8.2 Risk-Based Compliance Audit Planning: Scoping, Sampling, Fieldwork, and Workpapers

Key Takeaways

  • Compliance audit planning must be rigorously risk-based, aligning audit frequency, scope, and resource allocation with the organization's enterprise risk assessment, regulatory scrutiny, and past enforcement history.
  • Audit sampling strategies must be intentionally chosen: statistical sampling (attribute/stratified) provides mathematically defensible error rates across large populations, while judgmental/targeted sampling focuses on high-risk, red-flag transactions.
  • Compliance audit fieldwork employs a hierarchy of testing procedures—inquiry, observation, inspection of records, and re-performance—with physical inspection and re-performance offering the highest level of corroborative evidentiary value.
  • Audit documentation must satisfy the 'Reperformability Standard,' ensuring that an experienced, independent compliance professional could review the workpapers, re-execute the test steps, and arrive at the exact same conclusion without external explanation.
  • Documenting audit findings requires structuring all control exceptions using the Five C's Framework: Condition, Criteria, Cause, Consequence, and Corrective Action.
Last updated: August 2026

8.2 Risk-Based Compliance Audit Planning: Scoping, Sampling, Fieldwork, and Workpapers

An effective compliance program cannot audit every transaction, employee, vendor, or operational process across an enterprise. Attempting to conduct exhaustive, enterprise-wide auditing without risk prioritization squanders compliance resources on low-consequence administrative activities while leaving catastrophic legal vulnerabilities undetected.

Under FSGO §8B2.1(b)(5)(A) and Department of Justice (DOJ) guidelines, compliance auditing must be risk-based, methodologically disciplined, and thoroughly documented. From initial scoping and sample selection to fieldwork execution and workpaper archiving, compliance professionals must execute audits with professional skepticism, technical precision, and evidentiary rigor.


1. The Risk-Based Compliance Audit Lifecycle

A professional compliance audit follows a structured, six-phase lifecycle derived from the Institute of Internal Auditors (IIA) International Professional Practices Framework (IPPF) and standard compliance management practices:

The Six Phases of the Compliance Audit Lifecycle:
├── Phase 1: Risk Assessment & Universe Scoping (Heat maps, regulatory trends, past audit history)
├── Phase 2: Audit Engagement Planning & Notification (Audit charter, scope memo, kickoff meeting)
├── Phase 3: Sampling Methodology Selection (Statistical vs. Directed/Judgmental sampling)
├── Phase 4: Fieldwork & Substantive Testing (Inquiry, observation, inspection, re-performance)
├── Phase 5: Workpaper Documentation & Quality Review (Reperformability standard, sign-offs)
└── Phase 6: Reporting, Exit Conference & Remediation (Five C's findings, Management Action Plans)

Phase 1: Risk Assessment & Audit Universe Scoping

The audit universe encompasses all auditable business units, legal entities, corporate functions, third-party relationships, and regulatory risk areas within the enterprise. Scoping requires prioritizing high-inherent-risk areas based on:

  • Enterprise Compliance Risk Assessment (ECRA) Scores: Operations in high-corruption jurisdictions (Transparency International CPI), highly regulated sectors (healthcare, defense, financial services), or complex commercial structures.
  • Regulatory Enforcement Trends: Shifting priorities from the DOJ, SEC, FTC, EPA, or sector-specific regulators.
  • Operational and Management Changes: Rapid business expansion, cross-border M&A integrations, new enterprise software deployments, or high leadership turnover.
  • Historical Incident Data: Prior substantiated whistleblower allegations, recurring monitoring exceptions, or past audit findings.

Phase 2: Engagement Planning and Audit Scoping Memo

Prior to commencing fieldwork, the audit lead drafts a formal Audit Scoping Memorandum and Audit Program that defines:

  1. Audit Objectives: The specific compliance assertions being tested (e.g., verifying compliance with the Foreign Corrupt Practices Act in Latin American subsidiary sales).
  2. Audit Scope & Boundaries: The specific entities, locations, date ranges (e.g., Q1–Q4 of the preceding fiscal year), and transaction types included—and explicitly excluded—from testing.
  3. Test Procedures: Step-by-step audit testing scripts detailing the required evidence, sample size, testing methods, and pass/fail criteria.

2. Sampling Methodologies in Compliance Auditing

Selecting an appropriate sampling strategy is critical. An improper sampling methodology can result in flawed audit conclusions, either generating false assurance or misrepresenting localized errors as systemic control failures.

Sampling Methodology Taxonomy:
├── Statistical Sampling (Mathematical, Measurable Sampling Risk)
│   ├── Random Sampling: Equal selection probability; baseline compliance testing
│   ├── Stratified Sampling: Segmenting population by risk tiers (e.g., high-dollar vs. low-dollar)
│   └── Attribute Sampling: Binary testing (control present vs. control absent)
└── Non-Statistical / Directed / Judgmental Sampling (Targeted, Risk-Focused)
    ├── High-Value Threshold: 100% testing of transactions exceeding specific dollar limits
    ├── Red-Flag Anomaly Targeting: Specific testing of split purchase orders, round numbers, or risky vendors
    └── Outlier / Exception-Based: Testing specific transactions identified by continuous monitoring

Comprehensive Comparison of Audit Sampling Methods

Sampling TechniqueMethodological DescriptionIdeal Compliance Use CasePrimary Limitations & Exam Watch
Statistical Attribute SamplingMathematical selection where every item has a known selection probability; tests binary control compliance (Yes/No).Testing enterprise-wide policy adherence (e.g., verifying employee conflict-of-interest disclosure completion across 20,000 employees).Requires larger sample sizes; does not inherently focus on high-risk transactions unless stratified.
Stratified Risk SamplingDividing the population into distinct sub-populations (strata) based on risk attributes (e.g., transaction value, country risk score) and sampling each stratum independently.Auditing third-party distributor commissions across multi-tiered global operations (sampling 100% of high-risk agents and 10% of low-risk agents).Requires clean, well-categorized underlying ERP/financial data to perform accurate stratification.
Directed / Judgmental SamplingAuditor selects specific transactions based on professional judgment, specific red flags, high dollar values, or known vulnerabilities.Auditing high-risk third-party consulting contracts, government tender bid files, or executive expense reports.Cannot mathematically project error rates to the entire population; introduces potential auditor bias.
100% Full-Population TestingAutomated testing of every single transaction in the population using specialized audit software (e.g., ACL, IDEA, SQL).Testing sanctions screening against global vendor master files or detecting duplicate invoice payments.Limited to digital, structured data; cannot evaluate qualitative attributes (e.g., commercial reasonableness of deliverables).

Key Principle — Sampling Risk vs. Non-Sampling Risk:

  • Sampling Risk: The risk that the auditor's conclusion based on a sample differs from the conclusion that would be reached if the entire population were subjected to the same audit procedure.
  • Non-Sampling Risk: The risk that the auditor reaches an incorrect conclusion due to human error, misinterpreting evidence, or applying an inappropriate audit procedure (e.g., failing to recognize a forged invoice).
Loading diagram...
Compliance Audit Planning, Fieldwork, and Workpaper Documentation Process

3. Fieldwork Execution and the Hierarchy of Audit Evidence

Audit fieldwork involves gathering sufficient, competent, and relevant evidence to evaluate whether compliance controls operate effectively. Compliance auditors utilize four primary testing techniques, arranged in an ascending hierarchy of reliability:

Hierarchy of Audit Evidence Reliability:
├── Level 1: Inquiry (Oral interviews, questionnaires, management representations) -> Lowest Reliability
├── Level 2: Observation (Directly watching employees perform a control procedure)
├── Level 3: Inspection (Examining physical or electronic source records, contracts, approvals)
└── Level 4: Re-Performance (Independently executing the control from raw data) -> Highest Reliability

The Four Core Testing Techniques

  1. Inquiry: Interviewing process owners, compliance liaisons, and business managers. Limitation: Inquiry alone is never sufficient audit evidence; management statements must be corroborated by documentary proof.
  2. Observation: Watching personnel perform compliance tasks (e.g., witnessing warehouse personnel scan serialized medical devices or observing visitor badge screening at a secure facility). Limitation: Observation is valid only for the specific point in time when the auditor is present (the Hawthorne Effect: employees perform better when observed).
  3. Inspection of Records: Examining purchase orders, contracts, invoices, timesheets, proof of services, and management approval stamps. This is the cornerstone of compliance transaction testing.
  4. Re-Performance: The auditor independently recalculates, re-screens, or re-executes the control (e.g., re-running an automated sanctions screening algorithm against a test vendor database or independently recalculating complex distributor rebate tiers). Re-performance provides the highest degree of audit assurance.

4. Audit Workpaper Standards: The Reperformability Mandate

Audit workpapers constitute the official, legal, and operational record of the audit engagement. They document the planning, scoping, sampling, testing procedures, evidence collected, and conclusions reached.

The Reperformability Standard

The universal benchmark for compliance audit workpapers is the Reperformability Standard:

Audit workpapers must contain sufficient detail, clarity, and cross-referencing such that an experienced compliance auditor, having had no prior connection with the engagement, can review the workpapers, re-execute the exact same audit procedures on the same source data, and reach the identical factual conclusion without verbal explanation from the original auditor.

Core Workpaper Anatomy:
├── 1. Header Information: Engagement Title, Project ID, Date, Subject Business Unit
├── 2. Purpose & Objective: Clear statement of the specific compliance assertion being tested
├── 3. Scope & Sample Selection: Exact criteria used to extract the sample from the population
├── 4. Source of Data: System names, file paths, report run parameters, and extraction dates
├── 5. Step-by-Step Test Procedure: Precise testing scripts and evaluation rules
├── 6. Tickmarks & Legends: Standardized symbols indicating specific verification steps executed
├── 7. Summary of Findings & Exceptions: Clear tabulation of all errors, deviations, and root causes
├── 8. Auditor Conclusion: Explicit determination regarding control design and effectiveness
└── 9. Signatures & Approvals: Preparer signature/date and Reviewer/Supervisor sign-off/date

5. Structuring Audit Findings: The Five C's Framework

When compliance audit fieldwork identifies a control exception or regulatory violation, the finding must be articulated with precision. Vague findings produce administrative friction and fail to drive remediation. Best-in-class compliance programs utilize the Five C's Framework for all audit findings:

The Five C's of Compliance Audit Findings:
├── 1. Condition: What was actually found? (The factual situation and exception rate)
├── 2. Criteria: What should have happened? (The statutory mandate, policy clause, or SOP standard)
├── 3. Cause: Why did the breakdown occur? (The underlying root cause, e.g., training void, system bug)
├── 4. Consequence: What is the risk or impact? (Regulatory fines, legal liability, reputational loss)
└── 5. Corrective Action: What must management do? (Actionable remediation plan with owner & deadline)

Practical Application Example: Third-Party Due Diligence Finding

  • Condition: 14 out of 50 sampled international sales agent files (28%) lacked documented anti-corruption due diligence renewals prior to contract extension.
  • Criteria: Enterprise Third-Party Management Policy Section 4.2 requires mandatory due diligence refresh every 24 months for all high-risk intermediaries.
  • Cause: Automated ERP contract renewal workflows did not have a mandatory system hard-stop linked to the compliance due diligence expiration date.
  • Consequence: Exposure to vicarious liability under the FCPA and UK Bribery Act for corrupt actions by unvetted intermediaries.
  • Corrective Action: Management must configure a hard-stop in the ERP procurement module by November 15, preventing purchase order issuance to any intermediary with an expired due diligence certification, and immediately execute retroactive vetting on the 14 identified agents.
Test Your Knowledge

A senior compliance auditor is evaluating the company's anti-kickback compliance controls regarding physician consulting agreements. During fieldwork, the auditor interviews the Vice President of Medical Affairs, who provides a signed written statement affirming that all 120 consulting agreements executed during the fiscal year were strictly evaluated for Fair Market Value (FMV) and that physicians provided verified written work deliverables. The auditor places this statement in the workpapers and marks the control area as fully compliant without reviewing the underlying contracts, FMV valuation benchmarks, or physician work deliverables. How should the Chief Audit Executive evaluate this fieldwork under professional audit standards?

A
B
C
D
Test Your Knowledge

An internal compliance audit team is planning an anti-corruption audit across a multinational conglomerate operating in 45 countries. The organization utilizes over 3,000 third-party commercial intermediaries, ranging from low-risk freight forwarders in low-corruption countries to high-risk sales agents interacting directly with state-owned enterprises in high-corruption jurisdictions. What sampling methodology should the audit team select to ensure that high-consequence compliance risks receive rigorous testing while still evaluating overall program adherence?

A
B
C
D
Test Your Knowledge

During a compliance audit of a global technology firm, the audit team discovers that 18% of newly onboarded software distributors did not have signed anti-bribery contractual clauses attached to their master channel agreements, violating the corporate Code of Conduct. Commercial sales management objects to the auditor drafting a formal audit finding, arguing that because forensic data analytics revealed zero corrupt payments or bribes during the period, no compliance breach occurred. From a compliance audit and regulatory enforcement perspective, how should the audit lead respond?

A
B
C
D