{"description":"Runs on an Audit item created per cycle as the anchor — audit_type=internal, scope set to the IA professional-practice program for the period, period_start/period_end = the cycle window (a program cycle, not an engagement, so this is a documented reuse of the Audit type; it is the \"cycle item\" every stream links its evidence to and closes at the end). A decision-aware annual cycle that attests the ethics and professional-courage expectations and documents deviations, screens per-engagement conflicts and manages objectivity impairments, collects confidentiality acknowledgments and restricts audit-file access, and assesses competency against role requirements with approved, tracked continuing-professional-development plans for each auditor. It consumes no upstream workflow: prior-cycle carryover (unresolved-deviation and monitored-impairment Issue items still open against the prior cycle's Audit item, plus in-progress development plans) is its own input, and the population is confirmed against the HR roster, engagement staffing, and the audit-file access list before measurement begins. Named deliverables: the professional-practice requirements memo, the ethics attestation register, the conflict-of-interest declarations and impairment register, the confidentiality acknowledgment register and before/after audit-file access review, the competency assessments with coverage matrix and CPD plans, and the signed CAE conformance report to the audit committee — assembled into an indexed cycle evidence file on the anchor Audit item. Downstream is self-feeding: the carry-forward list produced at close hands off to the next run of this same workflow; there is no distinct downstream workflow. In scope: every auditor and assisting party (employees plus co-source, outsourced, and guest auditors) who performed internal audit work or holds audit-file access during the period, across all four expectation streams (ethics, objectivity, confidentiality, competency); out of scope: the audit engagements' own subject-matter conclusions and any HR, legal, or ethics-office investigation a disclosed concern is referred into.","edges":[{"id":"e-refresh-professional-practice-requirements-assess-ethics-deviations","source":"refresh-professional-practice-requirements","target":"assess-ethics-deviations"},{"id":"e-assess-ethics-deviations-remediate-ethics-deviations","label":"Deviations require action","source":"assess-ethics-deviations","target":"remediate-ethics-deviations","whenValue":"deviations_require_action"},{"id":"e-assess-ethics-deviations-compile-program-evidence-and-report","label":"No deviations","source":"assess-ethics-deviations","target":"compile-program-evidence-and-report","whenValue":"no_deviations"},{"id":"e-remediate-ethics-deviations-compile-program-evidence-and-report","source":"remediate-ethics-deviations","target":"compile-program-evidence-and-report"},{"id":"e-refresh-professional-practice-requirements-screen-conflicts-and-objectivity","source":"refresh-professional-practice-requirements","target":"screen-conflicts-and-objectivity"},{"id":"e-screen-conflicts-and-objectivity-apply-objectivity-safeguards","label":"Impairment management required","source":"screen-conflicts-and-objectivity","target":"apply-objectivity-safeguards","whenValue":"impairment_management_required"},{"id":"e-screen-conflicts-and-objectivity-compile-program-evidence-and-report","label":"Objectivity confirmed","source":"screen-conflicts-and-objectivity","target":"compile-program-evidence-and-report","whenValue":"objectivity_confirmed"},{"id":"e-apply-objectivity-safeguards-compile-program-evidence-and-report","source":"apply-objectivity-safeguards","target":"compile-program-evidence-and-report"},{"id":"e-refresh-professional-practice-requirements-compile-program-evidence-and-report","source":"refresh-professional-practice-requirements","target":"compile-program-evidence-and-report"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-AUDIT-04","UC-AUDIT-05","UC-AUDIT-06","UC-AUDIT-08"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","contentDigest":"sha256:12fca28d6d3a7fe7190b7ac924cfb3b588fd0ceaa1afc3769dc1f7303c2c1f8f","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:12fca28d6d3a7fe7190b7ac924cfb3b588fd0ceaa1afc3769dc1f7303c2c1f8f","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-internal-audit-ethics-objectivity-competency-program"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"audit-internal-audit-ethics-objectivity-competency-program","source":"coworkcanvas-gallery","standards":["iia-2024"],"teams":["internal-audit"]},"name":"Internal Audit Ethics, Objectivity & Competency Program","nodes":[{"data":{"description":"Authorize the versioned expectations before requests are issued, resolve applicability conflicts and account for the full attestation population before assessment.","formData":{"fields":[{"key":"integrity_and_courage_affirmation","label":"I have acted honestly and with professional courage, communicating results truthfully even when unwelcome (Standard 1.1)","required":false,"type":"checkbox"},{"key":"ethical_conduct_affirmation","label":"I have met the organization's ethical expectations and encouraged ethical conduct in others (Standard 1.2)","required":false,"type":"checkbox"},{"key":"legal_compliance_affirmation","label":"I have complied with applicable laws and regulations and engaged in no illegal or improper acts (Standard 1.3)","required":false,"type":"checkbox"},{"key":"pressure_disclosure","label":"Pressure to change or suppress a finding, rating, or conclusion","options":[{"label":"Nothing to disclose","value":"nothing_to_disclose"},{"label":"I have something to disclose — described below","value":"disclosure"}],"required":false,"type":"select"},{"key":"others_departures_disclosure","label":"Awareness of others' departures from these expectations","options":[{"label":"Nothing to disclose","value":"nothing_to_disclose"},{"label":"I have something to disclose — described below","value":"disclosure"}],"required":false,"type":"select"},{"key":"gifts_or_hospitality","label":"Gifts or hospitality received from an auditee above the policy threshold","options":[{"label":"Nothing to disclose","value":"nothing_to_disclose"},{"label":"Received — described below","value":"disclosure"}],"required":false,"type":"select"},{"key":"disclosure_detail","label":"Details of anything disclosed above, or anything else you judge relevant (visible only to the CAE and the stream owner)","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Authorize the versioned expectations before requests are issued, resolve applicability conflicts and account for the full attestation population before assessment.\n\n**Inputs**\nThe anchor Audit item for this cycle (audit_type=internal, scope = the professional-practice program, period_start/period_end = the cycle window) — created here as the cycle item every stream links its evidence to; the governing texts below are attached to it at the exact versions used.\n- The Global Internal Audit Standards, Domain II (Principles 1–5), plus any IIA Topical Requirements newly in force for the function — external authoritative texts, linked as documents to the anchor Audit item.\n- The organization's code of conduct and the internal-audit code of ethics and charter — represented as Policy items (Policy: policy_type=policy for the codes of conduct and ethics, policy_type=charter for the internal-audit charter; policy_owner; framework=iia-2024; domains include compliance_audit_assurance; review_frequency and next_review_date from the review cycle), each with its version-pinned governing document attached.\n- The objectivity and conflict-of-interest policy with its safeguard catalog — per-engagement screening, assignment rotation, recusal, cooling-off, disclosure — as a Policy item (Policy: policy_type=policy, policy_owner, framework=iia-2024, domains include compliance_audit_assurance) with the policy document attached; the program's standing safeguard expectations themselves live as the existing IIA Control items (framework=iia-2024, control_category=administrative — e.g. controls UC-AUDIT-04/05/06/08).\n- The confidentiality, data-handling, and records-retention policies and standards that govern audit files — Policy items (Policy: policy_type=policy or standard, policy_owner, framework=iia-2024, domains include data_protection_privacy, review_frequency) with the governed documents attached.\n- The role competency framework (the IIA Competency Framework or the function's own) with required proficiency per grade — a document linked here and re-consumed by the competency step.\n- Last cycle's requirements memo, for the diff — the document produced by the prior run's requirements step.\n\nThe confirmed population (reconciled across the HR roster, engagement staffing, and the audit-file access list), with contact details and assisting-party status.\n- The approved expectation set (Standards 1.1–1.3 anchors) from the requirements memo produced by the requirements-refresh checkpoint.\n- The attestation window dates and the escalation contacts.\n- Open disclosures from the prior cycle, so respondents are not re-asked about matters already in remediation.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive; nonexecuting auditors and assisting parties provide their own attestations owns the stated judgments and authorizations.*\n\n*Refresh professional-practice requirements.* Rebuild the authoritative set of ethics, objectivity, confidentiality, and competency expectations this cycle measures against — current to the standards and policies actually in force — with every change since last cycle flagged, dated, and owned.\n\n1. Anchor every expectation to its authority: honesty and professional courage (Standard 1.1 — truthful communication even when unwelcome), the organization's ethical expectations (1.2), legal and ethical behavior (1.3), individual objectivity (2.1), safeguarding objectivity (2.2), disclosing impairments (2.3), competency (3.1), continuing professional development (3.2), use of information (5.1), and protection of information (5.2). For each, state the evidence this cycle will collect — an expectation with no evidence plan is a gap in the program, not a footnote.\n2. Reconcile organization policy against the Standards: where policy is stricter (a two-year cooling-off instead of one, a lower gift threshold), the stricter rule governs; where policy is silent, the Standard is the floor. Log conflicts for explicit resolution — never silently average them.\n3. Verify the safeguard catalog is complete: the conflict-of-interest policy must actually provide for per-engagement screening, rotation, recusal, and disclosure. If a safeguard the objectivity stream depends on has no policy backing, flag it now so the fix precedes the screening, not the finding.\n4. Map applicability: which expectations bind employees only, which extend to co-source partners and external service providers (confidentiality and objectivity always do), and which engagements carry extra requirements (regulated entities, privacy regimes).\n5. Diff against the prior cycle: new or amended standards and Topical Requirements with effective dates, policy version changes, changed role competency requirements, and expectations whose applicability moved because roles, engagements, or the assisting-party mix changed. Assign an owner to every change.\n6. Human checkpoint: the CAE resolves ambiguities and approves the set as the measurement basis for the attestations and assessments that follow.\n\n*Run ethics and professional-courage attestation.* Obtain a dated, attributable acknowledgment of the integrity, ethical-conduct, and professional-courage expectations from every person in the confirmed population, through a disclosure channel built to surface concerns rather than suppress them.\n\n7. Build the attestation as affirmative first-person statements, not a \"read and understood\" checkbox: I have acted honestly and with professional courage, communicating results truthfully even when unwelcome (1.1); I have met the organization's ethical expectations and encouraged ethical conduct (1.2); I have complied with applicable laws and regulations and engaged in no illegal or improper acts (1.3).\n8. Add structured disclosure fields: pressure experienced to change or suppress a finding, rating, or conclusion; awareness of others' departures from the expectations; gifts or hospitality from auditees beyond the policy threshold; anything else the respondent judges relevant. Each field requires an explicit \"nothing to disclose\" selection — a blank is an incomplete response, never an implied no.\n9. State the handling rules on the form itself: disclosures are visible only to the CAE and the stream owner, and disclosing is expected professional behavior. A channel people fear produces clean forms and dirty facts.\n10. After CAE approval of the criteria, issue one identified form assignment to each population member who executes none of this workflow’s checkpoints. Include the criteria, respondent identity and role from the reconciled roster in the assignment context. Executors record their own signed statements in restricted native results or documents; have an independent reviewer or the audit committee review the CAE’s own declarations. Account for both channels in one population register with the due date (10–15 business days is typical), the expectation references, and the escalation contact; issue onboarding versions to joiners after launch.\n11. Chase to completion: reminder mid-window and again two days before the deadline; manager escalation past due; the CAE gets the final holdout list by name. Track coverage against the population, not against forms sent.\n12. Consolidate into a response register — person, role, response date, disclosures made — and verify each response is attributable (named, dated, unaltered). Move disclosed concerns into a restricted concern log with limited visibility.\n13. Human checkpoint: the CAE escalates final non-responders through their leadership and confirms the register covers 100% of the population before the deviation assessment runs.\n\n**Record in AssureSwarm**\nRequirements memo — the approved DOCX/PDF memo (expectations, applicability map, evidence plan) plus the XLSX change log attached as documents to this step; this is the named deliverable of the step.\n- Per-expectation requirement records — create-or-enrich a Control item per professional-practice expectation area (Control: framework=iia-2024, family=professional_practice, control_category=administrative, frequency=annual, control_owner), carrying the source reference in its description; do not duplicate an expectation already carried by an existing IIA Control.\n- Governing policies — create-or-enrich a Policy item for each governing text the cycle measures against (Policy: policy_type=policy for the code of conduct, code of ethics, objectivity/COI, confidentiality, data-handling and records-retention policies; policy_type=standard where the text is a standard; policy_type=charter for the internal-audit charter; policy_owner; framework=iia-2024; domains include compliance_audit_assurance; review_frequency and next_review_date from the review cycle; effective_date and version at the version used), and attach the version-pinned document to each; link each Policy to the anchor Audit item so the cycle carries its exact governing basis. The external Standards and Topical-Requirements texts stay as documents linked to the anchor item.\n- Change log — record the prior-versus-current diff and the change list with owners and effective dates as the XLSX attached above (query data drives the diff; there is no native change-log field).\n\nAttestation — the form on this step, assigned only to people outside the complete executor roster, captures the three first-person affirmations against Standards 1.1–1.3, an explicit answer on each disclosure field (pressure to change or suppress a result, others' departures, gifts or hospitality above threshold), and the disclosure detail. Track return status against the population; the population extracts (HR roster, engagement staffing, audit-file access list) are uploaded to this step as the reconciliation basis, and the CAE's escalation of holdouts goes in the step result.\n- Ethics attestation register — the consolidated per-person responses and disclosures as an XLSX document attached to this step, and the restricted concern log as a separate access-limited document; there is no per-person item type, so the register on the step is the durable home.\n- Coverage numbers — record population, responses, non-responders escalated, and disclosures received within the register document.\n\n**Exit criteria**\nRequirements memo approved; every expectation carries a source, an applicability map, and an evidence plan; every change since last cycle has an owner and an effective date; policy-versus-standard conflicts logged with a resolution path.\n\nEvery person in the population has an attributable, dated response or a named escalation in flight; every disclosure field explicitly answered; the concern log restricted and complete; coverage numbers recorded.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` sends the attestation assignments, reminders, and non-responder escalations with a logged chase trail.\n\n**Form recipient** — Auditors and assisting parties who execute none of this workflow’s checkpoints. Check the complete preparation, execution, review and approval roster first: anyone assigned a role anywhere in this workflow contributes through native results, documents and approvals instead. Read current evidence and declarations before requesting anything. Select only unresolved questions for the identified scope and period; known facts remain linked context, and no request is needed if nothing is missing. The catalog fields are optional so known or unasked facts need not be repeated; every question actually required by the assignment must have an attributable response or a recorded unresolved gap before the dependent judgment. A negative or declined affirmation remains visible; it must never be converted to a positive statement. Compare the complete executor roster with the population. Forms go only to people outside that roster. Executors record their own signed statements in restricted native results/documents; an independent reviewer handles the CAE’s own statement.","label":"Refresh professional-practice requirements","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload","coach-form-create","coach-workflow-scan","coach-notify"]}},"id":"refresh-professional-practice-requirements"},{"data":{"decisionField":"ethics_attestation_status","description":"Agent reconciles the attestations and disclosed concerns into a deviation register; human decides whether the ethics posture is clean or deviations require action","formData":{"fields":[{"key":"ethics_attestation_status","label":"Decision","options":[{"label":"No deviations","value":"no_deviations"},{"label":"Deviations require action","value":"deviations_require_action"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide whether the function's ethics posture for the period is clean or whether attestation gaps and disclosed concerns require documented action. The chief audit executive owns the call; it determines whether the remediation step runs at all.\n\n**Decision criteria**\n\nThe branch rests on evidence reconciled in this step: the response register tied to the confirmed population so every person is accounted for, and every open item classified — an unreturned attestation, a disclosed conflict-adjacent concern (logged here, routed to the objectivity stream), an admitted departure from the ethical expectations, or a professional-courage failure such as pressure on a finding that was neither resisted nor reported. Severity-rank each item: severe (dishonesty, an altered or suppressed result, a legal or regulatory breach), moderate (a policy departure, an unreported gift over threshold), administrative (a late or missing form with no underlying concern). Then test for clustering — several similar disclosures in one team or on one engagement indicate a systemic condition, not coincidence.\n\n- **No deviations (`no_deviations`)** — 100% of the confirmed population has an attributable, dated acknowledgment; every disclosure field is an explicit \"nothing to disclose,\" or the disclosed item is assessed as requiring no action with the reasoning written down (e.g., a de minimis gift already handled under the gifts policy); no professional-courage concerns; no prior-cycle ethics item still open. Ambiguity fails this branch — \"probably fine\" is `deviations_require_action` with a fast disposition, not `no_deviations`.\n- **Deviations require action (`deviations_require_action`)** — any missing or unattributable attestation at the deadline; any disclosed pressure on findings or ratings (treat as severe — this is the professional-courage core of Standard 1.1 and may warrant board awareness); any admitted departure; any concern requiring investigation or referral to HR, legal, or the ethics office; any systemic cluster. One administrative gap is enough — the question is whether action is required, not whether the news is bad.\n\n**Record in AssureSwarm**\n- Submit the decision form: `ethics_attestation_status` (the branch), the step result citing the coverage numbers and the deviation count by severity with register references, and the step's approver record (the CAE).\n- Upload the deviation register and the assessment summary to this step (document upload).\n\n**Exit criteria** — Form submitted; the rationale traces to the register (counts, severities, cluster analysis); the unselected branch is prunable.","kind":"decision","label":"Assess ethics deviations","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"assess-ethics-deviations"},{"data":{"description":"Agent opens and tracks a remediation item for each ethics deviation and records its resolution; human approves the dispositions and confirms each is documented","instructions":"**Objective** — Convert every ethics deviation into a tracked remediation item with an owner, a severity-scaled due date, and documented resolution, so the cycle closes with zero unresolved ethics items and a record that proves it.\n\n**Inputs**\n- The deviation register from the assessment, with classification and severity per item.\n- The restricted concern log and the underlying attestation responses.\n- The organization's routing rules: what goes to HR, the ethics office, or legal, and what internal audit handles itself.\n\n**Procedure**\n1. Open one remediation item per deviation carrying the person, the expectation touched, the accountable owner, and a due date scaled to severity: severe — immediate containment plus resolution within 30 days; moderate — 60 days; administrative — within the current reminder cycle.\n2. Missing attestations: obtain within five business days or escalate to the CAE for a conduct conversation. A refusal to attest is itself a reportable posture, not an administrative gap.\n3. Concerns needing investigation: route them out. Internal audit does not investigate serious matters involving its own staff alone — refer per the routing rules, keep the referral reference, and track the outcome without duplicating the investigation.\n4. Professional-courage failures (a result softened, suppressed, or unreported under pressure): the CAE re-reviews the affected engagement's conclusions, decides whether the report must be corrected or supplemented, and considers disclosure to those who relied on it — the same logic Standard 2.3 applies when an impairment surfaces after an engagement closes.\n5. For clusters, fix the cause, not just the instances: distinguish a training gap from cultural pressure from policy ambiguity, and open a corrective action with its own owner — reinforced expectations, targeted training, or a methodology or reporting-line change.\n6. Verify closure integrity: every deviation maps to exactly one remediation item; every closed item has resolution evidence (what was done, who approved it, when). Anything unowned or undated goes to the CAE — an unowned deviation blocks cycle closure.\n7. Human checkpoint: the CAE approves each disposition, confirms sensitive matters were routed to the right function, and confirms every deviation is addressed and documented before the cycle conclusion is issued.\n\n**Record in AssureSwarm**\n- Remediation items — create one Issue per deviation (Issue: issue_type=exception, source=self_assessment, severity matching the register classification, issue_owner = the accountable owner, identified_date, target_remediation_date scaled to severity, actual_remediation_date and verified_date on closure); record the register reference, expectation touched, and disposition in its description/remediation_plan.\n- Relationships — relate each remediation Issue to the anchor Audit item (the cycle item) so it carries forward as an existing open item; there is no Person item type, so the person involved is named in the Issue rather than linked.\n- Evidence — upload resolution evidence and referral confirmations as documents on each remediation Issue.\n\n**Exit criteria** — Every register row maps to a remediation item; severe items contained; referrals evidenced with references; closures carry dated resolution evidence and CAE approval; anything still open has an owner and a due date that will carry forward.","label":"Remediate and document ethics deviations","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"remediate-ethics-deviations"},{"data":{"decisionField":"objectivity_status","description":"Agent collects conflict-of-interest declarations, runs per-engagement conflict screening across the in-scope engagements, and drafts the impairment register; human decides whether objectivity holds or impairments must be managed","formData":{"fields":[{"key":"objectivity_status","label":"Decision","options":[{"label":"Objectivity confirmed","value":"objectivity_confirmed"},{"label":"Impairment management required","value":"impairment_management_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Determine whether every auditor and assisting party is objective — in fact and in appearance — across their current and planned assignments, or whether impairments exist that must be managed before engagement work proceeds. The chief audit executive owns the call under Standards 2.1–2.3.\n\n**Decision criteria**\n\nThe branch rests on evidence produced in this step: a signed conflict-of-interest declaration from every person in the population — financial interests, family and close personal relationships, prior operational roles, outside activities and directorships, and pending job discussions — then a per-engagement screen matching each declaration and each person's employment history against the full engagement roster. Screen for the recognized threat types: self-review (auditing a process, system, or control the person designed, operated, or had responsibility for), familiarity (a close relationship with the area's management, or the same auditor covering the same area beyond roughly three consecutive years), self-interest (a financial stake in the outcome, or interviewing for a role in the auditee — the impairment people least often volunteer), former-role conflicts (operational responsibility for the area within the past year — the cooling-off the Standards carry forward), and undue influence (management pressure on scope, rating, or staffing). The test throughout is the informed third party's perception, not the auditor's confidence in their own neutrality.\n\n- **Objectivity confirmed (`objectivity_confirmed`)** — every person has a current signed declaration; the screen ran against the complete engagement roster; and the impairment register has zero rows: no cooling-off breaches, no self-review or familiarity threats on any assignment, no undisclosed financial interests, rotation thresholds respected, and nothing an informed outsider would read as compromised. A missing or stale declaration fails this branch by itself — an unscreened person is an unconfirmed one.\n- **Impairment management required (`impairment_management_required`)** — the register contains at least one actual or perceived impairment on a current or planned assignment, or any declaration is missing or materially incomplete. Perceived counts the same as actual: an appearance problem on a live engagement is a live impairment. Name every impaired person-engagement pair with its threat type in the rationale — the safeguards step executes from that register, row by row.\n\n**Record in AssureSwarm**\n- Submit the decision form: `objectivity_status` (the branch), the step result citing declaration coverage, screen scope, and the impairment count by threat type, and the step's approver record (the CAE).\n- Use current signed declarations already held. Request only missing financial interests, close relationships, former roles, outside activities/directorships or pending job discussions from auditors and assisting parties outside the complete executor roster, with identity and engagement context supplied in the request. Keep such collection assignments separate from the routing SELECT. Executors record their own signed declaration in restricted native results/documents; an independent reviewer or the audit committee reviews the CAE’s own conflicts. Record the screening queries and match logic, and upload declarations, screening results and the impairment register.\n\n**Exit criteria** — Form submitted; declaration coverage is 100% or the gap itself drove the impairment branch; every register row carries person, engagement, threat type, and actual-versus-perceived; the unselected branch is prunable.","kind":"decision","label":"Screen conflicts and confirm objectivity","performedBy":{"primitives":["coach-form-create","coach-query-data","coach-document-upload"]}},"id":"screen-conflicts-and-objectivity"},{"data":{"description":"Agent implements and records the safeguard for each impairment - reassignment, rotation, recusal, supervisory review, or disclosure - and confirms residual objectivity; human approves the safeguards and any required stakeholder communication","instructions":"**Objective** — Apply, evidence, and approve a safeguard for every impairment in the register so no engagement proceeds under an unmanaged actual or perceived impairment, and required disclosures reach the parties entitled to them under Standard 2.3.\n\n**Inputs**\n- The impairment register from the screening decision: person, engagement, threat type, actual versus perceived.\n- The safeguard catalog from the objectivity policy: reassignment, rotation, recusal, independent supervisory review, disclosure.\n- The engagement roster and schedule, so replacements can be screened and sequenced.\n\n**Procedure**\n1. Apply the safeguard hierarchy: eliminate first — reassign the engagement or recuse the person; that is the default response. Mitigate second — rotation, or independent supervisory review with its depth stated (which sections are re-reviewed, by whom, to what standard). Disclose last, only where the impairment cannot be eliminated and the work must still proceed.\n2. Match safeguard strength to threat type: a cooling-off breach (operational responsibility within the past year) takes mandatory reassignment — supervisory review cannot cure an appearance problem. Self-review takes reassignment or independent re-performance of the affected sections. Familiarity takes rotation plus a fresh reviewer. A financial interest resolves by divestment or reassignment, whichever is faster. Undue influence from management escalates to the CAE and, where the pressure touches audit scope or ratings, to the board — that is a function-level independence matter, not a staffing fix.\n3. Restaff cleanly: rescreen every replacement against the same engagement before confirming — a safeguard that installs a new conflict is a defect, not a fix. Update the engagement staffing record and note the schedule impact.\n4. Draft each required disclosure: the impairment's nature, the safeguard applied, and the residual effect on the reliability of results. Route to the audit committee for impairments touching completed work or the CAE personally; to engagement stakeholders otherwise. Where an impairment is discovered on an already-issued engagement, Standard 2.3 requires disclosure to those who relied on the results — determine that population deliberately, not conveniently.\n5. Close the loop: reassess each register row after its safeguard and set its status — eliminated, mitigated with residual noted, or disclosed. No row stays open, and no engagement resumes until its rows are closed.\n6. Human checkpoint: the CAE approves each safeguard and each disclosure, and confirms no engagement continues with an unmanaged impairment.\n\n**Record in AssureSwarm**\n- Safeguard items — create one Issue per impairment (Issue: issue_type=observation, source=self_assessment, severity by threat type, issue_owner, remediation_plan = the applied safeguard, actual_remediation_date when the row closes) carrying the threat type and residual status in its description.\n- Relationships — relate each safeguard Issue to the anchor Audit item (the cycle item) and to the affected engagement's existing Audit item, so the impairment shows against both the program and the engagement it touched; the impaired person is named in the Issue (no Person item type).\n- Evidence — upload staffing-change confirmations and the approved Standard 2.3 disclosures as documents on each safeguard Issue.\n\n**Exit criteria** — Every register row carries an applied, CAE-approved safeguard with evidence; replacements rescreened clean; required disclosures delivered and acknowledged; per-row residual status recorded.","label":"Apply and record objectivity safeguards","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"apply-objectivity-safeguards"},{"data":{"description":"Approve evidence-based access restrictions and competency plans, then sign the reconciled program conclusion and committee report.","formData":{"fields":[{"key":"legitimate_use_affirmation","label":"I will use information obtained in audit work only for legitimate professional purposes and in conformance with laws, regulations, and policy (Standard 5.1)","required":false,"type":"checkbox"},{"key":"protection_affirmation","label":"I will protect that information — workpapers, interview notes, data extracts, draft reports, and personal data encountered in audits — from unauthorized access, use, or disclosure (Standard 5.2)","required":false,"type":"checkbox"},{"key":"survival_affirmation","label":"I understand this obligation survives the end of the engagement and the end of my employment or contract","required":false,"type":"checkbox"},{"key":"audit_file_stores_accessed","label":"Audit-file stores you currently hold access to (audit management system, workpaper repositories, shared drives or collaboration sites, analytics staging areas)","required":false,"type":"textarea"},{"key":"access_no_longer_needed","label":"Any of that access you no longer need, and the engagement it related to","required":false,"type":"textarea"},{"key":"copies_outside_approved_stores","label":"Any audit information held outside the approved stores (local drive, personal device, printed copies, external sharing links)","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve evidence-based access restrictions and competency plans, then sign the reconciled program conclusion and committee report.\n\n**Inputs**\nThe confirmed population with active assignments, joiners, and leavers.\n- Access lists for every audit-file store: the audit management system, workpaper repositories, shared drives and collaboration sites, and analytics staging areas holding audit data extracts.\n- Assisting-party contracts, for their confidentiality clauses.\n- The records-retention schedule for audit files.\n\nThe role competency framework with required proficiency per grade (general awareness → applied knowledge → expert is the common scale).\n- Evidence per auditor: engagement quality-review results, supervisor evaluations, certifications held, training records, and the prior-cycle assessment.\n- The forward audit plan, for the demand side of the function-level view.\n- CPE policies for the certifications the team holds.\n\nEvery stream's artifacts: the confirmed population and period boundaries and the requirements memo; the attestation register with the deviation register and resolutions where that branch ran; the declarations, screening results, impairment register, safeguards, and disclosures where that branch ran; the confidentiality acknowledgments and access review; the competency assessments, coverage matrix, and development plans.\n- The registers and trackers each step produced, for the metrics.\n- The records-retention schedule for professional-practice records.\n- The open-item lists: development plans in progress, impairments under monitoring, unfinished ethics remediation, and qualified-assistance arrangements that span the year.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. Chief Audit Executive owns the stated judgments and authorizations.*\n\n*Acknowledge confidentiality and review audit-file access.* Bind every auditor and assisting party to the confidentiality expectations (Standards 5.1–5.2) with a current acknowledgment, and restrict audit-file access to people with a legitimate, current professional need — during engagements and for as long as the files are retained afterward.\n\n1. Build the acknowledgment on the two obligations: use information obtained in audit work only for legitimate professional purposes and in conformance with laws, regulations, and policy (5.1); protect it from unauthorized access, use, or disclosure (5.2). Spell out what \"information\" covers — workpapers, interview notes, data extracts, draft reports, and personal data encountered in audits — and that the obligation survives both engagement end and employment end.\n2. For assisting parties, do both checks: the contract carries an adequate confidentiality clause including return or destruction of audit information at engagement end, and the individual still signs the acknowledgment — a clause their firm signed is not evidence the person on the engagement knows the rules.\n3. Pull the access lists for every audit-file store and reconcile against the population and active assignments. Flag: departed staff with live access (each one is also an offboarding-control failure — record it as such), assisting parties whose engagement ended, staff with access to engagements they are not staffed on, broad or administrator rights without a stated need, and external sharing links.\n4. Present the proposed restrictions to the CAE for authorization before applying them, using an already-authorized emergency removal procedure where a departed account requires immediate action. Restrict on least privilege: completed-engagement files go read-only to a restricted group; in-flight files are limited to the engagement team and supervisors; departed users are removed the day found; external-party access is time-bound to the engagement. Check archived and retained stores too — files kept under the retention schedule stay protected for their whole retention life, not just while the engagement is hot.\n5. Evidence the review with before-and-after access lists and the change records, so a reviewer can verify every flag was actioned or accepted with a written reason.\n6. Human checkpoint: the CAE confirms acknowledgment coverage and the authorized removals/restrictions, with evidence that audit files are accessible only for legitimate professional purposes. Include this review in the program conclusion; do not seek a second approval merely to file the access evidence.\n\n*Assess competency and plan development.* Assess each auditor against the knowledge, skills, and abilities their role requires, confirm the function can collectively deliver the audit plan (Standard 3.1), arrange qualified assistance where it cannot, and leave every auditor with an approved, trackable development plan (Standard 3.2).\n\n7. Assess each auditor area by area against the framework — professional ethics; governance, risk, and control; business acumen; communication; critical thinking; audit delivery; plus the function's specialist domains — at the proficiency their grade requires. Triangulate: a self-assessment alone is not an assessment. Where self-rating and supervisor rating differ by more than one level, calibrate with evidence; engagement quality results decide, not seniority.\n8. Verify certification currency: a practicing CIA reports 40 CPE hours a year, including 2 ethics hours, by December 31; CISA requires at least 20 hours a year and 120 per three-year cycle. A lapsed certification gets a reinstatement plan or stops being represented in bios and capability statements.\n9. Roll up to the function: build the competency-coverage matrix against what the forward plan actually demands — cybersecurity, fraud, model risk, ESG, a regulated domain. Standard 3.1 is collective: where the function lacks a competency the plan requires, the CAE either obtains qualified assistance (co-source or a guest specialist) or changes the plan. Record the arrangement or the plan change — a named gap with neither is a nonconformance, not a to-do.\n10. Write each development plan gap-first: objectives tied to the assessed gaps, named courses or certifications, hours, milestones scheduled across the year, and the ethics component. Add new-standards training wherever the requirements memo flagged a change in force.\n11. Compile the evidence set: individual assessments with their evidence references, the coverage matrix, the assistance arrangements, and the plans with owners and dates.\n12. Human checkpoint: the CAE approves each assessment, each assistance arrangement, and each development plan so progress can be tracked and reviewed through the year.\n\n*Compile program evidence and report.* Assemble the cycle's evidence into a self-contained, indexed file, draft the chief audit executive's report to the audit committee on the function's conformance with its ethics, objectivity, confidentiality, and competency expectations, and close the cycle on the CAE's sign-off with every open item carried into the next run.\n\n*The signed CAE conformance conclusion authorizes the subsequent archive, carryover and notification procedures.*\n\n13. Index the file by professional-practice area and link every artifact to the step that produced it. Every artifact must be dated and attributable; an undated register or an unsigned assessment goes back to its step now — not during the external quality assessment.\n14. Compute the cycle metrics: attestation and acknowledgment coverage (target 100% — report the actual with named exceptions), deviations opened and closed by severity with median days to close, impairments by threat type with the safeguard applied, access exceptions found and closed, competency gaps with assistance arranged, and development hours committed versus certification requirements.\n15. Draft the CAE's report: a conformance statement against Principles 1, 2, 3, and 5 of the Global Internal Audit Standards; each exception and its disposition; impairment disclosures made; systemic themes and what changed because of them. Cross-reference every figure to its source artifact — a number without a source line does not survive review. Write it to be checkable, not persuasive: this report is part of the evidence base the external quality assessment (required at least once every five years) will sample.\n16. Stand up the tracking dashboard for what stays open through the year: development-plan milestones, monitored impairments, and remediation still in flight.\n17. Run the completeness check against the artifact checklist: confirmed population and period boundaries, requirements memo, attestation register, deviation resolutions where that branch ran, declarations with screening results and safeguards where that branch ran, confidentiality acknowledgments and the access review, competency assessments and development plans, and the signed report. For a branch that did not run, the submitted routing decision and its native-result rationale is the record that it legitimately did not — verify that form is present rather than treating the absence as a gap.\n18. Human checkpoint: the CAE reviews the report and the indexed file, agrees follow-up actions with named owners and due dates, and signs off — confirming the file evidences the program to the audit committee and an external quality assessor without oral explanation. That sign-off is the cycle's closure.\n19. Export the full workflow record so the package stands alone as evidence the program operated for the period, and archive it with the evidence file at the retention location under the professional-practice retention rule. The retention period must at least span the external quality assessment cycle — assessments run at least every five years, and the assessor will sample this period — and attestations, declarations, and assessments must remain retrievable per person, not just per cycle.\n20. Carry the open items into the next cycle's intake with owners and due dates intact: development milestones, monitored impairments, open remediation, and year-spanning assistance arrangements. An item that loses its owner in the handoff is how ethics remediation quietly dies; the next cycle's intake consumes this list as prior-cycle carryover.\n21. Mark the cycle closed in the register with the archive references and the closure timestamp.\n22. Notify the audit committee and audit leadership that the cycle is closed and where the file lives.\n\n**Record in AssureSwarm**\nAcknowledgment — use one identified assignment per auditor or assisting party outside the complete executor roster, carrying known name and employment/assisting-party status in the request and using the native submission timestamp. Collect the legitimate-use, protection and survival affirmations, their declared audit-file stores, access no longer needed and copies outside approved stores. Executors supply their own signed acknowledgments in restricted native results/documents, with independent review of the CAE’s own statement. Its returned access declarations feed the reconciliation in item 3; record the access-reconciliation queries and results on the step.\n- Confidentiality acknowledgment register + access review — upload the consolidated acknowledgment register and the before/after audit-file access lists with change evidence as XLSX documents on this step (no per-person item type — the register on the step is the durable home).\n- Access failures — raise one Issue per departed-user-with-live-access or other material access exception (Issue: issue_type=deficiency, source=self_assessment, issue_owner, identified_date, target_remediation_date), related to the anchor Audit item so it tracks and carries forward with the rest of the cycle's open items.\n\nCompetency assessments + CPD plans — upload the individual assessments, the XLSX competency-coverage matrix, and the approved per-auditor development plans (objectives, courses, hours, milestones, owner) as documents on this step; there is no Person/Auditor or Development-Plan item type, so the per-auditor plan lives as a document here rather than as an item.\n- Rollup — record the assessment and coverage-matrix queries and results on the step.\n- Unfilled competency gaps — where the function lacks a plan-required competency and neither qualified assistance nor a plan change is arranged, raise an Issue (Issue: issue_type=deficiency, source=self_assessment, issue_owner, identified_date, target_remediation_date) related to the anchor Audit item; a resolved assistance arrangement is evidenced as a document instead.\n\nSigned CAE conformance report — the DOCX/PDF report to the audit committee, with the sign-off, attached as a document on this step; its figures cross-reference their source artifacts.\n- Indexed cycle evidence file — document-link every stream artifact (requirements memo, attestation register, declarations and impairment register, acknowledgment register and access review, competency assessments and plans) to the anchor Audit item so the cycle item carries the complete indexed file.\n- Open-items dashboard — create the professional-practice dashboard over the open Issue items linked to the anchor Audit item (deviation, impairment, access-failure, and competency-gap Issues) plus the monitored development milestones.\n- Close the cycle item — update the anchor Audit item: status → CLOSED, report_date = the sign-off date, rating (satisfactory | needs_improvement | unsatisfactory) reflecting the conformance conclusion, opinion = na (a professional-practice program carries no audit opinion), and the archive reference in its description.\n- Archive evidence — upload the completeness checklist and the archive confirmation with its references as documents on this step, and export the final workflow record with the report and sign-off attached into the archive as the durable trail.\n- Carry-forward handoff — attach the carry-forward list as a document on this step; the open Issue items themselves remain live against the anchor Audit item and are picked up as existing items by the next run of this workflow — that self-feeding intake is the only downstream.\n\n**Exit criteria**\nAcknowledgment coverage 100% including assisting parties; every access flag actioned or accepted with a reason; departed-user access at zero; post-engagement and archived stores verified protected.\n\nEvery auditor has a calibrated, evidence-referenced assessment and an approved development plan; every collective gap has an assistance arrangement or a documented plan change; certification currency verified; the full set uploaded and dated.\n\nIndex complete with zero undated or unattributed artifacts, or a pruned branch's decision record in its place; every metric traces to a source; the report is signed off by the CAE with follow-ups owned and dated; the dashboard is live for what remains open; the archive is confirmed at the retention location; carry-forward items live in the next cycle's intake with owners; the cycle item is closed and stakeholders notified.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` renders the indexed evidence file into a single reviewable package with cover index and cross-references.\n\n**Form recipient** — Auditors and assisting parties who execute none of this workflow’s checkpoints. Check the complete preparation, execution, review and approval roster first: anyone assigned a role anywhere in this workflow contributes through native results, documents and approvals instead. Read current evidence and declarations before requesting anything. Select only unresolved questions for the identified scope and period; known facts remain linked context, and no request is needed if nothing is missing. The catalog fields are optional so known or unasked facts need not be repeated; every question actually required by the assignment must have an attributable response or a recorded unresolved gap before the dependent judgment. A negative or declined affirmation remains visible; it must never be converted to a positive statement. Compare the complete executor roster with the population. Forms go only to people outside that roster. Executors record their own signed statements in restricted native results/documents; an independent reviewer handles the CAE’s own statement.","label":"Compile program evidence and report","performedBy":{"primitives":["coach-form-create","coach-query-data","coach-document-upload","coach-item-create","coach-items-link","coach-dashboard-create","coach-workflow-export","coach-render-package","coach-item-update"]}},"id":"compile-program-evidence-and-report"}],"sourceTemplateId":"workflow-library:audit-internal-audit-ethics-objectivity-competency-program"}
