How to Do an Audit: Planning, Fieldwork, and Reporting

Doing an audit means moving through a fixed sequence: plan the engagement, define scope, gather records, test transactions in the field, and issue an opinion, then follow up on what the report found. The specifics scale up or down with the size of the organization and whether regulators are involved, but the logic holds whether you’re auditing a small nonprofit or a public company. Here is how to do an audit from the first engagement conversation through the corrective action plan.

Know Which Kind of Audit You Are Doing

The steps below apply to both internal and external audits, but the stakes are different. An internal audit is run by your own staff or internal audit department, reports to senior leadership or the board’s audit committee, and stays inside the organization. Its purpose is operational: finding weaknesses and recommending fixes.

An external audit is run by an independent CPA firm with no financial ties to the company beyond the engagement itself. Its purpose is assurance for shareholders, lenders, and regulators, and for public companies the opinion is filed with the SEC. Formality, documentation standards, and legal exposure all lean heavily on the external side, so the procedures that follow are written with an external audit in mind.

Step 1: Plan the Engagement

Planning is where audits succeed or fail. An unclear scope or a misunderstanding about responsibilities will follow you into every later phase.

Sign an Engagement Letter

The engagement letter is the contract between the auditor and the organization. PCAOB standards require it to state that management is responsible for the financial statements and for maintaining effective internal controls, while the auditor is responsible for conducting the audit under professional standards and issuing an opinion.1PCAOB. Appendix C – Matters Included in the Audit Engagement Letter The letter also covers timeline, fees, and what happens if the auditor cannot complete the work or form an opinion.

Build an Audit Strategy

Once the letter is signed, the auditor sets the direction, timing, and resources for the engagement. PCAOB rules require considering the reporting objectives, the factors directing the team’s work, and what resources the job will need.2PCAOB. AS 2101 – Audit Planning In practice, that means studying the industry, reviewing prior-year findings, identifying areas with high fraud risk, and deciding which accounts need intensive testing versus lighter analytical work.

Risk assessment is concrete, not abstract. If the company recently changed accounting software, revenue recognition policies, or key financial personnel, those areas get more scrutiny. Auditors also weigh external pressures, such as whether management has an incentive to inflate earnings before a debt covenant measurement date.

Set Materiality Thresholds

Materiality is the dollar threshold below which a misstatement would not change a reasonable investor’s decision. Common benchmarks fall in the range of 3 to 10 percent of pre-tax profit, adjusted for the company’s circumstances. A company with volatile earnings might get a lower threshold; a stable utility company might get a higher one. Auditors then set a lower “performance materiality,” often 50 to 85 percent of the overall figure, as the trigger for investigating individual misstatements during fieldwork. The gap between the two acts as a buffer so that a pile of small errors does not slip past unnoticed.

Step 2: Define Scope and Objectives

Scope locks down what the auditor will examine: the time period, the entities or departments included, and which financial statement line items will get detailed testing. Most organizations pick a single fiscal year or quarter. Clear boundaries keep costs predictable and stop the audit from expanding into unrelated historical data.

For publicly traded companies, the scope has to meet federal requirements under the Sarbanes-Oxley Act. Section 302 requires principal executive and financial officers to personally certify that each quarterly and annual report is accurate and that internal controls are effective.3Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports Willfully certifying a report that does not comply carries criminal penalties of up to a $5 million fine and 20 years in prison; knowing but non-willful violations cap at $1 million and 10 years.4DOL. Sarbanes-Oxley Act of 2002 – Section 906 Private companies without federal reporting obligations do not face these certification rules, but the same discipline in defining scope still applies.

Objectives should focus on the accounts where the risk of material misstatement is highest: revenue recognition, debt covenants, related-party transactions. If prior audits flagged recurring weaknesses in inventory or payroll tax compliance, those move to the top of the list.

Step 3: Gather Documentation

Evidence starts with the company’s own records. Pulling everything together before fieldwork begins can shave days off the engagement and cut professional fees noticeably.

Core Financial Records

The general ledger records every transaction categorized by account. The trial balance summarizes the ending balance of each account and confirms that total debits equal total credits. Both usually come out of the accounting software or ERP system in spreadsheet format.

You also need bank statements for every corporate account, including checking, savings, and investment portfolios. Auditors reconcile these against the company’s recorded cash balances, working alongside the company’s own bank reconciliations to explain differences like outstanding checks or deposits in transit.

Payroll and Tax Documentation

Payroll is one of the largest expense categories and gets detailed scrutiny. Form 941, the Employer’s Quarterly Federal Tax Return, shows wages paid and taxes withheld throughout the year.5Internal Revenue Service. Instructions for Form 941 (03/2026) Auditors cross-reference Form 941 data with employee W-2 forms and payroll summary reports to verify the figures on the financial statements match what was reported to the IRS.

Prior Audit Reports and Internal Policies

Last year’s audit report gives the current team context. If the prior auditor flagged a weak approval process for vendor payments, the current team checks whether that weakness was actually fixed. Organizational charts and written standard operating procedures explain who approves transactions, who records them, and who has system access.

Organize Records and Meet Retention Rules

Every transaction above a set dollar threshold should have a matching receipt, invoice, or purchase order traceable to its general ledger entry. Digital folders organized by account type, such as accounts payable or fixed assets, speed up testing considerably.

Retention rules matter both during and after the audit. Under 18 U.S.C. ยง 1519, anyone who knowingly destroys or falsifies documents to obstruct a federal investigation faces up to 20 years in prison.6Office of the Law Revision Counsel. 18 USC 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations and Bankruptcy On the auditor’s side, SEC regulations require accounting firms to retain all audit workpapers, correspondence, and supporting documents for seven years after the engagement concludes, including materials containing data inconsistent with the auditor’s final conclusions.7eCFR. 17 CFR 210.2-06 – Retention of Audit and Review Records

Step 4: Do the Fieldwork

Fieldwork is where the audit turns from preparation into active investigation. The auditor mixes several testing techniques to verify that transactions actually happened, were recorded correctly, and were not left out of the financial statements.

Vouching and Tracing

These are the two fundamental directions of substantive testing, and they catch different problems. Vouching starts in the general ledger: the auditor picks a sample of recorded transactions and traces each one back to its original source document, such as a vendor invoice or shipping receipt. Vouching catches fabricated entries, because a fake transaction will not have legitimate supporting paperwork.

Tracing runs the other way. The auditor starts with source documents and follows them forward into the ledger. Tracing catches omissions, because a real transaction that never made it into the books will show up in the source records but not the statements. Statistical sampling picks a representative group of transactions for both techniques, giving high assurance without the cost of examining every entry.

Analytical Procedures

Not every test involves digging through individual documents. Analytical procedures use ratios, trend comparisons, and data relationships to flag accounts that look off. If revenue grew 25 percent but accounts receivable grew 60 percent, that gap demands an explanation. If utility costs dropped sharply in a quarter when the company expanded its warehouse space, something is wrong.

Trend analysis compares account balances over time; ratio analysis compares relationships between accounts or between financial and non-financial data. Both work best on large volumes of predictable transactions, like a retailer’s monthly cost of goods sold. When these procedures identify anomalies, the auditor follows up with targeted tests of details.

Physical Inspection, Reperformance, and Confirmations

For assets that physically exist, there is no substitute for seeing them. Auditors visit warehouses to count inventory, compare the count to the ledger, and check for obsolescence, damage, or theft that might require writing down the asset’s value. High-value equipment and real estate may be verified through title searches and on-site inspection.

Reperformance means the auditor independently recalculates key figures, like depreciation schedules, interest accruals, or loan amortization tables, to confirm the company’s math. This catches both software glitches and manual errors. The auditor also sends confirmation letters directly to third parties, such as banks, major customers, and creditors, asking them to verify balances. Confirmations carry extra weight because they come from sources outside the company’s control.

Staff Interviews and Internal Control Testing

Interviews with employees who handle financial transactions reveal whether internal controls work in practice, not just on paper. Auditors look specifically for segregation of duties: the person who authorizes a payment should not be the same person who cuts the check or reconciles the bank statement. When one individual controls a transaction end to end, the risk of fraud or undetected error jumps sharply. These conversations also surface workarounds, informal procedures, and system access issues that no policy manual would show.

Step 5: Issue the Audit Report

After testing wraps up, everything funnels into the audit report, which is the reason the engagement exists. The report delivers the auditor’s professional opinion on whether the financial statements are reliable.

Get a Management Representation Letter

Before issuing the report, the auditor obtains a written representation letter from management confirming its responsibility for the fair presentation of the financial statements and for the design of controls to prevent and detect fraud.8PCAOB. AS 2805 – Management Representations The letter is audit evidence, but it does not replace actual testing. Management is going on record, in writing, about claims the auditor has already independently verified. If management refuses to sign the letter, the auditor cannot issue an opinion.

Issue One of Four Opinions

The final opinion falls into one of four categories.

  • Unmodified (clean): the financial statements present the company’s position fairly in all material respects. This is the result every company wants.
  • Qualified: the statements are mostly fair, but there is a specific area where the auditor found a material misstatement or could not get enough evidence. The qualification explains the issue.
  • Adverse: the auditor found misstatements that are both material and pervasive across the statements. This outcome can rattle investors, trigger lender covenant violations, and draw regulatory attention.
  • Disclaimer: the auditor could not obtain enough evidence to form any opinion. This usually happens when records are so incomplete or access was so restricted that the work could not be done.

The report also describes the scope of work performed and states that management is responsible for the financial statements while the auditor is responsible only for the opinion. The engagement typically closes with a presentation to the board or audit committee, where the auditor walks through findings, identified weaknesses, and recommended improvements.

Step 6: Follow Up With a Corrective Action Plan

The audit does not really end when the report is issued. For organizations subject to federal grant requirements under the Uniform Guidance, management must prepare a corrective action plan for every finding in the auditor’s report. That plan has to identify the person responsible for each corrective action, describe what the organization will do to fix the problem, and include an anticipated completion date.9eCFR. 2 CFR 200.511 – Audit Findings Follow-Up

Even when not legally required, a formal corrective action plan is smart practice. Keep it separate from the audit report. Resist the temptation to agree with every finding and promise vague improvements. If management genuinely disagrees with a finding or believes no action is needed, the plan should say so and explain why in detail.

Follow-through is where many organizations slip. Assign each finding to a specific person with a real deadline, and build status reviews into regular management meetings. When the next audit cycle starts, the auditor’s first question will be what happened with last year’s findings. Documented evidence that each issue was resolved, or a credible explanation for why it was not, is the difference between a routine follow-up and a repeat finding that signals deeper problems.