Identifying Applicable Laws and Regulatory Mandates
Identifying applicable laws and regulatory mandates is a key step in building a risk-based internal audit plan. Compliance failures can bring fines, sanctions, litigation, loss of licenses, and reputational damage, so the chief audit executive (CAE) must understand which legal and regulatory requir… Identifying applicable laws and regulatory mandates is a key step in building a risk-based internal audit plan. Compliance failures can bring fines, sanctions, litigation, loss of licenses, and reputational damage, so the chief audit executive (CAE) must understand which legal and regulatory requirements apply to the organization and how they affect its risk profile. This topic links business knowledge (often tested in CIA Part 3) with audit planning practice (covered mainly in Part 2). The process begins with understanding the organization's industry, jurisdictions, products, and operating model. A multinational bank, for example, faces anti-money laundering, capital adequacy, consumer protection, data privacy, and securities rules, while a manufacturer may focus on environmental, health and safety, product safety, and trade regulations. Common cross-industry mandates include tax law, labor and employment law, anti-bribery and corruption laws (such as the FCPA or UK Bribery Act), financial reporting requirements (such as Sarbanes-Oxley), and data protection laws (such as GDPR). Useful sources include the legal department, compliance function, regulatory correspondence, prior examination findings, industry associations, external counsel, board and audit committee minutes, and regulatory update services. The CAE should also check whether regulators directly require certain audit activities, such as mandated audit frequency, specific coverage areas, or reports submitted to the regulator. These mandatory engagements must be built into the plan before discretionary, risk-based work is allocated. After identifying the requirements, internal audit assesses the likelihood and impact of noncompliance, considers how well the organization's compliance management system is designed, and decides how much reliance can be placed on second-line functions such as compliance and legal. Emerging or changing regulations deserve particular attention because new obligations often expose control gaps. Under the IIA's Global Internal Audit Standards, internal auditors must comply with laws relevant to the organization, and the audit plan must reflect the organization's risks and stakeholder expectations, which include regulatory compliance. The plan should be flexible enough to change when laws change, and the CAE should communicate significant compliance risks and resource limitations to senior management and the board.
Identifying Applicable Laws and Regulatory Mandates in the Internal Audit Plan (CIA Part 3)
Introduction
Identifying applicable laws and regulatory mandates is a core step when the chief audit executive (CAE) builds the risk-based internal audit plan. Before internal audit can decide which engagements to perform, it must know which legal and regulatory obligations apply to the organization. Some of these obligations create compliance risks that need assurance. Others directly require certain audit work, such as mandated reviews of internal control over financial reporting, anti-money laundering testing, or data privacy assessments.
In the CIA Part 3 syllabus, this topic sits within Internal Audit Management, under planning activities. It links to the Global Internal Audit Standards, especially Domain IV: Managing the Internal Audit Function. That domain covers internal audit strategy (Standard 9.2), assessing organizational risks (Standard 9.4), the internal audit plan (Standard 9.5), and coordination and reliance (Standard 9.6).
Why It Is Important
1. Legal and regulatory compliance is a major risk category. Breaking laws can lead to fines, sanctions, license revocation, criminal liability for executives, and lasting reputational damage. Compliance objectives are one of the core objective categories in the COSO Internal Control framework. Internal audit must consider them when assessing risk.
2. Some audit work is non-negotiable. Certain laws, regulators, or contracts require specific assurance activities. Examples include:
- Sarbanes-Oxley (SOX) Section 404 testing in the US
- Banking regulators requiring independent testing of AML/BSA programs
- Government grant compliance audits
- Industry rules such as HIPAA or PCI DSS
These items must appear in the plan regardless of how other risks are ranked. They often consume a large share of audit resources.
3. It affects resource allocation and plan credibility. If the CAE overlooks a mandate, the plan may leave the organization exposed. It may also demand unplanned work later, which disrupts the plan and strains resources.
4. It supports the board and senior management. The board relies on internal audit for assurance over governance, risk management, and control, including compliance. A plan that clearly addresses legal and regulatory requirements helps the board meet its oversight duties.
5. The Standards require it. The Global Internal Audit Standards expect the CAE to understand the organization's risks and the expectations of the board, senior management, and other stakeholders. Regulators are key external stakeholders. Standard 9.4 states that the CAE must consider risks from regulatory requirements. Where laws or regulations require specific internal audit services, the CAE must include them in the plan or arrange coordination with others who provide that assurance.
What It Is
Identifying applicable laws and regulatory mandates is the systematic process of determining which legal, regulatory, and contractual obligations:
(a) apply to the organization's industry, geographies, products, and activities;
(b) create compliance risks that should be considered in the risk assessment; and
(c) explicitly require internal audit (or another assurance provider) to perform specific work.
Key categories of requirements:
- Statutory laws: corporate law, securities law, tax law, labor and employment law, environmental law, anti-bribery and anti-corruption laws (e.g., FCPA, UK Bribery Act), data protection (e.g., GDPR).
- Regulations and regulatory guidance: rules issued by agencies such as securities commissions, central banks, insurance regulators, health authorities, and environmental agencies.
- Industry-specific mandates: banking (Basel framework, AML), healthcare (HIPAA), payment cards (PCI DSS, a contractual industry standard), utilities, pharmaceuticals (FDA rules).
- Listing requirements: stock exchange rules, such as the NYSE rule that listed companies maintain an internal audit function.
- Contractual obligations: loan covenants, grant agreements, joint venture agreements, and supplier or customer contracts that require audits or certifications.
- Internal mandates: board-directed requirements, the internal audit charter, and organizational policies.
Distinguishing two concepts:
- Compliance risk is the risk of failing to comply with applicable laws. It is assessed and prioritized like other risks.
- A regulatory mandate for audit work is an explicit requirement to perform certain assurance activities. It must be included in the plan, though the CAE may coordinate with or rely on other providers where permitted.
How It Works
Step 1: Understand the organization and its environment.
The CAE gathers information on:
- The industry the organization operates in
- The jurisdictions where it operates or sells
- Its legal structure (public, private, government, nonprofit)
- Its products and services
- Its sources of funding
Each of these drives which laws apply.
Step 2: Consult key internal sources.
- Legal counsel or the general counsel's office
- The compliance function or chief compliance officer, who often maintains a compliance obligations register
- Risk management (the enterprise risk register)
- Finance, tax, HR, IT security, and environmental and safety functions
- Board and audit committee minutes and the internal audit charter
- Prior audit reports, regulatory examination findings, and correspondence with regulators
Step 3: Consult external sources.
- Regulatory agency websites, bulletins, and enforcement actions
- Industry associations and professional bodies
- External auditors
- Legal and regulatory update services
- Peer organizations and benchmarking
Step 4: Build or update a regulatory inventory.
Many organizations keep a compliance universe or obligations register. For each requirement, it lists the owner, key controls, the assurance needed, and any mandated audit frequency. Internal audit uses this inventory as an input to the audit universe.
Step 5: Assess compliance risk.
Each obligation is assessed for impact and likelihood of non-compliance. Impact covers penalties, reputation, and operational consequences. Likelihood reflects factors such as complexity, recent changes, prior violations, and control maturity. New or changed regulations usually raise risk.
Step 6: Identify mandated audit activities.
The CAE separates out requirements that demand specific internal audit work, frequency, or reporting. These are scheduled in the plan as required engagements.
Step 7: Coordinate with other assurance providers.
Using the Three Lines Model, the CAE considers work done by:
- The compliance function (second line)
- External auditors
- Regulators and other assurance providers
This coordination avoids duplication and gaps. If internal audit relies on others' work, it must evaluate their competence, objectivity, and due professional care (Standard 9.6).
Step 8: Allocate resources and communicate.
Mandated and high-risk compliance engagements receive resources. If resources are insufficient, the CAE tells senior management and the board about the impact of resource limitations (Standard 9.5 and the resource-management standards in Principle 10). The plan, including the basis for compliance coverage, is presented to the board for approval.
Step 9: Monitor and update.
Laws change. The CAE reviews the plan at least semiannually under the Global Internal Audit Standards and adjusts it for:
- New legislation
- Regulatory enforcement trends
- Expansion into new markets
- Mergers and acquisitions
- Significant compliance failures
Roles and Responsibilities
- Management (first and second lines) owns compliance and implements controls.
- The compliance function monitors and advises on compliance (second line).
- Internal audit provides independent assurance on compliance processes and controls (third line). It does not take ownership of compliance, which would impair objectivity.
- The board or audit committee oversees compliance and approves the audit plan.
- Legal counsel interprets laws. Internal auditors are not expected to be legal experts. Under the Standards' competency requirements, they should have enough knowledge to identify risks and know when to consult experts.
Common Examples
- A US public company must include SOX 404-related testing, often coordinated with management's assessment and the external auditor.
- A bank's regulator requires periodic independent testing of the AML program. This becomes a required plan item.
- A university receiving federal grants faces single audit requirements and grant compliance obligations.
- A company expanding into the EU must consider GDPR compliance risk.
- A government agency's enabling statute may require internal audit to review specific programs annually.
Exam Tips: Answering Questions on Identifying Applicable Laws and Regulatory Mandates
Tip 1: Mandated work goes in the plan. If a question states that a law, regulator, or the board requires a specific audit, the correct answer usually includes it in the plan. This applies even if the risk assessment would rank it lower. Watch for distractors suggesting the CAE can skip mandated work because of low assessed risk.
Tip 2: Choose the best source of information. When asked how the CAE should identify applicable laws, the best answers typically involve consulting legal counsel and the compliance function and reviewing regulatory sources. Answers in which internal audit independently interprets laws or provides legal opinions are usually wrong.
Tip 3: Internal audit provides assurance, not ownership. Management is responsible for compliance. Reject answers in which internal audit designs compliance controls, takes ownership of compliance, or certifies legal compliance on management's behalf. Internal audit can, however, advise within its charter while preserving objectivity.
Tip 4: Think coordination and reliance. If other providers (compliance, external auditors, regulators) already cover a requirement, the best answer often involves coordinating or relying on their work after evaluating it. Duplicating effort is rarely best. Leaving gaps is never acceptable.
Tip 5: Recognize risk-raising triggers. New legislation, expansion into new jurisdictions, acquisitions, prior regulatory findings, whistleblower complaints, and changes in business model all increase compliance risk. Questions may ask which factor most warrants revising the plan. Look for significant changes in the regulatory environment.
Tip 6: Resource shortfalls must be communicated. If mandated work strains resources, the CAE should communicate the impact to senior management and the board. The CAE should not quietly drop engagements or reduce scope without disclosure.
Tip 7: Know the planning sequence. The usual order is:
1. Understand strategy and objectives.
2. Identify risks, including legal and regulatory requirements.
3. Assess and prioritize.
4. Include mandated engagements.
5. Coordinate with others.
6. Allocate resources.
7. Obtain board approval.
8. Monitor and update.
Questions asking for the first step generally point to understanding the organization, its objectives, and stakeholder expectations, including regulatory requirements.
Tip 8: Distinguish compliance risk from compliance mandates. Compliance risk is weighed in the risk assessment. A mandate is a requirement to perform specific work. Read carefully to see whether the question describes a risk to evaluate or a requirement to fulfill.
Tip 9: Watch the words BEST, MOST, and FIRST. Several options may be partially correct. Pick the one most aligned with the Standards:
- Risk-based planning
- Stakeholder input
- Board approval
- Independence and objectivity
- Coordination with other providers
Tip 10: Competency and use of experts. If a question involves complex or unfamiliar regulations, the best answer often involves obtaining training, using guest auditors, or engaging external specialists. Proceeding without adequate expertise or declining all coverage are usually wrong.
Sample Question Walkthrough
A CAE is preparing the annual plan. A recently enacted regulation requires the organization to obtain independent assurance over its data privacy controls each year. Risk assessment results show data privacy as moderate risk. What should the CAE do?
A. Exclude it because higher-risk areas take priority.
B. Include the required data privacy assurance in the plan and adjust resources or communicate constraints as needed.
C. Ask management to perform a self-assessment instead.
D. Defer it until the next plan cycle.
Answer: B. Mandated assurance must be addressed regardless of relative risk ranking. A self-assessment by management (option C) is not independent assurance. Deferring the work (option D) risks non-compliance.
Key Takeaways
- Laws, regulations, and contracts are critical inputs to the risk-based audit plan.
- Mandated audit work must be included or covered through coordinated assurance.
- Use legal, compliance, regulators, and external auditors as information sources.
- Management owns compliance. Internal audit provides independent assurance.
- Continuously monitor regulatory changes and update the plan accordingly.
- Communicate resource limitations and obtain board approval of the plan.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!