• Evaluation of conformance to IIA Standards and requirement to report the results of its
QAIP periodically to senior management and the governing body
• An external assessment of the activity at least once every five years
Independence and Objectivity; the charter should state that the CAE will ensure independence
and objectivity of the internal audit function to carry out its duties in an unbiased manner.
Furthermore, internal audit should have no direct operational responsibility or authority over any
of the activities audited.
Scope of Internal Audit Activities; the charter should define the scope of the internal audit
function. The scope should include providing independent assessments of the adequacy and
effectiveness of governance, risk management, and control processes.
c.) Discuss the various issues that are of primary concerns for an auditor involved in
information system audit [10]
Answer
Carrying out an audit requires the auditor to consider 3 types of risks. Firstly, inherent risk – The
‘natural’ risk that will occur with every information system. Different information systems have
different degree of risks. For example, a company’s logistics information system might face less
inherent risks as compared to its financial information system (simply because the financial
information system is more attractive to people looking to commit fraud).
Moreover, control risk – This type of risk occurs because of poor internal controls. Any type of
information system will have control risks if it has poor controls. For example, if the payroll
department’s files are not securely locked in a separate room, it faces a higher control risk.
Furthermore, detection risk – The risk that auditors face: The audit may not be able to detect
material flaws or errors in the system.
An Auditor should also be concerned about, Cybersecurity; cyber security audit is designed to be
a comprehensive review and analysis of your business’s IT infrastructure. It encompasses
everything that pertains to protecting our sensitive data, personally identifiable information,
protected health information, personal information, intellectual property data and governmental
and industrial information systems. It helps mitigate the consequences of a breach and
demonstrate that your organization has taken the necessary steps to protect client and company
data