{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-08","description":"Internal auditors use information obtained during their work only for legitimate professional purposes and in conformance with applicable laws, regulations, and organizational policies. Information is protected against unauthorized access, use, or disclosure during and after engagements, and confidentiality obligations extend to parties assisting the internal audit function. Confidentiality acknowledgments and access controls over audit files evidence operation.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"Principle 5","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 5.1","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 5.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"Internal auditors use information obtained during their work only for legitimate professional purposes and in conformance with applicable laws, regulations, and organizational policies. Information is protected against unauthorized access, use, or disclosure during and after engagements, and confidentiality obligations extend to parties assisting the internal audit function. Confidentiality acknowledgments and access controls over audit files evidence operation.","title":"Protect confidential information obtained in audit work","unified_id":"UC-AUDIT-08"},"id":"uc:UC-AUDIT-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-08","sourceIds":["iia-2024"],"sourceUrl":null,"title":"UC-AUDIT-08 — Protect confidential information obtained in audit work","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a160a23de4b6f873a280e360cacc0166831b8d5674c9aea7ebd9eaccf04c636","properties":{"control_id":"Std 5.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","sourceId":"uc:UC-AUDIT-08","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-5-1-a104f997.json","targetId":"ctrl:iia-2024:Std 5.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6983c85183a5499c444fbce8e3015adfe094e62cd133bedadc7d015884aac139","properties":{},"sourceDetailPath":"/data/v1/records/wf-a11-0924c009.json","sourceId":"wf:A11","targetDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","targetId":"uc:UC-AUDIT-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a7ac221e10c02521395d6a4c61ab901fd04e7b8a4edf79ee92931f7fa95fd40c","properties":{"control_id":"Std 5.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","sourceId":"uc:UC-AUDIT-08","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-5-2-6abd28a9.json","targetId":"ctrl:iia-2024:Std 5.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:affd917cc89589663894574ff457aaa83cbc34be4d0f5457fbce820f92b04277","properties":{"rationale":"Confidentiality (IIA Principle 5) is a required element of the IIA-conformant internal-audit function this risk lacks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","sourceId":"uc:UC-AUDIT-08","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5881f9f381a01a824176917e2d79ad2e3e9dcc1cd5b7ec07792d61f5e969abf","properties":{"control_id":"Principle 5","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","sourceId":"uc:UC-AUDIT-08","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-5-1246bfda.json","targetId":"ctrl:iia-2024:Principle 5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be6224ae9595302c7d4dea558fd61bfd9ffe779a3baa00b49df5af85952c57de","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","sourceId":"uc:UC-AUDIT-08","targetDetailPath":"/data/v1/records/risk-ai-highrisk-migration-border-47d2b2d8.json","targetId":"risk:ai-highrisk-migration-border","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e88d34804a0795c1b7b58eb7c149ae4768b888d73b9b4bdde07e79217898cc1b","properties":{},"sourceDetailPath":"/data/v1/records/wf-a5-cb7fa618.json","sourceId":"wf:A5","targetDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","targetId":"uc:UC-AUDIT-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb2c344bbe90a4f75071298d557c50302fdd4ba3602f91b281a0ae0d5dfd8ca4","properties":{},"sourceDetailPath":"/data/v1/records/wf-a10-c454863e.json","sourceId":"wf:A10","targetDetailPath":"/data/v1/records/uc-uc-audit-08-b0e8d44c.json","targetId":"uc:UC-AUDIT-08","type":"operates"}],"schemaVersion":1}
