{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","description":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"Principle 2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 2.3","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"Internal auditors maintain individual objectivity - an unbiased professional attitude free from conflicts of interest - in all engagements. The chief audit executive implements safeguards such as conflict screening, assignment rotation, and recusal to protect objectivity, and auditors promptly disclose actual or perceived impairments so they can be managed and, where necessary, communicated to affected stakeholders. A complete prior-responsibility register is maintained and used for every engagement assignment. An auditor who held operational, design, management, or supervisory responsibility for an activity during the preceding 12 months is subject to a 12-month cooling-off period; if that requirement is not met, the engagement is reassigned or a suitably qualified independent party provides assurance. Portfolio-level reporting to senior management and the board identifies actual and perceived self-review threats and their safeguards. Conflict declarations, prior-responsibility screening, reassignment or independent-assurance results, and safeguard records are retained.","title":"Maintain auditor objectivity and disclose impairments","unified_id":"UC-AUDIT-05"},"id":"uc:UC-AUDIT-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-05","sourceIds":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1084b9bd598ffa0e6391985bad5a84175d6b6c7e5bfb7baa1e6f7bdb61b9aa96","properties":{},"sourceDetailPath":"/data/v1/records/wf-a11-0924c009.json","sourceId":"wf:A11","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67abbb98674a60d1e311149a41268506b940f4b8ce615e56e53b8d61ee29fb76","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68c54ab14ccc33912e6227b99398a504ebcf0e728f632bbb0a7cf0da84f88b69","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-hr-employment-practices-disputes-2a788e39.json","targetId":"risk:hr-employment-practices-disputes","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:71ea591a30bb2547450d55fa30b3545b6eee9d654e32b64a78e867a353061f38","properties":{"control_id":"Std 2.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-2-1-bd937208.json","targetId":"ctrl:iia-2024:Std 2.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7570c0c37de5d53d21740767fc8ea868bdbe27a8ca8b45beddf0b5ced8d127c2","properties":{"rationale":"Individual objectivity with conflict screening, rotation, and recusal is what makes the audit genuinely independent and its assurance reliable.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:769743561dc289ced57b9ded66609f78483c955be227f5149e999a43b6eb56dd","properties":{"control_id":"Std 2.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-2-3-44f8f5b2.json","targetId":"ctrl:iia-2024:Std 2.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:856ae582614767a74c07a1041173d99810fa33db053c90655845d698a9a11860","properties":{"control_id":"Std 2.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-2-2-521156a0.json","targetId":"ctrl:iia-2024:Std 2.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d8e9f9fedb91b03a998461590d29e0537db1686a82fa64c9d0f1ca4bc5e616d","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a1f433171b5aaf25af2d32fbfc47776014edc843e7c1f77d8dd25b39f4b867f4","properties":{"control_id":"IIA-POS-TLM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 9–11, 20–22","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3ba1662732119bdd03bfba1ff4eeab149d3d59112dfde8329ad4373221db519","properties":{"control_id":"Principle 2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-2-88ab9637.json","targetId":"ctrl:iia-2024:Principle 2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec8bea9ce78a6a49049aa07087e07adc5bc84be5cd0d5fc0b7dac5a4fdcceab6","properties":{"control_id":"IIA-POS-ERM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 12–13, 15–20","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","sourceId":"uc:UC-AUDIT-05","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf89edb5d6d8bf07bc34ac2386e3eb74f9d169ebbc065ffc19d5228403c6a92","properties":{},"sourceDetailPath":"/data/v1/records/wf-d10-392b8e6b.json","sourceId":"wf:D10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fee400d0d63f9fa16f1118bab34ec9c6ea10a200b514523920d84336df0655ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-a10-c454863e.json","sourceId":"wf:A10","targetDetailPath":"/data/v1/records/uc-uc-audit-05-3332a81f.json","targetId":"uc:UC-AUDIT-05","type":"operates"}],"schemaVersion":1}
