Module I: INTERNAL AUDITING
Learning Objectives
At the end of the discussion, students should be able to:
1. Explain the Institute of Internal Auditors’ (IIA) mission of internal audit.
2. Differentiate between assurance and consulting services.
3. Understand and apply the IIA’s Code of Ethics.
4. Describe the elements of Quality Assurance and Improvement Programs (QAIP).
5. Analyze the role of internal audit in governance, risk management, and internal control.
6. Identify and explain the elements of fraud.
INTRODUCTION
Internal auditing is a vital component of modern organizations, ensuring that governance structures, ethical
standards, risk management systems, and internal controls function effectively.
A. INSTITUTE OF INTERNAL AUDITORS’ MISSION OF INTERNAL AUDIT
The Institute of Internal Auditors (IIA) is the global professional body for internal auditors, and it defines the mission
of internal audit as:
“To enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight.”
This mission statement is more than a slogan—it describes the very purpose of internal auditing in organizations
today.
1. Enhance and Protect Organizational Value
✓ Internal audit does not exist simply to find errors or expose fraud. Instead, it ensures that the
organization is protected from risks and that its systems, processes, and resources are optimized
to create value.
2. Risk-Based Approach
✓ Internal auditing is guided by risk assessment. Auditors focus their attention on areas that pose the
greatest risk to the achievement of organizational goals.
3. Objective Assurance
✓ Assurance is the independent evaluation of governance, risk management, and control processes.
✓ Being objective means that auditors present findings free from personal bias, undue influence, or
conflicts of interest.
4. Advice and Insight
✓ Beyond assurance, internal auditors provide consulting services by offering advice to management
on how to improve processes, adopt best practices, or manage risks.
✓ They provide insight, which goes beyond reporting what is wrong—it includes interpreting what
findings mean for the organization’s strategy and long-term goals.
Why the Mission Matters
✓ It positions internal auditing as a value-adding activity, not just a compliance function.
✓ It emphasizes the balance between assurance (evaluating controls and risks) and advisory roles (helping
management improve operations).
✓ It ensures that auditors contribute to organizational success, not just error detection.
B. ASSURANCE VS. CONSULTING SERVICES IN INTERNAL AUDITING
Internal auditing provides two main categories of services: assurance and consulting. While both are meant to
improve the organization’s operations, they differ in purpose, nature, and the role of the internal auditor.
1. Assurance Services
➢ Definition: Independent and objective evaluation of evidence to provide an opinion or conclusion regarding
an organization’s governance, risk management, and control processes.
➢ Purpose: To give confidence (assurance) to stakeholders—such as the board, management, or members—
that systems and controls are functioning properly.
➢ Key Characteristics:
Prepared by: DEMY N. CODNITA, CPA
First Semester AY 2025-2026
Page 1 of 5
Governance, Business Ethics, Risk Management and Internal Control
Auditor maintains independence and objectivity.
✓
Auditor’s role is to assess and report; management is responsible for implementing improvements.
✓
➢ Examples:
✓ Auditing financial statements or reports.
✓ Reviewing compliance with cooperative policies and government regulations.
✓ Evaluating the effectiveness of risk management systems.
2. Consulting Services
➢ Definition: Advisory and related client services, the nature and scope of which are agreed upon with the
client, intended to add value and improve operations.
➢ Purpose: To provide advice, guidance, and insight that supports management in decision-making and
process improvement.
➢ Key Characteristics:
✓ More collaborative in nature.
✓ Auditor may give recommendations, design advice, or facilitate solutions.
✓ Still must uphold objectivity, but independence is less rigid than in assurance.
➢ Examples:
✓ Advising on the design of a new internal control system.
✓ Facilitating workshops on risk management.
✓ Recommending IT systems to improve operational efficiency.
Illustrative Example
• Assurance: An internal auditor checks whether loan disbursement policies are being followed. They issue a
report showing compliance gaps.
• Consulting: The same auditor, upon management’s request, advises on designing a new loan approval
process to reduce risk and improve efficiency.
In short:
• Assurance = "We evaluate for you."
• Consulting = "We help you improve."
Why Both Are Important
✓ Assurance services protect organizational value by detecting weaknesses and ensuring accountability.
✓ Consulting services enhance organizational value by helping management anticipate risks and adopt better
practices.
Together, they align with the IIA’s Mission of Internal Audit: to enhance and protect organizational value
through risk-based and objective assurance, advice, and insight.
C. CONFORMANCE ON IIA’S CODE OF ETHICS
The Institute of Internal Auditors (IIA) developed a Code of Ethics to guide the professional conduct of internal
auditors worldwide. Since auditors are entrusted with sensitive information and are expected to be objective guardians
of governance, ethical behavior is the foundation of internal auditing.
Purpose of the Code of Ethics
✓ To promote an ethical culture in the auditing profession.
✓ To establish the principles and expectations for internal auditors’ behavior.
✓ To provide a framework for making sound ethical decisions in complex situations.
Four Principles of the IIA Code of Ethics
1. Integrity
✓ Internal auditors must perform their work with honesty, diligence, and responsibility.
✓ Integrity establishes trust and provides the basis for reliance on their judgment.
2. Objectivity
✓ Internal auditors must make balanced assessments, avoiding bias, conflict of interest, or undue
influence.
✓ Their conclusions should be based only on evidence.
Prepared by: DEMY N. CODNITA, CPA
First Semester AY 2025-2026
Page 2 of 5
Governance, Business Ethics, Risk Management and Internal Control
3. Confidentiality
✓ Internal auditors must respect and protect the value of information they obtain.
✓ They should not disclose information without proper authority or use it for personal gain.
4. Competency
✓ Internal auditors must apply knowledge, skills, and experience in performing their duties.
✓ They must continuously improve their professional proficiency.
Conformance in Practice
To conform to the Code of Ethics, internal auditors must:
✓ Apply the four principles in every audit engagement.
✓ Avoid any situation that compromises independence or objectivity.
✓ Report all findings honestly, even under pressure from management.
✓ Engage in continuous learning to maintain professional competence.
Failure to conform may lead to:
✓ Loss of professional certification (e.g., CIA).
✓ Disciplinary action by the IIA or the organization.
✓ Reputational damage and loss of trust.
Conformance to the IIA’s Code of Ethics ensures that internal auditors remain trusted advisors and guardians of
integrity within organizations. By practicing integrity, objectivity, confidentiality, and competency, auditors protect
organizational value and strengthen good governance.
D. ELEMENTS OF QUALITY ASSURANCE AND IMPROVEMENT PROGRAMS (QAIP)
The Quality Assurance and Improvement Program (QAIP) is a framework established by the Institute of Internal
Auditors (IIA) to ensure that internal audit activities maintain quality, effectiveness, and continuous
improvement.
The program is designed to provide reasonable assurance that internal auditing:
1. Conforms with the IIA Standards and Code of Ethics.
2. Operates in a manner that is efficient and effective.
3. Adds value to the organization by improving its governance, risk management, and internal control
processes.
Key Elements of QAIP
1. Ongoing Monitoring
✓ Continuous, day-to-day supervision and review of internal audit activities.
✓ Ensures audit work complies with standards, policies, and procedures.
2. Periodic Internal Assessments
✓ Conducted periodically by members of the internal audit team who are not directly involved in the
engagement.
✓ Focused on identifying strengths and areas for improvement.
3. External Assessments
✓ Independent evaluation conducted by qualified, external professionals or organizations.
✓ Required at least once every five years under the IIA Standards.
✓ Ensures credibility, independence, and compliance with global best practices.
4. Reporting of Results
✓ QAIP findings should be communicated to senior management and the board (or audit committee).
✓ Reports highlight the degree of conformance, strengths, and areas needing improvement.
5. Continuous Improvement
✓ QAIP is not just about compliance but about raising the quality of audit practices over time.
✓ Improvements may include staff training, adopting new audit tools, or refining methodologies.
Why QAIP Matters
✓ Ensures internal audit remains credible, objective, and reliable.
✓ Builds trust with stakeholders, including boards, regulators, and members.
✓ Promotes a culture of excellence and learning within the audit function.
Prepared by: DEMY N. CODNITA, CPA
First Semester AY 2025-2026
Page 3 of 5
Governance, Business Ethics, Risk Management and Internal Control
✓ Aligns internal audit with global professional standards.
E. ROLE OF INTERNAL AUDIT IN GOVERNANCE, RISK MANAGEMENT, AND INTERNAL CONTROL
Internal audit is more than just an activity of checking financial transactions—it is a strategic partner of the
organization. Its role is to provide independent, objective assurance and advisory services that help improve the
effectiveness of governance, risk management, and internal control (GRC) processes.
1. Role in Governance
➢ Governance refers to the framework of rules, practices, and processes through which an organization is
directed and controlled.
➢ Internal audit strengthens governance by ensuring:
✓ Transparency – verifying accuracy and reliability of reports presented to stakeholders.
✓ Accountability – checking that management and employees follow established policies.
✓ Ethical conduct – ensuring compliance with the organization’s code of ethics and values.
2. Role in Risk Management
➢ Risk management is the process of identifying, assessing, and responding to risks that may hinder the
achievement of objectives.
➢ Internal audit provides independent assurance that:
✓ Significant risks are identified and assessed.
✓ Controls are in place to mitigate risks.
✓ Risk responses (avoidance, mitigation, transfer, or acceptance) are effective.
➢ Internal auditors may also act as advisors, helping management improve risk identification and monitoring.
3. Role in Internal Control
➢ Internal control refers to the systems, rules, and procedures designed to ensure reliable reporting,
safeguard assets, and ensure compliance.
➢ Internal audit’s role is to:
✓ Evaluate the adequacy and effectiveness of controls.
✓ Test whether controls are working as intended.
✓ Recommend improvements when weaknesses are found.
F. ELEMENTS OF FRAUD
Fraud is a deliberate act of deception carried out to secure unfair or unlawful gain. In the context of governance,
risk management, and internal control, understanding the elements of fraud is essential because it helps
organizations design effective preventive and detective controls.
A widely used framework for analyzing fraud is the Fraud Triangle, developed by criminologist Donald Cressey. It
explains why individuals commit fraud by identifying three key elements:
1. Pressure (Incentive or Motivation)
➢ This refers to the reason or motivation that drives a person to commit fraud.
➢ It often involves financial difficulties, lifestyle demands, or workplace pressures.
Examples of pressure:
✓ Personal debts or financial hardship.
✓ Pressure to meet sales or performance targets.
✓ Addiction problems (e.g., gambling, substance abuse).
2. Opportunity
➢ Opportunity exists when an individual sees a weakness in internal controls or oversight that allows fraud
to occur without being detected.
➢ Even if a person feels financial pressure, fraud will not happen unless there is an opportunity.
Examples of opportunity:
✓ Lack of segregation of duties (e.g., one person handles both cash receipts and recording).
✓ Weak supervision or absence of monitoring.
✓ Inadequate audit trails or documentation.
Prepared by: DEMY N. CODNITA, CPA
First Semester AY 2025-2026
Page 4 of 5
Governance, Business Ethics, Risk Management and Internal Control
3. Rationalization (Justification)
➢ This refers to the way individuals justify or excuse their fraudulent behavior to themselves.
➢ People convince themselves that their actions are acceptable, temporary, or harmless.
Examples of rationalization:
✓ “I deserve this because I am underpaid.”
✓ “I’m just borrowing the money; I’ll return it later.”
✓ “The company won’t notice this small amount.”
Other Models of Fraud
While the Fraud Triangle is the most common, other models expand the concept:
✓ Fraud Diamond – adds a fourth element: Capability (skills, position, or access to commit and conceal fraud).
✓ Fraud Pentagon – adds Arrogance and Competence, recognizing personality traits and skills that influence
fraudulent behavior.
Prepared by: DEMY N. CODNITA, CPA
First Semester AY 2025-2026
Page 5 of 5