unified

UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities

Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Compliance, Audit & Assurance
type
preventive
category
administrative

Details

unified_id
UC-AUDIT-27
title
Govern expanded internal audit ERM responsibilities
statement
Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.
domain
Compliance, Audit & Assurance
control_type
preventive
control_category
administrative
members
    guidance
    • source
      iia-pos-2026-erm
      sourceTitle
      The Role of the Internal Audit Function in Enterprise Risk Management
      propositionId
      IIA-POS-ERM-01
      propositionTitle
      Board, Management, and Internal Audit Accountabilities
      sourcePages
      ERM pp. 3, 7–9
    • source
      iia-pos-2026-erm
      sourceTitle
      The Role of the Internal Audit Function in Enterprise Risk Management
      propositionId
      IIA-POS-ERM-03
      propositionTitle
      Safeguards for Expanded ERM Responsibility
      sourcePages
      ERM pp. 12–13, 15–20
    • source
      iia-pos-2026-three-lines
      sourceTitle
      Three Lines Model: Assurance and Advice in Support of Effective Governance
      propositionId
      IIA-POS-TLM-02
      propositionTitle
      Independence and Self-Review Safeguards
      sourcePages
      Three Lines pp. 9–11, 20–22

    Source

    No record-specific source URL is provided.

    Connections