Before internal audit information is released outside normal internal channels, legal representation should be consulted. Internal audit reports and workpapers may contain sensitive findings, confidential business information, legal exposure, personal data, fraud indicators, privileged communications, or regulatory implications. Releasing such information to other assurance providers without proper review can create legal and confidentiality risk. Option A is too broad because interactions with nongovernmental organizations vary by context and jurisdiction. Option B is false because disclosure laws differ significantly across countries. Option C may be relevant in specialized donor-funded environments, but it is not the strongest general rule. Internal audit must control dissemination of results and protect confidentiality. Therefore, Option D is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit