IIA-CIA-PART1 · Question #188
Which of the following scenarios violates The IIA's standard regarding internal audit independence?
The correct answer is C. The CAE regularly meets with the organization's chief risk officer, who validates all reported audit. Option C violates IIA independence standards because having the Chief Risk Officer (CRO) - a member of management - validate all reported audit findings gives management control over audit communication. IIA Standard 1110 requires the internal audit activity be free from…
Question
Which of the following scenarios violates The IIA's standard regarding internal audit independence?
Options
- AThe chief audit executive (CAE) reports on the internal audit activity's day-to-day tasks and
- BAn assessment of the risk management function is reviewed by an outside consulting firm because
- CThe CAE regularly meets with the organization's chief risk officer, who validates all reported audit
- DThe internal audit activity will experience staffing shortages for the next six months due to
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C69% (18)
- D19% (5)
Explanation
Option C violates IIA independence standards because having the Chief Risk Officer (CRO) - a member of management - validate all reported audit findings gives management control over audit communication. IIA Standard 1110 requires the internal audit activity be free from interference in reporting results; when the CRO can effectively filter or approve what findings are disclosed, the CAE's ability to report objectively is compromised.
Why the distractors are wrong:
- A - Dual reporting (administrative to management, functional to the board) is explicitly permitted and even encouraged by IIA standards; day-to-day administrative reporting to the CEO does not impair independence.
- B - Having an outside consulting firm review an assessment of the risk management function strengthens independence by adding an objective, external check - this is a best practice, not a violation.
- D - Staffing shortages are a resource/capacity concern addressed under IIA standards on proficiency and due professional care, not independence; needing to co-source or adjust workload does not compromise independence.
Memory tip: Think of independence as protecting the "last mile" of the audit process - the reporting stage. Any scenario where someone outside the internal audit activity controls, approves, or filters what gets communicated upward is a red flag. "Validates all reported findings" = management controls the message = independence violation.
Community Discussion
No community discussion yet for this question.