An auditor reviewing payroll sees the compensation of every executive in the company. Nothing stops her from telling anyone. Only the confidentiality principle does, and it binds her after she leaves the organization too.
Confidentiality is the ethics principle requiring you to respect the value and ownership of information you receive, and to use it only for authorized purposes. Two obligations sit inside it: protect the information, and do not exploit it.
The obligation attaches to information you receive because of your role, regardless of source. Working papers, interview notes, system extracts, whistleblower identities, draft findings, and the fact that an engagement is even happening are all in scope. Public information is not confidential simply because you found it during an engagement.
KEY: Confidentiality is not a promise of silence to the auditee. It restricts disclosure outside authorized channels; it never blocks reporting a finding to the chief audit executive or the board. A stem where an auditor hides a finding "to keep it confidential" is always wrong.
Common mistakes
- Using confidentiality to suppress a finding. Confidentiality governs who outside the chartered line hears it, never whether the chief audit executive and board hear it.
- Over-collecting data. Pulling all 8,400 payroll records for a 60-item sample multiplies exposure 140 times without improving evidence.
- Releasing records to outsiders directly. Subpoenas, regulator requests, and preservation notices go to the chief audit executive and legal counsel first.
Bottom line
- Confidentiality has two duties: protect information received in your role, and never use it for personal benefit or any unauthorized purpose.
- It restricts disclosure outside authorized channels; it never blocks reporting a finding to the chief audit executive or board.
- Obligation rank: legal duty first, professional requirements second, organizational policy third; concealing an illegal act is never a legitimate policy.
- Working papers are organizational records held in audit custody; follow retention schedules, and keep no personal copies after leaving.
Exam shortcut
Read the stem for direction of flow. Information moving up the chartered reporting line is always permitted; confidentiality never justifies withholding from the chief audit executive or board. Information moving sideways to a manager, or outward to a regulator, vendor, or personal device, requires authorization you almost certainly do not have alone.
The full lesson (about 1,895 words, 13 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 6
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.