0% found this document useful (0 votes)
23 views7 pages

Independence and Objectivity in Internal Audit

CIA Part 1 Personal Notes

Uploaded by

abdiweli
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
23 views7 pages

Independence and Objectivity in Internal Audit

CIA Part 1 Personal Notes

Uploaded by

abdiweli
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter 2 Independence, objectivity, and proficiency

Sub-unit 1 Independence of IAA

Independence is the freedom from conditions that threaten the ability of the internal audit activity to carry out
internal audit responsibilities in an unbiased manner.

To achieve the degree of independence necessary to effectively carry out the responsibilities of the internal audit
activity, the chief audit executive has direct and unrestricted access to senior management and the board. This can
be achieved through a dual-reporting relationship (Functional and administrative). Threats to independence must
be managed at the individual auditor, engagement, functional, and organizational levels.

Independence is an organizational attribute of the internal audit activity as a whole.

The chief audit executive must confirm to the board, at least annually, the organizational independence of the
internal audit activity.

Organizational independence is effectively achieved when the chief audit executive reports functionally to the
board.

# Functional reporting Administrative reporting


Meaning Provides independence and authority. Facilitates day-to-day operations
A functional reporting line to the board provides the CAE the CAE also has an administrative reporting line to
with direct board access for sensitive matters and enables senior management, which further enables the requisite
sufficient organizational status. It ensures that the CAE has stature and authority of internal audit to fulfill
unrestricted access to the board, typically the highest level responsibilities
of governance in the organization
Examples  Approving the internal audit charter.
 Budgeting and management accounting
 Approving the risk based internal audit plan.
 Approving the internal audit budget and resource  Human resource administration
plan.
 Internal communications and information flows
 Receiving communications from the chief audit
executive on the internal audit activity’s  Administration of internal audit activity’s policies
performance relative to its plan and other matters. and procedures
 Approving decisions regarding the appointment and
 APPROVAL FOR ANNUAL LEAVE FOR CAE
removal of the chief audit executive.
 Approving the remuneration of the chief audit  APPROVAL FOR LOANS FOR CAE – WHERE
executive. ORGANISATION ISSUES LOANS
 Making appropriate inquiries of management and
the chief audit executive to determine whether
there are inappropriate scope or resource
limitations.
the board monitors the ability of internal audit to operate independently and fulfill its charter.

at least annually, a private meeting with the board or audit committee and the CAE (without senior management
present) is formally conducted to discuss such matters or issues.

It is also helpful for the CAE to participate in one-on-one meetings or phone calls periodically with the board or
audit committee chair, either prior to scheduled meetings or routinely during the year, to ensure direct and open
communication.

Board meeting agendas and minutes are often sufficient to demonstrate whether the CAE has communicated and
interacted directly with the board.

the CAE cannot solely determine organizational independence and placement.


Conformance with Organizational Independence may be demonstrated, among other means, through

 The internal audit charter and the audit committee charter,


 The CAE’s job description and performance evaluation
 An internal audit policy manual that addresses policies
The internal audit activity must be free from interference in determining the scope of internal auditing,
performing work, and communicating results. The chief audit executive must disclose such interference to
the board and discuss the implications.

Sub-unit 2 objectivity

Independence is an attribute of the internal audit activity. In contrast, objectivity is an attribute of individual
internal auditors.

Objectivity is an unbiased mental attitude that allows internal auditors to perform engagements in such a
manner that they believe in their work product and that no quality compromises are made. Objectivity
requires that internal auditors do not subordinate their judgment on audit matters to others. Threats to
objectivity must be managed at the individual auditor, engagement, functional, and organizational levels.

Internal auditors must have an impartial, unbiased attitude and avoid any conflict of interest.

conflict of interest is any relationship that is, or appears to be, not in the best interest of the organization.

Conflict of interest is a situation in which an internal auditor, who is in a position of trust, has a
competing professional or personal interest. Such competing interests can make it difficult to fulfill his or
her duties impartially. A conflict of interest exists even if no unethical or improper act results. A conflict
of interest can create an appearance of impropriety that can undermine confidence in the internal
auditor, the internal audit activity, and the profession.
A conflict of interest could impair an individual’s ability to perform his or her duties and
responsibilities objectively.

Objectivity refers to an internal auditor’s impartial and unbiased mindset, which is facilitated by avoiding conflicts
of interest.

To manage internal audit objectivity effectively, many CAEs have an internal audit policy manual or handbook that
describes the expectation and requirements for an unbiased mindset for every internal auditor. Such a policy
manual may describe:

 The importance of objectivity to the internal audit profession.


 Typical situations that could undermine objectivity, such as
 Auditing in an area in which an internal auditor recently worked;
 Auditing a family member or a close friend; or
 Assuming, without evidence, that an area under audit is acceptable based solely on prior positive
experiences.
 Actions the internal auditor should take if he becomes aware of a current or potential objectivity concern
 Reporting requirements, where each internal auditor periodically considers and discloses conflicts of
interest
 Policies often require internal auditors to indicate that they understand the conflict-of-interest policy,
disclose potential conflicts, and sign annual statements indicating that no potential threats exist or
acknowledging any known potential threats.

To reinforce the importance of these policies and help ensure all internal auditors internalize their importance,
many CAEs will hold routine workshops or training on these fundamental concepts.
When assigning internal auditors to specific engagements, the CAE (or delegate) will consider potential objectivity
impairments and avoid assigning team members who may have a conflict.

the CAE needs to be thoughtful in designing the internal audit performance evaluation and compensation system
and consider whether the measurements used could impair an internal auditor’s objectivity.

Review of internal audit work results before the related engagement communications are released assists in
providing reasonable assurance that the work was performed objectively.

The CAE must establish policies and procedures to assess the objectivity of individual internal auditors, this can be
through periodic review of conflict of interest.

The responsibility to maintain objectivity rests with the CAE and with internal auditors themselves.

A conflict requires a relationship.

Sub-unit 3 Impairment of independence and Objectivity

impairments must be disclosed to the “appropriate” party.

If independence or objectivity is impaired in fact or appearance, the details of the impairment must be
disclosed to appropriate parties. The nature of the disclosure will depend upon the impairment.

Impairment to organizational independence and individual objectivity may include, but is not limited to:

 personal conflict of interest;


 scope limitations;
 restrictions on access to records, personnel, and properties; and
 resource limitations, such as funding

Impairment situations generally include:

 self-interest,
 self-review,
 familiarity,
 bias, or
 undue influence

Internal audit examples of organizational independence impairments include the following, which, if in effect,
can also undermine internal auditor objectivity:

 The CAE has broader functional responsibility than internal audit and executes an audit of a functional
area that is also under the CAE’s oversight.
 The CAE’s supervisor has broader responsibility than internal audit, and the CAE executes an
audit within his or her supervisor’s functional responsibility.
 The CAE does not have direct communication or interaction with the board.
 The budget for the internal audit activity is reduced to the point that internal audit cannot fulfill its
responsibilities as outlined in the charter.
Examples of objectivity impairments include:

 An internal auditor audits an area in which he or she recently worked, such as when an employee
transfers into internal audit from a different functional area of the organization and then is
assigned to an audit of that function.
 An internal auditor audits an area where a relative or close friend is employed.
 An internal auditor assumes, without evidence, that an area being audited has effectively mitigated risks
based solely on prior positive audit or personal experiences (e.g., a lack of professional skepticism).
 An internal auditor modifies the planned approach or results based on the undue influence of another
person, often someone senior to the internal auditor, without appropriate justification.
Both the nature of the impairment and board/senior management expectations will determine the appropriate
parties to be notified of the impairment and the ideal communication approach. For example:

 When the CAE believes the impairment is not real, but recognizes there could be a perception of
impairment, the CAE may choose to discuss the concern in engagement planning meetings with the
operating management, document the discussion (such as in an audit planning memo), and explain
why the concern is without merit. Such a disclosure may also be appropriate for a final engagement
report.
 When the CAE believes the impairment is real and is affecting the ability of internal audit to perform
its duties independently and objectively, the CAE is likely to discuss the impairment with the board and
senior management and seek their support to resolve the situation.
 When an impairment comes to light after an audit has been executed, and it impacts the reliability (or
perceived reliability) of the engagement results, the CAE will discuss it with operating and senior
management, as well as the board.

A scope limitation is a restriction placed on the internal audit activity that precludes the activity from
accomplishing its objectives and plans. Among other things, a scope limitation may restrict:

 The scope defined in the internal audit charter.

 The internal audit activity’s access to records, personnel, and physical properties relevant to the
performance of engagements.

 The approved engagement work schedule.

 The performance of necessary engagement procedures.

 The approved staffing plan and financial budget.


Internal auditors are not to accept fees, gifts, or entertainment from an employee, client, customer, supplier, or
business associate that may create the appearance that the auditor’s objectivity has been impaired.

Internal auditors are to report immediately the offer of all material fees or gifts to their supervisors.

the internal auditor’s objectivity is not impaired when the auditor recommends standards of control for systems or
reviews procedures before they are implemented.

Certain responsibilities lead to the presumption that objectivity is impaired. These responsibilities include
designing, installing, implementing, or drafting procedures for information systems.

Objectivity is presumed to be impaired if an auditor provides assurance services for an activity for which the
auditor had responsibility within the previous year.

Where the chief audit executive has or is expected to have roles and/or responsibilities that fall outside of internal
auditing, safeguards must be in place to limit impairments to independence or objectivity.

The chief audit executive may be asked to take on additional roles and responsibilities outside of internal auditing,
such as responsibility for compliance or risk management activities. These roles and responsibilities may impair, or
appear to impair, the organizational independence of the internal audit activity or the individual objectivity of the
internal auditor.
Assurance engagements for functions over which the chief audit executive has responsibility must be overseen by
a party outside the internal audit activity.

The internal audit activity may provide assurance services where it had previously performed consulting
services, provided the nature of the consulting did not impair objectivity and provided individual objectivity
is managed when assigning resources to the engagement.

Internal auditors may provide consulting services relating to operations for which they had previous
responsibilities.

If internal auditors have potential impairments to independence or objectivity relating to proposed


consulting services, disclosure must be made to the engagement client prior to accepting the
engagement.

The chief audit executive may be asked to take on additional roles and responsibilities outside of internal
auditing, such as responsibility for compliance or risk management activities. These roles and responsibilities
may impair, or appear to impair, the organizational independence of the internal audit activity or the
individual objectivity of the internal auditor. Safeguards are those oversight activities, often undertaken by
the board, to address these potential impairments, and may include such activities as periodically evaluating
reporting lines and responsibilities and developing alternative processes to obtain assurance related to the
areas of additional responsibility. The potential impairments exist because the chief audit executive is
expected to take responsibilities that fall outside of internal auditing. Accordingly, increasing the budget for
the internal audit activity cannot provide the necessary safeguards.

Sub-unit 4 auditor proficiency

The internal audit activity is considered proficient if the team collectively possesses or obtains the
competencies needed to perform its responsibilities.

performing engagements with proficiency and due professional care is the responsibility of every internal auditor.

The internal audit activity as a whole, not each auditor individually, must be proficient in all necessary
competencies.

The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies
needed to perform its responsibilities.

Proficiency is a collective term that refers to the knowledge, skills, and other competencies required of internal
auditors to effectively carry out their professional responsibilities.

Proficiency includes knowledge sufficient to evaluate fraud risks and IT risks and controls.

Internal auditors must have sufficient knowledge to evaluate the risk of fraud and the manner in which it is
managed by the organization, but are not expected to have the expertise of a person whose primary
responsibility is detecting and investigating fraud.
Internal auditors must have sufficient knowledge of key information technology risks and controls and
available technology-based audit techniques to perform their assigned work. However, not all internal
auditors are expected to have the expertise of an internal auditor whose primary responsibility is
information technology auditing.
The chief audit executive must decline the consulting engagement or obtain competent advice and
assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all
or part of the engagement.
Internal auditors become proficient through professional education (including continuing professional
development), professional experience, and certifications.
competency is the ability to perform a task or job properly. It is a set of defined knowledge, skills, and behavior.
The framework defines the three competency levels needed for each of the four knowledge areas to fulfill
International Professional Practices Framework (IPPF) requirements for all occupational levels of the internal
audit profession.
The three competency levels are:
 General awareness (staff, entry-level personnel)
 Applied knowledge (management, mid-level personnel)
 Expert (executive, senior-level personnel)

The four knowledge areas are as follows:


 Professionalism.
 Performance
 Environment
 Leadership and communication

Competency framework is a tool that defines the competencies needed to meet the requirements of the
international professional practice framework for the success of the internal audit profession. The framework
describes 10 interdependent core competencies:

1) professional ethics
2) Internal audit management
Technical expertise
3) IPPF
4) Governance, risk and control
5) Business acumen
Personnel skills
6) Communication
7) Persuasion and collaboration
8) Critical thinking
9) Internal audit delivery
10) Improvement and innovation

Sub-unit 5 internal audit resources

Internal resource:

The CAE must ensure that the internal audit activity is able to fulfill its responsibilities by Identifying the available
knowledge, skills, and competencies within the internal audit activity and this will help the CAE to determine
whether the current staff is sufficient to satisfy those responsibilities.

Senior management is responsible for the hiring of internal audit staff.

The following practices help the CAE identify the available resources:

 Hiring practices are an essential part of understanding the background of the internal audit staff.
During this process, the CAE identifies the internal auditor’s education, previous experience, and
specialized areas of knowledge.
 The CAE should conduct periodic skills assessments to determine the specific resources available.
Assessments should be performed at least annually.
 Staff performance appraisals are completed at the end of any major internal audit engagement.
These appraisals help the CAE assess future training needs and current staff abilities.
 Continuing professional development encourages continued growth. Acquired training also should
be considered when identifying internal audit resources.
Databases can be used to store internal audit background information. The information stored can include
lists of relevant skills, completed projects, acquired training, and development needs.
If the internal audit staff is not able to fulfill internal audit responsibilities, the use of external service providers
must be considered.
External resources
An organization may outsource none, all, or some of the functions of the internal audit activity. However, oversight
of and responsibility for the internal audit activity must not be outsourced.
Regardless of the degree of outsourcing, services still must be performed in accordance with the Standards, and
the guidance for obtaining external service providers should be followed.
Outsourcing alternatives include the following:
 Partial or total external sourcing on an ongoing basis
 Co sourcing for a specific engagement or on an ongoing basis
 Co sourcing is performance by internal audit staff of joint engagements with external service providers.
The CAE should use of expertise from outside the internal audit activity during assurance engagements when the
internal auditors lack the necessary expertise.

The chief audit executive must obtain competent advice and assistance if the internal auditors lack the knowledge,
skills, or other competencies needed to perform all or part of the engagement.

Each member of the internal audit activity need not be qualified in all disciplines. When necessary, the CAE can
obtain necessary knowledge, skills, and competencies from external service providers.

External service provider

Qualified external service providers may be recruited from many sources, such as a public accounting firm, an
external consulting firm, or a university.
However, an external service provider associated with the engagement client is unacceptable because the person
would not be independent or objective.
External service providers may more easily accommodate engagement requirements in distant locations.

You might also like