Regulatory Requirements and Internal Policies in Engagement Objectives
In CIA Part 2, engagement planning requires internal auditors to set clear objectives that state what the engagement is meant to accomplish. Regulatory requirements and internal policies are central inputs because they define the compliance expectations the organization must meet. Under the IIA Sta… In CIA Part 2, engagement planning requires internal auditors to set clear objectives that state what the engagement is meant to accomplish. Regulatory requirements and internal policies are central inputs because they define the compliance expectations the organization must meet. Under the IIA Standards, auditors set objectives after a preliminary risk assessment of the activity under review. These objectives should address governance, risk management, and control, including compliance with laws, regulations, policies, procedures, and contracts. Regulatory requirements are external obligations imposed by legislatures, government agencies, and industry regulators. Examples include data privacy laws, anti-money laundering rules, environmental regulations, financial reporting mandates such as Sarbanes-Oxley, and health and safety codes. Failing to comply can lead to fines, legal action, loss of licenses, and reputational damage. During planning, auditors identify which regulations apply to the area under review, assess the compliance risk, and write objectives such as evaluating whether controls ensure timely and accurate regulatory filings. Internal policies are the organization's own rules, such as codes of conduct, procurement policies, IT security standards, and delegation-of-authority matrices. They usually turn external requirements into operating practice and also reflect management's risk appetite. Engagement objectives may test whether policies are well designed, communicated, followed in practice, and kept current with changing regulations. Both sources supply the evaluation criteria auditors use to judge the condition they find. Auditors must confirm that the criteria are adequate. If they are missing or weak, auditors should work with management to develop suitable criteria, and they may report the gap itself as a finding. Practical steps include reviewing applicable laws, prior audit and regulatory examination results, and policy manuals, and interviewing compliance and legal staff. Auditors then align objectives with these requirements, define a scope that covers the high-risk compliance areas, and assign staff with the right expertise. Strong alignment makes the engagement relevant, defensible, and valuable to the board and senior management.
Regulatory Requirements and Internal Policies in Engagement Objectives (CIA Part 2: Engagement Planning)
Overview
In CIA Part 2 (Practice of Internal Auditing), the Engagement Planning domain tests whether you can set clear, risk-based engagement objectives. When internal auditors set those objectives, they must consider the organization's strategies, objectives and risks. They must also consider the regulatory requirements and internal policies and procedures that apply to the activity under review.
This guide explains what the concept is, why it matters, how it works in practice, and how to answer exam questions about it.
1. What It Is
Regulatory requirements are external obligations the organization must meet. Examples include:
- Laws and statutes, such as anti-bribery laws, data privacy laws (for example, GDPR), environmental laws and labor laws.
- Regulations issued by government agencies or industry regulators, such as banking regulators, securities commissions, health authorities and tax authorities.
- Contractual or industry obligations that work like regulations, such as PCI DSS for card data, licensing terms and grant conditions.
Internal policies and procedures are rules, standards and instructions that management and the board set to direct how the organization operates. Examples include:
- Codes of conduct and ethics policies.
- Delegation of authority and approval matrices.
- Procurement, IT security, travel and expense, and HR policies.
- Standard operating procedures and desk manuals.
Engagement objectives are broad statements of what the engagement intends to accomplish. Compliance-related objectives typically ask questions like these:
- Does the area comply with applicable laws and regulations?
- Are internal policies adequately designed and actually followed?
- Do internal policies adequately reflect current regulatory requirements?
The Global Internal Audit Standards (2024) cover this mainly under Standard 13.3 Engagement Objectives and Scope. The standard says objectives must reflect the results of the engagement risk assessment and relevant evaluation criteria. Under Standard 13.4 Evaluation Criteria, laws, regulations, policies and procedures are common sources of criteria. The older IPPF expressed the same idea in Standard 2210, which required auditors to consider the probability of significant errors, fraud, noncompliance and other exposures. Standard 2210.A3 required adequate criteria to evaluate governance, risk management and controls.
2. Why It Is Important
- Compliance is a core control objective. Frameworks such as COSO list compliance with laws and regulations as one of three objective categories, alongside operations and reporting.
- Noncompliance creates serious risks. These include fines, sanctions, license revocation, litigation, reputational damage and even personal liability for directors and officers.
- Regulations and policies supply evaluation criteria. Auditors need a benchmark to compare the condition against. Laws and policies are often the most objective and authoritative criteria available.
- They support risk-based planning. Areas subject to heavy or new regulation usually carry higher inherent risk and deserve more focused objectives.
- Stakeholders expect it. Boards, audit committees, regulators and external auditors rely on internal audit for assurance over compliance.
- They help ensure the engagement adds value. Auditors can check whether policies are outdated, missing or misaligned with regulations, not just whether people follow them.
3. How It Works in Practice
Step 1: Understand the activity under review. During preliminary planning, the auditor gathers background information. This includes process walkthroughs, prior audit reports, regulator correspondence and organizational charts. The auditor also identifies which laws, regulations and internal policies govern the area.
Step 2: Identify applicable requirements. Typical sources include:
- The legal or compliance department.
- Regulatory filings and examination reports.
- Policy repositories and management interviews.
- Industry associations.
- Recent changes in legislation.
Step 3: Perform the engagement-level risk assessment. The auditor considers questions such as:
- What happens if a requirement is not met?
- How likely is noncompliance?
- Are there recent regulatory changes, new products or new jurisdictions?
- Have regulators raised prior findings?
- How complex are the rules?
Step 4: Evaluate the adequacy of criteria. The Standards require auditors to determine whether management has established adequate criteria. If the criteria are adequate (for example, a current policy aligned with the law), the auditor uses them. If they are inadequate, the auditor works with management or the board to develop appropriate criteria. A finding may also be warranted if policies are missing or outdated.
Step 5: Draft engagement objectives. Example objectives include:
- Evaluate whether payroll processing complies with applicable wage and hour laws and the organization's payroll policy.
- Assess whether the vendor onboarding process is designed and operating effectively to comply with anti-bribery and sanctions regulations.
- Determine whether the IT access management policy reflects current data protection regulatory requirements.
Step 6: Set scope and the work program. The scope covers the relevant systems, locations, periods and records. The work program contains procedures that test compliance, such as sampling transactions and comparing them against legal or policy requirements.
Step 7: Coordinate. The auditor considers relying on or coordinating with other assurance providers. These include the compliance function, legal, external auditors and regulators. Coordination avoids duplication, consistent with the Standards on coordination and reliance.
Key distinctions to remember:
- Compliance with policy versus adequacy of policy. An employee may follow a policy perfectly while the policy itself breaches regulation. Good objectives address both.
- Assurance versus legal opinion. Internal auditors evaluate compliance controls and identify indicators of noncompliance. They do not provide legal opinions. Legal counsel interprets complex law.
- Management's responsibility. Management owns compliance and the design of policies. Internal audit provides independent assurance.
- Consulting engagements. Objectives here may involve advising on the design of a new compliance policy. Objectivity must still be preserved, and the auditor must not assume management responsibility.
4. Common Exam Question Types
- Best objective: Which engagement objective is most appropriate for an audit of X? The answer is usually the one tied to risks, regulations and policies, and stated in measurable terms.
- Most important factor: When establishing objectives for a heavily regulated area, what should the auditor consider first or most? The answer is usually applicable laws and regulations and the risk of noncompliance.
- Inadequate criteria scenario: The policy is outdated or missing. What should the auditor do? The answer is to work with management or the board to develop appropriate criteria, or to report the deficiency.
- Conflict scenario: Internal policy conflicts with regulation. The regulation takes precedence. The auditor should identify the gap and communicate it.
- Source of information: Where would the auditor best identify applicable regulations? Good answers include legal or compliance counsel, regulatory exam reports and the regulations themselves.
- Roles: Who is responsible for compliance? The answer is management. Internal audit provides assurance.
Exam Tips: Answering Questions on Regulatory Requirements and Internal Policies in Engagement Objectives
1. Think risk first. Objectives flow from the engagement risk assessment. Choose answers that link regulatory or policy requirements to significant risks rather than generic checklist testing.
2. Know the hierarchy. Laws and regulations override internal policies. If a policy conflicts with a law, the auditor flags the policy as deficient.
3. Check the adequacy of criteria. If an option says to evaluate whether management's criteria are adequate before testing compliance, it is often correct. If criteria are inadequate, the auditor works with management or the board to develop suitable criteria.
4. Do not overstep into legal advice. Reject options where the auditor issues a legal opinion or decides legal liability. Prefer options that consult legal counsel or the compliance function.
5. Remember who owns compliance. Management designs policies and ensures compliance. Be wary of answers where internal audit writes and implements policy during an assurance engagement, because that impairs objectivity.
6. Look for both design and operating effectiveness. Strong objectives ask whether policies are adequately designed (aligned with regulations) and operating effectively (followed in practice).
7. Watch the words 'first', 'most important' and 'best'. In planning questions, gaining an understanding of the area, including its regulatory environment, usually comes before drafting objectives or testing.
8. Recognize red flags that raise compliance risk. These include new legislation, regulator findings, prior audit issues, expansion into new jurisdictions, high penalties and complex rules. They justify specific compliance-focused objectives.
9. Distinguish objectives, scope and procedures. Objectives state what the engagement will achieve. Scope defines boundaries such as time, locations and systems. Procedures are the detailed steps. Do not pick a procedure when the question asks for an objective.
10. Remember coordination. If the compliance function or regulators have recently reviewed the area, consider coordination and reliance in planning. Do not simply duplicate their work.
11. Use elimination. Remove options that are too vague (for example, 'review the department'), outside internal audit's role, or that ignore significant regulatory exposure.
12. Apply the Standards' language. Remember three phrases: 'risks', 'evaluation criteria' and 'compliance with laws, regulations, policies and procedures'. Answers echoing these concepts are frequently correct.
Quick Example
Question: An internal auditor is planning an audit of the customer data handling process in a jurisdiction that recently enacted strict privacy legislation. The organization's data policy was last updated five years ago. Which engagement objective is most appropriate?
A. Determine whether employees follow the existing data policy.
B. Evaluate whether the data policy and related controls are adequate to ensure compliance with the new privacy legislation, and whether they operate effectively.
C. Provide a legal opinion on the organization's privacy exposure.
D. Rewrite the data policy for management.
Answer: B.
- A is wrong because it ignores that the outdated policy may itself be noncompliant.
- C is wrong because legal opinions are outside internal audit's role.
- D is wrong because rewriting the policy assumes management responsibility and impairs objectivity.
- B is correct because it addresses both the adequacy of the criteria against the regulation and operating effectiveness.
Summary
Regulatory requirements and internal policies are central inputs to engagement objectives. They define the risks of noncompliance and supply the criteria against which auditors evaluate performance. On the exam, choose answers that:
- Are risk-based.
- Assess both policy adequacy and compliance.
- Respect that laws override policies.
- Keep internal audit in an independent assurance role rather than a legal or management role.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!