Practice of Internal Auditing - Notes

License Agreement

  • The Institute of Internal Auditors (IIA) is the exclusive copyright owner of the materials.

  • User has the right to use the Materials solely for his/her own educational use, provided that the required fee has been paid.

  • User has no right to print or make any copies, in any media, of the materials, or to sell, sublicense, loan, or otherwise convey or distribute these materials or any copies thereof in any media.

IIA's CIA Challenge Exam Study Guide

  • The IIA's CIA Challenge Exam Study Guide is based on select portions of the Certified Internal Auditor (CIA) syllabus developed by The IIA.

  • Program developers do not have access to the exam questions.

  • Reading the text does not guarantee a passing score on the CIA exam.

  • Every effort has been made to ensure that all information is current and correct.

  • Materials are not intended to offer legal or professional services or advice.

  • This material is consistent with the revised Standards of the International Professional Practices Framework (IPPF) introduced in July 2015, effective in 2017.

  • It is unlawful to copy all or any portion of these materials.

Part 2: Practice of Internal Auditing

  • Focuses on the auditor’s abilities related to the Performance Standards (series 2000, 2200, 2300, 2400, 2500, and 2600).

  • Performance Standards describe the nature of internal auditing and provide quality criteria against which the performance of internal auditing services can be measured.

  • Standard 2100 (“Nature of Work”) is addressed in Part 1.

  • Part 2 is made up of four sections:

    • Section A: Managing the Internal Audit Activity.

    • Section B: Planning the Engagement.

    • Section C: Performing the Engagement.

    • Section D: Communicating Engagement Results and Monitoring Progress.

Section A: Managing the Internal Audit Activity

  • The chief audit executive (CAE) must effectively manage the internal audit activity to ensure that it adds value to the organization (Standard 2000).

Policies and Procedures
  • Performance Standard 2040, “Policies and Procedures”

  • The chief audit executive must establish policies and procedures to guide the internal audit activity.

  • The form and content of policies and procedures are dependent upon the size and structure of the internal audit activity and the complexity of its work:

    • Large, mature internal audit activities may have a formal internal audit operations manual that includes policies and procedures.

    • Smaller or less mature activities may not have a formal manual and instead may publish policies and procedures as separate documents or as part of an audit management software program.

  • The internal audit manual may include information on the quality assurance and improvement program and other administrative matters.

  • Policies and procedures are one type of tool the CAE has to ensure that internal audit follows a systematic and disciplined approach.

  • Policies and procedures should be reviewed periodically, and changes may be communicated:

    • In writing.

    • During internal audit staff meetings.

    • Through training.

  • When reviewing policies and procedures, the CAE should also consider whether existing policies and procedures, including the internal audit charter, accurately reflect the Core Principles, the Code of Ethics, and the Standards.

  • Documentation of policies and procedures and evidence that they have been clearly communicated to internal audit personnel may be used to demonstrate conformance with Standard 2040.

Policies Examples
  • The overall purpose and responsibilities of the internal audit activity.

  • Adherence to the mandatory guidance of the International Professional Practices Framework (IPPF).

  • Independence and objectivity.

  • Ethics.

  • Protecting confidential information.

  • Record retention.

Procedures Examples
  • Preparing a risk-based audit plan.

  • Planning an audit and preparing the engagement work program.

  • Performing audit engagements.

  • Documenting audit engagements.

  • Communicating results/reporting.

  • Monitoring and follow-up process.

Internal Audit Administration

  • Performance Standard 2030, “Resource Management”

  • The chief audit executive must ensure that internal audit resources are appropriate, sufficient, and effectively deployed to achieve the approved plan.

  • The Implementation Guidance for Standard 2030 recommends that the CAE usually begin by gaining a deeper understanding of the resources available to the internal audit activity in the board-approved internal audit plan.

    • The number of internal audit staff.

    • The number of productive work hours available.

    • The internal audit activity’s collective knowledge, skills, and other competencies.

    • Approved budget and funds available for training, technology, or additional staffing.

  • As part of resource management, it is recommended that the CAE establish a program for selecting and developing the human resources for the internal audit activity. For the internally staffed portion of the audit group, this program should include:

    • Developing written job descriptions for each level of audit staff.

    • Selecting qualified and competent individuals.

    • Training and providing continuing educational opportunities for each auditor.

    • Appraising each internal auditor’s performance at least annually.

  • Developing expectations that sustain strengths, proactively address areas for improvement, and help ensure service excellence.

  • The CAE should define the skill set needs based on:

    • The organization’s risks.

    • The internal audit plan.

  • Value drivers of key stakeholders.

  • By paying attention to the organization’s schedule and the availability of auditable entities, internal audit may be able to schedule audits during less-busy times of the year for business units and the organization as a whole.

Potential Engagement Sources

  • Performance Standard 2010, “Planning” The chief audit executive must establish a risk-based plan to determine the priorities of the internal audit activity, consistent with the organization’s goals.

  • Implementation Standard 2010.A1 (Assurance Engagements) The internal audit activity’s plan of engagements must be based on a documented risk assessment, undertaken at least annually.

  • Implementation Standard 2010.C1 (Consulting Engagements) The chief audit executive should consider accepting proposed consulting engagements based on the engagement’s potential to improve management of risks, add value, and improve the organization’s operations. Accepted engagements must be included in the plan.

  • External risks may be related to competition, suppliers, or other industry issues. Relevant risk factors may include pending regulatory or legal changes and other political and economic factors.

  • Impacts may be felt through organizational reputation in addition to typical financial impacts.

  • Sources of Potential Engagements The Audit Universe

  • The audit universe also includes:

    • Any applicable areas (e.g., financial reporting or compliance) that have a pervasive, organization-wide impact and fall under the internal audit “umbrella” from an assurance coverage perspective.

    • Relevant regulatory mandates in highly regulated industries.

    • Independent compliance assessments of high-risk areas as mandated by government agency examiners, even in the absence of specific laws and regulations requiring them.

  • The Organization’s Strategic Plan

  • Organizations may use a strengths, weaknesses, opportunities, and threats analysis (SWOT analysis) to identify and classify elements that can help or hinder the organization or its strategic plans or activities.

  • The risk perspective of executives and key operational managers is important, as they are responsible for:

    • Establishing plans.

    • Defining risk tolerances.

    • Allocating resources to achieve the plans.

    • Monitoring the activities being done to achieve the plans.

  • While compliance with some regulations is voluntary, many regulations have the force of law.

Leveraging Risk Management Frameworks

  • The internal audit activity can work in close cooperation with the risk management function. However, not every organization will have a stand-alone risk management function, so the ability for internal audit to work with risk management will vary from organization to organization.

  • Using third-party frameworks such as COSO ERM.

  • Developing their own framework in-house.

  • An assurance map is a matrix comprising a visual representation of the organization’s risks and all the internal and external providers of assurance services that cover those risks.

  • Assurance mapping steps include:

    1. Identifying sources of risk information.

    2. Organizing risks into categories for consolidated viewing.

    3. Identifying assurance providers.

    4. Gathering information and documenting assurance activities by risk categories.

    5. Periodically reviewing, monitoring, and updating the assurance map.

Assurance Engagements

  • Assurance services are an objective examination of the evidence for the purpose of providing an independent assessment on governance, risk management, and control processes of the organization.

Types of Assurance Engagements:
Operational Engagements
  • Operational audits are focused on providing assurance on governance, risk management, and controls in regard to the effectiveness and efficiency of operations.

  • risks related to operational effectiveness include business processes that fail to work toward or are counterproductive to organizational objectives.

  • Risks related to inefficiency involve achieving goals in a manner that is more costly than the value that is added or a selected benchmark.

Security Engagements

*Security audits primarily focus on governance, risks, and controls related to:
* Safeguarding of assets.
* Reliability and integrity of information.

Financial and Financial Reporting Engagements
  • Assurance on internal controls may be needed because of rules over the quality of those controls.

  • Financial reporting objectives should form the basis for the majority of internal controls.

Compliance Engagements
  • Compliance audits evaluate the adequacy and effectiveness of controls that keep the organization in compliance with applicable laws and regulations, contracts, and the organization’s own policies.

  • Performance Engagements Performance audit engagements assess whether management has appropriate, necessary, and sufficient monitoring and controlling activities in place to assess how the following areas are performing in pursuit of meeting strategic, tactical, and/or operational objectives and goals:

    • The organization as a whole Specific units or functional areas Specific job roles or individuals.

    • Performance reporting functions can also be audited.

External Business Relationship Audits
  • Internal audits of EBRs range from an audit of a single contract or relationship to an audit of an overall process that includes some organizational processes and some EBR processes.

Privacy Engagements
  • Privacy can be simply defined as the protection of the collection, storage, processing, dissemination, and destruction of personal information, but it can mean many things to many people.

Quality Engagements
  • Auditors measure an organization’s current operations against a set of standards or other criteria.

  • This may take the form of conformance to a methodology such as total quality management (TQM).

Due Diligence Audits
  • A due diligence audit may refer to either an investigation of an entity/transaction or an audit of the due diligence investigation process itself.

  • Whenever due diligence is discussed, due care is also mentioned. Due care is the level of caution exercised when performing the due diligence audit and reporting the results. Basically, did the internal auditor do what any reasonable person would do?

  • Purpose of Consulting Engagements Implementation Standard 1000.C1 (Consulting Engagements) The nature of consulting services must be defined in the internal audit charter.

  • There are three main types of consulting engagements: advisory, training, and facilitative.

  • Internal audit can: Help keep the organization up-to-date on the latest trends, regulations, and controls.

  • Internal Control Training Providing audit clients with the opportunity to attend a well-structured workshop on internal controls or the COSO internal control framework may:

  • Benchmarking is especially appropriate in performance and quality audits.

  • Internal auditors may also be called on to provide subject matter knowledge in the areas of internal controls and control-related considerations.

  • Blended Engagements

  • Blended engagements incorporate elements of both consulting and assurance services.

Communication and Reliance
  • Performance Standard 2050, “Coordination and Reliance” The chief audit executive should share information, coordinate activities, and consider relying upon the work of other internal and external assurance and consulting service providers to ensure proper coverage and minimize duplication of efforts.

CAE Annual Audit Plan Communication
  • Performance Standard 2020, “Communication and Approval” The chief audit executive must communicate the internal audit activity’s plans and resource requirements, including significant interim changes, to senior management and the board for review and approval.

Significant GRC Issue Reporting
  • Performance Standard 2060, “Reporting to Senior Management and the Board” The chief audit executive must report periodically to senior management and the board on the internal audit activity’s purpose, authority, responsibility, and performance relative to its plan and on its conformance with the Code of Ethics and the Standards.

Risk and Control Process Effectiveness Reporting
  • The CAE is responsible for reporting on the overall effectiveness of the organization’s internal control and risk management processes to both senior management and to the board.

  • Reviewing the role of the board, senior management, operations, and internal auditing in the risk management process.

Internal Audit Key Performance Indicators
  • To maintain and track consistent and effective communication with senior management and the board, the CAE may consider using a checklist of all other reporting requirements referenced throughout the Standards:

    • Internal audit charter.

    • The 1300 series of standards covers the CAE’s responsibility for developing and maintaining a quality assurance and improvement program that includes internal and external assessments.

Section B: Planning the Engagement

  • moves from the general work of internal auditing to the specific processes used to plan engagements, which include establishing engagement objectives, developing an audit program that incorporates activities aimed at meeting the organization’s risk management objectives, and allocating staff and resources.

  • Performance Standard 2200, “Engagement Planning” Internal auditors must develop and document a plan for each engagement, including the engagement’s objectives, scope, timing, and resource allocations. The plan must consider the organization’s strategies, objectives, and risks relevant to the engagement.

Engagement Objectives, Criteria, and Scope

Performance Standard 2210, “Engagement Objectives” Objectives must be established for each engagement.

  • Implementation Standard 2210.A3 (Assurance Engagements) Adequate criteria are needed to evaluate governance, risk management, and controls.

  • Performance Standard 2220,“Engagement Scope” The established scope must be sufficient to achieve the objectives of the engagement.

Engagement Planning Considerations
  • Performance Standard 2201, “Planning Considerations” In planning the engagement, internal auditors must consider:

    • The strategies and objectives of the activity being reviewed and the means by which the activity controls its performance.

    • The significant risks to the activity’s objectives, resources, and operations and the means by which the potential impact of risk is kept to an acceptable level.

    • Auditors typically need to gather information on client policies. They seek to understand IT systems used as well as the sources, types, and reliability of information used in processes.

Detailed Risk Assessments

Implementation Standard 2210.A2 (Assurance Engagements) Internal auditors must consider the probability of significant errors, fraud, noncompliance, and other exposures when developing the engagement objectives.

  • A risk-based approach requires internal auditors to first understand the entity and its environment in order to identify risks.

Engagement Procedures and Work Program
  • Performance Standard 2240, “Engagement Work Program” Internal auditors must develop and document work programs that achieve the engagement objectives.

  • Implementation Standard 2240.A1 (Assurance Engagements) Work programs must include the procedures for identifying, analyzing, evaluating, and documenting information during the engagement. The work program must be approved prior to its implementation, and any adjustments approved promptly.

  • Implementation Standard 2240.C1 (Consulting Engagements) Work programs for consulting engagements may vary in form and content depending upon the nature of the engagement.

  • The auditor must ensure that the tests are specific enough to avoid scope creep.

  • Each engagement procedure should be designed to test a particular control that addresses risk.

Engagement Resources
  • Performance Standard 2230, “Engagement Resource Allocation” Internal auditors must determine appropriate and sufficient resources to achieve engagement objectives based on an evaluation of the nature and complexity of each engagement, time constraints, and available resources.

  • To determine how to best allocate resources, auditors should understand the engagement:

    • Objectives.

    • Scope.

    • Nature.

    • Complexity.

Section C: Performing the Engagement

  • Performance Standard 2300, “Performing the Engagement” Internal auditors must identify, analyze, evaluate, and document sufficient information to achieve the engagement’s objectives.

Preliminary Survey Information Gathering and Examination
  • Information formulated during the planning process should include:

    • Engagement objectives that reflect the results of a preliminary risk assessment (Standard 2210/2210.A1).

    • Criteria that will be used to evaluate the governance, risk management, and controls of the area or process under review (Standard 2210.A3).

  • Auditors must apply professional skepticism to evaluate whether:

    • The information is sufficient and appropriate to provide a reasonable basis on which to form conclusions or recommendations.

    • Implementation Standard 1110.A1 (Assurance Engagements) The internal audit activity must be free from interference in determining the scope of internal auditing, performing work, and communicating results.

    • Performance Standard 2320, “Analysis and Evaluation” Internal auditors must base conclusions and engagement results on appropriate analyses and evaluation.

  • The internal auditor should begin by looking at prior audit documentation that is relevant.

    • An important item to check when reviewing previous audit reports is whether all prior audit issues have been adequately included in ongoing follow-up procedures, such as by being included in management’s tracking process, or if the issues have already been resolved.

    • The internal auditor should consider the time during which evidence will be available for testing.

    • Implementing better training or management discipline.

  • Internal control questionnaires (ICQs) [1] An internal control questionnaire (ICQ) is a preconstructed array of questions used to elicit key information about internal controls, especially when documenting initial responses to questions about these controls.

  • Utility software.

Checklists and Questionnaires
  • The internal audit function can use a risk assessment survey to get input from middle management. It may be brief and open-ended, or it may be a structured survey asking managers to assess a number of risk categories or risk-related statements.

    • Checklists. A checklist is a simple visual tool used to collect, track, and analyze data.

    • Internal control questionnaires (ICQs) [1] An internal control questionnaire (ICQ) is a preconstructed array of questions used to elicit key information about internal controls, especially when documenting initial responses to questions about these controls.

Computerized Audit Tools and Techniques
  • CAATs Common computer-assisted auditing techniques (CAATs) include:

    • Automated workpapers.

    • Continuous auditing.
      *Generalized audit software (GAS).

Evaluating Potential Sources of Evidence
  • Performance Standard 2310, “Identifying Information” Internal auditors must identify sufficient, reliable, relevant, and useful information to achieve the engagement’s objectives.

    • The reliability of audit information depends on the use of appropriate engagement techniques.

    • Internal auditors should identify and prioritize the most relevant and useful information and critically assess all engagement information as a whole.

Analytical Approaches and Process Mapping
  • Performance Standard 2320, “Analysis and Evaluation” Internal auditors must base conclusions and engagement results on appropriate analysis and evaluations.

    • To evaluate the controls, the following should be considered:

      • Were significant discrepancies or weaknesses discovered from the audit work performed and other assessment information gathered?

Engagement Conclusions

*Performing analysis and evaluation

  • Internal auditors must document information that logically supports the engagement results and conclusions.

  • The corrective action to address existing conditions or to improve operations, and they may suggest approaches to correcting or enhancing performance as a guide for management in achieving desired results.
    *Applicable recommendations and/or action plans to follow up with the results

Engagement Supervision Key Activities

To ensure objectives are achieved, quality is assured and staff is developed using supervision engagements

  • Performance Standard 2340, “Engagement Supervision” Engagements must be properly supervised to ensure objectives are achieved, quality is assured, and staff is developed.

  • Skills assessment of the internal audit staff is an ongoing process, and it generally provides sufficient information about internal auditors’ competencies to enable the CAE to appropriately assign internal auditors to engagements based on the auditors’:

    • Knowledge.

    • Skills.

    • Other competencies.

Coordinating Work
  • Close communication and coordination between affected team members should be encouraged.

  • A primary contact or liaison with the audit client should be assigned
    Proper supervision of engagements includes reviewing and approving workpapers.

Performance Appraisal

There is a process that measures the degree to which an employee accomplishes the work requirements stated in the performance standards and then communicates that information to the employee
***Audit Performance Quality Evidence:
*Direct observation and review delivered well with specific work
*Evidence also be with client audit and manager approval
*The post-audit appraisal can be delivered and discussed immediately following the audit.

Face-to-Face Meeting to have better discussion for the meeting to work and get better knowledge

Section D: Communicating Engagement Results and Monitoring Progress

What happens after the audit results happen to help better the effectiveness and help the mangement to get remediate the changes and help be monitore for what changed need improving

  • Performance Standard 2400, “Communicating Results” Internal auditors must communicate the results of engagements.

  • Policies and procedures in the audit manual. The use of any standard templates to ensure consistency in developing observations and conclusions

Communcation and Elements of quality
  • the CAE should always ensure the communication is accurate, clear and to correct a report

  • The CAE have a check list to avoid any GRC to have risks and reports
    and The engagement is for a balance team to work correctly
    *the communication is made better if these are followed
    **accurate, clear and consise messages

Interim Reports

To keep information up and keep people well know for the audit and if anything shifts or changes
This process helps people keep inforfed
** to give great quility work

Action Planing

The process that allows recommendations that may help with what needs more
With good work comes also SMART principle to make recomendations
*To reach great goals it will help the best direction with best benefits

Action planing Communication and reporting

*to make proper party to know what to expect for reports
The goal is always being and working on good practice and will have the best knowledge with internal and external

This has to consider for communication in how results affect one and all

CAE

Can make adjustments or has to tell if theres is issues and how to make right to what needs to change with the risks