Skip to main content
Category: Internal Audit

Audit Engagement

Also known as: Engagement
Simply put

An audit engagement is a defined piece of audit work in which an auditor examines a specific subject and reports findings to provide a level of assurance. In external auditing, it is typically a formal arrangement between an organization and an independent auditor to examine financial statements; in internal auditing, it is an individual assurance or advisory assignment carried out by the organization's own internal audit function. The scope, objectives, and terms are usually agreed and documented before the work begins.

Formal definition

An audit engagement is a discrete assurance (or, in internal audit, advisory) assignment governed by an agreed scope, objectives, criteria, and terms, and performed in accordance with applicable auditing standards. In the external financial-statement context, it is commonly documented in an engagement letter constituting an agreement between the client and an independent auditor to examine financial statements or another defined element, with the aim of providing reasonable assurance; supervisory responsibilities over the engagement team are addressed in PCAOB AS 1201, which assigns overall responsibility to the engagement partner. In the internal audit context, an engagement is an individual assurance or consulting assignment whose subject matter may be operational, compliance, financial, or IT-related, planned and executed by internal auditors rather than an independent third party. This entry distinguishes external audit engagements (performed by independent auditors) from internal audit engagements (performed by an organization's own internal audit function); the independence and objectivity considerations, reporting lines, and applicable standards differ between the two. It does not cover engagement-specific procedures, tooling, jurisdictional licensing requirements, or the detailed contents of engagement letters, which vary by standard, jurisdiction, and engagement type.

Why it matters

The audit engagement is the fundamental unit of work through which assurance is delivered, whether by an external auditor examining financial statements or by an organization's own internal audit function conducting an operational, compliance, financial, or IT-related assignment. Because scope, objectives, criteria, and terms are typically agreed and documented before work begins, the engagement construct disciplines assurance activity: it clarifies what is being examined, against what criteria, and what level of assurance is intended. Without a defined engagement, assurance work risks drifting in scope, producing findings that cannot be reliably relied upon by boards, audit committees, or regulators.

The distinction between external and internal engagements matters directly to how findings should be interpreted. An external audit engagement is a formal arrangement between an organization and an independent auditor, commonly documented in an engagement letter, and aims to provide reasonable assurance over financial statements or another defined element. An internal audit engagement is an individual assurance or advisory assignment performed by the organization's own internal audit function; its independence and objectivity considerations, reporting lines, and applicable standards differ from those governing external work. Conflating the two can lead stakeholders to over- or under-rely on a report, or to assume a level of external independence that an internal engagement does not carry.

Engagements also allocate responsibility for how the work is performed. In the external financial-statement context, supervisory responsibility over the engagement team is addressed in PCAOB AS 1201, which assigns overall responsibility to the engagement partner. Clear ownership of supervision supports the quality and consistency of the work performed, which in turn underpins the credibility of the assurance provided.

Who it's relevant to

Internal Auditors
Internal auditors plan and execute individual assurance and advisory engagements on behalf of their own organization. For them, the engagement defines a discrete assignment whose subject matter may be operational, compliance, financial, or IT-related, and it frames the objectives, scope, and criteria against which their work and reporting are structured.
External Auditors
Independent external auditors enter into audit engagements documented in an engagement letter to examine financial statements or another defined element, with the aim of providing reasonable assurance. Supervisory responsibility over the engagement team is a defined obligation; under PCAOB AS 1201, overall responsibility rests with the engagement partner.
Audit Committees and Boards
Governance bodies rely on the outputs of audit engagements to obtain assurance over financial reporting, controls, and compliance. Understanding whether a given engagement was performed by an independent external auditor or by the internal audit function helps them calibrate how much and what kind of reliance to place on the findings.
Compliance and Risk Professionals
Compliance and risk practitioners are frequently the subject of, or stakeholders in, audit engagements addressing compliance and operational areas. Clarity on the agreed scope, objectives, and criteria helps them prepare for the work and interpret findings within the intended level of assurance.

Inside Audit Engagement

Engagement Scope
The defined boundaries of the audit engagement, including the processes, units, systems, locations, and time periods to be examined. In internal audit, scope may cover operational, compliance, financial, IT, or governance subject matter rather than being limited to financial-statement assertions.
Engagement Objectives
The specific outcomes the engagement is intended to achieve, such as evaluating the design and operating effectiveness of controls, assessing compliance with policies or regulations, or providing assurance over a particular risk area. Objectives are typically linked to the organization's risk assessment.
Engagement Plan and Work Program
The documented approach setting out procedures, timing, resource allocation, and the nature and extent of testing. In internal audit this commonly derives from a risk-based annual audit plan approved by those charged with governance, such as an audit committee.
Evidence and Working Papers
The information gathered and documentation prepared to support observations and conclusions. Working papers typically record procedures performed, evidence obtained, and the basis for findings, and support supervisory review.
Responsible Personnel
The individuals accountable for the engagement, including the lead auditor and reviewers. In external audits under PCAOB standards this role is termed the 'engagement partner'; in internal audit the engagement is typically led by an internal audit manager or lead auditor who reports through the chief audit executive.
Reporting and Communication
The communication of results, including observations, root causes, recommendations, and management responses or action plans. Internal-audit reports are generally directed to management and to those charged with governance rather than to external stakeholders.
Independence and Objectivity Basis
The organizational positioning that supports the auditor's ability to reach unbiased conclusions. For internal audit this is typically achieved through functional reporting to the audit committee and administrative reporting arrangements, distinct from the external auditor's independence from the entity.

Common questions

Answers to the questions practitioners most commonly ask about Audit Engagement.

Does an audit engagement always require an independent third-party auditor?
No. Independence from a third party is characteristic of external audit engagements, but internal audit engagements are typically performed by an organization's own internal audit function, employees of the organization or of an affiliated group. In an internal audit context, independence and objectivity are maintained through organizational positioning, such as functional reporting to the board or audit committee and administrative reporting to senior management, rather than through the auditor being an external party. The defining requirement is objectivity and freedom from undue influence over the area under review, not third-party status.
Is an audit engagement limited to reviewing financial statements?
No. Financial-statement scope is common in external audit engagements, but internal audit engagements commonly cover a broad range of subject matter, including operational, compliance, information technology, governance, and fraud-related areas. In many frameworks, the scope of an internal audit engagement is determined through risk-based planning and the terms agreed with the audit committee or management, and it need not relate to financial reporting at all.
How is the scope of an internal audit engagement typically established?
Scope is commonly derived from the risk-based internal audit plan and refined during engagement planning. It is usually documented in an engagement objective and scope statement, often within an engagement plan or terms of reference, and may be discussed with the audit committee and relevant management. Scope defines the boundaries, period, locations, and processes to be examined, and typically notes any areas explicitly excluded.
What documentation is usually produced during an audit engagement?
Engagements commonly generate an engagement plan or program, working papers evidencing the work performed and conclusions reached, and a final engagement report or communication of results. Working papers typically support the observations, and reports commonly include findings, associated risks, and recommendations or management action plans. Retention and format may vary by organization policy and applicable professional standards.
How are engagement roles and responsibilities typically assigned?
Engagements are commonly staffed with a lead responsible for planning, supervision, and quality, supported by team members who perform testing and gather evidence. Terminology varies: external audit under some regimes uses the term engagement partner, while internal audit functions may use titles such as engagement lead, in-charge, or manager. Supervisory review of work and conclusions is a common quality expectation across settings.
How does an engagement conclude and what follow-up typically occurs?
An engagement generally concludes with communication of results to the appropriate stakeholders, often accompanied by agreed management action plans to address findings. Many internal audit functions perform follow-up to assess whether agreed actions have been implemented and remediation is effective. This entry does not address specific tooling, reporting templates, or timelines, which vary by organization and applicable standards.

Common misconceptions

An audit engagement is always performed by an independent third party external to the organization.
This describes an external audit. Internal-audit engagements are commonly conducted by employees of the organization who maintain objectivity through their positioning within the function, typically with functional reporting to an audit committee, rather than through third-party independence from the entity.
An audit engagement is fundamentally about examining financial statements.
Financial-statement work characterizes many external audit engagements, but internal-audit engagements may address operational, compliance, IT, governance, or fraud-related subject matter. The subject-matter scope varies and is generally driven by a risk-based audit plan.
The auditor conducting an engagement is responsible for the controls being tested.
Auditing is an assurance activity distinct from management's ownership of controls. The auditor evaluates and reports on controls but does not design, operate, or own them; blending these roles would compromise objectivity.

Best practices

Define engagement scope and objectives explicitly at the outset, linking them to the organization's risk assessment and, for internal audit, to the approved risk-based audit plan.
Prepare a documented work program that specifies the nature, timing, and extent of procedures, and adjust it as evidence emerges during the engagement.
Maintain sufficient, reliable working papers that record procedures performed, evidence obtained, and the basis for each observation and conclusion, supporting supervisory review.
Preserve objectivity by ensuring auditors do not evaluate areas for which they recently held operational responsibility, and by maintaining appropriate reporting lines to those charged with governance.
Communicate findings clearly to management and to those charged with governance, including root causes, recommendations, and agreed management action plans.
Use terminology accurately and consistently with the applicable framework, recognizing that role titles and requirements differ between internal-audit standards and external-audit standards such as those of the PCAOB.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.