Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 32 pages
Summary

Summary AUI NOTES

Document preview thumbnail
Preview 4 out of 32 pages

AUI3701 Summarised notes

Content preview

AUI3702 2019

Topic 1: IPPF requirements and guidance for performing tests of controls

Code of ethics & The rules of conduct
The purpose of the IIA Code of Ethics is to promote an ethical culture in the internal audit profession.
Internal auditors should strive to comply with these principles to earn the trust of those who rely on
their services.
• Integrity
o Perform work with honesty, diligence and responsibility
o Observe the law and make disclosures expected by law or the profession
o Not be part of illegal activity or acts discreditable to the profession or the organisation
o Respect and contribute to legitimate and ethical objectives of the organisation
• Objectivity
o Not participate in any activity or relationship which may impair unbiased assessment or which
is in conflict with the interests of the organisation
o Not accept anything which may impair professional judgement
o Disclose all known material facts that, if not disclosed, may distort the reporting of activities
under review
• Confidentiality
o Be prudent in the use and protection of information acquired
o Not use any information for personal gain and/or that is contrary to the law or detrimental to
the organisation
• Competency
o Engage only in those services for which they have the necessary knowledge, skills and
experience
o Perform internal audit services in accordance with the Standards
o Continually improve proficiency and the effectiveness and quality of services

INTERNATIONAL STANDARDS FOR THE PROFESSIONAL PRACTICE OF INTERNAL AUDITING
The Standards are mandatory requirements consisting of:
• statements of basic requirements for the professional practice of internal auditing and for
evaluating the effectiveness of its performance which are internationally applicable at
organisational and individual levels
• interpretations, which clarify terms or concepts within the statements
The purpose of the Standards is to
• delineate basic principles that represent the practice of internal auditing
• provide a framework for performing and promoting a broad range of value-added internal auditing
services
• establish the basis for the evaluation of internal audit performance
• foster improved organisational process and operations

The difference between attribute and performance standards is that attribute standards cover the
attributes of organisations and individuals performing internal auditing while performance standards
describe the nature of internal auditing and provide quality criteria against which the performance of
these services can be measured.
ATTRIBUTE STANDARDS
1000 – Purpose, Authority and Responsibility
1100 – Independence and Objectivity
1200 – Proficiency and Due Professional Care
1300 – Quality Assurance and Improvement Program
The key concepts to focus on when studying the Attribute Standards are
• the internal audit charter
• assurance and consulting services
• organisational independence
• individual objectivity
• proficiency
• due professional care
• ongoing monitoring
• using the statement “Conforms with the International standards for the Professional Practice
of Internal Auditing”


1

, AUI3702 2019
PERFORMANCE STANDARDS
2000 – Managing the Internal Audit Activity
2100 – Nature of Work
2200 – Engagement Planning
2300 – Performing the Engagement
2400 – Communicating Results
2500 – Monitoring Progress
2600 – Resolution of Senior Management’s Acceptance of Risks
The key concepts to focus on when studying the Performance Standards are
• adding value
• effectively managing the internal audit activity
• risk-based planning
• resource management
• coordination of activities with other assurance providers
• using a systematic and disciplined approach
• assessing and improving governance processes
• evaluating and improving risk management processes
• assist in maintaining effective controls
• engagement planning
• establishing engagement objectives
• engagement scope
• resources allocation
• work programmes
• identifying sufficient, reliable, relevant and useful information
• analysing and evaluating engagement results
• documenting information
• supervision
• communicating results
• disseminating results
• monitoring progress
• resolution of senior management’s acceptance of risks

Attribute standards:
Concept Standard Interpretation/Implementation
The internalaudit 1000 •The internalaudit charter should clearly state the internal
charter auditor’s responsibility and authority to conduct tests
ofcontrols within the organisation.•The charter should
authorise access to records,personneland physical
properties relevant to performing tests of controls.•Iftests of
controls resultinassurances to be provided to partiesoutside
the organisation, thecharter must define the nature of these
assurances.
Assurance& 1000 •The nature of assurance and consulting services
consultingservices involving tests of controls should be defined in
thecharter.(For a betterunderstanding of the difference
between assurance and consulting services, read the
section “Assurance and Consulting Services”in Reding et al,
chapter 2.)
Organisational 1110 •When testing controls, the internal audit activity must be
independence free from interference when determining the scope ofsuch
testing, the procedures applied to do the testing and
communicating the results of such testing.•To accomplish
this,the chief internal auditor should report to a levelwithin
the organisation that allows the internalaudit function to
accomplish its responsibilitiesand have direct interaction
with the board and auditcommittee.
Individualobjectivity 1120 •An internal auditor should have no conflicting intereststhat
may influence or mayappear to be influencing hisor her
ability to performtests of controls objectively.

2

, AUI3702 2019

Impairment to 1130 •If independence or objectivity isimpaired in fact
independence orappearance, the details of the impairment (i.e.
and/orobjectivity conflictofinterest, scope limitation, restriction on access to
records, personneland propertiesand resource limitations)
must be disclosed to appropriate parties.•Internal auditors
must refrain from performing tests ofcontrols as part of
assurance engagements in areastheywere previously
responsible for–atleast forone year.
Proficiency 1210
• Internal audit activities and individual internal auditors
involved in the testing of controls should possess the
knowledge, skills and other competencies needed to
conduct tests of controls.
• Practice Advisory 1210-1 elaborates on the proficiency
requirements for internal auditors.
• Where an internal audit activity lacks competencies to
conduct a specific assurance engagement, the
competencies should be obtained elsewhere.
• Internal auditors must have sufficient knowledge to
evaluate the risk of fraud when performing tests of controls.
• Internal auditors should have sufficient knowledge of key
information technology risks and controls and available
technology-based audit techniques to perform their
assigned work.

Due professional care 1220
• When performing tests of controls, the internal auditor
should exercise due professional care by considering the
- extent of work needed to achieve the engagement’s
objectives
- relative complexity, materiality or significance of matters to
which testing procedures are applied
- adequacy and effectiveness of governance, risk
management and control processes
- probability of significant errors, fraud or non-compliance
- cost of controls/assurance provided in relation to the
potential benefit
• When performing tests of controls the internal auditor
must consider the use of technology-based audit and other
data analysis techniques.
• Internal auditors must be alert to potential risks that might
affect objectives, operations or resources when testing
controls.
• When performing tests of controls as part of a consulting
engagement, internal auditors should consider
- the needs and expectations of clients, including the
nature, timing, and communication of engagement results
- relative complexity and extent of work needed to achieve
the engagement’s objectives
- cost of the consulting engagement in relation to potential
benefits

1311 • Tests of controls should be subjected to ongoing
monitoring which should form an integral part of the day-to-
day supervision, review, and measurement of the internal
audit activity.




3

, AUI3702 2019

Using the statement: 1340 • When reporting the results of an audit of controls, the
“Conforms with the auditor may only state that the audit was performed in
International conformance with the Standards if the results of the quality
standards for the assurance and improvement programme support this
Professional statement.
Practice of Internal
Auditing”

Performance standards:
Concept Standard Interpretation/Implementation
Risk based planning 2010 Test of control audits should form part of the internal audit
activity’s risk-based plans. In developing a risk-based plan
for the internal audit activity, the CAE takes into account the
organisation’s risk management framework, including using
risk appetite levels set by management for the different
activities or parts of the organisation.
Coordination of 2050 The internal auditors should share information and
activities with other coordinate activities with regard to control testing with other
assurance providers internal and external assurance providers and consulting
services to ensure proper coverage and minimise duplication
of efforts.
Using a systematic 2100 The internal audit activity must use a systematic and
and disciplined disciplined approach when performing tests of controls. This
approach approach will be discussed in more detail in topic 3 of this
module.
Assessing and 2110 Where deemed necessary the internal audit function will
improving governance perform tests of controls to assess and make
processes recommendations that will improve the organisation’s
governance processes. In doing this the internal audit activity
aims to
- promote appropriate ethics and values within the
organisation
- ensure effective organisational performance management
and accountability
- communicate risk and control information to appropriate
areas of the organisation and
- coordinate the activities of and communicate information
among the board, external and internal auditors and
management
Evaluating and 2120 Where deemed necessary the internal audit function will
improving risk perform tests of controls to assess and make
management recommendations that will improve the organisation’s risk
processes management process. In performing these tests the internal
audit activity will assess whether or not the
- organisational objectives support and align with the
organisation’s mission
- significant risks are identified and assessed
- appropriate risk responses are selected that align risks with
the organisation’s risk appetite
- relevant risk information is captured and communicated in a
timely manner across the organisation, enabling staff,
management and the board to carry out their responsibilities
Assisting in 2130 Where deemed necessary the internal audit function will
maintaining effective perform tests of controls to help the organisation maintain
controls effective controls by evaluating their effectiveness and
efficiency and by promoting continuous improvement. To this
effect, the internal audit activity evaluates risk exposures and
evaluates the design adequacy and operating effectiveness
of controls regarding the
- reliability and integrity of financial and operational

4

Document information

Uploaded on
August 5, 2019
Number of pages
32
Written in
2019/2020
Type
Summary
$5.17

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Anikapretorious
3.7
(126)
Sold
993
Followers
854
Items
469
Last sold
10 months ago

Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions