6.2 Due Professional Care & Skepticism
Key Takeaways
- Due professional care is the application of the care and skill expected of a reasonably prudent and competent internal auditor in the same or similar circumstances
- Care includes aligning work with organizational strategy and objectives and evaluating whether governance, risk management, and control (GRC) processes are both adequately designed and operating effectively
- Cost–benefit thinking shapes extent of testing and recommendations; it does not excuse ignoring material risk to save effort
- Planning and fieldwork must consider the probability of errors, fraud, and noncompliance—not assume honesty or perfect processing
- Professional skepticism is a questioning mindset and critical assessment of evidence; it is mandatory even when management is trusted and cooperative
What Due Professional Care Means
Due professional care is a Domain II expectation closely paired with competency. Competency is having (or obtaining) the capability; due care is using that capability diligently and thoughtfully on each engagement. The classic formulation is that internal auditors apply the care and skill expected of a reasonably prudent and competent internal auditor in similar circumstances.
Due care is not perfection, unlimited testing, or a guarantee that every error or fraud will be found. It is a reasonable, risk-based standard of performance: plan thoughtfully, gather sufficient appropriate evidence, evaluate fairly, document work, and communicate results with integrity.
On IAP / CIA Part 1 items, due care failures usually look like shortcuts—skipping risk assessment, accepting weak evidence, ignoring red flags, or recommending controls without considering practicality and cost relative to risk.
Assessing Strategy and Objectives
Internal auditing exists to help the organization create, protect, and sustain value. Due care therefore starts with understanding strategy and objectives—what the organization is trying to achieve and which risks threaten those aims.
When auditors assess strategy and objectives, they:
- Identify the objectives relevant to the engagement (strategic, operational, reporting, compliance).
- Understand how success is measured and where management monitors performance.
- Map significant risks that could prevent objective achievement.
- Align engagement objectives and scope with those risks rather than with convenience or last year’s identical program.
| Focus | Due-care behavior | Careless behavior |
|---|---|---|
| Strategy linkage | Engagement objective tied to risks that matter to board/management goals | Auditing low-risk trivia because it is familiar |
| Objective clarity | Criteria and success measures defined up front | Vague “review the process” with no evaluative criteria |
| Change in direction | Reassess scope when strategy or risk profile shifts mid-year | Rigidly completing an obsolete plan |
Due care does not mean internal audit sets strategy. It means auditors understand strategy well enough to evaluate whether governance, risk management, and controls supporting those objectives are fit for purpose.
Adequacy and Effectiveness of GRC Processes
A recurring Standards theme is evaluating governance, risk management, and control processes for adequacy (design) and effectiveness (operation).
- Adequacy / design asks: If the control or process operated as designed, would it reasonably address the risk? Missing segregation of duties in a payment workflow is a design problem.
- Effectiveness / operation asks: Does it actually work as intended over time? A well-designed approval control that is routinely bypassed is an operating effectiveness problem.
Due professional care requires auditors to gather evidence for the conclusion they issue. A design walkthrough alone cannot support a claim that controls operated effectively all year. Conversely, a sample of transactions cannot fix a fundamentally broken design—both dimensions may need attention.
When assessing GRC:
- Governance — tone, oversight structures, accountabilities, information flows to the board.
- Risk management — identification, assessment, response, monitoring; alignment with appetite/tolerance where established.
- Controls — preventive and detective activities, automated and manual, including monitoring controls.
Careless practice includes opining on “strong controls” after interviewing one manager, or rating enterprise risk management effective because a risk register exists—without testing whether risks are updated, owned, and acted on.
Cost versus Benefit
Due care includes cost–benefit judgment in two places: how much work to perform, and what to recommend.
Extent of procedures. Auditors should apply resources proportionate to risk. High residual risk and weak controls justify deeper testing; low risk and strong continuous monitoring may justify a lighter approach. Cost–benefit never means “skip work on a known material risk because overtime is expensive.”
Recommendations. Proposed actions should be practical relative to the risk reduction achieved. Requiring a dual-signature process on every $5 purchase requisition may be technically tighter yet economically absurd. Equally, rejecting a necessary control on a high-value wire process solely because it adds a day of processing is a false economy.
Exam stems often present an auditor who either:
- Tests everything exhaustively with no risk prioritization, or
- Cuts corners on high-risk areas to save budget.
Both miss due care. The prudent auditor right-sizes effort and remediation to risk and value.
Probability of Errors, Fraud, and Noncompliance
Planning and performing engagements with due care means considering the likelihood and impact that errors, fraud, and noncompliance could occur—not assuming processes work because people seem honest.
Factors that raise probability (and thus call for more care) include:
- Complex transactions or manual interventions.
- High turnover, new systems, or rushed period-end closes.
- Incentive pressure (sales targets, bonus metrics, cost-cutting mandates).
- Weak segregation, poor access management, or override culture.
- History of exceptions, regulatory findings, or tip-line allegations.
- Decentralized operations with uneven training.
| Risk type | What due care looks like |
|---|---|
| Error | Test for accuracy, completeness, cutoff; examine reconciliations and exception handling |
| Fraud | Consider incentives, opportunities, and rationalizations; design procedures responsive to fraud risk without turning every engagement into a full fraud investigation unless warranted |
| Noncompliance | Identify applicable requirements; test adherence and the controls that enforce it; escalate confirmed breaches through proper channels |
Internal auditors are not expected to detect every fraud. They are expected to consider fraud risk thoughtfully, respond to red flags, and avoid willful blindness. Ignoring obvious anomalies because “management would never do that” is a due-care failure.
Professional Skepticism
Professional skepticism is a questioning mind and a critical assessment of evidence. It sits inside due professional care as the attitude that keeps auditors from becoming cheerleaders or rubber stamps.
Skepticism in practice:
- Corroborate management representations with documents, data, or independent observation when the assertion matters.
- Seek contradictory as well as confirming evidence.
- Revisit conclusions when new information conflicts with the working papers.
- Remain courteous and collaborative without surrendering objectivity.
Skepticism is not cynicism. Treating every employee as dishonest destroys relationships and wastes resources. The balance is: trust is earned through evidence; evidence is tested, not merely received.
Common anti-patterns tested on the exam:
- Accepting photocopies or screenshots without considering alteration risk when stakes are high.
- Stopping work because a senior executive “vouched” for the control.
- Explaining away every exception as “timing” without analysis.
- Using inquiry alone to conclude on operating effectiveness for a significant control.
Applying Due Care Across the Engagement Lifecycle
| Phase | Due-care emphasis |
|---|---|
| Planning | Understand objectives/strategy; assess risks including error/fraud/noncompliance; set scope and resources using cost–benefit tied to risk |
| Fieldwork | Execute with skepticism; adjust procedures when evidence contradicts expectations; document adequately |
| Reporting | Base ratings and conclusions on sufficient appropriate evidence; communicate limitations; avoid overstatement or understatement |
| Follow-up | Verify remediation thoughtfully proportionate to risk—not paper closure based solely on management assertion when risk remains high |
Integrating Care with Competency and Ethics
Due care depends on competency (you cannot carefully apply skills you lack) and intersects confidentiality and objectivity (careful work still must protect information and remain unbiased). When time pressure, client pushback, or resource limits threaten the quality of work, due care requires escalating constraints—especially scope or resource limitations—so the board and CAE can respond. Silently narrowing a high-risk engagement to hit a deadline is not prudence; it is an impairment of quality that must be visible to those accountable for the internal audit function.
Which statement best describes due professional care for internal auditors?
An auditor concludes that accounts-payable controls are “effective” after a single walkthrough interview with the AP manager and no transaction testing. Which due-care problem is most evident?
During planning for a payroll engagement, which consideration best reflects due professional care regarding errors, fraud, and noncompliance?