Section B: Internal Audit Plan

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/14

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:35 AM on 8/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

15 Terms

1
New cards

According to this Standard, the CAE must create an internal audit plan that supports the achievement of the organization’s objectives. The CAE must base the internal audit plan on a documented assessment of the organization’s strategies, objectives, and risks. This assessment must be informed by input from the board and senior management as week as the CAE’s understanding of the organization’s governance, risk management, and control processes.

Standard 9.4: Internal Audit Plan

2
New cards

The assessment of the Internal Audit Plan must be performed at least _________.

annually

3
New cards

The internal audit plan must:

  • Consider the internal audit mandate and the full range of agreed-to internal audit services.

  • Specify internal audit services that support the evaluation and improvement of the organization’s governance, risk management, and control processes.

  • Consider coverage of information technology governance, fraud risk, the effectiveness of the organization’s compliance and ethics programs, and other high-risk areas.

  • Identify the necessary human, financial, and technological resources necessary to complete the plan.

  • Be dynamic and updated timely in response to changes in the organization’s business, risk operations, programs, systems, controls, and organizational culture.


4
New cards

The chief audit executive must review and revise the internal audit plan as necessary and communicate timely to the board and senior management:

  • The impact of any resource limitations on internal audit coverage

  • The rationale for not including an assurance engagement in a high-risk area or activity in the plan.

  • Conflicting demands for services between major stakeholders, such as high-priority requests based on emerging risks and request to replace planned assurance engagements with advisory engagements.

  • Limitations on scope or restrictions on access to information.


5
New cards

It is most useful when it is based on an understanding of the organization’s objectives and strategic initiatives and aligned with the organization’s structure or risk framework.

It is the is the comprehensive inventory of all auditable entities, processes, systems, departments, and third-party relationships within an organization.

Audit Universe

6
New cards

Emerging issues and technologies that may be considered by the CAE when creating the Audit Universe and the Internal Audit Plan:

  • Fraud Risks

  • Environmental, Social, and Governance Risks

  • Culture

  • Third-Party Risks

  • IT Risks


7
New cards

It is a network of interconnected devices that collect and exchange data over the internet (e.g., Smart Home Devices)

Internet of Things

8
New cards

It is the simulation of human intelligence by machines to perform tasks like learning, reasoning, and problem-solving (e.g., Chatbots)

Artificial Intelligence

9
New cards

It is a secure, decentralized digital ledger that records transactions across multiple computers (e.g., Cryptocurrency Transactions)

Blockchain

10
New cards

These are the digital representations of value, like cryptocurrencies, that exist electronically and enable online transactions (e.g., Bitcoin, NFTs)

Digital Currency and Assets

11
New cards

It is the software technology that automates repetitive, rule-based tasks to improve efficiency and accuracy (e.g., Automated Data Entry)

Robotic Process Automation

12
New cards

It is a branch of AI that enable systems to learn from data and improve over time without being explicitly programmed (e.g., Image Recognition)

Machine Learning

13
New cards

According to this Standard, the CAE must coordinate with internal and external providers of assurance services and consider relying upon their work. Coordination of services minimizes duplication of efforts, highlights gaps in coverage of key risks, and enhances the overall value added by providers

Standard 9.4: Coordination and Reliance

14
New cards

When the internal audit function relies on the work of other assurance service providers, the CAE is still responsible for the conclusions reached by the internal audit function (T/F)

True

15
New cards

To determine whether the internal audit function may rely on the work of another provider, the CAE or a methodology should consider the provider’s:

  • Potential or actual conflicts of interest and whether disclosures were made.

  • Reporting relationships and the potential impacts of this arrangement.

  • Relevance and validity of professional experience, qualifications, and certifications.

  • Methodology and the due professional care applied in planning, supervising, documenting, and reviewing the work.

  • Findings and conclusions and whether they are reasonable, based on sufficient, reliable, and relevant evidence.