6.2 Due Professional Care & Skepticism

Key Takeaways

  • Due professional care is the application of the care and skill expected of a reasonably prudent and competent internal auditor in the same or similar circumstances
  • Care includes aligning work with organizational strategy and objectives and evaluating whether governance, risk management, and control (GRC) processes are both adequately designed and operating effectively
  • Cost–benefit thinking shapes extent of testing and recommendations; it does not excuse ignoring material risk to save effort
  • Planning and fieldwork must consider the probability of errors, fraud, and noncompliance—not assume honesty or perfect processing
  • Professional skepticism is a questioning mindset and critical assessment of evidence; it is mandatory even when management is trusted and cooperative
Last updated: July 2026

What Due Professional Care Means

Due professional care is a Domain II expectation closely paired with competency. Competency is having (or obtaining) the capability; due care is using that capability diligently and thoughtfully on each engagement. The classic formulation is that internal auditors apply the care and skill expected of a reasonably prudent and competent internal auditor in similar circumstances.

Due care is not perfection, unlimited testing, or a guarantee that every error or fraud will be found. It is a reasonable, risk-based standard of performance: plan thoughtfully, gather sufficient appropriate evidence, evaluate fairly, document work, and communicate results with integrity.

On IAP / CIA Part 1 items, due care failures usually look like shortcuts—skipping risk assessment, accepting weak evidence, ignoring red flags, or recommending controls without considering practicality and cost relative to risk.

Assessing Strategy and Objectives

Internal auditing exists to help the organization create, protect, and sustain value. Due care therefore starts with understanding strategy and objectives—what the organization is trying to achieve and which risks threaten those aims.

When auditors assess strategy and objectives, they:

  • Identify the objectives relevant to the engagement (strategic, operational, reporting, compliance).
  • Understand how success is measured and where management monitors performance.
  • Map significant risks that could prevent objective achievement.
  • Align engagement objectives and scope with those risks rather than with convenience or last year’s identical program.
FocusDue-care behaviorCareless behavior
Strategy linkageEngagement objective tied to risks that matter to board/management goalsAuditing low-risk trivia because it is familiar
Objective clarityCriteria and success measures defined up frontVague “review the process” with no evaluative criteria
Change in directionReassess scope when strategy or risk profile shifts mid-yearRigidly completing an obsolete plan

Due care does not mean internal audit sets strategy. It means auditors understand strategy well enough to evaluate whether governance, risk management, and controls supporting those objectives are fit for purpose.

Adequacy and Effectiveness of GRC Processes

A recurring Standards theme is evaluating governance, risk management, and control processes for adequacy (design) and effectiveness (operation).

  • Adequacy / design asks: If the control or process operated as designed, would it reasonably address the risk? Missing segregation of duties in a payment workflow is a design problem.
  • Effectiveness / operation asks: Does it actually work as intended over time? A well-designed approval control that is routinely bypassed is an operating effectiveness problem.

Due professional care requires auditors to gather evidence for the conclusion they issue. A design walkthrough alone cannot support a claim that controls operated effectively all year. Conversely, a sample of transactions cannot fix a fundamentally broken design—both dimensions may need attention.

When assessing GRC:

  • Governance — tone, oversight structures, accountabilities, information flows to the board.
  • Risk management — identification, assessment, response, monitoring; alignment with appetite/tolerance where established.
  • Controls — preventive and detective activities, automated and manual, including monitoring controls.

Careless practice includes opining on “strong controls” after interviewing one manager, or rating enterprise risk management effective because a risk register exists—without testing whether risks are updated, owned, and acted on.

Cost versus Benefit

Due care includes cost–benefit judgment in two places: how much work to perform, and what to recommend.

Extent of procedures. Auditors should apply resources proportionate to risk. High residual risk and weak controls justify deeper testing; low risk and strong continuous monitoring may justify a lighter approach. Cost–benefit never means “skip work on a known material risk because overtime is expensive.”

Recommendations. Proposed actions should be practical relative to the risk reduction achieved. Requiring a dual-signature process on every $5 purchase requisition may be technically tighter yet economically absurd. Equally, rejecting a necessary control on a high-value wire process solely because it adds a day of processing is a false economy.

Exam stems often present an auditor who either:

  1. Tests everything exhaustively with no risk prioritization, or
  2. Cuts corners on high-risk areas to save budget.

Both miss due care. The prudent auditor right-sizes effort and remediation to risk and value.

Probability of Errors, Fraud, and Noncompliance

Planning and performing engagements with due care means considering the likelihood and impact that errors, fraud, and noncompliance could occur—not assuming processes work because people seem honest.

Factors that raise probability (and thus call for more care) include:

  • Complex transactions or manual interventions.
  • High turnover, new systems, or rushed period-end closes.
  • Incentive pressure (sales targets, bonus metrics, cost-cutting mandates).
  • Weak segregation, poor access management, or override culture.
  • History of exceptions, regulatory findings, or tip-line allegations.
  • Decentralized operations with uneven training.
Risk typeWhat due care looks like
ErrorTest for accuracy, completeness, cutoff; examine reconciliations and exception handling
FraudConsider incentives, opportunities, and rationalizations; design procedures responsive to fraud risk without turning every engagement into a full fraud investigation unless warranted
NoncomplianceIdentify applicable requirements; test adherence and the controls that enforce it; escalate confirmed breaches through proper channels

Internal auditors are not expected to detect every fraud. They are expected to consider fraud risk thoughtfully, respond to red flags, and avoid willful blindness. Ignoring obvious anomalies because “management would never do that” is a due-care failure.

Professional Skepticism

Professional skepticism is a questioning mind and a critical assessment of evidence. It sits inside due professional care as the attitude that keeps auditors from becoming cheerleaders or rubber stamps.

Skepticism in practice:

  • Corroborate management representations with documents, data, or independent observation when the assertion matters.
  • Seek contradictory as well as confirming evidence.
  • Revisit conclusions when new information conflicts with the working papers.
  • Remain courteous and collaborative without surrendering objectivity.

Skepticism is not cynicism. Treating every employee as dishonest destroys relationships and wastes resources. The balance is: trust is earned through evidence; evidence is tested, not merely received.

Common anti-patterns tested on the exam:

  • Accepting photocopies or screenshots without considering alteration risk when stakes are high.
  • Stopping work because a senior executive “vouched” for the control.
  • Explaining away every exception as “timing” without analysis.
  • Using inquiry alone to conclude on operating effectiveness for a significant control.

Applying Due Care Across the Engagement Lifecycle

PhaseDue-care emphasis
PlanningUnderstand objectives/strategy; assess risks including error/fraud/noncompliance; set scope and resources using cost–benefit tied to risk
FieldworkExecute with skepticism; adjust procedures when evidence contradicts expectations; document adequately
ReportingBase ratings and conclusions on sufficient appropriate evidence; communicate limitations; avoid overstatement or understatement
Follow-upVerify remediation thoughtfully proportionate to risk—not paper closure based solely on management assertion when risk remains high

Integrating Care with Competency and Ethics

Due care depends on competency (you cannot carefully apply skills you lack) and intersects confidentiality and objectivity (careful work still must protect information and remain unbiased). When time pressure, client pushback, or resource limits threaten the quality of work, due care requires escalating constraints—especially scope or resource limitations—so the board and CAE can respond. Silently narrowing a high-risk engagement to hit a deadline is not prudence; it is an impairment of quality that must be visible to those accountable for the internal audit function.

Test Your Knowledge

Which statement best describes due professional care for internal auditors?

A
B
C
D
Test Your Knowledge

An auditor concludes that accounts-payable controls are “effective” after a single walkthrough interview with the AP manager and no transaction testing. Which due-care problem is most evident?

A
B
C
D
Test Your Knowledge

During planning for a payroll engagement, which consideration best reflects due professional care regarding errors, fraud, and noncompliance?

A
B
C
D