{"description":"Runs on the existing audit item. Plan an audit engagement from four independent starting points — management self-identified issues, the external threat and regulatory landscape, prior audit history, and the in-scope risk and control set — which converge into the walkthrough question set, the walkthrough, and the approved risk and control matrix that governs fieldwork. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-walkthrough-questions-rcm","source":"walkthrough-questions","target":"rcm"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":["audit-planning-scoping"],"controlVerbs":{"UC-AUDIT-05":"tests","UC-AUDIT-11":"tests","UC-AUDIT-12":"tests"},"controls":["UC-AUDIT-05","UC-AUDIT-11","UC-AUDIT-12"],"department":"internal-audit","domains":["audit"],"kind":"audit-planning-scoping","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:audit-planning-scoping"}],"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","contentDigest":"sha256:b129f9b9eac5c2e11573cd10f14c1314472067164b8f97a66dcff8c708730543","prerequisites":{"anchorItemType":{"slug":"audit"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:audit-engagement-planning"}],"roles":[{"contribution":"expertise","description":"Engagement lead. Draft the walkthrough question set.","id":"reviewer-1","nodeIds":["walkthrough-questions"]},{"contribution":"approval","description":"Independent audit supervisor. Build the risk and control matrix.","id":"reviewer-2","nodeIds":["rcm"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:audit-planning-scoping"}],"releaseId":"sha256:b129f9b9eac5c2e11573cd10f14c1314472067164b8f97a66dcff8c708730543","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-planning-scoping"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"slug":"audit-planning-scoping","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit"]},"name":"Audit Planning & Scoping","nodes":[{"data":{"controls":[],"instructions":"**Objective**\nDraft the walkthrough question set. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the engagement mandate, the self-identification form issued to control owners, the obligations register with regulator and incident reporting, prior audit reports and open Issues for the area, and the risk and control registers.\n2. Use the self-identified issues and the owners who reported nothing, the external candidate risks and near-term obligations, the prior coverage and open findings, and the in-scope risk and control set with its unmapped risks and orphaned controls.\n\n**Procedure**\n1. Use current management self-identifications first. Only when a named control owner who is not executing this workflow must supply missing facts, prepare a form limited to those facts; request or chase responses only through an authorized channel. Restate each dated external source as a candidate risk. List prior coverage, carry open findings forward, and decide what can be relied on. Select the in-scope risks with a reason for each, list their asserted controls, and note the mapping gaps.\n2. Derive questions from each input and keep the origin attached, ask how the control actually operates, who performs it, what evidence it leaves, and what happens when it fails or is bypassed rather than whether it exists, include a question for every contradiction between the inputs, and sequence by process flow with an interviewee and evidence request on each.\n\nVerify team competence, disclose independence impairments and resolve safeguards before fieldwork; agree objectives, criteria, period, scope and materiality.\n\n**Record in AssureSwarm**\n1. Record the response status, the issues disclosed and the owners who did not respond; the sources reviewed, candidate risks and near-term obligations; prior coverage, open findings carried forward and the prior conclusions relied on; and the in-scope risks with rationale, their asserted controls, and the mapping gaps. Raise new items as Issues and link the risks and controls to this audit.\n2. Record the question set with the source of each question, the assigned interviewee, and the evidence to request, together with the interviewees, sessions, and dates. Also record evidence to request in the room.\n\n**Exit criteria**\nEngagement lead provides expertise: Every owner has responded or is recorded as non-responsive, the external view is sourced and dated, each reliance on a prior conclusion has a basis, the risk set is justified with its controls, and every contradiction between the inputs is a walkthrough question, not a conclusion. Every question traces to a planning input, contradictions between inputs are represented, each question has an interviewee and evidence request, and an approver accepted the instrument before the business is engaged.","kind":"task","label":"Draft the walkthrough question set","requiredApprovals":1},"id":"walkthrough-questions"},{"data":{"controls":["UC-AUDIT-05","UC-AUDIT-11","UC-AUDIT-12"],"instructions":"**Objective**\nBuild the risk and control matrix. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved question set, the in-scope risk and control set, process narratives, system screens, reports, and evidence produced in the room, and the interviewees confirmed for each session.\n2. Use the in-scope risk and control set, the walkthrough observations and deviations, prior testing results and reliance decisions, and the external obligations in scope.\n\n**Procedure**\n1. Walk the process in operating order rather than register order, follow at least one live item through every handoff, system, approval, and exception path, ask the assigned questions and follow each answer where it goes, observe the control operating rather than accepting a description, and capture who can override and what an override leaves behind.\n2. Record for each in-scope risk the controls that address it with owner, frequency, automation, and key-control status, conclude on design from what was observed rather than asserted, record a design gap where no control addresses a risk, define the testing approach and population for each control to be tested, and route gaps to Issues.\n\n**Record in AssureSwarm**\n1. Record the sessions, participants, item traced, observations against each question, deviations between asserted and observed design, and the evidence obtained or still outstanding. Also record walkthrough date; evidence still outstanding, with owner and date.\n2. Record the matrix row by row with risk, control, owner, design conclusion, testing approach, and population, link the risks and controls to this audit, and raise Issues for the design gaps. Also record matrix summary - risk, control, owner, design conclusion, testing approach; design gaps raised as Issues; planning decision.\n\n**Exit criteria**\nIndependent audit supervisor provides approval: The process has been observed end to end with at least one item traced through, every approved question is answered or recorded as unanswered with a reason, deviations are documented, and outstanding evidence requests have owners and dates. Every in-scope risk has either a mapped control with a design conclusion or a recorded design gap, the testing approach is defined for each control to be tested, and The authorized reviewer have accepted the matrix as the basis for fieldwork.","kind":"task","label":"Build the risk and control matrix","requiredApprovals":1},"id":"rcm"}],"sourceTemplateId":"workflow-library:audit-planning-scoping"}
