Picture a project team that opens the core banking screen on day one. They copy logs. They highlight rows. In week four someone asks a plain question. What conclusion is this sample meant to support? The room goes quiet. They were busy. They had not planned.
That quiet room is why this part exists. In Part 1, What Is an IT and IS Audit?, you met the four phases: plan, fieldwork, report, and follow-up. This is part 2 of 5 in Understanding IT and IS Audit. We stay on the first phase. Weak planning is the most common reason audits fail. The later work looks active, and it still answers the wrong question, or it answers no question at all.
You will feel the pull to start testing on the BBC Bank capstone. Resist it. Planning is the work you finish before you test anything.
Why Planning Comes First
A bank has more screens than your team has hours. Planning is how you decide, in writing, where those hours go. Before anyone opens a sample, you should be able to answer four questions.
Who gave us the authority to do this audit, and who receives the result? If you cannot name the giver of authority, a manager can tell you to stop.
How does this bank actually move money, and how does it keep the record? If you cannot tell that story, you will score a lecture, not the bank in front of you.
Which risks deserve the hours, and which problems are too small to matter? If everything is urgent, nothing is a choice.
What conclusion will we be able to draw, and what is outside the boundary? If the objective cannot be answered with yes or no, you do not yet know what you are testing.
If any answer is "we will see when we get there", you are not ready to test. The seven steps below are how you make the four answers specific, and how you get them agreed.
A plan is a promise about scope. It is also a promise about what you will leave alone.
The CISA Review Manual and the IT Audit Framework (ITAF) treat this planning as part of the audit, not as paperwork you skip. Hall's auditing text, and Cascarino's guide, are worth keeping open while you learn how a business process actually runs. They do not replace the walkthrough of your own bank.
Step 1: The Audit Charter
An audit charter is the document that creates the internal audit function and gives it authority. The board approves it. The board is the group of directors who govern the bank, above day-to-day management. They usually do this work through an audit committee, a small group of those directors who oversee audit. The point of that line is independence, which you met in Part 1. Managers should not be the ones who decide whether their own systems get a clean opinion.
A charter that is useful to a new auditor says four things in plain language.
The purpose of internal audit. It is there to give the board an independent, evidence-based view of controls.
The right of access. Auditors may see records, systems, and the people who run them.
The reporting line. The audit reports to the board, through the audit committee, rather than to the manager under review.
The freedom to choose work based on risk. Management may suggest topics. Management may not quietly delete the awkward one.
Without a charter, you are a visitor with a notebook. A manager can say, "Do not look at agency reversals. We are busy." If the charter gives you access, that refusal is something you report. If you have no charter, the refusal just ends the job.
For the capstone, write a one-page charter for BBC Bank's internal IS audit. Name the board as the giver of authority. Name the audit committee as the reporting line. Add one sentence that protects independence in appearance: auditors will not design the controls they later review.
The charter is standing. It is not rewritten for every topic. One charter. Many engagements. If you draft a fresh charter for agency banking, and another for leavers, you have mixed it up with the next document.
Step 2: The Engagement Letter
An engagement is one audit job. Agency banking reversals can be an engagement. Leaver access would be a different one. An engagement letter is the written agreement for this one job. External auditors almost always send one. Internal auditors should do the same, even when the team calls it an announcement memo or terms of reference. In this course, call it an engagement letter, so the class means the same paper.
The letter goes to the auditee. The auditee is the manager responsible for the area under review, not the whole bank. For agency banking, that may be the head of digital channels. Copy the head of internal audit, and copy the audit committee, so the reporting line in the charter is visible on this job too.
Put these items in the letter. Keep each one short.
The audit objective, in one or two sentences.
The scope, including what is out of scope.
The period you will cover. Name the start date and the end date.
The access you need: systems, logs, policies, and time with staff.
The timing, including the week of the exit meeting.
Who will receive the draft report, and who will receive the final report.
Sign it, and ask the auditee to sign it back. The signature does not make you their staff. It shows they were told what you would examine. Later, if someone says the team never knew reversals were in scope, you have the letter.
Students skip this step because it feels like admin. It is the moment the audit becomes a defined job. A charter without a letter is permission in general, and confusion on the day.
Step 3: Understand the Entity
The entity is the organisation you are auditing. Here, the entity is BBC Bank. Understanding the entity means you can explain how it serves customers, which systems hold the records, and what would hurt a customer or a regulator if it broke. You are not writing findings yet. You are learning the map.
The tool for this step is a walkthrough. A walkthrough is a slow pass through one real transaction with the person who processes it. You sit with them. You ask them to take one item from the start to the finish. You write down each screen, each handoff, and each check. You do not pull a sample yet. You do not argue. If you start correcting people during the walkthrough, they will show you the official path and hide the path they actually use.
Do the walkthrough on money movement. A bank is a machine for moving money and keeping that record true. Here is a teaching path for BBC Bank. It is a class model, not a description of a named bank in town. On the capstone, use the system names in your case pack. If the pack is quiet, label the stages clearly, and say that you did so.
A customer hands cash to an agent, starts a transfer in the app, or stands at a teller. That front door is the channel.
The channel sends a message to a switch. A switch is the system that routes the message between the channel and the bank's main ledger.
The core banking system posts the entry. This is the main ledger. It holds customer balances. A debit and a credit should land together. If they do not, the difference sits in a suspense account, a temporary parking place for items that are not yet matched.
At day end the bank settles with the agent network or with another bank. Settlement is the exchange that makes the earlier promise final.
Overnight, operations reviews items that failed, doubled, or timed out. Some of those items are reversed. A reversal undoes a posting. The business needs this window. A customer should not keep a double debit. The same window can hide a theft, which is why Part 1 spent time on night reversals.
In the morning, finance does a reconciliation. A reconciliation compares two records that should agree. One pair is the agent's float and the bank's record of that float. Float is the cash balance the agent is trusted to hold.
Write the walkthrough as a one-page narrative. Name the person you sat with, the transaction you followed, and the screens you saw. While you walk, note controls you saw, and controls you expected but did not see. Who can approve a reversal? Is that person different from the person who started it? Is the log a named user, or a shared ID such as NIGHT01? You are still not testing. You are marking the places you will come back to. If you cannot tell this story, stop. A risk score written before the story is a guess.
Step 4: Risk Assessment
A risk, in this course, is something that can go wrong in a way that matters. Part 1 joined two questions: how likely is it, and how bad is it if it happens. Planning turns those questions into a ranking, and into a decision about how hard you will test.
Audit risk and its three parts
Audit risk is the risk that you will conclude the controls are sound when they are not. It is the risk of a wrong clean opinion. A clean opinion tells the board that, for this scope and this period, the controls can be relied on. You want audit risk low. You do not want it at zero, because zero would mean testing every transaction, and that is not an audit. It is a second copy of the business.
Audit risk has three parts. Say the line in words before you trust it as a formula. In words: audit risk = inherent risk x control risk x detection risk.
audit risk = inherent risk x control risk x detection riskInherent risk is the risk built into the work itself, before any control is considered. Moving customer money through agents, with a reversal window overnight, is inherently risky. Money can move, and a reversal can hide the move. A typo on the staff canteen menu is not inherently risky. You do not lower inherent risk by writing a policy. The work is that kind of work.
Control risk is the risk that the controls will fail to prevent or detect the problem, or that the controls are missing. If the same officer can raise a reversal and approve it, control risk is high. If a second person must approve, and the system refuses to continue without that second person, control risk is lower. You assess control risk. You do not fix the control during the audit. Fixing it would put you on both sides of the work, and independence would be gone.
Detection risk is the risk that your own tests will miss a problem that is there. This is the part you control directly. A tiny sample, a chat that only asks "is this usually fine?", or a test aimed at the wrong screen will push detection risk up. A sharper sample, reperformance, and a log you read yourself will push it down. Reperformance, from Part 1, means you do the check or the calculation again yourself.
Read the multiplication as a planning rule. When inherent risk and control risk are both high, the only way to keep audit risk low is to drive detection risk down. That means more testing, and better testing. When inherent risk is low, you can accept a higher detection risk, which means less testing. Some books multiply the first two parts and call the product the risk of material misstatement. That long name means the chance that a serious problem exists and the bank's controls did not catch it. Your tests have to answer that combined chance. You do not need the long name on the capstone cover. You need the habit.
Here is a small number picture, so the multiplication is more than a slogan. Treat each part as a chance between 0 and 1, and treat 0.1 as the audit risk you are willing to accept on this job. Suppose inherent risk is 0.8 and control risk is 0.5. Together they are 0.8 x 0.5, which is 0.4. Detection risk can then be no higher than 0.1 divided by 0.4, which is 0.25. You still have real testing to do. You do not have to test everything. Now suppose the controls are weak, and control risk is 0.9. Then 0.8 x 0.9 is 0.72, and detection risk must fall to about 0.14. The sample gets deeper because the bank's own net is thin. These decimals are a teaching picture. On the capstone you will not compute every line to two places. You will write the decision in words. High and high means test harder.
Scoring and ranking risks
The three-part model tells you how hard to test. You still need a list you can sort. Score each risk on two scales, each from 1 to 5. Then multiply. The score is impact times likelihood, out of 25.
Impact is how bad it is if the event happens. Score the harm that could follow, rather than the loss you have already found.
1. Almost nobody is harmed. No customer money and no personal data are at stake.
2. A small inconvenience inside one team. It can be fixed without a customer feeling it.
3. A real error. It costs time or a modest sum, and it can be corrected in the open.
4. A serious loss, a customer harm that spreads, or a control failure on a payment path.
5. Customer money can be wrong or stolen, the ledger can lie, personal data can be exposed, or the regulator would expect to hear about it.
Likelihood is how probable the event is, given what you know today, including the controls you saw on the walkthrough.
1. Remote. Several failures would have to line up, and the controls you saw are strong.
2. Unlikely in a normal month, but possible if someone is careless.
3. It could happen this year. The controls are uneven.
4. The weakness is already visible, and the process runs often.
5. It is happening now, or nothing you saw stands in the way.
Use these cuts so the class ranks in the same way. There is no gap between them.
1 to 7: low. Record it. Do not build the engagement around it.
8 to 14: medium. Include it after the high scores have a home in the plan.
15 to 25: high. These risks shape the objective, the scope, and how deep you test.
Hold one high score and one low score side by side. Agency banking reversals: impact 5, because a bad reversal changes a customer balance and can hide fraud. Likelihood 4, because the window runs all the time and a walkthrough can already show a thin split of duties. Five times four is 20. The score is 20 out of 25. That risk is in the plan. We will write the full engagement around it in the worked example.
Now the other end, so the scale is honest. Part 1 used a wrong poster on the branch wall as a small matter. Impact 1. Likelihood 2. One times two is 2. A score of 2 does not enter this engagement. You can mention it in your notes. You do not spend the sample on it.
Two habits ruin a score sheet. The first is scoring impact as if no customers existed. A shared ID on a reversal screen is not low impact just because you have not yet found a theft. Impact asks what could happen. The second habit is scoring every line at 5. If every score is 25, you have not ranked anything. Force a difference, and write one sentence on why this 5 is worse than that 3.
Step 5: Materiality
Materiality is the size, or the nature, of a matter that would change a sensible reader's decision. The reader might be the audit committee. It might be a regulator. It might be a customer who trusts the balance on their phone. If they would care, the matter is material. If they would not, you are collecting trivia.
In a financial audit, materiality is often a single number, such as a slice of profit. In an IS audit you need that instinct and a second one. Some failures are material because of what they are, even when the shillings in front of you are small. A shared user ID on the reversal screen is material. You cannot tell who moved the money. One reversal of a small amount can still be material as a control failure, if the same path could move a large amount tonight.
For BBC Bank, write materiality in two lines, and label both as planning choices. They are not a law, and they are not a Bank of Uganda threshold unless you are quoting one.
Quantitative. A posting error of UGX 1,000,000 or more on a customer account is material for this engagement. So is a pattern of smaller errors that adds up to that amount. Quantitative means you are using a number.
Qualitative. Any control failure that lets one person both cause and hide a movement of customer money is material. So is a failure that exposes customer personal data. Qualitative means you are judging the kind of failure, rather than the sum alone.
Professionals also set performance materiality. That is a tighter amount, below the planning threshold, so that several small misses do not add up past the line. If your materiality is UGX 1,000,000, you might test as if UGX 600,000 already deserves attention. You do not need a perfect percentage in year three. You need to say which tighter figure you used, and why you did not wait for a huge loss before you cared.
Materiality also keeps the report clean. A logo in the wrong shade on an internal screen is not your finding, even if it annoys you. Write the thresholds into the plan. If you invent them after you see the results, you are fitting the ruler to the mistake.
Step 6: Objectives and Scope
An audit objective is the conclusion you intend to be able to draw. It is not a list of tasks. "To check agency reversals" describes your effort. It cannot pass or fail. "To determine whether agency banking reversals in the period were approved by someone other than the initiator, and logged to a named user" is an objective. At the end you will say yes, no, or yes with exceptions.
Use this shape. To determine whether [the process] [did the required thing] [during the period]. Then make sure a classmate could design a test from the sentence. If they cannot tell what evidence would make it true or false, it is not testable yet.
Write one main objective for the engagement. Add a second only when it is a genuinely different conclusion. Three objectives are often a sign that you have not chosen.
Scope is the fence around that objective. State four edges, and then state what is out.
Process. Which flow, not "the whole bank".
Systems. Name the channel, the switch, the core, the log. Use the names from your walkthrough.
Period. A start date and an end date. The period under review is the stretch of time you are judging. It should already have happened. You cannot audit next month. Six months is enough to see a pattern, and small enough to finish.
Locations. All agents, or one region. Say which.
Out of scope is part of the scope, not a footnote you skip. Branch teller cash, ATM disputes, loans, and the public website stay out, unless a reversal in your set touches them. Naming the outside is a kindness to the auditee. It also stops you from drowning.
Tie the objective to the score. If reversals scored 20, the objective should be about reversals. A tidy objective about password length, while reversals sit at 20 and passwords scored 6, means the plan has come loose from the ranking. Write one linking sentence. "This objective follows from risk R3, scored at 20."
Step 7: Write the Audit Plan
The audit plan is the document that brings the earlier steps into one place. It says what you will audit, and why. It is written before testing. On the capstone, if the plan is dated after the first sample, it is a story written to match work you already did. A reader can tell.
A plan for this course should contain the following.
A short background, taken from your walkthrough, not from a generic essay about banks.
The charter point you rely on for authority, and a note that the engagement letter was agreed.
The objective.
The scope, the period, and what is out of scope.
The risks, each with impact, likelihood, and the score out of 25.
Materiality, both the number and the qualitative line, plus performance materiality if you set one.
The criteria you will judge against, matched to the objective.
The timing, the people on the team, and who gets the report.
Notice what is not in that list. Sample sizes, the individual test steps, and the working paper index belong in the audit program. The audit program is the how. You write it in Phase 2, when fieldwork starts. The plan says what and why. The program says how.
Keeping them apart will save you. A clever test that does not serve the objective does not belong in the program. A risk scored at 20, with no later test that touches it, means the program dropped a promise the plan made.
What are audit criteria?
Audit criteria are the standards you will use to judge what you find. They answer a plain question: what should be? A finding needs a criterion. The condition is what is. The criterion is what ought to be. You cannot grade BBC Bank against your personal taste, or against a control you wish they had invented.
Name the criteria in the plan, and attach each one to the objective. For this course, four external sources, plus the bank's own rules, will cover most engagements.
COBIT 2019. This is ISACA's framework of governance and management objectives. Use it when the question is whether the bank governs and manages the process, rather than whether one setting looks tidy. For reversals, the objectives called Managed Operations (DSS01) and Managed Business Process Controls (DSS06) are the usual fit. DSS01 is about running operations in a controlled way. DSS06 is about controls inside the business process, including a split between the person who starts an action and the person who approves it. You do not need every COBIT objective. You need the ones that match.
ISO/IEC 27001. This is the international standard for an information security management system. A management system here means the policies, roles, and checks an organisation uses to keep security going. It is not a single piece of software. Use the standard when the objective is about security controls such as access and logging. Point at the topic that fits. Do not attach the whole standard to a narrow question.
Bank of Uganda guidelines. These are the supervisor's expectations for banks. Agency banking, operational risk, and the care of customer funds sit under that supervision. A Ugandan bank does not get to treat them as optional reading. Cite the guideline that matches your process, specifically enough that a classmate could find the same paragraph. Do not invent a circular number if the case pack does not give you one.
The Data Protection and Privacy Act, 2019. This is Uganda's law on personal data. Agency records hold names, phone numbers, and account details. If your objective touches who can see that data, or how long it is kept, the Act is a criterion.
The bank's own policies. These are often the strictest criterion in the file. If BBC Bank's reversal procedure says two different people must act, that procedure is your yardstick, even before you open COBIT. A bank that breaks its own rule has a clear gap. Quote the clause.
An objective about reversal approvals might use the bank's reversal procedure, a Bank of Uganda guideline on operational controls, and COBIT 2019 on managed operations and business process controls. ISO/IEC 27001 joins if you are judging access and logging. The Data Protection and Privacy Act, 2019 joins if the log holds personal data and you will judge who may read it. Write a small match: objective, criterion, and why this criterion. A criterion with no link to the objective is decoration.
Read the figure in number order, and follow the arrows. The line marked "then" carries you from the risk score down to materiality. Do not start at the last box.

A Worked Mini-Example
Stay with BBC Bank, and stay with one risk, so you can see a full Phase 1 on a single page. Treat every figure below as a teaching choice for the capstone, not as a rule from a regulator.
The process is agency banking. Customers deposit and withdraw through agents. When a posting fails or doubles, operations can reverse it. The walkthrough showed that the night officer sometimes both starts and approves the reversal, and that some entries sit under a shared ID.
You already have authority from the charter, and you have agreed an engagement letter with the head of digital channels. The letter names reversals, the six-month period, and the access you need to the log.
Score the risk. Impact is 5, because customer balances and fraud exposure are in play. Likelihood is 4, because the weak split of duties is already visible and the process runs all the time. Five times four is 20. The score is 20 out of 25. It is a high risk. It drives the engagement. The branch poster, scored at 2, stays out.
Objective. To determine whether reversals on the agency banking channel, during the six months under review, were initiated and approved by different people, and whether each reversal was logged to a named user.
Scope. The six months from 1 April 2026 to 30 September 2026. That period is already closed, which is what you want. In scope: agency deposit and withdrawal reversals, from the agent channel through the switch to the core posting and the reversal log. Out of scope: branch teller cash, ATM claims, loan recoveries, and the marketing website.
Materiality. Qualitative: any reversal that changes a customer balance with no separate approver, or with no named user, is material. Quantitative: a single error of UGX 1,000,000 or more is material, and so is a set of smaller reversals that reaches that amount. Performance materiality for the money tests: UGX 600,000.
Criteria. BBC Bank's own reversal procedure. Bank of Uganda guidelines on agent banking and on operational controls. COBIT 2019, using Managed Operations (DSS01) and Managed Business Process Controls (DSS06). ISO/IEC 27001, for access control and logging. The Data Protection and Privacy Act, 2019, for who may see the customer details inside the log.
The plan stops there. It does not yet say "sample 40 reversals", and it does not yet say "reperform the approval check on each row". Those lines are the audit program. They belong to Phase 2. If you can point, in this example, to the charter, the engagement letter, the walkthrough, the score of 20, materiality, the objective, the six-month scope, and the criteria, you have Phase 1 in your hands.
Common Planning Mistakes to Avoid
Five mistakes show up every year on this kind of work. All five are avoidable.
Testing before the plan exists. You pull a sample because the log looks interesting. Later you cannot say why those rows, and not others, answer the objective. Evidence without a plan is a pile of screenshots.
Writing objectives as activities. "To check", "to review", and "to look into" describe effort. They do not describe a conclusion. Rewrite until the sentence can be answered with yes or no, plus exceptions.
Scoring every risk as high. A sheet of 25s is not care. It is a refusal to choose. The audit then tries to cover the whole bank, and it covers nothing well. If two risks both feel serious, force a difference in impact or in likelihood, and write the reason.
Skipping the walkthrough and copying a checklist. Last year's plan, or a plan from the internet, does not know this bank's agents, this core system, or this night window. Understanding the entity is not a courtesy visit. It is where the risks come from.
Mixing up the plan and the program. A plan that is only a list of test steps has no why. A plan that never names criteria leaves Phase 2 with nothing to judge against. What and why stay in the plan. How waits for the program.
Avoid these five, and Phase 2 will have something solid to test. The next part of this series is where that testing begins.
Key Terms to Remember
Audit charter. The board-approved document that gives internal audit its purpose, its access, and its reporting line.
Engagement letter. The agreement for one audit job. It states the objective, the scope, the period, the access, and who gets the report.
Auditee. The manager responsible for the area under review.
Walkthrough. Following one real transaction from start to finish so you understand the path. It is learning, not a test.
Audit risk. The risk of a wrong clean opinion. In words: audit risk = inherent risk x control risk x detection risk.
Inherent risk. The risk in the work itself, before controls.
Control risk. The risk that controls fail or do not exist. You assess it. You do not fix it during the audit.
Detection risk. The risk that your tests miss a real problem. This is the part you lower by testing more, or better.
Impact and likelihood. The two scores, each from 1 to 5. Multiply them. The result is out of 25.
Materiality. The size or nature of a matter that would change a sensible reader's decision.
Audit objective. The conclusion you plan to draw, written so it can be tested. It starts with "to determine whether", not "to check".
Scope. The fence: process, systems, period, and locations, plus what is out.
Audit criteria. The standards you judge against. What should be.
Audit plan. The document that says what you will audit, and why, before you test.
Audit program. The Phase 2 document that says how you will test.
References
ISACA (2024). CISA Review Manual, 28th edition. Schaumburg, IL: ISACA.
ISACA (2020). IT Audit Framework (ITAF), 4th edition. Schaumburg, IL: ISACA.
ISACA (2019). COBIT 2019 Framework: Governance and Management Objectives. Schaumburg, IL: ISACA.
Hall, J. A. (2015). Information Technology Auditing, 4th edition. Boston: Cengage Learning.
Cascarino, R. E. (2012). Auditor's Guide to IT Auditing, 2nd edition. Hoboken: Wiley.
Your Reflection and Peer Review
This section is a required learning activity. Planning is abstract until you put it in your own words, so take this seriously.
Part A: Write your own reflection (about 300 to 400 words)
In the comments below, post a reflection answering the following.
In your own words, explain why planning comes before testing, using an analogy of your own.
Explain the difference between inherent risk, control risk and detection risk, and give one example of each from any organisation you know.
List your three key takeaways from this article and why each one matters.
Pick any process you know well, from your home, campus or a business, and write one clear audit objective for it, plus two risks you would score as high.
Describe one planning idea you found difficult, and what you now understand about it.
Part B: Critique at least five peers' reflections
Read your classmates' reflections and respond thoughtfully to at least five. For each, write two to four sentences that do the following.
Name one thing they explained well and say specifically why.
Point out one idea that was missing, unclear or not quite right, and suggest what you would change. Pay special attention to whether their audit objective is actually specific and testable.
Ask one real question that moves their thinking forward.
What a good critique looks like
Weak: "Good objective, well done." Strong: "Your objective about the library system is specific, which is good, but it is written as an activity rather than a conclusion. 'To check the library system' describes what you will do, not what you will conclude. Could you rewrite it as 'To determine whether only registered students can borrow books'? Also, is the risk you scored as high really high on impact, given how few books are involved?"
Ground rules
Critique the idea, not the person. Be specific, be kind, and aim to raise the understanding of the whole class.