2.2 Elements Used to Build Engagement Objectives

Key Takeaways

  • Official A.1.b elements that shape objectives are regulatory requirements; strategy and objectives; governance, risk management, and control processes; risk appetite and tolerance; internal policies; previous audit reports; work of other assurance providers; and whether the engagement is assurance or advisory
  • Each element changes the objective’s purpose, not just the background paragraph: regulation can force a compliance purpose; appetite can change what “significant” means; prior reports and other assurance change what must be followed up versus what may be relied upon
  • Assurance objectives are determined more independently by internal audit from risk and the IPPF; the nature and scope of advisory services are agreed with the stakeholder requesting the work
  • A payroll compliance assurance review and an advisory review of new ERP control design can cover the same process family and still have different objectives, different independence implications, and different Topical Requirement force
Last updated: August 2026

2.2 Elements Used to Build Engagement Objectives

Quick Answer: The 2025 CIA Part 2 expanded specs list the elements to consider when developing engagement objectives: regulatory requirements; the organization’s strategy and objectives; governance, risk management, and control processes; risk appetite and tolerance; internal policies; previous audit reports; work of other assurance providers; and whether the engagement is intended to provide assurance or advisory services. Each element changes the objective. Assurance objectives are determined more independently. Advisory nature and scope are agreed with the stakeholder requesting the service.

Standard 13.3 requires internal auditors to establish and document objectives that articulate the purpose of the engagement. Purpose is not a slogan. It is the question the work is designed to answer. If you copy last year’s objective, or accept the process owner’s wording, you have not “considered” the official elements—you have skipped them.

Do not jump to evaluation criteria here (Chapter 3) or to the work program (Chapter 10). This section is only: what are we trying to achieve, and which inputs change that statement?

How each official element changes the objective

Regulatory requirements. Law and regulation can turn an efficiency review into a compliance engagement. A U.S. payroll activity sits under the Fair Labor Standards Act (overtime, minimum wage, hours records), federal and state payroll-tax withholding and deposit rules, and often state wage-payment statutes. If those requirements apply, an objective that says only “evaluate whether payroll is processed efficiently” is incomplete. The objective should be able to support a conclusion on compliance with applicable wage-and-hour and payroll-tax requirements, in addition to whatever operational purpose remains. Regulation also constrains scope: excluding overtime because the sample is “hard” is not a planning convenience; it is dropping a legally relevant population.

Organization’s strategy and objectives. Internal audit’s Purpose is to strengthen the organization’s ability to create, protect, and sustain value. Engagement objectives should connect to what the activity is trying to achieve and how that activity supports enterprise strategy. If the strategy is rapid acquisition, a payroll objective that ignores onboarding of acquired-entity employees and conversion of their pay data misses the strategic risk. If the strategy is cost-out, an objective that never asks whether detective controls still operate after headcount cuts is equally misaligned. Strategy does not let you ignore regulation; it tells you which additional purposes belong in the objective.

Governance, risk management, and control processes. Part 2 conclusions later rest on the effectiveness of these three process groups (Section B.8). Objectives that only promise “test a sample of paychecks” never licensed you to conclude on governance or risk management. If the purpose includes those processes—and for many assurance engagements it should—the objective must say so. That is also how a Topical Requirement bites: cybersecurity’s baseline is G, R, and C, not “a few ITGCs.”

Risk appetite and tolerance. Appetite and tolerance change what “significant” means inside the objective. If the board has zero tolerance for payroll-tax penalties and wage-and-hour violations, the objective should prioritize compliance evidence over cycle-time improvement. If leadership has explicitly accepted a longer payroll-cycle time to protect accuracy, writing an objective that treats a two-day delay as a control failure fights the organization’s risk posture. Appetite is not a reason to ignore a mandatory Topical Requirement or a legal requirement. It is a reason to stop treating every inefficiency as equally important.

Internal policies. Policies are local criteria sources, but they also shape purpose. Dual control over bank-file release, segregation between timekeeping and pay-file approval, and required background checks for payroll administrators are policy-driven. An objective that tests only external law will miss a dual-control breakdown that never violated FLSA. Conversely, a policy that is silent or outdated does not erase regulation. When policy and law conflict, the objective must still be capable of addressing the binding requirement, and the conflict itself may become part of what you evaluate later.

Previous audit reports. Last year’s findings, management’s open actions, and areas not covered last cycle all change this year’s purpose. If overtime completeness was a repeat finding, an objective that “takes a fresh look at vendor setup” while skipping overtime is not independent thinking—it is coverage failure. If last year’s report already concluded on tax-deposit timing and actions are still in progress, you may follow up rather than re-perform the entire test—but that choice belongs in the documented objective and scope, not as an undocumented shortcut. Do not copy last year’s objective verbatim; the point of reading prior reports is to change this one.

Work of other assurance providers. SOX testers, external auditors, second-line compliance, and a co-sourced IT team may already cover pieces of payroll. That can narrow your objective if you have a documented basis to rely, or expand it if their work does not reach the risk that justified this engagement. Reliance is not automatic. If external audit tested a small sample of payroll accruals for the financial-statement opinion, that work may not support an operational objective on wage-and-hour completeness. Document why you will rely, partially rely, or not rely. Coordination belongs in planning; it is not a Part 3-only “assurance map” exercise when it changes this engagement’s purpose.

Assurance versus advisory. This element is the exam’s favorite because it changes who sets the objective.

AssuranceAdvisory
Who sets nature and scopeInternal audit determines objectives more independently from risk, the charter, Standards, and applicable Topical RequirementsNature and scope are agreed with the stakeholder requesting the service
Typical purposeIndependent conclusion on governance, risk management, and/or control processes (and often compliance)Advice, insight, or design input; not the same independent conclusion
Topical RequirementsMandatory when applicableRecommended, not required
Process-owner bargainingCannot silently drop high-risk coverage because a manager is uncomfortableCan agree a narrower advisory question, but must document the agreement and the service type
Later independenceBaseline is independent assuranceProviding design advice can create a self-review threat if the same team later gives assurance on that design

Concrete scenario: payroll compliance versus ERP control-design advisory

Engagement A — payroll compliance assurance. The annual plan includes payroll because wage-and-hour findings recurred and the organization is adding two acquired companies. Inputs: FLSA and payroll-tax rules (regulation); acquisition strategy; a prior report with open overtime actions; internal dual-control policy on the bank file; zero tolerance for tax penalties (appetite); external audit’s limited accrual testing (other assurance—insufficient to rely for wage-and-hour). Service type: assurance.

A defensible objective is: Evaluate whether payroll processing for U.S. employees, including recently acquired populations, complies with applicable wage-and-hour and payroll-tax requirements and whether related governance, risk management, and control processes—including privileged access to the payroll file—are designed and operating to provide reasonable assurance of that compliance.

Notice what the inputs did. Regulation put compliance in the purpose. Strategy put acquired populations in. Prior reports put overtime back in. Appetite weighted tax and wage violations over cycle time. Other assurance blocked a tempting scope cut. Cyber as a component pulled the Topical Requirement baseline into the objective. The payroll director does not get to rewrite that into “a friendly efficiency review.”

Engagement B — advisory on new ERP payroll-module control design. The CFO asks internal audit, before go-live, to advise on the proposed segregation-of-duties matrix and automated approval workflows. No historical transaction testing is requested. Service type: advisory. Nature and scope must be agreed and documented: review the design of SOD and automated approvals for the new module; exclude operating-effectiveness testing of the legacy system; exclude an assurance conclusion on current payroll compliance.

That objective is not a weaker version of Engagement A. It is a different purpose. Topical Requirements are recommended, not required; if cyber access design is in the agreed scope, applying the cybersecurity baseline is still good practice and should be written into the agreed statement. If the CFO later wants a sentence in the board pack that “internal audit certified the new payroll module,” that request is an attempt to relabel advisory as assurance. Refuse the relabel, or convert to a separately planned assurance engagement with independently determined objectives—and watch the self-review threat if the same auditors designed the controls they would then “assure.”

Writing the objective so it can survive fieldwork

A usable objective names the activity, the purpose (compliance, design, operating effectiveness of GRC processes, or agreed advisory question), the population or boundary at a high level, and—when relevant—the service type. It does not list every test. Tests are procedures; they come after objectives, criteria, and risk assessment.

Exam stems often hide a bad objective behind agreeable language. “Partner with payroll to improve the process” is advisory language inside an assurance slot. “Validate management’s assertion that controls are effective” without independent determination of purpose subordinates the objective to the auditee. “Review payroll” is not an objective; it is a topic. Build from the eight elements, then lock the service type, then write a sentence a competent outsider could use to judge whether the later scope was sufficient.

Test Your Knowledge

A CFO asks internal audit to review the control design of a new ERP payroll module before go-live and to agree the work will not include testing historical payroll transactions. How should engagement objectives be established?

A
B
C
D
Test Your Knowledge

Prior-year internal audit reports show a repeat overtime-completeness finding in payroll. External audit tested a small sample of payroll accruals for the financial-statement opinion. When building this year’s payroll assurance objective, what is the most appropriate use of those two sources?

A
B
C
D
Test Your Knowledge

The board’s stated risk appetite includes zero tolerance for payroll-tax penalties, while it has accepted longer payroll cycle times to protect accuracy. How should that appetite affect the payroll assurance objective?

A
B
C
D