Chief audit executive
   HOME

TheInfoList



OR:

The chief audit executive (CAE), director of audit, director of internal audit,
auditor general An auditor general, also known in some countries as a comptroller general or comptroller and auditor general, is a senior civil servant charged with improving government accountability by auditing and reporting on the government's operations. Freq ...
, or
controller Controller may refer to: Occupations * Controller or financial controller, or in government accounting comptroller, a senior accounting position * Controller, someone who performs agent handling in espionage * Air traffic controller, a person ...
general is a high-level independent corporate
executive Executive ( exe., exec., execu.) may refer to: Role or title * Executive, a senior management role in an organization ** Chief executive officer (CEO), one of the highest-ranking corporate officers (executives) or administrators ** Executive dir ...
with overall responsibility for
internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
. Publicly traded corporations typically have an
internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
department, led by a chief audit executive ("CAE") who reports functionally to the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
of the board of directors, with administrative reporting to the
chief executive officer A chief executive officer (CEO), also known as a central executive officer (CEO), chief administrator officer (CAO) or just chief executive (CE), is one of a number of corporate executives charged with the management of an organization especial ...
. The profession is unregulated, though there are a number of international standard setting bodies, an example of which is the
Institute of Internal Auditors The Institute of Internal Auditors (IIA) is an organization which advocates, provides educational conferences, and develops standards, guidance, and certifications for the internal audit profession. History Established in 1941, the IIA today ...
("IIA"). The IIA has established Standards for the Professional Practice of Internal Auditing and has over 150,000 members representing 165 countries, including approximately 65,000
Certified Internal Auditor The Institute of Internal Auditors (IIA) is an organization which advocates, provides educational conferences, and develops standards, guidance, and certifications for the internal audit profession. History Established in 1941, the IIA today ...
s. The CAE is intrinsically an independent function; otherwise it may become dysfunctional and of low quality (but there are many degrees in the level of independence and efficiency). The CAE function exists only to constitute a third-level of control in the organisation, which must be independent from the first-level control (the first-level layer belongs to the management of an organisation, who is responsible in the first instance for acting in compliance with the organisation’s rules) and consecutively second-level (which are the supporting units i.e. legal, HR, risk function, financial control etc.). An effective independence is the result of both an attitude of CAE, and of prerogatives/guarantees conceded by the organisation or given by the organisation’s principals (e.g., the board of directors or audit committee). Because the CAE understands risks and controls, company strategy and the regulatory environment the CAE may assume additional organizational responsibilities beyond traditional internal auditing.


Independent attitude

The CAE should be independent in the performance of his/her duties, so that he/she can carry out his/her work freely without admitting interference, and as objectively as possible. Independence permits him/her to render impartial and unbiased judgements, which are essential to the proper evaluation of management and controls. It also allows him/her to view the financial actions, procedures and decisions in a detached way. This may become of an importance when providing objective assurance about the internal control framework.


Organizational independence

To perform their role effectively, CAEs require organizational independence from
management Management (or managing) is the administration of an organization, whether it is a business, a nonprofit organization, or a Government agency, government body. It is the art and science of managing resources of the business. Management includ ...
, to enable unrestricted
evaluation Evaluation is a systematic determination and assessment of a subject's merit, worth and significance, using criteria governed by a set of standards. It can assist an organization, program, design, project or any other intervention or initiative to ...
of
management Management (or managing) is the administration of an organization, whether it is a business, a nonprofit organization, or a Government agency, government body. It is the art and science of managing resources of the business. Management includ ...
activities and personnel. This can be analysed in the different points below: * (for a different analysis of independence, see organizational independence analysed by the IIA) All the elements below should be granted to the CAE in the basic rules of the organisation, or stated in the charter of audit approved by the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
and promulgated in the organization ( IIA Standard 1110 Organizational Independence, and standard 1000C1).


Independent function: no conflict of interest allowed

Even though the CAE may be formally part of the
management structure Management (or managing) is the administration of an organization, whether it is a business, a nonprofit organization, or a government body. It is the art and science of managing resources of the business. Management includes the activities ...
of the organisation (among the “
chief executive A chief executive officer (CEO), also known as a central executive officer (CEO), chief administrator officer (CAO) or just chief executive (CE), is one of a number of corporate executives charged with the management of an organization especially ...
s”), he/she does not participate in any management decision process or accept any responsibility in the execution of company activities. CAEs may advise management (must, when it is about compliance, risk management,
internal control Internal control, as defined by accounting and auditing, is a process for assuring of an organization's objectives in operational effectiveness and efficiency, reliable financial reporting, and compliance with laws, regulations and policies. A broad ...
s...) and the board of directors (or similar
oversight Oversight may refer to: Governance *Regulation – rulemaking *Separation of powers in state governance (checks and balances) - the concept of separate branches of government or agencies exercising authority over one another *Checks and control ...
body) regarding how to better execute their responsibilities. But she/he remains independent of the activities observes or audits.


Hierarchical independence

The primary customer of internal audit activity is the entity charged with
oversight Oversight may refer to: Governance *Regulation – rulemaking *Separation of powers in state governance (checks and balances) - the concept of separate branches of government or agencies exercising authority over one another *Checks and control ...
of management's activities. This is typically the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
, a sub-committee of the board of directors. To provide hierarchical independence, most chief audit executives report to the
chairperson The chairperson, also chairman, chairwoman or chair, is the presiding officer of an organized group such as a board, committee, or deliberative assembly. The person holding the office, who is typically elected or appointed by members of the grou ...
of the audit committee as to the performance of his/her duties. The definition (and regular revision) of the scope of the function should be agreed between the CAE and the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
. The internal audit’s annual
work plan Work may refer to: * Work (human activity), intentional activity people perform to support themselves, others, or the community ** Manual labour, physical work done by humans ** House work, housework, or homemaking ** Working animal, an animal tr ...
, which for practical reasons must be discussed with the auditees, is subject to the approbation of the sole
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
, board of directors, or other appropriate governing authority (IIA Standard 1110 Organizational Independence). The internal rules and practices of the directorate of internal audit (
audit manual An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon.” Auditing ...
) are of the responsibility of the CAE.


Independent status

The independence of the CAE in the performance of his duties should be guaranteed in the staff rules. The
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
should have sole competence for the final decision on appointment and dismissal of the CAE”, and for his remuneration, activity appraisal and
career The career is an individual's metaphorical "journey" through learning, work and other aspects of life. There are a number of ways to define career and the term is used in a variety of ways. Definitions The ''Oxford English Dictionary'' defi ...
advancement. The CAE is liable to
disciplinary action In a deliberative assembly, disciplinary procedures are used to punish members for violating the rules of the assembly. Codes and rules According to Robert's Rules of Order Newly Revised (RONR), discipline could include censure, fine, suspension ...
but only with the concurrence of the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
. This could happen if he/she is negligent in the performance of his duties.


Independent communication right

The CAE reports directly to the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
and the board. There should be a report from the CAE to each ordinary
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
meeting and if deemed necessary to the board. Such reports should be addressed directly to the chairman of the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
with parallel copy to the
director-general A director general or director-general (plural: ''directors general'', ''directors-general'', ''director generals'' or ''director-generals'' ) or general director is a senior executive officer, often the chief executive officer, within a governmen ...
. However, the CAE in the performance of his daily work communicates and liaises with the
director-general A director general or director-general (plural: ''directors general'', ''directors-general'', ''director generals'' or ''director-generals'' ) or general director is a senior executive officer, often the chief executive officer, within a governmen ...
and the staff of the organisation.


Independent budgeting

Although CAEs and
internal auditor An internal auditor is an auditor who is appointed by the Board of directors of the company in order to carry out the internal audit function. Generally an employee of the company acts as an internal auditor, whereas some companies appoint an exter ...
s are paid by the company, the
human resource Human resources (HR) is the set of people who make up the workforce of an organization, business sector, industry, or economy. A narrower concept is human capital, the knowledge and skills which the individuals command. Similar terms include ...
budget of the
directorate of internal audit Directorate may refer to: Contemporary *Directorates of the Scottish Government * Directorate-General, a type of specialised administrative body in the European Union * Directorate-General for External Security, the French external intelligence a ...
, in particular, should be protected from interference from the audited organisation. The typical risk is that the audit's budget subject to the approval of director of HR and of the DG is a source of potential interference or friendly pressure to self-limit the CAE’s critic exercise of an independent viewpoint. An appeal to the board, even expressly foreseen as part of the communication right of the CAE, is often ineffective on short-term imposed constraints, given the time constraints of the
budget process A budget process refers to the process by which governments create and approve a budget, which is as follows: * The Financial Service Department prepares worksheets to assist the department head in preparation of department budget estimates * The A ...
. The best practice is that the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
's opinion is required on the CAE’s draft budget, well in advance of the normal budgeting process of the organisation.


Access to information

Information is of key importance to organize, prepare and perform internal audits. Independent auditors are generally granted full access to any and all information they require to discharge their responsibilities. Reasonable restrictions would be limited to things such as personal information in personnel records such as health information. Unduly restricted access to information is a major impediment to an independent auditor and indicates that an organization is not truly supportive of the auditor's mandate and its commitment to sound governance should be questioned.


Typical duties


Status, strategy and organisation of the internal audit department

* Ensure that the status (e.g. stipulated in an audit charter), strategy, resources of the
internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
department are aligned and are consistent with the organization's objectives and
governance Governance is the process of interactions through the laws, norms, power or language of an organized society over a social system ( family, tribe, formal or informal organization, a territory or across territories). It is done by the gove ...
policy. * Establish appropriate policies and procedures to guide the internal audit function, and ensure the
quality Quality may refer to: Concepts *Quality (business), the ''non-inferiority'' or ''superiority'' of something *Quality (philosophy), an attribute or a property *Quality (physics), in response theory * Energy quality, used in various science discipl ...
of the
assurance services Assurance service is an independent professional service, typically provided by Chartered or Certified Public Accountants or Chartered Certified Accountants, with the goal of improving information or the context of information so that decision ...
delivered.


Management, supervision of the internal audit activity

* Obtain (or manage the production of) a risk analysis; ** Ensure that the
risk assessment Broadly speaking, a risk assessment is the combined effort of: # identifying and analyzing potential (future) events that may negatively impact individuals, assets, and/or the environment (i.e. hazard analysis); and # making judgments "on the ...
is done at least annually; ** Establish risk-based audit plans to set out the priorities of the
internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
function, consistent with the organizational objectives. * Considers the input of senior
management Management (or managing) is the administration of an organization, whether it is a business, a nonprofit organization, or a Government agency, government body. It is the art and science of managing resources of the business. Management includ ...
, senior departmental management, of the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
; * The internal audit plan usually addresses
financial reporting Financial statements (or financial reports) are formal records of the financial activities and position of a business, person, or other entity. Relevant financial information is presented in a structured manner and in a form which is easy to un ...
and other fundamental controls, to be coordinated with the audit plan of the
statutory auditor Statutory auditor is a title used in various countries to refer to a person or entity with an auditing role, whose appointment is mandated by the terms of a statute. World usage A "statutory audit" is a legally required review of the accuracy ...
* Coordinate internal auditing activities and plans with other internal and external providers of assurance and
consulting A consultant (from la, consultare "to deliberate") is a professional (also known as ''expert'', ''specialist'', see variations of meaning below) who provides advice and other purposeful activities in an area of specialization. Consulting servic ...
activities to ensure proper coverage and minimize duplication of effort. * Communicate plan of engagements and resource requirements for the internal audit function, including significant interim changes to the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
. This communication shall include the impact of resource limitations. *Ensure that internal audit resources are appropriate, sufficient and effectively deployed to achieve the internal audit plan approved by the audit committee or the board. Ensure that internal auditors have appropriate professional qualifications and skills, and opportunities for sufficient training and development to maintain and develop their internal auditing competence and to obtain
Certified Internal Auditor The Institute of Internal Auditors (IIA) is an organization which advocates, provides educational conferences, and develops standards, guidance, and certifications for the internal audit profession. History Established in 1941, the IIA today ...
certification. *Ensure the timely completion of internal auditing engagements. *Ensure that reports on internal auditing engagements are provided to the audit committee with a minimum of delay. *Provide an annual holistic opinion on the effectiveness and adequacy of risk management,
control Control may refer to: Basic meanings Economics and business * Control (management), an element of management * Control, an element of management accounting * Comptroller (or controller), a senior financial officer in an organization * Controllin ...
, and
governance Governance is the process of interactions through the laws, norms, power or language of an organized society over a social system ( family, tribe, formal or informal organization, a territory or across territories). It is done by the gove ...
processes.


Quality management

The CAE is responsible for assuring that appropriate engagement supervision is provided. Supervision is a process begins with planning and continues throughout the examination,
evaluation Evaluation is a systematic determination and assessment of a subject's merit, worth and significance, using criteria governed by a set of standards. It can assist an organization, program, design, project or any other intervention or initiative to ...
, communication, and follow-up phases of the engagement. *Develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit function, and continuously monitor its effectiveness. *In collaboration with the audit committee, ensure that a practice inspection or other external review of the internal audit function is conducted at least every 3 years, by a qualified, independent external review team, and that the results of this external assessment are communicated to the audit committee. * Ensure that professional internal
auditing standards An audit is an "independent examination of financial information of any entity, whether profit oriented or not, irrespective of its size or legal form when such an examination is conducted with a view to express an opinion thereon.” Auditing ...
are followed (e.g. IIA standards or local standards). NB:
Generally accepted auditing standards Generally Accepted Auditing Standards, or GAAS are sets of standards against which the quality of audits are performed and may be judged. Several organizations have developed such sets of principles, which vary by territory. In the United States, ...
and
International Standards on Auditing International Standards on Auditing (ISA) are professional standards for the auditing of financial information. These standards are issued by the International Auditing and Assurance Standards Board (IAASB). According to Olung M (CAO - L), ISA g ...
are
external audit An external auditor performs an audit, in accordance with specific laws or rules, of the financial statements of a company, government entity, other legal entity, or organization, and is independent of the entity being audited. Users of these en ...
standards. * Report at least annually to the audit committee on the internal audit function's conformance with professional internal auditing standards.


Reporting of critical findings

Inform the Audit Committee without delay of any issue of risk,
control Control may refer to: Basic meanings Economics and business * Control (management), an element of management * Control, an element of management accounting * Comptroller (or controller), a senior financial officer in an organization * Controllin ...
or
management Management (or managing) is the administration of an organization, whether it is a business, a nonprofit organization, or a Government agency, government body. It is the art and science of managing resources of the business. Management includ ...
practice that may be of significance. The chief audit executive (CAE) reports the most critical issues to the
audit committee An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external. In a U ...
quarterly, along with management's progress towards resolving them. Critical issues typically have a reasonable likelihood of causing substantial financial or reputational damage to the company. For particularly complex issues, the responsible manager may participate in the discussion. Such reporting is critical to ensure the function is respected, that the proper "
tone at the top "Tone at the top" is a term that originated in the field of accounting and is used to describe an organization's general ethical climate, as established by its board of directors, audit committee, and senior management. Having good tone at the top ...
" exists in the organization, and to expedite resolution of such issues. It is a matter of considerable judgement to select appropriate issues for the audit committee's attention and to describe them in the proper context.


Survey results

Various
consulting A consultant (from la, consultare "to deliberate") is a professional (also known as ''expert'', ''specialist'', see variations of meaning below) who provides advice and other purposeful activities in an area of specialization. Consulting servic ...
and
public accounting An accountant is a practitioner of accounting or accountancy. Accountants who have demonstrated competency through their professional associations' certification exams are certified to use titles such as Chartered Accountant, Chartered Certifi ...
firms perform research on audit committees, to provide benchmarking data. Some results are identified below: *54% of committee members surveyed felt the audit committee was "very effective," while 38% indicated "somewhat effective." *Risk management,
internal control Internal control, as defined by accounting and auditing, is a process for assuring of an organization's objectives in operational effectiveness and efficiency, reliable financial reporting, and compliance with laws, regulations and policies. A broad ...
, and accounting estimates and judgments were the top priority areas for 2007. *41% were "very satisfied" with the internal audit function, while 52% were "somewhat satisfied." *Two-thirds felt the chief
internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
position was for a professional internal
auditor An auditor is a person or a firm appointed by a company to execute an audit.Practical Auditing, Kul Narsingh Shrestha, 2012, Nabin Prakashan, Nepal To act as an auditor, a person should be certified by the regulatory authority of accounting and a ...
, rather than as a "stepping stone" to other roles.


See also

* Comptroller *
Lead auditor {{unreferenced, date=April 2009 Most publicly traded corporations typically have an internal auditing department, led by a chief audit executive ("CAE"), with lead internal auditors managing small teams of internal auditors for one audit engagemen ...
*
Control Control may refer to: Basic meanings Economics and business * Control (management), an element of management * Control, an element of management accounting * Comptroller (or controller), a senior financial officer in an organization * Controllin ...
* COSO framework *
Audit risk Audit risk (also referred to as residual risk) as per ISA 200 refers to the risk that the auditor expresses an inappropriate opinion when the financial statements are materiality misstated. This risk is composed of: * Inherent risk (IR), the ri ...
* Financial audit *
Information technology audit An information technology audit, or information systems audit, is an examination of the management controls within an Information technology (IT) infrastructure and business applications. The evaluation of evidence obtained determines if the inform ...
*
Internal audit Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to ...
*
Institute of Internal Auditors The Institute of Internal Auditors (IIA) is an organization which advocates, provides educational conferences, and develops standards, guidance, and certifications for the internal audit profession. History Established in 1941, the IIA today ...
*
Corporate governance Corporate governance is defined, described or delineated in diverse ways, depending on the writer's purpose. Writers focused on a disciplinary interest or context (such as accounting, finance, law, or management) often adopt narrow definitions ...
* ISA 310 Knowledge of the Business ;External audit * Certified Public Accountant (CPA) *
External auditor An external auditor performs an audit, in accordance with specific laws or rules, of the financial statements of a company, government entity, other legal entity, or organization, and is independent of the entity being audited. Users of these enti ...
*
Statutory auditor Statutory auditor is a title used in various countries to refer to a person or entity with an auditing role, whose appointment is mandated by the terms of a statute. World usage A "statutory audit" is a legally required review of the accuracy ...
*
Auditor general An auditor general, also known in some countries as a comptroller general or comptroller and auditor general, is a senior civil servant charged with improving government accountability by auditing and reporting on the government's operations. Freq ...
*
International Organization of Supreme Audit Institutions The International Organization of Supreme Audit Institutions (INTOSAI) is an intergovernmental organization whose members are supreme audit institutions. Nearly every supreme audit institution in the world is a member of INTOSAI. Depending on t ...


References


External links


the Institute of Internal Auditors
{{DEFAULTSORT:Chief Audit Executive Internal audit Corporate governance A