6.3 Confidentiality & Appropriate Use of Information
Key Takeaways
- Internal auditors must respect confidentiality obligations arising from law, regulation, professional standards, and organizational policies
- Information, methodologies, and working papers obtained or created in audit work may be used only for lawful, authorized internal audit purposes and must be protected like other confidential records—not for personal gain or unauthorized disclosure
- Privacy and data ownership rules constrain collection, retention, cross-border transfer, and sharing of personal or proprietary information
- Protecting information includes access controls, secure transmission/storage, careful report distribution, and vigilance in public or social settings
- Legal or professional duties to disclose (for example, to regulators or the board under mandate) are handled through proper channels—not informal leaks
Confidentiality as an Ethical Duty
Principle 5 of the Global Internal Audit Standards requires internal auditors to maintain confidentiality. Confidentiality means protecting information acquired while performing internal audit services and using that information only for legitimate, authorized purposes. It is both an ethical duty and a practical necessity: if auditees believe information will be gossiped, posted, or reused for personal advantage, access collapses and the function cannot fulfill its purpose.
Confidentiality is not absolute secrecy from the board or from legally mandated recipients. It is controlled stewardship: the right information to the right parties through the right channels, with unnecessary exposure minimized.
Policies, Laws, and Professional Obligations
Auditors must know and follow the rules that govern information in their environment:
- Organizational policies — data classification, acceptable use, records retention, clear-desk/clear-screen, BYOD, email forwarding, and incident reporting.
- Laws and regulations — privacy statutes, banking secrecy, health information rules, securities laws on material nonpublic information, trade-secret protections, and sector-specific confidentiality duties.
- Professional Standards and the internal audit charter/methodology — expectations for safeguarding engagement information and communicating results appropriately.
- Contractual commitments — NDAs with vendors, joint-venture partners, or acquisition targets that may bind auditors when those parties are in scope.
| Source of duty | Example constraint | Auditor response |
|---|---|---|
| Privacy law | Limits on collecting or exporting employee personal data | Minimize data collected; anonymize when feasible; follow legal hold/retention rules |
| Securities law | Material nonpublic information | No tipping, no personal trading on audit knowledge |
| Company policy | Client data classified “restricted” | Store only in approved repositories; no personal email |
| Charter / Standards | Results communicated to appropriate parties | Use approved reporting lines; avoid side-channel disclosure |
Exam scenarios often contrast an auditor who “shares early findings with a friend in another department for a heads-up” against one who routes communications through agreed engagement protocols. Informal leakage is a confidentiality breach even if motives seem helpful.
Appropriate Use of Information and Internal Audit Methodologies
Appropriate use means information obtained through internal audit is applied only to perform, supervise, improve, or report on internal audit services—and related authorized quality or regulatory processes—not for unrelated personal or political ends.
Examples of inappropriate use:
- Trading on nonpublic information learned in an audit.
- Sharing draft findings with competitors, media, or social networks.
- Using salary or medical details discovered in fieldwork for gossip or leverage.
- Copying proprietary algorithms or customer lists for a side business.
- Recirculating another auditor’s confidential working papers outside the function without authorization.
Internal audit methodologies, programs, risk rankings, and working papers deserve protection because they reveal how the organization is evaluated and where controls are weak. Leaving detailed test sheets on a shared printer, posting methodology binders to an open collaboration site, or emailing full workpapers to a broad distribution list creates unnecessary exposure. Protecting methodology is not about hiding from the board; it is about preventing uncontrolled spread of sensitive control intelligence.
Authorized uses include:
- Planning and performing engagements.
- Supervisory review and quality assurance.
- Reporting to the CAE, board/audit committee, and agreed management recipients.
- Supporting external assessors or regulators when disclosure is properly authorized.
- Training internal auditors with sanitized examples when policy allows.
Privacy and Ownership of Information
Modern engagements routinely touch personal data (employees, customers, patients, citizens) and proprietary business information (pricing, IP, M&A plans). Confidentiality competency includes recognizing privacy and ownership boundaries.
Privacy considerations:
- Collect only what the engagement objectively needs (data minimization).
- Prefer aggregated or masked data when individual identifiers are unnecessary.
- Understand lawful bases and cross-border transfer restrictions that may apply.
- Coordinate with privacy, legal, or information-security functions when engagements involve special-category data or novel data analytics.
Ownership considerations:
- Business data remains the organization’s property; auditors are stewards, not owners.
- Third-party data obtained under contract may carry stricter limits than internal data.
- When using analytics platforms or AI tools, confirm that uploading engagement data to external systems is allowed—many policies forbid sending confidential data to public generative-AI services.
A frequent trap is an auditor exporting a full HR dump “to make sampling easier” and storing it on a personal laptop. Even if the audit purpose is legitimate, the method of handling can violate privacy policy and confidentiality standards.
Protecting Information in Day-to-Day Work
Protection is operational, not theoretical. Practical controls include:
- Access limitation — need-to-know within the audit team; timely removal of access after the engagement.
- Secure storage — encrypted drives/repositories approved by IT; no unprotected USB copies of sensitive extracts.
- Secure transmission — approved channels; password-protected attachments when required; avoid public Wi-Fi for sensitive uploads without protection.
- Physical control — clean desk; lock screens; caution with printed drafts in shared spaces.
- Report distribution control — targeted recipient lists; watermarks or portal controls where used; care with forwarding.
- Conversational discipline — no engagement details in elevators, rideshares, conferences, or social media.
- End-of-engagement hygiene — return or securely destroy local copies per retention policy; retain official records in the system of record only.
| Situation | Protecting action |
|---|---|
| Draft report with unresolved fraud indicators | Restrict circulation; involve CAE/legal as policy requires |
| Working from home | Use VPN and approved devices; prevent family access to screens/documents |
| Vendor co-sourced team | Bind them to confidentiality terms; control what data leaves the environment |
| Board deck excerpting customer PII | Remove or mask identifiers unless the board truly needs them |
Disclosure Duties versus Leaks
Confidentiality does not forbid required reporting. Auditors may have duties to disclose information to:
- The board or audit committee under the charter and Standards.
- Regulators or external auditors when authorized or legally compelled.
- Legal counsel in coordinated investigations.
The distinction is process. Proper disclosure is documented, authorized, and directed to the appropriate governance or legal channel. A leak to the press, an anonymous social post, or a selective tip to one executive to undermine another is not “transparency”—it is a breach.
If local law or professional obligations create tension (for example, suspected illegal acts), the auditor follows organizational escalation protocols and seeks guidance from the CAE and legal advisors rather than improvising public disclosure.
Confidentiality Across the Engagement Lifecycle
- Planning — define data needs; confirm legal/privacy constraints; establish secure workspaces.
- Fieldwork — gather minimum necessary information; label and store correctly; challenge unsafe sharing requests.
- Reporting — say what recipients need for oversight and action; omit gratuitous personal detail.
- After issuance — apply retention schedules; protect archives; control access to historical workpapers.
Linking Confidentiality to Competency and Due Care
Competency includes knowing applicable information rules; due care includes applying protective measures consistently under deadline pressure. High-risk moments—mobile work, cloud analytics, messaging apps, and “quick shares” of drafts—are where confidentiality failures cluster. The Internal Audit Practitioner who treats information as a privileged trust, not a personal notebook, meets Domain II expectations and preserves the credibility the entire function depends on.
An internal auditor learns during an acquisition due-diligence review that the target’s earnings are weaker than public rumors suggest. Which action violates confidentiality and appropriate use of information?
Which practice best protects confidential engagement information?
Management asks an auditor to email a spreadsheet of employee medical leave details—collected for a benefits-control test—to an external marketing consultant “for a wellness campaign idea.” What should the auditor do?