Independence and Objectivity
Why the most helpful thing an auditor can do is often the one thing they must refuse, and how the exam ranks independence against every practical consideration.
What this makes you able to do
Evaluate threats to the independence and objectivity of the IS audit function and determine an appropriate safeguard.
By the end you can
- Distinguish organisational independence from individual objectivity.
- Recognise the self-review, advocacy and familiarity threats in an engagement scenario.
- Select a safeguard proportionate to the threat rather than defaulting to disclosure.
Transcript
Independence and objectivity. This lesson is about why the most helpful thing an auditor could do is often the one thing they must refuse, and how the exam ranks independence against every practical consideration.
Here is the situation. The chief information officer asks you to sit on the design workshops for the new access recertification process. You know more about access recertification than anyone else in that room. You would genuinely improve the outcome. And the access management audit is scheduled for the same year.
Saying yes is the most useful thing you could do, and it is the answer the exam marks wrong. Not because helping is bad, but because of what it costs you later.
The exam distinguishes carefully between two things, and questions often turn on which one is at stake. Independence is organisational and structural. It concerns the audit function position: who it reports to, who sets its budget and scope, and whether the management it audits can influence its findings. Objectivity is individual and mental. It concerns whether a particular auditor can form an unbiased judgement on a particular engagement.
Which means both can fail separately. An audit function can be perfectly independent while an individual auditor on it is not objective for a given job. And the fix for that is reassignment, not restructuring. Reading which one a question is about tells you which remedy it is looking for.
Now the threats worth recognising. Self-review, where you would be auditing your own work, whether that work was designing a control, implementing a system, or operating the process in a previous role.
Advocacy, where you have promoted a position, a product or a party, which compromises objectivity afterwards. And familiarity, where long association with the auditee produces sympathy and reduced professional scepticism. Rotation is the standard safeguard for that one.
Then self-interest, where you hold a financial or personal stake in the outcome. And intimidation, meaning pressure, actual or perceived, from management with the standing to affect you. Five threats, and the exam expects you to name which one a scenario describes.
Self-review is the one Domain 1 tests hardest, and there is a trap inside it. Candidates assume that expertise cures the conflict, that being the best qualified person to design the control makes it safer for them to do it. It is the opposite. Being the best qualified person is exactly what creates the self-review threat when you later audit it.
The exam also expects safeguards to be proportionate, and it ranks them. Strongest first: do not take the work at all, or remove the conflicted individual from that part of it.
Then reassign to an auditor without the involvement. Then independent review of the conflicted auditor work by someone unconflicted. And last, disclosure to those charged with governance.
That ranking catches people out, because in professional life disclosure is often what actually happens. On the exam, disclosure is the last resort. It tells the reader that the work may be compromised without preventing the compromise. If one option offers reassignment and another offers disclosure, reassignment wins every time.
Finally, independence does not mean silence. You can state the control requirements a solution should satisfy. You can comment on risks in a proposed design. You can say whether a control as described would address a known risk. What you cannot do is select, design, implement, operate or approve the control, or accept the risk. That line, between advising on requirements and making the management decision, is where most scenario questions are set.
So carry this away. In a smaller organisation you may genuinely be the only person who knows how to design the control. The exam does not model that world. If an option has the auditor performing a management function, it is wrong, however sensible it would be on a Monday morning.
1.An IS auditor previously worked for two years as the system administrator of the ERP platform now in scope for audit. What is the MOST appropriate action?
2.Which of the following BEST ensures the organisational independence of the internal IS audit function?
3.During an audit, management asks the IS auditor to recommend a specific vendor for a new identity management system. What is the auditor's GREATEST concern in agreeing?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
