CAE Communication with Senior Management and the Board
In CIA Part 3 and internal audit operations, communication between the Chief Audit Executive (CAE) and senior management and the board is central to an effective internal audit function. It keeps governance bodies informed, supports independence, and confirms that internal audit delivers value. Und… In CIA Part 3 and internal audit operations, communication between the Chief Audit Executive (CAE) and senior management and the board is central to an effective internal audit function. It keeps governance bodies informed, supports independence, and confirms that internal audit delivers value. Under the IIA Standards (Standard 2060 in the former IPPF, carried forward in Domains II, III and IV of the 2024 Global Internal Audit Standards), the CAE must report periodically on several areas. These include internal audit's purpose, authority and responsibilities as defined in the charter; performance against the approved audit plan and budget; and conformance with the Standards and ethical requirements, including results of the Quality Assurance and Improvement Program (QAIP). The CAE must also report significant risk exposures and control issues, including fraud risks, governance weaknesses and other matters the board needs to know. Other required topics are resource adequacy and the effect of any resource limitations, and threats or impairments to independence or objectivity. The CAE also reports the status of management action plans. Risk acceptance is a key requirement. If the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must first discuss the matter with senior management. If it remains unresolved, the CAE must escalate it to the board. Reporting lines matter. The CAE typically reports functionally to the board or audit committee, which approves the charter, the risk-based plan, the budget, and the CAE's appointment, removal and remuneration. Administratively, the CAE reports to senior management, often the CEO. Regular private sessions with the board, without management present, strengthen independence. The CAE agrees the frequency, format and content of these communications with the board and senior management. Common formats include quarterly audit committee reports, dashboards, an annual summary or overall opinion, and immediate escalation of urgent issues. Communications should be accurate, objective, clear, concise, constructive, complete and timely. Done well, they build trust, enable informed oversight and position internal audit as a strategic advisor in governance, risk management and control.
CAE Communication with Senior Management and the Board: Complete CIA Exam Guide
Overview
Communication between the Chief Audit Executive (CAE) and senior management and the board is one of the most heavily tested governance topics in the CIA exam. It covers what the CAE must report, to whom, how often, and what to do when there is disagreement. Without effective communication, internal audit cannot add value, protect its independence, or help the organization manage risk.
1. Why It Is Important
Governance and accountability: The board oversees risk management, control, and governance. It relies on the CAE for an independent, objective view of how well those processes work.
Independence and objectivity: A direct line of communication to the board protects internal audit from undue influence by management. The board can then hear unfiltered information.
Risk escalation: Significant risk exposures, control weaknesses, fraud risks, and governance problems must reach the people who can act on them.
Resource adequacy: The board must understand whether internal audit has enough budget, staff, and skills to deliver the plan. It must also understand the consequences of any shortfalls.
Credibility and value: Regular, clear reporting shows stakeholders what internal audit has achieved. It also builds trust and supports internal audit's mandate.
Conformance with the Standards: The IIA Standards require specific communications. Failure to make them is a nonconformance.
2. What It Is: Key Concepts and Definitions
Chief Audit Executive (CAE): The person responsible for leading the internal audit function. Titles vary, for example Head of Internal Audit or Chief Audit Officer.
Board: The highest governing body that directs or oversees the organization and to which the CAE functionally reports. This is often an audit committee acting on the board's behalf. In organizations without a formal board, it may be a council, trustees, or another designated oversight body.
Senior management: The highest level of executive management, such as the CEO and CFO, who are responsible for running the organization.
Functional reporting (to the board): The board's oversight of internal audit. It covers:
- approving the internal audit charter;
- approving the risk-based audit plan;
- approving the budget and resource plan;
- receiving communications on performance;
- approving decisions on appointing and removing the CAE, and their compensation;
- making appropriate inquiries about scope or resource limitations.
Administrative reporting (usually to the CEO): Day-to-day support, such as budgeting and accounting, human resources administration, internal communications, and internal policies and procedures.
Standards framework
The CIA exam is aligned with the IIA's Global Internal Audit Standards, effective January 2025. Older study materials use the former IPPF Standards. Both are listed below so you can recognize references in either.
Former IPPF (2017):
- 1110 Organizational Independence
- 1111 Direct Interaction with the Board
- 1320 Reporting on the QAIP
- 1322 Disclosure of Nonconformance
- 2020 Communication and Approval
- 2060 Reporting to Senior Management and the Board
- 2600 Communicating the Acceptance of Risks
Global Internal Audit Standards (2024):
- Domain III (Governing the Internal Audit Function): Principle 6 Authorized by the Board, Principle 7 Positioned Independently, Principle 8 Overseen by the Board, including Standard 8.1 Board Interaction
- Standard 9.4 Internal Audit Plan
- Standard 10.1 Financial Resource Management
- Standard 11.3 Communicating Results
- Standard 11.5 Communicating the Acceptance of Risks
- Standard 12.1 Internal Quality Assessment
3. How It Works: What the CAE Communicates
A. Periodic reporting (former Standard 2060 / Domain III and Principle 11)
The CAE must report periodically on:
- internal audit's purpose, authority, responsibility, and mandate;
- performance against the approved plan;
- conformance with the Code of Ethics (Ethics and Professionalism) and the Standards;
- significant risk exposures and control issues, including fraud risks;
- governance issues;
- other matters requested by the board or senior management;
- results of the Quality Assurance and Improvement Program (QAIP).
Frequency and content are agreed with senior management and the board. They depend on how important the information is and how urgently action is needed.
B. The audit plan and resources (former 2020 / Standard 9.4 and 10.x)
The CAE communicates the following to senior management and the board for review and approval:
- the risk-based internal audit plan;
- resource requirements;
- significant interim changes to the plan.
The CAE must also communicate the impact of resource limitations on audit coverage. The board, not management, approves the plan and budget.
C. Independence and objectivity
The CAE must confirm to the board, at least annually, the organizational independence of the internal audit activity. If independence or objectivity is impaired, in fact or appearance, the CAE must disclose the details to the appropriate parties. Examples include scope restrictions, restricted access to records or personnel, and resource limitations. When the CAE has roles or responsibilities beyond internal auditing, such as compliance or risk management, safeguards must be in place. Those roles and safeguards should be discussed with the board.
D. Direct and private access
The CAE should communicate and interact directly with the board. This typically includes:
- attending board or audit committee meetings;
- holding private (executive) sessions without management present.
This lets the board raise sensitive matters, such as concerns about management, freely.
E. Communicating the acceptance of risks (former 2600 / Standard 11.5)
This sequence is tested very frequently.
Step 1: The CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, beyond its risk appetite or tolerance.
Step 2: The CAE first discusses the matter with senior management.
Step 3: If the matter is not resolved, the CAE communicates it to the board.
The CAE does not resolve the risk, override management, or accept risk on management's behalf. Responsibility for risk decisions stays with management and the board.
F. QAIP and conformance
The CAE reports QAIP results to senior management and the board, including internal and external assessments. External assessments are required at least once every five years. When nonconformance affects the overall scope or operation of internal audit, the CAE must disclose:
- the nonconformance;
- the reason for it;
- its impact.
Internal audit may state that it 'conforms with the Standards' only if the QAIP supports that statement.
G. Engagement and overall results
Final engagement communications go to parties who can ensure results receive due consideration. The CAE may also provide overall opinions or conclusions on governance, risk management, and control. These are supported by sufficient, relevant, and reliable information and consider the expectations of senior management, the board, and other stakeholders. Before releasing results outside the organization, the CAE must:
- assess the potential risk to the organization;
- consult with senior management and/or legal counsel as appropriate;
- control dissemination by restricting the use of the results.
H. Characteristics of quality communications
Communications must be:
- accurate
- objective
- clear
- concise
- constructive
- complete
- timely
If a final communication contains a significant error or omission, the CAE must send corrected information to everyone who received the original.
4. Practical Examples
Example 1: Management decides not to fix a serious IT security weakness because of cost. The CAE believes the residual risk exceeds the organization's risk appetite. The CAE discusses it with senior management first. If they will not reconsider, the CAE reports the matter to the audit committee.
Example 2: Budget cuts mean the plan cannot cover several high-risk areas. The CAE informs senior management and the board of the resource limitation and its impact on coverage.
Example 3: The CFO restricts internal audit's access to certain records. This is a scope limitation that impairs independence. The CAE must communicate it to the board.
Example 4: The CAE suspects the CEO is involved in fraud. The CAE should communicate directly with the board or audit committee, not with the CEO.
5. Exam Tips: Answering Questions on CAE Communication with Senior Management and the Board
Tip 1: Know the escalation sequence. For risk acceptance, the order is: senior management first, then the board if unresolved. A choice that goes straight to the board, skipping management, is usually wrong. The exception is when senior management itself is the problem, for example suspected executive fraud.
Tip 2: The CAE informs; management and the board decide. Reject answers in which the CAE:
- accepts risk;
- implements controls;
- forces corrective action;
- reports issues externally to regulators on their own initiative, unless legally required.
Tip 3: Separate functional from administrative reporting. The board approves the charter, plan, budget, and CAE appointment, removal, and compensation. The CEO handles administrative matters such as expense approvals and HR processes. If a choice says the CEO approves the audit plan or dismisses the CAE without board approval, it signals impaired independence.
Tip 4: Memorize the periodic reporting list. Use the mnemonic PARPC-RG-QO:
- Purpose, Authority, Responsibility;
- Performance against plan;
- Conformance;
- Risk exposures (including fraud);
- Governance issues;
- QAIP results;
- Other matters requested.
Tip 5: Resource limitations must be disclosed. Whenever resources, budget, or scope are restricted, the correct answer usually involves communicating the impact to senior management and the board.
Tip 6: Watch qualifiers. Words like 'MOST appropriate', 'FIRST', 'BEST', and 'PRIMARY' matter. 'First' often points to discussion with management or gathering facts. 'Most important reason' often points to independence or enabling the board's oversight.
Tip 7: Private sessions are a hallmark of independence. When asked how to strengthen independence or board oversight, choose answers involving direct, unrestricted access and executive sessions with the audit committee.
Tip 8: Annual confirmation of independence. If asked how often the CAE must confirm organizational independence to the board, the answer is at least annually.
Tip 9: Errors and omissions. If a significant error is found after issuing a report, the CAE communicates corrected information to all parties who received the original.
Tip 10: Frequency and content are agreed, not fixed. The Standards do not prescribe an exact frequency, such as quarterly, for periodic reports. They are determined collaboratively with senior management and the board.
Tip 11: Recognize both standard sets. Older questions cite numbers like 2060 or 2600. Newer ones refer to Principles, Domains, and Standards such as 11.5. The concepts are largely the same, so focus on the principle rather than the number.
6. Sample Exam-Style Questions
Q1: The CAE believes senior management has accepted a level of risk that is unacceptable to the organization. What should the CAE do FIRST?
A) Report the matter to the board immediately
B) Discuss the matter with senior management
C) Notify external regulators
D) Implement compensating controls
Answer: B. The CAE must first discuss the matter with senior management. Only if it remains unresolved is it escalated to the board. C and D go beyond internal audit's role.
Q2: Which of the following BEST supports the organizational independence of the internal audit activity?
A) The CAE reports administratively to the CFO
B) The CEO approves the internal audit budget
C) The board approves the appointment and removal of the CAE
D) Senior management sets the audit plan
Answer: C. Board approval of CAE appointment and removal is a key element of functional reporting and independence.
Q3: Budget cuts prevent internal audit from covering several high-risk areas. What should the CAE do?
A) Silently reduce the scope of engagements
B) Communicate the impact of the resource limitations to senior management and the board
C) Outsource the work without approval
D) Defer the areas to the next year without disclosure
Answer: B. The Standards require the CAE to communicate the impact of resource limitations.
7. Key Takeaways
- The CAE reports functionally to the board and administratively to the CEO.
- Periodic reports cover the mandate, performance, conformance, significant risks including fraud, governance, and QAIP results.
- The plan, resource needs, significant changes, and the impact of resource limitations must be communicated and approved.
- Independence is confirmed to the board at least annually, and impairments must be disclosed.
- For unacceptable risk acceptance, discuss with senior management first, then escalate to the board.
- The CAE advises and informs; it never assumes management's decision-making responsibility.
- Communications must be accurate, objective, clear, concise, constructive, complete, and timely.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!