An audit reveals that a manager's spouse is receiving paychecks, but is not employed by the organization. According to IIA guidance, which of the following actions should the internal auditor take?
A.
Contact the external auditor and provide all relevant documentation.
B.
Report the finding to senior management in a timely manner, following the normal chain of command.
C.
Meet with the local manager to obtain more information on the finding before taking further action.
D.
Bypass the normal chain of command and contact the board directly to report the finding.
When an internal auditor discovers a significant issue, such as a manager’s spouse receiving paychecks without being employed, it’s essential to follow the appropriate protocols for reporting the finding.
IIA Standard 2060 – Reporting to Senior Management and the Board:
This standard mandates that the chief audit executive (CAE) must communicate significant risk exposures and control issues to senior management and the board. Following the normal chain of command ensures that the issue is escalated appropriately without bypassing necessary channels.
Ethical Considerations and Confidentiality:
According to the IIA’s Code of Ethics, internal auditors must respect the confidentiality of the information they handle. Reporting through the established chain of command ensures that sensitive issues are handled discreetly and appropriately.
IIA Standard 2440 – Disseminating Results:
This standard requires that the results of the audit, including significant findings, should be communicated to the appropriate parties. Reporting to senior management first allows for an initial review and appropriate action before escalating to higher levels, if necessary.
Option A (Contacting the external auditor): While external auditors may need to be informed, this step should follow internal reporting protocols, not precede them.
Option C (Meeting with the local manager): This could compromise the investigation, as the local manager may be involved in the issue.
Option D (Bypassing the chain of command): This should only be done in extreme circumstances, such as when senior management is directly involved in the wrongdoing, which is not indicated in this scenario.
Detailed Explanation:Why Not Other Options?
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit