Internal Audit Basics
Exam | Short | Domain | Focus | % | Themes | Topic | Details |
---|---|---|---|---|---|---|---|
Internal Auditing Basics | Basic | 1 | Mandatory Guidance | 35-45 | Definition of Internal Auditing | 1. Define purpose, authority, and responsibility of the internal audit activity | |
Code of Ethics | 1. Abide by and promote compliance with The IIA Code of Ethics | ||||||
International Standards | 1. Comply with The IIA's Attribute Standards | a. Determine if the purpose, authority, and responsibility of the internal audit activity are documented in audit charter, approved by the Board and communicated to the engagement clients b. Demonstrate an understanding of the purpose, authority, and responsibility of the internal audit activity |
|||||
2. Maintain independence and objectivity | a. Foster independence - Understand organizational independence - Recognize the importance of organizational independence - Determine if the internal audit activity is properly aligned to achieve organizational independence |
||||||
b. Foster objectivity - Establish policies to promote objectivity - Assess individual objectivity - Maintain individual objectivity - Recognize and mitigate impairments to independence and objectivity |
|||||||
3. Determine if the required knowledge, skills, and competencies are available | a. Understand the knowledge, skills, and competencies that an internal auditor needs to possess b. Identify the knowledge, skills, and competencies required to fulfill the responsibilities of the internal audit activity |
||||||
4. Develop and/or procure necessary knowledge, skills and competencies collectively required by the internal audit activity | - | ||||||
5. Exercise due professional care | - | ||||||
6. Promote continuing professional development | a. Develop and implement a plan for continuing professional development for internal audit staff b. Enhance individual competency through continuing professional development |
||||||
7. Promote quality assurance and improvement of the internal audit activity | a. Monitor the effectiveness of the quality assurance and improvement program b. Report the results of the quality assurance and improvement program to the board or other governing body c. Conduct quality assurance procedures and recommend improvements to the performance of the internal audit activity |
||||||
2 | Internal Control/Risk | 25-35 | Types of Controls | preventive, detective, input, output, etc. | |||
Management Control Techniques | - | - | |||||
Internal Control Framework Characteristics and Use | 1. Develop and implement an organization-wide risk and control framework | (e.g., COSO, Cadbury) | |||||
Alternative Control Frameworks | - | - | |||||
Risk Vacabulary and Concepts | - | - | |||||
Fraud Risk Awareness | 1. Types of fraud | - | |||||
2. Fraud red flags | - | ||||||
3 | Conducting Internal Audit Engagements - Audit Tools and Techniques | 25-35 | Data Gathering | Collect and analyze data on proposed engagements | 1. Review previous audit reports and other relevant documentation as part of a preliminary survey of the engagement area 2. Develop checklists/internal control questionnaires as part of a preliminary survey of the engagement area 3. Conduct interviews as part of a preliminary survey of the engagement area 4. Use observation to gather data 5. Conduct engagement to assure identification of key risks and controls 6. Sampling (non-statistical [judgmental] sampling method, statistical sampling, discovery sampling, and statistical analyses techniques) |
||
Data Analysis and Interpretation | 1. Use computerized audit tools and techniques 2. Conduct spreadsheet analysis 3. Use analytical review techniques 4. Conduct benchmarking 5. Draw conclusions |
(e.g., data mining and extraction, continuous monitoring, automated work papers, embedded audit modules) - (e.g., ratio estimation, variance analysis, budget vs. actual, trend analysis, other reasonableness tests) - - |
|||||
Data Reporting | 1. Report test results to auditor in charge 2. Develop preliminary conclusions regarding controls |
- | |||||
Documentation / Work Papers | 1. Develop work papers | - | |||||
Process Mapping | (Including Flowcharting) | - | |||||
Evaluate Relevance, Sufficiency, and Competence of Evidence | 1. Identify potential sources of evidence | - |
see also: