Headline goes here - Chartered Institute of Internal Auditors

Accreditation of prior learning (APL) –
portfolio of evidence documentation
IIA Advanced Diploma
M3 Risk Assurance and Audit Management
Outline
You should complete and submit this documentation if you wish to make a submission for accreditation of prior learning for the module
indicated above, once you have registered for the qualification. Guidance notes are provided in a separate document available on the
Institute’s website.
In this document you will find sixteen defined knowledge areas each requiring you to provide and discuss evidence of learning. You will
also find a concluding testimonial sheet for completion to accompany the entire submission.
Initial submission: You should complete any two of the evidence pages for two separate knowledge areas from within this pack and
return electronically to the IIA via the address [email protected], using the title APL- Initial submission. You will receive
comments and feedback from an assessor to help you with your full submission.
Full submission: On receipt of your feedback from your initial submission, you will be given advice for completion of all sixteen
knowledge areas and concluding testimonial. Following review and signature by your authenticating signatory or signatories (electronic
insertion of name and date constitutes signature), you should submit the complete document electronically to address
[email protected], using the title APL- Full submission.
Payment details
An assessment fee of £137.50 + VAT is payable (current to 31 March 2015). We can invoice you or your employer. Your employer may
require a purchase order number to be supplied with the invoice. Please note the required purchase order number in the box below or
state "Not required". If no purchase order number is supplied then submission of this application will be taken as confirmation that your
employer does not require a purchase order number. Please complete the options below:
Invoice me
Invoice my employer
Purchase order number
Submission confirmation
I supply the information below as my submission for the accreditation of prior learning for the module named above. I also supply a copy
of my Curriculum Vitae showing my internal audit experience totalling more than five years. I understand that my submission will be
assessed under the process outlined in the APL policy and supporting materials:
Full Name
Membership number
Date
April 2014
-1-
Ref
Knowledge area
Syllabus reference
M3.1
Comparison of national and international governance codes and
frameworks
1.1, 1.2
Indicative knowledge and understanding requirements:
National and international governance codes and legislative frameworks, their application (use, benefits and
limitations) across organisations and their impact on internal audit; and the differences between principles and
rule-based frameworks and illustrate the strengths and weaknesses of each.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-2-
Date
Ref
Knowledge area
Syllabus reference
M3.2
The principal providers of assurance
1.3
Indicative knowledge and understanding requirements:
Principal assurance providers, how they contribute to the overall governance framework and their relationship
with internal audit (including management, audit committees, compliance function, insurance function, security
function, risk management function, health and safety function, public sector inspectorates, and external
assurance providers).
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-3-
Date
Ref
Knowledge area
Syllabus reference
M3.3
Organisational culture
1.4
Indicative knowledge and understanding requirements:
The development and key drivers of organisational culture and the internal political environment.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-4-
Date
Ref
Knowledge area
Syllabus reference
M3.4
The impact of internal and external factors on corporate governance
1.5
Indicative knowledge and understanding requirements:
How cultural, political, societal, technological, legislative, environmental and ethical factors influence corporate
governance.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-5-
Date
Ref
Knowledge area
Syllabus reference
M3.5
The principles of embedded risk management
2.1
Indicative knowledge and understanding requirements:
How embedding risk management within an organisation can lead to a more integrated and risk aware culture
(including: the advantages and disadvantages of a risk aware culture; potential barriers to embedding risk
management (such as risk lethargy, the size and diversity of the organisation, geographical spread and the nature
of the product/service offering); risk management frameworks, including enterprise wide risk management (ERM);
and the use of technological solutions).
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-6-
Date
Ref
Knowledge area
Syllabus reference
M3.6
Advanced approaches to and broader dimensions of risk management
2.2, 2.3, 2.6
Indicative knowledge and understanding requirements:
Advanced approaches to risk management (including: critically evaluating risk policy and its component parts
(such as risk appetite and risk tolerance); explaining the difference between gross and net risks; understanding
and assessing different approaches to risk incident capture, reporting and monitoring, including technological
solutions; and evaluating the process of identifying potential new sources of risk from the internal and external
environments and their potential impact of the organisation); the broader dimensions of risk management and
their importance to the overall risk management framework (including: risk financing; risk psychology and human
behaviour; insurance as a risk mitigator; capital modelling techniques; and the impact of risk assurance on
shareholder value); and how stakeholder pressure influences risk management and how stakeholder relationships
should be managed to mitigate stakeholder risk.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-7-
Date
Ref
Knowledge area
Syllabus reference
M3.7
The significance of specific topical risks
2.4
Indicative knowledge and understanding requirements:
Specific and topical risk types and their importance to different business sectors (including: agency risk
(agents/principals); credit risk; financial risk; fraud risk; information systems risk; internal systems and control risk;
internet and e-commerce risk; legal risk; market risk; organisational/operational risk; outsourcing risk; pensions
risk; political risk; project risk; reputational risk; service delivery risk; strategic risk).
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-8-
Date
Ref
Knowledge area
Syllabus reference
M3.8
The reasons for organisational failure
2.5
Indicative knowledge and understanding requirements:
The reasons for organisational failure, what happens when things go wrong (causes and implications) and
organisational response, together with the lessons learned from organisational successes.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
-9-
Date
Ref
Knowledge area
Syllabus reference
M3.9
The broader roles of internal audit
3.1, 3.2, 3.6, 3.7, 3.8
Indicative knowledge and understanding requirements:
Broader roles of internal audit and the constraints relating to them when working as consultant/adviser, negotiator,
facilitator and mentor, related to this to specific examples of internal audit activities designed to add value to an
organisation; internal audit roles relating to risk management in an organisational context, the need for
maintaining independence and the expectations of management; when it is appropriate to undertake a
consultancy assignment and the skills set required successfully to complete such an assignment within an
organisational context; audit involvement in complex and sensitive organisational areas (such as providing
assurance on ethical and social risks, the use of consultants, reviewing board effectiveness, reviewing the control
mechanisms for the delivery of organisational goals, and forensic accounting); and the role of internal audit in
fraud with reference to practical guidance and the lessons learned from major fraud cases.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 10 -
Date
Ref
Knowledge area
Syllabus reference
M3.10
The principle of reasonable assurance
3.3
Indicative knowledge and understanding requirements:
The definition of ‘reasonable assurance’ in a business context and how to manage stakeholders’ expectation of
internal audit in this regard, including: the boundaries of assurance; recognising the risks which could cause a
flawed assurance opinion to be given; evidence required to support the assurance opinion; evaluating evidence;
and the balance between positive and negative assurance.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 11 -
Date
Ref
Knowledge area
Syllabus reference
M3.11
The IPPF in practice
3.4
Indicative knowledge and understanding requirements:
How the professional practices framework and standards are used in practice and how they may guide the
internal auditor in situations such as personal responsibility, conflict of interest, ethical conflict and whistle
blowing.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 12 -
Date
Ref
Knowledge area
Syllabus reference
M3.12
The application and limits of the tools and techniques of internal audit
3.5
Indicative knowledge and understanding requirements:
The application and limitations of tools and techniques (including IT) used in audit and the most appropriate
approach to use in a particular assignment.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 13 -
Date
Ref
Knowledge area
Syllabus reference
M3.13
The principles of audit management
4.1, 4.2
Indicative knowledge and understanding requirements:
How to manage effectively an internal audit function (including: recruiting teams; training and CPD; motivating
and retaining staff; managing staff problems; marketing the internal audit function; managing the internal audit
reputation; using IT to streamline the audit process, using standards to guide work and decision making; planning
and managing the audit work plan; audit control processes, customer satisfaction survey techniques; data privacy
and freedom of information; benchmarking and evaluating the success of internal audit; the management of large
and small teams; and the management of specialist and generalist auditors; and the application of knowledge
management in the internal audit function making specific reference to the effective sharing of knowledge
internally and externally.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 14 -
Date
Ref
Knowledge area
Syllabus reference
M3.14
The importance of relationships and networking
4.3, 4.4, 4.6, 4.7
Indicative knowledge and understanding requirements:
Internal audit’s relationship with senior management and the board of directors and how to build and nurture open
and effective communication channels; the use and importance of networking as a basis for maintaining
awareness of events and their potential impact upon audit plans; how internal audit can work effectively with other
internal and external review and assurance agencies in order to provide an overall assurance opinion; and the
audit consultancy process, with reference to independence and the use of technological solutions.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 15 -
Date
Ref
Knowledge area
Syllabus reference
M3.15
The principles of effective reporting
4.5
Indicative knowledge and understanding requirements:
The principles of effective reporting to the board, the audit committee and other stakeholders, including: what and
when to report, and to whom; why reporting must take cognisance of the organisational context; and reporting and
confidentiality.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 16 -
Date
Ref
Knowledge area
Syllabus reference
M3.16
Assessing and evaluating the audit function
4.8, 4.9, 4.10
Indicative knowledge and understanding requirements:
How to undertake a risk assessment of the internal audit function, the principal risks and how they may be
managed; the advantages and disadvantages of in-house, out-sourced and co-sourced provision of internal audit;
and how internal audit can contribute to the management development and the implementation of the various
means of internal audit provision.
Source(s) of evidence – what specific evidence sources can you produce that demonstrate you have the required
knowledge and understanding? These must be listed with a brief description and must be reviewed by the person
who is authenticating your submission.
Explanation of how the evidence satisfies the knowledge and understanding requirements – how does the
evidence cited demonstrate that you have the required knowledge and understanding? (Word count: 500)
Authenticating signature: I have viewed the evidence quoted above and in my opinion it demonstrates the
candidate has the required knowledge and understanding of this subject.
Name
Signature
- 17 -
Date
Please provide details of the person(s) making the authenticating signature for your portfolio.
Ideally the signatory should be a member of the IIA and hold a relevant professional qualification. Where this is
not possible you should explain why the person or persons signing your portfolio is/are most appropriately placed
to do so.
Signatory (1)
Name:
Job role/title:
Relevant professional qualifications held:
Professional relationship to you with relevant dates:
Signatory (2)
Name:
Job role/title:
Relevant professional qualifications held:
Professional relationship to you with relevant dates:
Signatory (3)
Name:
Job role/title:
Relevant professional qualifications held:
Professional relationship to you with relevant dates:
Candidate’s signature: I confirm that all of the evidence referred to in this portfolio is recent, reliable
and authentic.
Name
Signature
- 18 -
Date
www.iia.org.uk
Chartered Institute of Internal Auditors
13 Abbeville Mews, 88 Clapham Park Road, London SW4 7BX
tel 020 74980101 fax 020 7978 2492 email [email protected]
© March 2012
- 19 -