A
- Assurance services
- Objective assessments of governance, risk management, or control processes that result in a conclusion or opinion, such as a controls assessment or a compliance audit. One of the two service categories internal audit provides.
- Advisory services
- Services in which internal auditors provide advice and insight without giving an assurance conclusion, such as control training, benchmarking, or advice during system development. Nature and scope are agreed with management.
B
- Board
- The highest-level governing body charged with overseeing the organization's strategy and operations, such as a board of directors or an audit committee acting on its behalf. The body to which the CAE reports functionally.
C
- Chief audit executive (CAE)
- The senior leader responsible for managing the internal audit function, including the audit plan, resources, quality, and communication with senior management and the board. Reports functionally to the board and administratively within the organization.
- Control environment
- The attitudes, awareness, and actions of the board and management concerning internal control, sometimes called tone at the top. The foundation on which specific control activities rest.
D
- Due professional care
- The care and skill of a reasonably prudent and competent internal auditor, including assessing engagement costs relative to benefits, the probability of significant errors or fraud, and the adequacy of governance, risk management, and control processes.
- Detective control
- A control designed to identify an undesirable event after it has occurred, such as reconciliations, cycle counts, or exception reports.
F
- Fraud triangle
- The model explaining the conditions under which fraud occurs: motivation (pressure), opportunity, and rationalization. Used in assessing fraud risk during planning and engagements.
G
- Global Internal Audit Standards
- The IIA's authoritative framework for the professional practice of internal auditing, published January 2024. Organized into 5 domains, 15 principles, and numbered standards, each with requirements and considerations for implementation. Replaced the 2017 International Standards.
I
- Internal audit mandate
- The authority, role, and responsibilities granted to the internal audit function by the board, established through the internal audit charter. The mandate is the foundation for the function's position and scope of work.
- Internal audit charter
- The formal document that defines the internal audit function's purpose, authority, role, and responsibilities. Developed by the chief audit executive, discussed with senior management, and approved by the board.
- Independence
- The freedom of the internal audit FUNCTION from conditions that threaten its ability to carry out responsibilities in an unbiased manner. Established positionally, chiefly through the CAE's functional reporting line to the board.
- Inherent risk
- The level of risk before considering the effect of management's risk responses and controls. Compare residual risk.
O
- Objectivity
- An unbiased mental attitude required of each INDIVIDUAL internal auditor, allowing judgments free of compromise and conflicts of interest. Impairments include self-review, familiarity, and financial interests.
P
- Professional skepticism
- Maintaining an unbiased mental attitude and critically assessing the reliability of information rather than assuming it, an element of due professional care.
- Preventive control
- A control designed to stop an undesirable event before it occurs, such as segregation of duties, authorization limits, or physical access restrictions.
R
- Risk appetite
- The amount and types of risk an organization is willing to pursue or accept in pursuit of its objectives, typically articulated at board level. Translated into operational limits through risk tolerance.
- Risk tolerance
- The acceptable variation around specific objectives and performance targets, translating the organization's broad risk appetite into operational boundaries.
- Residual risk
- The risk remaining after management's responses and controls have taken effect. When residual risk exceeds the organization's appetite, the CAE may need to escalate through the risk-acceptance communication process.
S
- Self-review threat
- An objectivity impairment that arises when an auditor assesses work he or she previously performed or was responsible for, such as auditing a process the auditor designed. The standard safeguard is reassignment.
T
- Three Lines Model
- The IIA's model for organizational roles in risk and control: management owns and manages risk (first line), risk and compliance functions support and monitor (second line), and internal audit provides independent assurance (third line).
- Topical Requirements
- Mandatory components of the IIA's International Professional Practices Framework that set a minimum baseline for auditing specified risk areas, such as cybersecurity. Mandatory for assurance engagements when the topic is in scope.