0% found this document useful (0 votes)
61 views4 pages

PwC Audit Guide Overview

The document outlines standards for internal auditing attributes, independence and objectivity, proficiency and due professional care, and quality assurance. Some key points: 1) It establishes standards for the internal audit charter, independence, objectives, scope, resources, and work plans for engagements. 2) The internal audit function must be independent and report functionally to the board. Auditors must maintain objectivity and avoid conflicts of interest. 3) Auditors must have sufficient knowledge and competence to perform their duties with due professional care. They must continue developing their skills through training.

Uploaded by

Farhan Shoukat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
61 views4 pages

PwC Audit Guide Overview

The document outlines standards for internal auditing attributes, independence and objectivity, proficiency and due professional care, and quality assurance. Some key points: 1) It establishes standards for the internal audit charter, independence, objectives, scope, resources, and work plans for engagements. 2) The internal audit function must be independent and report functionally to the board. Auditors must maintain objectivity and avoid conflicts of interest. 3) Auditors must have sufficient knowledge and competence to perform their duties with due professional care. They must continue developing their skills through training.

Uploaded by

Farhan Shoukat
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Attribute Standards

 1000: Purpose, Authority and Responsibility


o Formally Documented Charter
o Must be consistent with mandatory elements of IPPF
o Periodically reviewed and presented to senior mgt and board for approval
o Must include nature of assurance (A1) and consulting (C1) assignment
o 1010: must recognize mandatory nature of IPPF elements
 1100: Independence and Objectivity
o Independent means freedom from impairing influences, objective means unbiased
judgement
o 1110: organizational independence; as in reporting of IA function to board
 Organizational independence status of IA must be reported to board at least
annually
 Charter, risk based audit plan, budget and resource plan, appointment and
removal of internal audit chief, remuneration must be approved by board
 No interference in defining scope, performing audit and communicating
results (A1)
 1111: Direct Interaction of HIA with the board
 1112: In case of additional responsibilities, necessary safeguards to avoid
impairment must be in place
o 1120: Individual objectivity; unbiased, impartial, No conflict of interest in internal
auditor
o 1130: Impairment to independence must be disclosed
 Such as personal conflict of interest, scope limitation, restriction on access,
resource limitation
 (A1) if previously responsible for a function, don’t audit it now
 (A2) if HIA is responsible for a function, it must be audited by someone outside
IAD
 (A3) if previously provided consultancy, can be audited, while ensuring that
there is no impairment. Can be taken care of while assigning different
resources
 (C1) if previously responsible, can provide consulting service
 (C2) if there is a potential impairment, it must be disclosed
 1200: Proficiency and Due Professional Care
o 1210: Proficiency; must have knowledge, skills and relevant competencies
 (A1) HIA must obtain competent advice and assistance if proficiency is lacking
 (A2) Must be able to evaluate risk of fraud, not necessary be able to detect
frauds
 (A3) Must be able to evaluate IT risks, not necessarily IT auditor
 (C1) must decline if proficiency is lacking, or take competent advice, assistance
o 1220: Due professional care; apply care and skill as a prudent and competent auditor
 It does not mean infallibility
 (A1) must consider, extent of work needed, relative complexity/ materiality/
Significance, adequacy of governance and controls, probability of errors/
frauds/ violations and cost vs benefit of audit,
 (A2) must consider tech based audit techniques and data analysis
 (A3) be alert to significant risks
 (C1) consider expectations, relative complexity, work needed and cost vs
benefit.
o 1230 continued professional development; enhance knowledge, skills
 1300: Quality Assurance and Improvement Program
o HIA must develop and maintain it
o 1310: must include internal and external assessment
 1311: Internal assessment; mostly revolves around conformance with IPPD,
includes On-going monitoring and periodic self-assessment
 1312: at least once every 5 years. Must be discussed with board regarding
form, frequency ad qualification of external assessor
 External assessor should be qualified, having relevant experience and
independent (no conflict of interest)
o 1320: results of internal and external assessment should be disclosed to board
 Scope, frequency, qualification and independence of assessors, conclusion of
assessment and corrective action plan
 1321: use “Conforms with IPPF” only if supported by assessment results
 1322: Non-conformance must be disclosed

Performance Standards

 2000: Managing IA
o Responsibility of HIA, must add value to organization
o 2010; a risk based plan of engagements, in line with organizational goals, in
consultation with senior management
 (A1) plan must be based on a documented risk assessment conducted at least
annually
 (A2) Expectations of board, senior management and stakeholders must be
considered for opinions and conclusions
 Proposed consulting engagements should be accepted based on value addition
to organizations
o 2020; plan and resource requirement must be communicated to board and sr mgt for
review and approval
o 2030; HIA must ensure that resources are appropriate, sufficient and effectively
deployed
o 2040; HIA develops policies and procedures for IAD
o 2050; HIA coordinates, info sharing and consider relying upon other assurance reports
for avoiding duplication and max coverage.
o 2060: HIA periodically reports to board and sr mgt audit charter, independence status,
audit plan and progress, resource requirement, results, conformance status and mgt’s
response on disagreed points (risk accepted beyond risk apetite)
o 2070; external service provider must tell mgt its responsibility of having an effective
IAD
 2100: Nature of Work
o 2110; Governance
 Review and recommendations on strategic and operations decision making,
oversight of risk and control, culture, performance, communication,
coordination
 (A1) must evaluate ethics related
 (A2) must evaluate IT governance related
o 2120; Risk Management
 Objectives and mission are aligned, significant risks are identified, risks are
aligned with risk appetite, appropriate risk responses are selected, relevant
risk information is captured and communicated in timely manner
 Information to support this assessment may be gathered during multiple
engagements and viewed together to form an opinion
 (A1) evaluate risk exposures relating to governance operations and
information system regarding achievement of st objectives, reliability of
information, efficiency of operations, and compliance to laws and regulations
 (A2) must evaluate potential for fraud occurance
 (C1) address risks related to engagement and be alert to other risks
 (C2) incorporate knowledge of risks gained from consulting to the evaluation
 (C3) if assisting mgt in risk mgt process, do not engage in actual risk
management which is responsibility of mgt.
o 2130; Controls
 (A1) must evaluate effectiveness of control relating to governance, operations
and information system regarding achievement of st objectives, reliability and
integrity of information, efficiency and effectiveness of operations, and
compliance to laws and regulations
 (C1) incorporate knowledge of controls gained from consulting to the
evaluation
 2200: develop and document a plan for each engagement including objective, scope, timing
and resource allocation
o 2201; consider objectives of activity, performance control mechanism, significant risks
and mitigants in place, adequacy and possible improvements to governance risk mgt
and control processes.
 (A1) establish a written understanding for external process owner and user
 (C1) establish understanding, in written for significant engagements, about
expectations, authority, responsibility, limitations etc
o 2210; must establish objectives
 (A1) prelim assessment of risks, the results must be reflected in objectives
 (A2) consider probability of significant error and frauds
 (A3) Adequate criteria is needed for evaluation, If criteria by mgt/board is
adequate then use it, otherwise develop a adequate criteria which could be
internal, external or leading practices
 (C1) must address governance, rm and control process to the extent agreed
 (C2) must be aligned with org values and objectives
o 2220; establish sufficient Scope
 (A1) consider relevant systems, records, properties etc
 (A2) if consulting is needed during assurance, establish a written
understanding
 (C1) scope should be sufficient for agreed upon objectives
 (C2) evaluate controls as per objectives and be alert to other control gaps
o 2230; appropriate and sufficient resource allocation
o 2240; develop and document a work plan
 (A1) must include procedure for identifying, evaluating, analyzing and
documenting information. Must be approved prior to implementation
 (C1) work plans may vary in form depending on nature of assignment
 2300; performing engagement
o 2310; identify sufficient, reliable, useful, and relevant information
o 2320; opinion must be formed on analysis and evaluation of information
o 2330; information must be documented
 (A1) HIA must control access to engagement records. Prior permission for
sharing it with external parties
 (A2) develop retention requirements of engagement records
 (C1) develop policy for consulting engagement record retentions, access
control and release
o 2340; must be supervised, review of work should be performed and documented
 2400; communication of results
o 2410; communication must include objective, scope and results
 (A1) include applicable conclusions and recommendations/action plans
 (A2) encouraged to acknowledge satisfactory performance if there is
 (A3) when released to 3rd parties, include limitation on use and distribution
 (C1) may vary in form depending upon nature of consulting engagement
o 2420; quality, must be accurate, objective, clear, concise, constructive, complete and
timely
 2421; if errors communicated, disclose it in subsequent communication
o 2430; use of ‘conducted in conformance with IPPF’ only if assessment results support
so
 2431; if non-conformance, disclose it, principle violated, reason and impact
o 2440; HIA is responsible for communicating results
o 2450; overall opinion must consider stakeholders objectives, must be supported by
sufficient reliable relevant ad useful information
 2500; HIA must establish a system to monitor disposition of results communicated to mgt
o (A1) follow-up process to monitor management actions or acceptance of risk on
observations
o (C1) follow up to the extent agreed
 2600; the unresolved matters, where HIA does not agree with the management’s acceptance
of risk, must be discussed with mgt first and then with the board

Common questions

Powered by AI

Internal auditors must have the proficiency to evaluate IT risks to understand their potential impact on the organization's operations and governance. However, being an IT auditor is not necessary because IT auditors typically possess deep technical expertise, whereas internal auditors can use tools or seek assistance from IT specialists to evaluate risks effectively. This approach leverages diverse expertise while maintaining robust risk evaluation .

Developing a risk-based plan involves conducting a documented risk assessment annually, consulting with senior management, and considering the board's expectations. This process aligns audit activities with organizational goals and ensures resources are directed toward areas with the most significant risk, facilitating effective risk management and enhancing organizational value .

A preliminary assessment of risks enables auditors to understand potential areas of concern and align audit objectives to address significant risks. This ensures the audit engagement is focused, relevant, and effective in evaluating the controls as they relate to governance, operations, and compliance, driving audit efficiency and effectiveness .

Internal auditors use ongoing monitoring as part of internal assessments to ensure continuous adherence to the International Standards for the Professional Practice of Internal Auditing. This continuous oversight helps identify areas for improvement promptly, supports self-assessment, and addresses potential issues before they escalate, thereby strengthening quality assurance .

Challenges in maintaining external assessor independence include potential conflicts of interest and ensuring the assessor is not influenced by organizational ties. Strategies to address these challenges include selecting assessors with relevant expertise and independence, ensuring no previous engagement with the audited functions, and adhering to stringent qualification criteria for independence .

A formally documented charter must be consistent with the mandatory elements of the International Professional Practices Framework (IPPF). It should include the nature of assurance and consulting assignments, and it must be periodically reviewed and presented to senior management and the board for approval. These measures ensure the charter aligns with IPPF by embedding mandatory standards and reinforcing accountability through periodic reviews and approvals .

Organizational independence ensures that the internal audit function is free from impairing influences, allowing it to operate without interference when defining scope, performing audits, and communicating results. Reporting to the board and having key functions like the audit plan, budget, and the appointment or removal of the internal audit chief approved by the board supports unbiased auditing practices .

A Quality Assurance and Improvement Program, required by the IPPF, involves both internal and external assessments. It reinforces integrity and effectiveness by ensuring ongoing conformance with professional standards through consistent monitoring and feedback. External assessments, at least every five years, offer an independent validation of adherence to standards, supporting continual improvement .

An internal auditor must remain unbiased and impartial, avoiding any conflict of interest which could impair judgment. If there is personal conflict of interest, scope limitation, or other impairments, it must be disclosed. Failure to maintain objectivity could lead to skewed audit outcomes and damage the credibility of audit findings .

Collaboration with other assurance providers avoids duplication, maximizes coverage and enhances the efficiency of the internal audit process. By sharing information and relying on other assurance outputs, the internal audit function can allocate resources more effectively and provide comprehensive coverage, enhancing both efficiency and the robustness of audit outcomes .

You might also like