Skip to content

Audit Plan

What is Audit Plan?

A document that describes the activities and arrangements for an audit, including scope, objectives, timing, and resource requirements. Audit plans ensure systematic and efficient audit execution.

Audit

Each of these is named in at least one of the same controls as audit plan. The number is how many controls name both.

What the standards actually require on audit plan

Requirements naming audit plan across 6 standards, quoted from the control text.

IT Audit Plan. The third line of defence, IT audit, should provide the audit committee of the board (or equivalent) with independent assurance over the cyber risk programme through a risk-based IT audit plan (para 23).

BMA-7 · Information Technology Audit Plan

ICT and security risk management shall be subject to independent and periodic audit by staff with sufficient ICT and security knowledge, following a risk-based audit plan.

EBA-GL-3.3.6 · Audit

Governance, systems and processes for ICT and security risks should be audited periodically, in line with the audit plan, by auditors with sufficient ICT/security knowledge to provide independent assurance to the AMSB, with frequency and focus commensurate wit...

EIOPA-ICTSG-GL.5 · Audit

Plan and conduct internal audits using a risk-based approach with independent auditors.

ISO22313-9.2 · Guidance on internal audit

Implement IT Audit + Third-Party Risk Management per MAS TRM Chapters 14 + 15 + MAS Notice 658 on Outsourcing. Chapter 14 IT Audit - IT audit charter approved by Board Audit Committee + IT audit plan risk-based + IT audit methodology + IT auditor competency (C...

MAS-TRM-Third-Party-IT-Audit-Chapters-14-15-Outsourcing-Notice-658-Concentration-Risk-Exit-Strategy · MAS TRM Third Party + IT Audit + Chapters 14-15 + Outsourcing + Notice 658 + Concentration Risk + Exit Strategy

Operate Internal Audit per 12 CFR Part 30 Appendix D Section II.C.3. Internal Audit must (a) be a function independent of the front line units and Independent Risk Management with authority and independence to provide assurance to the Board on the design and o...

OCCHS-5 · Internal Audit: Independence, Scope, Methodology, and Reporting

Questions people ask about audit plan

What is Audit Plan?
A document that describes the activities and arrangements for an audit, including scope, objectives, timing, and resource requirements. Audit plans ensure systematic and efficient audit execution.
Why is Audit Plan important for compliance?
Audit Plan is a key concept in Audit. Understanding audit plan helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Audit Plan?
Audit Plan appears in the requirement text of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07), EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600), ISO 22313:2020 - Guidance on Business Continuity Management Systems, Monetary Authority of Singapore Technology Risk Management Guidelines. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Audit Plan?
Explore our compliance framework pages to see how audit plan applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Audit Plan applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.