Join our Newsletter — 33% off our NHI Course

What is the difference between audit planning and audit fieldwork?

Audit planning sets the foundation by defining objectives, scope, timelines, responsibilities, and applicable requirements. Audit fieldwork is the execution phase, where the team tests controls, gathers evidence, and answers auditor questions. Planning determines what should be examined and why, while fieldwork determines whether controls actually meet the stated requirements in practice.

Audit Planning Defines the Test, Fieldwork Proves It

Audit planning is where the audit is shaped: the team defines scope, objectives, criteria, timing, staffing, and the evidence it expects to need. Fieldwork is where that plan is executed through inquiry, walkthroughs, testing, sampling, and documentation review. The difference is not just timing, it is purpose: planning sets the questions, fieldwork answers them with evidence.

Planning also determines what is in and out of scope, which systems or controls matter most, and what level of assurance the audit is trying to reach. That matters because a poorly scoped plan can produce efficient fieldwork that still misses the real risk. Good planning gives fieldwork a defensible target and prevents the team from testing everything, or the wrong things.

What Changes Between Planning and Fieldwork

Planning is mostly a design activity. The audit team gathers background information, identifies applicable requirements, maps the control environment, and decides how much testing is appropriate. It is also where coordination happens, including scheduling, ownership, and request lists, so the audit can move smoothly once execution begins. In other words, planning is about preparation and audit strategy.

Fieldwork is the operational phase. The team collects evidence, evaluates whether controls are designed and operating as intended, interviews control owners, and follows up on exceptions. This is where reality is checked against the plan. A control may look strong on paper during planning, but fieldwork determines whether it actually works in practice, consistently and with enough evidence to support the conclusion.

The two phases are tightly linked, but they are not interchangeable. Planning without fieldwork produces assumptions, while fieldwork without planning becomes unfocused and harder to defend. For the reader who needs a concrete audit reference point, SOC 2 Trust Services Criteria (AICPA) is a useful example of how audit criteria drive both the plan and the evidence-gathering work.

Risk and Threat Considerations

The main risk is treating planning as a paperwork exercise and fieldwork as a box-ticking exercise. When that happens, the audit can miss control gaps, under-test high-risk areas, or over-rely on management assertions instead of independent evidence. Weak planning also creates a blind spot: teams may collect lots of evidence without testing the controls that actually matter.

Failure mechanism: scope drift, weak criteria, or poor evidence targeting causes the audit to examine low-value areas while material control failures remain untested or under-documented.

Impact: the resulting opinion or report can overstate control effectiveness, delay remediation, and leave stakeholders exposed to unresolved compliance, operational, or security issues.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Audit fieldwork verifies whether access controls operate as planned and evidenced.
Recommendation — Test access control operation and retain evidence that confirms the control works in practice.
NIST CSF 2.0 GV.OV — Governance Oversight Audit planning sets scope, responsibilities, and oversight expectations for the engagement.
ID.IM — Improvements Fieldwork findings should feed documented remediation and control improvement actions.
Recommendation — Define audit scope, roles, and oversight criteria before evidence collection begins. Translate fieldwork exceptions into tracked improvements and remediation ownership.

Practitioner Guidance

What to verify: Before fieldwork starts, verify that every control test maps back to an approved objective, a defined criterion, and a specific evidence source. If the team cannot explain why a test exists, the plan is not yet mature enough.

Decision rule: If the risk is high or the control is frequently manual, spend more effort on walkthroughs, sample design, and evidence quality during planning, because weak scoping usually shows up later as inconclusive fieldwork.

What good looks like: A strong audit plan gives fieldwork a clear test matrix, named owners, realistic timing, and a documented rationale for sample size and coverage. Fieldwork should then produce evidence that is traceable, repeatable, and sufficient to support the conclusion.

Practitioner takeaway: Planning decides whether the audit will be credible; fieldwork decides whether it will be true.