Internal auditing is defined by the Institute of Internal Auditors (IIA)
as helping an organization “accomplish its objectives by bringing a
systematic, disciplined approach to evaluate and improve the
effectiveness of risk management, control, and governance
processes” (Whittington & Pany, 2021). The presence of internal
auditing is considered part of a business’ internal control which
evaluates the effectiveness of all other controls. The AICPA includes
internal auditing as part of the monitoring portion of a business’
internal control.
The article I selected for this week’s discussion addresses an added
factor to internal auditing that is not seen with external auditing.
When an organization uses external auditing, the internal auditors
must deal with the risk of entrusting their data to an outside party.
There is a separate group of factors with regard to internal controls,
such as assessing “whether data can be sent out the door” and
considering “what would happen if the organization’s auditor,
consultant, or SaaS experiences a data breach” (Bridgmon &
Robberson, 2022). It seems as though while external auditors must
determine functionality and compliance of organizations, the internal
auditors of said organizations must determine whether the external
auditors are sufficient enough. Internal auditors must “monitor their
own outside service providers to reduce the risk of unauthorized
disclosure” in the form of data breaches, hacking, or the added
branch of potential fraud (Bridgmon & Robberson, 2022).
Bridgmon, A., & Robberson, S. (2022). Practicing What It Preaches:
Internal audit must ensure the data it entrusts to external parties is
safeguarded. Internal
Auditor, 79(3). https://link.gale.com/apps/doc/A713047878/AONE?
u=nhc_main&sid=bookmark-AONE&xid=1082adcc
Whittington, R., & Pany, K. (2021). Principles of Auditing & Other
Assurance Services (22nd ed.). McGraw-Hill Education.