Not applicable

Hi @Rajeesh Raj1 ,

An Organization Creates Auditable units with entities such as business units,departments, vendors,products, Business processes , Business Applications, locations, Authority Documents and Policies to perform  RISK ASSESSMENTS .

After RISK ASSESSMENTS ae performed , based on risk ratings , the audit managers can decide if they want to audit the entities . They can scope an auditable unit as an entity on an engagement.