The Institute of Internal Auditors (IIA) Code of Ethics extends beyond high-level philosophy to provide practical behavioral rules that govern the everyday activities of practicing internal auditors. The code is divided into four core principles, each supported by explicit rules of conduct that must be enforced to maintain professional standing.
                       ┌────────────────────────────────────────┐
                       │          IIA CODE OF ETHICS            │
                       └───────────────────┬────────────────────┘
                                           ▼
       ┌───────────────────┬───────────────┴───────────────┬───────────────────┐
       ▼                   ▼                               ▼                   ▼
  [Integrity]        [Objectivity]                 [Confidentiality]     [Competency]
  • Honest labor     • Fair assessment             • Safe data logs      • Certified execution
  • Law observance   • No gift bias                • No private gain     • Continuous study
  • Truthful reports • Clear conflict checks       • Secure storage      • Quality improvement

1. Integrity
  • Rules of Conduct: Internal auditors shall perform their work with honesty, diligence, and responsibility. They must observe the law and make disclosures required by law and the profession. They must not knowingly be a party to any illegal activity, or engage in acts that are discreditable to the profession of internal auditing or to the organization.
  • Applied Corporate Dilemma: If an auditor discovers a deliberate misstatement in an environmental compliance report, they cannot omit the finding from their report to maintain corporate harmony. Omitting the finding would violate the rule of honesty and render the auditor a party to a regulatory misstatement.
2. Objectivity
  • Rules of Conduct: Internal auditors shall not participate in any activity or relationship that may impair, or be presumed to impair, their unbiased assessment. This participation includes those activities or relationships that may be in conflict with the interests of the organization. They shall not accept anything that may impair or be presumed to impair their professional judgment, such as expensive corporate gifts, entertainment, or financial favors.
  • Applied Corporate Dilemma: An internal auditor cannot audit a department or process they managed within the past 12 months. Reviewing one’s historical management decisions creates a structural self-review bias that compromises the objectivity of the audit.
3. Confidentiality
  • Rules of Conduct: Internal auditors shall be prudent in the use and protection of information acquired in the course of their duties. They shall not use information for any personal gain or in any manner that would be contrary to the law or detrimental to the legitimate and ethical objectives of the organization.
  • Applied Corporate Dilemma: During a financial acquisition review, an auditor gains early access to anonymized corporate performance logs that indicate upcoming profit growth. The auditor cannot share this information with associates or use it to execute private stock trades.
4. Competency
  • Rules of Conduct: Internal auditors shall engage only in those services for which they have the necessary knowledge, skills, and experience. They shall perform internal auditing services in accordance with the International Standards for the Professional Practice of Internal Auditing. They must continually improve their proficiency and the effectiveness and quality of their services through continuous professional education (CPE).
  • Applied Corporate Dilemma: An audit function without certified cybersecurity specialists should not attempt to execute a deep penetration test or source-code audit of an infrastructure platform. Instead, the Chief Audit Executive (CAE) must co-source the engagement by bringing in qualified external technology specialists to support the review.