1/90
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Principle 13:
Plan Engagements Effectively
Standard 13.1:
Engagement Communication
Standard 13.2:
Engagement Risk Assessment
Standard 13.3
Engagement Objectives and Scope
Standard 13.4:
Evaluation Criteria
Standard 13.5:
Engagement Resources
Standard 13:6:
Work Program
Principle 14:
Conduct Engagement Work
Standard 14.1:
Gathering Information for Analyses and Evaluation
Standard 14.2:
Analyses and Potential Engagement Findings
Standard 14.3:
Evaluation of Findings
Standard 14.4:
Recommendations and Action Plans
Standard 14.5:
Engagement Conclusions
Standard 14.6:
Engagement Documentation
Principle 15:
Communicate Engagement Results and Monitor Action Plans
Standard 15.1:
Final Engagement Communication
Standard 15.2:
Confirming the Implementation of Recommendations or Action Plans
Standards that are under Principle 13: Plan Engagements Effectively
CROC ReP
Communication
Risk assessment
Objectives and scope
Criteria
Resources
Program
Standards that are under Principle 14: Conduct Engagement Work
AFReCDo
Analyses and evaluation
Findings
Recommendations and action plans
Conclusion
Documentation
Standards that are under Principle 15: Communicate Engagement Results and Monitor Action Plans
FI
Final engagement communication
Implementation of recommendations and action plans
It is a document, developed by the chief audit executive, that identifies the engagement and other internal audit services anticipated to be provided during a given period.
Internal Audit Plan
The internal audit plan should be __________ and __________, reflecting timely adjustments in response to changes affecting the organization
risk based and dynamic
It includes the process during which internal auditors gather information, assess and prioritize risks relevant to the activity under review, establish engagement objectives and scope, identify evaluation criteria, and create a work program for an engagement
Engagement Plan
IA Annual Plan vs Engagement Plan
Aspect | IA Annual Plan | Engagement Plan |
Purpose | Provides a strategic overview of audit activities for the year. | Provides detailed guidance for specific audit engagement. |
Scope | Covers multiple engagements across various risk areas. | Focuses on one specific engagement at a time. |
Development Process | Based on a comprehensive risk assessment considering organizational objectives. | Based on engagement-specific risk assessment and scope. |
Approval Authority | Requires approval from the board and senior management. | Approved by the Chief Audit Executive (CAE) and/or Engagement Supervisor. |
Update Frequency | Reviewed and updated at least annually, or more frequently if needed. | Reviewed and adjusted as needed during the engagement. |
Resource Allocation | Allocates resources across the audit function for all planned engagements. | Allocates resources specifically for the engagement. |
Risk Consideration | Identifies high-risk areas that require assurance. | Assesses risks specific to the engagement and determines audit procedures. |
Communication | Communicated to the board, senior management, and key stakeholders. | Communicated to auditees and relevant stakeholders during planning meetings. |
Output of Standards 13.1: Engagement Communication
Engagement Announcement Letter, Kick-off Meeting, Close-out Meeting, Ongoing Stakeholder Communication
Considerations for Implementation (Flow of Communication) - Standard 13.1
Opening/Entrance Meeting or Memo
Engagement Plan Details
Evidence Request List
Expectation Setting
Status Update
Closing/Exit Meeting or Memo
Results (Findings, recommendations, and/or action plans)
Monitoring (Recommendation and/or Action Plans)
Output of Standards 13.2: Engagement Risk Assessment
Risk Assessment Narrative, Process Flowchart, Design Adequacy Test Results, Risk & Control Matrix
Output of Standards 13.3: Engagement Objectives and Scope
Finalized Objectives and Scope
Output of Standards 13.4: Evaluation Criteria
Established Criteria for Testing Operating Effectiveness
Output of Standards 13.5: Engagement Resources
Confirmed Resource Requirements (HR, Financial, & Technology)
Output of Standards 13.6: Work Program
Documented Audit Test Procedures/Engagement Work Program
For advisory services, a formal, documented risk assessment may not be necessary (T/F)
True (Standard 13.2 Engagement Risk Assessment)
To develop an adequate understanding, internal auditors must identify and gather reliable, relevant, and sufficient information regarding:
The organization’s strategies, objectives, and risks relevant to the activity under review.
The organization’s risk tolerance, if established.
The risk assessment supporting the internal audit plan.
The governance, risk management, and control processes of the activity under review.
Applicable frameworks, guidance, and other criteria that can be used to evaluate the effectiveness of those processes.
Internal auditors must identify the risks to review by:
Identifying the potentially significant risks to the objectives of the activity under review.
Considering specific risks related to fraud.
Evaluating the significance of the risks and prioritizing them for review.
When internal auditors have identified the relevant risks for an activity under review in past engagements, only a review and update of the previous engagement risk assessment is required (T/F)
True (Standard 13.2 Engagement Risk Assessment)
It is a narrative summary reflecting the internal audit activity’s understanding of the processes, aligned with organizational objectives and known risks.
Engagement Background
It is a visual representation that illustrates the key steps, inputs, outputs, and responsible parties within the process, supporting clarity in subsequent planning stages.
Flowchart/Process Map
Steps on Risk ASsessment
Identify relevant risks based on strategic objectives, operations, regulatory compliance, and known vulnerabilities.
Establish criteria for risk assessment, such as likelihood and impact.
Prioritize high risks that may significantly affect the process or prevent the achievement of objectives.
It enables auditors to systematically identify and assess risks that may impact the achievement of objectives, utilization of resources, or operational effectiveness within the area or process under review.
Creating or reviewing this is widely recognized best practice in internal auditing.
It also provides a structured overview of key risks and their corresponding mitigating controls and can also help auditors identify the objectives of subprocesses that fall within the audit scope.
Risk and Control Matrix
The key functions of Risk and Control Matrix (RCM) are:
A tool to identify, assess, prioritize, and document risks and their corresponding controls.
A repository capturing risk exposures that threaten an organization’s processes and the measures in place to address them.
A snapshot of the organization’s current posture, reflecting how well key risks are mitigated by formalized control activities.
It must articulate the purpose of the engagement and describe the specific goals to be achieved, including those mandated by laws and/or regulations.
Engagement Objectives
It must establish the engagement’s focus and boundaries by specifying the activities, locations, processes, systems, components, time period to be covered in the engagement, and other elements to be reviewed, and be sufficient to achieve the engagement objectives.
Scope
It must be discussed with management with identified, with a goal of achieving resolution. It is an assurance engagement condition, such as resource constraints or restrictions on access to personnel, facilities, data, and information, that prevent internal auditors from performing the work as expected in the audit work program.
Scope limitations
In alignment with GIAS 2024, advisory engagements are required to assess the governance, risk management, and control processes (GRC) related to the engagement area (T/F)
False (assurance)
The assessment of GRC must address two key aspects:
Design Adequacy
Operating Effectiveness
It determines whether controls, processes, and governance structures are appropriately designed to mitigate identified risks and support the achievement of objectives. This assessment asks: If the control is executed as intended, will if effectively mitigate the risk?
Design Adequacy
A well-designed controls should directly address the relevant risk, be clearly documented, and align with internal policies, procedures, and external compliance requirements. (T/F)
True
It evaluates whether controls are functioning consistently and as intended over time. This involves verifying the execution, frequency, and consistency of control activities and ensuring responsible personnel are performing them correctly. The key question is: Is the control actually working in practice to reduce the risk?
Operating Effectiveness
Internal auditors must identify the most relevant criteria to be used to evaluate the aspects of the activity under review defined in the engagement objectives and scope (T/F)
True (Standard 13.4 Engagement Criteria)
For assurance services, the identification of evaluation criteria may not be necessary, depending on the agreement with relevant stakeholders. (T/F)
False (advisory)
Internal auditors must assess the extent to which the board and senior management have established adequate criteria to determine whether the activity under review has accomplished its objectives and goals (T/F)
True
If criteria are adequate, internal auditors must use them for evaluation. If the criteria are inadequate, internal auditors must identify appropriate criteria through ___________
discussion with the board and/or senior management
It refers to the standards or benchmarks used by internal auditors to evaluate whether a process, activity, or control is operating as intended.
They define the desired state against which the actual condition is assessed, serving as the foundation for identifying findings, exceptions, or observations.
Criteria
When a gap exists between the expected (criteria) and the observed (condition), it results in an ______________ that may point to noncompliance, control deficiencies, or improvement opportunities.
audit finding
The evaluation of internal control is a critical aspect of engagement work, helping determine whether the organization is effectively managing _________.
key risks
Key risk may relate to:
The assignment of authority and responsibility
Compliance with laws, policies, and procedures
The accuracy and reliability of information
The efficient and effective use of organizational resources
The safeguarding of assets
Under Standard 13.5 Engagement Resources: When planning an engagement, internal auditors must identify the types and quantity of resources necessary to achieve the engagement objectives.
Internal auditors must consider:
The nature and complexity of the engagement.
The time frame within which the engagement is to be completed.
Whether the available financial, human, and technological resources are appropriate and sufficient to achieve the engagement objectives.
If the available resources are appropriate or insufficient, how can an internal auditor obtain the resources?
Internal auditors must discuss the concerns with the chief audit executive
Internal auditors must develop and document an engagement ________ to achieve the engagement objectives.
work program (Standard 13.6)
The engagement work program must be based on the information obtained during _________, including, when applicable, the results of the _______________.
engagement planning, engagement risk assessment
The engagement work program must identify:
Criteria to be used to evaluate each objective.
Tasks to achieve the engagement objectives.
Methodologies, including the analytical procedures to be used, and tools to perform the tasks.
Internal auditors assigned to perform each task.
They must review and approve the engagement work program before it is implemented and promptly when any subsequent changes are made
The chief audit executive
To ensure a focused and effective engagement, internal auditors must determine the ___________ necessary to assess risks in the area under review and evaluate the ___________
specific audit procedures, design adequacy and operating effectiveness of existing controls
To avoid scope creep, audit procedures should be __________
clearly defined, directly aligned with the engagement objectives, and documented in a structured work program
When developing a work program, internal auditors consider the _____,______, ______ of the audit tests needed to fulfill the engagement objectives.
nature, timing, and extent
Each procedure in the work program must be designed to test a specific control related to an identified risk (T/F)
True
Generally, a work program formats include:
The name of the internal auditor performing the task
The date of completion
Evidence of supervisory review and approval
The sampling methodology used, if applicable
Internal auditors use a variety of techniques to gather audit evidence, including:
RIRI OA
Reperformance
Inspection
Recalculation
Inquiry
Observation
Analytical procedures
Common audit sampling technique where each item has an equal chance of selection. It is used for general testing.
Random Sampling
Common audit sampling technique where it focuses on dollar amounts. It is useful for detecting over/understatements in account balances.
Monetary Unit Sampling
Common audit sampling technique where population is grouped by characteristics (e.g., value or type). Sample are drawn from each stratum.
Stratified Sampling
Common audit sampling technique where it tests whether a specific characteristics or attribute is present in the population (e.g., authorization present or not).
Attribute Sampling
Common audit sampling technique where it quantifies the monetary impact of a population’s characteristics.
Variable Sampling
Common audit sampling technique where sampling is based on auditor expertise and knowledge of risk areas. It is ideal for targeted testing.
Judgmental Sampling
Common audit sampling technique where it is used when a single instance of error or fraud would require further investigation.
Discovery Sampling
It is a formal communication between the internal audit team and the engagement client prior to the start of fieldwork. This meeting is used to discuss the engagement objectives, scope, and key areas of focus, as well as to align on the timeline, logistics, and roles and responsibilities during the audit. It helps establish mutual understanding, foster cooperation, and sets clear expectations for the engagement process.
The entrance meeting or pre-audit conference
Principle 11:
Communicate Effectively
Standards: BECEC
Standard 11.1:
Building Relationships and Communicating with Stakeholders
Standard 11.2:
Effective Communication
Standard 11.3:
Communication Results
Standard 11.4:
Errors and Omissions
Standard 11.5:
Communicating the Acceptance of Risks
The chief audit executive must guides the internal audit function to communicate effectively with its stakeholder (T/F)
True (Principle 11: Communicate Effectively)
As the requirements of Standards 11.1: Building Relationships and Communicating with Stakeholders. The CAE must develop an approach for internal audit function to build relationship and trust with key stakeholders, including the board, senior management, operational management, regulators, and internal and external assurance providers and other consultants.
The CAE must promote formal and informal communication between the internal audit function and stakeholders, contributing to mutual understanding of:
Organizational interests and concerns.
Approaches for identifying and managing risks and providing assurance.
Roles and responsibilities of relevant parties and opportunities for collaboration.
Relevant regulatory requirements.
Significant organizational processes, including financial reporting.
According to Standard 11.2: Effective communication, it defines communication as free from errors, faithful to facts, and supported by reliable information.
Accurate
According to Standard 11.2: Effective communication, it defines communication as impartial and unbiased, ensuring finding and recommendations are based on fair assessments.
Objective
According to Standard 11.2: Effective communication, it defines communication as logical, easily understood, and free of excessive technical jargon. Use consistent terminology, define unique terms, and provide significant supporting details.
Clear
According to Standard 11.2: Effective communication, it defines communication as succinct, avoiding unnecessary details, redundancies, or irrelevant information.
Concise
According to Standard 11.2: Effective communication, it defines communication as helpful and improvement-oriented, with a cooperative tone to encourage collaboration and actionable insights.
Constructive
According to Standard 11.2: Effective communication, it defines communication as it provides sufficient, reliable, and relevant information to support conclusions, tailored to the needs of different stakeholders.
Complete
According to Standard 11.2: Effective communication, it defines communication that it must de delivered promptly to enable corrective actions, with timing adapted to the engagement’s nature and significance.
Timely