3.7 Proficiency and Due Professional Care

Key Takeaways

  • Proficiency can be met collectively: when a competency is missing, the CAE obtains or procures it (expert, co-source, training) rather than proceeding unqualified.
  • Auditors need enough knowledge to evaluate fraud and IT risk, but are not expected to be fraud investigators or IT specialists.
  • Due professional care means the skill and caution of a reasonably prudent auditor — it is NOT a guarantee of infallibility or 100% fraud detection.
  • Exercising due care weighs work extent, complexity/materiality, control adequacy, probability of error/fraud, cost-benefit, and use of data analytics.
  • Proficiency is sustained through continuing professional development (CPE); the CIA is the benchmark credential and requires ongoing CPE to stay active.
Last updated: June 2026

Proficiency: A Function-Level and Individual-Level Duty

Proficiency means internal auditors possess or obtain the knowledge, skills, and competencies needed to perform their responsibilities. The exam stresses one subtlety: proficiency can be satisfied at the collective (function) level — the audit activity as a whole must be proficient, even if no single auditor knows everything.

If a needed competency is missing...Acceptable responses
For the whole engagementDecline, or obtain competent advice/assistance (use a subject-matter expert)
For one auditorAssign the work to a proficient colleague, or supplement with training/supervision
For a specialized area (e.g., data analytics, fraud, IT, actuarial)Procure the skill via an external service provider or co-sourcing

Under the 2025 Standards, the CAE must ensure the function collectively possesses or obtains the competencies to fulfill its mandate. A worked rule: if internal audit is asked to audit a complex derivatives portfolio and no one has the expertise, the CAE does not simply proceed and disclaim — the CAE obtains competent advice and assistance (hires or co-sources an expert). "Decline the engagement" is only correct when competent help cannot be obtained at all.

Required Knowledge, Skills, and the CIA Itself

Proficiency requires both technical and behavioral (soft) skills:

  • Technical: the Standards and IPPF, risk and control frameworks (e.g., COSO), data analytics, IT general controls, fraud indicators, and the relevant business/industry knowledge.
  • Behavioral: communication, critical thinking, persuasion and negotiation, conflict management, and collaboration.

Key memorize-this points:

  • Auditors must have sufficient knowledge to evaluate the risk of fraud and how it is managed — but they are not expected to have the expertise of a person whose primary responsibility is detecting and investigating fraud.
  • Auditors should understand key IT risks and controls and available technology-based audit techniques, again without being IT specialists.
  • The CIA designation is the benchmark professional credential, and proficiency is sustained through continuing professional development (CPD/CPE) — for the CIA, ongoing CPE hours are required to keep the credential active.

The "reasonable competent auditor" standard governs: an auditor must know what a prudent, competent internal auditor would know for that assignment, not what a topic specialist would know.

Due Professional Care: Skill and Caution, Not Infallibility

Due professional care is the care and skill expected of a reasonably prudent and competent internal auditor. The single most tested idea: due professional care does NOT mean infallibility — it does not guarantee that all risks or all fraud will be detected, and it does not require examining every transaction. It requires reasonable care, not perfect results.

In exercising due professional care, the auditor weighs:

  • The extent of work needed to achieve engagement objectives.
  • The relative complexity, materiality, or significance of matters.
  • The adequacy and effectiveness of governance, risk management, and control processes.
  • The probability of significant errors, fraud, or noncompliance.
  • The cost of assurance relative to potential benefits (cost-benefit).
  • Use of technology-based audit techniques and data analysis where appropriate.

Professional skepticism

Due care includes professional skepticism — a questioning mind and critical assessment of evidence, neither assuming management is dishonest nor assuming unquestioned honesty.

Worked decision

An auditor performs a competent, properly scoped audit using sampling and reasonable procedures, yet a sophisticated, well-concealed fraud is later discovered in an untested transaction.

Has the auditor breached due professional care? No — due care is about reasonable skill and caution, not detecting every concealed fraud. Sampling is acceptable; the auditor exercised the alertness a prudent auditor would. The breach would only arise if the auditor ignored obvious red flags a reasonably prudent auditor would have investigated. That distinction — reasonable alertness vs. guaranteed detection — is the exam's favorite trap in this domain.

Continuing Professional Development and Specialist Help

Proficiency is not a one-time state; auditors must maintain it through continuing professional development (CPD/CPE). For the CIA designation, holders must report ongoing CPE hours each reporting period to keep the credential active (practicing CIAs carry a higher annual requirement than non-practicing holders). Letting CPE lapse moves a CIA to inactive status — a frequently tested consequence. Beyond formal credits, development includes on-the-job training, professional reading, conferences, and rotational assignments.

Using subject-matter experts without losing ownership

When the function procures specialist help — IT, forensic, actuarial, valuation — the CAE must still evaluate the expert's competence, independence, and objectivity and ensure the work meets the engagement's objectives. The internal audit function retains responsibility for the conclusions even when relying on an external specialist; it cannot simply pass through the expert's opinion unexamined.

Technology and data analytics as a proficiency expectation

The current Standards explicitly expect auditors to consider technology-based audit techniques and data analytics. Proficiency now includes knowing when analytics, continuous auditing, or full-population testing would be more effective than manual sampling — and having access to those skills in the function.

Decision summary for this domain

SituationCorrect response
Auditor lacks a needed skill for one taskReassign to a proficient colleague or supervise/train
Function lacks a competency entirelyObtain/procure it (expert, co-source); decline only if unobtainable
Concealed fraud missed despite a competent auditNo due-care breach — care is reasonableness, not infallibility
Obvious red flag ignoredDue-care breach — a prudent auditor would have followed up
CIA's CPE not reportedCredential becomes inactive

One last distinction the exam loves

Proficiency answers "do we have the skill?"; due professional care answers "did we apply reasonable skill and caution on this engagement?" A team can be fully proficient yet still breach due care by rushing an engagement, skipping obvious follow-up, or ignoring a red flag. Conversely, a careful auditor who simply lacks a specialized skill has a proficiency gap, not a due-care failure. When a stem hinges on a missing competency, think proficiency; when it hinges on sloppy or careless execution despite having the skill, think due professional care.

Test Your Knowledge

Internal audit is asked to audit a highly technical cybersecurity area in which no current staff member is proficient. Under the proficiency requirement, the CAE should FIRST:

A
B
C
D
Test Your Knowledge

An auditor conducts a properly planned, competently executed audit using sampling, yet a cleverly concealed fraud in an untested transaction surfaces months later. Regarding due professional care, this means:

A
B
C
D