Compliance Process Risks and Controls
In CIA Part 2, engagement planning requires internal auditors to understand the risks and controls in compliance processes. These processes help the organization follow laws, regulations, contracts, internal policies, and procedures. The IIA Standards require auditors to consider the objectives of … In CIA Part 2, engagement planning requires internal auditors to understand the risks and controls in compliance processes. These processes help the organization follow laws, regulations, contracts, internal policies, and procedures. The IIA Standards require auditors to consider the objectives of the activity under review, its significant risks, and the adequacy and effectiveness of the related governance, risk management, and control processes. Key compliance risks include: - Regulatory noncompliance that leads to fines, penalties, sanctions, or loss of licenses. - Reputational damage from publicized violations. - Legal liability and litigation. - Failure to identify new or changing regulations. - Inadequate training that causes unintentional breaches. - Deliberate misconduct, such as bribery, fraud, or data privacy violations. - Noncompliance by third parties such as vendors, agents, and outsourced providers. Typical controls include: - A compliance program supported by a strong tone at the top and board oversight. - A designated chief compliance officer or compliance function. - A regulatory inventory that maps each obligation to an accountable owner. - Written codes of conduct, policies, and procedures. - Periodic compliance risk assessments to prioritize high-risk areas. - Employee training and annual certifications. - Ongoing monitoring and testing. - Whistleblower hotlines with non-retaliation protections. - Consistent disciplinary actions. - Third-party due diligence. - Regular reporting of compliance metrics to management and the audit committee. Frameworks such as COSO and the U.S. Federal Sentencing Guidelines help guide program design. During planning, auditors gather background information through interviews, prior audit reports, regulatory examination findings, complaint logs, and incident records. They perform a preliminary risk assessment, identify key controls, and set the engagement objectives and scope. A typical objective is to determine whether the compliance function effectively identifies obligations, prevents violations, and detects violations promptly. Auditors often prepare a risk and control matrix that links each compliance risk to its mitigating controls and the planned audit tests. Auditors should also apply the Three Lines Model. Management owns compliance, the compliance function oversees it, and internal audit provides independent assurance. Finally, auditors should seek legal expertise when needed, stay alert to fraud indicators, and design work programs that evaluate both the design adequacy and the operating effectiveness of compliance controls.
Compliance Process Risks and Controls: A Complete CIA Part 2 Guide to Engagement Planning
Introduction
Compliance process risks and controls are a core topic in CIA Part 2 (Practice of Internal Auditing), under Engagement Planning. Internal auditors are often asked to plan engagements that check whether an organization follows laws, regulations, contracts, and internal policies. To plan such an engagement well, the auditor must understand the risks in the compliance process and the controls that address them. This guide explains why the topic matters, what it covers, how it works in practice, and how to answer exam questions on it.
Why Compliance Process Risks and Controls Are Important
1. Legal and financial exposure: Non-compliance can lead to fines, penalties, lawsuits, loss of licenses, and even criminal liability for directors and officers.
2. Reputational damage: Regulatory breaches, such as data privacy violations, environmental incidents, or bribery, can quickly destroy stakeholder trust.
3. Governance expectations: The board and senior management rely on internal audit for independent assurance that compliance risks are identified and managed. The IIA Standards require internal audit to evaluate risk exposures relating to compliance with laws, regulations, policies, procedures, and contracts.
4. Operational continuity: Some regulators can suspend operations, for example in health, safety, or banking.
5. Dynamic environment: Regulations change often, and organizations operate across many jurisdictions. This raises the risk of outdated compliance programs.
6. Exam relevance: The CIA exam regularly tests the ability to identify compliance risks, link them to suitable controls, and choose the right planning steps for a compliance engagement.
What Is the Compliance Process?
The compliance process is the set of activities an organization uses to make sure it follows external and internal requirements. These requirements fall into two groups.
External requirements:
- Laws and statutes, such as anti-bribery, anti-money laundering, tax, labor, and environmental law.
- Regulations issued by government agencies.
- Industry standards and contractual obligations, such as loan covenants, licensing terms, and service level agreements.
Internal requirements:
- Policies, procedures, codes of conduct, and ethics policies.
A typical compliance process, often called a compliance program or compliance management system, includes:
1. Identification of applicable laws, regulations, and obligations, often kept in a regulatory inventory or compliance register.
2. Compliance risk assessment to rank requirements by likelihood and impact of non-compliance.
3. Policies and procedures that turn requirements into operational practice.
4. Assigned responsibility, such as a Chief Compliance Officer, compliance function, and process owners.
5. Training and communication so employees know their obligations.
6. Monitoring and testing, both ongoing and periodic, by management and the compliance function.
7. Reporting and escalation of breaches, including whistleblower or hotline mechanisms.
8. Investigation, discipline, and remediation of violations.
9. Regulatory change management to update the program when rules change.
10. Oversight by the board or audit committee.
Key Compliance Process Risks
1. Failure to identify requirements: The organization is unaware of an applicable law or of a new regulation.
2. Regulatory change risk: Policies are not updated in time when laws change.
3. Inadequate risk assessment: Compliance resources are aimed at low-risk areas while high-risk areas go unmonitored.
4. Unclear ownership and accountability: No one is responsible for specific obligations.
5. Poor tone at the top: Management pressure to meet targets encourages rule-breaking. This is a weak control environment.
6. Insufficient training and awareness: Employees break rules out of ignorance.
7. Ineffective monitoring: Violations are not detected promptly.
8. Weak reporting channels: Employees fear retaliation, so issues go unreported.
9. Inconsistent enforcement: Violations are not disciplined consistently, which weakens deterrence.
10. Third-party risk: Agents, suppliers, or distributors breach laws on the organization's behalf, for example through bribery.
11. Inaccurate regulatory reporting: Filings submitted to regulators are late, incomplete, or wrong.
12. Inadequate documentation and record retention: The organization cannot show evidence of compliance when regulators ask.
13. Lack of independence of the compliance function: Compliance reports to the business units it oversees.
14. Multi-jurisdictional complexity: Requirements conflict or differ across countries.
Key Compliance Controls
Preventive controls stop violations before they occur:
- A code of conduct and compliance policies approved by the board.
- A regulatory inventory or obligations register with assigned owners.
- Regulatory change monitoring through legal subscriptions, counsel, and industry associations.
- Mandatory training with attestations or certifications.
- Third-party due diligence and contract clauses, such as anti-bribery and right-to-audit clauses.
- Segregation of duties and authorization limits.
- Pre-approval for high-risk activities, such as gifts, political contributions, and new market entry.
- System-enforced controls, such as automated sanctions screening and access restrictions.
Detective controls identify violations that have occurred:
- Compliance monitoring and testing programs.
- Whistleblower hotlines with anonymity and non-retaliation protections.
- Exception reports and data analytics, such as unusual payments or transactions to high-risk countries.
- Reconciliations of regulatory filings to source data.
- Periodic management self-assessments and certifications.
- Internal audit compliance reviews.
Corrective controls fix issues and prevent them from recurring:
- Investigation protocols.
- Consistent disciplinary action.
- Root cause analysis and corrective action plans.
- Voluntary disclosure to regulators where appropriate.
- Policy updates after incidents.
Governance controls:
- An independent Chief Compliance Officer with direct access to the board or audit committee.
- Regular compliance reporting to the board.
- An adequately resourced compliance function.
How It Works: Planning a Compliance Engagement
When planning a compliance engagement, the internal auditor follows the engagement planning requirements of the IIA Standards. These include establishing objectives, scope, and a work program, and considering risks and controls.
Step 1: Understand the area under review. Gather background information: applicable laws and regulations, prior audit reports, regulatory examination findings, the organization's compliance register, the organizational structure, and recent incidents. Interview the compliance officer, legal counsel, and process owners.
Step 2: Identify and assess compliance risks. Do a preliminary risk assessment. Consider the significance of each requirement, the penalty for violations, the complexity of the rules, recent regulatory changes, past violations, and management's own risk assessment.
Step 3: Establish engagement objectives. Objectives should reflect the risks. Example: To determine whether controls provide reasonable assurance that the organization complies with anti-money laundering regulations.
Step 4: Define scope. Decide on the requirements, locations, business units, time period, and third parties to cover. Scope must be sufficient to meet the objectives. Note any items that are excluded.
Step 5: Identify and evaluate controls. Document the control design using walkthroughs, flowcharts, and narratives. Compare it with criteria, such as the regulation itself, internal policies, or frameworks like COSO and ISO 37301 (Compliance Management Systems).
Step 6: Determine evaluation criteria. The IIA Standards require adequate criteria for evaluating governance, risk management, and control. In compliance engagements, the laws and regulations themselves often serve as the criteria. If management's criteria are inadequate, the auditor should work with management to develop suitable criteria.
Step 7: Allocate resources. Consider whether the team has enough expertise. Specialized regulations, such as tax, environmental, or healthcare rules, may require legal or technical experts. The auditor may use guest auditors or outsourced specialists, but should not give legal opinions.
Step 8: Develop the work program. Include procedures such as:
- Reviewing the compliance register for completeness against current law.
- Testing training completion records.
- Sampling transactions to test adherence to requirements.
- Reviewing hotline logs and investigation outcomes.
- Recomputing and reconciling regulatory filings.
- Testing third-party due diligence files.
- Reviewing board minutes for compliance reporting.
Step 9: Coordinate and communicate. Agree on the plan with management. Consider relying on the work of other assurance providers, such as the compliance function or external regulators, after evaluating their objectivity and competence.
Roles and Responsibilities: A Common Exam Theme
- Management, the first line, owns compliance and is responsible for complying with laws and regulations.
- The compliance function, the second line, designs the compliance framework, monitors it, and advises.
- Internal audit, the third line, provides independent assurance on whether the compliance process is adequate and effective. Internal audit should not own compliance processes, because this would impair objectivity.
- The board or audit committee oversees the compliance program.
- Legal counsel interprets the law. Internal auditors are not expected to be legal experts, but they should have enough knowledge to identify compliance risks and should consult counsel when needed.
- Suspected illegal acts should be communicated to the right level of management and the board, and legal counsel should be consulted. The auditor should follow the organization's policies and applicable laws on reporting.
Worked Example
Question: An internal auditor is planning an engagement to assess compliance with a new data privacy regulation that took effect six months ago. Which of the following should the auditor do FIRST?
A. Test a sample of customer consent records.
B. Obtain an understanding of the regulation's requirements and management's process for implementing them.
C. Recommend that management appoint a data protection officer.
D. Issue a report on the organization's non-compliance.
Answer: B. Planning begins with understanding the requirements and the process, including risks and controls. Testing (A) comes during fieldwork. Recommending (C) or reporting (D) before gathering evidence is premature.
Exam Tips: Answering Questions on Compliance Process Risks and Controls
1. Know the planning sequence. Understand the area, then assess risk, set objectives, define scope, set criteria, allocate resources, and build the work program. When asked what to do first, the answer is usually to gain an understanding or perform a risk assessment, not testing.
2. Management owns compliance. If an option suggests internal audit should design, implement, or run the compliance program, it is usually wrong because it threatens objectivity. Internal audit evaluates and recommends.
3. Laws and regulations are the criteria. In compliance engagements, the regulation defines what is acceptable. Questions about appropriate criteria often point to the legal or regulatory requirement itself.
4. Match the control to the risk. Learn common pairings:
- Unawareness of new laws: regulatory change monitoring.
- Employee ignorance: training and attestation.
- Undetected violations: monitoring, analytics, and hotlines.
- Fear of reporting: anonymous hotline with non-retaliation policy.
- Third-party bribery: due diligence and contract clauses.
- Weak deterrence: consistent discipline.
5. Separate preventive, detective, and corrective controls. Read the question carefully. If it asks for the best preventive control, rule out hotlines and audits, which are detective.
6. Tone at the top is foundational. When asked for the most important element of an effective compliance program, answers about management commitment, board oversight, or the control environment are often correct.
7. Auditors are not lawyers. If an option says the auditor should give a legal opinion or decide on legal liability, it is likely wrong. The right action is to consult legal counsel.
8. Handle suspected illegal acts properly. Report to appropriate management and the board, consult legal counsel, and follow policy. Do not confront suspects or contact regulators on your own unless law or policy requires it.
9. Look for risk-based answers. The IIA favors risk-based planning. Options that focus effort on high-impact, high-likelihood requirements, such as those with severe penalties or a history of violations, are usually better than ones that cover everything equally.
10. Consider reliance on others. Internal audit may rely on the compliance function's work only after assessing its competence, objectivity, and due professional care. Watch for options that rely on it blindly.
11. Watch for qualifiers. Words such as MOST, BEST, FIRST, PRIMARY, and LEAST matter. Several options may be partly true, so choose the one that best fits the stage of the engagement and the auditor's role.
12. Expect scenarios. Many questions describe a situation, such as a company entering a new country, a new regulation, or repeated regulatory fines. Identify the root risk first, then choose the control or planning step that addresses it most directly.
13. Use the three lines model. Place each party's role correctly: business owners in the first line, compliance in the second, and internal audit in the third.
14. Documentation equals evidence. If an organization cannot prove compliance, regulators often treat it as non-compliance. Record retention and documentation controls are frequently tested.
Summary
Compliance process risks arise when an organization fails to identify, implement, monitor, or enforce legal, regulatory, contractual, and policy requirements. Controls include governance, preventive, detective, and corrective measures, such as a regulatory inventory, change monitoring, training, hotlines, monitoring and testing, and consistent discipline. When planning a compliance engagement, the internal auditor gains an understanding of the area, assesses risks, sets objectives, scope, and criteria (usually the laws themselves), allocates competent resources, and develops a risk-based work program. Throughout, the auditor stays objective, consults legal experts when needed, and remembers that management owns compliance while internal audit provides independent assurance.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!