4.2 Ethics, Integrity & ISACA Code of Professional Ethics

Key Takeaways

  • The ISACA Code of Professional Ethics establishes seven mandatory provisions that guide the professional conduct of all CRISC credential holders, exam candidates, and members.
  • Provision 6 strictly mandates the full disclosure of all significant facts known to the practitioner that, if not disclosed, may distort the reporting of risk assessment and audit findings.
  • Conflicts of interest—whether actual, potential, or perceived—require immediate formal disclosure to relevant stakeholders and complete recusal from decision-making or assessment roles.
  • Provision 4 enforces confidentiality and privacy of information acquired during professional duties, permitting disclosure only when formally compelled by authorized legal or regulatory mandates.
  • Provision 5 dictates that practitioners must maintain professional competence and undertake only those engagements they can reasonably expect to complete with requisite skills and knowledge.
Last updated: August 2026

4.2 Ethics, Integrity & ISACA Code of Professional Ethics

In information technology risk management, technical expertise alone is insufficient to protect organizations and their stakeholders. Risk professionals possess privileged access to sensitive architectures, vulnerability data, financial records, and strategic plans. Furthermore, executive leadership, boards of directors, regulators, and the public place immense trust in the objectivity and accuracy of risk assessments. When ethical integrity fails, the entire governance structure collapses, exposing organizations to catastrophic financial loss, regulatory sanctions, and reputational ruin.

To establish a binding ethical standard across the global IT governance and risk profession, ISACA established the ISACA Code of Professional Ethics. Adherence to this code is a mandatory prerequisite for earning and maintaining the Certified in Risk and Information Systems Control (CRISC) designation.

+-----------------------------------------------------------------------------+
|                   THE 7 PROVISIONS OF THE ISACA CODE OF ETHICS              |
|                                                                             |
|   [PROVISION 1] Standards & Procedures (Support governance & controls)      |
|   [PROVISION 2] Due Care & Objectivity (Perform with diligence & standards) |
|   [PROVISION 3] Stakeholder Interest & Law (Act lawfully & creditably)      |
|   [PROVISION 4] Confidentiality & Privacy (Protect info, no personal gain)  |
|   [PROVISION 5] Competency & Due Care (Undertake only competent work)       |
|   [PROVISION 6] Full Disclosure in Reporting (Disclose all significant facts)|
|   [PROVISION 7] Professional Education (Support stakeholder understanding)  |
+-----------------------------------------------------------------------------+

1. The Seven Mandatory Provisions of the ISACA Code of Professional Ethics

ISACA members and certification holders must adhere to seven explicit ethical mandates. Failure to comply can result in formal investigation by the ISACA Board of Directors and Ethics Committee, leading to reprimands, credential suspension, or permanent revocation of all ISACA designations.

Provision 1: Standards and Procedures

"Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise information systems and technology, including: audit, control, security and risk management."

  • Practical Application: CRISC practitioners must actively promote defensible frameworks (e.g., COBIT, ISO 31000, NIST CSF, ISO/IEC 27001) rather than ad-hoc, informal practices. Practitioners must never encourage or participate in circumventing established organizational controls or governance policies.

Provision 2: Due Care and Objectivity

"Perform their duties with objectivity, due diligence and professional care, in accordance with professional standards and best practices."

  • Practical Application: Due care requires exercising the level of diligence, prudence, and thoroughness that a competent professional would apply under similar circumstances. Objectivity mandates maintaining an unbiased mental attitude, ensuring that assessments are grounded in empirical evidence rather than personal relationships, political pressures, or preconceived conclusions.

Provision 3: Stakeholder Interests and Lawful Conduct

"Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not engage in acts discreditable to the profession."

  • Practical Application: Practitioners must align risk activities with the legitimate business interests of stakeholders (shareholders, customers, employees, regulators) while strictly obeying all applicable laws. Engaging in illegal acts, fraud, bribery, falsification of records, or unethical hacking constitutes an act discreditable to the profession.

Provision 4: Privacy, Confidentiality, and Prohibition of Personal Benefit

"Maintain the privacy and confidentiality of information obtained in the course of their duties unless disclosure is required by legal authority. Such information shall not be used for personal benefit or released to inappropriate parties."

  • Practical Application: Risk practitioners routinely discover proprietary intellectual property, customer Personally Identifiable Information (PII), and critical security vulnerabilities. This data must remain strictly confidential and must never be leveraged for insider trading, commercial advantage, personal financial gain, or leaked to unauthorized parties.
  • The Legal Exception: The duty of confidentiality is not absolute when in conflict with lawful judicial or regulatory processes. If subpoenaed by a court of law or required by statutory reporting mandates (such as mandatory breach disclosure laws), the practitioner is legally and ethically bound to comply.

Provision 5: Professional Competency and Skills Maintenance

"Maintain competency in their respective fields and agree to undertake only those activities they can reasonably expect to complete with the necessary skills, knowledge and competence."

  • Practical Application: Practitioners have a twofold obligation: (1) maintain continuous professional education (earning required annual/triennial CPEs), and (2) frankly assess their own capabilities before accepting an assignment. A risk practitioner specializing in IT governance must not independently accept an engagement requiring advanced cryptographic mathematical proofs or industrial SCADA engineering if they lack the requisite competency.

Provision 6: Full and Truthful Disclosure in Reporting

"Inform appropriate parties of the results of work performed, including the full disclosure of all significant facts known to them that, if not disclosed, may distort the reporting of the results."

  • Practical Application: This is one of the most frequently tested provisions on the CRISC examination. Practitioners must never conceal, omit, soften, or manipulate risk findings to please executives, meet project deadlines, or avoid organizational conflict. If a critical vulnerability or compliance non-conformity exists, it must be documented factually and reported to appropriate governance authorities.

Provision 7: Education and Understanding for Stakeholders

"Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise information systems and technology, including: audit, control, security and risk management."

  • Practical Application: Practitioners should not treat risk management as an esoteric technical mystery. They are obligated to educate business leaders, operational staff, and committee members to elevate the organization's collective risk intelligence.
+-----------------------------------------------------------------------------+
|                 ISACA CODE OF ETHICS — PROVISION MAPPING MATRIX             |
|                                                                             |
|   PROVISION       CORE FOCUS                 KEY EXAM TRIGGERS              |
|   -------------   -----------------------    ------------------------------ |
|   Provision 1     Governance Standards       Implementing COBIT / ISO       |
|   Provision 2     Objectivity & Due Care     Unbiased evidence collection   |
|   Provision 3     Stakeholder Interests      Lawful conduct & character     |
|   Provision 4     Privacy & Confidentiality  Subpoenas vs. Insider Trading  |
|   Provision 5     Competency & Scope         Declining unqualified work     |
|   Provision 6     Integrity in Reporting     Never omitting bad findings    |
|   Provision 7     Stakeholder Education      Training & raising awareness   |
+-----------------------------------------------------------------------------+

2. Managing Conflicts of Interest: Objectivity vs. Independence

A Conflict of Interest occurs when a practitioner's personal, financial, or professional relationships compromise—or create the reasonable perception of compromising—their ability to exercise impartial judgment.

+-----------------------------------------------------------------------------+
|                 CONFLICT OF INTEREST GOVERNANCE & RESOLUTION                |
|                                                                             |
|   [STEP 1: IDENTIFICATION]                                                  |
|   Identify Actual, Potential, or Perceived Conflict of Interest             |
|   (e.g., Financial shares in vendor, family member owns bidding firm,       |
|    assessing a system the practitioner recently built/managed)              |
|                             |                                               |
|                             v                                               |
|   [STEP 2: FORMAL DISCLOSURE]                                               |
|   Immediately disclose the conflict in writing to Management / Ethics Comm  |
|                             |                                               |
|                             v                                               |
|   [STEP 3: RECUSAL & INDEPENDENT REASSIGNMENT]                              |
|   Recuse oneself entirely from evaluation, scoring, and approval workflows  |
|   Assign an independent, qualified third party to conduct the assessment    |
|                             |                                               |
|                             v                                               |
|   [STEP 4: TRANSPARENT AUDIT DOCUMENTATION]                                 |
|   Document the disclosure, recusal, and mitigation in official GRC records  |
+-----------------------------------------------------------------------------+

Types of Conflicts of Interest:

  • Actual Conflict: A direct clash between professional duty and private interest (e.g., scoring an RFP bid where the practitioner owns 15% equity in the bidding vendor).
  • Potential Conflict: A situation that may evolve into an actual conflict in the future (e.g., evaluating a technology vendor while currently interviewing for an executive role at that vendor).
  • Perceived / Apparent Conflict: A scenario where a reasonable third party, possessing all relevant facts, would conclude that the practitioner's objectivity is compromised, even if the practitioner believes they can remain impartial (e.g., auditing an enterprise system designed and deployed by the practitioner's spouse).

Objectivity vs. Independence:

DimensionObjectivity (Mental Attitude)Independence (Structural Position)
DefinitionAn unbiased, honest, and impartial state of mind that does not subordinate judgment to others.Freedom from conditions, relationships, and reporting lines that threaten the ability to perform work impartially.
NatureIndividual quality (Internal mindset).Organizational / Structural quality (External positioning).
EvaluationCan a practitioner evaluate evidence purely on technical and factual merits?Does the practitioner report to the executive whose systems they are assessing?
RequirementMandatory for all risk practitioners, assessors, and advisors.Mandatory for internal/external auditors (Third Line); risk practitioners (Second Line) maintain objectivity while advising First Line operations.

[!IMPORTANT] The "Personal Objectivity" Fallacy: On the CRISC exam, when a conflict of interest is identified, it is never acceptable for a practitioner to claim: "I will remain objective and fair, so I don't need to disclose or recuse myself." The presence of an actual or perceived conflict mandates immediate formal disclosure and recusal, regardless of how impartial the practitioner believes themselves to be.


3. Integrity in Risk Reporting: The "Whitewashing" Trap

One of the most intense ethical pressures a CRISC practitioner will encounter is the demand from business executives to soften, downplay, or completely omit critical risk findings from formal governance reports.

+-----------------------------------------------------------------------------+
|                  ETHICAL DILEMMA: EXECUTIVE RISK SUPPRESSION                |
|                                                                             |
|   SCENARIO:                                                                 |
|   A pre-launch risk assessment of a new mobile banking platform reveals an  |
|   unauthenticated API endpoint exposing customer account numbers.           |
|                                                                             |
|   EXECUTIVE PRESSURE:                                                       |
|   The VP of Digital Products states: "If this critical finding is in the    |
|   board report, the launch will be blocked and we will miss Q4 targets.     |
|   Downgrade it to 'Low' or leave it out. We promise to patch it next month."|
|                                                                             |
|   THE ETHICAL & CRISC MANDATE (PROVISION 6):                                |
|   1. The practitioner CANNOT omit, downgrade, or obscure the finding.       |
|   2. The report must objectively document the vulnerability, the exposure,  |
|      and the potential business impact.                                     |
|   3. The practitioner presents the objective facts to the Asset Owner and   |
|      Risk Committee. If the business owner decides to accept the risk, the  |
|      formal acceptance is documented under proper fiduciary governance.     |
+-----------------------------------------------------------------------------+

The Core Governance Boundary in Reporting

  • The Risk Practitioner's Duty: Identify, assess, and report risk objectively, truthfully, and completely (Provision 6).
  • The Business Asset Owner's Duty: Decide whether to mitigate, avoid, transfer, or formally accept the residual risk within enterprise risk appetite.
  • The Line of Integrity: The risk practitioner does not make business decisions, but they must never distort facts to make a dangerous business decision look safe.

4. Confidentiality vs. Legal Compulsion & Whistleblowing

Provision 4 of the ISACA Code of Professional Ethics establishes that confidentiality is a sacred professional trust. However, practitioners must understand the precise boundaries between proprietary confidentiality and legal compliance.

+-----------------------------------------------------------------------------+
|                  CONFIDENTIALITY DECISION FLOWCHART (PROVISION 4)           |
|                                                                             |
|               Request / Pressure to Disclose Information                    |
|                                   |                                         |
|                                   v                                         |
|                 Is disclosure required by law or a                          |
|                 valid court order / formal subpoena?                        |
|                               /       \                                     |
|                        [YES] /         \ [NO]                               |
|                             v           v                                   |
|                  +-------------+     +-------------------------------+      |
|                  | COMPLY WITH |     | MAINTAIN STRICT               |      |
|                  | LEGAL ORDER |     | CONFIDENTIALITY               |      |
|                  | Consult     |     | Do not release to unauthorized|      |
|                  | legal       |     | parties or use for personal   |      |
|                  | counsel     |     | financial gain.               |      |
|                  +-------------+     +-------------------------------+      |
+-----------------------------------------------------------------------------+

Critical Distinctions:

  1. Authorized Legal Compulsion: If a practitioner receives a valid judicial subpoena, a court order, or is subject to statutory reporting laws (e.g., mandatory reporting of child sexual abuse material or critical infrastructure reporting under CIRCIA), disclosing information does not violate ISACA ethics. Legal authority overrides organizational nondisclosure agreements (NDAs).
  2. Unauthorized Public Leaks: Taking proprietary company vulnerability data and leaking it to journalists, social media, or public forums without formal legal protection or statutory whistleblower status is a direct violation of Provision 4 and Provision 3.
  3. Insider Trading & Commercial Exploitation: Learning about an unannounced corporate acquisition or catastrophic unpatched zero-day vulnerability and trading company stock (or advising family to trade) constitutes severe criminal fraud and an immediate violation of Provision 4.

5. Professional Competency & Due Care (Provision 5 & 2)

Risk practitioners must recognize their professional limitations. When an organization requests a risk evaluation in a highly specialized domain where the practitioner lacks adequate technical knowledge:

  • Acceptable Actions:
    • Transparently inform management of skill boundaries.
    • Partner with or hire qualified Subject Matter Experts (SMEs) to perform the specialized technical evaluations while the CRISC practitioner facilitates the overall risk governance framework.
    • Undertake formal training and acquire the prerequisite competence before delivering conclusions.
  • Unacceptable Ethical Violations:
    • Accepting an engagement under false pretenses of expertise.
    • Guessing or utilizing automated tools without understanding their output, leading to false assurance for the enterprise.

6. CRISC Exam Traps & Real-World Ethical Scenarios

+-----------------------------------------------------------------------------+
|                 CRISC ETHICS CASE: THE PRE-IPO CONCEALMENT                  |
|                                                                             |
|   SCENARIO:                                                                 |
|   A senior IT risk analyst at a FinTech startup preparing for an IPO        |
|   discovers that the core database storing 2 million user credit cards is   |
|   unencrypted and accessible via legacy debugging ports.                    |
|                                                                             |
|   THE DILEMMA:                                                              |
|   The Chief Financial Officer informs the analyst: "We are filing our S-1   |
|   next week. If this is listed as an unmitigated material weakness in the   |
|   risk register, our valuation will plummet. Record it as a low-priority   |
|   procedural improvement instead."                                          |
|                                                                             |
|   CORRECT ETHICAL RESOLUTION:                                               |
|   Under Provision 6, the analyst MUST refuse to falsify the risk rating.    |
|   The risk must be documented accurately based on actual likelihood and     |
|   impact. The analyst escalates through proper governance channels          |
|   (Audit Committee / CRO / General Counsel). Falsifying the risk register   |
|   violates ISACA ethics and constitutes securities fraud.                   |
+-----------------------------------------------------------------------------+

[!CAUTION] Classic Exam Trap — The "Friendly Compromise" Distractor: Exam scenarios often describe an executive asking for a "temporary favor" to omit an audit finding, delay reporting until next quarter, or reclassify a critical defect as low risk. Distractor choices will offer tempting middle-ground solutions, such as "Agree to document the finding in an informal private email rather than the official report." This is a trap! ISACA requires uncompromising, formal disclosure of all significant facts in the official work product.

Test Your Knowledge

During a comprehensive IT risk assessment of a core banking application scheduled for an upcoming product launch, a CRISC practitioner identifies a critical vulnerability in transaction validation that could allow unauthorized fund transfers. The project executive requests that the practitioner omit this finding from the formal assessment report to prevent delaying the launch, promising that a patch will be deployed post-launch. According to the ISACA Code of Professional Ethics, how MUST the practitioner respond?

A
B
C
D
Test Your Knowledge

A certified risk practitioner is assigned to evaluate competing third-party vendor proposals for a high-value enterprise cloud migration contract. The practitioner realizes that one of the bidding vendors is owned by an immediate family member. What is the practitioner's FIRST and most ethical course of action?

A
B
C
D
Test Your Knowledge

An IT risk consultant certified in CRISC is asked by a healthcare client to perform a specialized cryptographic mathematical proof and architectural audit of an experimental post-quantum encryption algorithm. The consultant possesses broad enterprise risk and GRC experience but lacks formal training or expertise in advanced post-quantum cryptography. According to the ISACA Code of Professional Ethics, what is the practitioner required to do?

A
B
C
D
Test Your Knowledge

A certified risk professional working for a critical infrastructure operator discovers evidence during an internal risk audit indicating that the organization experienced an unreported regulatory breach involving consumer data exfiltration. Six months later, the practitioner leaves the company. A government regulatory agency issues a formal legal subpoena demanding testimony and audit records regarding the incident. According to the ISACA Code of Professional Ethics, how must the practitioner handle the duty of confidentiality?

A
B
C
D