10.1 Evaluating Adequacy of the Engagement Work Program
Key Takeaways
- GIAS Standard 13.6 requires a documented work program that achieves the engagement objectives and identifies evaluation criteria, tasks, methodologies including analytical procedures and tools, and the internal auditors assigned to each task.
- The chief audit executive must review and approve the work program before it is implemented and promptly when any subsequent changes are made.
- Adequacy is judged against objectives and high residual risks: design, operating-effectiveness, and efficiency procedure families must be present where those are objectives, and each task must plan the evidence to be obtained.
- A library or prior-year file is not adequate until it is tailored to this activity, system, period, and risk assessment; copy-paste programs are a standard CIA trap.
- When the activity, risks, operations, programs, systems, or controls change significantly, update the work program and obtain prompt re-approval rather than improvising or silently dropping tests.
Evaluating the engagement work program is where planning either becomes a usable fieldwork plan or stays a stack of copied steps. CIA Part 2 objective A6d asks you to evaluate adequacy, not to invent a house style. The governing standard is Global Internal Audit Standards (GIAS) Standard 13.6, Work Program. Conformance with the 2024 Standards is expected from 9 January 2025. If a stem still smells like 2017 Standard 2240, translate it: the current test is 13.6 plus the engagement risk assessment from Chapter 7.
Quick Answer: An adequate work program is based on engagement planning (including the engagement risk assessment when applicable); identifies evaluation criteria, tasks to achieve the objectives, methodologies (including analytical procedures) and tools, and the internal auditors assigned to each task; is sufficient to achieve the engagement objectives; is reviewed and approved by the chief audit executive (CAE) before implementation; and is updated and re-approved promptly when the activity or its risks change. A generic copy-paste file that skips high residual risks, omits planned evidence, or silently drops tests is not adequate.
What Standard 13.6 Requires the Program to Identify
Internal auditors must develop and document a work program that achieves the engagement objectives. GIAS 13.6 requires that program to rest on information obtained during engagement planning, including—when applicable—the results of the engagement risk assessment.
The work program must identify:
- Criteria to be used to evaluate each objective.
- Tasks to achieve the engagement objectives.
- Methodologies, including the analytical procedures to be used, and tools to perform the tasks.
- Internal auditors assigned to perform each task.
CIA items often wrap two extra adequacy questions around that mandatory list. First, is the extent of work (period, locations, population or sample approach, depth of test) enough for the residual risk? Extent usually lives inside the task and methodology description, not as a decorative cover-sheet field. Second, are specialists named when the assigned team cannot perform a task competently? Specialist need is a Standard 13.5 resource decision, but an adequate program makes the assignment visible—named internal auditor, guest auditor, or co-sourced specialist—rather than leaving a high-skill task as staff, TBD.
Engagement objectives are set under Standard 13.3 (Chapter 2). The work program does not replace those objectives; it operationalizes them. If an approved objective has no corresponding tasks, criteria, and assigned person, the program is not adequate for that objective even if every other template box is ticked.
Approval, Review, and Subsequent Changes
The CAE must review and approve the engagement work program before it is implemented and promptly when any subsequent changes are made. In many functions the CAE designates an engagement supervisor to perform that review. CIA stems still treat documented supervisory approval as the control: an unsigned draft is not a license to start testing.
Promptly is the keyword for changes. Expanding or shrinking samples, dropping a location, swapping observation for a desk review, or adding a specialist after a system incident are changes. Obtaining initials at the closing meeting after the work was skipped is not prompt approval. It is an undocumented limitation.
Adequacy Tests That Separate a Plan from a Template
Completeness of headings is not adequacy. Score the program against the objectives and against high residual risks from planning.
| Adequacy test | Question the reviewer asks | Typical CIA failure |
|---|---|---|
| High residual-risk coverage | Does every high residual risk have tasks, criteria, and extent? | Last year's accounts-payable program ignores this year's ERP vendor-master access risk |
| Design vs operating effectiveness vs efficiency | Where those are objectives, are matching procedure families present? | Design walk-throughs only, when the objective includes operating effectiveness |
| Planned evidence | Does each task state what evidence, from whom, and how much? | Test a sample of invoices with no source, period, or population |
| Tailoring | Is this program built for this activity, system, period, and geography? | Industry template with the client name search-and-replaced |
| Sufficiency vs objectives | If every task is executed as written, would the objectives be achieved? | Three days of cutoff work against a six-location revenue objective |
| Assignment and skills | Are named auditors or specialists competent for each task? | New hire assigned to review firewall rules with no specialist support |
| Approval trail | Is the current version approved, and are changes re-approved promptly? | Supervisor signed an obsolete draft; fieldwork used a different file |
Chapter 9 already taught procedures to evaluate control design, test operating effectiveness, and test control efficiency. Do not rebuild those catalogs here. The adequacy question is narrower: if the engagement objectives include design, operating effectiveness, or efficiency, the work program must contain the corresponding procedure family. A beautifully written design walk-through script cannot support an operating-effectiveness objective by itself.
Evidence planning is the other frequent miss. An adequate task names the record or system extract, the owner, the period, and whether the auditor will inspect, reperform, observe, confirm, or analyze. Obtain evidence as needed is not a procedure.
Copy-Paste Programs Are the Reliable Trap
A library program is a starting point. Adequacy is judged after tailoring to this engagement. Red flags the exam loves:
- Same steps as last year despite a system conversion, acquisition, new third party, new regulation, or new Topical Requirement in scope.
- Tasks written as management control objectives (vendor payments are accurate) instead of auditor procedures (recalculate three-way match exceptions for March–May disbursements).
- No line of sight from high residual risks to specific tasks.
- Methodologies listed as per methodology with no methodology.
- Assignments still TBD after a fieldwork start date is locked.
- Efficiency objectives with no efficiency-oriented procedures, or the reverse: a cost-study disguised as an assurance program with no design or operating-effectiveness work.
If the in-charge cannot explain why a step is in or out, the program is not ready for CAE or supervisor approval.
Update the Program When Risks Change
Planning is not a frozen photograph. When the organization's activities, risks, operations, programs, systems, or controls change significantly—or when fieldwork reveals a risk that planning missed—the work program must be reassessed. Revise tasks, methodologies, extent, tools, and assignments, then obtain prompt approval of the change.
Two opposite failures both miss 13.6:
- Rigid execution of an obsolete program (it was already approved, so we will not add the new payment interface).
- Informal improvisation (we skipped the inventory observation because the warehouse was busy) with no documented, approved change.
The professional path is recognize the change, decide whether the current program is still sufficient to achieve the objectives, revise it, approve it, and then execute the revised program. Silently doing less work to protect the original due date is not an update; it is the resource-limitation trap Chapter 10.3 treats as a finding against the auditors.
Worked Adequacy Review
Consider a procure-to-pay engagement. Approved objectives: (1) vendor-master changes are authorized, (2) three-way match operates effectively during the period, and (3) duplicate-payment prevention is efficient enough to catch repeats at reasonable cost. Residual risk is high for vendor-master access after ERP go-live, medium for matching, and medium for duplicates.
An adequate program would state criteria (policy, configuration standards, duplicate-payment threshold); assign vendor-master access and configuration tests to someone with ERP security skill or name a specialist; include operating-effectiveness procedures for the match (not only a design narrative); include efficiency-oriented analytics for duplicates without turning the whole job into a consulting cost study; specify evidence and extent; and show CAE or supervisor approval before kickoff.
A program that copies test 25 invoices from last year, ignores ERP access, and lists no specialist is not adequate—even if someone signed the cover sheet. Signature without substance does not satisfy 13.6.
How to Attack a CIA Stem
When the item gives you a work-program excerpt, score in this order: (1) Does it cover the high residual risks and the stated objectives? (2) Does it identify 13.6's required elements, including extent and evidence inside the tasks? (3) Are design, operating-effectiveness, and efficiency procedure families present where those are objectives? (4) Is approval timely, including for changes? Pick adequate only when those tests pass. A header, a budget, and a signature block are not enough.
Under GIAS Standard 13.6, which of the following must the engagement work program identify?
An in-charge copies last year's accounts-payable work program, updates the date, and begins testing. This year's high residual risk is unauthorized vendor-master access after an ERP go-live. The copied program has no access, configuration, or ITGC tasks. Which conclusion is best?
When must the CAE review and approve the engagement work program?