4.1 Audit Planning & Overall Audit Strategy (AU-C 300)

Key Takeaways

  • Audit planning is a continuous, iterative process governed by AU-C 300 that begins shortly after engagement acceptance and continues through the completion of the audit.
  • The Overall Audit Strategy establishes the scope, timing, direction, and resource allocation of the engagement, guiding the development of the detailed Audit Plan.
  • The detailed Audit Plan operationalizes the strategy by specifying the nature, timing, and extent of planned risk assessment procedures and further audit procedures at the assertion level.
  • Engagement partners and key team members must participate in mandatory planning discussions, including the AU-C 240 / AU-C 315 fraud brainstorming session.
  • Under AU-C 260, the auditor communicates an overview of the planned scope and timing, including significant risks, without detail that would make procedures predictable.
Last updated: September 2026

4.1 Audit Planning & Overall Audit Strategy (AU-C 300)

Exam Focus: Audit planning is one of the most heavily tested foundational topics on the CPA AUD exam. Candidates must master the distinct responsibilities outlined in AU-C 300 (Planning an Audit), the precise boundary separating the Overall Audit Strategy from the Detailed Audit Plan, the mandatory participation of engagement leadership in risk brainstorming sessions, and the critical rules governing communications with Those Charged with Governance (TCWG) under AU-C 260.


1. Overview and Purpose of Audit Planning

Under AU-C 300, planning an audit involves establishing the overall audit strategy for the engagement and developing an audit plan. Adequate planning is not merely a procedural formality; it directly impacts audit quality, efficiency, and the auditor's ability to obtain sufficient appropriate audit evidence to reduce audit risk to an acceptably low level.

Why Planning Matters

Effective planning benefits the audit of financial statements in several distinct ways:

  1. Focusing on High-Risk Areas: Helps the auditor devote appropriate attention to important areas of the audit (e.g., highly subjective accounting estimates, complex revenue transactions, or areas with elevated fraud risk).
  2. Timely Problem Identification: Enables the auditor to identify and resolve potential problems on a timely basis (such as contentious accounting treatments, going concern indicators, or IT system migrations).
  3. Organizing and Managing the Engagement: Ensures the engagement is properly organized and managed so that it runs effectively and efficiently within required filing and reporting deadlines.
  4. Appropriate Resource Selection: Assists in selecting engagement team members with appropriate levels of capabilities and competence to respond to anticipated risks, including assigning specialists or experienced professionals to complex areas.
  5. Direction, Supervision, and Review: Facilitates the direction and supervision of engagement team members and the review of their work per AU-C 220 (Quality Management for an Engagement Conducted in Accordance with GAAS).
  6. Coordination: Facilitates coordination of work done by component auditors, service auditors, and valuation or IT specialists.
+-----------------------------------------------------------------------------------------+
|                              AU-C 300 PLANNING ARCHITECTURE                              |
|                                                                                         |
|  [ Preliminary Engagement Activities ]                                                   |
|    • Client Continuance & Ethical Evaluation (Independence)                             |
|    • Terms of Engagement / Engagement Letter (AU-C 210)                                 |
|                            │                                                            |
|                            ▼                                                            |
|  [ Overall Audit Strategy ]                                                             |
|    • Scope (Framework, Locations, Specialists)                                          |
|    • Timing (Reporting Deadlines, Interim vs. Final)                                    |
|    • Direction (Materiality, High-Risk Areas, Tone at the Top)                          |
|    • Resources (Staffing, Partner Review Hours, Specialist Allocation)                  |
|                            │                                                            |
|                            ▼                                                            |
|  [ Detailed Audit Plan ]                                                                |
|    • Risk Assessment Procedures (AU-C 315)                                              |
|    • Planned Further Audit Procedures: Tests of Controls & Substantive Tests (AU-C 330) |
|    • Other Procedures Required by GAAS (Confirmations, Legal Inquiries, Inventory)      |
+-----------------------------------------------------------------------------------------+

2. Preliminary Engagement Activities

AU-C 300 dictates that the auditor must perform specific preliminary engagement activities at the beginning of the current audit engagement—prior to starting significant planning activities:

A. Client Acceptance and Continuance (AU-C 220)

The auditor must evaluate whether the firm maintains the capabilities, competence, time, and resources to perform the engagement. Furthermore, the firm must assess management integrity and consider whether significant matters arose during the current or prior engagements that affect continuance.

B. Compliance with Ethical and Independence Requirements (AU-C 220)

The engagement partner must evaluate compliance with relevant ethical requirements, including independence (both independence of mind and appearance) under the AICPA Code of Professional Conduct and, where applicable, the SEC and PCAOB rules. Any identified threats to independence must be eliminated or reduced to an acceptable level via safeguards; if safeguards are insufficient, the firm must withdraw or decline the engagement.

C. Establishing an Understanding of the Terms of Engagement (AU-C 210)

The auditor must confirm that a mutual understanding exists between the auditor and management (and, when appropriate, TCWG) regarding the terms of the audit engagement. This understanding must be documented in a written Engagement Letter, establishing:

  • The objective and scope of the audit.
  • The responsibilities of the auditor.
  • The responsibilities of management (for financial statement preparation, design and maintenance of internal controls, and providing unrestricted access to records and personnel).
  • Identification of the applicable financial reporting framework (e.g., U.S. GAAP, IFRS).
  • The expected form and content of reports to be issued.

3. Overall Audit Strategy vs. Detailed Audit Plan

A critical distinction tested on the CPA exam is the difference between the Overall Audit Strategy and the Detailed Audit Plan. While the strategy provides the broad operational blueprint, the audit plan provides the detailed tactical execution.

STRATEGY = The "What, When, Where, and Who" (High-Level Direction & Resource Allocation)
PLAN     = The "How" (Specific Step-by-Step Audit Programs at the Assertion Level)

Components of the Overall Audit Strategy

In establishing the overall audit strategy, the auditor focuses on four core elements:

  1. Characteristics of the Engagement (Scope):
    • The applicable financial reporting framework (e.g., U.S. GAAP vs. cash/tax special purpose framework).
    • Industry-specific reporting requirements (e.g., statutory insurance accounting, banking regulations).
    • Operating locations, subsidiaries, and segments requiring component audits.
    • The need for specialized IT audit capabilities or valuation specialists.
    • The extent of reliance on internal audit work or service organization controls (SOC reports).
  2. Reporting Objectives, Timing, and Communications (Timing):
    • Entity's reporting timetable and filing deadlines (e.g., SEC Form 10-K deadline, debt covenant deadlines).
    • Key dates for board and audit committee meetings.
    • Timing of interim procedures versus year-end substantive procedures.
    • Organization of team progress meetings and partner review milestones.
  3. Significant Factors Directing Engagement Efforts (Direction):
    • Setting planning materiality, performance materiality, and tolerable misstatement.
    • Preliminary identification of high-risk areas and significant risks (e.g., revenue recognition, complex estimates).
    • Results of prior audits and evaluation of the entity's control environment ("tone at the top").
    • Significant entity or industry changes (mergers, new IT systems, changes in accounting standards).
  4. Nature, Timing, and Extent of Resources (Resource Deployment):
    • Selecting engagement team members (assigning experienced staff to high-risk areas).
    • Allocating hours and budget across specific audit areas.
    • Scheduling the timing of resource deployment (e.g., inventory count observations on December 31).

Components of the Detailed Audit Plan

The audit plan is more detailed than the strategy. It directly translates the strategy into operational audit programs. Per AU-C 300, the audit plan must include a description of:

  1. Planned Risk Assessment Procedures: The nature, timing, and extent of procedures planned under AU-C 315 to understand the entity, its environment, and its internal control, thereby identifying and assessing risks of material misstatement (RMM).
  2. Planned Further Audit Procedures: The nature, timing, and extent of tests of controls and substantive procedures at the assertion level planned under AU-C 330 in response to assessed risks.
  3. Other Audit Procedures: Any other procedures required to comply with GAAS (e.g., direct inquiries of legal counsel per AU-C 501, sending bank confirmations per AU-C 505, or evaluating subsequent events per AU-C 560).

Structural Comparison: Strategy vs. Plan

AttributeOverall Audit StrategyDetailed Audit Plan
Primary PurposeEstablishes scope, timing, direction, and guides resource deploymentTranslates strategy into tactical procedures to gather sufficient evidence
Level of DetailHigh-level, macro overview of engagement parametersGranular, step-by-step audit programs at the transaction/assertion level
Key ElementsScope, reporting deadlines, preliminary materiality, staffing allocationsRisk assessment procedures, tests of controls, substantive tests of details, analytics
Timing of CreationFormulated first during the initial planning phaseDeveloped iteratively as risk assessment procedures yield concrete risk findings
Authoritative FocusAU-C 300.07–.08AU-C 300.09 and AU-C 330

4. The Continuous, Dynamic & Iterative Nature of Planning

Exam Trap: Many candidates mistakenly view planning as a one-time phase that concludes once fieldwork begins. Under GAAS, planning is continuous, dynamic, and iterative throughout the entire engagement.

As the audit progresses, unexpected events, changes in conditions, or audit evidence obtained from procedures may require the auditor to modify the overall audit strategy and audit plan:

  • Unexpected Substantive Misstatements: If substantive tests uncover frequent, unexpected misstatements in inventory valuations, initial risk assessments of control risk must be revised upward, necessitating expanded substantive testing or lower tolerable misstatement.
  • Control Testing Failures: If planned reliance on internal controls is shattered because tests of operating effectiveness reveal high deviation rates, the auditor must discard the planned control reliance strategy and substantially increase the extent and rigor of substantive procedures.
  • New Information or Scope Limitations: Discovery of undisclosed related-party transactions or regulatory investigations requires updating the audit plan to include targeted investigative procedures.

Whenever significant revisions are made to the strategy or plan, the auditor must document the rationale for the modifications and the resulting changes to planned procedures in the audit working papers.


5. Engagement Team Leadership & Mandatory Brainstorming Sessions

Audit planning requires active engagement leadership. AU-C 300 explicitly mandates that the engagement partner and other key members of the engagement team must be involved in planning the audit, including participating in the discussion among team members.

+---------------------------------------------------------------------------------+
|                MANDATORY ENGAGEMENT TEAM BRAINSTORMING SESSION                  |
|                             (AU-C 240 & AU-C 315)                               |
|                                                                                 |
|   Key Participants: Engagement Partner, Managers, In-Charge, Specialists        |
|                                                                                 |
|   Core Agendas:                                                                 |
|   1. Financial Statement Susceptibility to Error & Fraud                        |
|   2. Management Override of Controls & Concealment Techniques                   |
|   3. Incentives, Pressures, Opportunities, and Rationalizations (Fraud Triangle)|
|   4. Setting the Tone of Professional Skepticism Across the Team                |
|   5. Designing Unpredictable Audit Procedures                                   |
+---------------------------------------------------------------------------------+

The Mandatory Fraud Brainstorming Session (AU-C 240 / AU-C 315)

GAAS requires a formal discussion among key engagement team members regarding the susceptibility of the entity's financial statements to material misstatement:

  • Susceptibility to Fraud and Error: Discussion of how and where the financial statements might be susceptible to material misstatement due to fraud, how management could perpetrate and conceal fraudulent financial reporting, and how entity assets could be misappropriated.
  • Maintaining Professional Skepticism: The engagement partner must emphasize the necessity of maintaining an attitude of professional skepticism throughout the audit—setting aside any prior beliefs regarding management honesty and integrity.
  • Communication Across Team: If team members operate in different physical locations (e.g., component auditors or multi-location teams), the partner must determine which matters to communicate to team members not directly participating in the primary session.
  • Ongoing Dialogue: Brainstorming is not limited to a single initial meeting. If new fraud indicators arise during fieldwork, team communications must resume to reassess fraud risks.

6. Planning Communications with Those Charged with Governance (TCWG)

Under AU-C 260 (The Auditor's Communication With Those Charged With Governance), the auditor must establish a two-way dialogue with the audit committee or board of directors. During the planning phase, specific guidelines govern what the auditor communicates:

What the Auditor Communicates Regarding Planning

Required communications include:

  1. The auditor's responsibilities under GAAS (reasonable, not absolute, assurance).
  2. An overview of the planned scope and timing of the audit, including the significant risks the auditor identified.

Application guidance lists matters the overview may include:

  • How the auditor plans to address significant risks.
  • The auditor's approach to internal control relevant to the audit.
  • How materiality is applied, focusing on the factors considered rather than specific amounts.
  • The planned use of the internal audit function, component auditors, or specialists.

Protecting Audit Effectiveness (Critical Boundary)

Exam Trap: GAAS cautions that describing planned procedures in too much detail can reduce the effectiveness of the audit, especially when some members of TCWG also manage the entity.

To keep procedures unpredictable, auditors generally avoid disclosing:

  • The detailed, specific nature, timing, or extent of audit procedures (e.g., "We will test invoices above $15,000 recorded on October 12–14").
  • Specific materiality amounts (discussion of materiality focuses on the factors considered).
  • The specific locations selected for surprise cash counts or unannounced inventory observations.
  • The specific algorithmic logic or parameters used in data analytics and audit sampling routines.

Communicating the general audit approach fosters constructive two-way dialogue without handing the client a roadmap to evade detection.

Test Your Knowledge

Which of the following activities is properly categorized as part of developing the Overall Audit Strategy under AU-C 300, rather than developing the Detailed Audit Plan?

A
B
C
D
Test Your Knowledge

During initial planning, the auditor communicates with the audit committee (Those Charged with Governance) under AU-C 260. Which of the following communications is required while preserving the effectiveness of the audit?

A
B
C
D
Test Your Knowledge

An audit team originally formulated an overall audit strategy premised on relying on the client's internal controls over sales order processing, planning extensive interim testing and limited year-end substantive procedures. However, interim tests of operating effectiveness reveal widespread control deviations. Under AU-C 300, how should the auditor proceed?

A
B
C
D
Test Your Knowledge

Under AU-C 240 and AU-C 315, which of the following represents a mandatory requirement concerning the engagement team's planning meetings?

A
B
C
D