Audit objectives must be tied to the risks relevant to the activity under review. According to Standard 2210 – Engagement Objectives, objectives must be established for each engagement based on a preliminary risk assessment. Meeting with the board (A) may help in identifying broad concerns, but objectives are engagement-specific. Establishing boundaries (C) and outlining scope (D) are done after objectives are defined. Therefore, the auditor must first conduct a risk assessment (B) to determine the key exposures and align objectives to those risks. This ensures the engagement is risk-based and adds value by focusing on areas of highest importance.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit