Hey, welcome to VoraPrep Audio. Glad you could tune in.
Today we're talking about something that sounds a little dry, but is honestly the backbone of every single successful audit: the engagement work program. And getting this wrong has a real cost. I heard about an internal audit team at a big retailer… they were looking at inventory controls. The new manager just grabbed last year's work program, didn't really think about it, and sent his team out for three weeks to test physical inventory counts.
The team did great work. The only problem? The *real* risk, the thing that cost the company two million dollars last quarter, was how they were writing off *obsolete* inventory. The team's entire fieldwork was pointed in the wrong direction. They gathered perfect evidence for the wrong problem. It's like training for a marathon when you’re supposed to be in a swimming competition. All that effort, completely wasted.
That's why the Global Internal Audit Standards, or GIAS, have Standard 2240. It basically says you have to develop and document a work program for every engagement. Think of it like an architect's blueprint for a house. You wouldn't just show up with a pile of lumber and start nailing boards together, right? Of course not. The blueprint tells you exactly what steps to take, what materials you need, where everything goes, to make sure the final building is solid.
The work program is your blueprint for the audit. It’s a step-by-step roadmap that lays out exactly what you need to do to gather the right kind of evidence. It's also how your supervisor knows what you're up to and can check your progress. It becomes the official record of what you planned to do. And honestly, for newer auditors, it's a fantastic training tool.
Now, a critical piece of this standard is that the work program has to be approved by your engagement supervisor *before* you start the real work. And if you need to change the plan midway through, those changes need to be approved, too. That supervisory review is a safety check. It makes sure everyone agrees on the blueprint before you start pouring the concrete.
So, what's actually in this blueprint? The heart of it is the list of audit procedures. These are the specific tasks you perform to gather evidence. And picking the right task for the job is a huge part of being a good auditor.
You’ve got a few main tools in your toolbox. You can just ask people questions. That’s called inquiry. It’s a great starting point, but you can't build your whole conclusion on it. It’s just what someone told you.
So, you might follow that up with observation—literally just watching a process happen. If they say they always lock the cash drawer, you can watch them do it. That's pretty persuasive evidence, but it only tells you what happened at that exact moment you were watching.
A much more common tool is inspection of records or documents. This is where you dig into the paperwork, whether it's on paper or on a screen. You’re looking at invoices, contracts, reports… this is where a lot of the audit happens.
And sometimes you need to do an inspection of tangible assets. This is the physical stuff. If the books say there are 100 laptops in storage, you go count the laptops. You’re verifying they actually exist.
A really powerful one is reperformance. This is where you independently do a task that someone else was supposed to do. For example, if the company’s process is to calculate depreciation expense, you can take their data and recalculate it yourself to see if you get the same number.
And finally, there are analytical procedures. This is where you step back and look at the big picture, studying relationships in the data. You might look at trends over time, or compare your company's ratios to an industry benchmark. If sales went up 50% but the cost of goods sold stayed flat… that’s a relationship that doesn't seem plausible, and it's something you'd want to investigate.
It’s really important to understand how the work program and the working papers fit together. They're two sides of the same coin. The work program is the *plan*—it's the list of what you're *going* to do. The working papers are the *proof*—they document what you actually *did*, what you found, and what you concluded. Every single step in your work program should point to a specific spot in your working papers. That creates a clear trail. Someone should be able to pick up your file, see the objective, follow the steps in your work program, look at the evidence in your working papers, and come to the exact same conclusion you did.
Let's make this real. Imagine you're an auditor at a company called Axiom Manufacturing. Your objective is to verify that all big-ticket equipment purchases—say, over $50,000—followed the company's competitive bidding policy.
So, how do you build a work program for that? First, you'd identify your population. You’d get a data dump from the accounting system of all capital equipment bought in the last year. Then, you'd filter that list down to just the purchases over 50 grand.
Next, you can't test all of them, so you’d select a sample, maybe 25 purchases. Now for the core of it—the procedures. For each of those 25 purchases, you'd write out the exact steps. Something like this:
First, you'd inspect the purchase order to make sure it was for capital equipment and that the amount matches what's in the system. Then, for that same purchase, you'd inspect the procurement file to see if there's proof of at least three competitive bids, just like the policy requires. What if there aren't three bids? Your next procedure would be to ask the procurement manager why, and then inspect the file for a special form, a sole-source justification that's been properly approved. And finally, you might reperform a step—you’d trace the winning bid amount to the purchase order and the final invoice just to make sure they all match up.
After you've done that for all 25 items in your sample, you can form a conclusion about whether the competitive bidding process is working.
See how each step is a specific action? The tempting, but totally wrong, approach would be to just go interview the procurement manager and ask, "Hey, do you guys follow the bidding policy?" Relying only on that inquiry gives you really weak evidence. The strength of a good work program is using multiple procedures that back each other up.
When you see these questions on the exam, here's how to think it through. First, find the objective. What is the question *really* asking you to test for? Compliance? Accuracy? Existence? The objective is your North Star. Second, what’s the main risk? What's the thing that could go wrong? Then, look at your answer choices. Which of those actions gives you the most direct, most reliable evidence to address that specific objective and risk? You want to cut through the noise and pick the procedure that gets straight to the point.
One of the biggest traps is confusing the objective with the procedure. Remember, the objective is *what* you want to achieve. For example, "Determine if payroll calculations are accurate." The procedure is *how* you're going to do it: "Recalculate gross-to-net pay for a sample of 25 employees." If an answer choice sounds like a command or a task, it’s probably a procedure, not the overall goal.
If you need a little something to remember this, think of the word PROOF. A good work program has all the P.R.O.O.F. The P is for Procedures—the specific steps. R is for Responsibility—who is doing the work. The first O is for the Objective Link—how does this step help meet the goal? The second O is for the Output—what evidence will you get from this? And F is for Finish Date—what's the timeline?
And a final exam-day tip: always choose the procedure that provides the *most direct* evidence. If the objective is to test whether inventory *exists*, the most direct evidence is to go physically count it. Reviewing inventory records from a desk is indirect. Going and touching it is direct.
Alright, let's try a quick knowledge check. An auditor is planning to assess a company's business continuity plan. Which of the following is an engagement *objective*, not a procedure? A. Reviewing the results of the last disaster recovery test. B. Interviewing the IT director about backup protocols. C. Verifying the plan was updated and approved this year. or D. Determining whether key business functions can be recovered within established timeframes.
The answer is D. A, B, and C are all specific tasks—procedures—you would perform to achieve the high-level goal, which is D.
Okay, one more. Standard 2240 says the work program has to be approved before it's used. Who has to approve it? A. The Chief Audit Executive B. The engagement client C. The engagement supervisor D. The audit committee
That's C, the engagement supervisor. That's the key control to make sure the plan is solid before the work begins.
So, the work program isn't just paperwork. It's your strategic plan. It turns your objectives into action, it keeps the team on track, and it ensures your final conclusion is built on a solid foundation of evidence.
If you're looking for more ways to practice concepts like this, check out Vora Prep dot com. VoraPrep is a full exam-prep app with lessons, tons of practice questions, and even an AI tutor to help you work through the tough spots. You can try it out for free.
Thanks for studying with me today. Keep up the great work. You've got this.