CORAA

SIA 220 — Conducting Overall Internal Audit Planning

ICAI Internal Audit Standards Board · October 2022 compendium · 200 series
Reviewed 1 October 2026

SIA 220 covers the entity-wide internal audit plan, usually for a year. The plan has to line up with the charter and objectives, rest on a risk assessment, have its scope, methodology and coverage agreed with those charged with governance, and be resourced with enough skilled people.

This page covers SIA 220 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

Same number, different title in the current set
In ICAI’s February 2026 compendium, the current set, SIA 220 is titled Internal Audit Planning. This page covers SIA 220 as it stands in the October 2022 compendium: Conducting Overall Internal Audit Planning. Only the titles of the February 2026 set are listed here; its text is not summarised on this site. See both title lists side by side.

What the internal auditor has to do

  • Prepare a written overall plan for the period through a laid-down process.
  • Build an audit universe of every auditable unit and assess the risk of each one independently.
  • Decide how often each assignment will be done during the plan period.
  • Get the plan reviewed and approved by the Board or Audit Committee.
  • Monitor the plan during the year and go back to the approvers before any significant change.

Key requirements of SIA 220

Paragraph numbers refer to SIA 220 as it appears in ICAI’s Compendium of Standards on Internal Audit (as on 1 October 2022). The points below are close paraphrases, not quotations.

  • Planning happens at two levels: an overall entity-wide plan for a period, usually a year, presented to the Board or Audit Committee; and a plan for each assignment, which is the subject of SIA 310.(para 1.1)
  • The standard quotes rule 13(2) of the Companies (Accounts) Rules: the Audit Committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit.(para 1.3)
  • The plan is written and comes out of a laid-down process.(para 3.1)
  • Technology deployment and resource allocation are essential elements of planning.(para 3.1, 4.6, 4.7)
  • The plan is reviewed and approved by the Board or Audit Committee.(para 3.2)
  • Knowledge of the entity and discussions with stakeholders are documented.(para 3.3, 4.2, 4.3)
  • An audit universe covers all auditable units: locations, functions, business units, legal entities and third parties. Units are left out only for justifiable reasons, and the exclusions are highlighted to the body approving the plan.(para 3.4, 4.4)
  • Every auditable unit gets an independent risk assessment.(para 3.5, 4.5)
  • The plan sets the periodicity of assignments during the plan period.(para 1.4(c))
  • The plan is monitored during execution. A significant modification is made only after consulting those who originally approved it, and is documented and communicated.(para 3.6)

How SIA 220 shows up in the internal audit file

  • The written annual plan and the minute or record of its approval by the Board or Audit Committee.
  • The audit universe register, with any excluded units and the reason for each exclusion.
  • The risk assessment for each auditable unit.
  • Notes of discussions with stakeholders and of the team's knowledge of the entity.
  • A change log for the plan, showing who was consulted before each significant change.

Common mistakes in practice

  • A plan that was never formally approved by the Board or Audit Committee.
  • An audit universe that quietly leaves out locations, legal entities or third parties, with no reason recorded and nothing said to the approvers.
  • Adopting management's risk ratings instead of carrying out an independent risk assessment.
  • Changing the plan mid-year without going back to those who approved it.
  • Planning the audits without planning the people and technology needed to do them.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Related standards

SIA 310 · Planning the Internal Audit AssignmentSIA 210 · Managing the Internal Audit FunctionSIA 230 · Objectives of Internal AuditSIA 250 · Communication with those Charged with Governance

How this relates to global frameworks

The IIA's Global Internal Audit Standards (effective 9 January 2025) are a separate set from a different body, and there is no paragraph-for-paragraph match. The closest IIA principle is Plan Strategically.

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. The effective-date clause in each 2019 standard said it applied to internal audits beginning on or after a date to be notified by the Council of ICAI.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 220

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 220 into practice. Free to use.

Internal Audit Annual Plan Template →Internal Audit Risk Assessment Matrix →Internal audit annual plan generator →Internal audit scope of work generator →Internal audit risk scorer →Audit universe and risk taxonomy →

SIA 220 — frequently asked

What is SIA 220?

SIA 220, Conducting Overall Internal Audit Planning, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 220 covers the entity-wide internal audit plan, usually for a year. The plan has to line up with the charter and objectives, rest on a risk assessment, have its scope, methodology and coverage agreed with those charged with governance, and be resourced with enough skilled people.

Who approves the annual internal audit plan under SIA 220?

The Board or the Audit Committee. SIA 220 para 3.2 requires the overall plan to be reviewed and approved by the Board or Audit Committee, and para 3.6 requires a significant change to be made only after consulting those who originally approved the plan.

Is SIA 220 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 220 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 220 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 220?

The written annual plan and the minute or record of its approval by the Board or Audit Committee. The audit universe register, with any excluded units and the reason for each exclusion. The risk assessment for each auditable unit. Notes of discussions with stakeholders and of the team's knowledge of the entity. A change log for the plan, showing who was consulted before each significant change.

Is SIA 220 the same standard in the February 2026 compendium?

The number is the same but the title is not. In ICAI's February 2026 compendium, which ICAI lists as applicable from 1 April 2026, SIA 220 is titled "Internal Audit Planning". This page covers SIA 220 as it stands in the October 2022 compendium, titled "Conducting Overall Internal Audit Planning". Only the titles of the February 2026 set are listed here; check its text in that compendium before citing it.

← Previous
SIA 210 — Managing the Internal Audit Function
Next →
SIA 230 — Objectives of Internal Audit