Standards interpretation

Record integrity in relation to internal audit

Standards Interpretation

This interpretation addresses record integrity in relation to internal audit: applicability, materiality, decision records and corrective-action verification.

Scope and application of record integrity in relation to internal audit

In the context of internal audit, responsibility should be identifiable at the point where consequential decisions are made.

For the control, a reliable record should identify what occurred, when it occurred, who was responsible, the authority for the action and any later correction. For internal audit, records should remain protected against unauthorised alteration while legitimate amendments remain visible.

Relevant evidence for record integrity in relation to internal audit will normally include role-based access and access reviews, lawful authority and consent records where relevant, retention and secure disposal evidence, a register of information assets and purposes, and supplier and transfer arrangements. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. Across the defined scope, an unresolved contradiction is a limitation on the conclusion and should be reported as such.

Application to record integrity in relation to internal audit

In examining record integrity in relation to internal audit, for the control, education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period.

Failure in relation to the applicable expectation may arise even where the stated policy is reasonable. Material concerns include uncontrolled supplier access or transfer, excessive access to learner information, collection without a defined educational or legal purpose, and secondary use without adequate authority.

  • Control third-party processing.
  • Test incident and recovery arrangements.
  • Assign accountable data owners.
  • Minimise collection.
  • Verify accuracy where information affects learners.

Controls for record integrity in relation to internal audit

Review of the control should specify mandatory fields, source ownership, access rights, retention and correction procedures. Test a sample from creation through use, amendment, reporting and disposal, including records created during disruption or by a delivery partner.

In the context of internal audit, the final record on the applicable requirement should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion.

Interpretation of the applicable expectation should avoid two errors: treating a formal commitment as proof of effect, and treating one adverse case as proof that every part of the system has failed. For the matter, security, privacy and data quality are related but distinct. When examining internal audit, a secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. For the conclusion, interpretive guidance should not create an obligation that is absent from the governing instrument or applicable law.

For decisions concerning internal audit, decisions concerning the control should remain traceable to the information available for the stated reference period.

Review of record integrity in relation to internal audit

In examining record integrity in relation to internal audit, across the defined scope, material revisions should be traceable to their reason and effective date.

The objective for internal audit should be explicit, the evidence proportionate and learner impact visible. Where evidence concerning internal audit cannot support assurance, the limitation should be reported and corrective work should remain open.