Policies and Procedures as Sources of Information: A Complete CIA Part 2 Guide
Introduction
In CIA Part 2 (Practice of Internal Auditing), the domain Information Gathering, Analysis, and Evaluation tests how internal auditors collect sufficient, reliable, relevant, and useful information during an engagement. Policies and procedures are among the first and most basic sources an auditor reviews. They show how management intends a process to work. The auditor then compares that intent with what actually happens in practice.
Why It Is Important
1. They set the criteria. Under the IIA Standards (Global Internal Audit Standards, Domain V, Standard 13.4 on evaluation criteria), auditors must identify the criteria used to judge the activity under review. Internal policies and procedures are usually the main source of these criteria.
2. They help the auditor understand the process. During preliminary planning, policies and procedures show who does what, which approvals are needed, which controls exist, and how documents flow.
3. They support control design assessment. Documented procedures let the auditor judge whether controls are adequately designed before testing whether they operate effectively.
4. They reveal gaps and risks. Missing, outdated, contradictory, or unclear policies are findings in their own right. They point to weaknesses in the control environment and in governance.
5. They make the work efficient. Reviewing documents first helps the auditor focus fieldwork on high-risk areas and design targeted tests.
What It Is
Policies are broad statements of management intent, direction, and principles. They state what must be achieved and why. Example: a policy that all purchases above a threshold require competitive bids.
Procedures are detailed, step-by-step instructions that put policies into action. They state how, who, and when. Example: the steps to obtain three quotes, document the evaluation, and route it for approval.
Related documents include:
- Process manuals and standard operating procedures (SOPs)
- Codes of conduct
- Delegation of authority matrices
- Job descriptions and organization charts
- Flowcharts and narratives
- Board-approved charters
Where they fit among information sourcesPolicies and procedures are
documentary information. They are usually generated internally by management. They tell the auditor how things
should work, not how they
do work. This makes them a starting point, not conclusive evidence.
How It Works in an EngagementStep 1: Planning and gaining an understanding.- Obtain and read the relevant policies, procedures, prior audit reports, and organization charts.
- Identify key objectives, risks, and controls.
- Check whether the documents are current, approved, communicated, and consistent with laws, regulations, and higher-level policies.
Step 2: Corroborating the documentation.- Interviews: ask staff to describe what they actually do.
- Walkthroughs: trace one transaction from start to finish.
- Observation: watch the procedure being performed.
A walkthrough confirms the auditor's understanding and shows differences between the documented process and actual practice.
Step 3: Evaluating design adequacy.Ask whether the policy, if followed, would mitigate the risk. Consider:
- Segregation of duties
- Authorization levels
- Reconciliations
- Clarity of instructions
- Whether responsibilities are clearly assigned
Step 4: Testing compliance and operating effectiveness.Use the policy as the criterion and test a sample of transactions against it. Typical techniques are inspecting documents, vouching, tracing, and reperformance.
Step 5: Reporting findings.A finding typically includes:
- Criteria: often the policy itself
- Condition: what the auditor found
- Cause: why it happened
- Effect: the risk or impact
- Recommendation
If no policy exists, the auditor may use external criteria such as laws, industry standards, or frameworks like COSO. Where criteria are unclear, the auditor should work with management to agree on suitable criteria.
Key Concepts and Limitations- Documented is not the same as performed. A well-written policy gives no assurance that it is followed. Compliance must be tested.
- Reliability: internally prepared documents are generally less reliable than external evidence or direct auditor observation and reperformance. A policy shows design intent, not operating evidence.
- Currency: outdated policies may not reflect new systems, regulations, or organizational changes.
- Informal practices: in small units or new processes, procedures may be undocumented. The auditor then relies more on interviews, observation, and flowcharting, and may recommend formal documentation.
- Deviations may be acceptable. An exception approved by authorized personnel may be legitimate. Unapproved workarounds are a finding.
- Hierarchy: laws and regulations override board policies. Board policies override departmental procedures. Conflicts between levels are a governance issue.
- Management responsibility: management designs, approves, and maintains policies. Internal audit evaluates them and recommends improvements. Writing them would impair objectivity.
Exam Tips: Answering Questions on Policies and Procedures as Sources of InformationTip 1: Know the purpose at each phase.- Planning: to understand the process and identify controls.
- Fieldwork: to provide criteria for testing.
- Reporting: to support the criteria element of a finding.
If a question asks for the
first or
best initial step, reviewing existing documentation such as policies, procedures, and prior reports is often correct.
Tip 2: Distinguish design from operation.Reviewing a policy manual supports conclusions about design only. If an answer choice claims that reading procedures proves controls are working effectively, eliminate it. Effectiveness requires testing.
Tip 3: Rank evidence reliability.From most to least reliable:
- Direct auditor knowledge (observation, reperformance)
- External documents
- Internal documents with strong controls
- Oral statements
A procedures manual is internal documentary evidence. It is useful but not conclusive on its own.
Tip 4: Use walkthroughs to confirm understanding.Questions often ask how to verify that documented procedures reflect actual practice. The best answer is usually a walkthrough or observation, not more document review or relying only on management's description.
Tip 5: Missing or outdated policies are findings.When a scenario says procedures are undocumented or outdated, the correct response is usually:
- Gather information through interviews, observation, and flowcharting.
- Report the weakness.
- Recommend that management develop or update the policies.
It is not to have internal audit write them. Assuming operational responsibility impairs objectivity.
Tip 6: Criteria selection.If internal policies are absent or inadequate, look for answers that use authoritative external criteria or criteria agreed with management. Avoid answers where the auditor invents personal standards without discussion.
Tip 7: Watch for conflicts.If a procedure conflicts with a law or a higher-level policy, the law or higher authority prevails. The conflict should be reported to the appropriate level of management, and possibly the board.
Tip 8: Read the qualifier words.Words such as
most,
best,
primary,
first, and
least decide the answer. For example, the
primary purpose of reviewing procedures during a preliminary survey is to understand the process and its controls, not to detect fraud or form an opinion.
Tip 9: Link deviations to root cause.When staff do not follow procedures, the better answer explores
why. Possible causes include lack of training, poor communication, impractical procedures, or weak supervision. The best answers address the cause rather than just noting the exception.
Sample QuestionAn internal auditor reviews the accounts payable procedures manual and concludes the controls are well designed. What should the auditor do next to determine whether the controls function as described?
A. Ask the AP manager to confirm in writing that procedures are followed.
B. Perform a walkthrough and test a sample of transactions against the documented procedures.
C. Rely on the manual because it was approved by the CFO.
D. Rewrite the procedures to strengthen controls.
Answer: B.- A is weaker oral or management-provided evidence.
- C confuses design with operation.
- D impairs objectivity.
SummaryPolicies and procedures tell the auditor how management intends processes to operate. They are essential for understanding processes, setting criteria, and assessing control design. They are internal documentary evidence and must be corroborated through walkthroughs, observation, and testing. On the exam, remember:
document review shows design; testing proves operation; management owns the policies; internal audit evaluates them.