8.2 Partnering with Executive Management & Second-Line Functions

Key Takeaways

  • Internal audit must establish collaborative partnerships with C-suite executives and second-line functions while maintaining uncompromising objectivity and operational independence.
  • Under the IIA Three Lines Model, internal audit (third line) provides independent assurance over both first-line operations and second-line specialized oversight functions (ERM, Compliance, Legal, InfoSec).
  • Collaboration includes sharing risk taxonomies, continuous monitoring data, and creating combined assurance maps to eliminate redundant testing and audit fatigue.
  • Internal auditors may participate on management steering committees strictly as non-voting advisors or observers; holding voting rights or approving management decisions destroys audit objectivity.
  • If management accepts a level of residual risk that the CAE believes exceeds organizational risk appetite, the CAE must discuss the issue with senior management and, if unresolved, escalate directly to the board under GIAS Standard 11.3 and 15.2.
Last updated: September 2026

8.2 Partnering with Executive Management & Second-Line Functions

[!IMPORTANT] The Collaboration and Objectivity Balance: While the Chief Audit Executive reports functionally to the board, the internal audit activity operates daily within the executive ecosystem. To deliver tangible value, internal audit must establish collaborative partnerships with executive leadership (CEO, CFO, COO, CIO, CISO) and second-line functions (Enterprise Risk Management, Compliance, Legal, Information Security). However, internal audit must rigorously defend its professional objectivity by maintaining strict operational boundaries and refusing to usurp management authority.

In modern corporate governance, internal audit cannot operate as an insular critic that emerges only to deliver retrospective fault-finding. High-performing audit departments actively partner with executive management and second-line assurance functions to enhance risk culture, accelerate business transformations, and eliminate assurance redundancies. The primary challenge for the Chief Audit Executive (CAE) is fostering organizational collaboration without compromising the independence and objectivity mandated by the Global Internal Audit Standards.


Strategic Partnership with Executive Management (CEO, CFO, COO, CIO, CISO)

Executive leadership guides organizational strategy, capital allocation, and operational delivery. Internal audit must maintain continuous alignment with these leaders through structured communication channels:

  • Chief Executive Officer (CEO): Monthly or bi-weekly strategic briefings regarding enterprise risks, culture, organizational transformations, and emerging governance matters.
  • Chief Financial Officer (CFO): Regular discussions covering financial reporting integrity, capital investments, liquidity management, internal controls over financial reporting (ICFR), and fraud deterrence.
  • Chief Operating Officer (COO): Periodic walk-throughs focused on supply chain resilience, operational throughput, plant safety, and fulfillment controls.
  • Chief Information Officer (CIO) & Chief Information Security Officer (CISO): Ongoing alignment on infrastructure upgrades, cloud migrations, zero-trust security architectures, and third-party cyber risks.

Proactive Advisory Engagements

Executive leadership frequently undertakes complex transformations where control design errors cause severe operational disruption. Internal audit delivers substantial value through proactive advisory engagements:

  • Pre-Implementation Reviews: Evaluating control architecture, data conversion integrity, and security parameters during major ERP or software implementations prior to deployment.
  • Process Re-engineering Consulting: Providing advisory feedback on internal control design, automation opportunities, and segregation of duties during corporate reorganizations or acquisitions.
  • Risk Self-Assessment Facilitation: Leading workshops that assist operational managers in identifying and evaluating key risks within their units without audit assuming control ownership.

Collaboration with Second-Line Assurance Functions

Under the IIA Three Lines Model, the governing body and senior management rely on three distinct operational lines:

  1. First-Line Roles: Operating managers who directly own, manage, and execute operational risks and controls.
  2. Second-Line Roles: Specialized functions (Risk Management, Compliance, Legal, InfoSec, Quality) that provide expertise, establish policy frameworks, monitor compliance, and support risk management.
  3. Third-Line Roles: Internal audit, which provides independent, objective assurance on the adequacy and effectiveness of both first- and second-line activities.

Coordinating Risk Assessments and Sharing Data

To prevent organizational "audit fatigue" and redundant testing, internal audit coordinates closely with second-line teams:

  • Harmonized Risk Taxonomy: Collaborating with ERM and Compliance to adopt consistent risk definitions, impact ratings, and probability scoring scales across the enterprise.
  • Shared Monitoring Data: Sharing continuous monitoring analytics, automated exception dashboards, and audit software tools across Compliance, InfoSec, and Internal Audit.
  • Combined Assurance Mapping: Creating an integrated matrix mapping key risks to assurance activities across all lines, highlighting gaps and eliminating redundant testing.
  • Maintaining Second-Line Boundaries: Because second-line teams are management functions that establish policies and assist operations, internal audit cannot uncritically rely on second-line findings without independent testing, and must periodically audit the effectiveness of second-line activities.

Safeguarding Independence and Objectivity: The Golden Boundaries

During advisory projects and executive committees, the boundary between objective advisor and operational manager can blur. The CAE must enforce strict governance safeguards:

  • Prohibition of Operational Duties: Internal auditors may advise on control design, benchmark frameworks, and recommend improvements. However, internal auditors must never assume operational duties: designing, implementing, or operating operational controls; authorizing transactions; or directing non-audit staff.
  • Committee Participation (Observer vs. Voting Member): CAEs and audit leaders are frequently invited to join executive steering committees (e.g., Enterprise Risk Committee, IT Council, AI Governance Board). Internal audit participates strictly as a non-voting advisor or observer. Internal audit must never hold voting rights or approve management decisions, vendor selections, or project milestones. Voting co-authors the decision, destroying objectivity for future audits.
  • The 12-Month Cooling-Off Period: Under GIAS Standard 3.1, when internal auditors transfer from operational roles or previous operational management duties, they are strictly prohibited from conducting assurance engagements over those operational areas for at least 12 months.

Advisory Boundaries: The Permissibility Matrix

Activity / Engagement ScenarioPermissible?Governance Conditions & Safeguards
Pre-implementation advice on ERP control designYES (Advisory)Internal audit recommends controls; management explicitly chooses, designs, and implements them.
Drafting operational standard operating procedures (SOPs)NO (Impairment)Operating management must draft SOPs. Internal audit may only review drafts for control adequacy.
Attending Enterprise Risk Management (ERM) committeeYES (Observer)CAE attends as a non-voting member, providing risk insight without approving corporate tolerances.
Voting to approve core banking vendor selectionNO (Impairment)Vendor selection is a management decision. Internal audit may only evaluate RFP control processes.
Auditing an operational unit managed 8 months ago by a new auditorNO (Impairment)Must enforce a 12-month cooling-off period; assign another staff auditor with no prior operational ties.
Sharing continuous auditing scripts with ComplianceYES (Collaboration)Coordinates assurance and reduces duplicate testing across the Three Lines.

Managing Disagreements and Executive Impasses

Disagreements arise when audit findings challenge high-priority management initiatives (e.g., strategic acquisitions or aggressive system rollouts):

  1. Fact-Based CCCE Framing: Anchor discussions in Criteria, Condition, Cause, and Effect. Verify working paper evidence collaboratively with management to ensure factual accuracy.
  2. Focus on Business Impact: Reframe findings as risk protection mechanisms that help management achieve strategic goals safely, rather than bureaucratic criticisms.
  3. Document Management's Position: If management agrees on facts but disputes risk ratings or recommendations, document management's formal response in the final report.
  4. Escalation of Unacceptable Residual Risk: Under GIAS Standard 11.3 and 15.2, if executive management decides to accept residual risk that exceeds enterprise risk appetite, the CAE must discuss the matter with senior management. If an impasse persists, the CAE must escalate the accepted risk directly to the Audit Committee and Board for final determination.
Loading diagram...
Three Lines Coordination, Committee Boundaries, and Escalation Architecture
Test Your Knowledge

The Chief Information Officer (CIO) invites the Chief Audit Executive to serve as an active member of the enterprise IT Steering Committee, which oversees the procurement, vendor selection, and implementation milestones for a $50 million cloud infrastructure migration. How should the CAE respond to preserve internal audit objectivity?

A
B
C
D
Test Your Knowledge

An internal audit department is coordinating its annual assurance activities with the organization's second-line Compliance and Enterprise Risk Management (ERM) functions. Which of the following practices represents an appropriate collaboration that respects the IIA Three Lines Model?

A
B
C
D
Test Your Knowledge

During an operational audit of a major digital marketing transformation, the audit team discovers that customer data is being shared with external advertising partners without obtaining required user consent, creating massive exposure to international regulatory penalties. The VP of Digital Strategy insists that pausing data sharing will jeopardize the company's annual revenue targets and demands that internal audit drop the observation. After consulting with the CEO, the CEO supports the VP's stance and formally accepts the residual risk, which the CAE believes severely exceeds enterprise risk appetite. What is the mandatory protocol for the CAE under GIAS Standard 11.3 and 15.2?

A
B
C
D