MasomoHub · CIA Part 1 · Section A

Purpose, independence and the internal audit role

Distinguish assurance from advice, understand reporting relationships and recognise threats to independence.

Syllabus 2025 · Reviewed 3 Sep 2026

Start with the purpose

Internal audit helps an organisation understand whether its governance, risk management and controls support its objectives. It provides independent assessment and practical advice. It does not take ownership of the processes it evaluates.

In an examination scenario, identify three things before choosing an answer: the objective at risk, the person who owns the decision, and the evidence available to the auditor. A response can sound helpful while assigning management's responsibility to internal audit.

Mandate, charter and reporting

The mandate establishes internal audit's authority and responsibilities. The charter documents how the function operates, including its position, reporting relationships, scope and access. The chief audit executive works with the board and senior management to establish appropriate arrangements. Board approval gives the charter authority; informal acceptance by an operational manager is insufficient.

Functional reporting to the board supports independence. Administrative reporting supports day-to-day operations such as facilities and payroll. Assess who can influence audit scope, resources, appointment of the chief audit executive and communication of results. A reporting line that appears appropriate on paper does not cure a practical restriction on access.

Independence and objectivity

Independence concerns the position and freedom of the audit function. Objectivity concerns an auditor's impartial judgment. A chief financial officer preventing an audit of treasury creates a restriction on the function. An auditor assessing a process they recently managed creates a self-review threat. Disclosure and safeguards must address the actual threat; simply promising to be fair is not enough.

When a limitation arises, establish the facts, assess its significance and communicate through the appropriate governance channel. Do not silently accept a scope restriction or claim to have obtained evidence that was withheld.

Assurance and advisory work

Service Main question Boundary
Assurance What does the evidence show about the subject being assessed? The auditor reaches an objective assessment against suitable criteria.
Advisory How could a proposed process or decision be improved? Management retains responsibility for decisions and implementation.

An auditor can advise a project team on access controls before a system goes live. Approving user access on management's behalf would move the auditor into operational responsibility. Advising on a control and later assessing it also requires consideration of objectivity threats and safeguards.

Worked example

A procurement director asks internal audit to select the winning supplier because the auditors understand fraud risks. The useful response is to explain relevant risks, evaluate the procurement controls and advise on evaluation criteria. Management should choose the supplier. Taking the decision would make a later procurement audit a review of internal audit's own action.

Common mistakes

  • Treating internal audit as the owner of risk management.
  • Assuming a direct board reporting line removes every independence threat.
  • Confusing advice on control design with responsibility for operating the control.
  • Choosing absolute assurance when evidence and judgment support reasonable conclusions.

Check your understanding

Why is unrestricted access important? An auditor needs sufficient relevant information to support conclusions. Restrictions can weaken the scope and reliability of the work.

Who decides how a business risk is treated? Management makes and owns the response, within the organisation's governance arrangements. Internal audit evaluates and advises.

Revision prompt: For each scenario, state who owns the decision before deciding what the auditor should do.