
What Are the 7 Steps in the Audit Process?
In the audit process, your auditor evaluates your organization's financial, operational or compliance activities in seven steps:
The audit engagement letter
Before planning starts, your auditor agrees the terms of the audit with your management or board, in an engagement letter or another written agreement, under AU-C 210. Your auditor puts six things in it:
- The objective and scope of the audit.
- Your auditor's responsibilities.
- Your management's responsibilities, including the financial statements and internal control.
- A statement that an unavoidable risk exists that your auditor may not detect some material misstatements, because of the inherent limitations of an audit and of internal control.
- The financial reporting framework you report under.
- The expected form of the auditor's report, and a statement that the report may differ from that form in some circumstances.
Read it before you sign, because your team's responsibilities are set there.
1. Planning
During this phase, your auditor defines the scope, objectives and timeline of the audit, gathers preliminary information about your processes and identifies key areas of focus. With a developed plan, your auditor works efficiently and toward your goals.
2. Risk Assessment
In this step, your auditor evaluates potential risks to your operations or financial reporting, and identifies areas with a higher likelihood of errors, fraud or non-compliance. Your auditor then prioritizes effort and resources around those areas.
3. Internal Control Testing
Your auditor assesses the effectiveness of your internal controls to determine whether they adequately mitigate risks, reviewing the policies, procedures and systems you use to safeguard assets and support reliable financial reporting. Your auditor tests those controls to find weaknesses and to check compliance with regulations.
4. Fieldwork
In fieldwork, your auditor works on site or remotely to collect data and verify compliance with established criteria, examining records, interviewing employees and observing processes to gather evidence. Your auditor forms conclusions about your performance from that groundwork.
5. Evidence Collection
Your auditor compiles and analyzes documentation, transactions and other data to support its findings. The evidence must be sufficient and reliable to substantiate the conclusions drawn during the audit.
6. Reporting
During the reporting phase, your auditor presents its findings to stakeholders. In the audit report, your auditor sets out observations, identifies issues and recommends improvements.
7. Follow-Up
In the follow-up stage, your auditor checks that you have addressed the issues identified during the audit, and may review the corrective actions you implemented and evaluate their effectiveness.
The seven steps of the audit process
Your auditor works through seven steps: planning, risk assessment, internal control testing, fieldwork, evidence collection, reporting and follow-up.
Your auditor uses them as one framework for evaluating your operations.
Your auditor follows them to keep the audit thorough, accurate and accountable. Before fieldwork, see what not to say during an audit.
The four types of audit opinion
At the reporting stage, your auditor gives one of four opinions on your financial statements, under AU-C 700 and 705:
| Unmodified. | Your statements are presented fairly, in all material respects, under your reporting framework. |
|---|---|
| Qualified. | Your auditor found a material misstatement, or could not get enough evidence, and the effect is material but not pervasive. Your auditor words it "except for." |
| Adverse. | Your auditor found misstatements that are material and pervasive. Your statements are materially misstated. |
| Disclaimer. | Your auditor could not get enough evidence, and the possible effects are material and pervasive. Your auditor gives no opinion. |
With an adverse opinion, your auditor knows the statements are wrong; with a disclaimer, your auditor could not find out. If you are a public company, your auditor calls the clean opinion unqualified, under PCAOB standards.

Questions about your last audit report
Send us last year's audit report and management letter. We will tell you how your lender, board or funder will read the opinion, and what to fix before the next audit.
The audit cycle, from step seven back to step one
In a recurring internal audit program, your auditor uses the follow-up to see which action plans remain open, then plans the next audit around them. Audit teams draw the seven steps as an audit cycle to show that link:
Audit procedures, the techniques inside the steps
Your auditor uses the steps to organize the work. Audit procedures are the techniques it applies through the audit, in risk assessment, in control testing and in substantive work, and the AICPA lists seven of them in its auditing standards. Your auditor draws on these four:
Inspection.
Your auditor reads the record itself, whether that is an invoice, a contract, a bank statement or a signed approval.
External confirmation.
Your auditor writes to your bank, your customer or your lender and uses the reply to verify the figure in your ledger.
Recalculation and reperformance.
Your auditor redoes the arithmetic, or redoes the control itself, and compares the result with yours.
Analytical procedures.
Your auditor studies the relationships in your numbers, year on year or against an expectation, and asks about what does not fit.
Your auditor also observes a process, inquires of your staff, and performs a test of details, which may cover every item, selected items or a sample. Your auditor sets that mix as the audit methodology and updates it as it learns more about the risks and the evidence.
Three, five or seven stages of an audit
Three stages.
Auditors who use three stages name planning, fieldwork and reporting, putting testing and evidence inside fieldwork and follow-up inside reporting.
Five stages.
Auditors who use five stages name risk assessment and follow-up separately, and keep control testing and evidence inside fieldwork.
Seven steps.
Auditors who use seven steps separate control testing from fieldwork, and evidence collection from both.
Count the stages in your own audit plan before you map it against any of these, because your team works to that plan.
500+
completed audits
50
states served
AICPA
peer-reviewed firm
16+
years in audit
Firm figures as of September 2026, from the Dimov Audit homepage.
Audit services
Treat the information as general, and ask a CPA about your own audit before you act on it.
Talk to an auditor about your next audit
Tell us your year end, what your funder, lender or board asked for, and which findings from last year's audit are still open. We will scope the work and tell you what your team should have ready.
Contact
Connect with Dimov Audit
Our dedicated team is ready to assist you on your path to financial success.
24 Mercer St, 2nd Floor, Suite 214
New York, NY 10013
United States
Reviewed by George Dimov, CPA. Dimov Audit performs financial statement audits and other attestation work for companies and nonprofits across all 50 states. Profile

