CIA-1 - Governance, Risk Management, and Control - Section C.3

Recognize ethical and compliance-related issues, including the ethical, legal, and compliance requirements applicable to an organization and the internal auditor's role in the organization's ethical framework.

Identify the ethical, legal, and regulatory compliance requirements that apply to an organisation and recognise where breaches create risk. Describe the internal auditor's role within the organisation's ethical framework, including assessing whether governance supports ethical conduct and whether mechanisms exist to raise and address ethical concerns.

Compliance requirementsEthical frameworkCode of conduct

Practice question for this objective

Free sampleGovernance, Risk Management, and Controlmedium

During a governance engagement at Harwell Foods, the internal auditor confirms that the organisation has a written code of conduct, but finds no confidential channel through which staff can report suspected ethical breaches and no evidence that anyone monitors adherence to the code. What should the auditor do?

  • ADesign and launch a confidential reporting channel for staff, because internal audit is trusted and well placed to run such a mechanism.
  • BReport that the ethical framework lacks a means to raise and monitor concerns, a gap that weakens governance over ethical conduct in the organisation. Correct
  • CConclude that the ethical framework is sound because a written code of conduct is in place, and close the engagement without further work.
  • DRefer the code to human resources for wording improvements and defer any conclusion on the ethical framework to a later engagement.
Internal audit assesses whether mechanisms exist to raise and monitor ethics concerns and reports gaps, rather than building the mechanism itself. A code of conduct with no reporting channel and no monitoring cannot show that ethical conduct is supported in practice. Internal audit's role in the ethical framework is to assess these mechanisms and report weaknesses, so identifying the gap is correct while owning or excusing it is not.

Why A is wrong: Building and operating the channel looks helpful, but owning a mechanism that internal audit should later assess takes on a management responsibility and impairs its independence.

Why B is correct: Internal audit's role is to assess whether governance supports ethical conduct and whether mechanisms exist to raise and address concerns, so reporting this evidenced gap is the appropriate action.

Why C is wrong: The existence of a code is tempting evidence of a framework, but a document alone does not show that concerns can be raised or that adherence is monitored, so the conclusion is unsupported.

Why D is wrong: Polishing the wording sounds constructive, but it addresses the wrong issue and postpones reporting a real governance gap the current engagement has already evidenced.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Governance, Risk Management, and Control objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.