1/59
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
It is an international professional association with global headquarters in Lake Mary, Florida, USA. It is the internal audit profession's global voice, recognized authority, acknowledged leader, chief advocate, and principal educator.
Institute of Internal Auditors (IIA)
It organizes the authoritative body of knowledge, promulgated by The Institute of Internal Auditors, for the professional practice of internal auditing.
It addresses current internal audit practices while enabling practitioners and stakeholders globally to be flexible and responsive to the ongoing needs for high-quality internal auditing in diverse environments and organizations of different purposes, sizes, and structures.
International Professional Practices Framework (IPPF)
Three Major Parts of IPPF (GTG)
Global Internal Audit Standards
Topical Requirements
Global Guidance
These guide the worldwide professional practice of internal auditing and serve as a basis for evaluating and elevating the quality of the internal audit function.
Global Internal Audit Standards
Domains of Global Internal Audit Standards
Domain I: Purpose of Internal Auditing
Domain II: Ethics and Professionalism
Domain III: Governing the Internal Audit Function
Domain IV: Managing the Internal Audit Function
Domain V: Performing Internal Audit Services
These are designed to enhance the consistency and quality of internal audit services related to specific audit subjects and to support internal auditors performing engagements in those risk areas. Internal auditors must conform with the relevant requirements when the scope of an engagement includes one of the identified topics.
Topical Requirements
These supports the Standards by providing nonmandatory information, advice, and best practices for performing internal audit services. It is endorsed by The IIA through formal review and approval processes.
Global Guidance
These provide detailed approaches, step-by-step processes, and examples on subjects
Global Practice Guides
These provide auditors with the knowledge to perform assurance or advisory services related to an organization’s information technology and information security risks and controls.
Global Technology Audit Guides (GTAG)
It is the foundational document that guides internal auditors in performing their work with competence, integrity, and consistency. Is is developed through an internationally recognized due process by the International Internal Audit Standards Board (IIASB) and overseen by the IPPF Oversight Council
Global Internal Audit Standards 2024 (GIAS)
GIAS:
Principles:
Domains:
Standards:
Principles: 15
Domains: 5
Standards: 52
Under GIAS, these are mandatory requirements that internal auditors must follow.
Standards
Under GIAS, these are practical recommendations on how to apply the Standards.
Considerations for Implementation
Under GIAS, these are illustrations of documents or practices that demonstrate alignment with the Standards.
Examples of Evidence of Conformance
It is intended to assist internal auditors and internal audit stakeholders in understanding and articulating the value of internal auditing.
Purpose Statement
Primary Purpose of Internal Auditing
Strengthens the organization's ability to create, protect, and sustain value.
Provides independent, risk-based, and objective assurance, advice, insight, and foresight to the board and management.
“Value” Created by Internal Auditing
Enhances the achievement of organizational objectives.
Improves governance, risk management, and control processes.
Supports decision-making and oversight.
Bolsters the organization's reputation and credibility with stakeholders.
Increases the ability to serve the public interest.
Conditions for Effectiveness
Performed by competent professionals in alignment with the Global Internal Audit Standards.
Operates with independent positioning and direct accountability to the board.
Free from undue influence, ensuring objective assessments.
It refers to the official authorization for the internal audit function, often defined in the internal audit charter, and may be influenced by laws and regulations.
Internal Audit Mandate
Conditions that may warrant a follow up discussion with the board and senior management on the internal audit mandate.
Notable change in the Global Internal Audit Standards.
A significant acquisition or reorganization.
Significant changes in the board and/or Senior Management.
Significant changes to the organization’s strategies, objectives, risk profile, or the environment in which it operates.
New laws or regulations that may affect the nature and/or scope of internal audit services.
Key Components of Internal Audit Mandate
Authority
Role
Responsibilities
Authority
Directly reports to the board for independence.
Has unrestricted access to board, records, personnel, and physical property within the organization.
Role
Deliver internal audit services (assurance and advisory).
The CAE might also take on additional responsibilities, such as overseeing risk management or compliance, but these should be clearly defined and separate from internal audit responsibilities.
Responsibilities
Accountable for delivering audit services and meeting stakeholder expectations.
Compliance with laws, regulations, and policies.
Ensures compliance with Global Internal Audit Standards.
Coordinates with other functions (e.g., risk management, compliance) to clarify responsibilities.
Role of the Chief Audit Executive (CAE)
Provide necessary information to the board and senior management to establish the internal audit mandate. Need niyang i-explain kung ano yung scope, authority, role, and responsibilities ng internal audit function sa organization nila.
Coordinate with other assurance providers to understand roles and responsibilities.
Document/develop the mandate in the internal audit charter, which is approved by the board.
Conduct at least an annual assessment to determine whether changes in circumstances require a discussion about the internal audit mandate.
Role of the Board
Discuss with the CAE to establish appropriate authority, roles, and responsibilities of internal audit.
Approve the Internal Audit Charter, which outlines the mandate and scope.
Role of the Senior Management
Participate in discussions and provide input on internal audit expectations.
Support the mandate and authority throughout the organization.
It is a formal document that includes the internal audit function’s mandate, organizational position, reporting relationships, scope of work, types of services, and other specifications.
Internal Audit Charter
Key components of an Internal Audit Charter:
Purpose of Internal Auditing
Commitment to adhere to the Standards.
Mandate outlining the scope, services, and the board’s responsibilities and expectations regarding management’s support on internal audit mandates.
Organizational positioning and reporting relationships.
Functional Reporting - reporting to board and audit committee
Administrative Reporting - report to CEO and Senior Management
Importance of Discussing the Charter with the Board and Senior Management
Ensures that the board and senior management understand the scope, role, and expectations for the internal audit function.
Facilitates agreement between the CAE, board, and senior management on the internal audit function's mandate and strategic objectives.
A periodic review and discussion of the charter helps align the internal audit function with organizational changes, such as new risks, strategies, or regulations.
Importance of Board Approval
Board approval grants the internal audit function the authority to operate independently and without restrictions across the organization.
Approval by the board ensures the internal audit mandate, scope, and services are formally recognized and aligned with the organization’s needs.
These pertain to services through which internal auditors perform objective assessments to provide assurance
Assurance Services
Examples of assurance services
Compliance, financial, operational/performance, and technology engagements.
Internal auditors may provide limited or reasonable assurance, depending on the nature, timing, and extent of procedures (T/F)
True
These are the services through which internal auditors provide advice to an organization’s stakeholders without providing assurance or taking on management responsibilities.
Advisory Services
Overview of Assurance and Advisory Services
ASPECT | ASSURANCE | ADVISORY |
Objective | To provide assurance. | To provide advice/insights. |
Nature and Scope | Determined by the Internal Auditor. | Based on agreement with the client. |
Focus | Focuses on evaluating processes, controls, and compliance related to governance, risk management, and internal controls. | Addresses specific needs or requests from management or stakeholders. |
Consideration | Historical data. | Future activity. |
Suitable Criteria | Predefined standards, policies, or frameworks (e.g., COSO, ISO standards, regulatory requirements) to benchmark against. | Goals or objectives defined collaboratively with the client. |
Parties Involved | 3-party Involvement: (1) Process Owner, (2) Internal Auditor, and (3) User. | 2-Party Involvement: Internal Auditor and Client |
Result | Formal audit report containing statements as to the assurance/opinion on the audited area | Recommendations/advice/insight |
Sample Activities | Assurance services include performing financial, performance, compliance, system security, and due diligence engagements | Advisory services include providing counsel, advice, facilitation, and training. |
Types of Assurance Services
Risk and Control Assessments
Operational Audit
Financial Audit
Regulatory Compliance Audit
Third-Party and Contract Compliance Audit
IT Security and Privacy Audit
Performance and Quality Audit
Audit of Organizational Culture
Audits of the Management Reporting Process
It evaluates risks across organizational processes and systems.
Assess the design and operating effectiveness of internal controls.
Provide recommendations to mitigate identified risks.
Risk and Control Assessments
It examines processes and procedures to identify areas for efficiency improvement.
Operational Audit
It validates the accuracy of financial statements and adherence to accounting standards.
Financial Audit
It ensures compliance with laws, regulations, and industry standards.
Regulatory Compliance Audit
It examines compliance with contractual obligations and agreements.
Assess third-party relationships for risks, performance, and compliance with organizational policies.
Third-Party and Contract Compliance Audit
It reviews IT systems to identify vulnerabilities in cybersecurity and data protection.
Ensure compliance with data privacy laws and organizational IT policies.
IT Security and Privacy Audit
It evaluates operational efficiency and effectiveness.
Measure whether organizational activities meet established quality benchmarks.
Performance and Quality Audit
It assess alignment between the organization’s values, policies, and behaviors.
Identify cultural risks that may impact employee performance or ethical practices.
Audit of Organizational Culture
It evaluates the reliability, timeliness, and accuracy of reports provided to management.
Assess the quality of data and information used for decision-making.
Audits of the Management Reporting Process
Educate staff and management on risk management principles and effective internal controls.
Provide training on identifying, assessing, and mitigating risks.
Risk and Control Trainings
Provides independent evaluation of system design, processes, and testing to ensure alignment with organizational goals, regulatory standards, industry practices, while also ensuring risks are identified and mitigated through effective internal controls.
Reviews the system post-implementation to verify that it operates as intended.
System Design and Development
Provides insights/advice regarding the risks such as financial, operational, legal, and compliance, and the overall internal control environment and governance of a potential investment, acquisition, or partnership to ensure informed decision-making.
Due Diligence Services
Advising on the development and improvement of data privacy policies, procedures, and training programs to promote organizational awareness and adherence to data privacy standards.
Data Privacy
Provides insights on best practices to identify gaps and improvement opportunities.
Benchmarking
Advises with an independent assessment on the overall internal control environment of the organization.
Guides stakeholders on how to effectively design and operationalize internal controls.
Internal Control Assessments
Reviews and documents current processes to identify gaps and ensure currency of process mapping.
Provides recommendations for process optimization and aligning process workflows with industry best practices to improve overall efficiency and compliance.
Process Mapping
It is the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner.
Independence
Independence Requirements
The CAE must confirm to the board the organizational independence of the internal audit function at least annually. This includes communicating incidents where independence may have been impaired, and the actions or safeguards employed to address the impairment.
The CAE must document in the IA charter the reporting relationships and organizational positioning of the IA function, as determined by the board.
The CAE must discuss with the board and senior management any current or proposed roles and responsibilities that have the potential to impair the internal audit function’s independence, either in fact or appearance.
Board’s Role in Promoting Independence
Establish direct reporting with the CAE for effective oversight.
Authorize CAE appointment and removal.
Support CAE’s independence through input on evaluation and remuneration.
Ensure internal audit function is free from management interference.
Acknowledge impairments and approve safeguards.
Senior Management’s Role in Promoting Independence
Position the internal audit function at a level that ensures independence.
Recognize the CAE’s direct reporting relationship to the board.
Collaborate with the board and CAE to address and safeguard against independence impairments.
Examples of Impairments to Independence
The chief audit executive lacks direct communication or interaction with the board.
Management attempts to limit the scope of the internal audit services that were previously approved by the board and documented in the internal audit charter.
Management attempts to restrict access to the data, records, information, personnel, and physical properties required to perform the internal audit services.
Management pressures internal auditors to suppress or change internal audit findings.
The budget for the internal audit function is reduced to a level that leaves the function unable to fulfill its responsibilities as outlined in the internal audit charter.
An assurance engagement is performed by the internal audit function or supervised by the chief audit executive in a functional area for which the chief audit executive is responsible, has oversight, or is otherwise able to exert significant influence.
The internal audit function performs, or the chief audit executive supervises, assurance services related to an activity that is managed by a senior executive (non-CEO) to which the chief audit executive reports administratively. For example, the chief audit executive reports to the chief financial officer and is responsible for auditing treasury, a function that also reports to the chief financial officer.
The CAE is sometimes asked to take on roles that may impair the IA function’s independence. Examples of such situations include:
A new regulatory requirement prompts an immediate need to develop controls and other risk management activities to ensure compliance.
The chief audit executive has the most appropriate expertise to adapt existing risk management activities to a new business segment or geographic market.
The organization’s resources are too constrained, or the organization is too small to afford a separate compliance function.
IA’s Role in Risk Management
IA provides independent assurance that risks are being managed effectively by the first and second lines of defense while safeguarding its independence.
It integrates risk management, governance, and assurance roles across the organization
Three Lines Model
They are directly responsible for owning and managing risks
Examples: Business units, frontline operations, customer service teams.
First Line or the operational management
They have oversight and monitoring functions which support the organization’s risk management by providing policies, guidance, and expertise.
Examples: Risk management, compliance, and control functions.
Second Line or other assurance providers
They provide independent assurance on the effectiveness of governance, risk management, and controls.
Third Line or the internal audit