Circular No. 08/2021/TT-BTC issues Vietnam’s Internal Audit Standards and Professional Ethics Principles for Internal Auditors applicable to enterprises, state agencies, and public service units. This document guides the implementation of internal audits to ensure independence, objectivity, and effectiveness in financial management activities.
Đối tượng áp dụng
["Enterprises", "State agencies", "Public service units"]
Các điểm cốt lõi
- "Enterprises, state agencies, and public service units must comply with Vietnam’s Internal Audit Standards and Professional Ethics Principles for Internal Auditors as stipulated in Appendix I and II of this Circular" (Article 2)
- Organizations not subject to mandatory compliance are encouraged to apply the aforementioned standards and principles
- This Circular takes effect from April 1, 2021
- Enterprises, state agencies, and public service units are provided specific guidance on standards and ethical principles in internal auditing
- Organizations not subject to mandatory compliance have additional options to apply the standards and principles to enhance the quality of financial management activities
- The accounting and auditing sector is supported in establishing and implementing professional regulations
🌐 Tác động xã hội từ văn bản này
- Enterprises, state agencies, and public service units are provided specific guidance on standards and ethical principles in internal auditing
- Organizations not subject to mandatory compliance have additional options to apply the standards and principles to enhance the quality of financial management activities
- The accounting and auditing sector is supported in establishing and implementing professional regulations
❓ Câu hỏi thường gặp
When does Circular No. 08/2021/TT-BTC take effect?
This Circular takes effect from April 1, 2021.
Which organizations must comply with Vietnam’s Internal Audit Standards and Professional Ethics Principles for Internal Auditors?
Enterprises, state agencies, and public service units as specified in Articles 8, 9, and 10 of Decree No. 05/2019/NĐ-CP.
Which organizations are encouraged to apply the internal audit standards and principles?
Units not falling under the scope defined in Clause 1 of Article 2 of this Circular.
Toàn văn
MINISTRY OF FINANCE
SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
Number: 8/2021/TT-BTC
Hanoi, January 25, 2021
CIRCULAR
Issuing Vietnam Internal Audit Standards
and Professional Ethics Principles for Internal Auditors
‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾‾
Pursuant to the Accounting Law No. 88/2015/QH13 dated November 20, 2015;
Pursuant to Decree No. 05/2019/NĐ-CP dated January 22, 2019 of the Government on internal audit;
Pursuant to Decree No. 87/2017/NĐ-CP dated July 26, 2017, issued by the Government, stipulating the functions, tasks, powers, and organizational structure of the Ministry of Finance;
On the proposal of the Director of the Department of Accounting and Auditing Supervision;
The Minister of Finance issues this Circular on issuing Vietnam Internal Audit Standards and Professional Ethics Principles for Internal Auditors.
Article 1. Scope of Regulation
This Circular promulgates Vietnam Internal Audit Standards (Annex I) and Professional Ethics Principles for Internal Auditors (Annex II).
Article 2. Applicability
1. Vietnam Internal Audit Standards and Professional Ethics Principles for Internal Auditors apply to enterprises, state agencies, public service units as prescribed in Article 8, Article 9, and Article 10 of Decree No. 05/2019/NĐ-CP dated January 22, 2019 of the Government on internal audit and related organizations and individuals involved in the internal audit activities of these entities.
2. Entities not falling within the scope prescribed in Clause 1 of this Article are encouraged to implement Vietnam Internal Audit Standards and Professional Ethics Principles for Internal Auditors as stipulated in Annex I and Annex II attached hereto.
Article 3. Implementation Organization
1. This Circular takes effect from April 1, 2021.
2. The Director of the Department of Accounting and Auditing Supervision, the Head of the Ministry's Office, and the heads of relevant units shall be responsible for guiding the implementation and enforcement of this Circular.
|
Place of Receipt: - General Secretary's Office; - National Assembly's Office; - President's Office; - Central Party Office and its Departments; - Government Office; - Supreme People's Procuracy, Supreme People's Court; - State Audit Agency; - Ministries, agencies equivalent to ministries, and agencies under the Government; - Provincial People's Committees, Municipalities directly under the Central Government; - DEPARTMENT OF LEGAL DOCUMENT REVIEW - MINISTRY OF JUSTICE; - Units under and affiliated with the Ministry of Finance; - Vietnam Chamber of Commerce and Industry (VCCI); - State Capital Investment Committee; - Vietnam Association of Accountants (VAA); - Vietnam Institute of Certified Public Accountants (VACPA); - Auditing firms; - Official Gazette; Central Steering Committee for Anti-Corruption; ||| - Government website and Ministry of Finance website; - File: VT, Department of Accounting and Auditing. |
DEPUTY MINISTER DEPUTY MINISTER (Signed) Ta Anh Tuan |
Appendix I
VIETNAM INTERNAL AUDIT STANDARDS
(Issued together with Circular No. 8/2021/TT-BTC dated January 25, 2021 of the Minister of Finance)
Introduction to the standards
Internal audit is conducted in entities with different purposes, scales, levels of complexity, and structures, and is performed by personnel within and outside the entity. Adherence to Vietnam Internal Audit Standards is essential for fulfilling the responsibilities of internal auditors and the internal audit function.
Purpose of the standards
1. To provide a framework for implementing and promoting internal audit activities that create value for the entity.
2. To establish a basis for evaluating internal audit activities.
3. To encourage improved processes and activities within the entity.
The standards are a set of mandatory principle-based provisions, including:
Core provisions on internal audit practice and the evaluation of internal audit effectiveness at both individual and entity levels.
Interpretations of the standards aim to clarify terms and concepts within the standards.
Internal audit standards consist of two main groups: attribute standards and activity standards.
Attribute standards: refer to the characteristics of the entity and individuals performing internal audit work.
Activity standards: describe the nature of internal audit activities and set quality criteria for measuring internal audit activities. Both attribute and activity standards apply to all internal audit activities.
Based on attribute standards and activity standards, additional guidance on implementation is developed by specifying requirements for assurance engagements (denoted by A) or consulting engagements (denoted by C).
Assurance engagements involve internal auditors objectively assessing evidence to form opinions or conclusions regarding an entity, activity, function, process, system, or other matters. The nature and scope of assurance engagements are determined by the internal auditor.
Typically, there are three parties involved in assurance engagements:
(1). Individuals or groups directly involved in the entity, activity, function, process, system, or other content, referred to as the auditee.
(2). Individuals or groups conducting the assessment, referred to as the internal auditor.
(3). Individuals or groups using the assessment results, referred to as the users.
Consulting engagements have the nature of providing advice and are usually carried out at the specific request of authorized persons within the entity. The nature and scope of consulting engagements need to be clearly agreed upon. Consulting engagements typically involve two parties:
(1). Individuals or groups providing consulting services - the internal auditor.
(2). Individuals or groups seeking and receiving consulting services - the party requiring advice.
When conducting consulting engagements, internal auditors should maintain objectivity and should not assume management responsibility for the advised activities.
The standards apply to internal auditors and the internal audit department. Internal auditors are responsible for adhering to standards related to their personal objectivity, professional competence, due care, and standards related to the performance of their duties. For those in charge of internal audit, there is an additional responsibility to ensure overall compliance of internal audit activities with internal audit standards.
If internal auditors or the internal audit department cannot comply with certain parts of the standards due to legal prohibitions or regulations, they must still comply with other parts of the standards and provide appropriate explanations.
If the standards are applied together with other requirements prescribed by competent authorities, the internal audit report may need to cite the use of those requirements, as appropriate. In such cases, when the internal audit department complies with the standards and identifies inconsistencies between the standards and other requirements, the internal auditor and the internal audit department must comply with the higher requirement between the standards or other requirements.
Explanation of terms
Strategic multi-purpose hydropower plant
Highest management level: The level that performs the highest management (such as the board of directors/board of members/company chairman of enterprises, Minister of ministries, Head of ministerial-level agencies, Head of government-affiliated agencies, Chairman of provincial/municipal People's Committees under the central government, Head of public service units) responsible for governance, direction, or supervision of the unit’s activities, as well as receiving reports from the senior management team of the unit. The term "Board" in the standards may also refer to a committee or a department authorized by the highest management level to perform certain functions (for example, the audit committee under the board of directors).
Senior management team: includes the general management board, the directorate board, and executive directors managing business operations; leaders at the ministry, ministerial-level agency, government-affiliated agency, provincial/municipal People's Committee under the central government, public service unit levels; heads of subordinate units of ministries, ministerial-level agencies, government-affiliated agencies, provincial/municipal People's Committees under the central government, public service units.
Internal audit head: is the person designated by the competent authority according to the law or by the unit to be responsible for the internal audit work of the unit.
Internal auditor: is the person performing the internal audit work of the unit.
Related party of the internal auditor: is the father, mother, adoptive father, adoptive mother, father-in-law, mother-in-law, father-in-law, mother-in-law, wife, husband, biological child, adopted child, full brother, full sister, younger brother, brother-in-law, younger brother-in-law, sister-in-law, younger sister-in-law.
SCOPE OF CHARACTERISTICS
1000 - Purpose, Authority, and Responsibilities of Internal Audit
The purpose, authority, and responsibilities of internal audit must be formally defined in the internal audit charter, consistent with the mission of internal audit and mandatory guidance in the Vietnamese Internal Audit Standards and the Code of Professional Ethics for Internal Auditors. Periodically, the internal audit head must review and present the internal audit charter to the senior management team and the highest management level for approval.
Interpretation of the standard:
The internal audit charter is a formal document defining the purpose, authority, and responsibilities of internal audit activities. The internal audit charter also specifies the position of internal audit within the unit, including the reporting relationship regarding the professional responsibility of the internal audit head to the highest management level; it defines the authority to access books, records, personnel, and assets related to the performance of assurance and advisory activities; it determines the scope of internal audit activities. The highest management level is the highest approving body for the internal audit charter.
1000.A1 - The nature of assurance services provided to the unit must be specified in the internal audit charter.
1000.C1 - The nature of advisory services provided to the unit must be specified in the internal audit charter.
1010 - Recording Mandatory Guidance in the Internal Audit Charter
The mandatory contents of the Vietnamese Internal Audit Standards and the Code of Professional Ethics for Internal Auditors must be included in the internal audit charter. The internal audit head should discuss with the senior management team of the unit and the highest management level about the purpose, tasks, scope, authority, and responsibilities of internal audit and the mandatory guidance of the Vietnamese Internal Audit Standards and the Code of Professional Ethics for Internal Auditors.
1100 - Independence and Objectivity
The internal audit department must be independent, and the internal auditor must be objective in performing their duties.
Interpretation of the standard:
Independence means that the internal audit department is not constrained by conditions that could threaten its ability to fulfill internal audit responsibilities impartially. To achieve the necessary level of independence for effectively performing internal audit responsibilities, the internal audit head has the right to directly and unrestrictedly access the senior management team and the highest management level. This can be achieved through a parallel reporting relationship. Risks threatening independence must be controlled and managed at all levels from the internal auditor to assurance activities, advisory activities, to the internal audit function, and to the organizational level of the unit.
Objectivity is demonstrated in an unbiased attitude, allowing the internal auditor to perform assurance and advisory activities in a manner they believe will produce reliable results without compromising on the quality of the work. Objectivity requires that the internal auditor not be influenced by others when making judgments about audit issues. Risks threatening objectivity must be controlled and managed at all levels from the internal auditor to assurance activities, advisory activities, to the internal audit function, and to the organizational level of the unit.
1110 - Organizational Independence
The internal audit head must report to the competent authority within the unit that allows the internal audit department to carry out its responsibilities. At least once a year, the internal audit head must confirm the organizational independence of the internal audit department with the highest management level.
Interpretation of the standard:
The organizational independence is effectively achieved when the head of internal audit reports professionally to the highest level of management. An example of reporting professionally to the highest level of management is demonstrated through the highest level of management's involvement in:
Approving the internal audit charter;
Approving the risk-oriented internal audit plan;
Approving the budget and internal audit resource plan;
Receiving reports from the head of internal audit on the implementation of internal audits according to the audit plan and other related issues;
Approving decisions related to the appointment and removal of the head of internal audit position;
Approving the salary of the head of internal audit;
Conducting necessary inquiries with the unit's senior management and the head of internal audit to determine whether the scope of audit is inappropriate or there are limitations in internal audit resources.
1110.A1 - The internal audit department must not be interfered with in determining the scope of work, performing tasks, and reporting exchange results. If there is interference, the head of internal audit must present it to the highest level of management and discuss the impacts of such interference.
1111 - Reporting directly to the highest level of management
The head of internal audit must report directly to the highest level of management.
1112 - The role of the head of internal audit outside the scope of internal audit
When the head of internal audit concurrently holds positions outside the internal audit scope, measures must be taken to limit the risk of affecting the organizational independence or objectivity of the internal audit department.
Interpretation of the standard:
The head of internal audit may be required to hold additional roles and responsibilities outside the internal audit activities, such as compliance activities or risk management. These roles and responsibilities may diminish or appear to diminish the organizational independence of the internal audit department or the objectivity of the internal auditor. Protective measures include supervisory activities regularly conducted by the highest level of management to address potential diminishment and may include periodic evaluations of reporting channels, responsibilities, and building alternative processes to ensure matters related to areas where the head of internal audit concurrently holds positions.
1120 - Objectivity of the internal auditor
The internal auditor must ensure fairness and impartiality,
Interpretation of the standard:
The internal auditor may encounter conflicts of interest while performing professional duties. Such conflicts of interest make it difficult for the internal auditor to perform their tasks. Conflicts of interest exist even if they do not cause serious consequences regarding ethics or professional activities. Conflicts of interest can lead to misrepresentation of practices, thereby reducing confidence in the internal auditor, the internal audit department, and the internal audit profession. Conflicts of interest also reduce the ability of the internal auditor to perform their duties and responsibilities objectively.
1130 - Diminishment of independence or objectivity
If the independence or objectivity is diminished in substance or appearance, such diminishment must be explained to appropriate levels. The content presented will depend on the situation and nature of the diminishment.
Interpretation of the standard:
The diminishment of organizational independence and the objectivity of the internal auditor may include but are not limited to personal conflicts of interest; audit scope; restricted access to information, personnel, assets, and resources (such as the budget allocated for internal audit).
Determining the appropriate levels to explain about the diminishment of independence or objectivity depends on the expectations of responsibility of the internal audit department and the head of internal audit towards senior management and the highest level of management as stipulated in the internal audit charter, as well as depending on the nature and content of the diminishment.
1130.A1 - The internal auditor must avoid participating in evaluating activities that they have previously been involved in and responsible for. Impartiality is considered diminished if the internal auditor performs assurance activities for an activity they were involved in or responsible for within three years from the decision not to perform the activity or manage the department.
1130.A2 - Assurance activities with audit subjects under the responsibility of the head of internal audit must be subject to supervision by an independent department from the internal audit department for those assurance activities.
1130.A3 - The internal audit department may perform assurance activities for the department they previously advised if the nature of the advisory activity does not diminish impartiality and individual impartiality is maintained when allocating resources for assurance activities.
1130.C1 - The internal auditor may perform advisory activities related to previous activities under their responsibility.
1130.C2 - If there are risks of diminishing the independence or objectivity of the internal auditor related to advisory activities, the internal auditor must present to the client before accepting the work.
1200 - Professional competence and due diligence
Internal audit must be performed with professional competence at a proficient level and the necessary professional due diligence.
1210 - Professional competence
Those performing internal audit tasks must have the necessary knowledge, skills, and other professional competencies to fulfill their responsibilities. The internal audit department must have or acquire the necessary knowledge, skills, and other professional competencies to fulfill the responsibilities of the internal audit department.
Interpretation of the standard:
Professional competence is a general term referring to the knowledge, skills, and other professional competencies necessary for an internal auditor to effectively perform their professional responsibilities. Professional competence also includes considering current activities, trends, and timely issues to provide relevant advice and recommendations. Internal auditors are encouraged to demonstrate their professional competence through obtaining relevant certifications and degrees in internal auditing.
1210.A1 - The head of internal audit must seek appropriate professional advice and assistance if the internal audit team lacks sufficient knowledge, skills, and other professional competencies required to carry out all or part of the internal audit work.
1210.A2 - Although it is not expected that the head of internal audit will have the specialized knowledge of a fraud investigator, the head of internal audit must have sufficient knowledge to assess fraud risks and organizational risk management techniques.
1210.A3 - Internal auditors need to have sufficient knowledge about key risks and controls related to information technology, as well as IT-based audit techniques to perform their assigned tasks. However, not all internal auditors are expected to have the specialization of an IT-focused internal auditor.
1210.C1 - If internal auditors lack sufficient knowledge, skills, and other professional competencies to perform all or part of advisory duties, the head of internal audit must either decline the assignment or seek necessary assistance or advice.
1220 - Professional Care
Internal auditors must apply the level of care and necessary professional skills of a competent and prudent internal auditor reasonably. However, professional care does not imply the absence of errors.
1220.A1 - Internal auditors must demonstrate professional care by considering:
The scope of work necessary to achieve the objectives of assurance activities.
The complexity, materiality, or significant issues to which audit procedures are applied.
The adequacy and effectiveness of governance, risk management, and control processes.
The likelihood of errors, fraud, and significant non-compliance issues.
The relationship between costs and potential benefits of assurance activities.
1220.A2 - In demonstrating professional care, internal auditors must consider applying data analysis techniques as well as IT-based audit techniques.
1220.A3 - Internal auditors must always focus on significant risks that could affect organizational goals, activities, and resources. However, even if audit procedures are performed with appropriate professional care, it cannot guarantee that all significant risks will be detected.
1220.C1 - For advisory activities, internal auditors must demonstrate professional care by considering:
The necessity and expectations of the entity being advised, including the content, timing, and reporting of advisory activity results.
The complexity involved and the extent of work needed to achieve the objectives of advisory activities.
The relationship between costs and potential benefits of advisory activities.
1230 - Updating Knowledge
Internal auditors must enhance their knowledge, skills, and other professional competencies through continuous professional development.
1300 - Quality Assurance and Improvement Program
The head of internal audit must establish and maintain a quality assurance and improvement program for all aspects of the internal audit function.
Interpretation of the standard:
A quality assurance and improvement program is designed to evaluate the internal audit function's compliance with internal audit standards and assess how internal auditors apply the principles of internal audit ethics. The program also evaluates the effectiveness and performance of the internal audit function and identifies opportunities for improvement. The head of internal audit should recommend that senior management oversee the quality assurance and improvement program.
1310 - Requirements of the Quality Assurance and Improvement Program
The quality assurance and improvement program should include both internal reviews and independent reviews.
1311 - Internal Reviews
Internal reviews must include:
Continuous monitoring of the internal audit department's performance.
Periodic reviews conducted by the internal audit department itself.
Interpretation of the standard:
Continuous monitoring activities are an integral part of the daily supervision, review, and evaluation activities of the internal audit department. These activities are integrated into ongoing policies and guidelines used to manage the internal audit department. Monitoring uses necessary processes, tools, and information to assess compliance with internal audit standards and professional ethics principles.
Periodic reviews are carried out to evaluate compliance with internal audit standards and professional ethics principles.
Professional knowledge of internal auditing requires at least an understanding of all aspects of internal audit standards.
1312 - Independent Reviews
Independent reviews can be conducted by an independent specialist or a group of specialists from outside the entity at least once every five (05) years. The head of the internal audit department must discuss with the highest management level about:
The form and frequency of independent reviews.
Credentials, expertise, skills, as well as independence of the independent reviewer or group of reviewers, including potential conflicts of interest.
Interpretation of Standards
Independent reviews can be achieved through a comprehensive review conducted by an independent reviewer or self-assessment by the entity confirmed by an independent reviewer.
An independent reviewer or group of reviewers demonstrates professional competence in two areas: professional practice of internal auditing and independent review process. Professional competence can be demonstrated through a combination of practical experience and theoretical expertise. Practical experience from entities of similar size, complexity, industry, or field, as well as relevant technical issues, will add more value to the independent review process. In the case of a group of independent reviewers, it is not necessary for each individual to possess all required competencies, but overall professional competence is assessed for the group. The head of the internal audit department uses professional judgment to determine whether the independent reviewer or group of reviewers can demonstrate the necessary professional competencies.
Independent reviewers or groups of reviewers are individuals who have no conflict of interest and are neither employees nor under the control of the entity whose internal audit activities need to be reviewed. The head of the internal audit department should propose that the highest management level oversee the independent review to reduce existing or potential conflicts of interest.
1320 - Reporting on the Quality Assurance and Improvement Program
The head of the internal audit department must report the results of the quality assurance and improvement program for internal auditing to the highest executive board and management level of the entity. The report should include:
Scope and frequency of internal review reports and independent review reports.
Expertise and independence of the independent reviewer or group of reviewers, including potential conflicts of interest.
Conclusions of the independent reviewer.
Remedial actions.
Interpretation of the standard:
The form, content, and frequency of reporting the results of the quality assurance and improvement program for internal auditing are determined through discussions and consultations with the highest executive board and management level, taking into account the responsibilities of the internal audit department and the head of the internal audit department as stipulated in the internal audit charter. To ensure compliance with standards and professional ethics principles of internal auditing, the results of independent reviews and periodic internal reviews are reported immediately upon completion of the reviews, and the results of continuous monitoring activities are reported at least once a year. The results include the assessment by the reviewer or group of reviewers regarding the degree of compliance of internal audit activities.
STANDARDS FOR ACTIVITIES
2000 - Management of Internal Audit Activities
The head of the internal audit department must effectively manage internal audit activities to ensure added value for the entity.
Interpretation of the standard:
Internal audit activities are managed effectively when:
Achieving objectives and fulfilling responsibilities set forth in the internal audit charter.
Complying with internal audit standards.
Internal auditors comply with standards and professional ethics principles.
Considering trends and current issues that may affect the entity.
Internal audit activities add value to the entity and related parties when considering strategy, objectives, and risks; Efforts are made to improve governance processes, risk management processes, and internal control processes, and provide appropriate assurances objectively.
2010 - Planning
The head of the internal audit department must establish an internal audit plan based on a risk-oriented approach to determine the priority of internal audit activities, consistent with the entity's objectives.
Interpretation of the standard:
To develop a risk-oriented internal audit plan, the head of the internal audit department consults with the highest executive board and management level and understands the entity's strategy, objectives, risks, and risk management processes. The head of the internal audit department must review and adjust the plan, if necessary, to ensure alignment with changes in the entity's business aspects, risks, operations, programs, systems, and internal controls.
2010.A1 - The internal audit plan must be developed based on documented risk assessments and conducted at least once a year. The opinions of the senior management and highest governing body must be considered in this process.
2010.A2 - The head of internal audit must be aware of and consider the expectations of senior management, the highest governing body, and other interested parties when issuing internal audit opinions and other conclusions.
2010.C1 - The head of internal audit should consider accepting advisory engagements based on the potential for such advisory activities to improve risk management, add value, and enhance unit operations. The internal audit plan must include accepted advisory activities.
2020 - Reporting and Approval
The head of internal audit must report the internal audit plans and resource requirements, including significant changes during the period, to senior management and the highest governing body for review and approval. The head of internal audit also must report the impact of resource limitations.
2030 - Resource Management
The head of internal audit must ensure that the resources of internal audit are appropriate, adequate, and used efficiently to accomplish approved plans.
Interpretation of the standard:
Appropriateness refers to the combination of knowledge, skills, and other professional capabilities necessary to carry out the plan. Adequacy refers to the quantity of resources needed to execute the plan. Resources are used efficiently when they are utilized in a manner that enables internal audit to complete the approved plan optimally.
2040 - Policies and Procedures
The head of internal audit must establish policies and procedures to guide the internal audit function.
Interpretation of the standard:
The form and content of internal audit policies and procedures depend on the size and organizational structure of the internal audit function as well as the complexity of its work.
2050 - Coordination Work and Reliability
The head of internal audit of the entity should share information, coordinate activities, and consider using the results of consulting and assurance providers both within and outside the entity to ensure full implementation of activities and minimize duplication.
Interpretation of the standard:
The head of internal audit may rely on the results of other parties providing consulting and assurance services while coordinating activities. A consistent process for determining reliability should be established, and the head of internal audit should consider the professional capability, objectivity, and due professional care of consulting and assurance service providers. The head of internal audit should also understand the scope, objectives, and outcomes of other parties providing consulting and assurance services. When using the results of other parties, the head of internal audit remains responsible for ensuring adequate support for the conclusions and opinions of the internal audit function.
2060 - Reporting to Senior Management and the Highest Governing Body
Periodically, the head of internal audit must report to senior management and/or the highest governing body regarding the purpose, authority, responsibilities, and implementation status related to the internal audit function's plan, as well as compliance with internal audit standards and internal audit professional ethics principles. These reports must include significant risks, control issues, fraud risks, governance issues, and other matters requiring attention from senior management and/or the highest governing body.
Interpretation of the standard:
The head of internal audit, the entity’s senior management, and the highest governing body jointly determine the frequency and content of reporting. The frequency and content of reporting depend on the importance of the information to be exchanged and the urgency of actions required by senior management and the highest governing body.
The head of internal audit must report and communicate with the entity’s senior management and the highest governing body on the following items:
Internal audit charter.
Independence of the internal audit function.
Internal audit plan and progress against the plan.
Resource requirements.
Results of internal audit activities.
Compliance with internal audit standards and professional ethics principles and action plans to address significant compliance issues.
Management responses to risks that may not be acceptable to the entity according to the judgment of the head of internal audit.
These requirements and other reporting requirements of the head of internal audit are referenced throughout the internal audit standards.
2070 - External Service Providers and Entity Responsibility for Internal Audit
In the case of outsourcing internal audit activities, external service providers must inform the entity about the entity's responsibility to maintain effective internal audit operations.
Interpretation of the standard:
This responsibility is demonstrated through a quality assurance and improvement program that evaluates compliance with internal audit standards and professional ethics principles.
2100 - Nature of Internal Audit Activities
Internal audit activities must assess and contribute to improving governance processes, risk management processes, and control processes through a systematic approach with rigorous principles and a risk-oriented perspective. The credibility and value of internal audit are enhanced when internal auditors are proactive and their assessments reveal new, deep insights and consider future impacts.
2110 - Governance
Internal audit activities must evaluate and make appropriate recommendations to improve governance processes for the following issues:
Issuing strategic decisions and operations.
Supervising risk management and internal control.
Strengthening appropriate values and ethics within the unit.
Ensuring effective organizational management and accountability in the implementation of unit activities.
Reporting on risks and controls to relevant departments within the unit.
Coordinating activities and exchanging information between the highest level of management, independent auditors, internal auditors, other service assurance providers, and management levels.
2110.A1 - Internal audit activities must assess the design, implementation, and effectiveness of activities, programs, and objectives related to the unit's ethics.
2110.A2 - Internal audit activities must assess whether the information technology governance supports the unit's strategies and objectives.
2120 - Risk Management
Internal audit activities must evaluate and contribute to improving the effectiveness of the unit's risk management processes.
Interpretation of the standard:
Determining whether the risk management process is effective is a judgment drawn from the internal auditor's assessment of whether:
The unit's objectives support and align with the unit's mission.
Significant risks are identified and assessed.
Appropriate risk responses are selected and aligned with the unit's risk assessment level.
Relevant risk information is captured and communicated promptly throughout the unit to enable individuals, departments, management levels, and the highest level of management to fulfill their responsibilities.
Internal audit activities can collect information for this evaluation through various assurance and advisory activities. Understanding the unit's risk management processes and their effectiveness can be gained by considering the results of these assurance and advisory activities as a whole.
Risk management processes are monitored through regular management activities as well as separate evaluations or both.
2120.A1 - Internal audit activities must assess risks that impact the following aspects of the governance system, operational system, and information system of the unit:
Achieving the unit's strategic objectives.
Reliability and transparency of financial and operational information.
Efficiency and performance of activities and programs.
Asset protection management.
Compliance with laws, regulations, policies, procedures, and contracts.
2120.A2 - Internal audit activities must assess potential fraud occurrences and evaluate how the unit manages fraud risks.
2120.C1 - In advisory activities, internal auditors must consider risks consistent with advisory activity objectives and always be aware of significant other risks.
2120.C2 - Internal auditors must integrate knowledge of risks obtained from different advisory activities to evaluate the unit's risk management processes.
2120.C3 - When supporting management in establishing and improving risk management processes, internal auditors must avoid assuming any management responsibility in risk management activities.
2130 - Control
Internal audit activities must assist the unit in maintaining effective controls by evaluating the effectiveness and performance of controls and recommending continuous improvements.
2130.A1 - Internal audit activities must assess the adequacy and effectiveness of controls established for risks in the governance system, operational system, and information system of the unit relating to:
Achieving the unit's strategic objectives.
Reliability and transparency of financial and operational information.
Efficiency and performance of activities and programs.
Asset protection management.
Compliance with laws, regulations, policies, procedures, and contracts.
2130.C1 - Internal auditors must integrate knowledge of controls obtained from different advisory activities to evaluate the unit's control processes.
2200 - Planning Assurance or Advisory Activities
Internal auditors must prepare and document plans for each assurance or advisory activity including objectives, scope, duration of the assurance or advisory activity, and resource allocation. The plan must consider the unit's strategy, objectives, and risks related to the assurance or advisory activity.
2201 - Considerations when planning
When planning, internal auditors must consider the following issues:
Reviewing the strategy and objectives of the subject and tools for controlling the implementation of the subject's activities.
Reviewing significant risks to the subject's objectives, resources, and activities, as well as tools used to control the potentially acceptable impact of those risks.
Reviewing the accuracy and effectiveness of the subject's governance, risk management, and internal control processes compared to relevant frameworks or models.
Opportunities for significant improvements in the subject's governance, risk management, and internal control processes.
2201.C1 - Internal auditors confirm their understanding with the subjects requiring advice about the purpose, scope, responsibilities of each party, and other expectations of the unit. For large advisory contracts, this must be documented in writing.
2210 - Objectives of Assurance and Advisory Activities
Objectives must be set for each assurance or advisory activity.
2210.A1 - Internal auditors must conduct preliminary assessments of risks related to the audit subject. Audit objectives must reflect the results of this preliminary assessment.
2210.A2 - Internal auditors must consider the likelihood of significant errors, fraud, non-compliance issues, and other significant risks while establishing audit objectives.
2210.A3 - There must be appropriate criteria to evaluate internal controls, risk management, and governance. Internal auditors must ensure the appropriateness of the criteria established by management levels to determine whether the goals and purposes have been achieved. If deemed appropriate, internal auditors must use these criteria for evaluation. If deemed inappropriate, internal auditors must discuss with management levels and/or the highest governing body to develop suitable evaluation criteria.
Interpretation of the standard:
Types of criteria may include:
Internal (such as unit processes and policies).
External (such as laws and regulations issued by competent authorities).
Practices (such as professional and industry guidelines).
2210.C1 - Advisory objectives must focus on governance processes, risk management processes, and control processes at a level previously agreed upon with the entity requiring advisory services.
2210.C2 - Advisory objectives must align with the values, strategies, and goals of the entity requiring advisory services.
Scope of Work
The scope of work for each assurance activity and advisory activity must be sufficient to achieve the set objectives.
2220.A1 - The scope of work must include reviewing systems, records, personnel, and related tangible assets, including those under third-party control.
2220.A2 - During the implementation of an assurance activity, if advisory activities arise, the objectives, scope, responsibilities of each party, as well as other expectations should be agreed upon in writing, and the results of advisory activities should be exchanged according to relevant advisory standards.
2220.C1 - When conducting advisory activities, internal auditors must ensure that the scope of work is adequately defined to achieve agreed-upon objectives. If during the execution of the work, internal auditors identify limitations within the advisory scope, they must discuss these limitations with the entity requiring advisory services to decide whether to continue the assignment.
2220.C2 - During the execution of advisory activities, internal auditors must review controls consistent with the objectives of the advisory activity and must always pay attention to significant control issues.
2230 - Allocation of Resources
Internal auditors must determine the necessary and appropriate resources to achieve set objectives based on an assessment of the nature and complexity of each assurance activity or advisory activity, as well as time and resource constraints.
Interpretation of the standard:
Appropriateness refers to the combination of knowledge, skills, and other professional competencies needed to perform internal audit work. Sufficiency pertains to the quantity of resources required to perform internal audit work with the necessary professional care.
2240 - Audit Program
Internal auditors must establish and document audit programs to achieve the objectives of each assurance activity or advisory activity.
2240.A1 - Audit programs must include procedures for identifying, analyzing, evaluating, and documenting information during the performance of assurance activities. These programs must be approved before implementation and immediately upon any modification.
2240.C1 - The implementation program for advisory activities may differ in form and content depending on the nature of the advisory activity.
2300 - Conducting Internal Audits
Internal auditors must identify, analyze, evaluate, and document comprehensive information to achieve set objectives.
2310 - Identifying Information
Internal auditors are required to identify complete, reliable, relevant, and useful information for achieving the objectives of assurance or advisory activities.
Interpretation of the standard:
Complete information reflects reality, accuracy, and persuasiveness such that a prudent person, if provided with complete information, could draw similar conclusions as an internal auditor. Reliable information is the best information that can be collected through appropriate techniques in assurance or advisory activities. Relevant information supports findings and recommendations of internal auditors and is consistent with the objectives of assurance or advisory activities. Useful information will help the organization achieve its goals.
2320 - Analyzing and Evaluating Information
Internal auditors must draw conclusions and results of assurance or advisory activities based on appropriate analysis and evaluation.
2330 - Recording Information
Internal auditors must record complete, reliable
2330.A1 - The head of internal auditing must control access to audit files. The head of internal auditing must obtain approval from the high-level management board of the entity and/or the legal department, if applicable, before providing information in audit files to external parties.
2330.A2 - The head of internal auditing must establish retention requirements for audit files, regardless of the storage format. These retention requirements must be consistent with the entity's guidelines as well as legal and regulatory retention requirements.
2330.C1 - The head of internal auditing must establish policies for the preservation and retention of advisory files and the provision of information to interested parties both inside and outside the entity. These policies must be consistent with the entity's guidelines as well as legal and regulatory retention requirements.
2340 - Monitoring Implementation
Internal assurance activities and advisory activities must be appropriately monitored to ensure that the set objectives, quality requirements, and human resource development are achieved.
Interpretation of the standard:
The level of monitoring required depends on the internal auditor's professional expertise and experience, as well as the complexity of the assurance activity or advisory activity. The head of internal audit is responsible for overseeing internal assurance activities or advisory activities, regardless of whether they are performed by the internal audit department, but may delegate this responsibility to experienced internal auditors to conduct reviews. Evidence of monitoring must be retained and recorded.
2400 - Report on the Results of Internal Audit
Internal auditors must report on the results of assurance activities and advisory activities.
2410 - Reporting Criteria
Reports must include the objectives, scope of work, and conclusions.
2410.A1 - Final audit reports must include appropriate conclusions, recommendations, and action plans. When necessary, audit opinions should be provided. Internal audit opinions must consider the expectations of senior management, the highest level of governance, and interested parties, and must be based on complete, reliable, reasonable, and useful information.
Interpretation of the standard:
Opinions at the assurance activity level may be rankings, conclusions, or other descriptions of audit results. Such assurance activities may relate to internal controls over a process, a risk, or a specific unit. Formulating these opinions requires considering the audit results and their significant impact.
2410.A2 - Encourage internal auditors to confirm full implementation in audit reports.
2410.A3 - In cases where audit results are provided externally, the report must include limitations on the recipients and users of the report.
2410.C1 - Reporting and updating progress and results of advisory services can vary in form and content depending on the nature of the advisory task and the requirements of the advisory recipient.
2420 - Quality of Reports
Internal audit reports must be accurate, objective, clear, concise,
Interpretation of the standard:
An accurate report has no errors or omissions and truthfully reflects the core facts. An objective report demonstrates fairness, impartiality, and lack of bias, resulting from an unbiased assessment based on relevant situations and appropriate information. A clear report presents content in a comprehensible and logical manner, avoiding unnecessary technical terms while providing all relevant and important information. A concise report addresses the issue directly, succinctly, and avoids unnecessary verbosity. A constructive report is beneficial to the audit subject and the organization, and provides necessary improvements. A comprehensive report includes all content considered important to the recipient and encompasses all findings, important and relevant information serving as the basis for recommendations and internal audit conclusions. A timely report is delivered at the right moment and is appropriate, depending on the significance of the reported issue, allowing management to take appropriate corrective actions.
2421 - Errors and Omissions
If the final official report contains significant errors or omissions, the head of internal audit must communicate corrected information to all previous recipients of the report.
2430 - Use of the Phrase "Compliance with Vietnamese Internal Audit Standards"
Assurance activities and advisory activities must comply with Vietnamese Internal Audit Standards.
2431 - Presenting Non-Compliance Issues
When non-compliance with internal audit standards and internal audit ethical principles affects an assurance activity or advisory activity, the internal audit report must present:
Which standard or principle in the internal audit standards or internal audit ethical principles was not followed;
The reasons for non-compliance;
The impact of non-compliance on the assurance activity, advisory activity, and the internal audit report results.
2440 - Issuance and Distribution of Reports
The head of internal audit must report the results of internal audit to appropriate parties.
Interpretation of the standard:
The head of internal audit is responsible for reviewing and approving the final official report before issuance and determining the method of distribution and recipients of the report. The head of internal audit remains ultimately responsible even if delegating this responsibility to another person.
2440.A1 - The head of internal audit is responsible for communicating and reporting the final results of assurance activities to relevant parties to ensure that these results are carefully considered.
2440.A2 - Unless there are legal regulations or directives from competent authorities, before providing assurance results externally, the head of internal audit must:
Assess potential risks to the organization arising from external provision of results;
Consult with senior management of the organization and/or legal counsel if appropriate;
Control the issuance and distribution of reports through limiting the use of audit results.
2440.C1 - The head of internal audit is responsible for reporting the final advisory results to the advisory recipient.
2440.C2 - In cases where governance, risk management, and control issues are identified during the advisory process, internal auditors must communicate and report to senior management of the organization and the highest level of governance if these issues are significant to the organization.
2450 - Overall Opinion
In the case of issuing an overall opinion, this opinion must consider the strategy, objectives, risks of the entity; the expectations of the entity's senior management, highest level of governance, and other interested parties. The overall opinion issued must be based on complete, reliable, relevant, and useful information.
Interpretation of the standard:
The overall opinion will include:
The scope of work, including the time frame to which the opinion refers.
Any limitations or restrictions on the scope of work.
Consideration of all related projects, including the use of work provided by others for assurance activities.
A summary of the information serving as the basis for the internal audit opinion.
The control framework, risk criteria, or other standards used as the basis for the overall opinion.
The overall opinion, judgment, or conclusion.
The reasons for a negative aspect of an overall opinion must be clearly stated in the report.
2500 - Monitoring the Implementation of Audit Recommendations
The head of the internal audit function must establish and maintain a system to monitor the implementation of audit recommendations reported to the entity's senior management.
2500.A1 - The head of the internal audit function must establish a tracking process to monitor and ensure that the entity's management implements audit recommendations effectively, as well as the acceptance of risks by the entity's senior management for not implementing audit recommendations.
2500.C1 - Internal audit activities must monitor the results of implementing the recommendations from advisory engagements within the agreed scope with the auditee.
2600 - Communication on Risk Acceptance
If the head of the internal audit function concludes that the entity's management has accepted a level of risk that may not be acceptable for the entity, the head of the internal audit function must report this issue to the entity's senior management. If the issue remains unresolved, the head of the internal audit function must report it to the highest level of governance.
Interpretation of the standard:
The identification of risks accepted by senior management can be seen through an assurance activity, advisory engagement, monitoring the results of implementing previous audit recommendations by management, or through other measures. Handling such risks does not fall under the responsibility of the head of the internal audit function.
Appendix II
PROFESSIONAL ETHICAL PRINCIPLES
INTERNAL AUDIT
(Issued together with Circular No. 8/2021/TT-BTC dated January 25, 2021 of the Minister of Finance)
1. Internal auditors are expected to apply and uphold the following ethical principles:
a) Integrity
The integrity of internal auditors establishes trust and forms the basis for the reliability of their judgments.
Internal auditors must perform their professional duties with honesty, diligence, and accountability; comply with laws and regulations, and disclose necessary information as required by law and internal audit professional requirements; refrain from illegal activities or engaging in activities that harm the reputation of the profession or the entity.
b) Objectivity
Internal auditors must ensure objectivity, accuracy, honesty, and fairness in performing internal audit tasks. Internal auditors demonstrate the highest level of professional objectivity in collecting, evaluating, and communicating information about reviewed activities and processes. Internal auditors provide objective assessments of all appropriate situations and are not influenced by personal interests or those of others in making judgments and conclusions.
c) Confidentiality
Internal auditors respect the values and rights of information provided and do not disclose such information without authorization from competent authorities unless disclosure is part of their professional responsibility or required by law.
d) Professional Competence and Due Care
Internal auditors apply knowledge, skills, and experience in providing services and internal audit activities. They act prudently in accordance with professional standards and techniques.
d) Professional Behavior
Internal auditors must comply with laws and relevant regulations, avoiding any actions that diminish the reputation of their profession.
2. The head of the internal audit function, in addition to ensuring compliance with the professional ethical principles set out in Clause 1 of Appendix II - Part on Professional Ethical Principles of Internal Auditing, must implement measures to monitor, evaluate, and manage to ensure that internal auditors adhere to the professional ethical principles of internal auditing.
PRACTICE REQUIREMENTS
1. Integrity
Internal auditors need to:
1.1. Perform professional duties with honesty, diligence, and accountability.
1.2. Comply with laws and regulations, and disclose necessary information as required by law and internal audit professional requirements.
1.3. Refrain from illegal activities or activities that damage the reputation of the internal auditing profession or the entity/organization.
1.4. Respect and contribute to legitimate and moral purposes of the entity/organization.
2. Objectivity
Internal auditors:
2.1. Do not engage in activities or relationships that could impair or appear to impair the objectivity of internal auditors' judgments. This includes activities and relationships that may create conflicts of interest with the audited entity/organization.
2.2. Do not accept anything that could impair or appear to impair the professional judgment of internal auditors.
2.3. Present all significant information collected by internal auditors. This is information that, if not presented, could negatively impact the reporting of audit activities.
3. Confidentiality
Internal auditors need to:
3.1. Exercise caution in using and protecting information collected during the audit process.
3.2. Not use provided information for personal purposes or in any form contrary to the law or inconsistent with legitimate and ethical objectives of the entity/organization.
4. Professional competence and due care
Internal auditors:
4.1. Participate in activities or provide internal audit services only when possessing the necessary expertise, skills, and experience.
4.2. Perform internal audit services/work in accordance with Vietnamese internal audit standards.
4.3. Continuously improve professional skills, efficiency, and quality of internal audit services/activities.
4.4. Act with due care, consistent with applicable professional standards and techniques.
5. Professional conduct
Internal auditors must:
5.1. Comply with laws and relevant regulations.
5.2. Avoid any action that diminishes the reputation of their profession.
Văn bản gốc (PDF)
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.