Considering Board and Management Requests in the Internal Audit Plan (CIA Part 3)
Overview
A risk-based internal audit plan is not built by internal audit alone. The chief audit executive (CAE) must gather input from the board and senior management. They also receive specific requests for assurance and advisory (consulting) engagements, both during annual planning and throughout the year. CIA Part 3 tests whether you know how to evaluate, prioritize, accept, defer or decline these requests without compromising independence, objectivity or the risk-based nature of the plan.
Why It Is Important
1. Alignment with organizational objectives: The board and senior management understand the strategy, emerging risks and stakeholder concerns. Their input keeps the plan relevant and value-adding.
2. Stakeholder expectations: Under the IIA Global Internal Audit Standards (Domain IV, Standard 9.4, Internal Audit Plan), the plan must be informed by input from the board and senior management. The CAE must also consider requests for services.
3. Credibility and relationships: Responding properly to requests builds trust (Standard 11.1, Building Relationships and Communicating with Stakeholders).
4. Protecting independence: Requests can be used, intentionally or not, to steer internal audit away from high-risk areas, restrict scope or push auditors into management roles. The CAE must recognize and manage these threats.
5. Resource management: Every accepted request consumes limited resources. Accepting one may mean deferring another engagement, so the trade-off must be visible to the board.
What It Is
Considering board and management requests means three things:
- Soliciting input on risks, concerns and priorities during the risk assessment that underpins the plan.
- Evaluating specific requests for assurance or advisory engagements against risk, value and capacity.
- Deciding how to handle each request: include it in the plan, schedule it later, combine it with another engagement, or decline it.
- Communicating the effect of these decisions to the board, which approves the plan.
Common sources of requests include:
- The audit committee or board chair, for example asking for a review of cybersecurity readiness or the culture of a subsidiary.
- The CEO, CFO or other executives, for example asking for a review of a new system implementation or a process improvement study.
- Operational managers, for example asking for advice on control design.
- Regulators or external auditors, through management, for example asking for reliance work.
How It Works
Step 1: Gather input during planning.
The CAE interviews or surveys board members and senior management about strategic objectives, key risks, changes and areas of concern. This input is one element of the risk assessment, alongside the following:
- the organization's risk management outputs
- prior audit results
- industry trends
- regulatory requirements
- the CAE's own judgment
Step 2: Evaluate each request.
Useful evaluation criteria include:
- Risk significance: Does the request address a significant risk to organizational objectives?
- Value added: Will it improve governance, risk management or control processes? Traditionally, the CAE considers accepting consulting engagements based on their potential to improve the management of risks, add value and improve operations.
- Alignment with strategy and the internal audit charter: Is the work within internal audit's mandate?
- Independence and objectivity: Would the work require assuming management responsibilities, such as designing and operating controls or making decisions? Would it create a conflict of interest, for example auditing work that the auditor recently performed or advised on?
- Competency and resources: Does internal audit have the skills, time and budget? If not, could it use a co-source, a guest auditor or an external service provider?
- Coverage by other providers: Is the area already assured by the second line, external auditors or others? Consider coordination and reliance.
- Timing and urgency: Is there a deadline, such as a system go-live or a regulatory date?
Step 3: Prioritize and decide.
Requests are ranked against the other potential engagements in the audit universe using the same risk-based approach. Board requests carry significant weight because the board oversees internal audit. Even so, the CAE should advise the board if a request would displace higher-risk work. Management requests are considered seriously but do not override the risk assessment.
Step 4: Handle requests that threaten independence.
The CAE should decline or reshape work that would impair independence or objectivity. Examples include:
- implementing controls
- approving transactions
- running a process
- agreeing to exclude an area from scope
Attempts to restrict scope, access or resources must be discussed with, and if necessary escalated to, the board.
Step 5: Communicate and obtain approval.
The CAE communicates the following to the board and senior management for review, and to the board for approval:
- the plan
- resource requirements
- the impact of resource limitations
- the rationale for including or excluding requested work
Step 6: Respond dynamically during the year.
The plan should be reviewed and adjusted as risks change. Mid-year requests are assessed in the same way. If an accepted request causes significant changes, such as deferring or cancelling planned engagements, the CAE communicates them promptly to the board and senior management and obtains board approval as required.
Key Distinctions to Remember
- Input versus control: The board and management provide input, and the board approves the plan. The CAE develops the plan and retains professional judgment over its risk basis.
- Assurance versus advisory: Advisory requests are accepted when they add value and do not impair objectivity. The nature and scope of advisory work is agreed with the client.
- Board requests versus management requests: The board is internal audit's primary oversight body, so its requests are generally accommodated. Management requests that conflict with risk priorities are discussed openly, and unresolved disagreements may be raised with the board.
Exam Tips: Answering Questions on Considering Board and Management Requests
1. Think risk-based first. The best answer usually evaluates the request against the risk assessment and organizational objectives. It rarely accepts or rejects the request automatically.
2. Never sacrifice independence. If the request involves the following, the correct answer is to decline, reshape or disclose the impairment:
- making management decisions
- designing or implementing controls
- limiting scope
- auditing one's own recent work
3. Watch for the 'most appropriate first step'. This is often to discuss the request with the requester to understand its objectives, or to assess its risk and resource implications. It is usually not to start fieldwork immediately.
4. Resource trade-offs go to the board. When accepting a request means deferring planned high-risk work, choose the answer that communicates the impact to the board and seeks approval.
5. The board approves the plan; management does not. Distractors often suggest that senior management or the CEO approves the plan or its changes. The board approves; senior management reviews and provides input.
6. Scope restrictions require escalation. If management asks internal audit to avoid an area or withhold findings, the correct response is to discuss the request and, if unresolved, report it to the board.
7. Consulting acceptance criteria. Remember the key phrase: potential to improve management of risks, add value and improve operations.
8. Skill gaps are not a reason for automatic refusal. Look for options such as obtaining competent assistance (co-sourcing or experts), or declining only if competency truly cannot be obtained.
9. Coordination and reliance. If other assurance providers already cover the area, the best answer may be to coordinate with or rely on their work rather than duplicate it.
10. Eliminate extreme answers. Options with words like 'always accept board requests without evaluation' or 'never perform management requests' are usually wrong.
Quick Example
The CFO asks internal audit to design the control framework for a new ERP system and then audit it after go-live. What should the CAE do?
Best answer: Offer advisory services, such as advising on control considerations, without taking ownership of control design. Recognize the objectivity threat to the later assurance work, for example by assigning different auditors or disclosing the prior involvement. Assess the resource impact and inform the board of significant plan changes.
Summary
Board and management requests are a vital input to a relevant, value-adding internal audit plan. The CAE must filter every request through the risk assessment, the charter, independence requirements and resource constraints. The rationale and impact must then be communicated transparently to the board, which approves the plan.