Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161
Risk-based audit planning is the framework that turns risk assessment conclusions into a coherent, defensible audit strategy. Under PCAOB standards, planning is not a preliminary step. It is a required discipline that determines the quality of everything that follows.
Amendments to AS 2101 highlight the engagement partner’s personal responsibility for planning. Moreover, they emphasize that planning decisions must connect directly to identified risks of material misstatement.
Part I.A deficiencies frequently trace back to planning failures. When partners approve an audit plan with incomplete risk assessment, the engagement is already compromised before fieldwork begins. Insufficient substantive procedures follow naturally from misunderstood risks. Consequently, control weaknesses go undetected because nobody designed procedures to find them.
At Shah Teelani & Associates, we build risk-based audit planning into every engagement from day one. This blog explains what PCAOB AS 2101 requires and how an effective audit strategy is built and documented.
What AS 2101 Requires From Audit Planning
PCAOB AS 2101, Audit Planning, establishes the mandatory framework every registered firm must follow. It covers two interconnected obligations — the overall audit strategy and the detailed audit plan.
Planning the audit includes establishing the overall audit strategy for the engagement and developing an audit plan. The audit plan includes, in particular, planned risk assessment procedures and planned responses to the risks of material misstatement.
Neither the strategy nor the plan can stand independently. The strategy sets the direction. The plan specifies how each identified risk gets addressed. Together they create the roadmap the engagement team follows from first procedures through final opinion.
The Engagement Partner’s Personal Responsibility
The engagement partner is responsible for the engagement and its performance. Accordingly, the engagement partner is responsible for planning the audit. When the engagement partner seeks assistance from other team members, the engagement partner nevertheless retains primary responsibility. The assistance provided by other engagement team members does not replace or reduce the engagement partner’s responsibility.
This personal accountability is not a formality. It means the engagement partner must understand every significant planning decision — not simply sign off on a template prepared by others. PCAOB inspectors evaluate whether the engagement partner actually directed and shaped the planning process. Consequently, reviewer sign-offs on templates prepared without genuine partner input do not satisfy this requirement.
Step 1 — Establishing the Overall Audit Strategy
The overall audit strategy sets the scope, timing, and direction of the entire engagement. It answers four core questions: What are the reporting objectives? Which factors significantly direct the engagement team? What did preliminary activities reveal? What resources does the engagement require?
In establishing the overall audit strategy, the auditor should take into account the reporting objectives of the engagement and the nature of communications required by PCAOB standards, the factors that are significant in directing the activities of the engagement team, the results of preliminary engagement activities and evaluation of important matters, and the nature, timing, and extent of resources necessary to perform the engagement.
The strategy must reflect the specific circumstances of each engagement. Prior-year files inform the strategy — however, they do not substitute for it. Therefore, any element carried forward from prior year must be reconsidered against current-year findings.
Strategy and Risk Assessment Linkage
The overall audit strategy does not exist in isolation. It connects directly to the risk assessment process. High-risk areas receive more attention. Complex transactions require more experienced team members. Additionally, areas with material weakness history require expanded testing.
Where inspectors find strategy documents that read identically to prior-year files — with no updates reflecting current-year circumstances — they treat this as a planning deficiency. The strategy must demonstrate that the auditor considered what changed.
Step 2 — Setting Materiality
Materiality is a foundational planning decision. It defines the threshold below which misstatements would not affect a reasonable investor’s judgment. Every subsequent scope decision flows from this number.
To obtain reasonable assurance about whether the financial statements are free of material misstatement, the auditor should plan and perform audit procedures to detect misstatements that, individually or in combination with other misstatements, would result in material misstatement of the financial statements. This includes being alert while planning and performing audit procedures for misstatements that could be material due to quantitative or qualitative factors.
Materiality is not purely mathematical. A misstatement can be material because of its nature — not just its size. Furthermore, misstatements involving related party transactions, management compensation, or loan covenant compliance may be material even when they fall below a quantitative threshold.
Performance Materiality and Tolerable Misstatement
Effective risk-based audit planning establishes three materiality-related thresholds. Overall materiality defines the planning benchmark. Performance materiality — set below overall materiality — provides a buffer. It reduces the probability that aggregate uncorrected misstatements exceed the overall threshold. Tolerable misstatement then applies the performance materiality concept to individual account-level testing decisions.
In determining tolerable misstatement and planning and performing audit procedures, the auditor should take into account the nature, cause, and amount of misstatements accumulated in audits of prior periods.
All three thresholds must be documented and applied consistently. Moreover, any changes from the prior year must be explained with specific reasoning.
Step 3 — Developing the Detailed Audit Plan
The detailed audit plan translates the overall strategy into specific procedures for each significant account, transaction class, and disclosure. It is the operational document the engagement team executes.
The auditor should develop and document an audit plan that includes a description of the planned nature, timing, and extent of risk assessment procedures; the planned nature, timing, and extent of tests of controls and substantive procedures; and other planned audit procedures required to be performed so that the engagement complies with PCAOB standards.
Each element of the plan must be tailored. Nature refers to the type of procedure — inspection, observation, inquiry, confirmation, recalculation, or analytical procedure. Timing refers to when the procedure is performed — interim or year-end. Extent refers to the depth and breadth of testing — sample sizes, thresholds, and the degree of disaggregation applied.
Why Templates Fail the PCAOB Standard
Standardized audit programs applied without meaningful tailoring do not satisfy PCAOB requirements. The audit plan must show that its design responded to what the auditor found during risk assessment — not what a template defaulted to.
When partners approve an audit plan with incomplete risk assessment, the engagement is already compromised. Insufficient substantive procedures follow naturally from misunderstood risks.
Consequently, every procedure in the plan must connect to a specific risk. Where a procedure addresses a significant risk, the plan must show why that particular procedure is responsive to that specific risk at that specific assertion. Generic responses to complex risks are a consistent inspection deficiency.
Step 4 — Tailoring Procedures to Identified Risks
Risk-based audit planning requires that each identified risk drives a specific audit response. High-risk areas require more extensive procedures. Significant risks require direct substantive procedures — they cannot be addressed by controls testing alone.
Certain areas consistently demand more tailored planning because of the complexity, subjectivity, or fraud risk they carry. These include:
- Revenue recognition — contract terms, performance obligations, variable consideration, and timing of recognition
- Significant accounting estimates — goodwill impairment, fair value measurements, allowances, and contingent liabilities
- Business combinations — purchase price allocation, goodwill, and intangible asset identification
- Related party transactions — completeness, appropriate terms, and arm’s-length evaluation
- Going concern — cash flow forecast reliability, debt covenant status, and management’s mitigation plans
- Digital assets — valuation, custody, classification, and disclosure
- Stock-based compensation — valuation inputs, vesting conditions, and expense recognition
Each of these areas requires procedures specifically designed for the risks it presents. Furthermore, the engagement file must show that the tailoring was deliberate — not coincidental.
Step 5 — Planning for Multi-Location Engagements
Many public companies operate across multiple locations or business units. Risk-based audit planning must address how audit coverage is distributed across those locations.
In an audit of the financial statements of a company with operations in multiple locations or business units, the auditor should determine the extent to which audit procedures should be performed at selected locations or business units to obtain sufficient appropriate evidence. The auditor should assess the risks of material misstatement to the consolidated financial statements associated with each location or business unit and correlate the amount of audit attention devoted to the location with the degree of risk.
Where other auditors perform work at specific locations, the lead auditor’s planning obligations expand accordingly. The involvement of the lead auditor — through a combination of planning, performing audit procedures, and supervising other auditors — should be commensurate with the risks of material misstatement associated with those locations or business units.
Multi-Auditor ICFR Planning
In integrated audits involving other auditors, additional planning requirements apply. The lead auditor of the financial statements must participate sufficiently in the audit of internal control over financial reporting to provide a basis for serving as lead auditor of ICFR.
Therefore, the planning documentation must address both the financial statement and ICFR scope when other auditors are involved. Surface-level supervisory references in the plan without specific involvement requirements are insufficient.
Step 6 — Independence Confirmation at Planning
Under amended AS 2101 — effective December 15, 2026 — independence confirmation is a required planning step. It is not an administrative task separate from audit planning.
The engagement partner must confirm that the firm satisfies all applicable independence requirements before the audit begins. Where other auditors participate, the lead auditor must obtain written independence affirmations from each firm. Additionally, any relationship that may bear on independence must be documented and disclosed to the audit committee before fieldwork commences.
This requirement reinforces that independence is an ongoing engagement obligation. However, it begins at planning — not at client acceptance or issuance of the report.
Step 7 — Documenting the Planning Process
Audit planning documentation must support every significant decision made before fieldwork begins. It must enable an experienced auditor — with no prior connection to the engagement — to understand why each procedure was planned and how each procedure responds to an identified risk.
Effective planning documentation includes:
- The overall audit strategy with explicit linkage to current-year risk assessment findings
- Materiality calculations — overall, performance, and tolerable misstatement — with clear reasoning
- A detailed audit plan showing nature, timing, and extent of every planned procedure
- Documentation of significant planning judgments and the basis for each decision
- Independence confirmation records for all engagement team members and participating firms
- Evidence that the engagement partner personally directed and reviewed the planning process
Better planning doesn’t just reduce inspection risk. It creates the clarity that keeps engagements profitable and teams aligned from kickoff through sign-off.
Updating the Plan During the Engagement
Risk-based audit planning is not a one-time activity. The plan must be updated whenever new information changes the risk picture. This happens regularly during public company audits.
New information requiring plan updates includes interim financial results that differ materially from expectations, previously undisclosed transactions or estimates, audit committee communications about emerging risks, and fieldwork findings that indicate higher risk than initially assessed.
Failure to update the plan is a planning deficiency — not merely a documentation issue. Moreover, an audit plan that no longer reflects the current risk environment cannot support an appropriate audit opinion. Therefore, engagement teams must treat plan maintenance as a continuous responsibility throughout the fieldwork period.
What the 2026 Inspection Environment Means for Planning
PCAOB inspection selection in 2025 prioritized the financial, real estate, and information technology sectors. Inspectors also focused on public companies impacted by supply chain challenges, companies engaging in M&A activity, and companies with heightened going concern risk.
These priorities signal where planning must be most rigorous in 2026. M&A activity requires specific business combination planning. Supply chain disruption requires expanded inventory and going concern procedures. Additionally, IT sector complexity requires specific revenue recognition and intangible asset planning.
Furthermore, amended AS 2101 — effective December 15, 2026 — strengthens the engagement partner’s planning responsibilities. Firms still relying on prior-year templates without meaningful tailoring must address this gap before the effective date.
What Issuers and Finance Teams Should Know
Risk-based audit planning affects issuers directly. The quality of issuer-provided information shapes the quality of the auditor’s risk assessment — which in turn shapes the quality of the plan.
Specifically, finance teams support effective audit planning by:
- Providing timely access to key personnel across finance, operations, and management
- Sharing draft financial statements and supporting schedules before fieldwork begins
- Disclosing unusual transactions, estimates, and accounting judgments proactively
- Making internal audit findings and control assessments available to the external auditor
- Flagging significant changes from the prior year that affect financial reporting
Strong cooperation at the planning stage reduces surprises during fieldwork. Consequently, it produces a more targeted engagement and a more defensible final opinion.
The Bottom Line
Risk-based audit planning connects risk assessment conclusions to audit procedures through a documented, defensible strategy. It is the engagement partner’s personal responsibility. It must be tailored to each engagement. Moreover, it must be updated when circumstances change.
In 2026, with amended AS 2101 strengthening planning requirements and PCAOB inspections tracing Part I.A deficiencies back to planning failures, every registered firm must treat risk-based audit planning as a core competency — not an administrative prerequisite.
Shah Teelani & Associates (PCAOB Reg. No. 7161) builds engagement-specific risk-based audit planning into every public company audit. We work with US-listed and OTC public companies that understand the difference between a plan that satisfies a template and one that genuinely drives audit quality.
If your organization requires a PCAOB-registered auditor committed to rigorous audit planning, we welcome the conversation.