,

GIAS Domain II: Ethics and Professionalism, Including Professional Courage

The Global Internal Audit Standards did something to ethics that the old framework never quite managed: they made it testable. The 2017 Code of Ethics sat beside the Standards as principles and rules of conduct; under the Standards that took effect on 9 January 2025 it became Domain II, Ethics and Professionalism, five principles and thirteen numbered standards with requirements written as “must”, considerations for implementation, and examples of evidence of conformance. That change matters in practice because a quality assessment now asks a chief audit executive to show, not assert, that the function demonstrates integrity, maintains objectivity, is competent, exercises due professional care and keeps information confidential. This guide goes through the domain standard by standard, with what each requires, how it is evidenced, where functions fall short, a conformance mapping table, a Domain II conformance record template and a worked self-assessment at a six-person audit function.

This guide was rewritten in September 2026 from a shorter version published in August 2026. Standard titles and numbering follow the Global Internal Audit Standards as published by The IIA on 9 January 2024; the requirement summaries are paraphrases for orientation and the Standards themselves are the authority.

In this guide

The domain at a glance: five principles, thirteen standards

PrincipleStandardIn one line
1. Demonstrate Integrity1.1 Honesty and Professional CourageBe truthful, and raise what needs raising even when it is unwelcome
1.2 Organization’s Ethical ExpectationsUnderstand and uphold the organization’s code, and report conduct that departs from it
1.3 Legal and Ethical BehaviorDo not participate in illegal or discreditable acts; act on knowledge of them
2. Maintain Objectivity2.1 Individual ObjectivityJudge without bias, conflicts or undue influence
2.2 Safeguarding ObjectivityThe CAE builds the policies and assignments that protect objectivity
2.3 Disclosing Impairments to ObjectivityActual or perceived impairments are disclosed to the right people, before and after the fact
3. Demonstrate Competency3.1 CompetencyThe function collectively has, or obtains, the knowledge and skills its work requires
3.2 Continuing Professional DevelopmentIndividuals keep and grow their competence, and can show it
4. Exercise Due Professional Care4.1 Conformance with the Global Internal Audit StandardsKnow the Standards, apply them, and disclose nonconformance
4.2 Due Professional CareMatch the work to the engagement’s nature, circumstances and complexity
4.3 Professional SkepticismQuestion, corroborate, and evaluate the reliability of what you are told
5. Maintain Confidentiality5.1 Use of InformationUse information only for authorized purposes, never for personal gain
5.2 Protection of InformationProtect information per policy and law, including after leaving

Why the Code of Ethics became standards

Under the 2017 International Professional Practices Framework, the Code of Ethics was a separate mandatory element: four principles (integrity, objectivity, confidentiality, competency) and rules of conduct, with the Standards referring to it and the certification disciplinary process enforcing it. It worked as a statement of values and poorly as a subject of assessment, because nothing in it said what evidence a conforming function would hold. The new Standards absorbed it into Domain II, added due professional care as a fifth principle (drawing on the old Standards 1200 series), and gave every standard the same three-part structure the rest of the framework uses: requirements, considerations for implementation, and examples of evidence of conformance. The consequence is that Domain II is assessed in the same way as Domains III to V, by a quality assessor asking for artifacts, and a function that has always behaved ethically but never documented how will find itself with observations. The Global Internal Audit Standards hub covers the framework’s overall shape and the IPPF-to-GIAS mapping traces each old Code element to its new home.

Two features of the domain are easy to miss. First, most of its requirements bind individual internal auditors as well as the function, so the evidence is partly personal: an auditor’s own CPD record, disclosure of a conflict, refusal of a gift. Second, several standards place obligations on the chief audit executive to create the conditions in which individuals can conform, which means the CAE’s policies and assignment decisions are themselves the evidence. A function can fail Domain II at either level.

Principle 1: Demonstrate Integrity

Standard 1.1, Honesty and Professional Courage, is the one that changed the profession’s vocabulary. Honesty was always required; professional courage, the willingness to communicate what needs communicating and to raise concerns even when the audience will not welcome them, is new as a written requirement, and it applies to the individual auditor and to the CAE. The requirement is that internal auditors perform their work with honesty and professional courage, communicating truthfully and accurately, and that they raise issues, even unfavorable ones, to the appropriate parties. The evidence is in the file: reports that state unfavorable conclusions without softening, escalations recorded when management disagreed, workpapers showing that a finding was not removed under pressure, and a CAE who can point to the occasions the function said what it had to. The consideration the Standards add is that the organization’s culture and the CAE’s support are what make courage possible for junior staff, and a function whose reports never contain an Unsatisfactory rating should ask itself whether that is because nothing was unsatisfactory.

Standard 1.2, Organization’s Ethical Expectations, requires internal auditors to understand, respect and support the organization’s ethical expectations, its code of conduct and related policies, and to report behavior inconsistent with them through the organization’s channels. Standard 1.3, Legal and Ethical Behavior, requires that internal auditors not engage in or be party to activity that is illegal or discreditable to the organization or the profession, and that they act on knowledge of such activity by reporting it as required. Together they mean the function is bound by the same code as everyone else and additionally by the profession’s, and the evidence is training completion, signed acknowledgments of the code, the function’s own gift and hospitality register, and records of any reports made. The culture audit guide covers how the organization’s ethical expectations are themselves audited; here the question is whether the auditors meet them.

Professional courage as a system, not a trait

Standard 1.1 asks individuals for courage, and the functions that conform reliably are the ones that have built structures so that courage is rarely required of a junior auditor alone. Five structures do most of the work. A rating methodology agreed with the audit committee in advance, so that an Unsatisfactory opinion follows from stated rules rather than from the CAE’s nerve on the day, as the finding severity ratings guide describes. A report-change rule: any finding removed or rating changed after the draft is issued to management is recorded with the evidence that justified the change, and changes made without new evidence are visible to the reviewer and, if the CAE chooses, to the committee. An escalation path that every auditor knows: to the engagement manager, to the CAE, to the audit committee chair, with the CAE’s direct access to the board under Domain III as the backstop. A practice of recording management disagreements in the report itself rather than resolving them by omission, which the report writing guide covers. And protection: a stated policy, endorsed by the committee, that auditors will not be penalized for conclusions reached on evidence, with the CAE’s own performance evaluation set by the committee rather than by the executives the function audits. The evidence of conformance with 1.1 is then partly structural (the methodology, the rule, the path, the policy) and partly historical (the reports that said unwelcome things and survived), and a quality assessor should be able to see both.

Principle 2: Maintain Objectivity

2.1 Individual Objectivity

Objectivity is an unbiased mental attitude that lets the auditor make judgments free of undue influence and conflict of interest, and the standard requires internal auditors to maintain it, to identify and manage threats to it, and to avoid accepting anything, from gifts to assignments, that impairs or appears to impair it. The considerations name the threats: self-review of work the auditor performed or areas they managed, familiarity from long association, undue influence from stakeholders, financial or personal interest, and bias from prior conclusions. Evidence at the individual level is an annual objectivity declaration, disclosure of relationships and prior roles, and the assignment records that show the auditor was not placed where they had a conflict.

2.2 Safeguarding Objectivity

This is the CAE’s standard. It requires the CAE to establish policies and procedures and to make assignments in ways that safeguard objectivity: assessing auditors’ objectivity when assigning work, rotating assignments, not assigning auditors to assess areas for which they had operational responsibility within a period the considerations describe as at least a year, managing the situation where the CAE has responsibilities beyond internal audit, and considering objectivity when the function performs advisory work in an area it will later audit. Evidence is the written policy, the assignment process and its records, the treatment of staff who transferred in from the business, and the safeguards applied where the CAE wears a second hat, which the Domain III guide discusses under independence.

2.3 Disclosing Impairments to Objectivity

Where objectivity is or appears to be impaired, the standard requires disclosure to the appropriate parties: before the engagement, to the CAE, who decides whether to reassign or safeguard; and where an impairment is discovered after the work, to the stakeholders who relied on it, with an assessment of the effect on the conclusions. The evidence is the disclosure record and, where it applies, the communication to stakeholders, which is the part functions omit because it is uncomfortable.

Objectivity in practice: the six situations

The objectivity standards are abstract until they meet a staffing decision, and the same six situations account for nearly every impairment a quality assessment finds. The table pairs each with the threat the Standards name, the safeguard a conforming function applies, and the evidence that shows the safeguard operated.

SituationThreatSafeguardEvidence
An auditor transfers in from the businessSelf-review of their own prior work or areaNo assurance assignments in the former area for at least a year; disclosure recorded; the assignment check appliedObjectivity policy; assignment record showing the exclusion; disclosure log entry
The CAE holds a second role (compliance, risk, a project, ERM)Self-review and management-responsibility conflictBoard-approved safeguard: the second role’s area is audited by an independent party, or the CAE recuses from its oversight; the arrangement is disclosed to the board and reassessed annuallyBoard minutes; charter clause; the independent review’s report
Advisory work followed by assurance in the same areaSelf-review of the function’s own adviceDifferent staff, a cooling period, or disclosure that the assurance covers implementation rather than design of what was advisedEngagement records; planning memo stating the safeguard
Long association with one auditee or processFamiliarityRotation of lead auditors on a cycle; second-reviewer independenceRotation schedule; review sign-offs
Gifts, hospitality, favorsUndue influence, perceived or actualRegister with thresholds; refusal as the default from auditees during an engagementRegister entries; policy acknowledgments
Personal or financial relationships with auditeesConflict of interestAnnual and per-engagement declarations; reassignment where a relationship existsDeclarations compared to the plan; assignment records

Two of the six generate most of the argument. The CAE’s second role is common in smaller organizations and is permitted by the Standards provided the safeguards are in place and the board has approved them; what is not permitted is silence, and the assessment asks for the board’s approval and the annual reassessment before it asks about anything else. The transfer from the business is the situation where the “at least a year” consideration is misread as a rule that allows assignment on day 366: the requirement is that objectivity not be impaired, and an auditor who designed the process three years ago may still be impaired for it, which the assignment check has to consider case by case.

Principle 3: Demonstrate Competency

Standard 3.1, Competency, requires internal auditors to possess or obtain the knowledge, skills and abilities their responsibilities require, to engage only in services for which they are competent or can become competent with assistance, and requires the CAE to ensure that the function collectively has what its plan demands, obtaining outside expertise where it does not. The evidence is a competency framework or skills inventory mapped to the plan, the gaps identified and the co-sourcing or training that closed them, which the co-sourcing guide covers from the resourcing side. Standard 3.2, Continuing Professional Development, requires internal auditors to maintain and develop their competence through continuing professional education, staying current with the Standards, the profession and the organization’s industry, and to keep records; for holders of IIA certifications the CPE reporting rules apply (40 hours a year for a Certified Internal Auditor in practice, with ethics hours included), and the CIA CPE requirements guide sets those out. The evidence is the training record per person, reviewed by the CAE annually, and the plan’s skills demands compared to what the records show.

Principle 4: Exercise Due Professional Care

Standard 4.1, Conformance with the Global Internal Audit Standards, requires internal auditors to understand the Standards and to plan and perform their work in conformance with them, and it carries the rule that where laws or regulations conflict with the Standards, the law prevails and the conflict is disclosed; it also carries the disclosure duty where nonconformance affects an engagement or the function, which the QAIP playbook explains in the reporting context. Standard 4.2, Due Professional Care, requires the auditor to consider the nature, circumstances and complexity of the engagement, the extent of work needed to achieve its objectives, the relative complexity and materiality of matters, the probability of significant errors, fraud or nonconformance, the cost of assurance relative to benefit, and the use of technology and analytics; it is the standard behind the planning judgment the planning memo template records. Standard 4.3, Professional Skepticism, requires a questioning mind and a critical assessment of information, including corroboration and an evaluation of the reliability of what management provides, and it is the standard behind the evidence hierarchy in the audit evidence guide and the reason a management explanation is not a conclusion. Evidence for the principle is mostly in the engagement files: planning memos that show the considerations, workpapers that show corroboration, review notes that show challenge.

Principle 5: Maintain Confidentiality

Standard 5.1, Use of Information, requires internal auditors to use information only for the purposes for which it was obtained and authorized, never for personal gain or in ways contrary to law or detrimental to the organization’s legitimate objectives, and to respect the confidentiality of information even after they leave the function or the organization. Standard 5.2, Protection of Information, requires them to protect information in accordance with the organization’s policies and applicable laws, with the CAE establishing the function’s own procedures for handling, storing, transmitting and retaining information, including the data the function obtains for analytics. The second standard has become the more demanding of the two as audit functions take on more data: an analytics program that copies the payroll file into a shared workbook has breached it, and the payroll analytics guide and the data privacy audit guide describe the handling arrangements that conform. Evidence is the confidentiality policy and acknowledgments, the function’s information handling procedure, the access controls over the audit management system and evidence store, and the retention and destruction records for engagement data.

Evidence of conformance and the common gaps

StandardEvidence a conforming function holdsWhere functions usually fall short
1.1 Honesty and Professional CourageUnfavorable conclusions issued as written; escalation records; CAE communications to the board on disagreements; ethics trainingRatings inflated after management pushback; no record that a removed finding was removed on evidence
1.2 Organization’s Ethical ExpectationsCode acknowledgments; training; the function’s reports of inconsistent behavior through official channelsAuditors exempted from the organization’s code training “because they audit it”
1.3 Legal and Ethical BehaviorGift and hospitality register; policy on outside interests; records of reports madeNo register; gifts from auditees accepted informally
2.1 Individual ObjectivityAnnual declarations; disclosed relationships and prior roles; refusal recordsDeclarations signed and filed without anyone reading them against the plan
2.2 Safeguarding ObjectivityObjectivity policy; assignment process with conflict check; rotation records; safeguards for the CAE’s other roles; advisory-to-assurance cooling rulesNo written policy; transferees assigned to their former area; CAE with second-line duties and no safeguard documented
2.3 Disclosing ImpairmentsDisclosure log; reassignments; stakeholder communications where impairment found after the factImpairments handled by conversation, never recorded
3.1 CompetencySkills inventory mapped to the plan; gap analysis; co-sourcing and hiring decisions traced to itThe plan includes IT, cyber and analytics work the team cannot perform, with no external expertise arranged
3.2 Continuing Professional DevelopmentTraining records per person; CPE reporting for certified staff; annual CAE reviewRecords kept by individuals only; certifications lapsed unnoticed
4.1 Conformance with the StandardsMethodology aligned to the Standards; conformance statements in reports; nonconformance disclosures; QAIP resultsReports claim conformance the QAIP has never tested
4.2 Due Professional CarePlanning memos recording the considerations; resource decisions; use of analytics documentedSame budget and approach for every engagement regardless of complexity
4.3 Professional SkepticismCorroboration in workpapers; review notes; findings supported beyond management assertionExplanations accepted as evidence; management representations closing findings
5.1 Use of InformationConfidentiality acknowledgments; policy on use after leaving; access logsFormer auditors’ access never removed; audit reports circulated beyond authorized readers
5.2 Protection of InformationInformation handling procedure; secure evidence store with access control; retention and destruction records; analytics data arrangementsEvidence on personal drives and email; analytics extracts with personal data kept indefinitely

What the chief audit executive has to build

Read across the thirteen standards, the CAE’s obligations under Domain II come to six artifacts and two processes. The artifacts: an objectivity and independence policy covering declarations, conflicts, rotation, transfers from the business, advisory-to-assurance cooling periods and the CAE’s own second roles; a confidentiality and information handling procedure covering the evidence store, analytics data, transmission, retention and destruction, and use after leaving; a competency framework or skills inventory mapped to the audit plan; a continuing professional development policy with records and an annual review; an ethics section in the function’s methodology that states the organization’s code and the Standards’ requirements and how reports of inconsistent behavior are made; and a gift and hospitality register. The processes: an assignment process that checks objectivity before every engagement and records the check, and a disclosure process for impairments discovered before or after the work, with a defined route to stakeholders. The Domain IV guide covers the methodologies standard (9.3) under which most of these artifacts are housed, and the QAIP self-assessment template is where their existence and operation are tested each year.

Two of the artifacts deserve a note on proportion. A six-person function does not need a forty-page objectivity policy; it needs a two-page one that says what happens when someone transfers in from operations, when the CAE is asked to run a project, and when an auditee sends a case of wine. And the information handling procedure has become the artifact most likely to be tested against real events, because the function’s analytics work now routinely holds data more sensitive than anything in its reports.

How a quality assessor tests the domain

Domain II is assessed in three passes, and knowing the passes tells a CAE what to have ready. The document pass reads the artifacts: the objectivity policy, the confidentiality procedure, the competency framework, the CPD policy, the ethics section of the methodology and the registers, checking each against the standard it serves and for a review date within the year. The records pass tests operation on the population: every auditor’s declaration, CPD record and confidentiality acknowledgment for the period, the assignment records for every engagement in the plan traced to the objectivity check, the disclosure log, the gift register and the evidence store’s access list, with leavers’ access confirmed removed. The engagement pass samples files, usually three to five across the year including at least one with an unfavorable conclusion, and reads them for the domain’s fingerprints: the planning memo’s due-care considerations, the corroboration behind each finding, the review notes that show challenge, the handling of management’s responses, and the retention of evidence in the function’s store rather than in mailboxes. The assessor’s conclusion per standard is generally conforms, partially conforms or does not conform, using the IIA’s quality assessment vocabulary, and an external quality assessment under Standard 8.4 will run the same three passes with less patience for artifacts that exist but were never used. The QAIP playbook sets out the internal assessment cycle in which the passes run, and the timing rule that a function should have completed at least one honest internal assessment before its first external one.

For a small function the three passes take two or three days if the artifacts exist and a season if they do not, which is the practical argument for building them in the ninety-day program the playbook describes. The assessment also produces the domain’s contribution to the QAIP report to the board, which under the Standards must state the function’s conformance and the results of the assessment, and a Domain II section that runs to a page with one or two observations is what a well-run function should expect to write.

The Domain II conformance record

One record per year, completed as part of the internal quality assessment under Standard 12.1, with a row per standard. It is the Domain II section of the self-assessment the QAIP self-assessment template lays out.

Domain II conformance record

1. Scope. Function; period; assessor; sources reviewed (policies, declarations, training records, engagement files sampled, registers, disclosure log).

2. Per standard (1.1 to 5.2). Requirement in the function’s own words; artifacts held (reference); operation evidence (what was sampled and what it showed); conclusion (generally conforms / partially conforms / does not conform); observation and action if any.

3. Individual-level tests. Declarations obtained from every auditor; CPD records reviewed for every auditor; certifications verified; confidentiality acknowledgments on file; leavers’ access removed.

4. Assignment tests. Sample of engagements traced to the objectivity check; any transferee assignments; any advisory-to-assurance sequences; CAE second-role safeguards.

5. Courage and skepticism evidence. Engagements with unfavorable conclusions issued; disagreements escalated; findings removed and the evidence basis; workpaper corroboration sampled.

6. Information handling. Evidence store access review; analytics data arrangements and destruction records; retention compliance.

7. Overall result for the domain. Overall conformance; observations by standard; actions with owners and dates; matters for the audit committee.

8. Sign-off. Assessor, CAE, dates; reference to the QAIP report to the board.

Worked example: MidState Beverage’s Domain II self-assessment

MidState Beverage, the illustrative three-state drinks distributor used across this site, has a six-person internal audit function: a chief audit executive, a manager, two seniors, a staff auditor and an analytics and IT auditor. It built its quality assurance and improvement program in ninety days during FY27, as the QAIP playbook describes, and the first internal assessment found three partial conformances, all in Domains IV and V (Standards 9.4, 12.2 and 15.2). Domain II came out as generally conforming, but the assessment produced two observations and one decision that show how the domain works in a small function.

The first observation was under Standard 2.2. One of the two seniors had transferred into internal audit from depot operations in March 2026, where she had supervised two of the twelve depots, and the FY27 route cash audit, planned for the first quarter of the fiscal year, would have tested the depot reconciliation control at all twelve, including hers. The CAE had assigned her to the engagement because she knew the process, which is the reasoning the standard exists to stop. The assessment recorded the assignment as an impairment that the objectivity policy, written in the same ninety days, would have caught, and the CAE reassigned her to the warehouse inventory engagement, put the staff auditor on route cash, and recorded the decision in the disclosure log under 2.3 with the note that no work had yet been performed. The second observation was under 3.2: the CPD records showed four of the six staff had met the 40-hour expectation the function had set for everyone, certified or not, and the two who had not were the CAE and the analytics auditor, who had spent the year building the QAIP and the analytics program respectively; the observation was recorded with a plan rather than excused.

The decision was under 1.1. The route cash audit’s report, FY27-01, carried an Unsatisfactory opinion and five findings, and the chief operating officer had asked the CAE, in writing, to reconsider the opinion on the ground that the depot reconciliation had been performed everywhere even if not independently. The CAE’s reply, which the assessment cited as the function’s evidence of professional courage, explained that the rating rule had been agreed with the audit committee, that the independence failure at nine depots was the finding, and that the opinion would stand; the COO accepted the residual risk on part of one finding, which was recorded under Standard 11.5 as the Domain IV guide describes, and the exchange went to the audit committee with the report. The assessment also tested 5.2 against a real event, the payroll analytics run described in the payroll analytics guide: the handling arrangement with HR, the pseudonymization, the restricted store and the destruction record were all present, and the assessor’s only note was that the arrangement should become a standing agreement rather than a per-run negotiation. The Domain II section of the QAIP report to the audit committee ran to one page, which is the right length for a domain that is conforming.

Common mistakes

Treating Domain II as a values statement rather than a set of standards with evidence. Assigning transferees to their former areas because they know the process. Letting the CAE’s second role (compliance, risk, a project) run without a documented safeguard. Collecting objectivity declarations and never comparing them to the plan. Keeping CPD records with individuals and discovering lapsed certifications at renewal. Claiming conformance with the Standards in every report before the QAIP has tested anything. Accepting management’s explanation as corroboration. Handling impairments by conversation. Storing engagement evidence and analytics data wherever the auditor finds convenient. Softening an opinion after pushback with no evidence basis for the change, which is the failure Standard 1.1 was written to name. The Domain V guide covers the engagement standards where skepticism and due care are exercised, the inside the internal audit department guide the operating model these standards sit in, and the Topical Requirements guide the mandatory layer that Domain II’s conformance requirement (4.1) now includes.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading