1/48
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
When studying the purpose statement, remember an effective internal audit function PRODS an organization toward success by enhancing:
Processes;
Reputation;
Objectives;
Decision-making; and by
Serving the interest of the public.
PRODS = Processes, Reputation, Objectives, Decision-making, Serving the interest of the public.
Consider the mnemonic STARR when considering what elements the internal audit mandate helps to establish for the internal audit function.
ST: The scope and type of internal audit services to be delivered
A: The internal audit function's authority
R: The role of the internal audit function
R: The responsibilities of the internal audit function
The mnemonic COMP can be used to recall the four required components of the internal audit charter:
C: Commitment to adhering to the Global Internal Audit Standards
O: Organizational position and reporting relationships
M: Internal Audit Mandate
P: Purpose of Internal Auditing
An organization's board is responsible for approving the internal audit charter.
What is Assurance and Advisory
Assurance engagements involve an internal auditor providing an opinion on past events related to an organization's objectives or processes.
Advisory engagements relate to an internal auditor providing insights on ways to improve the organization's processes or objectives in the future.
What is a compliance audit?
Compliance audits relate to the organization's compliance with laws, regulations, or policies, whereas a third-party audit may relate to an external party's compliance with contract terms. Although both relate to compliance, one is focused on the organization's own compliance, whereas the other is focused on the compliance of an external party.
What is the reporting relationship of the CAE?
The reporting relationship of the chief audit executive, both functionally and administratively, must allow for unrestricted access to report relevant matters to the highest level of governance within the organization.
What is the success of IA CAE dependent on?
The success of the internal audit function is dependent upon the conditions within the organization that support the CAE:
Reports directly to the board;
Has the appropriate qualifications; and
Is positioned at a level of the organization that supports the internal audit function to perform services without interference.
What type of independence should IA be aware of to maintain reliability?
The organization must be aware of actual and perceived independence impairments to maintain the reliability of the internal audit function's services in the view of stakeholders.
Consider using the mnemonic TACO to help remember that the Standard requirements outline that internal auditors must be:
Truthful
Accurate
Clear
Open
Internal auditors must be truthful, accurate, clear, open, and respectful in all professional relationships and communications.
The CAE must maintain a work environment where internal auditors feel supported when expressing legitimate, evidence-based engagement results, regardless of whether those results are favorable or unfavorable. This is essential for fostering integrity during internal audit engagements, as it encourages internal auditors to disclose results honestly without fear of repercussion.
Internal auditors must avoid any action that could be considered discreditable to the profession of internal auditing or to the organization. This includes behaviors that might not be strictly illegal but could damage the organization's reputation, harm its employees, or undermine the integrity of the internal audit profession.
Consider the mnemonic FPS (frames per second) to remember examples of bias:
F: Familiarity bias
P: Prejudice or unconscious bias
S: Self-review bias
An impairment of objectivity exists in appearance when a reasonable third party perceives objectivity to be impaired, even if no actual impairment has occurred. Therefore, perceived impairments are as important as actual impairments for internal auditors.
Please consider the mnemonic CUPS to help remember examples of conflicts of interest:
C: Conflicting interests
U: Undue financial or personal benefits
P: Protecting oneself from harm or loss
S: Showing favoritism
Safeguarding Objectivity in Internal Audit Services
Assurance Services
The 12-Month Rule: Refrain from providing assurance services for activities for which the internal auditor had responsibility within the previous 12 months.
For assurance services over activities where advisory services were performed previously, the CAE must:
Confirm that objectivity is not impaired due to prior advisory services; and
Assign resources to manage the individual activity.
For assurance services over functions the CAE has responsibility for, the engagement must be overseen by an independent party outside of the internal audit function.
Advisory Services
For advisory services over activities internal auditors had previous responsibilities for, disclose the prior responsibility to the party requesting the service before accepting the engagement.
Disclosure of Impairments to Objectivity
Prompt disclosure to appropriate parties when impaired in fact or appearance.
Responsibilities of Individual Internal Auditors
Internal auditors must inform the CAE or a designated supervisor when becoming aware of an impairment.
Responsibilities of the CAE
The CAE must discuss with:
(1) the management of the activity under review,
(2) the board,
(3) senior management, and/or
(4) other affected stakeholders
to determine the appropriate actions in the following circumstances:
An impairment affecting an internal auditor's ability to perform duties objectively.
An impairment affecting the reliability or perceived reliability of the engagement findings, recommendations, and/or conclusions.
Impairment of the CAE
If the CAE's own objectivity is impaired, it must be disclosed directly to the board.
The individual internal auditor, not the CAE, is responsible for ensuring conformance with the Standards on continuing professional development.
According to The IIA, holders of the Certified Internal Auditor® (CIA) certification are required to self-certify annually with respect to the completion of required continuing education hours by December 31.
The number of annual continuing professional education hours required varies globally and depends on whether the certified individual is practicing or nonpracticing. The required annual continuing professional education hours for CIAs who are actively performing internal audit or related activities (practicing individuals) is 40 hours, while that for those who are not retired but not actively performing those activities (nonpracticing individuals) is 20 hours.
It is important to note that the requirements under Standard 4.2: Due Professional Care apply to both assurance and advisory services.
An example of exercising due professional care in relation to cost-benefit analysis is conducting a thorough assessment of an engagement's potential benefits to the organization, comparing the benefits to the estimated costs, and documenting the decision-making process to help ensure the internal audit function's resources are used effectively and the engagement's value justifies its expense.
Each internal auditor has the responsibility to exercise due professional care.
In addition, the CAE has the ultimate responsibility for ensuring due professional care through managing the internal audit function and implementing a quality assurance and improvement program (QAIP).
To protect proprietary information, internal auditors may be required to follow specific policies and procedures, even when managing information within the organization, such as:
Collecting only the data necessary to complete the assigned engagement and using it solely for the engagement's intended purposes (Custody, retention, and disposal).
Safeguarding information from both intentional and accidental disclosure by implementing controls such as data encryption, email distribution limitations, restricted social media usage, and constraining physical access to the data (Release of records).
Deleting or removing access to the data once it is no longer needed (Access to or handling of information that is no longer needed).
Consider the mnemonic CAR to remember methods for protecting information:
C – Custody, retention, and disposal of engagement records
A – Access to or handling of confidential information no longer needed
R – Release of engagement records to internal and external parties
In most organizations, the ultimate responsibility for guiding the governance process lies with the board.
The board is responsible for establishing and maintaining the organization's governance processes and obtaining assurances concerning the effectiveness of the risk management and control processes.
A primary role of the internal audit function is to evaluate and enhance an organization's:
Governance
Risk management
Control processes
Roles Relating to Governance
The board is responsible for guiding the governance process. In most organizations, the board has the ultimate responsibility for governance.
Senior management is accountable for leading risk management and control processes and may delegate responsibilities to designated line management serving as risk owners.
The internal audit function evaluates governance processes and helps enhance the organization's governance framework.
External assurance providers complement the work of internal auditors while also helping meet regulatory requirements.
As outlined in the Standards:
“A thorough understanding of the organization's governance, risk management, and control processes enables the chief audit executive to identify and prioritize opportunities to provide internal audit services that may enhance the organization's success.”
The identified opportunities form the basis of the internal audit strategy and plan.
The control environment is influenced by management style and how leadership fulfills its oversight responsibilities.
Because it focuses on:
Integrity
Ethical values
Competence in daily business activities
the control environment is often associated with the organization's culture.
The internal audit function reviews the organization's related objectives, programs, and activities.
These could include:
Mission and value statements
A code of conduct
Hiring and training processes
Anti-fraud and whistleblowing policies
A hotline and investigation process
An organization's code of conduct/ethics is a critical element of an ethics and compliance program that communicates expected behaviors and helps ensure compliance with:
Ethical requirements
Legal requirements
Compliance requirements
The internal audit function's role in an organization's ethical framework is to assist with the monitoring and assessment of the effectiveness of the organization's:
Ethics program
Compliance program
Related controls
The internal audit function evaluates whether ethics and compliance activities are designed and operating effectively to support the organization's governance objectives.
Provide your feedback on BizChat
All audit projects performed by an internal auditor should include, at a minimum, an informal risk assessment related to the organization's ethical climate.
The primary purpose of using an Enterprise Risk Management (ERM) framework is to bring:
Structure
Consistency
Accountability
into an organization's risk management process.
A good indicator of an organization's risk management maturity is the degree to which risk management activities are integrated with:
Strategic planning
Business processes
Operational decision-making
The more risk management is embedded into these activities, the more mature the organization's risk management process is.
The internal auditor should consider the findings and conclusions of multiple engagements to identify:
Patterns
Trends
Gaps
related to the effectiveness of the organization's risk management process.
The internal auditor should communicate these insights to the board and senior management.
COSO's Internal Control-Integrated Framework (2013) does not prescribe specific controls that an organization should implement for effective internal control.
Instead, the selection and design of controls require management's judgment based on factors that are unique to the organization.
An effective and efficient system of internal control is the responsibility of management.
The internal audit function plays a critical role in providing:
Assurance services
Advisory services
intended to enhance the benefits provided to the organization by its system of internal control.
The act of fraud requires an intent to deceive, whereas error is an unintentional misstatement or omission of fact.
Memory Tip:
Fraud = Intentional
Error = Unintentional
Financial statement fraud may include:
Fictitious revenue
Improper asset valuation
Memory Tip:
Think "Revenue & Assets". Financial statement fraud commonly involves either overstating revenue or misstating asset values to make financial results appear stronger than they really are.
The IT landscape is ever-evolving, and IT fraud risks continue to expand as technological developments and increased reliance on information inputs and outputs support business operations.
Importantly, evolving IT environments can:
Increase the likelihood of fraud schemes
Create diverse fraud risks
Require organizations to consider both the adoption and non-adoption of new technologies when identifying IT fraud risks
Memory Tip:
Think "Technology Changes = Fraud Risks Change." As technology evolves, organizations must continuously reassess fraud risks associated with both new and existing technologies.
Remember OPA! when conducting a fraud risk assessment for an internal audit engagement.
O – Obtain an understanding of the organization's fraud risks.
P – Plan to brainstorm potential fraud risks.
A – Assess the identified fraud risks.
Memory Tip:
OPA! is an expression used to warn others of unnoticed dangers, making it a useful reminder of the fraud risk assessment process:
Obtain → Plan → Assess.
While management is ultimately responsible for:
Fraud prevention
Fraud detection
Fraud investigation
it is imperative that all organizational functions work collaboratively to reduce fraud risk.
Memory Tip:
Management owns fraud risk, but fighting fraud is everyone's responsibility. Internal audit, compliance, legal, HR, operations, and employees all play a role in reducing the organization's exposure to fraud.
A whistleblower hotline's lack of use does not, by itself, indicate a red flag.
It may simply mean:
There are no matters to report, or
Employees are using other reporting channels.
Memory Tip:
No hotline reports ≠ No ethics program effectiveness issues. A lack of hotline activity alone is not sufficient evidence of a problem.
Remember RIB when identifying fraud red flags.
R – Research
I – Interview
B – Brainstorm
Use these three techniques to help identify potential fraud indicators and areas of heightened fraud risk during an engagement.
Memory Tip:
Just like the human body has RIBs, fraud red flag detection has three key components:
Research → Interview → Brainstorm
The internal audit function supports the organization's fraud risk management program by:
Providing assurance services over controls designed to prevent or detect fraud in a timely manner.
Providing advisory services to management for the design and implementation of controls, including controls related to the fraud investigation process.
Memory Tip: Internal Audit does not own fraud risk. Instead, it helps by providing:
A&A = Assurance + Advisory
Assurance: Are fraud controls working?
Advisory: How can fraud controls be improved?
The most effective approach to assessing potential fraud schemes is to think like a fraudster.
By focusing on control weaknesses, internal auditors can better understand how a fraudster might exploit vulnerabilities to carry out a scheme.
Key Concept:
Fraudsters target weak controls.
Identifying and analyzing control weaknesses helps uncover potential fraud opportunities.
Viewing the process from the fraudster's perspective improves fraud risk identification and assessment.
Memory Tip:
"Follow the Weakness." If you want to find potential fraud schemes, look for weak controls because that's where fraudsters look first.
The internal audit function's role in investigations should be clearly defined and included in:
The internal audit charter
The organization's fraud policies and procedures
Memory Tip:
Think "Document the IA Role." Internal Audit's responsibilities relating to fraud investigations should be formally established before an investigation occurs, ensuring expectations and authority are clearly communicated.
Although the internal audit function may monitor the progress of remediation efforts, responsibility for:
Resolving fraud incidents
Implementing corrective actions
Executing remediation efforts
rests with management and the board (governing body).
Memory Tip:
Internal Audit Monitors; Management Fixes.
Internal Audit can track and report on remediation progress, but management and the board own the responsibility for resolving fraud issues and implementing corrective actions.
Fraud investigation testing should include transactional data analysis.
The ability to analyze large data sets enables the fraud investigation team to:
Better assess the extent of the suspected fraud
Quantify the financial impact
Refine investigative procedures based on identified patterns and anomalies
Memory Tip:
"Follow the Data." Large-scale transactional data analysis helps investigators determine how much fraud occurred, how widespread it was, and what the financial consequences may be.