Domain 1: The IS Audit Process8 min · 3 questions

Standards, Ethics and the Audit Charter

What gives an IS auditor the authority to demand evidence, and what obliges them to hand back work they are not competent to perform.

What this makes you able to do

Evaluate whether an audit engagement is being conducted in accordance with professional standards and an approved audit charter.

By the end you can

  • Distinguish between standards, guidelines and procedures and state which are mandatory.
  • Identify the elements an audit charter must establish for the audit function to operate.
  • Determine the correct response when an engagement conflicts with the code of professional ethics.

Transcript

Standards, ethics and the audit charter. This lesson is about two things: what gives an information systems auditor the authority to demand evidence, and what obliges that same auditor to hand back work they cannot competently perform.

Start with a situation. An infrastructure manager tells you the configuration files you have asked for are commercially sensitive, and cannot be shared with audit. You have never been refused before, and the request sounds almost reasonable when they say it.

So what actually gives you the right to insist? It is not your job title, and it is not seniority. It is a document that most auditors read once when they join and then never think about again.

That document is the audit charter. It is approved at the highest level, normally by the board or the audit committee, and it is what establishes that the audit function exists at all and what it is permitted to do.

For the exam, know what a charter has to establish. First, the purpose, responsibility and authority of the audit function. That is the foundation everything else sits on.

Second, and this is the one that gets tested hardest, the reporting line. Audit should report to the audit committee or the board, not to the management it audits.

And then the right of access to records, personnel, systems and premises. The scope of audit activity. And accountability, meaning how the function reports on its own performance. When a question involves access being refused or management disputing audit remit, the charter is almost always the correct first reference.

Look again at that reporting line, because it is not administrative detail. An audit function that reports to the chief information officer cannot independently audit the chief information officer. The reporting line is the structural guarantee of independence. Without it, independence depends on everybody continuing to behave well, which is not a control.

Now the framework itself, and one distinction the exam tests directly. Standards are mandatory. They state what an auditor must do, and a departure has to be justified and disclosed. Guidelines are guidance on applying those standards. They are not mandatory, but an auditor who ignores relevant guidance should be able to say why. Tools and techniques are examples of procedures, and are purely informational.

Three provisions of the code of ethics produce most of the questions. Competence, meaning you undertake only activities you can reasonably expect to complete with professional competence. Due care and objectivity in performing your duties. And confidentiality of the information you obtain, with one important limit: confidentiality does not override a legal obligation to disclose.

The competence rule catches experienced candidates out, because in real engagements people learn on the job constantly. The exam does not accept that. If an engagement is beyond your competence, you decline it, or you obtain the competence, through training or by bringing in a specialist. Performing the work anyway and disclosing the limitation in the report does not repair it. The work was still done without the ability to do it.

So carry this away. When someone refuses you access, the instinct is to escalate or to concede. The better first move is to refer to the charter, because it tells you whether this is a genuine restriction on your scope or simply a misunderstanding about what you are already entitled to see.

Knowledge check
0 / 3
  1. 1.An IS auditor is refused access to a system's configuration files by the infrastructure manager, who says the files are commercially sensitive. What should the auditor do FIRST?

  2. 2.Which of the following is MOST important to include in an IS audit charter?

  3. 3.An IS auditor is assigned to review a blockchain implementation and has no knowledge of the technology. According to the code of professional ethics, what should the auditor do?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.