What Is an Audit Program? Components, Types, and Standards

An audit program is the written, step-by-step plan that tells an audit team exactly which procedures to perform, how to perform them, when, and by whom. It translates the engagement’s risk-based strategy into concrete instructions a staff auditor can pick up and execute, and it gives supervisors and regulators a way to verify later that the work was actually done. Professional standards require auditors to document this plan before fieldwork begins, specifying the nature, timing, and extent of every procedure the team will run.1Public Company Accounting Oversight Board. AS 2101 Audit Planning

Without one, an audit team risks missing significant risks, duplicating effort, or failing to gather enough evidence to support its opinion. With one, the engagement partner can supervise the work, reviewers can confirm procedures were performed as intended, and inspectors years down the line can evaluate whether the audit met professional standards.2Public Company Accounting Oversight Board. AS 1201 Supervision of the Audit Engagement

What Goes Into an Audit Program

Every audit program is built from the same structural pieces, even when the specifics vary widely by client and industry.

Objectives and Scope

The program opens by stating what the auditor is trying to accomplish. Objectives tie directly to financial statement assertions: does the inventory exist, are all liabilities recorded, is revenue accurate, does the company actually own what its balance sheet says it owns? Each material account gets mapped to the assertions most likely to be misstated, and objectives flow from that mapping.3Public Company Accounting Oversight Board. AS 2110 Identifying and Assessing Risks of Material Misstatement

Scope defines the boundaries: which accounts, which financial periods, which locations. Clear scope keeps the team focused on the areas where misstatement would matter most and prevents drift into work that was never risk-assessed.

Materiality Thresholds

Before any test gets designed, the auditor sets a materiality level for the financial statements as a whole. This is the dollar amount below which a misstatement wouldn’t reasonably change an investor’s decision, and PCAOB standards require it to be expressed as a specific number rather than a vague notion.4Public Company Accounting Oversight Board. AS 2105 Consideration of Materiality in Planning and Performing an Audit

Below overall materiality sits tolerable misstatement, often called performance materiality, which is set lower to create a buffer. If overall materiality is $500,000, the team might set tolerable misstatement at $300,000 so that the combined effect of small undetected errors doesn’t accidentally breach the overall threshold. Some accounts get their own lower materiality if they’re particularly sensitive, such as related-party transactions or executive compensation disclosures.4Public Company Accounting Oversight Board. AS 2105 Consideration of Materiality in Planning and Performing an Audit

Detailed Procedures

The heart of the program is the procedure list. These are concrete instructions, not general goals. Instead of “verify cash,” a well-written step reads something like: “Obtain the December 31 bank statement and reconciliation, trace all reconciling items over $10,000 to supporting documentation, and confirm balances directly with the bank.”

Staffing, Timing, and Sign-Offs

Each procedure carries a time estimate and an assigned person. Complex, judgment-heavy work like evaluating fair value estimates goes to experienced team members; routine reconciliations go to staff. PCAOB standards explicitly require that the skill of the person performing the work match the risk level of the task.5Public Company Accounting Oversight Board. AS 2301 The Auditors Responses to the Risks of Material Misstatement

The program also carries preparer and reviewer sign-off spaces for each step. These are substantive checkpoints, not paperwork. The reviewer has to evaluate whether the work was actually performed, whether the objective was achieved, and whether the results support the conclusion reached.2Public Company Accounting Oversight Board. AS 1201 Supervision of the Audit Engagement

Tests of Controls vs. Substantive Procedures

Procedures inside an audit program generally fall into two categories, and the balance between them is one of the biggest design decisions the auditor makes.

  • Tests of controls evaluate whether the client’s internal controls are designed properly and are actually operating as intended. An example is testing whether purchase orders over a certain dollar amount consistently received the required approval.
  • Substantive procedures test account balances and transactions directly for misstatement. Sending confirmation letters to customers, recalculating depreciation schedules, and physically counting inventory all fall here.

Strong controls over a process like cash disbursements can allow the team to reduce substantive testing in that area. Weak controls over revenue recognition push the program toward heavier substantive work.5Public Company Accounting Oversight Board. AS 2301 The Auditors Responses to the Risks of Material Misstatement

How an Audit Program Is Built

Building the program is one of the most judgment-intensive parts of any audit. It starts with risk assessment and ends with a tailored set of written procedures.

Risk Assessment

The auditor performs risk assessment procedures to identify where material misstatements could occur, looking at industry conditions, the client’s business operations, its internal controls, and its financial data for anomalies. Risks get identified at the financial-statement level (broad issues like management integrity or a deteriorating financial position) and at the assertion level (specific risks tied to particular accounts).3Public Company Accounting Oversight Board. AS 2110 Identifying and Assessing Risks of Material Misstatement Fraud risk gets its own dedicated assessment. Every significant risk identified must be met with an appropriately targeted procedure in the program.

Mapping Assertions to Procedures

Each risk gets tied to the financial statement assertion it threatens, and each assertion drives the type of procedure needed. If the main concern about accounts receivable is existence, the program calls for direct confirmation with customers. If the concern about inventory is valuation, the program emphasizes testing for obsolescence and comparing carrying values to net realizable value. The assertion-to-procedure link is what makes an audit program defensible: every step exists because a specific risk to a specific assertion required it.

Sampling

Most programs don’t test every transaction. They specify sample sizes and selection methods for each procedure. PCAOB standards on sampling establish that the required sample size depends on both the objective of the test and the acceptable level of sampling risk, so higher assessed risk means larger samples and more persuasive evidence.6Public Company Accounting Oversight Board. AS 2315 Audit Sampling Professional judgment drives these decisions whether the auditor uses statistical or nonstatistical methods.

Built-In Unpredictability

An easily missed requirement: PCAOB standards require auditors to incorporate an element of unpredictability into the procedures selected each year. That means varying the types of tests performed, changing which locations get visited, or shifting the timing of procedures from one year to the next. The point is to reduce the chance that management could anticipate what the auditor will look at and prepare accordingly.5Public Company Accounting Oversight Board. AS 2301 The Auditors Responses to the Risks of Material Misstatement

How the Program Gets Used During the Audit

Once the program is finalized, execution moves through assignment, fieldwork, and review.

Before anyone starts testing, supervisors must communicate three things to each team member: the objectives of the procedures they’ll perform, the nature and timing of those procedures, and any matters that could affect either the work or the evaluation of results.2Public Company Accounting Oversight Board. AS 1201 Supervision of the Audit Engagement Skipping that briefing is where execution problems often start, because a staff auditor performing a step without understanding its purpose can produce evidence that is technically complete but substantively useless.

Programs are not locked once fieldwork begins. When the team discovers unexpected issues, such as control deficiencies that weren’t apparent during planning, unusual transactions, or evidence that contradicts management’s representations, the program has to be updated. The engagement partner evaluates significant issues that arise and determines responses, which may include expanding sample sizes, adding new procedures, or testing areas that weren’t originally in scope.2Public Company Accounting Oversight Board. AS 1201 Supervision of the Audit Engagement If materiality is reassessed downward mid-engagement, the standards require the auditor to check whether existing procedures are still sufficient and modify them if not.4Public Company Accounting Oversight Board. AS 2105 Consideration of Materiality in Planning and Performing an Audit

After fieldwork wraps up, senior team members review completed workpapers against the audit program to confirm that every planned procedure was performed, documented, and concluded on. The engagement partner bears ultimate responsibility for this review, and all review and evaluation must be completed before the audit report is released.2Public Company Accounting Oversight Board. AS 1201 Supervision of the Audit Engagement

Common Types of Audit Programs

The structure above applies broadly, but audit programs look different depending on the engagement’s purpose.

Financial Statement Audits

The most common type. The program focuses on whether a company’s financial statements are presented fairly under the applicable accounting framework, usually GAAP. Procedures are heavily assertion-based, targeting risks associated with specific account balances, transaction classes, and disclosures. The end product is the auditor’s opinion on the financial statements as a whole.

Integrated Audits (SOX 404)

For public companies, auditors typically perform an integrated audit covering both the financial statements and the effectiveness of internal control over financial reporting, as required by Section 404 of the Sarbanes-Oxley Act.7U.S. Securities and Exchange Commission. Sarbanes-Oxley Disclosure Requirements The audit program is designed so that control testing serves both purposes at once. It follows a top-down approach, starting with entity-level controls and working down to process-level controls over significant accounts, and it tests both design effectiveness and operating effectiveness.8Public Company Accounting Oversight Board. AS 2201 An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Compliance Audits

Compliance audit programs test whether an organization is following specific laws, regulations, or contractual requirements. The procedures target the controls and transactions tied to the relevant rules, whether that’s the Foreign Corrupt Practices Act,9U.S. Department of Justice. Foreign Corrupt Practices Act Unit debt covenants in a loan agreement, or healthcare billing regulations.

A notable subcategory is the Single Audit, required for non-federal entities that spend $1,000,000 or more in federal awards during a fiscal year. Single audit programs follow both generally accepted government auditing standards and the OMB’s Uniform Guidance, and they require a risk-based approach to determine which federal programs qualify as major programs subject to detailed testing.10eCFR. 2 CFR Part 200 Subpart F Audit Requirements

Operational Audits

Operational audit programs focus on how efficiently and effectively a business process runs, rather than on whether financial numbers are accurate. The scope might cover supply chain logistics, manufacturing throughput, IT operations, or human resources. The output is typically a set of recommendations to management rather than a formal opinion.

IT Audits

IT audit programs address risks that don’t surface in traditional financial testing: access controls and user permissions, data backup and recovery, network security, system change management, and compliance with frameworks like HIPAA or PCI-DSS. Because virtually every financial process now runs through technology, IT audit findings often feed directly into the financial statement audit program. A material weakness in IT general controls can undermine the reliability of every automated control and system-generated report the financial auditors planned to rely on.

Internal Audit Programs

Internal audit programs serve the organization’s own management and board rather than outside stakeholders, and they tend to cover a broader range of topics including operational efficiency and strategic alignment. External audit programs are generally more detailed in their financial testing because of the higher assurance standard required for a public opinion.

Which Standards Apply

A distinction that trips people up: the standards governing audit programs differ depending on whether the client is publicly traded. Public company audits fall under PCAOB standards, which tend to be more prescriptive. Private company audits follow AICPA clarified auditing standards (the AU-C sections). Both frameworks require a documented audit plan and procedures responsive to assessed risks, but the specific requirements, particularly around internal control testing and documentation, are more extensive for public companies because of the Sarbanes-Oxley integrated audit requirement.8Public Company Accounting Oversight Board. AS 2201 An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Government audits add another layer. Entities subject to the GAO’s Government Auditing Standards (the Yellow Book) must meet additional requirements around independence, reporting, and the scope of their programs.11U.S. Government Accountability Office. Government Auditing Standards 2024 Revision When federal funds are involved and the Single Audit threshold is met, the program must also incorporate Uniform Guidance requirements.

How Technology Is Changing Audit Programs

Audit programs in 2026 look meaningfully different from those written a decade ago. Instead of pulling a sample of 50 invoices from a population of 10,000, auditors can use technology-assisted analysis to scan entire transaction populations and flag anomalies, unusual patterns, or items that fall outside expected parameters. The auditor’s work shifts from manually vouching documents toward investigating the exceptions the technology surfaces.

The PCAOB amended its standards on audit evidence (AS 1105) and risk responses (AS 2301) to address technology-assisted analysis, defined as analyzing information in electronic form with technology-based tools. These amendments are effective for audits of fiscal years beginning on or after December 15, 2025, and are designed to ensure auditors still obtain sufficient appropriate evidence rather than relying on technology outputs without proper evaluation.12Public Company Accounting Oversight Board. Amendments Related to Aspects of Designing and Performing Audit Procedures that Involve Technology-Assisted Analysis of Information in Electronic Form

Technology doesn’t replace the audit program. It changes what goes into it. Procedures still need to be documented, assigned, and reviewed. The difference is that some of those procedures now involve configuring and validating automated tools rather than manually pulling binders of support.

How Long Audit Programs Must Be Kept

After the audit wraps up, the program and all supporting workpapers must be retained for a minimum period that depends on whether the client is public or private.

  • For public companies, the Sarbanes-Oxley Act requires audit firms to retain documentation for at least seven years from the report release date. Firms have 45 days after the report release date to assemble the complete and final set of audit documentation.13Public Company Accounting Oversight Board. AS 1215 Audit Documentation Appendix A
  • For private companies, AICPA standards require retention for at least five years from the report release date.

The retention clock starts when the auditor grants permission to use the audit report, or if no report is issued, when fieldwork was substantially completed.13Public Company Accounting Oversight Board. AS 1215 Audit Documentation Appendix A If a firm’s audit gets selected for a PCAOB inspection or a peer review, inspectors will pull the audit program and workpapers to evaluate whether the engagement was planned and executed in accordance with professional standards. Incomplete or missing documentation can result in inspection findings, disciplinary action, or both.