Learn Internal Audit Plan (CIA Part 3) with Interactive Flashcards
Master key concepts in Internal Audit Plan through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.
Defining the Audit Universe
In CIA Part 3, defining the audit universe is the first step in building a risk-based internal audit plan. The audit universe is the complete inventory of auditable entities, meaning every area of the organization that internal audit could review. Under IIA guidance, the chief audit executive must base the plan on a documented assessment of the organization's strategies, objectives, and risks, and that assessment starts with a clearly defined universe. Auditable entities can be organized in several ways: by business unit or subsidiary, by geographic location, by core and support process (procurement, payroll, revenue, IT general controls), by information system, by major project or program, by legal or regulatory obligation, and by significant third-party relationship such as outsourced services. Many organizations combine these views into a matrix so that cross-functional risks are not missed. To build the universe, auditors review organizational charts, strategic plans, budgets, process maps, risk registers, regulatory requirements, and prior audit results. They also interview senior management and the board. The goal is completeness, because any area left out of the universe will never be considered for audit coverage. Entities should also be defined at a practical size: specific enough to be audited in one engagement, but broad enough to keep the list manageable. Once the universe is defined, each entity is risk-assessed using factors such as financial materiality, complexity, regulatory exposure, control environment, pace of change, fraud potential, and time since the last audit. The resulting risk ranking helps the chief audit executive decide which entities enter the annual or rolling plan. Coverage by other assurance providers, such as compliance or external audit, should be mapped to avoid duplication. The universe is not static. It must be updated at least annually, and whenever there are acquisitions, new products, new systems, restructurings, or emerging risks like cybersecurity or ESG issues. This keeps the audit plan aligned with the organization's current risk profile and supports communication with the board about audit coverage.
Key Components of the Audit Universe
The audit universe is the complete inventory of all auditable entities, processes, functions, and activities within an organization. It is the foundation from which the chief audit executive (CAE) builds the risk-based internal audit plan required by the IIA Standards. Its key components are described below. First, organizational units: business divisions, subsidiaries, departments, geographic locations, and joint ventures that can be audited as distinct entities. Second, business processes: core and support processes that cut across units, such as procure-to-pay, order-to-cash, payroll, treasury, inventory management, and financial reporting. Third, information technology: systems, applications, infrastructure, cybersecurity, data governance, and IT general controls, which are increasingly significant risk areas. Fourth, governance, risk management, and compliance areas: board oversight, ethics programs, enterprise risk management, regulatory compliance, and fraud risk management. Fifth, strategic initiatives and projects: new products, mergers and acquisitions, system implementations, and major capital projects, along with emerging risks such as ESG and third-party or outsourcing risk. Each auditable entity should be linked to the organization's strategic objectives and described with supporting attributes, including the process owner, applicable regulations, financial materiality, and the date and results of prior audits. Each entity is then risk-assessed using factors such as financial impact, complexity, rate of change, control environment, management concerns, fraud susceptibility, and regulatory exposure. Ranking entities by risk helps the CAE prioritize coverage, set audit frequency, and allocate limited resources. The audit universe should also map assurance coverage provided by other parties, such as external auditors, compliance teams, and second-line functions, to avoid duplication and support coordination. Finally, it must be dynamic: the CAE should update it at least annually, and whenever significant organizational, regulatory, or technological changes occur, so the audit plan stays aligned with stakeholder expectations and the organization's current risk profile.
Applying IIA Topical Requirements in Audit Planning
Under the IIA's Global Internal Audit Standards (effective January 2025), Topical Requirements are a mandatory component of the International Professional Practices Framework. Each one sets a minimum baseline for auditing a specific, high-risk subject, starting with Cybersecurity. Others, such as Third-Party Risk, are in development. For CIA Part 3, understand that Topical Requirements strengthen, rather than replace, the risk-based planning process described in Standard 9.4 (Internal Audit Plan).
The chief audit executive first performs the organization-wide risk assessment. If that assessment identifies a covered topic as a significant risk, or an engagement includes the topic in its scope, the related Topical Requirement applies. Topical Requirements therefore do not dictate what goes into the plan. Risk drives the plan, and the requirement then governs how the topic is evaluated once it is included. Conformance is mandatory for assurance engagements and recommended for advisory engagements.
When a requirement applies, auditors must assess the topic across three dimensions: governance, risk management, and control processes. For cybersecurity, this means reviewing:
- governance elements such as strategy, policies, roles, and board oversight;
- risk management activities such as identifying, assessing, and escalating cyber risks;
- controls such as access management, incident response, monitoring, and vendor security.
The CAE should consider whether the internal audit function has enough competency and resources, including co-sourcing or specialists, to apply the requirement properly. This feeds into resource planning and budget discussions with the board. Auditors must document how each requirement was applied. If any element is excluded from an engagement, the rationale must be documented, for example because the element was covered by another assurance provider or was out of scope.
Conformance with Topical Requirements is evaluated within the Quality Assurance and Improvement Program (QAIP) and during external quality assessments. Exam questions typically test these applicability triggers, the risk-based relationship between the plan and the requirements, documentation expectations, and the CAE's responsibility for ensuring capability and conformance.
Considering Board and Management Requests
When developing the risk-based internal audit plan, the chief audit executive (CAE) must consider requests and input from the board and senior management. This ensures the plan aligns with organizational strategies, objectives, and key stakeholder expectations. Under the IIA's Global Internal Audit Standards (Standard 9.4, Internal Audit Plan), and previously Standard 2010 (Planning), the CAE seeks input on the organization's risks, concerns, and priorities while preserving internal audit's independence and objectivity.
Key considerations include:
1. Gathering input: The CAE meets periodically with board members, the audit committee, and senior management to understand strategic initiatives, emerging risks, regulatory changes, and areas of concern. Interviews, surveys, and risk workshops are common methods.
2. Evaluating requests: Requests are not automatically included. The CAE assesses each one against the organization-wide risk assessment, considering its significance, its alignment with objectives, and its potential to improve governance, risk management, and control processes. Consulting requests are accepted based on their potential to add value and improve operations.
3. Balancing resources: Because audit resources are limited, the CAE prioritizes requests alongside risk-based assurance work. If accommodating a request would leave high-risk areas uncovered, the CAE must communicate the resource limitation and its impact to senior management and the board.
4. Maintaining independence: Management requests must not dictate audit scope in ways that impair objectivity or let management steer auditors away from sensitive areas. The board, not management, ultimately approves the plan.
5. Flexibility: The plan should be dynamic and allow for ad hoc requests arising from new risks, fraud allegations, or organizational changes. Significant changes are communicated to the board and senior management for review and approval.
6. Documentation and communication: The CAE documents how stakeholder input influenced the plan and explains why any requests were declined or deferred.
For the CIA exam, remember that stakeholder input is essential, but the plan must remain risk-based, independent, and approved by the board.
Identifying Applicable Laws and Regulatory Mandates
Identifying applicable laws and regulatory mandates is a key step in building a risk-based internal audit plan. Compliance failures can bring fines, sanctions, litigation, loss of licenses, and reputational damage, so the chief audit executive (CAE) must understand which legal and regulatory requirements apply to the organization and how they affect its risk profile. This topic links business knowledge (often tested in CIA Part 3) with audit planning practice (covered mainly in Part 2).
The process begins with understanding the organization's industry, jurisdictions, products, and operating model. A multinational bank, for example, faces anti-money laundering, capital adequacy, consumer protection, data privacy, and securities rules, while a manufacturer may focus on environmental, health and safety, product safety, and trade regulations. Common cross-industry mandates include tax law, labor and employment law, anti-bribery and corruption laws (such as the FCPA or UK Bribery Act), financial reporting requirements (such as Sarbanes-Oxley), and data protection laws (such as GDPR).
Useful sources include the legal department, compliance function, regulatory correspondence, prior examination findings, industry associations, external counsel, board and audit committee minutes, and regulatory update services. The CAE should also check whether regulators directly require certain audit activities, such as mandated audit frequency, specific coverage areas, or reports submitted to the regulator. These mandatory engagements must be built into the plan before discretionary, risk-based work is allocated.
After identifying the requirements, internal audit assesses the likelihood and impact of noncompliance, considers how well the organization's compliance management system is designed, and decides how much reliance can be placed on second-line functions such as compliance and legal. Emerging or changing regulations deserve particular attention because new obligations often expose control gaps.
Under the IIA's Global Internal Audit Standards, internal auditors must comply with laws relevant to the organization, and the audit plan must reflect the organization's risks and stakeholder expectations, which include regulatory compliance. The plan should be flexible enough to change when laws change, and the CAE should communicate significant compliance risks and resource limitations to senior management and the board.
Market Trends, Organizational Changes, and Emerging Issues
In the Certified Internal Auditor (CIA) curriculum, the internal audit plan is a risk-based, dynamic document. The IIA's Global Internal Audit Standards (Standard 9.4) require the chief audit executive (CAE) to base the plan on a documented assessment of the organization's strategies, objectives and risks, and to review and adjust it as conditions change. Three key inputs drive these adjustments.
Market Trends: These are external shifts in the industry, economy, competition, technology and customer behavior. Examples include rising interest rates, supply chain disruption, digital transformation, new competitors or changing consumer preferences. Auditors monitor trends through industry publications, economic data, peer benchmarking and discussions with management. A market trend may increase the likelihood or impact of certain risks, such as liquidity, credit, or revenue risk. The audit plan may then need to move these areas up in priority or add new engagements.
Organizational Changes: These are internal developments that alter the risk profile. Examples include mergers and acquisitions, restructurings, new leadership, new product lines, system implementations such as ERP migrations, outsourcing and expansion into new regions. Change often weakens controls, because processes are redesigned, staff turn over and segregation of duties may lapse. The CAE should keep regular communication with senior management and the board to learn of planned changes early. Internal audit can then provide assurance or advisory services before, during or after the transition.
Emerging Issues: These are new or evolving risks that may not yet be well understood or captured in the risk register. Examples include cybersecurity threats, artificial intelligence governance, ESG and climate reporting, data privacy regulations, geopolitical instability and fraud schemes. Auditors identify them through professional networks, regulatory updates and horizon scanning.
Collectively, these factors ensure the audit plan stays relevant, flexible and aligned with stakeholder expectations. Significant changes to the plan must be communicated to senior management and the board for review and approval. The CAE must also assess whether internal audit has adequate resources, skills and competencies to address the new areas, using co-sourcing or training where needed.
Emerging Technology Risks in Audit Planning
In CIA Part 3, which covers business knowledge for internal auditing, emerging technology risks are a key input to the risk-based internal audit plan. Under the IIA Global Internal Audit Standards, the chief audit executive must build a plan from a documented assessment of the organization's strategies, objectives, and risks. That plan must be updated as the risk landscape changes, and rapidly evolving technologies are among the fastest-moving drivers of change. Emerging technologies include artificial intelligence and machine learning, robotic process automation, cloud computing, blockchain and distributed ledgers, the Internet of Things, big data analytics, and mobile and remote-work platforms. Each creates opportunities and new exposures. These include cybersecurity threats, data privacy and regulatory compliance issues, algorithmic bias and model risk, third-party and vendor dependence, weak data integrity, inadequate change management, skills shortages, and governance gaps where adoption outpaces policies and controls. When planning, auditors should first identify which technologies the organization is adopting or piloting and how they link to strategic objectives. They should then assess inherent risk, control maturity, and potential impact on financial reporting, operations, and reputation, and prioritize engagements. Internal audit can add value by providing advisory services early in implementation, such as reviewing project governance, system development controls, and security by design, rather than waiting for post-implementation assurance. Planning must also address internal audit's own capability. The CAE should evaluate whether staff have sufficient competencies in IT, data analytics, and cyber risk. Gaps can be closed through training, guest auditors, or cosourcing, consistent with proficiency and due professional care requirements. Many functions adopt agile or rolling audit plans, continuous risk assessment, and continuous auditing tools so they can respond quickly to technological change. Coordination with second-line functions such as IT risk, information security, and compliance helps avoid duplication and supports combined assurance. Finally, the CAE communicates technology-related risks and resource needs to senior management and the board, ensuring the plan reflects the organization's risk appetite and strategic direction.
Audit Cycle Requirements
In the Certified Internal Auditor (CIA) curriculum, audit cycle requirements refer to how often each auditable entity in the audit universe must be reviewed. They are a key input when the chief audit executive (CAE) builds the risk-based internal audit plan. Under the IIA Standards (Standard 2010 Planning and its successor, Global Internal Audit Standard 9.4 Internal Audit Plan), the plan must reflect the organization's priorities and risks. Cycle requirements help make that coverage systematic and defensible.
There are two main sources of cycle requirements. The first is mandatory or externally imposed cycles, which come from laws, regulators, contracts, or the board. Examples include annual reviews of internal control over financial reporting under Sarbanes-Oxley, banking regulations requiring periodic reviews of anti-money-laundering or capital adequacy processes, and grant or contract compliance audits. These must be scheduled regardless of internal risk scores.
The second is risk-driven cycles, in which frequency is tied to each unit's assessed risk. A common approach audits high-risk areas annually, moderate-risk areas every two to three years, and low-risk areas every four to five years. Some low-risk units may be covered only through continuous monitoring or control self-assessment.
When planning, the CAE should balance the following considerations:
- Coverage of the entire audit universe over a defined period, so that no significant area goes unreviewed indefinitely.
- Available resources and competencies. If resources fall short of what cycle requirements demand, the CAE must communicate the impact to senior management and the board.
- Flexibility. Cycles should not be rigid. Emerging risks, organizational changes, fraud events, or new systems may justify accelerating or deferring audits.
- Coordination with other assurance providers, such as external auditors, compliance, and risk management, to avoid duplication.
- Approval. The board must review and approve the plan, including significant changes to planned cycles.
For the exam, remember that a purely cyclical, calendar-driven plan is weaker than a risk-based plan. Cycles serve as a baseline and a compliance safeguard. Risk assessment ultimately determines priority, and the plan should be reviewed and adjusted at least annually.
Risk Assessment Methodology and Risk Prioritization
Under the IIA Standards, the chief audit executive (CAE) must build a risk-based internal audit plan, grounded in a documented risk assessment that is updated at least annually. In the current CIA syllabus, audit planning is tested mainly in Part 2, while Part 3 supplies the business knowledge (strategy, IT, finance, operations) needed to judge risk well.
Risk Assessment Methodology: First, define the audit universe, meaning all auditable entities such as processes, business units, systems, projects and third parties. Next, understand the organization's strategy, objectives and existing enterprise risk management (ERM) results, and interview senior management and the board. Then identify risks for each entity: strategic, operational, financial, compliance, IT/cyber, fraud and reputational. Each risk is evaluated on two main dimensions. Impact is the financial, operational or reputational consequence. Likelihood is the probability of occurrence. Auditors may also weigh velocity (speed of onset), complexity, transaction volume, prior audit findings, management changes, regulatory change and time since the last audit. Inherent risk is assessed first. Control effectiveness is then considered to estimate residual risk. Scoring may be qualitative (high, medium, low), quantitative (weighted numeric factors) or a combination, often shown on a heat map.
Risk Prioritization: Entities are ranked by their composite risk scores. The highest-risk areas receive more frequent audits (for example annually), and lower-risk areas follow a longer cycle. The CAE adjusts priorities for several factors:
- requests from the board and senior management;
- regulatory mandates;
- emerging risks;
- reliance on assurance providers such as external auditors, compliance or second-line functions (combined assurance).
Priorities must also be matched with available resources, skills and budget. Any resource shortfall that limits coverage must be communicated to senior management and the board.
Outcome: The prioritized plan, including engagements, timing and resource needs, is reviewed by senior management and approved by the board. The plan stays flexible and is revised whenever significant changes occur in the business, its risks or its controls.
Keeping the Audit Plan Aligned with Strategy and Stakeholders
Keeping the internal audit plan aligned with strategy and stakeholders means the plan stays a living document that reflects the organization's objectives, risks, and the expectations of those it serves, rather than a fixed annual schedule. Under the Global Internal Audit Standards (notably Standard 9.4, Internal Audit Plan), the chief audit executive (CAE) builds the plan from a documented risk assessment, at least annually, and updates it as conditions change.
Strategic alignment starts with understanding the organization's mission, strategic objectives, business model, and risk appetite. The CAE links each planned engagement to the key risks that threaten those objectives, such as digital transformation, regulatory change, cybersecurity, ESG commitments, or mergers. This ensures audit resources go where they add the most value and support the board's oversight of strategy.
Stakeholder alignment requires ongoing communication with the board, senior management, and other key parties, including external auditors, regulators, and second-line functions such as risk management and compliance. The CAE gathers their perspectives on emerging risks and assurance needs, coordinates coverage to avoid duplication or gaps, and may rely on other assurance providers where appropriate (Standard 9.5).
Because risks shift quickly, many functions use rolling or dynamic plans, such as quarterly or six-month horizons, revisited regularly. Triggers for revision include new strategies, reorganizations, significant incidents, new regulations, technology changes, or audit findings that reveal new exposures. Significant changes, along with their rationale and impact on coverage, must be communicated to the board and senior management for review and approval.
The CAE must also report whether resources are sufficient to deliver the plan and explain the consequences of resource limitations, such as risks that will not be covered. Key practices include continuous risk monitoring, periodic plan reviews, stakeholder meetings, documented change logs, and linking plan items to strategic objectives. For the CIA exam, remember: a risk-based plan, flexibility, board approval, communication of changes, and coordination with other assurance providers.
Maintaining a Dynamic Audit Plan
Maintaining a dynamic audit plan means treating the internal audit plan as a living, risk-based document rather than a fixed annual schedule. Under the IIA's Global Internal Audit Standards (Standard 9.4, Internal Audit Plan), the chief audit executive (CAE) must create a plan that supports the organization's objectives and must review and revise it in response to changes in the organization's business, risks, operations, programs, systems, and controls. The goal is to keep internal audit's resources focused on the areas of greatest risk and value at any given time.
A dynamic plan rests on continuous risk assessment. Instead of assessing risk once a year, the CAE tracks emerging risks and changing conditions, such as new regulations, mergers and acquisitions, technology implementations, cybersecurity threats, leadership changes, economic shifts, fraud incidents, or significant control failures. Useful sources include ongoing discussions with senior management and the board, results of completed engagements, enterprise risk management updates, key risk indicators, continuous monitoring and data analytics, and input from other assurance providers.
Many functions use rolling plans, such as quarterly or six-month horizons, or an agile approach. In these models, engagements are prioritized in a backlog and reprioritized as risks evolve. Flexibility is also built in by holding some resources in reserve for special requests, investigations, or emerging issues, and by balancing assurance and advisory work.
Governance and communication are essential. The CAE must communicate significant changes to the plan, and their impact, to the board and senior management for review and approval. This includes explaining any resource limitations that prevent coverage of high-risk areas, so leadership understands any assurance gaps they are accepting.
Finally, a dynamic plan requires matching resources to priorities, documenting the reasons for changes, and periodically confirming that the plan still aligns with organizational strategy. This keeps internal audit relevant, responsive, and credible as a trusted advisor.
Communicating the Audit Plan and Subsequent Changes
Communicating the audit plan is how the Chief Audit Executive (CAE) obtains formal support and approval for internal audit's planned coverage. Under the IIA Standards (Standard 2020 in the 2017 framework, carried forward into Standard 9.4 of the Global Internal Audit Standards), the CAE must communicate the internal audit plan and its resource requirements to senior management and the board for review and approval. This communication normally includes the risk-based engagements planned for the period and the rationale for selecting them. It also covers the staffing, budget, skills and technology needed to carry out the plan, along with the expected assurance and advisory coverage and any reliance on other assurance providers. Most importantly, the CAE must explain the impact of resource limitations, meaning any significant risks or areas that will not be covered because resources are insufficient. This lets the board judge whether the remaining risk is acceptable or whether more resources should be provided. Senior management reviews the plan for operational relevance, and the board (or audit committee) gives final approval, which reinforces internal audit's independence. Because risks, operations, systems and regulations change, the audit plan must be dynamic and reviewed regularly, often quarterly or whenever significant events occur. Significant interim changes must be communicated promptly to senior management and the board for review and approval. Examples include adding or cancelling major engagements, reacting to emerging risks such as fraud, cyber incidents, mergers or new regulations, and changes in staffing or budget. Minor scheduling adjustments usually do not require formal approval, but the CAE should define in the internal audit charter or policies what counts as significant. Documentation of the approved plan, every revision, and the reasons for each change supports quality assurance reviews and demonstrates conformance. For the CIA exam, remember the key elements: the plan is risk-based, it is approved by the board, resource limitations and their impact must be disclosed, and significant changes require re-communication and approval.
Internal and External Assurance Providers
In the CIA Part 3 syllabus, which covers managing the internal audit function, internal and external assurance providers matter when building a risk-based internal audit plan. The Chief Audit Executive (CAE) should identify every party that gives assurance over the organization's risks and coordinate with them. This avoids duplicated work, closes coverage gaps, and gives the board and senior management a complete view of assurance. The IIA's Global Internal Audit Standards address this under Coordination and Reliance (Standard 9.5).
Internal assurance providers are functions inside the organization that monitor risk and control. Under the IIA Three Lines Model, they include first-line management controls and self-assessments. They also include second-line functions such as risk management, compliance, information security, quality assurance, health and safety, environmental monitoring, and legal. These groups usually report to management, so they are less independent than internal audit, which is the third line.
External assurance providers are outside the organization. Examples include the external financial statement auditor, regulators and government inspectors, ISO certification bodies, actuaries, and specialist consultants. Another example is a service organization auditor who issues SOC 1 or SOC 2 reports on outsourced processes. Some external providers report mainly to outside stakeholders, while others are engaged by the board or management.
When planning, the CAE often builds an assurance map. This tool links key risks to the providers that cover them and shows where coverage overlaps or is missing. It supports a combined assurance approach. Before relying on another provider's work, the CAE should evaluate their:
- competence
- objectivity and independence
- due professional care
- scope and methodology
- quality of evidence and reporting
The level of reliance can then be adjusted, for example by reducing internal audit's planned work in well-covered areas. The CAE should document the basis for reliance and share relevant information with these providers.
Even when relying on others, the CAE remains responsible for the conclusions and opinions that internal audit gives. Effective coordination improves efficiency and optimizes audit resources. It also strengthens the board's confidence in the organization's overall governance, risk management, and control.
Coordinating Assurance Coverage and Assurance Mapping
In CIA Part 3, coordinating assurance coverage and assurance mapping are key techniques the chief audit executive (CAE) uses when building a risk-based internal audit plan. Under the IIA Standards (formerly Standard 2050, now Standard 9.5 of the Global Internal Audit Standards), the CAE should share information, coordinate activities and consider relying on the work of other internal and external assurance and consulting providers. The goal is to ensure proper coverage and minimize duplication of effort. Assurance providers typically include first-line management self-assessments, second-line functions such as risk management, compliance, quality, health and safety and information security, and third-line internal audit. External providers include external auditors, regulators and specialist consultants. Coordinating with them reduces audit fatigue for the business, lowers costs and gives the board a more complete view of risk. Assurance mapping is the practical tool used to achieve this coordination. It is a matrix or grid that lists the organization's key risks or processes on one axis and the assurance providers on the other. Each cell records who provides assurance, the scope, frequency, last review date, and the level or strength of assurance provided. The map reveals gaps, where significant risks receive little or no assurance, and overlaps, where several providers review the same area unnecessarily. Internal audit can then focus its plan on high-risk gaps and reduce effort where reliable coverage already exists. This approach is often called combined assurance. Before relying on another provider's work, the CAE must evaluate that provider's competence, objectivity and due professional care. The CAE must also assess the scope, objectives and quality of the work performed. Reliance does not transfer responsibility, because internal audit remains accountable for its own conclusions. The CAE should document the basis for reliance, communicate the results to senior management and the board, and update the assurance map as risks and providers change.
Relying on the Work of Other Assurance Providers
Relying on the work of other assurance providers is a key consideration when the chief audit executive (CAE) builds the risk-based internal audit plan. Under the Global Internal Audit Standards (Standard 9.5, Coordination and Reliance), the CAE should coordinate with internal and external providers of assurance and advisory services and consider relying on their work. This improves coverage, reduces duplication and audit fatigue, and supports a combined assurance view for the board. Other providers fit the Three Lines Model. Second-line functions include risk management, compliance, information security, health and safety, and quality assurance. External providers include external auditors, regulators, certification bodies, and outsourced specialists. The process usually starts with an assurance map. This links the organization's key risks to the providers that cover them, showing gaps and overlaps. The plan can then focus internal audit resources where assurance is weak or absent. Before relying on another provider's work, the CAE must evaluate several factors: 1) Independence and objectivity, including reporting lines, conflicts of interest, and whether the provider assesses areas it manages. 2) Competence, including qualifications, experience, and professional certifications. 3) Due professional care, including whether the work was properly planned, supervised, documented, and reviewed. 4) Scope, objectives, and methodology, and whether they match internal audit's needs. 5) Whether findings and conclusions are reasonable and supported by sufficient evidence. The CAE should document the basis for reliance. The degree of reliance can vary: full reliance, partial reliance with additional testing, or no reliance. Reliance does not transfer accountability. Internal audit remains responsible for its own conclusions and opinions. The CAE should also establish a consistent process for coordination, such as shared risk terminology, timing of work, and reporting. The CAE should communicate the reliance approach to senior management and the board. For the CIA exam, remember these points: coordination is expected, reliance requires evaluation, and responsibility for internal audit conclusions always stays with internal audit.