CIA-2 - Engagement Planning - Section A.1

Determine engagement objectives and scope, applying Topical Requirements and considering regulatory requirements, organizational strategy, prior audit reports, and whether the engagement is assurance or advisory.

Set engagement objectives and scope by weighing regulatory requirements, the organisation's strategy and objectives, existing governance, risk, and control processes, risk appetite and tolerance, internal policies, prior audit reports, and the work of other assurance providers. Distinguish whether the engagement provides assurance or advisory services, identify and document scope limitations during planning, and manage stakeholder requests and mid-engagement changes to objectives or scope.

Engagement objectivesTopical RequirementsScope limitation

Practice question for this objective

Free sampleEngagement Planningmedium

While planning an assurance engagement over an insurer's claims-handling process, the internal audit team learns a new data-protection regulation took effect this quarter and directly governs how claims data is stored. The original scope, drafted last year, does not mention it. What is the best next step?

  • AKeep the original scope and note the regulation as a matter for next year's engagement plan instead.
  • BAsk management to confirm in writing that the process already complies, and rely on that confirmation for scope.
  • CRevise the engagement objectives and scope to reflect the new regulation's requirements affecting claims-data controls. Correct
  • DExpand the scope to audit the organisation's entire regulatory-compliance function across all departments.
New regulatory requirements relevant to the audit area should be reflected in engagement objectives and scope during planning. Objectives and scope must consider regulatory requirements, so a regulation newly governing the data under review is incorporated by revising scope proportionately, not deferred, delegated to a management assertion, or over-expanded.

Why A is wrong: Deferring is tempting to protect the timeline, but a live regulation governing the very data under review is a current risk the scope should address.

Why B is wrong: A management assurance is low-reliability evidence and does not replace the team's own scoping judgement about a newly relevant regulation.

Why C is correct: Regulatory requirements shape objectives, so updating scope to cover the new data-protection rules keeps the engagement relevant to current risk.

Why D is wrong: This overreaches; the trigger is one regulation affecting claims data, and ballooning scope organisation-wide dilutes the engagement objectives.

See more CIA-2 practice questions, answers explained.

More in this domain

Back to all Engagement Planning objectives, or the CIA-2 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.