1/14
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
According to this Standard, the CAE must create an internal audit plan that supports the achievement of the organization’s objectives. The CAE must base the internal audit plan on a documented assessment of the organization’s strategies, objectives, and risks. This assessment must be informed by input from the board and senior management as week as the CAE’s understanding of the organization’s governance, risk management, and control processes.
Standard 9.4: Internal Audit Plan
The assessment of the Internal Audit Plan must be performed at least _________.
annually
The internal audit plan must:
Consider the internal audit mandate and the full range of agreed-to internal audit services.
Specify internal audit services that support the evaluation and improvement of the organization’s governance, risk management, and control processes.
Consider coverage of information technology governance, fraud risk, the effectiveness of the organization’s compliance and ethics programs, and other high-risk areas.
Identify the necessary human, financial, and technological resources necessary to complete the plan.
Be dynamic and updated timely in response to changes in the organization’s business, risk operations, programs, systems, controls, and organizational culture.
The chief audit executive must review and revise the internal audit plan as necessary and communicate timely to the board and senior management:
The impact of any resource limitations on internal audit coverage
The rationale for not including an assurance engagement in a high-risk area or activity in the plan.
Conflicting demands for services between major stakeholders, such as high-priority requests based on emerging risks and request to replace planned assurance engagements with advisory engagements.
Limitations on scope or restrictions on access to information.
It is most useful when it is based on an understanding of the organization’s objectives and strategic initiatives and aligned with the organization’s structure or risk framework.
It is the is the comprehensive inventory of all auditable entities, processes, systems, departments, and third-party relationships within an organization.
Audit Universe
Emerging issues and technologies that may be considered by the CAE when creating the Audit Universe and the Internal Audit Plan:
Fraud Risks
Environmental, Social, and Governance Risks
Culture
Third-Party Risks
IT Risks
It is a network of interconnected devices that collect and exchange data over the internet (e.g., Smart Home Devices)
Internet of Things
It is the simulation of human intelligence by machines to perform tasks like learning, reasoning, and problem-solving (e.g., Chatbots)
Artificial Intelligence
It is a secure, decentralized digital ledger that records transactions across multiple computers (e.g., Cryptocurrency Transactions)
Blockchain
These are the digital representations of value, like cryptocurrencies, that exist electronically and enable online transactions (e.g., Bitcoin, NFTs)
Digital Currency and Assets
It is the software technology that automates repetitive, rule-based tasks to improve efficiency and accuracy (e.g., Automated Data Entry)
Robotic Process Automation
It is a branch of AI that enable systems to learn from data and improve over time without being explicitly programmed (e.g., Image Recognition)
Machine Learning
According to this Standard, the CAE must coordinate with internal and external providers of assurance services and consider relying upon their work. Coordination of services minimizes duplication of efforts, highlights gaps in coverage of key risks, and enhances the overall value added by providers
Standard 9.4: Coordination and Reliance
When the internal audit function relies on the work of other assurance service providers, the CAE is still responsible for the conclusions reached by the internal audit function (T/F)
True
To determine whether the internal audit function may rely on the work of another provider, the CAE or a methodology should consider the provider’s:
Potential or actual conflicts of interest and whether disclosures were made.
Reporting relationships and the potential impacts of this arrangement.
Relevance and validity of professional experience, qualifications, and certifications.
Methodology and the due professional care applied in planning, supervising, documenting, and reviewing the work.
Findings and conclusions and whether they are reasonable, based on sufficient, reliable, and relevant evidence.