2.1 The Statutory Mandate of the New IIA Standards
The professional execution of internal auditing is governed globally by the Global Internal Audit Standards (GIAS) promulgated by the Institute of Internal Lawyers (IIA). The GIAS establishes a mandatory, auditable framework that defines the structural requirements, operational performance benchmarks, and ethical rules that all internal auditors must satisfy. [1, 2, 3, 4, 5]
Compliance with these standards is a core listing rule across global stock exchanges and a baseline requirement under standard corporate law, ensuring that internal audit departments operate with consistent technical rigor across international jurisdictions.
2.2 Deconstructing the Four Core Ethical Principles of the GIAS
The ethical framework of the GIAS moves past generic behavioral statements and enforces four strict, distinct operational principles that guide daily audit activities: [1]
- Integrity: Auditors must perform their work with honesty, diligence, and responsibility. This requires full compliance with statutory laws, making explicit disclosures required by the profession, and refusing to engage in activities that could compromise the firm or the internal audit function.
- Objectivity: Auditors must not participate in any activity or relationship that could impair, or appear to impair, their unbiased assessment. This includes refusing to audit an operational process or business unit where the auditor maintained direct management authority within the previous twelve months.
- Confidentiality: Auditors must protect all data assets and sensitive information gathered during an investigation. They are legally barred from disclosing corporate records to outside entities without explicit authorization, unless there is a mandatory statutory or legal obligation to report non-compliance.
- Competency: Auditors must possess and continuously develop the technical knowledge, practical skills, and specialized certifications (such as the Certified Internal Auditor – CIA designation) required to execute complex control reviews. [1, 2, 3, 4, 5]
To verify that the internal audit function maintains full compliance with the GIAS ethical code and operational performance standards, the board mandates the implementation of a continuous Quality Assurance and Improvement Program (QAIP). The QAIP requires a multi-layered verification approach: [1, 2]
The QAIP Verification Cycle:
[Continuous Project Reviews] ──► [Annual Internal Assessments] ──► [Independent External Assessments (Every 5 Years)]
The cycle includes continuous internal reviews of individual audit files, annual self-assessments of the entire department’s performance, and a mandatory Independent External Assessment conducted by an qualified, outside review team at least once every five years. The external findings are reported straight to the audit committee, ensuring continuous improvement at the governance layer. [1, 2]
Â