I. MANAGING THE INTERNAL AUDIT FUNCTION (40%-50%)
A. Strategic Role of Internal Audit
B. Operational Role of IA
C. Establish Risk-Based IA Plan
1. Use market, Product, and industry to identify new internal audit engagement opportunities.
2. Use a risk framework to identify sources of potential engagements (e.g., audit universe, audit cycle requirements, management requests, regulatory mandates)
3. Establish a framework for assessing risk
4. Rank and validate risk priorities to prioritize engagements in the audit plan
5. Identify internal audit resource requirements for annual IA plan
6. Communicate areas of significant risk and obtain approval from the board for the annual engagement plan
7. Types of engagements
a. Conduct assurance engagements
a.1 Risk and control self-assessments
a) Facilitated approach
(1) Client-facilitated
(2) Audit facilitated
b) Questionnaire approach
c) Self certification approach
a.2 Audits of third parties and contract auditing
a.3 Quality audit engagements
a.4 Due diligence audit engagements
a.5 Security audit engagements
a.6 Privacy audit engagements
a.7 Performance audit engagements(key performance indicators)
a.8 Operational audit engagements (efficiency and effectiveness)
a.9 Financial audit engagements
b. Compliance audit engagements
c. Consulting engagements
c.1 Internal control training
c.2 Business process mapping
c.3 Benchmarking
c.4 System development reviews
c.5 Design of performance measurement systems
I. MANAGING THE INTERNAL AUDIT FUNCTION (40%-50%)A. Strategic Role of Internal AuditB. Operational Role of IAC. Establish Risk-Based IA Plan1. Use market, Product, and industry to identify new internal audit engagement opportunities.2. Use a risk framework to identify sources of potential engagements (e.g., audit universe, audit cycle requirements, management requests, regulatory mandates) 3. Establish a framework for assessing risk4. Rank and validate risk priorities to prioritize engagements in the audit plan5. Identify internal audit resource requirements for annual IA plan6. Communicate areas of significant risk and obtain approval from the board for the annual engagement plan7. Types of engagementsa. Conduct assurance engagementsa.1 Risk and control self-assessmentsa) Facilitated approach(1) Client-facilitated(2) Audit facilitated b) Questionnaire approachc) Self certification approacha.2 Audits of third parties and contract auditinga.3 Quality audit engagementsa.4 Due diligence audit engagementsa.5 Security audit engagementsa.6 Privacy audit engagementsa.7 Performance audit engagements(key performance indicators)a.8 Operational audit engagements (efficiency and effectiveness)a.9 Financial audit engagements b. Compliance audit engagementsc. Consulting engagementsc.1 Internal control trainingc.2 Business process mappingc.3 Benchmarkingc.4 System development reviewsc.5 Design of performance measurement systems
การแปล กรุณารอสักครู่..
