{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","description":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-03","propositionTitle":"Safeguards for Expanded ERM Responsibility","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 12–13, 15–20","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-02","propositionTitle":"Independence and Self-Review Safeguards","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 9–11, 20–22","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"Any ERM, compliance, risk-management, or other second-line responsibility assigned to the internal audit function or chief audit executive is classified as assurance, advisory, administrative, supervisory, or operational; justified and documented in the internal audit charter or a board-approved appendix; and approved by the board with the associated independence and objectivity risks. Internal audit does not select or own risk responses or other management decisions. Expanded responsibilities are time-bounded with a transition plan when intended to be temporary, and actual or perceived impairments are disclosed to the board. Internal auditors do not provide assurance over an activity they designed, operated, managed, or supervised during the preceding 12 months; another suitably qualified and independent party provides assurance for affected areas. Safeguards, alternative assurance, and transition status are reviewed periodically.","title":"Govern expanded internal audit ERM responsibilities","unified_id":"UC-AUDIT-27"},"id":"uc:UC-AUDIT-27","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-27","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dbb135014fc23b5e9e783cdceff73a0dbe3290e67bee867d9f1144353fe09c6","properties":{"rationale":"Board-approved service boundaries, impairment disclosure, and independent coverage preserve assurance credibility for the stakeholders who rely on internal audit.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13c15c39b720105320ae0c15edeef87c33dc872270c01113fc115be7c028447e","properties":{"control_id":"IIA-POS-ERM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 3, 7–9","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7935b88e335a1fb9072eb8a5457ddf3271eab7fd68665ced0fc14a5439796813","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:806bf2cd1daca69abb1a4ae1ab016c6f590f9c99251a3cd266bea7c58307de2f","properties":{"control_id":"IIA-POS-TLM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 9–11, 20–22","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-02-c2f0d9a7.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c522f6d83718a2d10d7fb32cfd1a6507f5a6bf9f81ac574ec79e964ff79599c3","properties":{"control_id":"IIA-POS-ERM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 12–13, 15–20","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-03-2ed09a44.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e440dc99ef84dba28eab3f5113cdab754bbd2af30d33effae6aaa6846849553e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a8-414556d8.json","sourceId":"wf:A8","targetDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","targetId":"uc:UC-AUDIT-27","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec08a2873e334dc6214319db8a39cc09b8f0ad002710d7722b3fcb850f80ebc6","properties":{"rationale":"Separating management decisions from internal audit and requiring independent coverage preserve assurance credibility when governance evaluates strategic execution.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-27-b7e48974.json","sourceId":"uc:UC-AUDIT-27","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"}],"schemaVersion":1}
