Attribute Standards
1000: Purpose, Authority and Responsibility
o Formally Documented Charter
o Must be consistent with mandatory elements of IPPF
o Periodically reviewed and presented to senior mgt and board for approval
o Must include nature of assurance (A1) and consulting (C1) assignment
o 1010: must recognize mandatory nature of IPPF elements
1100: Independence and Objectivity
o Independent means freedom from impairing influences, objective means unbiased
judgement
o 1110: organizational independence; as in reporting of IA function to board
Organizational independence status of IA must be reported to board at least
annually
Charter, risk based audit plan, budget and resource plan, appointment and
removal of internal audit chief, remuneration must be approved by board
No interference in defining scope, performing audit and communicating
results (A1)
1111: Direct Interaction of HIA with the board
1112: In case of additional responsibilities, necessary safeguards to avoid
impairment must be in place
o 1120: Individual objectivity; unbiased, impartial, No conflict of interest in internal
auditor
o 1130: Impairment to independence must be disclosed
Such as personal conflict of interest, scope limitation, restriction on access,
resource limitation
(A1) if previously responsible for a function, don’t audit it now
(A2) if HIA is responsible for a function, it must be audited by someone outside
IAD
(A3) if previously provided consultancy, can be audited, while ensuring that
there is no impairment. Can be taken care of while assigning different
resources
(C1) if previously responsible, can provide consulting service
(C2) if there is a potential impairment, it must be disclosed
1200: Proficiency and Due Professional Care
o 1210: Proficiency; must have knowledge, skills and relevant competencies
(A1) HIA must obtain competent advice and assistance if proficiency is lacking
(A2) Must be able to evaluate risk of fraud, not necessary be able to detect
frauds
(A3) Must be able to evaluate IT risks, not necessarily IT auditor
(C1) must decline if proficiency is lacking, or take competent advice, assistance
o 1220: Due professional care; apply care and skill as a prudent and competent auditor
It does not mean infallibility
(A1) must consider, extent of work needed, relative complexity/ materiality/
Significance, adequacy of governance and controls, probability of errors/
frauds/ violations and cost vs benefit of audit,
(A2) must consider tech based audit techniques and data analysis
(A3) be alert to significant risks
(C1) consider expectations, relative complexity, work needed and cost vs
benefit.
o 1230 continued professional development; enhance knowledge, skills
1300: Quality Assurance and Improvement Program
o HIA must develop and maintain it
o 1310: must include internal and external assessment
1311: Internal assessment; mostly revolves around conformance with IPPD,
includes On-going monitoring and periodic self-assessment
1312: at least once every 5 years. Must be discussed with board regarding
form, frequency ad qualification of external assessor
External assessor should be qualified, having relevant experience and
independent (no conflict of interest)
o 1320: results of internal and external assessment should be disclosed to board
Scope, frequency, qualification and independence of assessors, conclusion of
assessment and corrective action plan
1321: use “Conforms with IPPF” only if supported by assessment results
1322: Non-conformance must be disclosed
Performance Standards
2000: Managing IA
o Responsibility of HIA, must add value to organization
o 2010; a risk based plan of engagements, in line with organizational goals, in
consultation with senior management
(A1) plan must be based on a documented risk assessment conducted at least
annually
(A2) Expectations of board, senior management and stakeholders must be
considered for opinions and conclusions
Proposed consulting engagements should be accepted based on value addition
to organizations
o 2020; plan and resource requirement must be communicated to board and sr mgt for
review and approval
o 2030; HIA must ensure that resources are appropriate, sufficient and effectively
deployed
o 2040; HIA develops policies and procedures for IAD
o 2050; HIA coordinates, info sharing and consider relying upon other assurance reports
for avoiding duplication and max coverage.
o 2060: HIA periodically reports to board and sr mgt audit charter, independence status,
audit plan and progress, resource requirement, results, conformance status and mgt’s
response on disagreed points (risk accepted beyond risk apetite)
o 2070; external service provider must tell mgt its responsibility of having an effective
IAD
2100: Nature of Work
o 2110; Governance
Review and recommendations on strategic and operations decision making,
oversight of risk and control, culture, performance, communication,
coordination
(A1) must evaluate ethics related
(A2) must evaluate IT governance related
o 2120; Risk Management
Objectives and mission are aligned, significant risks are identified, risks are
aligned with risk appetite, appropriate risk responses are selected, relevant
risk information is captured and communicated in timely manner
Information to support this assessment may be gathered during multiple
engagements and viewed together to form an opinion
(A1) evaluate risk exposures relating to governance operations and
information system regarding achievement of st objectives, reliability of
information, efficiency of operations, and compliance to laws and regulations
(A2) must evaluate potential for fraud occurance
(C1) address risks related to engagement and be alert to other risks
(C2) incorporate knowledge of risks gained from consulting to the evaluation
(C3) if assisting mgt in risk mgt process, do not engage in actual risk
management which is responsibility of mgt.
o 2130; Controls
(A1) must evaluate effectiveness of control relating to governance, operations
and information system regarding achievement of st objectives, reliability and
integrity of information, efficiency and effectiveness of operations, and
compliance to laws and regulations
(C1) incorporate knowledge of controls gained from consulting to the
evaluation
2200: develop and document a plan for each engagement including objective, scope, timing
and resource allocation
o 2201; consider objectives of activity, performance control mechanism, significant risks
and mitigants in place, adequacy and possible improvements to governance risk mgt
and control processes.
(A1) establish a written understanding for external process owner and user
(C1) establish understanding, in written for significant engagements, about
expectations, authority, responsibility, limitations etc
o 2210; must establish objectives
(A1) prelim assessment of risks, the results must be reflected in objectives
(A2) consider probability of significant error and frauds
(A3) Adequate criteria is needed for evaluation, If criteria by mgt/board is
adequate then use it, otherwise develop a adequate criteria which could be
internal, external or leading practices
(C1) must address governance, rm and control process to the extent agreed
(C2) must be aligned with org values and objectives
o 2220; establish sufficient Scope
(A1) consider relevant systems, records, properties etc
(A2) if consulting is needed during assurance, establish a written
understanding
(C1) scope should be sufficient for agreed upon objectives
(C2) evaluate controls as per objectives and be alert to other control gaps
o 2230; appropriate and sufficient resource allocation
o 2240; develop and document a work plan
(A1) must include procedure for identifying, evaluating, analyzing and
documenting information. Must be approved prior to implementation
(C1) work plans may vary in form depending on nature of assignment
2300; performing engagement
o 2310; identify sufficient, reliable, useful, and relevant information
o 2320; opinion must be formed on analysis and evaluation of information
o 2330; information must be documented
(A1) HIA must control access to engagement records. Prior permission for
sharing it with external parties
(A2) develop retention requirements of engagement records
(C1) develop policy for consulting engagement record retentions, access
control and release
o 2340; must be supervised, review of work should be performed and documented
2400; communication of results
o 2410; communication must include objective, scope and results
(A1) include applicable conclusions and recommendations/action plans
(A2) encouraged to acknowledge satisfactory performance if there is
(A3) when released to 3rd parties, include limitation on use and distribution
(C1) may vary in form depending upon nature of consulting engagement
o 2420; quality, must be accurate, objective, clear, concise, constructive, complete and
timely
2421; if errors communicated, disclose it in subsequent communication
o 2430; use of ‘conducted in conformance with IPPF’ only if assessment results support
so
2431; if non-conformance, disclose it, principle violated, reason and impact
o 2440; HIA is responsible for communicating results
o 2450; overall opinion must consider stakeholders objectives, must be supported by
sufficient reliable relevant ad useful information
2500; HIA must establish a system to monitor disposition of results communicated to mgt
o (A1) follow-up process to monitor management actions or acceptance of risk on
observations
o (C1) follow up to the extent agreed
2600; the unresolved matters, where HIA does not agree with the management’s acceptance
of risk, must be discussed with mgt first and then with the board