SlideShare una empresa de Scribd logo
1 de 19
Information Technology
Audit
Business Practice Training
Sean D. Obi, CISA, CISM, PMP
IT Audit | IT Risk | IT Compliance
Understanding basic approaches towards Information Technology
review
@seanpizzie
1
www.techembro.com
@techembro
Internal Audit - Introduction
 Internal auditing is an independent, objective assurance and
consulting activity designed to add value and improve an
organization's operations. It helps an organization accomplish its
objectives by bringing a systematic, disciplined approach to evaluate
and improve the effectiveness of risk management, control, and
governance processes.
 The internal audit program provides assurance that internal controls
in place are adequate to mitigate risks, governance processes are
effective and efficient, and organizational goals and objectives are
being met.
@seanpizzie 2
www.techembro.com
@techembro
Internal Audit – Introduction (Cont’d)
 Internal auditing bridges the gap between management and the
executive leadership or the board of an agency; assesses the ethical
climate and the effectiveness and efficiency of operations; and serves
as an organization’s safety net for compliance with rules, regulations,
and overall best business practices.
 Internal audits are performed by professionals employed by the
agency who have an in-depth understanding of the business culture,
systems, and processes.
 The internal audit function is an integral part of the agency and
derives its authority from senior management. It serves to promote
objective, comprehensive review coverage, and to assure the
consideration of audit recommendations.
@seanpizzie 3
www.techembro.com
@techembro
Internal Audit – Introduction (Cont’d)
 The chief audit executive (CAE) is the person within an agency with
overall responsibility for the internal audit program. The CAE is
responsible for developing the internal audit charter, staffing,
administering, and managing the internal audit program to ensure it
operates in accordance with professional standards and adds value to
the organization. The CAE reports to the agency director or board
significant nonconformance of professional standards that impacts the
overall scope or operation of the internal audit program.
 Depending on an agency’s governance structure, an audit
committee may be used to help the agency review, monitor, and/or
direct the agency’s activities related to maintaining effective internal
control. An agency audit committee could also improve financial
practices and reporting, and enhance both the internal and external
audit functions.@seanpizzie 4
www.techembro.com
@techembro
Internal Audit – Introduction (Cont’d)
 The internal auditor or other professionals (internal or external to the
agency) may provide assurance and advisory support to management
in areas such as developing appropriate procedures to conduct risk
assessments and internal reviews of control activities.
 External auditors are not part of an agency’s internal audit program
and cannot be a replacement for or supplement to an adequate
internal audit program. The role of the external auditor is to provide
independent accountability and assurance to the public and external
stakeholders. However, this independent assurance is also valuable
feedback to those charged with governance and agency management.
@seanpizzie 5
www.techembro.com
@techembro
Professional audit standards
 The internal audit program must conform to either the International
Standards for the Professional Practice of Internal Auditing and Code
of Ethics (IIA Red Book), Generally Accepted Government Auditing
Standards (GAO Yellow Book), or both.
 Regardless of which set of standards are adopted, the internal
auditing program should adhere to the following core principles and
mandatory attributes of internal auditing.
@seanpizzie 6
www.techembro.com
@techembro
Professional audit standards
Core principles
 Demonstrates integrity
 Demonstrates quality and continuous improvement
 Demonstrates competence and due professional care
 Communicates effectively
 Is objective and free from undue influence
 Provides risk-based assurance
 Aligns with the strategies, objectives, and risks of the organization
 Is insightful, proactive, and future-focused
 Is appropriately positioned and adequately resourced
 Promotes organizational improvement
@seanpizzie
7
www.techembro.com
@techembro
Professional audit standards
Common mandatory attributes
 Organizational independence
 Individual objectivity
 Proficiency and due professional care
 Quality assurance and improvement program
@seanpizzie
8
www.techembro.com
@techembro
Internal and external auditors
As an integral part of the organization, internal auditors possess an in-
depth understanding of the agency’s culture, operations, strategies, and
risks. External auditors gain an understanding of operations only as
needed to inform their specific audit.
Some key differences between internal and external auditing to consider
in coordinating efforts include:
Internal audit
 Staffed by employees or contractors of the agency.
 Mandated to provide assurance and advice to senior management (and
board, if applicable) to improve the state of governance, risk
management, and control within the agency.
 Focused on all functions and operations of the agency.
 Required to meet audit standards for organizational independence.
 Provide continuous services to management.
@seanpizzie 9
www.techembro.com
@techembro
Internal and external auditors
External audit
 Staffed by employees or contractors of the external audit
organization.
 Mandated by authorizing law, rule, or other authority to provide
assurance to external stakeholders (the public, legislature,
federal regulators, etc.) on the accuracy of agency reports,
compliance with laws and rules, and efficiency of operations.
 Focused on areas stipulated by statute, rule, or authority.
 Independent of the agency.
 Audits may be intermittent or routine such as the end of a
fiscal period or grant period.
@seanpizzie 10
www.techembro.com
@techembro
Components of an Internal Audit Charter
What is an Audit Charter?
Internal audit functions play a vital role in providing assurance of an
organization’s risk management practices and protecting and
enhancing organizational value.
The internal audit charter is a formal document that clearly defines
and articulates “marching orders” for the internal audit function from
the governing body (typically the audit committee) and management.
It should be reviewed and approved by the governing body on an
annual basis. The charter must define, at minimum, the following
items:
@seanpizzie 11
www.techembro.com
@techembro
Components of an Internal Audit Charter
“Cont’d”
 Internal audit’s purpose within the organization
 Internal audit’s authority
 Internal audit’s responsibility
 Internal audit’s position within the organization
The charter provides a blueprint for how internal audit will operate and
allows the governing body to emphasize the value it places on the
independence of the internal audit function. The charter establishes this
independence by defining reporting lines from the Chief Audit Executive
(CAE) to the governing body and, administratively, to executive
management.
@seanpizzie 12
www.techembro.com
@techembro
Vital Components of an Audit Charter
the IIA identified seven vital components that support the overall
strength and effectiveness of the internal audit function and should
be included in the internal audit charter:
1. Mission and Purpose
The charter should define both the mission and the purpose of the
internal audit function. The mission should be to enhance and protect
organizational value by providing risk-based and objective assurance,
advice, and insight. Internal audit’s independent and objective assurance
and consulting services should be designed to add value and improve the
organization’s operations.
@seanpizzie 13
www.techembro.com
@techembro
Vital Components of an Audit Charter
2. Adherence to the International Standards for the Professional
Practice of Internal Auditing
The charter should include details about how the internal audit function
governs itself and how it adheres to the IIA’s International Professional
Practices Framework (IPPF), including:
 Standards
 Core principles for the professional practice of internal auditing
 Definition of internal auditing
 Code of ethics
@seanpizzie
14
www.techembro.com
@techembro
Vital Components of an Audit Charter
3. Authority
The charter should define the CAE’s functional and administrative
reporting relationship in the organization as noted above. In addition, a
statement should be included affirming that the governing body will
establish, maintain, and assure that the internal audit function has
sufficient authority to fulfill its duties.
@seanpizzie 15
www.techembro.com
@techembro
Vital Components of an Audit Charter
4. Independence and Objectivity
The charter should state that the CAE will ensure independence and
objectivity of the internal audit function to carry out its duties in an
unbiased manner. Furthermore, internal audit should have no direct
operational responsibility or authority over any of the activities
audited.
@seanpizzie 16
www.techembro.com
@techembro
Vital Components of an Audit Charter
5. Scope of Internal Audit Activities
The charter should define the scope of the internal audit function.
The scope should include providing independent assessments of the
adequacy and effectiveness of governance, risk management, and
control processes.
@seanpizzie 17
www.techembro.com
@techembro
Vital Components of an Audit Charter
6. Responsibility
The responsibility of the internal audit function should also be described
in the charter and the following should be performed at least annually:
 Verification that the internal audit function is fulfilling its mandate
 Assurance of compliance with IIA standards
 Communication of the results of its work and follow up of agreed
corrective actions
@seanpizzie 18
www.techembro.com
@techembro
Vital Components of an Audit Charter
7. Quality Assurance and Improvement Program
The charter should define the internal audit’s Quality Assurance and
Improvement Program (QAIP), which covers all aspects of the internal
audit function including:
 Evaluation of conformance to IIA Standards and requirement to report
the results of its QAIP periodically to senior management and the
governing body
 An external assessment of the activity at least once every five years
@seanpizzie 19
www.techembro.com
@techembro

Más contenido relacionado

La actualidad más candente

MEASURING INTERNAL AUDIT PERFORMANCE
MEASURING INTERNAL AUDIT PERFORMANCEMEASURING INTERNAL AUDIT PERFORMANCE
MEASURING INTERNAL AUDIT PERFORMANCE
bbongio
 
Control interno-auditoria - copia
Control interno-auditoria - copiaControl interno-auditoria - copia
Control interno-auditoria - copia
MARSHY LABK
 

La actualidad más candente (20)

Introduction to internal auditing
Introduction to internal auditingIntroduction to internal auditing
Introduction to internal auditing
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
 
Internal control and Control Self Assessment
Internal control and Control Self AssessmentInternal control and Control Self Assessment
Internal control and Control Self Assessment
 
eeeeeEjemplo practico de auditoria informática
eeeeeEjemplo practico de auditoria informáticaeeeeeEjemplo practico de auditoria informática
eeeeeEjemplo practico de auditoria informática
 
Internal audit ppt
Internal audit  pptInternal audit  ppt
Internal audit ppt
 
Basic internal auditing
Basic internal auditingBasic internal auditing
Basic internal auditing
 
Risk based internal auditing
 Risk based internal auditing Risk based internal auditing
Risk based internal auditing
 
MEASURING INTERNAL AUDIT PERFORMANCE
MEASURING INTERNAL AUDIT PERFORMANCEMEASURING INTERNAL AUDIT PERFORMANCE
MEASURING INTERNAL AUDIT PERFORMANCE
 
Audit & compliance
Audit & complianceAudit & compliance
Audit & compliance
 
Internal audit department
Internal audit departmentInternal audit department
Internal audit department
 
Basic Internal Auditing Presentation
Basic Internal Auditing PresentationBasic Internal Auditing Presentation
Basic Internal Auditing Presentation
 
Steps in it audit
Steps in it auditSteps in it audit
Steps in it audit
 
CURSO DE AUDITORIA RESUMEN
CURSO DE AUDITORIA RESUMENCURSO DE AUDITORIA RESUMEN
CURSO DE AUDITORIA RESUMEN
 
Compliance audit
Compliance auditCompliance audit
Compliance audit
 
Steps for setting up Internal Audit Function / Department in Small / Medium S...
Steps for setting up Internal Audit Function / Department in Small / Medium S...Steps for setting up Internal Audit Function / Department in Small / Medium S...
Steps for setting up Internal Audit Function / Department in Small / Medium S...
 
Matriz de riesgos formato (Auditoria informática)
Matriz de riesgos formato (Auditoria informática)Matriz de riesgos formato (Auditoria informática)
Matriz de riesgos formato (Auditoria informática)
 
16 planeacion estrategicaseguridad
16 planeacion estrategicaseguridad16 planeacion estrategicaseguridad
16 planeacion estrategicaseguridad
 
Ppt on risk based internal audit
Ppt on risk based internal auditPpt on risk based internal audit
Ppt on risk based internal audit
 
Control interno-auditoria - copia
Control interno-auditoria - copiaControl interno-auditoria - copia
Control interno-auditoria - copia
 
An introduction to internal auditing
An introduction to internal auditingAn introduction to internal auditing
An introduction to internal auditing
 

Similar a Overview of Internal Audit

Applicability of internal audit capsule on ia program good
Applicability of internal audit capsule on ia program goodApplicability of internal audit capsule on ia program good
Applicability of internal audit capsule on ia program good
SARVJEET KAUSHAL
 
The Objectives Of Internal Audit
The Objectives Of Internal AuditThe Objectives Of Internal Audit
The Objectives Of Internal Audit
Sonia Sanchez
 
Internal Audit Of The California Department Of Public...
Internal Audit Of The California Department Of Public...Internal Audit Of The California Department Of Public...
Internal Audit Of The California Department Of Public...
Tina Jordan
 
319155985-project-report-on-a-CA-firm (1).pdf
319155985-project-report-on-a-CA-firm (1).pdf319155985-project-report-on-a-CA-firm (1).pdf
319155985-project-report-on-a-CA-firm (1).pdf
InfantRagulD
 
Designing Effective Financial Controls
Designing Effective Financial ControlsDesigning Effective Financial Controls
Designing Effective Financial Controls
Stephen G. Lynch
 

Similar a Overview of Internal Audit (20)

The Internal Audit Framework
The Internal Audit FrameworkThe Internal Audit Framework
The Internal Audit Framework
 
Applicability of internal audit capsule on ia program good
Applicability of internal audit capsule on ia program goodApplicability of internal audit capsule on ia program good
Applicability of internal audit capsule on ia program good
 
vdocuments.mx_cia-part-1-slides.ppt
vdocuments.mx_cia-part-1-slides.pptvdocuments.mx_cia-part-1-slides.ppt
vdocuments.mx_cia-part-1-slides.ppt
 
Internal Audit
Internal AuditInternal Audit
Internal Audit
 
Frequently asked questions on auditing in dubai
Frequently asked questions on auditing in dubaiFrequently asked questions on auditing in dubai
Frequently asked questions on auditing in dubai
 
The Objectives Of Internal Audit
The Objectives Of Internal AuditThe Objectives Of Internal Audit
The Objectives Of Internal Audit
 
Internal auditing for “one & all” (second edition)
Internal auditing for “one & all” (second edition)Internal auditing for “one & all” (second edition)
Internal auditing for “one & all” (second edition)
 
Basics of internal audit
Basics of internal auditBasics of internal audit
Basics of internal audit
 
Fice Of Internal Audit
Fice Of Internal AuditFice Of Internal Audit
Fice Of Internal Audit
 
UBL AUDITING DUBAI
UBL AUDITING DUBAIUBL AUDITING DUBAI
UBL AUDITING DUBAI
 
Value based internal auditing - Nilai Dasar Internal Audit
Value based internal auditing - Nilai Dasar Internal AuditValue based internal auditing - Nilai Dasar Internal Audit
Value based internal auditing - Nilai Dasar Internal Audit
 
CIA part 1 essentials of internal auditing
CIA part 1 essentials of internal auditingCIA part 1 essentials of internal auditing
CIA part 1 essentials of internal auditing
 
Risk based auditing
Risk based auditingRisk based auditing
Risk based auditing
 
Internal Audit Of The California Department Of Public...
Internal Audit Of The California Department Of Public...Internal Audit Of The California Department Of Public...
Internal Audit Of The California Department Of Public...
 
Tyco Internal Audit Case Study
Tyco Internal Audit Case StudyTyco Internal Audit Case Study
Tyco Internal Audit Case Study
 
Internal Audit Project
Internal Audit ProjectInternal Audit Project
Internal Audit Project
 
Auditing.docx
Auditing.docxAuditing.docx
Auditing.docx
 
319155985-project-report-on-a-CA-firm (1).pdf
319155985-project-report-on-a-CA-firm (1).pdf319155985-project-report-on-a-CA-firm (1).pdf
319155985-project-report-on-a-CA-firm (1).pdf
 
Outsourced Internal Audits in Dubai.pptx
Outsourced Internal Audits in Dubai.pptxOutsourced Internal Audits in Dubai.pptx
Outsourced Internal Audits in Dubai.pptx
 
Designing Effective Financial Controls
Designing Effective Financial ControlsDesigning Effective Financial Controls
Designing Effective Financial Controls
 

Último

An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
SanaAli374401
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
QucHHunhnh
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
QucHHunhnh
 

Último (20)

Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
Measures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SDMeasures of Dispersion and Variability: Range, QD, AD and SD
Measures of Dispersion and Variability: Range, QD, AD and SD
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
1029-Danh muc Sach Giao Khoa khoi 6.pdf
1029-Danh muc Sach Giao Khoa khoi  6.pdf1029-Danh muc Sach Giao Khoa khoi  6.pdf
1029-Danh muc Sach Giao Khoa khoi 6.pdf
 
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
SECOND SEMESTER TOPIC COVERAGE SY 2023-2024 Trends, Networks, and Critical Th...
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Advance Mobile Application Development class 07
Advance Mobile Application Development class 07Advance Mobile Application Development class 07
Advance Mobile Application Development class 07
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docx
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 

Overview of Internal Audit

  • 1. Information Technology Audit Business Practice Training Sean D. Obi, CISA, CISM, PMP IT Audit | IT Risk | IT Compliance Understanding basic approaches towards Information Technology review @seanpizzie 1 www.techembro.com @techembro
  • 2. Internal Audit - Introduction  Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.  The internal audit program provides assurance that internal controls in place are adequate to mitigate risks, governance processes are effective and efficient, and organizational goals and objectives are being met. @seanpizzie 2 www.techembro.com @techembro
  • 3. Internal Audit – Introduction (Cont’d)  Internal auditing bridges the gap between management and the executive leadership or the board of an agency; assesses the ethical climate and the effectiveness and efficiency of operations; and serves as an organization’s safety net for compliance with rules, regulations, and overall best business practices.  Internal audits are performed by professionals employed by the agency who have an in-depth understanding of the business culture, systems, and processes.  The internal audit function is an integral part of the agency and derives its authority from senior management. It serves to promote objective, comprehensive review coverage, and to assure the consideration of audit recommendations. @seanpizzie 3 www.techembro.com @techembro
  • 4. Internal Audit – Introduction (Cont’d)  The chief audit executive (CAE) is the person within an agency with overall responsibility for the internal audit program. The CAE is responsible for developing the internal audit charter, staffing, administering, and managing the internal audit program to ensure it operates in accordance with professional standards and adds value to the organization. The CAE reports to the agency director or board significant nonconformance of professional standards that impacts the overall scope or operation of the internal audit program.  Depending on an agency’s governance structure, an audit committee may be used to help the agency review, monitor, and/or direct the agency’s activities related to maintaining effective internal control. An agency audit committee could also improve financial practices and reporting, and enhance both the internal and external audit functions.@seanpizzie 4 www.techembro.com @techembro
  • 5. Internal Audit – Introduction (Cont’d)  The internal auditor or other professionals (internal or external to the agency) may provide assurance and advisory support to management in areas such as developing appropriate procedures to conduct risk assessments and internal reviews of control activities.  External auditors are not part of an agency’s internal audit program and cannot be a replacement for or supplement to an adequate internal audit program. The role of the external auditor is to provide independent accountability and assurance to the public and external stakeholders. However, this independent assurance is also valuable feedback to those charged with governance and agency management. @seanpizzie 5 www.techembro.com @techembro
  • 6. Professional audit standards  The internal audit program must conform to either the International Standards for the Professional Practice of Internal Auditing and Code of Ethics (IIA Red Book), Generally Accepted Government Auditing Standards (GAO Yellow Book), or both.  Regardless of which set of standards are adopted, the internal auditing program should adhere to the following core principles and mandatory attributes of internal auditing. @seanpizzie 6 www.techembro.com @techembro
  • 7. Professional audit standards Core principles  Demonstrates integrity  Demonstrates quality and continuous improvement  Demonstrates competence and due professional care  Communicates effectively  Is objective and free from undue influence  Provides risk-based assurance  Aligns with the strategies, objectives, and risks of the organization  Is insightful, proactive, and future-focused  Is appropriately positioned and adequately resourced  Promotes organizational improvement @seanpizzie 7 www.techembro.com @techembro
  • 8. Professional audit standards Common mandatory attributes  Organizational independence  Individual objectivity  Proficiency and due professional care  Quality assurance and improvement program @seanpizzie 8 www.techembro.com @techembro
  • 9. Internal and external auditors As an integral part of the organization, internal auditors possess an in- depth understanding of the agency’s culture, operations, strategies, and risks. External auditors gain an understanding of operations only as needed to inform their specific audit. Some key differences between internal and external auditing to consider in coordinating efforts include: Internal audit  Staffed by employees or contractors of the agency.  Mandated to provide assurance and advice to senior management (and board, if applicable) to improve the state of governance, risk management, and control within the agency.  Focused on all functions and operations of the agency.  Required to meet audit standards for organizational independence.  Provide continuous services to management. @seanpizzie 9 www.techembro.com @techembro
  • 10. Internal and external auditors External audit  Staffed by employees or contractors of the external audit organization.  Mandated by authorizing law, rule, or other authority to provide assurance to external stakeholders (the public, legislature, federal regulators, etc.) on the accuracy of agency reports, compliance with laws and rules, and efficiency of operations.  Focused on areas stipulated by statute, rule, or authority.  Independent of the agency.  Audits may be intermittent or routine such as the end of a fiscal period or grant period. @seanpizzie 10 www.techembro.com @techembro
  • 11. Components of an Internal Audit Charter What is an Audit Charter? Internal audit functions play a vital role in providing assurance of an organization’s risk management practices and protecting and enhancing organizational value. The internal audit charter is a formal document that clearly defines and articulates “marching orders” for the internal audit function from the governing body (typically the audit committee) and management. It should be reviewed and approved by the governing body on an annual basis. The charter must define, at minimum, the following items: @seanpizzie 11 www.techembro.com @techembro
  • 12. Components of an Internal Audit Charter “Cont’d”  Internal audit’s purpose within the organization  Internal audit’s authority  Internal audit’s responsibility  Internal audit’s position within the organization The charter provides a blueprint for how internal audit will operate and allows the governing body to emphasize the value it places on the independence of the internal audit function. The charter establishes this independence by defining reporting lines from the Chief Audit Executive (CAE) to the governing body and, administratively, to executive management. @seanpizzie 12 www.techembro.com @techembro
  • 13. Vital Components of an Audit Charter the IIA identified seven vital components that support the overall strength and effectiveness of the internal audit function and should be included in the internal audit charter: 1. Mission and Purpose The charter should define both the mission and the purpose of the internal audit function. The mission should be to enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight. Internal audit’s independent and objective assurance and consulting services should be designed to add value and improve the organization’s operations. @seanpizzie 13 www.techembro.com @techembro
  • 14. Vital Components of an Audit Charter 2. Adherence to the International Standards for the Professional Practice of Internal Auditing The charter should include details about how the internal audit function governs itself and how it adheres to the IIA’s International Professional Practices Framework (IPPF), including:  Standards  Core principles for the professional practice of internal auditing  Definition of internal auditing  Code of ethics @seanpizzie 14 www.techembro.com @techembro
  • 15. Vital Components of an Audit Charter 3. Authority The charter should define the CAE’s functional and administrative reporting relationship in the organization as noted above. In addition, a statement should be included affirming that the governing body will establish, maintain, and assure that the internal audit function has sufficient authority to fulfill its duties. @seanpizzie 15 www.techembro.com @techembro
  • 16. Vital Components of an Audit Charter 4. Independence and Objectivity The charter should state that the CAE will ensure independence and objectivity of the internal audit function to carry out its duties in an unbiased manner. Furthermore, internal audit should have no direct operational responsibility or authority over any of the activities audited. @seanpizzie 16 www.techembro.com @techembro
  • 17. Vital Components of an Audit Charter 5. Scope of Internal Audit Activities The charter should define the scope of the internal audit function. The scope should include providing independent assessments of the adequacy and effectiveness of governance, risk management, and control processes. @seanpizzie 17 www.techembro.com @techembro
  • 18. Vital Components of an Audit Charter 6. Responsibility The responsibility of the internal audit function should also be described in the charter and the following should be performed at least annually:  Verification that the internal audit function is fulfilling its mandate  Assurance of compliance with IIA standards  Communication of the results of its work and follow up of agreed corrective actions @seanpizzie 18 www.techembro.com @techembro
  • 19. Vital Components of an Audit Charter 7. Quality Assurance and Improvement Program The charter should define the internal audit’s Quality Assurance and Improvement Program (QAIP), which covers all aspects of the internal audit function including:  Evaluation of conformance to IIA Standards and requirement to report the results of its QAIP periodically to senior management and the governing body  An external assessment of the activity at least once every five years @seanpizzie 19 www.techembro.com @techembro