国际注册内部审计师实务框架1

职业道德规范
《职业道德规范》的建立对于内部审计职业必要而又适用,它是给予内部审计对风险管理、控制和治理作出的客观确认以信任的基础。

协会的《职业道德规范》延展了内部审计的定义,包括两个基本部分:
1.与内部审计职业和实务相关的原则;
2.描述内部审计师行为规范的行为规则。

这些规则有助于将上述原则运用于实践中,目
的在于指导内部审计师的道德行为。

《职业道德规范》与协会的实务框架和其他相关的公告一起,为服务于他人的内部审计师提供指导。

“内部审计师”指协会会员,IIA职业资格的获得者或申请者以及那些在内部审计定义范围内提供内部审计服务的人。

适用性与执行
《职业道德规范》既适用于提供内部审计服务的个人,也适用于提供内部审计服务的团体。

对于协会会员、IIA职业资格的获得者或申请者,违反《职业道德规范》将根据协会的规章和行政指南予以评价和管理。

在行为规则中没有提及的特殊行为,如果其无法接受或有损信誉,会员、资格获得者或申请者有责任接受纪律处罚。

原则
内部审计师应运用并信守以下原则:
1
内部审计师的公正建立信用,从而为对其判断的信任提供基础。

2
在收集、评价和沟通有关被检查的活动或过程的信息时,内部审计师展示其最大限度的职业客观。

在作出判断时,内部审计师不受其个人喜好或他人的不适当影响,对所有相关环境作出公正的评价。

3
内部审计师尊重其获取的信息的价值和所有权,没有适当授权不得披露信息,除非是在有法律或职业义务的情况下。

4
内部审计师在执行内部审计业务时能够使用所需要的知识、技能和经验。

行为规则
公正
内部审计师:
11应当诚实、勤恳并负责地开展工作。

12应当遵守法律,按照法律及职业要求进行披露。

13不得蓄意参与非法活动,或参加有损于内部审计职业或其所在组织的行为。

14应当遵守并贡献于组织的法律和道德目标。

客观
内部审计师:
21不应参与可能妨碍或被认为妨碍其公正评价的活动或关系,包括参与与组织利益相冲突的活动和关系。

22不能接受可能妨碍或被认为会妨碍其职业判断的任何物品。

23应当披露已知的,如果不予披露、可能会歪曲检查工作报告的所有重大事实。

内部审计师:
31应当谨慎利用和保护履行职责过程中获取的信息。

32不应当利用信息牟取私利,或者以任何有悖法律规定或有损组织法律和道德目标的方式使用信息。

胜任
内部审计师:
41应当只从事与其所具备的知识、技能和经验相适应的服务活动。

42应当按照《国际内部审计专业实务标准》开展内部审计服务。

43应当持续提高能力和服务的效果、质量。

合集下载

内部审计业务知识概述

内部审计业务知识概述

《标准》
标准被分为三类:属性标准、工作标准和实施标准。 属性标准反映提供内部审计服务的组织和个人的属性;(1000宗旨权利和职责;
1100独立性和客观性;1200专业能力与应有的职业谨慎;1300质量评价与改进程序) 工作标准对内部审计服务的本质进行说明,并提供了可以衡量绩效的审计服务的标
准。(2000内部审计活动管理;2100工作性质;2200业务计划;2300业务的实施; 2400结果的通报;2500监督进展;2600管理层对风险的接受) 属性标准与工作标准适用于所有的内部审计服务。 实施标准对属性标准与工作标准进行扩展,为内部审计开展确认和咨询活动的具体 业务提供标准。这些标准最终将指导解决一些具体行业、具体区域或具体审计服务 的问题。(包含在属性标准和工作标准中,标志A,C)
2. 内部审计客体
内部审计客体,其实质是指内部审计对象和 内部审计业务范围。
IIA最近发布的调查报告将内部审计职能涉及 到的活动分为三大类25项:
内部控制活动(14项) 风险管理活动(5项) 公司治理活动(6项)。
内部控制活动
合规性审计
控制系统的有效性评价 经营审计
项目管理审计
安全评价和调查
业务类
第2204号内部审计具体准则——对舞弊行为进行检 查和报告
第2203号内部审计具体准则——信息系统审计 第2202号内部审计具体准则——绩效审计(原第 25号
、第 26号、第 27号合并修订)
第2201号内部审计具体准则——内部控制审计(原来
12号【遵循性审计】、16号【风险管理审计】、21号【内部审计的控 制自我评估法】、(23%) 风险管理程序审计(20.4%) 战略和绩效的结合评价(19.9%) 道德审计(19.9%) 与国际财务报告标准(IFRS)标准接轨(

内部审计实务标准(doc 90)

内部审计实务标准(doc 90)

内部审计实务标准(doc 90)内部审计实务标准本文目录:内部审计师协会职业道德规范内审实务标准简介IIA颁布《内部审计实务标准》修订本的补充实务公告内部审计师协会职业道德规范1、基本内容2、重点难点和和疑点基本内容--------------------------------------------------------------------------------《道德规范》的目的是促进内部审计职业领域内的道德文化的发展。

国际注册内部审计师协会理事会在1999年6月通过的《道德规范》中指出:道德规范对于内部审计职业来说是必要的和适当的,因为它是建立信任的基础。

这种基础为评价和改进风险管理、控制和治理过程,帮助组织实现其目标,提供了保证。

《道德规范》既适用于提供内部审计服务的个人,也适用于提供内部审计服务的团体。

对于协会会员、IIA职业资格的接受者或参加者,对《道德规范》的违背将根据协会的规章和行政指南予以评价和管理。

2000年6月通过的新《道德规范》包括两个基本部分:一是与内部审计职业和实务相关的原则(共4条原则:正直、客观、保密、能力);二是描述内部审计师预期行为规范的行为规则(在4条原则之下共有12条行为规则)。

这些规则有助于将上述原则运用于实践中,目的在于指导内部审计师的行为。

内部审计师应使用和信守以下原则:1、正直内部审计师的正直建立起信用,从而为其判断的可靠度提供基础。

这条原则包括4条行为规则:1.1 应当诚实、勤奋并负责地完成工作。

内部审计师在工作中应使用在内部审计业务中所需要的知识、技能和经验。

这条原则包括3条行为规则:4.1 应当只从事他们具备必要的知识、技能和经验的服务活动。

4.2 应当根据《内部审计实务标准》完成内部审计。

重点、难点和疑点--------------------------------------------------------------------------------在《内部审计师职业道德规范》中,“行为规则”是灵魂,应重点掌握这一部分的内容,尤其是其中的:内部审计师协会成员和注册内部审计师不应参与可能妨碍或被认为妨碍其公正评价的一些活动。

国际注册内部审计师(CIA)考试大纲(第二部分)

国际注册内部审计师(CIA)考试大纲(第二部分)

国际注册内部审计师(CIA)考试大纲(第二部分)第二部分:内部审计实务I管理内部审计活动(20%)1.内部审计的运营A描述有关计划、组织、指导和监督内部审计运营的政策和流程B理解内部审计活动的行政工作(如预算、资源管理、招募、人员配置等)2.制定以风险为基础的内部审计计划A确定潜在的审计业务来源(审计范围、审计周期需求、管理层的要求、监管要求、相关市场和行业走向、新出现的问题等)B确定风险管理框架,用于评估风险,并根据风险评估的结果确定审计业务的重点C理解确认业务的种类(风险和控制评估、第三方审计和合同审计、安全与保密、绩效和质量审计、关键绩效指标、运营审计、财务和合规审计等)D理解旨在提供意见和建议的咨询业务的种类(培训、系统设计、系统开发、尽职调查、保密、对标分析、内部控制评估、流程设计等)E描述内部审计与外部审计、监管机构以及其他内部确认职能部门之间的协作,以及内部审计与其他确认服务提供方之间相互利用工作成果的可能性3.与高级管理层和董事会沟通并向其报告A了解首席审计执行官负责向高级管理层和董事会报告年度审计计划,并寻求获得董事会的批准B确定重大风险的暴露、控制和治理,以便首席审计执行官向董事会报告C了解首席审计执行官负责向高级管理层报告组织内部控制和风险管理程序的整体有效性D了解首席审计执行官定期与高级管理层和董事会沟通的内部审计关键绩效指标II计划审计业务(20%)1.制定计划A确定审计业务的目标、评估标准和业务范围B制定业务计划,确保能够识别关键的风险和控制C对每个审计领域开展具体风险评估,包括评估风险和控制因素,并确定其重要程度D确定审计业务流程,编制审计工作方案E确定审计业务所需的人员和资源水平III执行审计业务(40%)1.信息收集A收集并检查相关信息(检查之前的审计报告和数据、开展穿行测试、访谈、观察等),并将其作为对审计业务领域进行初步调查的一项内容B编制检查清单以及风险和控制调查问卷,并将其作为对审计业务领域进行初步调查的一项内容C运用适当的抽样(非统计抽样、判断抽样、发现抽样等)和数据分析技巧2.分析和评估A运用计算机辅助审计工具和技能(数据挖掘和提取、持续监控、自动化工作底稿、内置审计模块等)B评估潜在证据来源的相关性、充分性和可信度C运用适当的分析方法和流程图绘制技术(过程识别、工作流分析、流程图生成和分析、意大利面条图和RACI图等)D确定和运用分析性检查技术(比率估计、差异分析、预算与实际对比、趋势分析、其他合理性测试、对标分析)E编制工作底稿和记录相关信息的档案文件,为审计结论和业务成果提供支持F总结和归纳审计结果,包括对风险和控制进行评估的结果3.审计业务督导A确定业务督导过程中的重要活动(协调工作分配、检查工作底稿、评估审计人员的工作表现等)IV沟通审计结果和监督改进(20%)1.沟通审计结果和风险接纳程度A与审计业务客户进行初步沟通。

国际注册内部审计师考试攻略

国际注册内部审计师考试攻略

国际注册内部审计师考试攻略一、ACCA+CIA 双重持证ACCA (特许公认会计师公会)与IIA(国际注册内部审计师协会)达成协议,自2015年11月起,ACCA会员可参加为其特别设计的CIA(国际注册内部审计师)测试。

一旦ACCA会员通过此项测试,则可获得国际注册内部审计师称号。

该测试包含了CIA资格考试的核心考纲以及学习目标。

ACCA与IIA都对此次携手合作表达了良好的祝愿。

ACCA战略与发展执行董事Alan Hatfield表示,虽然ACCA会员在其学习过程中已经学习了相当的有关风险、内部控制以及公司治理的知识,但连篇累赘的有关低质量内审以及由此造成的投资者信心下降的报道,还是提醒我们应该加强有关内部审计的学习。

此次为ACCA会员提供CIA挑战测试不但可以帮助他们获得CIA称号,也是一个提升他们内审专业知识的良机。

而IIA主席兼CEO Richard F. Chambers也表示与ACCA的协议达成创造了双方合作的'先河。

此外,ACCA还在其官方的网站上开辟了专门的版块为IIA及ACCA会员提供有关内审的相关资料。

这些资料包括了一些专业的指导以及有关内审的文章,为管理层以及审计委员会提供了有益的帮助。

ACCA and IIA joinforces to boost internal audit industry with new exam and specialised resources,Internal auditexam offered to ACCA members alongside membership of the IIA。

This deal willprovide an opportunity for ACCA members to become CIA certified through acustomised exam, which will include key syllabus and learning outcomes of theCIA exam.“This is an excellent opportunity to allowexisting ACCA members to further develop their expertise in this specialisedfield in which, being qualified clearly matters. Offering the CIA ChallengeExam to our members is a value-add, where our members working in internalaudit, or those who are looking to develop a career in internal audit, canobtain the CIA designation and clearly demonstrate their expertise in thisarea.“ACCA has alsolaunched a new resource for IIA and ACCA members working in internal audit witha section on the ACCA website. Thisincludes useful guides and articlesincluding internal audit for managers and also for the audit committee.二、CIA考试指南信息一.时间:每年举行一次,时间为11月第3周的周六、周日。

国际内部资料审计专业实务框架

国际内部资料审计专业实务框架

1000-宗旨、权力和职责内部审计部门的宗旨、权力和职责必须在内部审计章程中按照内部审计定义、《职业道德规范》和《标准》的相关内容正式确定。

首席审计执行官必须定期审查内部审计章程,并提交高级管理层和董事会审批。

释义内部审计章程是确定内部审计活动宗旨、权力和职责的正式文件。

它确立了内部审计部门在组织内部的地位,授权内部审计部门接触与业务开展相关的记录、人员和实物资产,界定内部审计活动的范围。

内部审计章程的最终审批权在董事会。

1000.A1---向组织提供的确认服务的性质必须在内部审计章程中明确规定。

如果内部审计部门向组织外部的有关方面提供确认服务,则此类确认服务的性质也必须在内部审计章程中确定。

1000.C1---咨询服务的性质必须在内部审计章程中确定。

1010-在内部审计章程中确认“内部审计定义”、《职业道德规范》和《标准》“内部审计定义”、《职业道德规范》和《标准》的强制性质必须在内部审计章程中得到确认。

首席审计执行官应当向高级管理层和董事会解释并讨论“内部审计定义”、《职业道德规范》和《标准》。

1100-独立性和客观性内部审计部门必须保持其独立性,内部审计师必须客观地开展工作。

释义独立性指内部审计部门或首席审计执行官不偏不倚地履行职责,免受任何威胁其履职能力的情况影响。

要达到有效履行内部审计部门职责所必须的独立程度,首席审计执行官需要直接且无限制地与高级管理层和董事会接触。

这一要求可以通过建立双重报告关系来实现。

独立性所面临的各种威胁必须在审计师个人、具体业务、职能部门和整个组织等不同层面上得到解决。

客观性指不偏不倚的工作态度,保持客观性,内部审计师方可在开展业务时确信其工作成果,不做任何质量方面的妥协。

客观性要求内部审计师对于审计事项的判读不得屈服于他人。

客观性所面临的各种威胁必须在审计师个人、具体业务、职能部门和整个组织等不同层面上得到解决。

1110-组织的独立性首席审计执行官必须向组织内部能够确保内部审计部门履行职责的层级报告。

2024cia大纲

2024cia大纲

2024cia大纲目录一、介绍二、大纲内容2.1 审计基础知识2.2 审计程序与技术2.3 财务报表审计2.4 内部控制审计2.5 风险管理审计2.6 信息科技审计三、考试要求四、结语这篇文档旨在介绍2024CIA大纲的主要内容,为考生提供备考指导。

通过了解大纲内容,考生可以更好地把握考试重点,有针对性地进行复习。

同时,本文还对考试要求进行了说明,以便考生更好地了解考试标准和要求。

一、介绍CIA是国际注册内部审计师考试的简称,是由国际内部审计师协会(IIA)举办的一项全球性资格考试。

该考试旨在测试考生在内部审计领域的专业知识和技能,是国际内部审计界最具权威性的认证之一。

2024年CIA大纲的发布,对于考生来说是一个重要的参考依据,能够帮助考生了解考试内容和要求,从而更好地备考。

二、大纲内容2.1 审计基础知识本部分主要包括审计的基本概念、原则、标准、方法等方面的知识,是考生进行后续学习的必备基础。

考生需要掌握审计的本质、目标、范围和标准等方面的知识,同时还需要了解审计人员的职业道德和职业责任等方面的要求。

2.2 审计程序与技术本部分主要介绍审计程序和技术的相关知识,包括审计计划、风险评估、控制测试、实质性测试等方面的知识。

考生需要了解审计程序的流程和要求,掌握常用的审计技术和方法,并能运用这些技术和方法进行有效的审计工作。

2.3 财务报表审计本部分主要介绍财务报表审计的相关知识,包括财务报表的编制和审查等方面的知识。

考生需要了解财务报表的构成和编制要求,掌握财务报表的审查方法和技术,并能对财务报表进行有效的审查和评估。

中国内部审计新准则及实务指南讲解

中国内部审计新准则及实务指南讲解《中国内部审计准则》及实务指南讲稿为了进一步加强内部审计的规范化和职业化建设,推动内部审计事业科学发展,2021年8月20日,中国内部审计协会以公告形式发布了新修订的《内部审计基本准则》、《内部审计人员职业道德规范》、《内部审计具体准则》20个,并于2021年1月1日起施行。

新准则的发布,标志着我国内部审计准则体系进一步完善和成熟,并逐步与国际惯例接轨。

中国内部审计协会对2021年以来颁布的内部审计基本准则、内部审计人员职业道德规范和29个具体准则进行了修订。

内部审计审计准则的修订和发布,是我国内部审计规范化建设的一件大事,是完善内部审计规范体系的重要举措,对提升内部审计在组织中的地位,规范内部审计机构和内部审计人员的行为,保证审计质量,防范审计风险,促进内部审计事业健康发展具有积极的意义。

现将修订的主要内容作如下讲解:一、关于准则修订的必要性中国内部审计协会于2021年陆续发布了内部审计准则,包括《内部审计基本准则》、《内部审计人员职业道德规范》以及29个内部审计具体准则和5个实务指南,形成了由内部审计基本准则、内部审计具体准则、内部审计实务指南以及内部审计人员职业道德规范构成的较为完善的内部审计准则体系。

内部审计准则的颁布和实施有力地促进了我国内部审计工作的规范化建设。

实践证明,这些准则是符合当时历史条件下内部审计工作发展要求的,也是被广大内部审计机构和人员接受和认可的,至今仍有很强的现实指导意义。

但是,近年来我1国内部审计环境发生了重大变化,内部审计工作面临着新的机遇和挑战,同时,国际内部审计准则修订也带来了新的理念,提供了新的借鉴内容。

因此,有必要修订和完善准则体系,以进一步规范审计行为,促进审计质量不断提升,进而推动内部审计工作科学发展。

二、关于准则修订的主要原则此次准则修订的主要原则为:一是保持现有的准则体系的连续性和稳定性。

保留被内部审计实践证明比较成熟的规定,在传承、发展的基础上,对内容作进一步调整、完善和优化;二是增强准则体系的逻辑性和系统性。

第1章国际内部审计专业实务框架强制性指南


内部审计产品形式:
提供处理意见 咨询建议 书面报告或口头交流
为组织增值提供服务的目标定位: 使内部审计与管理层的目标定位保持一致,更利于实现内部审计 与管理层的密切合作
获取领导的支持,取得被审者的认 同,推动价值信息采用,影响领导 和被审者决策,落实决策执行,评 价决策执行的效果
1.2.2 内部审计主体:内部审计外包
• 内部审计外包(internal audit outsourcing) 是指组织将其内部审计职能部分或全部通过契约 委托给组织外部的机构执行。 • 内部审计外包的推出
–安达信、安永、毕马威等咨询机构最先提出内部审计 外部化,在20 世纪90 年代迅速发展,在大规模公司 更为流行,财富100 强公司有50%以上外包了相当部分 的内部审计职能。 –据美国内部审计师协会调查,实行内部审计外包化的美 国企业已占21.5%,汽车、电子、感光材料等行业超过 50%。
• 内部审计外包的缺点 –外部收费较高; –逐渐失去对公司的了解与专业审计技能; –公司缺乏对审计及其质量的控制; –未来管理层没有机会参加内部审计。 • 内部审计外包对内部审计的威胁: –在组织内部机构调整和重构中,作为非核心管理 活动的不成功的内部审计机构首当其冲惨遭淘汰。 –内部审计要充分认识到竞争的现实性、残酷性。 –内部审计是资源耗费者、成本中心,还是价值增 加者、利润中心?决定着内部审计机构的存亡。
2内部审计定义iia新定义的变化变化的方面变化的内容内部审计目标为管理层提供保护建设服务衡量评价其他控制有效性协助组织成员有效履行职责增加价值和改善组织的运营内部审计服务对象管理层组织内部审计主体内部审计机构外包内部审计职能检查评价确认咨询内部审计本质独立评价活动独立客观的确认咨询活动内部审计内容财务活动经营活动风险管理控制和管理过程的有效性企业目标审计目标价值增值提供价值信息推进价值信息的利用实现价值增值的企业目标121内部审计目标

国际内部审计专业实务框架

国际内部审计专业实务框架国际内部审计专业实务框架修订说明鉴于全球内部审计职业的快速发展,2006年国际内部审计师协会(IIA)理事会组建了筹划指导委员会和专门小组,重新审视《内部审计专业实务框架》(PPF)及相关制定过程,重点是回顾该专业实务框架的范围,增加专业标准制定、复核及颁布过程的透明度和一贯性。

专门小组的工作结果形成了全新的《国际内部审计专业实务框架》(IPPF)和重新改组的专业实务委员会(PPC)。

根据IIA理事会2007年6月批准的使命声明,专业实务委员会目前负责协调《国际内部审计专业实务框架》的审核与发布工作。

作为整合IIA所发布标准的概念性框架,《国际内部审计专业实务框架》的范围缩减到只包括由IIA国际技术委员会按照适当程序制定的权威标准。

该权威标准由以下两部分构成:强制性指南。

遵循强制性指南的原则对于内部审计专业实务是必须且重要的。

强制性指南的制定遵循既定的尽职审查程序,包括公布征求意见稿,广泛听取各界的意见。

《国际内部审计专业实务框架》的三个强制部分为“内部审计定义”、《职业道德规范》和《国际内部审计专业实务框架》(以下简称《标准》)。

强力推荐的指南。

强力推荐的指南是IIA通过正式批准程序认可的,阐述有效执行“内部审计定义”、《职业道德规范》和《标准》的实务,包括立场公告、实务公告和实务指南。

新版IPPF所作的重大改变是:(l)程序改进。

加强了IPPF的各个部分,提高了透明度并确定了权威标准的修订周期。

标准的修订周期目前确定为三年,尽管并非每三年都需要进行修改,IIA仍致力于确保对标准作全面的审核,并视需要进行修订。

(2)发展与实务帮助。

这一部分不再纳入框架体系。

它曾经包含了内部审计师在工作过程中可能会用到的所有资源(例如培训、出版物和研究报告等)。

由于新版IPPF的范围只包括上述的权威标准,这项内容不再适合于新的框架。

(3)释义。

这是新增的对标准中的术语和短语作出的进一步阐释,置于需要加以解释的相关标准条款之下。

国际内部审计专业实务框架IPPF_Standards_2011-01

INTERNATIONAL STANDARDS FOR THE PROFESSIONALPRACTICE OFINTERNAL AUDITING (STANDARDS)Introduction to the International StandardsInternal auditing is conducted in diverse legal and cultural environments; within organizations that vary in purpose, size, complexity, and structure; and by persons within or outside the organization. While differences may affect the practice of internal auditing in each environment, conformance with The IIA’s International Standards for the Professional Practice of Internal Auditing (Standards) is essential in meeting the responsibilities of internal auditors and the internal audit activity.If internal auditors or the internal audit activity is prohibited by law or regulation from conformance with certain parts of the Standards, conformance with all other parts of the Standards and appropriate disclosures are needed.If the Standards are used in conjunction with standards issued by other authoritative bodies, internal audit communications may also cite the use of other standards, as appropriate. In such a case, if inconsistencies exist between the Standards and other standards, internal auditors and the internal audit activity must conform with the Standards, and may conform with the other standards if they are more restrictive.The purpose of the Standards is to:1. Delineate basic principles that represent the practice of internalauditing.2. Provide a framework for performing and promoting a broadrange of value-added internal auditing.Issued: October 2008 Page 1 of 353. Establish the basis for the evaluation of internal auditperformance.4. Foster improved organizational processes and operations.The Standards are principles-focused, mandatory requirements consisting of:∙Statements of basic requirements for the professional practice of internal auditing and for evaluating the effectiveness of performance, which are internationally applicable at organizational and individual levels.∙Interpretations, which clarify terms or concepts within the Statements.The Standards employ terms that have been given specific meanings that are included in the Glossary. Specifically, the Standards use the word ―must‖ to specify an unconditional requirement and the word ―should‖ where conformance is expected unless, when applying professional judgment, circumstances justify deviation.It is necessary to consider the Statements and their Interpretations as well as the specific meanings from the Glossary to understand and apply the Standards correctly.The structure of the Standards is divided between Attribute and Performance Standards. Attribute Standards address the attributes of organizations and individuals performing internal auditing. The Performance Standards describe the nature of internal auditing and provide quality criteria against which the performance of these services can be measured. The Attribute and Performance Standards are also provided to apply to all internal audit services. Implementation Standards are also provided to expand upon the Attribute and Performance standards, by providing the requirements applicable to assurance (A) or consulting (C) activities.Assurance services involve the internal auditor’s objective assessment of evidence to provide an independent opinion or conclusionsregarding an entity, operation, function, process, system, or other subject matter. The nature and scope of the assurance engagement are determined by the internal auditor. There are generally three parties involved in assurance services: (1) the person or group directly involved with the entity, operation, function, process, system, or other subject matter — the process owner, (2) the person or group making the assessment —the internal auditor, and (3) the person or group using the assessment — the user.Consulting services are advisory in nature, and are generally performed at the specific request of an engagement client. The nature and scope of the consulting engagement are subject to agreement with the engagement client. Consulting services generally involve two parties: (1) the person or group offering the advice —the internal auditor, and (2) the person or group seeking and receiving the advice —the engagement client. When performing consulting services the internal auditor should maintain objectivity and not assume management responsibility.The review and development of the Standards is an ongoing process. The Internal Audit Standards Board engages in extensive consultation and discussion prior to issuing the Standards. This includes worldwide solicitation for public comment through the exposure draft process. All exposure dr afts are posted on The IIA’s Web site as well as being distributed to all IIA institutes.Suggestions and comments regarding the Standards can be sent to:The Institute of Internal AuditorsStandards and Guidance247 Maitland AvenueAltamonte Springs, FL 32701-4201, USAE-mail: guidance@ Web: ***INTERNATIONAL STANDARDS FOR THE PROFESSIONALPRACTICEOF INTERNAL AUDITING (STANDARDS)Attribute Standards1000 – Purpose, Authority, and ResponsibilityThe purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent with the Definition of Internal Auditing, the Code of Ethics, and the Standards. The chief audit executive must periodically review the internal audit charter and present it to senior management and the board for approval.Interpretation:The internal audit charter is a formal document that defines the internal audit activity's purpose, authority, and responsibility. The internal audit charter establishes the internal audit activity's position within the organization, including the nature of the chief audit executive’s functional reporting relationship with the board; authorizes access to records, personnel, and physical properties relevant to the performance of engagements; and defines the scope of internal audit activities. Final approval of the internal audit charter resides with the board.1000.A1 –The nature of assurance services provided to the organization must be defined in the internal audit charter. If assurances are to be provided to parties outside the organization, the nature of these assurances must also be defined in the internal audit charter.1000.C1 – The nature of consulting services must be defined in the internal audit charter.1010 –Recognition of the Definition of Internal Auditing, the Code of Ethics, and the Standards in the Internal Audit Charter The mandatory nature of the Definition of Internal Auditing, the Code of Ethics, and the Standards must be recognized in the internal audit charter. The chief audit executive should discuss the Definition of Internal Auditing, the Code of Ethics, and the Standards with senior management and the board.1100 – Independence and ObjectivityThe internal audit activity must be independent, and internal auditors must be objective in performing their work.Interpretation:Independence is the freedom from conditions that threaten the ability of the internal audit activity to carry out internal audit responsibilities in an unbiased manner. To achieve the degree of independence necessary to effectively carry out the responsibilities of the internal audit activity, the chief audit executive has direct and unrestricted access to senior management and the board. This can be achieved through a dual-reporting relationship. Threats to independence must be managed at the individual auditor, engagement, functional, and organizational levels.Objectivity is an unbiased mental attitude that allows internal auditors to perform engagements in such a manner that they believe in their work product and that no quality compromises are made. Objectivity requires that internal auditors do not subordinate their judgment on audit matters to others. Threats to objectivity must be managed at the individual auditor, engagement, functional, and organizational levels. 1110 – Organizational IndependenceThe chief audit executive must report to a level within the organization that allows the internal audit activity to fulfill its responsibilities. The chief audit executive must confirm to the board, at least annually, the organizational independence of the internal audit activity.Interpretation:Organizational independence is effectively achieved when the chief audit executive reports functionally to the board. Examples of functional reporting to the board involve the board:∙Approving the internal audit charter;∙Approving the risk based internal audit plan;∙Receiving communications from the chief audit executive on the internal audit activity’s performance relative to its plan and other matters;∙Approving decisions regarding the appointment and removal of the chief audit executive; and∙Making appropriate inquiries of management and the chief audit executive to determine whether there are inappropriate scope or resource limitations.1110.A1 –The internal audit activity must be free from interference in determining the scope of internal auditing, performing work, and communicating results.1111 – Direct Interaction with the BoardThe chief audit executive must communicate and interact directly with the board.1120 – Individual ObjectivityInternal auditors must have an impartial, unbiased attitude and avoid any conflict of interest.Interpretation:Conflict of interest is a situation in which an internal auditor, who is in a position of trust, has a competing professional or personal interest. Such competing interests can make it difficult to fulfill his or her duties impartially. A conflict of interest exists even if no unethical or improper act results. A conflict of interest can create an appearance of impropriety that can undermine confidence in the internal auditor, the internal audit activity, and the profession. A conflict of interest couldimpair an individual's ability to perform his or her duties and responsibilities objectively.1130 – Impairment to Independence or ObjectivityIf independence or objectivity is impaired in fact or appearance, the details of the impairment must be disclosed to appropriate parties. The nature of the disclosure will depend upon the impairment. Interpretation:Impairment to organizational independence and individual objectivity may include, but is not limited to, personal conflict of interest, scope limitations, restrictions on access to records, personnel, and properties, and resource limitations, such as funding.The determination of appropriate parties to which the details of an impairment to independence or objectivity must be disclosed is dependent upon the expectations of the internal audit activity’s and the chief audit executive’s responsibilities to senior managem ent and the board as described in the internal audit charter, as well as the nature of the impairment.1130.A1 – Internal auditors must refrain from assessing specificoperations for which they were previously responsible.Objectivity is presumed to be impaired if an internal auditorprovides assurance services for an activity for which the internalauditor had responsibility within the previous year.1130.A2 – Assurance engagements for functions over which thechief audit executive has responsibility must be overseen by aparty outside the internal audit activity.1130.C1–Internal auditors may provide consulting servicesrelating to operations for which they had previous responsibilities.1130.C2–If internal auditors have potential impairments toindependence or objectivity relating to proposed consultingservices, disclosure must be made to the engagement client prior to accepting the engagement.1200 – Proficiency and Due Professional CareEngagements must be performed with proficiency and due professional care.1210 – ProficiencyInternal auditors must possess the knowledge, skills, and other competencies needed to perform their individual responsibilities. The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities.Interpretation:Knowledge, skills, and other competencies is a collective term that refers to the professional proficiency required of internal auditors to effectively carry out their professional responsibilities. Internal auditors are encouraged to demonstrate their proficiency by obtaining appropriate professional certifications and qualifications, such as the Certified Internal Auditor designation and other designations offered by The Institute of Internal Auditors and other appropriate professional organizations.1210.A1–The chief audit executive must obtain competent advice and assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all or part of the engagement.1210.A2 – Internal auditors must have sufficient knowledge to evaluate the risk of fraud and the manner in which it is managed by the organization, but are not expected to have the expertise ofa person whose primary responsibility is detecting andinvestigating fraud.1210.A3–Internal auditors must have sufficient knowledge of key information technology risks and controls and available technology-based audit techniques to perform their assigned work. However, not all internal auditors are expected to have the expertise of an internal auditor whose primary responsibility is information technology auditing.1210.C1 – The chief audit executive must decline the consulting engagement or obtain competent advice and assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all or part of the engagement.1220 – Due Professional CareInternal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor. Due professional care does not imply infallibility.1220.A1– Internal auditors must exercise due professional care by considering the:∙Extent of work needed to achieve the engagement’s objectives;∙Relative complexity, materiality, or significance of matters to which assurance procedures are applied;∙Adequacy and effectiveness of governance, risk management, and control processes;∙Probability of significant errors, fraud, or noncompliance;and∙Cost of assurance in relation to potential benefits.1220.A2–In exercising due professional care internal auditors must consider the use of technology-based audit and other data analysis techniques.1220.A3– Internal auditors must be alert to the significant risks that might affect objectives, operations, or resources. However,assurance procedures alone, even when performed with due professional care, do not guarantee that all significant risks will be identified.1220.C1– Internal auditors must exercise due professional care during a consulting engagement by considering the:∙Needs and expectations of clients, including the nature, timing, and communication of engagement results;∙Relative complexity and extent of work needed to achieve the engagement’s objectives; and∙Cost of the consulting engagement in relation to potential benefits.1230 – Continuing Professional DevelopmentInternal auditors must enhance their knowledge, skills, and other competencies through continuing professional development.1300 – Quality Assurance and Improvement ProgramThe chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity.Interpretation:A quality assurance and improvement program is designed to enable an evaluation of the internal audit activity’s conformance with the Definition of Internal Auditing and the Standards and an evaluation of whether internal auditors apply the Code of Ethics. The program also assesses the efficiency and effectiveness of the internal audit activity and identifies opportunities for improvement.1310 – Requirements of the Quality Assurance and Improvement ProgramThe quality assurance and improvement program must include both internal and external assessments.1311 – Internal AssessmentsInternal assessments must include:∙Ongoing monitoring of the performance of the internal audit activity; and∙Periodic reviews performed through self-assessment or by other persons within the organization with sufficient knowledge of internal audit practices.Interpretation:Ongoing monitoring is an integral part of the day-to-day supervision, review, and measurement of the internal audit activity. Ongoing monitoring is incorporated into the routine policies and practices used to manage the internal audit activity and uses processes, tools, and information considered necessary to evaluate conformance with the Definition of Internal Auditing, the Code of Ethics, and the Standards. Periodic reviews are assessments conducted to evaluate conformance with the Definition of Internal Auditing, the Code of Ethics, and the Standards.Sufficient knowledge of internal audit practices requires at least an understanding of all elements of the International Professional Practices Framework.1312 – External AssessmentsExternal assessments must be conducted at least once every five years by a qualified, independent reviewer or review team from outside the organization. The chief audit executive must discuss with the board:∙The need for more frequent external assessments; and∙The qualifications and independence of the external reviewer or review team, including any potential conflict of interest. Interpretation:A qualified reviewer or review team demonstrates competence in two areas: the professional practice of internal auditing and the external assessment process. Competence can be demonstrated through a mixture of experience and theoretical learning. Experience gained in organizations of similar size, complexity, sector or industry, and technical issues is more valuable than less relevant experience. In the case of a review team, not all members of the team need to have all the competencies; it is the team as a whole that is qualified. The chief audit executive uses professional judgment when assessing whether a reviewer or review team demonstrates sufficient competence to be qualified.An independent reviewer or review team means not having either a real or an apparent conflict of interest and not being a part of, or under the control of, the organization to which the internal audit activity belongs.1320 –Reporting on the Quality Assurance and Improvement ProgramThe chief audit executive must communicate the results of the quality assurance and improvement program to senior management and the board.Interpretation:The form, content, and frequency of communicating the results of the quality assurance and improvement program is established through discussions with senior management and the board and considers the responsibilities of the internal audit activity and chief audit executive as contained in the internal audit charter. To demonstrate conformance with the Definition of Internal Auditing, the Code of Ethics, and the Standards, the results of external and periodic internal assessments are communicated upon completion of such assessments and the results of ongoing monitoring are communicated at least annually. The results include the reviewer’s or review team’s assessment with respect to the degree of conformance.1321 –Use of “Conforms with the International Standards for the Professional Practice of Internal Auditing”The chief audit executive may state that the internal audit activity conforms with the International Standards for the Professional Practice of Internal Auditing only if the results of the quality assurance and improvement program support this statement.Interpretation:The internal audit activity conforms with the Standards when it achieves the outcomes described in the Definition of Internal Auditing, Code of Ethics, and Standards. The results of the quality assurance and improvement program include the results of both internal and external assessments. All internal audit activities will have the results of internal assessments. Internal audit activities in existence for at least five years will also have the results of external assessments.1322 – Disclosure of NonconformanceWhen nonconformance with the Definition of Internal Auditing, the Code of Ethics, or the Standards impacts the overall scope or operation of the internal audit activity, the chief audit executive must disclose the nonconformance and the impact to senior management and the board.Performance Standards2000 – Managing the Internal Audit ActivityThe chief audit executive must effectively manage the internal audit activity to ensure it adds value to the organization.Interpretation:The internal audit activity is effectively managed when:∙The results of the internal audit activity’s work achieve the purpose and responsibility included in the internal audit charter;∙The internal audit activity conforms with the Definition of Internal Auditing and the Standards; and∙The individuals who are part of the internal audit activity demonstrate conformance with the Code of Ethics and the Standards.The internal audit activity adds value to the organization (and its stakeholders) when it provides objective and relevant assurance, and contributes to the effectiveness and efficiency of governance, risk management, and control processes.2010 – PlanningThe chief audit executive must establish risk-based plans to determine the priorities of the internal audit activity, consistent with the organization’s goals.Interpretation:The chief audit executive is responsible for developing a risk-based plan. The chief audit executive takes into account the organization’s risk management framework, including using risk appetite levels set by management for the different activities or parts of the organization. If a framework does not exist, the chief audit executive uses his/her own judgment of risks after consultation with senior management and the board.2010.A1–The internal audit activity’s plan of engagements must be based on a documented risk assessment, undertaken at least annually. The input of senior management and the board must be considered in this process.2010.A2– The chief audit executive must identify and consider the expectations of senior management, the board, and other stakeholders for internal audit opinions and other conclusions.2010.C1–The chief audit executive should consider accepting proposed consulting engagements based on the en gagement’s potential to improve management of risks, add value, and improve the organization’s operations. Accepted engagements must be included in the plan.2020 – Communication and ApprovalThe chief audit executive must communicate the internal audit activity’s plans and resource requirements, including significant interim changes, to senior management and the board for review and approval. The chief audit executive must also communicate the impact of resource limitations.2030 – Resource ManagementThe chief audit executive must ensure that internal audit resources are appropriate, sufficient, and effectively deployed to achieve the approved plan.Interpretation:Appropriate refers to the mix of knowledge, skills, and other competencies needed to perform the plan. Sufficient refers to the quantity of resources needed to accomplish the plan. Resources are effectively deployed when they are used in a way that optimizes the achievement of the approved plan.2040 – Policies and ProceduresThe chief audit executive must establish policies and procedures to guide the internal audit activity.Interpretation:The form and content of policies and procedures are dependent upon the size and structure of the internal audit activity and the complexity of its work.2050 – CoordinationThe chief audit executive should share information and coordinate activities with other internal and external providers of assurance and consulting services to ensure proper coverage and minimize duplication of efforts.2060 – Reporting to Senior Management and the BoardThe chief audit executive must report periodically to senior management and the board on the internal audit activity’s purpose, authority, responsibility, and performance relative to its plan. Reporting must also include significant risk exposures and control issues, including fraud risks, governance issues, and other matters needed or requested by senior management and the board. Interpretation:The frequency and content of reporting are determined in discussion with senior management and the board and depend on the importance of the information to be communicated and the urgency of the related actions to be taken by senior management or the board.2070 –External Service Provider and Organizational Responsibility for Internal AuditingWhen an external service provider serves as the internal audit activity, the provider must make the organization aware that the organization has the responsibility for maintaining an effective internal audit activity. InterpretationThis responsibility is demonstrated through the quality assurance and improvement program which assesses conformance with the Definition of Internal Auditing, the Code of Ethics, and the Standards. 2100 – Nature of WorkThe internal audit activity must evaluate and contribute to the improvement of governance, risk management, and control processes using a systematic and disciplined approach.2110 – GovernanceThe internal audit activity must assess and make appropriate recommendations for improving the governance process in its accomplishment of the following objectives:∙Promoting appropriate ethics and values within the organization;∙Ensuring effective organizational performance management and accountability;∙Communicating risk and control information to appropriate areas of the organization; and∙Coordinating the activities of and communicating information among the board, external and internal auditors, and management.2110.A1–The internal audit activity must evaluate the design, implementation, and effectiveness of the organization’s ethics-related objectives, programs, and activities.2110.A2 –The internal audit activity must assess whether the information technology governance of the organization supports the organization’s strategies and objectives.2120 – Risk ManagementThe internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes.Interpretation:Determining whether risk management processes are effective is a judgment resulting from the internal auditor’s assessment that:∙Organizational objectives support and align with theorganization’s mission;∙Significant risks are identified and assessed;∙Appropriate risk responses are selected that align risks with the organization’s risk appetite; and∙ Relevant risk information is captured and communicated in a timely manner across the organization, enabling staff,management, and the board to carry out their responsibilities.The internal audit activity may gather the information to support this assessment during multiple engagements. The results of these engagements, when viewed together, provide an understanding of the organization’s risk management processes and their effectiveness.Risk management processes are monitored through ongoing management activities, separate evaluations, or both.2120.A1–The internal audit activity must evaluate risk exposures relating to the organization’s governance, operations, and information systems regarding the:∙Reliability and integrity of financial and operational information;∙Effectiveness and efficiency of operations and programs;∙Safeguarding of assets; and∙Compliance with laws, regulations, policies, procedures, and contracts.2120.A2 –The internal audit activity must evaluate the potential for the occurrence of fraud and how the organization manages fraud risk.。

  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。
相关文档
最新文档