Independence and Objectivity

A chief audit executive can join a strategic meeting, challenge a proposal, and maintain constructive relationships with senior management without losing independence. Another can keep a deliberate distance and still lack the authority to investigate a sensitive issue.
The difference is not proximity. It is who controls scope, access, resources, conclusions, and the ability to escalate a matter to the board.
Independence does not require isolation. It requires governance that protects the function from interference and professional discipline that supports impartial judgment. Influence is essential; risk begins when it is exchanged for subordination, management ownership, or silence about an impairment.
Independence and objectivity are not interchangeable
The Global Internal Audit Standards, effective since January 9, 2025, deliberately separate two related concepts.
Independence primarily belongs to the function. It is the absence of conditions that impair the internal audit function’s ability to carry out its responsibilities impartially. It is protected through the chief audit executive’s direct accountability to the board, sufficient organizational stature, authority to access people and information, and freedom from interference when determining scope, performing engagements, and communicating results.
Objectivity belongs to the individual and to each professional judgment. It is an impartial and unbiased mindset that enables an auditor to assess all relevant circumstances without subordinating judgment to others. An independently positioned function supports objectivity, but it cannot guarantee it. An auditor may have direct access to the board and still be affected by familiarity, self-review, personal interests, or informal pressure.
The remedies are different. A structural weakness cannot be corrected by reminding the team to remain objective, and a strong reporting line does not replace management of individual conflicts and biases.
Proximity is not the problem; interference is
Internal audit needs access, context, and trusted relationships. Without them, the function enters decisions too late, understands risk less clearly, and offers less useful insight. The Standards recognize that the chief audit executive reports functionally to the board and often reports administratively to a member of management. The administrative relationship can enable day-to-day access, organizational authority, and business understanding when appropriate safeguards are in place.
The real test is not how often internal audit speaks with management. It is whether the function can disagree without improper consequences.
Interference may be present when management restricts access to data or people, narrows a board-approved scope, pressures auditors to change a finding, delays a communication, or reduces the budget to a level that prevents the function from fulfilling its mandate. Risk also arises when the chief audit executive reports administratively to an executive and provides assurance over activities controlled by that same executive.
The board therefore cannot act as a passive recipient of reports. It must actively protect independence by approving reporting relationships, participating in the appointment and removal of the chief audit executive, providing private meeting opportunities, supporting adequate resources, and ensuring sensitive matters can be escalated without management filters.
A close relationship can increase influence. A poorly designed reporting relationship can determine which truths reach the board.
Impairments must be addressed before they contaminate judgment
The Standards require internal auditors to recognize and avoid or mitigate actual, potential, and perceived impairments. Perception is not a superficial reputation issue. If a reasonable observer could conclude that judgment has been compromised, confidence in the work declines even when the auditor believes the conclusion was impartial.
Some impairments are obvious: a financial interest, a gift, a close personal relationship, or direct pressure to soften results. Others emerge from operational decisions that initially appear efficient.
| Situation | Risk to independence or objectivity | Possible response |
|---|---|---|
| An auditor is assigned assurance work over an activity they recently managed. | Self-review and insufficient critical distance. The Standards presume objectivity to be impaired when responsibility existed during the previous 12 months. | Reassign the engagement, defer it when appropriate, or use independent oversight. |
| The chief audit executive temporarily assumes compliance, risk management, or another management role. | Internal audit may later assure decisions, controls, or outcomes for which the chief audit executive was responsible. | Document the role, obtain board approval for safeguards, set a transition plan, and arrange independent assurance during the assignment and for at least the following 12 months. |
| Management limits scope, access, budget, or communication. | Structural impairment to the function’s independence. | Escalate to the board, document the limitation, and agree actions that restore authority and resources. |
| Team performance or compensation depends heavily on the number of findings, identified savings, or satisfaction of the audited area. | Incentives to exaggerate, suppress, or negotiate conclusions. | Redesign metrics, balance performance criteria, and strengthen supervision and review. |
| An auditor has a long-standing or close relationship with the activity under review. | Familiarity bias, excessive acceptance, or unchallenged assumptions. | Rotate staff, add an independent review, disclose the relationship, or change the assignment. |
Early identification makes it possible to act before the impairment affects evidence or conclusions. When an impairment is discovered after an engagement, the chief audit executive must consider its effect on the actual or perceived reliability of the results and communicate with the affected parties.
Safeguards must change the situation, not merely document it
A conflict disclosure is not, by itself, a safeguard. Transparency is essential, but an effective response changes who performs the work, who reviews it, what scope is covered, or where accountability sits.
The Standards identify options such as reassigning auditors, rescheduling the engagement, adjusting scope, outsourcing performance or supervision, and using an independent provider that reports directly to the board. When the chief audit executive holds additional responsibilities, the charter should document the nature and duration of the role and the related safeguards.
This approach is consistent with the logic of the IESBA Code, even though external audit operates in a different context. The Code requires professional accountants to identify and evaluate self-interest, self-review, advocacy, familiarity, and intimidation threats. When a threat is not at an acceptable level, the professional must eliminate the circumstance creating it, apply an effective safeguard, or decline or end the activity.
That framework offers a useful discipline for internal audit: not every threat can be solved through another layer of review. Sometimes the only defensible answer is to remove an individual, separate a responsibility, or refuse to perform the work under the proposed conditions.
Influence without management ownership
Internal audit influence can be a strength. The function can participate early in a transformation, provide criteria, test assumptions, identify scenarios, and surface risks before a decision becomes difficult to reverse. Remaining outside every important conversation out of fear of “losing independence” can reduce value without protecting objectivity.
The boundary is crossed when the auditor stops advising and starts deciding for management. Facilitating a risk workshop is not the same as accepting the identified risks. Commenting on control design is not the same as owning implementation and operation. Presenting alternatives is not the same as approving the solution.
The Standards allow internal audit to provide advisory services and later provide assurance when the chief audit executive confirms that the nature of the advisory work does not impair objectivity and assigns resources in a way that protects individual objectivity. Prior involvement should be assessed, not hidden. The more influence internal audit exercised over the design or decision, the stronger the need for reassignment, independent review, or an alternative provider.
For external audit, ISA 200 requires compliance with relevant ethical requirements, including those related to independence. The IESBA Code describes independence as both independence of mind and independence in appearance. Internal audit does not replicate the external auditor’s separation from the entity; it operates within the organization. Yet both disciplines share an essential proposition: trust depends on the quality of the judgment and on relationships and responsibilities that allow others reasonably to believe in that judgment.
A practical test for the board and chief audit executive
Independence and objectivity become operational when they can be tested through concrete questions:
- Can internal audit determine and perform its work without management controlling scope, access, or the wording of conclusions?
- Can the chief audit executive meet directly and privately with the board, particularly on sensitive matters?
- Are reporting relationships, additional roles, and safeguards documented in the charter and reviewed periodically?
- Are conflicts, prior responsibilities, incentives, and relationships considered before each engagement is staffed?
- Would the selected safeguard genuinely reduce the risk in the view of a reasonable and informed third party, or merely generate more documentation?
- Is the organization prepared to reassign, outsource, or decline the work when an impairment cannot be managed?
These questions also explain why the topic is central to the current CIA Part 1 syllabus. The syllabus covers impairments arising from inappropriate reporting lines, budget restrictions, scope and access limitations, first- and second-line responsibilities, conflicts of interest, gifts, disclosure, reassignment, and outsourcing.
The professional lesson is not to memorize a list. It is to recognize that independence and objectivity are protected through visible governance and engagement staffing decisions.
An influential internal audit function does not avoid every difficult conversation. It participates enough to understand and contribute, retains the authority to challenge, discloses impairments, and accepts boundaries when it cannot assure its own work. Close enough to understand the business, directly connected to the board, and sufficiently free to say what must be said: that is the right distance.
Sources
- The Institute of Internal Auditors, Global Internal Audit Standards
- The Institute of Internal Auditors, CIA Part 1 syllabus
- IAASB, 2025 Handbook of International Pronouncements, Volume 1
- IESBA, International Code of Ethics for Professional Accountants
- IESBA, 2025 Handbook of the International Code of Ethics, Volume 1