Mandatory Guidance Flashcards

1
Q

The 6 parts of the IPPF

A
  • the definition of internal auditing
  • the code of ethics
  • the standards
  • practice advisories (PAs)
  • practice guides
  • position papers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Mandatory components of the IPPF

A
  • the definition of internal auditing
  • the code of ethics
  • the standards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Recommended components of the IPPF

A
  • practice advisories (PAs)
  • practice guides
  • position papers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The IIA’s best practices

A
  • practice advisories (PAs)

- practice guides

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The 4 purposes of the standards

A
  • delineate basic principles that represent the practice of internal auditing
  • provide a framework for performing and promoting a broad range of value-added internal auditing
  • establish the basis for the evaluation of internal audit performance
  • foster improved organizational processes and operations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Another name for the IPPF

A

The red book

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The 3 types of standards

A
  • attribute standards
  • performance standards
  • implementation standards
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Attribute standards

A
  • address the characteristics of organizations and people performing internal audit activities
  • apply to all internal audit services and internal auditors individually
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The 4 major sections of attribute standards

A
  • purpose, authority and responsibility
  • independence and objectivity
  • proficiency and due professional care
  • quality assurance and improvement program
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Performance standards

A
  • describe the nature of internal auditing and provide quality criteria for evaluating audit performance
  • apply to all internal audit services and internal auditors individually
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The 7 major sections of performance standards

A
  • managing the internal audit activity
  • nature of work
  • engagement planning
  • performing the engagement
  • communicating results
  • monitoring progress
  • communicating the acceptance of risks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Implementation standards

A
  • expand upon attribute and performance standards

- provide separate mandatory instructions for implementing the attribute and performance standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The 2 types of audit engagements

A
  • assurance
  • consulting

note: these do not have to be mutually exclusive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Assurance engagements

A

involve the auditor’s objective assessment of evidence to provide an independent opinion or conclusion regarding an entity, operation, function, process, system, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who determines the scope of an assurance engagement?

A

the internal auditor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The 3 parties involved in assurance services

A
  • the process owner (client)
  • the internal auditor
  • the user of the assessment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Consulting engagements

A
  • advisory in nature

- generally performed at the request of the client

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Who determines the scope of a consulting engagement?

A

mutually agreed upon between the internal auditor and the client

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

The 2 parties involved in consulting services

A
  • the process owner (client)

- the internal auditor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

4 categories of consulting engagements

A
  • formal
  • informal
  • special
  • emergency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Formal consulting engagements

A

planned and subject to written agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Informal consulting engagements

A

routine activities (e.g. participation on standing committees, limited-life projects, ad hoc meetings, routine information exchange)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Special consulting engagements

A

participation on a merger or acquisition team or system conversion team

24
Q

Emergency consulting engagements

A

participation on a team established for recovery or maintenance of operations after a disaster or other extraordinary business event

OR

participation on a team assembled to supply temporary help to meet a special request or unusual deadline

25
Note on consulting & assurance services
shouldn't use consulting services as a means of getting past having an assurance engagement BUT services once conducted as an assurance engagement may be performed in a consulting engagement - just have to watch out for redundancy
26
Numbering conventions for standards
- attribute standards are the 1000s - performance standards are the 2000s - implementation standards can be either & also include lettering to denote whether they relate to assurance (A) or consulting (C) engagements
27
Note on standards and the law
if a law prohibits auditors from complying with certain parts of the standards, it must be disclosed ONLY the law overrides the Code of Ethics and the Standards
28
Who drafts Practice Advisories?
the IIA's Professional Issues Committee
29
Practice Advisories
provide concise and timely guidance in applying the Code of Ethics and the Standards, as well as promoting best practices
30
Practice Advisories cover which topics?
- international, country or industry-specific issues - specific types of engagements - legal or regulatory issues
31
Practice Advisories DO cover:
- approach - methodology - considerations
32
Practice Advisories DO NOT cover:
detailed processes and procedures Note: These are covered by Practice Guides
33
How are Practice Advisories developed?
- suggestions can be submitted from anyone | - formal review process performed by the Professional Issues Committee
34
Practice Guides
- provide detailed guidance for conducting internal audit activities - include detailed processes and procedures (e.g. tools and techniques, programs, step-by-step approaches, examples of deliverables)
35
Are Practice Advisories and Practice Guides available to anyone?
NO, these are password protected on the IIA's website, as they are intended for member use only
36
Position Papers
- assist in understanding specific governance, risk or control issues - assist in delineating the related roles and responsibilities of the internal audit profession
37
Are Position Papers available to anyone?
YES
38
Are the definition of Internal Auditing, the Code of Ethics and the Standards available to anyone?
YES
39
Integrated audits provide assurance over any combination of these 5 engagement types:
- financial - controls - IT - compliance - operations
40
The 5 financial assertions
- existence or occurrence - completeness - valuation and allocation - rights and obligations - presentation and disclosure
41
What is the highest level of governing body charged with the responsibility to direct and/or oversee the activities and management of an organization?
the Board
42
Definition of Internal Auditing
- an independent, objective assurance and consulting activity designed to add value and improve an organization's operations - helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes
43
Internal audit activity
a department, division, team of consultants, etc. that provides independent, objective assurance and consulting services designed to add value and improve an organization's operations
44
GRC
- governance - risk - control
45
What is the foundation of internal auditing? (2 things)
- organizational independence | - individual objectivity
46
Organizational independence exists if the CAE: (3 things)
- reports functionally to the Board - has direct and unrestricted access to the Board - reports administratively to the CEO or a similar head of the organization
47
The CAE can report administratively to a different organizational level as long as the internal audit activity controls, without interference: (3 things)
- the scope of the work - the performance of the work - the reporting of results
48
There is an increasing view of internal audit having a positive influence over: (2 things)
- governance | - risk management process
49
Governance
combination of processes and structures implemented by the board to inform, direct, manage and monitor the activities of the organization toward the achievement of its objectives
50
With respect to governance, internal auditors can ensure a company has:
- proper tone at the top - management and operating methodology - ethics and integrity
51
Nature and Work for the Internal Audit Activity: Risk Help an organization manage risk by: (3 things)
- identifying and evaluating significant exposures to risk - contributing to the improvement of risk management and control systems - monitoring and evaluating the risk management system
52
Nature and Work for the Internal Audit Activity: Control Help an organization maintain effective controls by: (2 things)
- evaluating the effectiveness and efficiency of controls | - promoting the continuous improvement of the control environment
53
Nature and Work for the Internal Audit Activity: Governance Help an organization assess and make recommendations for improving governance in its accomplishment of the following objectives: (4 things)
- promoting appropriate ethics and values within the organization - ensuring effective organizational performance management and accountability - effectively communicating risk and control information to appropriate areas of the organization - effectively coordinating the activities of, and communicating information among, the board, external and internal auditors and management
54
IIA's view of 'modern' internal auditing
internal auditors pursue cooperative, productive working relationships through value-added activities as opposed to being the client's adversary
55
Internal audit activity's purpose (5 items)
- provide an independent, objective assurance and consulting activity - add value and improve an organization's operations - support organizational objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of GRC processes - determine if organizational GRC processes are in place and are functioning properly - communicate any opportunities for improvement or risk exposure to the appropriate management level
56
Internal audit activity's authority (3 items)
- provide appropriate unfettered access to records, personnel and physical properties - maintain full and open access with the audit committee, board of directors or other governing authority - secure necessary internal and external resources to accomplish audit activity objectives as planned
57
Internal audit activity's responsibility (5 items)
- document the objectives and scope of the engagement as well as the methodology to be used - ensure that audit activity staff have sufficient knowledge, skills, experience and/or professional certifications to fulfill the engagement charter - communicate the results of the internal audit activity or other matters that the CAE determines necessary to senior management, the audit committee, the board or other governing body of the organization - consider the coordination of internal and external audit work to increase economy, efficiency and effectiveness of the overall audit process - do not perform management activities