1/69
Vocabulary practice flashcards covering Topic 1: Foundation of Internal Audit Function and Topic 2: Ethics and Professionalism.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Purpose Statement of Internal Auditing
Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight.
Governance
The combination of processes and structures implemented by the board to inform, direct, manage, and monitor the activities of the organization toward the achievement of its objectives.
Risk Management
A process to identify, assess, manage, and control potential events or situations to provide reasonable assurance regarding the achievement of the organization's objectives.
Control
Any action taken to manage risk and increase the likelihood of achieving established objectives.
Assurance Service
An objective examination of evidence for the purpose of providing an independent assessment on governance, risk management, and control processes.
Board Responsibility in GRC
Governance is mainly the responsibility of the Board.
Management Responsibility in GRC
Risk management and control processes are mainly the responsibility of management.

Core Value of Internal Auditing Services
The core value delivered through services provided, which consist of assurance and advisory (consulting) services.
Objectives of Assurance Services
To strengthen the organization's ability to create and maintain value, and help ensure efficient operations, compliance with laws, effective risk management, and proper asset safeguarding.
Operational Audit
An assurance service that evaluates the efficiency and effectiveness of an organization's operational processes.
Financial Audit
An assurance service focused on reviewing financial statements and financial reporting processes.
Compliance Audit
An assurance service evaluating adherence to specific laws, regulations, policies, and procedures.
Performance Audit
An assurance service evaluating program or operational performance against established goals and metrics.
System Security (IT) Audit
An assurance service focused on evaluating information technology infrastructure, system security, and control environments.
Due Diligence Audit
An assurance service involving detailed investigation and evaluation prior to entering into a business transaction or contract.
Advisory Services
Consulting services that add value and improve governance, risk management, and control (GRC), with nature and scope subject to agreement with the client.
Counsel
An advisory service involving the provision of professional guidance or advice on specific organizational issues.
Facilitation
An advisory service where the internal auditor assists and guides client workshops or processes without taking operational ownership.
Forensic Services
Specialized advisory services involving the investigation, detection, or prevention of fraud and financial misrepresentation.
Internal Audit Mandate
The authority, role, and responsibilities of the internal audit function established, approved, and supported by the Board and documented in the Charter.
Internal Audit Charter
A formal document developed and maintained by the CAE that specifies the internal audit purpose, mandate, authority, role, responsibilities, and reporting relationships.
Dual-Reporting Relationship
The reporting structure where the internal audit function reports functionally to the Board and administratively to Senior Management.
Functional Reporting Line
Direct reporting line to the Board that safeguards independence and ensures direct access for internal audit.
Administrative Reporting Line
Reporting line to Senior Management covering day-to-day administrative operations and resource allocation.
Mandate Authority
The aspect of the mandate defining internal audit's organizational position, direct reporting to the Board, and unrestricted access to the board and all organizational activities.
Mandate Scope
The aspect of the mandate defining activities, assets, restrictions, nature of services (assurance/advisory), and limitations.
Internal Audit Deliverables
The services/outputs provided by internal audit, consisting of observations (findings), conclusions and opinions, and recommendations (action plans).
Internal Audit Observations
Findings identified by internal audit during an engagement regarding governance, risk management, or control processes.
Internal Audit Recommendations
Action plans proposed by internal auditors to remediate findings and strengthen GRC processes.
CAE Charter Responsibilities
Developing and maintaining the charter, and regularly assessing whether organizational changes require charter discussions with the board and senior management.
Board (Audit Committee) Roles in Internal Audit
Approving the hiring and dismissal of the CAE, communicating internal audit authority/duties, and reviewing and approving the internal audit charter.
Senior Management Roles in Internal Audit Charter
Communicating expectations to be evaluated for inclusion in the charter, and working with the Board to decide the extent and types of internal audit services.
Sarbanes-Oxley Act of 2002 (SOX)
Legislation that elevated internal auditing by making it central to accurate financial reporting and internal controls over financial reporting (ICFR).
Internal Controls over Financial Reporting (ICFR)
Controls designed to provide reasonable assurance regarding financial reporting reliability and financial statement preparation under SOX.
SOX Section 302
Corporate Responsibility for Financial Reports, mandating that principal executive officers (CEO) and principal financial officers (CFO) personally certify quarterly and annual SEC reports.
Disclosure Controls and Procedures (DC&P)
Controls encompassing both financial and non-financial disclosure processes that management must establish, maintain, and evaluate under SOX Section 302.
DC&P Evaluation Timeline
Management must evaluate the effectiveness of disclosure controls and procedures within 90 days prior to filing under SOX Section 302.
SOX Section 302 Required Disclosures
Mandated disclosure to external auditors and the audit committee of significant deficiencies, material weaknesses, fraud involving key employees, and significant control changes.
SOX Section 404(a)
Requirement that management annually assess and report on the effectiveness of the company's internal control over financial reporting (ICFR) in its annual report.
SOX Section 404(b)
Requirement that an independent external auditor attest to and report on ICFR effectiveness for accelerated filers (larger public companies).
Internal Audit Role in SOX Compliance
Assisting management in documenting, testing, and evaluating internal controls, performing independent tests, and recommending improvements without explicit legislative mandate.
Independence
Freedom from conditions that impair the internal audit function's ability to perform responsibilities without bias.
Annual Independence Confirmation
The requirement for the CAE to confirm the organizational independence of the internal audit function to the board at least annually.
12-Month Rule for Temporary Non-Audit Tasks
If the CAE temporarily assumes non-audit tasks, an independent 3rd party must oversee those areas during that period and for the following 12 months.
Impairments to Independence
Conditions including lack of direct board communication, scope restrictions, restricted access, pressure to alter findings, budget cuts, or non-audit roles.

IIA's Three Lines Model
A governance framework outlining roles for governing bodies, operational management, risk/compliance functions, and internal audit.
Governing Body (Three Lines Model)
The organizational oversight role accountable to stakeholders, characterized by integrity, leadership, and transparency.
First Line Roles (Three Lines Model)
Operational management functions responsible for providing products/services to clients and managing day-to-day risk ("Self-Check").
Second Line Roles (Three Lines Model)
Management functions providing expertise, support, monitoring, and challenge on risk-related matters ("Check others").
Third Line Roles (Three Lines Model)
Internal audit function providing independent, objective assurance and advice on all matters related to goal achievement ("Independent Assessment").
External Assurance Providers (Three Lines Model)
Independent external entities offering assurance to fulfill regulatory mandates or stakeholder requirements.
Integrity
Adherence to ethical principles including honesty and professional courage to act based on relevant facts ("doing the right thing when no one is looking").
Professional Courage
Communicating truthfully and taking appropriate action, even when situations are difficult.
Material Facts Disclosure Requirement
The requirement for internal auditors to disclose all material facts that could affect the organization's ability to make well-informed decisions.
Legal Violation Reporting Duty
The obligation to refuse intentional participation in unlawful actions and report identified legal/regulatory violations to authorities able to act.
Objectivity
An unbiased mental attitude that allows internal auditors to make professional judgments, fulfill responsibilities, and achieve purpose without compromise.
Self-Review Bias
A bias caused by a lack of critical perspective on one's own work.
Familiarity Bias
A bias resulting from making assumptions based on past experience that compromise professional skepticism.
Prejudice or Unconscious Bias
Misinterpretation of information based on predisposed ideas that cause inaccurate judgments.
12-Month Rule for Assurance Objectivity
Internal auditors must not provide assurance services for an activity for which they were responsible in the previous 12 months or will be in the next 12 months.
CAE Conflict Supervision Safeguard
Assurance work related to matters for which the CAE is responsible must be supervised by someone independent of the internal audit team.
Conflict of Interest
A situation, activity, or relationship that may influence, or appear to influence, an internal auditor's ability to make objective professional judgments.
Undue Personal Gain
An improper personal benefit that creates an actual or apparent conflict of interest for an internal auditor.
Competency
The requirement that internal auditors possess and acquire the knowledge, skills, and abilities to effectively carry out their duties.
Continuous Skill Improvement
The requirement for internal auditors to keep their skills up to date and continuously improve competencies to meet job responsibilities.
Due Professional Care
Taking great care when planning and conducting internal audit activities by following Standards, considering specific context, and employing professional skepticism.
Professional Skepticism
A curious mindset where auditors do not take anything for granted, critically question claims, and form objective judgments based on facts and logic.
Confidentiality
The duty of internal auditors to protect information, using it solely for professional tasks and preventing unauthorized access or release.
Information Security Compliance Duty
The obligation for internal auditors to know and follow laws, rules, policies, and procedures related to confidentiality, privacy, and information security.
Authorized Sharing of Information
Internal auditors must not share confidential information unless required to do so by law or through professional obligations.