ACCT 422 CH 1, 2 IA FOUNDATIONS AND ETHICS AND PROFESSIONALISM

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/69

flashcard set

Earn XP

Description and Tags

Vocabulary practice flashcards covering Topic 1: Foundation of Internal Audit Function and Topic 2: Ethics and Professionalism.

Last updated 3:59 AM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

70 Terms

1
New cards

Purpose Statement of Internal Auditing

Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight.

2
New cards

Governance

The combination of processes and structures implemented by the board to inform, direct, manage, and monitor the activities of the organization toward the achievement of its objectives.

3
New cards

Risk Management

A process to identify, assess, manage, and control potential events or situations to provide reasonable assurance regarding the achievement of the organization's objectives.

4
New cards

Control

Any action taken to manage risk and increase the likelihood of achieving established objectives.

5
New cards

Assurance Service

An objective examination of evidence for the purpose of providing an independent assessment on governance, risk management, and control processes.

6
New cards

Board Responsibility in GRC

Governance is mainly the responsibility of the Board.

7
New cards

Management Responsibility in GRC

Risk management and control processes are mainly the responsibility of management.

8
New cards
<p>Core Value of Internal Auditing Services</p>

Core Value of Internal Auditing Services

The core value delivered through services provided, which consist of assurance and advisory (consulting) services.

9
New cards

Objectives of Assurance Services

To strengthen the organization's ability to create and maintain value, and help ensure efficient operations, compliance with laws, effective risk management, and proper asset safeguarding.

10
New cards

Operational Audit

An assurance service that evaluates the efficiency and effectiveness of an organization's operational processes.

11
New cards

Financial Audit

An assurance service focused on reviewing financial statements and financial reporting processes.

12
New cards

Compliance Audit

An assurance service evaluating adherence to specific laws, regulations, policies, and procedures.

13
New cards

Performance Audit

An assurance service evaluating program or operational performance against established goals and metrics.

14
New cards

System Security (IT) Audit

An assurance service focused on evaluating information technology infrastructure, system security, and control environments.

15
New cards

Due Diligence Audit

An assurance service involving detailed investigation and evaluation prior to entering into a business transaction or contract.

16
New cards

Advisory Services

Consulting services that add value and improve governance, risk management, and control (GRC), with nature and scope subject to agreement with the client.

17
New cards

Counsel

An advisory service involving the provision of professional guidance or advice on specific organizational issues.

18
New cards

Facilitation

An advisory service where the internal auditor assists and guides client workshops or processes without taking operational ownership.

19
New cards

Forensic Services

Specialized advisory services involving the investigation, detection, or prevention of fraud and financial misrepresentation.

20
New cards

Internal Audit Mandate

The authority, role, and responsibilities of the internal audit function established, approved, and supported by the Board and documented in the Charter.

21
New cards

Internal Audit Charter

A formal document developed and maintained by the CAE that specifies the internal audit purpose, mandate, authority, role, responsibilities, and reporting relationships.

22
New cards

Dual-Reporting Relationship

The reporting structure where the internal audit function reports functionally to the Board and administratively to Senior Management.

23
New cards

Functional Reporting Line

Direct reporting line to the Board that safeguards independence and ensures direct access for internal audit.

24
New cards

Administrative Reporting Line

Reporting line to Senior Management covering day-to-day administrative operations and resource allocation.

25
New cards

Mandate Authority

The aspect of the mandate defining internal audit's organizational position, direct reporting to the Board, and unrestricted access to the board and all organizational activities.

26
New cards

Mandate Scope

The aspect of the mandate defining activities, assets, restrictions, nature of services (assurance/advisory), and limitations.

27
New cards

Internal Audit Deliverables

The services/outputs provided by internal audit, consisting of observations (findings), conclusions and opinions, and recommendations (action plans).

28
New cards

Internal Audit Observations

Findings identified by internal audit during an engagement regarding governance, risk management, or control processes.

29
New cards

Internal Audit Recommendations

Action plans proposed by internal auditors to remediate findings and strengthen GRC processes.

30
New cards

CAE Charter Responsibilities

Developing and maintaining the charter, and regularly assessing whether organizational changes require charter discussions with the board and senior management.

31
New cards

Board (Audit Committee) Roles in Internal Audit

Approving the hiring and dismissal of the CAE, communicating internal audit authority/duties, and reviewing and approving the internal audit charter.

32
New cards

Senior Management Roles in Internal Audit Charter

Communicating expectations to be evaluated for inclusion in the charter, and working with the Board to decide the extent and types of internal audit services.

33
New cards

Sarbanes-Oxley Act of 2002 (SOX)

Legislation that elevated internal auditing by making it central to accurate financial reporting and internal controls over financial reporting (ICFR).

34
New cards

Internal Controls over Financial Reporting (ICFR)

Controls designed to provide reasonable assurance regarding financial reporting reliability and financial statement preparation under SOX.

35
New cards

SOX Section 302

Corporate Responsibility for Financial Reports, mandating that principal executive officers (CEO) and principal financial officers (CFO) personally certify quarterly and annual SEC reports.

36
New cards

Disclosure Controls and Procedures (DC&P)

Controls encompassing both financial and non-financial disclosure processes that management must establish, maintain, and evaluate under SOX Section 302.

37
New cards

DC&P Evaluation Timeline

Management must evaluate the effectiveness of disclosure controls and procedures within 90 days prior to filing under SOX Section 302.

38
New cards

SOX Section 302 Required Disclosures

Mandated disclosure to external auditors and the audit committee of significant deficiencies, material weaknesses, fraud involving key employees, and significant control changes.

39
New cards

SOX Section 404(a)

Requirement that management annually assess and report on the effectiveness of the company's internal control over financial reporting (ICFR) in its annual report.

40
New cards

SOX Section 404(b)

Requirement that an independent external auditor attest to and report on ICFR effectiveness for accelerated filers (larger public companies).

41
New cards

Internal Audit Role in SOX Compliance

Assisting management in documenting, testing, and evaluating internal controls, performing independent tests, and recommending improvements without explicit legislative mandate.

42
New cards

Independence

Freedom from conditions that impair the internal audit function's ability to perform responsibilities without bias.

43
New cards

Annual Independence Confirmation

The requirement for the CAE to confirm the organizational independence of the internal audit function to the board at least annually.

44
New cards

12-Month Rule for Temporary Non-Audit Tasks

If the CAE temporarily assumes non-audit tasks, an independent 3rd party must oversee those areas during that period and for the following 12 months.

45
New cards

Impairments to Independence

Conditions including lack of direct board communication, scope restrictions, restricted access, pressure to alter findings, budget cuts, or non-audit roles.

46
New cards
<p>IIA's Three Lines Model</p>

IIA's Three Lines Model

A governance framework outlining roles for governing bodies, operational management, risk/compliance functions, and internal audit.

47
New cards

Governing Body (Three Lines Model)

The organizational oversight role accountable to stakeholders, characterized by integrity, leadership, and transparency.

48
New cards

First Line Roles (Three Lines Model)

Operational management functions responsible for providing products/services to clients and managing day-to-day risk ("Self-Check").

49
New cards

Second Line Roles (Three Lines Model)

Management functions providing expertise, support, monitoring, and challenge on risk-related matters ("Check others").

50
New cards

Third Line Roles (Three Lines Model)

Internal audit function providing independent, objective assurance and advice on all matters related to goal achievement ("Independent Assessment").

51
New cards

External Assurance Providers (Three Lines Model)

Independent external entities offering assurance to fulfill regulatory mandates or stakeholder requirements.

52
New cards

Integrity

Adherence to ethical principles including honesty and professional courage to act based on relevant facts ("doing the right thing when no one is looking").

53
New cards

Professional Courage

Communicating truthfully and taking appropriate action, even when situations are difficult.

54
New cards

Material Facts Disclosure Requirement

The requirement for internal auditors to disclose all material facts that could affect the organization's ability to make well-informed decisions.

55
New cards

Legal Violation Reporting Duty

The obligation to refuse intentional participation in unlawful actions and report identified legal/regulatory violations to authorities able to act.

56
New cards

Objectivity

An unbiased mental attitude that allows internal auditors to make professional judgments, fulfill responsibilities, and achieve purpose without compromise.

57
New cards

Self-Review Bias

A bias caused by a lack of critical perspective on one's own work.

58
New cards

Familiarity Bias

A bias resulting from making assumptions based on past experience that compromise professional skepticism.

59
New cards

Prejudice or Unconscious Bias

Misinterpretation of information based on predisposed ideas that cause inaccurate judgments.

60
New cards

12-Month Rule for Assurance Objectivity

Internal auditors must not provide assurance services for an activity for which they were responsible in the previous 12 months or will be in the next 12 months.

61
New cards

CAE Conflict Supervision Safeguard

Assurance work related to matters for which the CAE is responsible must be supervised by someone independent of the internal audit team.

62
New cards

Conflict of Interest

A situation, activity, or relationship that may influence, or appear to influence, an internal auditor's ability to make objective professional judgments.

63
New cards

Undue Personal Gain

An improper personal benefit that creates an actual or apparent conflict of interest for an internal auditor.

64
New cards

Competency

The requirement that internal auditors possess and acquire the knowledge, skills, and abilities to effectively carry out their duties.

65
New cards

Continuous Skill Improvement

The requirement for internal auditors to keep their skills up to date and continuously improve competencies to meet job responsibilities.

66
New cards

Due Professional Care

Taking great care when planning and conducting internal audit activities by following Standards, considering specific context, and employing professional skepticism.

67
New cards

Professional Skepticism

A curious mindset where auditors do not take anything for granted, critically question claims, and form objective judgments based on facts and logic.

68
New cards

Confidentiality

The duty of internal auditors to protect information, using it solely for professional tasks and preventing unauthorized access or release.

69
New cards

Information Security Compliance Duty

The obligation for internal auditors to know and follow laws, rules, policies, and procedures related to confidentiality, privacy, and information security.

70
New cards

Authorized Sharing of Information

Internal auditors must not share confidential information unless required to do so by law or through professional obligations.