Code of Ethics
Principles relevant to the profession and practice of internal auditing and Rules of Conduct that describe behavio
International Professional Practices Framework (IPPF)
The conceptual framework that organizes the authoritative guidance promulgated by The IIA.
Internal audit activity
A department, division, team of consultants, or other practitioner(s) that provide independent, objective assuran
Board
The highest level governing body (e.g., a board of directors, a supervisory board, or a board of governors or trust
Assurance services
Objective examination of evidence for the purpose of providing an independent assessment on risk managemen
Internal auditing
An independent, objective assurance and consulting activity designed to add value and improve an organization'
Charter
In terms of the internal audit activity, a formal written document that defines the activity's purpose, authority, a
Engagement
A specific internal audit assignment, task, or review activity, such as an internal audit, control self-assessment re
Consulting services
Advisory and related client service activities, the nature and scope of which are agreed with the client and which
Chief audit executive (CAE)
The top position in an organization responsible for internal audit activities.
Objectivity
An unbiased mental attitude that allows internal auditors to perform engagements in such a manner that they b
uct that describe behavior expected of internal auditors.
ndent, objective assurance and consulting services designed to add value and improve an organization's operations.
ard of governors or trustees) charged with the responsibility to direct and/or oversee the organization's activities and hold s
ment on risk management, control, or governance processes for an organization.
mprove an organization's operations; brings a systematic, disciplined approach to evaluate and improve the effectiveness o
y's purpose, authority, and responsibility. It establishes the internal audit activity's position within the organization; authori
ntrol self-assessment review, fraud examination, or consultancy.
with the client and which are intended to add value and improve an organization's governance, risk management, and contr
ch a manner that they believe in their work product and that no significant quality compromises are made. It requires that i
tion's operations.
on's activities and hold senior management accountable.
rove the effectiveness of risk management, control, and governance processes.
he organization; authorizes access to records, personnel, and physical properties relevant to the performance of engageme
management, and control processes without the internal auditor assuming management responsibility.
e made. It requires that internal auditors do not subordinate their judgment on audit matters to others.
rformance of engagements; and defines the scope of internal audit activities.
Functional reporting
A reporting structure where the governing authority sets the direction and approve the policies of the internal auditi
Conflict of interest
Any relationship that is or appears to be not in the best interest of the organization; would prejudice an individual's
Independence
The freedom from conditions that threaten the ability of the internal audit activity to carry out internal audit respon
Objectivity
An unbiased mental attitude that allows internal auditors to perform engagements in such a manner that they belie
Administrative reporting
A reporting structure where the administrative unit facilitates the day-to-day operations of the internal audit activit
policies of the internal auditing activity. This structure provides the ultimate source of independence and authority.
uld prejudice an individual's ability to perform his or her duties and responsibilities objectively.
rry out internal audit responsibilities in an unbiased manner.
ch a manner that they believe in their work product and that no significant quality compromises are made. It requires that inte
of the internal audit activity.
e and authority.
e made. It requires that internal auditors do not subordinate their judgment on audit matters to others.
Due professional care
Comprehending the objectives and scope of the engagement, as well as the competencies that will be required to e
Certification
The systematic measurement of characteristics such as education and experience that results in recognition of an in
Skills
The level of proficiency needed to perform the internal audit activity.
Proficiency
The knowledge, skills, and other competencies required of internal auditors to effectively carry out their professiona
Continuing professional development
The means by which members of a profession maintain, improve, and broaden the knowledge, skills, and competen
Knowledge
The body of information necessary to perform the internal audit activity.
Competencies
The collective knowledge, skills, abilities, and personal attributes that can lead to exceptional performance.
es that will be required to execute the audit work and any policies and procedures specific to the internal audit activity and the
esults in recognition of an individual as one who meets the suggested knowledge and other minimum requirements for a positi
y carry out their professional responsibilities.
wledge, skills, and competence required in their professional lives.
tional performance.
ternal audit activity and the organization.
m requirements for a position or a profession.
Continuous improvement
An ongoing, cyclical process of regularly evaluating and working to improve a product, service, or process, either
Reciprocal peer assessment
A teaming arrangement in which the internal audit activity for one organization agrees to perform the full extern
Balanced scorecard (BSC)
A strategic measurement and management system that links long-term strategic planning objectives with day-to
External assessment
A full evaluation of the performance of the internal audit activity performed by a qualified, independent assesso
Quality assurance
The process of assuring that an internal audit function operates according to a set of standards defining the spec
Quality
An organization's standards of excellence for product or service output.
Conformance
The practices of the internal audit activity, taken as a whole, satisfy the requirements of the Definition of Interna
Internal assessment
Ongoing monitoring of the performance of the internal audit activity coupled with periodic self-assessments or a
Quality assurance and improvement program (QAIP)
A program designed to enable an evaluation of the internal audit activity's conformance with the Standards and
Nonconformance
Situation in which the impact and severity of deficiencies in the practices of the internal audit activity are so sign
ervice, or process, either by a series of incremental improvements or by larger initiatives that may result in breakthrough im
o perform the full external assessment or validation for an SAIV for another organization in exchange for that organization p
ng objectives with day-to-day activities; measures financial performance, customer knowledge, internal business processes,
ed, independent assessor or assessment team from outside the organization. Must be conducted at least once every five ye
ndards defining the specific elements that must be present to ensure that the findings of the internal audit function are legi
the Definition of Internal Auditing, the Code of Ethics, and the Standards.
dic self-assessments or assessments by other persons within the organization with sufficient knowledge of internal audit pr
with the Standards and an evaluation of whether internal auditors apply the Code of Ethics. It also assesses the efficiency a
audit activity are so significant that they impair the activity's ability to discharge its responsibilities.
esult in breakthrough improvements.
ge for that organization providing a similar service.
rnal business processes, and learning and growth.
least once every five years.
al audit function are legitimate.
edge of internal audit practices.
assesses the efficiency and effectiveness of the internal audit activity and identifies opportunities for improvement.
or improvement.
Values
Beliefs about right versus wrong that guide people's and organizations' decisions and actions, especially in situati
Compliance
The conformity and adherence to policies, plans, procedures, laws, regulations, contracts, or other requirements
Corporate social responsibility (CSR)
The way firms integrate social, environmental, and economic concerns into their values, culture, decision making
Strategy
Refers to how management plans to achieve the organization's objectives.
Triple bottom line
A concept that corporate success should be measured in three dimensions--economic, social, and environmenta
Culture
The values and norms that exist in an organization.
Governance
The combination of processes and structures implemented by the board in order to inform, direct, manage and m
Sustainable development
A strategy to promote the long-term viability of an organization's operations and actions by ensuring that the cu
Audit scope
The established parameters and boundaries of the audit engagement. It identifies what will be reviewed (proces
Conduct
The tangible manifestation of culture through the actions, behaviors, and decisions of the individuals who form a
IT governance
The leadership, structure, and oversight processes that ensure the organization's IT supports the objectives and
tions, especially in situations that require making tradeoffs between conflicting objective.
s, or other requirements.
culture, decision making, strategy and operations in a transparent and accountable manner and thereby establish better pr
ocial, and environmental--not just by traditional economic profitability measures.
rm, direct, manage and monitor the activities of the organization toward the achievement of its objectives.
by ensuring that the current and future needs of the organization and society can be met.
will be reviewed (processes, activities, and time period) and what will be excluded from the engagement.
e individuals who form an organization.
ports the objectives and strategies of the organization.
ereby establish better practices within the firm, create wealth, and improve society.
Enterprise risk management (ERM)
A structured, consistent, and continuous process across the whole organization for identifying, assessing, deciding o
Controllable risk
The portion of inherent risk that management can reduce through day-to-day operations and management activitie
Risk identification
The method of recognizing possible threats and opportunities.
Inherent risk
The risk derived from the environment without the mitigating effects of internal controls.
Likelihood
The probability that a given event will occur.
Risk management
A process to identify, assess, manage, and control potential events or situations to provide reasonable assurance reg
Risk response
The actions taken to manage risk.
Risk
The possibility of an event occurring that will have an impact on the achievement of objectives; measured in terms o
Risk tolerance
The acceptable levels of variation relative to the achievement of objectives.
Heat map
A two-axis risk assessment chart or grid that places impact on one axis and likelihood on the other to create a comb
Risk assessment
The identification of risk, the measurement of risk, and the process of prioritizing risk or selecting alternatives based
Impact
The result, effect, or consequences of an event.
Residual risk
The risk remaining after management takes action to reduce the impact and likelihood of an adverse event, includin
Event
An incident or occurrence resulting from internal or external sources that affects the implementation of strategy or
Risk rating
A combination assessment of a risk's impact and likelihood.
Risk register
A spreadsheet or document that links risks to organizational objectives, provides an assessment of each risk, includi
Risk attitude
An organization's approach to assess and eventually pursue, retain, or turn away from risk.
Materiality
A threshold level above which items would make a difference to a decision-maker (material) and below which the it
Opportunity
As related to risk, an uncertain event with a positive consequence.
Risk appetite
The amount of risk an organization is willing to accept in pursuit of value.
Uncertainty
A condition where the outcome can only be estimated.
tifying, assessing, deciding on responses to, and reporting on opportunities and threats that affect the achievement of its objec
s and management activities.
de reasonable assurance regarding the achievement of an organization's objectives.
ectives; measured in terms of impact and likelihood.
the other to create a combination assessment of a risk's overall rating.
selecting alternatives based on risk.
f an adverse event, including control activities in responding to a risk.
plementation of strategy or achievement of objectives.
essment of each risk, including its impact and probability, identifies the risk owner, and identifies the response or key control to
rial) and below which the items are insignificant (immaterial).
he achievement of its objectives.
e response or key control to address the risk.
Control
Any action taken by management, the board, and other parties to manage risk and increase the likelihood that estab
Control processes
The policies, procedures, and activities that are part of a control framework, designed to ensure that risks are conta
Internal control
A process designed to provide reasonable assurance regarding the achievement of objectives in the categories of eff
Key controls
Controls that must operate effectively to reduce a significant risk to an acceptable level.
Secondary controls
Controls that help the process run smoothly but are not essentials.
Compensating controls
Controls that compensate for the lack of an expected control; for example, close supervisory review may compensa
Preventive control
A type of proactive control that deters undesirable events from occurring.
Detective control
A type of control that is reactive and that detects undesirable events that have occurred.
Manual controls
Tasks that prevent or detect a deviation from the approved procedure. Work by some type of conscious interventio
Automated controls
Controls that operate without human intervention.
IT general control (ITGC)
An IT control that applies generally to the IT environment or overall mix of systems, networks, data, people, and pro
Application control
An IT control related to the specific functioning of an application system that supports a specific business process.
Technical controls
The specific IT controls that must be in place for management and governance controls to be effective.
Input controls
A type of control intended to prevent computer errors by controlling data as it manually or electronically enters the
Processing controls
Automated error checks built into computer processing as well as segregation of duties such as controlling program
Output controls
Detective controls that find errors and verify the accuracy and reasonableness of output data after processing is com
System of internal control
A method to appropriately manage risk so that business objectives can be achieved at the lowest cost.
Control framework
A recognized system of concepts encompassing all elements of internal control.
Control environment
The attitude and actions of the board and management regarding the significance of control within the organization
Control self-assessment
A variety of assessment techniques, including facilitated workshops and surveys, in which the assessment is perform
Major deficiencies
A type of internal control deficiency that severely reduces the likelihood that the organization can achieve its objecti
Significant deficiencies
A type of internal control deficiency that severely reduces the likelihood that the organization can achieve its objecti
Material weaknesses
Omissions or misstatements of information that would significantly impact the decisions of the users of financial rep
Deficiency
A condition within enterprise risk management worthy of attention that may represent a perceived, potential, or re
ase the likelihood that established objectives and goals will be achieved.
ensure that risks are contained within the risk tolerances established by the risk management process.
ctives in the categories of effectiveness and efficiency of operations, reliability of financial reporting, and compliance with appli
sory review may compensate for a lack of segregation of duties where a small staff size makes proper segregation impractical.
pe of conscious intervention.
works, data, people, and processes.
specific business process.
o be effective.
or electronically enters the system.
such as controlling programmers' access to files and records.
data after processing is complete.
he lowest cost.
trol within the organization; provides the discipline and structure for the achievement of the primary objectives of the system
h the assessment is performed by people involved in the area or process being assessed rather than by an independent party.
zation can achieve its objectives and prevents management from determining that it has met the requirements for an effective
zation can achieve its objectives and prevents management from determining that it has met the requirements for an effective
of the users of financial reports.
a perceived, potential, or real shortcoming or an opportunity to strengthen enterprise risk management to increase the likeliho
, and compliance with applicable laws and regulations.
per segregation impractical.
ry objectives of the system of internal control.
n by an independent party.
quirements for an effective system of internal control.
quirements for an effective system of internal control.
ment to increase the likelihood that the entity's objectives will be achieved.
Red flags
A term used to refer to indicators of fraud; signs that indicate both the inadequacy of controls in place to deter f
Fraud
Any illegal acts characterized by deceit, concealment, or violation of trust.
Misappropriation of assets
Theft of a material amount of an organization's assets.
Bribery
The offering, giving, receiving, or soliciting of anything of value to influence an outcome.
Corruption
The misuse of entrusted power for private gain.
Whistleblowers
A term used to refer to individuals who report fraud and abuse.
Forensic auditing
The application of auditing skills to gather evidence that may be used in a court of law for a criminal or civil matt
Fraud risk
The probability that fraud will occur and the potential severity or consequences to the organization when it occu
Fraud triangle
A set of three conditions that, if present in the right proportions, suggest the possibility of fraud: opportunity, m
Channel loading
The practice of inflating sales figures by forcing more products through a distribution channel than the channel c
ntrols in place to deter fraud and the possibility that some perpetrator has already overcome these weak or absent controls
or a criminal or civil matter.
rganization when it occurs.
of fraud: opportunity, motive, and rationalization.
annel than the channel can actually sell.
weak or absent controls to commit fraud.