The CEO has delegated several responsibilities to the internal audit activity. Which of the following directives should concern the chief audit executive the most?
The directive that should concern the chief audit executive (CAE) the most is that internal auditors shall perform risk management activities. While internal auditors can assess and provide assurance on risk management processes, taking on the role of performing risk management activities can impair their objectivity and independence. Risk management is a management responsibility, and if internal auditors are involved in these activities, it could lead to conflicts of interest and compromise their ability to provide independent assurance.
The IIA Standards: Standard 1112 – Chief Audit Executive Roles Beyond Internal Auditing: " If the chief audit executive has or is expected to have roles and/or responsibilities that fall outside of internal auditing, safeguards must be in place to limit impairments to independence or objectivity. "
The IIA Practice Guide: " Independence and Objectivity " : Discusses the importance of maintaining independence by avoiding operational responsibilities like risk management.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit