and support its own findings from its own work; carrying last period's issues or evidence into this one corrupts the record. Issues remain separate records linked back to the audit, never copied into the new period.\n15. Human checkpoint: the engagement lead confirms the seeded scope, period, and team before the record leaves planning. A rollover in particular needs the lead to re-confirm the team and re-validate scope for the new period.\n\n*Classify disposition.* Classify what planning surfaced so only the relevant closure path stays live. The engagement lead owns the call: did planning finish clean, surface remediable gaps, or hit something that outranks this workflow's authority?\n\n\n\n**clean** (No reportable gap) — scope, risk assessment, control population, sampling plan, memos, and the seeded record all completed and approved with no open control gaps, no unresolved [NEEDS INFO] markers, no scope limitation, and no red flag from the planning interviews. Route straight to package assembly.\n- **remediate** (Remediation required) — planning surfaced correctable gaps that need an owned action plan but do not threaten the engagement: control gaps found during population mapping that management should start closing before fieldwork; population or system-report deficiencies that block a clean sample draw until fixed; open questions converted into actions with owners; a resource shortfall with an agreed fix. The test: each item has a plausible owner and a fix date inside the engagement timeline.\n- **escalate** (Escalate significant issue) — something beyond the engagement lead's authority: a management-imposed scope limitation that impairs the engagement objective (an impairment the CAE must handle and disclose); suspected fraud surfaced during planning; denial of access to records, systems, or people; or an exposure so far above appetite that waiting for fieldwork is indefensible. Escalation happens before the package is finalized, not inside it.\n\n**Record in AssureSwarm**\nThe rendered internal planning memo (DOCX/PDF) with all eight sections, uploaded on this step and linked to the engagement's Audit item.\n- The computed tollgate dates written to the Audit item's date fields — fieldwork_start, fieldwork_end, report_date — alongside the audit-committee date they derive from.\n- The drafted AAM and APM document references (whichever were produced); the template used; the list of [NEEDS INFO] markers still open.\n- Links from the memos to the engagement's scope, risks, and controls.\n- For a review pass: the consistency and universe-alignment issues found, each with kind, severity, location, and recommendation.\n\nField updates on the Audit item: audit_type, scope, period_start, period_end, lead_auditor (a rollover records the NEW Audit item's ID instead).\n- Item relationships from the Audit to its Risk items, Control items, and in-scope Process entries; the attached workflow instance ID.\n- For a rollover: a one-line note of the source period it was seeded from and confirmation that no prior-period Issue items or evidence were carried over.\n\nSubmit `disposition_path` on this step's form. The step result cites the specific gap, control or incident records that drove the classification; the native approval record identifies the decision owner.\n\n**Exit criteria**\nAll eight internal-memo sections present; every tollgate date traces to the audit-committee date by the fixed offsets; every AAM and APM slot is either filled from the audit data or carries a [NEEDS INFO] marker with a specific question, with no slot filled by an invented value; risks and controls cited to source rather than copied verbatim; firm boilerplate legal text unchanged; the AAM a strict subset of the APM; open questions surfaced, not buried; any review-pass issues resolved or recorded with an owner; the approved memo set — internal memo with computed tollgate timeline, AAM, APM — is linked to the engagement record and ready for the audit record to be seeded from it.\n\nA planning-status Audit item exists — enriched, not duplicated — linked to scope, the RCM (Risk and Control items), authority sources, and a clean workflow instance; the record's scope and linkages match the approved memo; team and evidence are blank pending the lead's confirmation; and, for a recurring engagement, the new period's item advanced correctly with zero prior-period findings or evidence carried forward.\n\nForm submitted with an evidence-cited rationale and named owner; unused branches are prunable because the selected value matches the outbound edges.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` renders the internal memo, AAM, and APM as distributable documents from the same structured engagement data and links them to the engagement record.","kind":"decision","label":"Classify disposition","performedBy":{"agent":"audit-artist","note":"assembles the eight-section planning memo with its audit-committee-date tollgate timeline and drafts the AAM and APM from the same audit data, never inventing missing slots recurring-engagement seed + period-rollover engine","primitives":["coach-query-data","coach-document-upload","coach-items-link","coach-render-package","coach-item-create","coach-workflow-attach"]}},"id":"classify-disposition"},{"data":{"description":"Create an owned action plan for gaps","instructions":"**Objective** — Convert each remediable planning gap into an owned, dated action plan with interim mitigation and pre-agreed validation evidence, so gaps found in planning actually close instead of resurfacing as fieldwork findings.\n\n**Inputs**\n- The disposition rationale and the flagged gap records: control gaps, population or data deficiencies, converted open questions, resource shortfalls.\n- The engagement timeline — which tollgate each gap blocks.\n- Auditee contacts with the authority to own fixes.\n\n**Procedure**\n1. Write a root cause per gap, distinguishing the three common species: the control was never designed (design absence), the data to test it does not exist or is unreliable (information gap), or nobody is resourced to operate it (capacity gap). The fix differs by species; a due date without a root cause is a wish.\n2. Assign the owner who actually controls the fix — a process or control owner on the auditee side, never the auditor. The auditor tracks; the business remediates.\n3. Set the due date against the milestone the gap blocks: population remediation must land before the fieldwork-start tollgate or the sampling plan re-opens; a control-gap fix may extend past fieldwork if the gap will simply be reported as a finding.\n4. Record the interim mitigation covering the exposure while the action is open, and define the validation evidence now — the specific artifact that will prove closure — so closure is not negotiated after the fact.\n5. Set the reporting cadence: action status reviewed at each tollgate; an action overdue by ten business days escalates to the engagement lead.\n\n**Record in AssureSwarm**\n- Create an Issue item per gap — issue_owner, target_remediation_date, root_cause, identified_date, source: internal_audit, issue_type per species (deficiency for a design absence; observation for an information or capacity gap) — with the interim mitigation and validation-evidence definition in remediation_plan.\n- Link each Issue to the Risk or Control it protects and to the engagement's Audit item.\n- Add the Issues to the engagement's watchlist for cadence tracking.\n\n**Exit criteria** — Every remediable gap has an Issue with owner, root cause, milestone-tied due date, interim mitigation, and defined validation evidence; the escalation rule is recorded; links are in place.","label":"Create action plan"},"id":"create-action-plan"},{"data":{"description":"Escalate to engagement lead, CAE delegate, or audit committee delegate or document risk acceptance","instructions":"**Objective** — Put the significant issue in front of the right authority — engagement lead, CAE delegate, or audit-committee delegate — with a decision memo that forces an explicit outcome: proceed, delay, descope, cancel, or formally accept the risk.\n\n**Inputs**\n- The disposition rationale and the evidence behind the significant issue.\n- The engagement objective and what the issue does to it: coverage lost, objective impaired.\n- The engagement's escalation ladder, and the function's fraud-response protocol where one exists.\n\n**Procedure**\n1. Draft the decision memo: issue statement; evidence references; quantified impact (audit coverage lost, exposure in currency or rating terms, which engagement objective is impaired); the options with consequences — proceed with the limitation and disclose it in the report, delay until access or resourcing resolves, descope and report the impairment, or cancel and return the area to the plan queue; and a recommendation.\n2. Route by nature and severity. A scope limitation or access denial that impairs the objective goes to the CAE delegate — impairments are disclosed, not absorbed. Suspected fraud follows the fraud-response protocol and goes to the CAE directly: restrict access to the memo, name no suspects in broadly visible records, and do not alert potential subjects. An above-appetite exposure goes to management at the level authorized to accept it.\n3. If the authority accepts the risk: capture the acceptance in writing with its conditions, a time box, and a re-review date. Record it structurally, not as a memo footnote — set treatment: accept on the affected Risk item (re-confirming its residual_rating), and create an Issue item with issue_type: policy_exception carrying exception_approver (the accepting authority) and exception_expiry_date (the re-review date), linked to that Risk. Acceptance belongs to management at the right level — and note explicitly that acceptance does not bind or pre-empt the eventual audit conclusion.\n4. If the authority directs a change (delay, descope, cancel): record the direction and its effect on the scope, the memo set, and the seeded record, and name a follow-up owner for each consequence.\n\n**Record in AssureSwarm**\n- Attach the decision memo to this step, with restricted access where fraud is involved.\n- For an acceptance: the policy_exception Issue item (exception_approver, exception_expiry_date, conditions in its description) linked to the affected Risk item, whose treatment is set to accept.\n- For a direction (delay, descope, cancel): the decision, decider, and date on this step, linked to the engagement's Audit item.\n- Create follow-up Issue items with owners for every condition and consequence.\n\n**Exit criteria** — A written decision from the named authority exists with conditions and follow-up ownership; an acceptance exists as a time-boxed policy_exception Issue tied to its Risk, never only as memo text; fraud-sensitive material is access-restricted; the engagement's path forward (proceed, delay, descope, cancel, or accepted risk) is unambiguous going into package approval.","label":"Escalate or accept risk"},"id":"escalate-or-accept-risk"},{"data":{"decisionField":"approval_path","description":"Approve the reconciled planning package and its permitted conditions, or return specific changes to scope, sampling or evidence.","formData":{"fields":[{"key":"approval_path","label":"Approve or revise package","options":[{"label":"Approved","value":"approved"},{"label":"Revision required","value":"revise"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve the reconciled planning package and its permitted conditions, or return specific changes to scope, sampling or evidence.\n\n**Inputs**\nThe locked scope; the signed-off risk register; the control population; the sampling plan with seeds; the internal planning memo, AAM, and APM.\n- Any action plans (remediate path) or the escalation decision memo and risk-acceptance record (escalate path).\n- The open constraints and assumptions logged across planning.\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Engagement lead or higher delegated authority required by the package owns the stated judgments and authorizations.*\n\n*Prepare final package.* Assemble the complete planning package so the approver can reach a decision inside one reviewable set, without leaving it to hunt for evidence.\n\n1. Compile the package in decision order: the proposed conclusion first (\"planning complete, ready for fieldwork\" or a conditioned equivalent), then the memo set, then the supporting analyses (the RCM — the risk register and mapped control population — and the sampling plan), then the exception material (action plans, escalation outcomes, open constraints).\n2. Re-run the cross-checks that go stale between steps: tollgate dates still consistent with today's calendar (re-baseline if planning overran); every risk named in the memo traces to the register; every sampled control exists in the population; no unresolved [NEEDS INFO] marker anywhere in the memo set.\n3. Reference, do not duplicate: outputs owned by other records — universe suggested changes, action items, the seeded audit record — are linked, so the package cannot drift from the records after approval.\n4. State unresolved constraints and assumptions explicitly, each with a recommendation. An approver who discovers an unstated constraint later treats the whole approval as void, whatever the record says.\n5. Apply the completeness gate before submitting: the reviewer must be able to verify any assertion in the package by following a link, never by asking for a file.\n\n*Approve or revise package.* The approver — engagement lead, CAE delegate, or audit-committee delegate per the delegation ladder — decides whether the planning package is fit to sign or goes back for rework. This is the planning sign-off gate; nothing downstream starts until it clears.\n\n\n\n**approved** (Approved) — the package is complete and internally consistent: all eight memo sections present; tollgate dates trace to the audit-committee date; sample sizes trace to the frequency-by-risk basis with departures documented; every key risk carries mapped controls or a recorded gap with an action; no unresolved [NEEDS INFO] markers or open escalations; and the approver holds authority for everything in it — an impairment or accepted risk needs the CAE-delegate level, not the lead. Minor items may ride along as recorded conditions: select `approved` and record the conditions rather than selecting `revise` when the conditions do not change the plan's substance.\n- **revise** (Revision required) — any load-bearing element is missing, stale, or unsupported: unsigned risk ratings, missing seeds or draw parameters, tollgates inconsistent with the calendar, an unresolved escalation, or an approver-required change to scope or sampling depth. Note the flow: the revise branch runs through condition resolution and then directly to recording the decision — so the approver's comments must be specific and complete at this decision. Vague \"tighten it up\" feedback cannot be verifiably resolved; write conditions that can each be checked.\n\n**Record in AssureSwarm**\nAttach the compiled package to this step.\n- Link the memo documents, risk register, control population, sampling plan, action items, and the seeded audit record.\n- Record the proposed conclusion and the open-constraint list as this step's summary.\n\nSubmit `approval_path` on this step's form. For revise, the step result lists every condition to resolve, numbered and independently verifiable; for approved, it records any riding conditions. Identify the approver in the native approval record.\n\n**Exit criteria**\nOne package containing or linking the conclusion, memos, analyses, and exception material; cross-checks re-run and clean; every assertion verifiable by link; ready to route for approval.\n\nForm submitted; for revise, a numbered condition list exists; for approved, conditions (if any) are recorded; the unused branch is prunable.","kind":"decision","label":"Approve or revise package"},"id":"approve-or-revise-package"},{"data":{"description":"Resolve reviewer comments or approval conditions","instructions":"**Objective** — Close every approver condition verifiably so the approval can be recorded without another full review cycle — this path flows directly to the decision record, so resolution must be airtight here.\n\n**Inputs**\n- The numbered condition list from the approval decision's rationale.\n- The package and the underlying records each condition touches.\n\n**Procedure**\n1. Log each condition as its own tracked entry with an owner and a resolution note. Conditions resolved in bulk hide the one that was not.\n2. Classify each condition before acting, because the fix path differs: an evidence gap — attach the missing artifact to the step that used it; an analysis change — re-rate a risk or re-size a sample, then cascade it (a re-sized sample updates the sampling plan, the memo's sampling section, and the seeded record's expectations); a scope change — re-opens the workplan lock and needs the engagement lead's re-approval of the lock, not just an edit; a wording change — memo only.\n3. Make each change where the data lives — the item, field, or document — then re-render the affected memo from the data. Editing memo text while the underlying record still says otherwise is how packages and records diverge.\n4. Record before-and-after per condition: what changed, where, and the evidence reference.\n5. Obtain the approver's confirmation on each resolved condition, as a comment or re-approval on this step. Because the flow proceeds straight to recording the decision, an unconfirmed resolution is an unresolved condition.\n\n**Record in AssureSwarm**\n- The condition log with per-condition owner, classification, before-and-after, and evidence reference.\n- The updated underlying items and re-rendered memo documents.\n- The approver's confirmation captured on this step.\n\n**Exit criteria** — Every condition individually resolved, evidenced, and confirmed by the approver; cascaded updates (sampling plan, memos, seeded record) consistent; no condition closed by assertion alone.","label":"Resolve approval conditions"},"id":"resolve-approval-conditions"},{"data":{"description":"Accept the approved planning basis, retained sample selections, reporting commitments and outstanding monitored conditions.","instructions":"**Objective** — Accept the approved planning basis, retained sample selections, reporting commitments and outstanding monitored conditions.\n\n**Inputs**\nThe approval decision, or the confirmed condition resolutions arriving from the revise path, plus the final package version.\n- The tollgate schedule from the memo, including the planned planning-sign-off date (audit-committee date minus 90 days).\n\nThe approved package and the recorded approval decision.\n- The seeded audit record with its attached workflow instance.\n- Open action items and approval conditions, with owners.\n- The full workflow run: every step's records, decisions, approvals, and documents.\n- The obligations that outlive planning: action plans, approval conditions, and the AAM release date.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Internal Audit Engagement Lifecycle owner owns the stated judgments and authorizations.*\n\n*Record approval decision.* Capture the formal planning approval — who, when, which package version, under what conditions — as the durable planning-tollgate record the rest of the engagement points back to.\n\n1. Record the approver's identity and role, and check authority against the delegation ladder: a lead-level sign-off cannot carry an impairment or an accepted risk — those need the CAE delegate's name on them.\n2. Record the decision date and compare it to the planned planning-sign-off tollgate. If sign-off landed late, state the slip and whether the downstream tollgates (fieldwork start and end, draft report, final report) were re-baselined or compressed — a silent slip here surfaces later as an impossible fieldwork window.\n3. Pin the approved version: the approval names the exact package version (a dated attachment or document version), so any later edit is visibly post-approval.\n4. Enumerate what the approval covers: the internal planning memo, the AAM cleared for issuance, the APM, the sampling plan, and the seeded audit record.\n5. Register the conditions that ride with the approval as tracked items with owners and due dates — conditions living only in a memo footnote do not get done.\n6. Schedule the AAM release per the memo timeline: two to three weeks before fieldwork start, to the auditee distribution list.\n\n*Handoff to related workflow.* Hand the approved planning outputs to the Internal Audit Engagement Lifecycle workflow so fieldwork starts from planning's record instead of re-deriving it, and close Audit Engagement Planning on an immutable trail with live monitoring on everything that outlasts it; the human moment is securing the downstream owner's acknowledgment of the package and its boundaries.\n\n_Items 12–16 close the workflow (folded from the former \"Close and archive\" step); the acknowledged handoff recorded here is the closure, not a separate confirmation._\n\n7. Assemble the handoff package on the audit record: the approved internal planning memo with its tollgate dates; the AAM with its scheduled release date and the APM; the engagement RCM — the Risk items with prioritized objectives and the Control items with key-control flags and noted gaps, all linked to the Audit item; the sampling plan with seeds and drawn selections; the open action Issues and conditions with owners; and the assumptions register (period boundaries, reliance arrangements, constraint decisions).\n8. Create or link the downstream Internal Audit Engagement Lifecycle workflow on the seeded audit record, and assign its first step's owner, so the handoff has a receiving human rather than just a record.\n9. State the do-not-repeat list explicitly in the handoff: downstream must not re-perform the risk assessment, must not re-draw samples — a re-draw breaks the recorded-seed reproducibility chain — and must not re-issue the AAM. If fieldwork believes a sample or a rating is wrong, that comes back as a change against this record, never a silent redo.\n10. Note where each artifact lives — which step holds which document — so downstream references rather than copies.\n11. Confirm receipt: the downstream owner acknowledges the package and the do-not-repeat list on the new workflow's first step. That acknowledgment is this step's human moment and the trigger for closing out.\n12. Sweep the trail end to end: every executed step holds its records; each decision form was submitted with rationale and owner; approvals are present where the flow required them; every document the memos reference is attached where the record says it is.\n13. Archive the final package versions as the immutable planning baseline. Anything that changes after this point changes in the Internal Audit Engagement Lifecycle workflow against the seeded record — never by editing the archived planning package.\n14. Update the linked records so portfolio reporting stays true: the universe entry's last-planned date, the audit-plan entry's status, and the links from open action items to the engagement.\n15. Arm the monitoring that outlives this workflow: the AAM release follow-up (two to three weeks before fieldwork start), and condition and action due dates on the watchlist.\n16. Communicate closure to the engagement lead and stakeholders: the final outcome (planning approved and handed off) and where the record lives. Retain workpapers per the function's retention policy.\n\n**Record in AssureSwarm**\nThe approver, role, date, and the approval captured on this step.\n- A link to the exact approved package version.\n- Condition items with owners and due dates; the AAM release date as a dated follow-up on the engagement item.\n\nThe linked downstream workflow instance on the audit record, with its first-step owner assigned.\n- The handoff package contents linked, not duplicated; the do-not-repeat list and the assumptions register recorded on this step.\n- The downstream owner's acknowledgment.\n- The archived package versions attached to this step as the immutable planning baseline.\n- Updated universe-entry and plan-entry fields; watchlist entries for the AAM release, conditions, and actions.\n- The closure comment to the lead and stakeholders on the engagement item.\n\n**Exit criteria**\nApproval recorded with authority verified, version pinned, coverage enumerated, and conditions tracked; the AAM release scheduled; any tollgate slip stated together with its re-baseline decision.\n\nThe downstream workflow exists, is owned, and has acknowledged the handoff; every handoff artifact is reachable by link from the audit record; the do-not-repeat boundary is recorded; the trail is complete with no undocumented step; the baseline is archived; linked records are updated; monitoring is armed; closure is communicated and workpapers retained per policy.","label":"Handoff to related workflow"},"id":"handoff-to-related-workflow"}],"sourceTemplateId":"workflow-library:audit-engagement-planning"}
