Foundations of Internal Auditing

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/59

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:29 AM on 7/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

60 Terms

1
New cards

It is an international professional association with global headquarters in Lake Mary, Florida, USA. It is the internal audit profession's global voice, recognized authority, acknowledged leader, chief advocate, and principal educator.

Institute of Internal Auditors (IIA)

2
New cards

It organizes the authoritative body of knowledge, promulgated by The Institute of Internal Auditors, for the professional practice of internal auditing.

It addresses current internal audit practices while enabling practitioners and stakeholders globally to be flexible and responsive to the ongoing needs for high-quality internal auditing in diverse environments and organizations of different purposes, sizes, and structures.

International Professional Practices Framework (IPPF)

3
New cards

Three Major Parts of IPPF (GTG)

  1. Global Internal Audit Standards

  2. Topical Requirements

  3. Global Guidance

4
New cards

These guide the worldwide professional practice of internal auditing and serve as a basis for evaluating and elevating the quality of the internal audit function.

Global Internal Audit Standards

5
New cards

Domains of Global Internal Audit Standards

  • Domain I: Purpose of Internal Auditing

  • Domain II: Ethics and Professionalism

  • Domain III: Governing the Internal Audit Function

  • Domain IV: Managing the Internal Audit Function

  • Domain V: Performing Internal Audit Services

6
New cards

These are designed to enhance the consistency and quality of internal audit services related to specific audit subjects and to support internal auditors performing engagements in those risk areas. Internal auditors must conform with the relevant requirements when the scope of an engagement includes one of the identified topics.

Topical Requirements

7
New cards

These supports the Standards by providing nonmandatory information, advice, and best practices for performing internal audit services. It is endorsed by The IIA through formal review and approval processes.

Global Guidance

8
New cards

These provide detailed approaches, step-by-step processes, and examples on subjects

Global Practice Guides

9
New cards

These provide auditors with the knowledge to perform assurance or advisory services related to an organization’s information technology and information security risks and controls.

Global Technology Audit Guides (GTAG)

10
New cards

It is the foundational document that guides internal auditors in performing their work with competence, integrity, and consistency. Is is developed through an internationally recognized due process by the International Internal Audit Standards Board (IIASB) and overseen by the IPPF Oversight Council

Global Internal Audit Standards 2024 (GIAS)

11
New cards

GIAS:

  • Principles:

  • Domains:

  • Standards:

  • Principles: 15

  • Domains: 5

  • Standards: 52

12
New cards

Under GIAS, these are mandatory requirements that internal auditors must follow.

Standards

13
New cards

Under GIAS, these are practical recommendations on how to apply the Standards.

Considerations for Implementation

14
New cards

Under GIAS, these are illustrations of documents or practices that demonstrate alignment with the Standards.

Examples of Evidence of Conformance

15
New cards

It is intended to assist internal auditors and internal audit stakeholders in understanding and articulating the value of internal auditing.

Purpose Statement

16
New cards

Primary Purpose of Internal Auditing

  • Strengthens the organization's ability to create, protect, and sustain value.

  • Provides independent, risk-based, and objective assurance, advice, insight, and foresight to the board and management.

17
New cards

“Value” Created by Internal Auditing

  • Enhances the achievement of organizational objectives.

  • Improves governance, risk management, and control processes.

  • Supports decision-making and oversight.

  • Bolsters the organization's reputation and credibility with stakeholders.

  • Increases the ability to serve the public interest.

18
New cards

Conditions for Effectiveness

  • Performed by competent professionals in alignment with the Global Internal Audit Standards.

  • Operates with independent positioning and direct accountability to the board.

  • Free from undue influence, ensuring objective assessments.

19
New cards

It refers to the official authorization for the internal audit function, often defined in the internal audit charter, and may be influenced by laws and regulations.

Internal Audit Mandate

20
New cards

Conditions that may warrant a follow up discussion with the board and senior management on the internal audit mandate.

  • Notable change in the Global Internal Audit Standards.

  • A significant acquisition or reorganization.

  • Significant changes in the board and/or Senior Management.

  • Significant changes to the organization’s strategies, objectives, risk profile, or the environment in which it operates.

  • New laws or regulations that may affect the nature and/or scope of internal audit services.

21
New cards

Key Components of Internal Audit Mandate

  • Authority

  • Role

  • Responsibilities

  • Authority

    • Directly reports to the board for independence.

    • Has unrestricted access to board, records, personnel, and physical property within the organization.

  • Role

    • Deliver internal audit services (assurance and advisory).

    • The CAE might also take on additional responsibilities, such as overseeing risk management or compliance, but these should be clearly defined and separate from internal audit responsibilities.

  • Responsibilities

    • Accountable for delivering audit services and meeting stakeholder expectations.

    • Compliance with laws, regulations, and policies.

    • Ensures compliance with Global Internal Audit Standards.

    • Coordinates with other functions (e.g., risk management, compliance) to clarify responsibilities.

22
New cards

Role of the Chief Audit Executive (CAE)

  • Provide necessary information to the board and senior management to establish the internal audit mandate. Need niyang i-explain kung ano yung scope, authority, role, and responsibilities ng internal audit function sa organization nila.

  • Coordinate with other assurance providers to understand roles and responsibilities.

  • Document/develop the mandate in the internal audit charter, which is approved by the board.

  • Conduct at least an annual assessment to determine whether changes in circumstances require a discussion about the internal audit mandate.

23
New cards

Role of the Board

  • Discuss with the CAE to establish appropriate authority, roles, and responsibilities of internal audit.

  • Approve the Internal Audit Charter, which outlines the mandate and scope.

24
New cards

Role of the Senior Management

  • Participate in discussions and provide input on internal audit expectations.

  • Support the mandate and authority throughout the organization.

25
New cards

It is a formal document that includes the internal audit function’s mandate, organizational position, reporting relationships, scope of work, types of services, and other specifications.

Internal Audit Charter

26
New cards

Key components of an Internal Audit Charter:

  • Purpose of Internal Auditing

  • Commitment to adhere to the Standards.

  • Mandate outlining the scope, services, and the board’s responsibilities and expectations regarding management’s support on internal audit mandates.

  • Organizational positioning and reporting relationships.

    • Functional Reporting - reporting to board and audit committee

    • Administrative Reporting - report to CEO and Senior Management

27
New cards

Importance of Discussing the Charter with the Board and Senior Management

  • Ensures that the board and senior management understand the scope, role, and expectations for the internal audit function.

  • Facilitates agreement between the CAE, board, and senior management on the internal audit function's mandate and strategic objectives.

  • A periodic review and discussion of the charter helps align the internal audit function with organizational changes, such as new risks, strategies, or regulations.

28
New cards

Importance of Board Approval

  • Board approval grants the internal audit function the authority to operate independently and without restrictions across the organization.

  • Approval by the board ensures the internal audit mandate, scope, and services are formally recognized and aligned with the organization’s needs.

29
New cards

These pertain to services through which internal auditors perform objective assessments to provide assurance

Assurance Services

30
New cards

Examples of assurance services

  • Compliance, financial, operational/performance, and technology engagements.

31
New cards

Internal auditors may provide limited or reasonable assurance, depending on the nature, timing, and extent of procedures (T/F)

True

32
New cards

These are the services through which internal auditors provide advice to an organization’s stakeholders without providing assurance or taking on management responsibilities.

Advisory Services

33
New cards

Overview of Assurance and Advisory Services

ASPECT

ASSURANCE

ADVISORY

Objective

To provide assurance.

To provide advice/insights.

Nature and Scope

Determined by the Internal Auditor.

Based on agreement with the client.

Focus

Focuses on evaluating processes, controls, and compliance related to governance, risk management, and internal controls.

Addresses specific needs or requests from management or stakeholders.

Consideration

Historical data.

Future activity.

Suitable Criteria

Predefined standards, policies, or frameworks (e.g., COSO, ISO standards, regulatory requirements) to benchmark against.

Goals or objectives defined collaboratively with the client.

Parties Involved

3-party Involvement: (1) Process Owner, (2) Internal Auditor, and (3) User.

2-Party Involvement: Internal Auditor and Client

Result

Formal audit report containing statements as to the assurance/opinion on the audited area

Recommendations/advice/insight
Training

Sample Activities

Assurance services include performing financial, performance, compliance, system security, and due diligence engagements

Advisory services include providing counsel, advice, facilitation, and training.

34
New cards

Types of Assurance Services

  • Risk and Control Assessments

  • Operational Audit

  • Financial Audit

  • Regulatory Compliance Audit

  • Third-Party and Contract Compliance Audit

  • IT Security and Privacy Audit

  • Performance and Quality Audit

  • Audit of Organizational Culture

  • Audits of the Management Reporting Process

35
New cards
  • It evaluates risks across organizational processes and systems.

  • Assess the design and operating effectiveness of internal controls.

  • Provide recommendations to mitigate identified risks.

Risk and Control Assessments

36
New cards

It examines processes and procedures to identify areas for efficiency improvement.

Operational Audit

37
New cards

It validates the accuracy of financial statements and adherence to accounting standards.

Financial Audit

38
New cards

It ensures compliance with laws, regulations, and industry standards.

Regulatory Compliance Audit

39
New cards
  • It examines compliance with contractual obligations and agreements.

  • Assess third-party relationships for risks, performance, and compliance with organizational policies.

Third-Party and Contract Compliance Audit

40
New cards
  • It reviews IT systems to identify vulnerabilities in cybersecurity and data protection.

  • Ensure compliance with data privacy laws and organizational IT policies.

IT Security and Privacy Audit

41
New cards
  • It evaluates operational efficiency and effectiveness.

  • Measure whether organizational activities meet established quality benchmarks.

Performance and Quality Audit

42
New cards
  • It assess alignment between the organization’s values, policies, and behaviors.

  • Identify cultural risks that may impact employee performance or ethical practices.

Audit of Organizational Culture

43
New cards
  • It evaluates the reliability, timeliness, and accuracy of reports provided to management.

  • Assess the quality of data and information used for decision-making.

Audits of the Management Reporting Process

44
New cards
  • Educate staff and management on risk management principles and effective internal controls.

  • Provide training on identifying, assessing, and mitigating risks.

Risk and Control Trainings

45
New cards
  • Provides independent evaluation of system design, processes, and testing to ensure alignment with organizational goals, regulatory standards, industry practices, while also ensuring risks are identified and mitigated through effective internal controls.

  • Reviews the system post-implementation to verify that it operates as intended.

System Design and Development

46
New cards

Provides insights/advice regarding the risks such as financial, operational, legal, and compliance, and the overall internal control environment and governance of a potential investment, acquisition, or partnership to ensure informed decision-making.

Due Diligence Services

47
New cards

Advising on the development and improvement of data privacy policies, procedures, and training programs to promote organizational awareness and adherence to data privacy standards.

Data Privacy

48
New cards

Provides insights on best practices to identify gaps and improvement opportunities.

Benchmarking

49
New cards
  • Advises with an independent assessment on the overall internal control environment of the organization.

  • Guides stakeholders on how to effectively design and operationalize internal controls.

Internal Control Assessments

50
New cards
  • Reviews and documents current processes to identify gaps and ensure currency of process mapping.

  • Provides recommendations for process optimization and aligning process workflows with industry best practices to improve overall efficiency and compliance.

Process Mapping

51
New cards

It is the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner.

Independence

52
New cards

Independence Requirements

  • The CAE must confirm to the board the organizational independence of the internal audit function at least annually. This includes communicating incidents where independence may have been impaired, and the actions or safeguards employed to address the impairment.

  • The CAE must document in the IA charter the reporting relationships and organizational positioning of the IA function, as determined by the board.

  • The CAE must discuss with the board and senior management any current or proposed roles and responsibilities that have the potential to impair the internal audit function’s independence, either in fact or appearance.

53
New cards

Board’s Role in Promoting Independence

  • Establish direct reporting with the CAE for effective oversight.

  • Authorize CAE appointment and removal.

  • Support CAE’s independence through input on evaluation and remuneration.

  • Ensure internal audit function is free from management interference.

  • Acknowledge impairments and approve safeguards.

54
New cards

Senior Management’s Role in Promoting Independence

  • Position the internal audit function at a level that ensures independence.

  • Recognize the CAE’s direct reporting relationship to the board.

  • Collaborate with the board and CAE to address and safeguard against independence impairments.

55
New cards

Examples of Impairments to Independence

  • The chief audit executive lacks direct communication or interaction with the board.

  • Management attempts to limit the scope of the internal audit services that were previously approved by the board and documented in the internal audit charter.

  • Management attempts to restrict access to the data, records, information, personnel, and physical properties required to perform the internal audit services.

  • Management pressures internal auditors to suppress or change internal audit findings.

  • The budget for the internal audit function is reduced to a level that leaves the function unable to fulfill its responsibilities as outlined in the internal audit charter.

  • An assurance engagement is performed by the internal audit function or supervised by the chief audit executive in a functional area for which the chief audit executive is responsible, has oversight, or is otherwise able to exert significant influence.

  • The internal audit function performs, or the chief audit executive supervises, assurance services related to an activity that is managed by a senior executive (non-CEO) to which the chief audit executive reports administratively. For example, the chief audit executive reports to the chief financial officer and is responsible for auditing treasury, a function that also reports to the chief financial officer.

  • The CAE is sometimes asked to take on roles that may impair the IA function’s independence. Examples of such situations include:

    • A new regulatory requirement prompts an immediate need to develop controls and other risk management activities to ensure compliance.

    • The chief audit executive has the most appropriate expertise to adapt existing risk management activities to a new business segment or geographic market.

    • The organization’s resources are too constrained, or the organization is too small to afford a separate compliance function.

56
New cards

IA’s Role in Risk Management

IA provides independent assurance that risks are being managed effectively by the first and second lines of defense while safeguarding its independence.

57
New cards

It integrates risk management, governance, and assurance roles across the organization

Three Lines Model

58
New cards

They are directly responsible for owning and managing risks

  • Examples: Business units, frontline operations, customer service teams.

First Line or the operational management

59
New cards

They have oversight and monitoring functions which support the organization’s risk management by providing policies, guidance, and expertise.

  • Examples: Risk management, compliance, and control functions.

Second Line or other assurance providers

60
New cards

They provide independent assurance on the effectiveness of governance, risk management, and controls.

Third Line or the internal audit