{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-01","description":"The organization maintains an internal audit function that provides the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight to protect and sustain organizational value. The function is positioned independently of management activities it audits: the chief audit executive reports functionally to the board, holds the qualifications and competencies the role requires, and has unrestricted access to the board. Independence is affirmed to the board at least annually.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"Purpose","coverage":"partial","delta":"the Purpose principle spans the full internal-audit value proposition - assurance, advice, insight, and foresight - beyond the independence-and-positioning objective of this control","framework":"iia-2024","relationship":"intersects_with"},{"control_id":"Principle 7","coverage":"partial","delta":"Principle 7 also encompasses board-approved mandate authorities satisfied by companion board-oversight controls (Std 6.x home), beyond organizational independence and CAE qualifications","framework":"iia-2024","relationship":"intersects_with"},{"control_id":"Std 7.1","coverage":"partial","delta":"board governance authorities - approving the audit mandate/charter, CAE appointment/removal and remuneration, and the audit budget/resources - satisfied by companion board-oversight controls (Std 6.x home)","framework":"iia-2024","relationship":"intersects_with"},{"control_id":"Std 7.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The organization maintains an internal audit function that provides the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight to protect and sustain organizational value. The function is positioned independently of management activities it audits: the chief audit executive reports functionally to the board, holds the qualifications and competencies the role requires, and has unrestricted access to the board. Independence is affirmed to the board at least annually.","title":"Maintain an independent internal audit function","unified_id":"UC-AUDIT-01"},"id":"uc:UC-AUDIT-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-01","sourceIds":["iia-2024"],"sourceUrl":null,"title":"UC-AUDIT-01 — Maintain an independent internal audit function","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b26709c3ba466809d188e2ad740a24aa7c0739369ecd0524b9f3b00397466dd","properties":{"control_id":"Purpose","coverage":"partial","delta":"the Purpose principle spans the full internal-audit value proposition - assurance, advice, insight, and foresight - beyond the independence-and-positioning objective of this control","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/ctrl-iia-2024-purpose-a4eefd7e.json","targetId":"ctrl:iia-2024:Purpose","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3cd9e93b1db7d573021cfcecaf56b4b709c9f491b66dc9fdb173ff48dafe6028","properties":{"control_id":"Std 7.1","coverage":"partial","delta":"board governance authorities - approving the audit mandate/charter, CAE appointment/removal and remuneration, and the audit budget/resources - satisfied by companion board-oversight controls (Std 6.x home)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-7-1-fc3a5a1e.json","targetId":"ctrl:iia-2024:Std 7.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:679df51ba19baa1ab408a42c81b70fee5d365a672037b38e8826035adc254a84","properties":{"rationale":"An independent internal audit function reporting functionally to the board is exactly the independent-assurance capability whose absence defines this risk.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6dd01ff618821943d0fb201edd89c61ad400dc48462c99a5a3968243c5a71384","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","targetId":"uc:UC-AUDIT-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81bb3624240c195066d4e34d6573c9cd30a6977213379935f683d10ad3900cc4","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","targetId":"uc:UC-AUDIT-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:964afe1d1b1bc2392fff55e8277931f6b797ec0e663a915cffcd58d9291f2fd2","properties":{"rationale":"CAE functional reporting and unrestricted board access give the board independent assurance, supporting effective oversight of risk and control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c9b315ff6be89224a340d99dc5a850d4497eaecbcdf6eed0d606d07c7c0625e1","properties":{"control_id":"Std 7.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-7-2-2579d0aa.json","targetId":"ctrl:iia-2024:Std 7.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f04d2fc0fbc2c6bf27d14eb2f85aad70ededdde4a5940a2bf6b3447e3890ec0f","properties":{"control_id":"Principle 7","coverage":"partial","delta":"Principle 7 also encompasses board-approved mandate authorities satisfied by companion board-oversight controls (Std 6.x home), beyond organizational independence and CAE qualifications","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-7-36188fe8.json","targetId":"ctrl:iia-2024:Principle 7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f451f67badbd29a9756c83a7e527070da7cf80190957c1d6738366233fddd186","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-01-10668058.json","sourceId":"uc:UC-AUDIT-01","targetDetailPath":"/data/v1/records/risk-ops-advisory-duty-of-care-78f8b64d.json","targetId":"risk:ops-advisory-duty-of-care","type":"mitigates"}],"schemaVersion":1}
