{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-02","description":"The board establishes and approves the internal audit mandate - the function's authority, role, and responsibilities - and documents it in an internal audit charter that is reviewed and reapproved periodically. The charter grants unrestricted access to the records, personnel, and physical property relevant to engagements, and the board and senior management visibly champion and support the mandate. The approved charter and review records are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"Principle 6","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 6.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 6.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 6.3","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The board establishes and approves the internal audit mandate - the function's authority, role, and responsibilities - and documents it in an internal audit charter that is reviewed and reapproved periodically. The charter grants unrestricted access to the records, personnel, and physical property relevant to engagements, and the board and senior management visibly champion and support the mandate. The approved charter and review records are retained.","title":"Establish a board-approved internal audit mandate and charter","unified_id":"UC-AUDIT-02"},"id":"uc:UC-AUDIT-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-02","sourceIds":["iia-2024"],"sourceUrl":null,"title":"UC-AUDIT-02 — Establish a board-approved internal audit mandate and charter","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05da3c1a3dedd1e9a35c02e39967ebbc42b8d777389b8735f7e0dd30ce4a174d","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","targetId":"uc:UC-AUDIT-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:195c77e86c3a1a11349e89ef584cde371806f0613b27ef3e8e42545dc859c910","properties":{"rationale":"A board-approved mandate/charter granting unrestricted access to records and personnel establishes the authority for independent audit to operate.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ec52e3db07ecca842a5074bbaade05abd7731f511886da483f75e6f1bb3b491","properties":{"control_id":"Std 6.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-6-1-955a92e1.json","targetId":"ctrl:iia-2024:Std 6.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:45ba062bf9ad1f3c5aa1ddb880443104a414c5794361f9832e9585af0b2bbeb2","properties":{"control_id":"Principle 6","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-6-dc3030fa.json","targetId":"ctrl:iia-2024:Principle 6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d267c88d57a775742e932ac4bebd9bd96a44865bbbe30bf8f6d36c5bb4acc15","properties":{"rationale":"Board and senior-management support with unrestricted access give internal audit the independence to detect and deter management override.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/risk-fin-financial-statement-fraud-1dd35d5a.json","targetId":"risk:fin-financial-statement-fraud","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:829f0394bc4acc320556da8ab04a112151a3b715b83221df8bab75c51fcb9b60","properties":{"control_id":"Std 6.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-6-3-9061debc.json","targetId":"ctrl:iia-2024:Std 6.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:937712095376dc945a8e6eeea8d315d6390e91bd401e90f310499d4669ed0422","properties":{"control_id":"Std 6.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-6-2-5f08a028.json","targetId":"ctrl:iia-2024:Std 6.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc59bceb7c7330ae1a004bbf1793a8387893a56fe59e36e673b7cc183cc80492","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","targetId":"uc:UC-AUDIT-02","type":"operates"}],"schemaVersion":1}
