7.3 Ethics & Compliance Issues
Key Takeaways
- Organizations face layered ethical, legal, and compliance requirements from laws, regulations, contracts, codes of conduct, and professional standards
- An ethical framework typically includes values, a code of conduct, training, speak-up channels, investigation protocols, and consistent consequences
- Internal audit evaluates the design and effectiveness of ethics and compliance programs and may advise, but management owns the programs and the board oversees them
- Compliance failures and ethical breaches are governance issues when oversight, escalation, or accountability break down—not merely isolated HR events
- When ethics or compliance concerns implicate senior management, internal audit's reporting line to the board becomes critical for independent communication
Ethics and Compliance in Syllabus C3
Syllabus topic C3 focuses on ethical, legal, and compliance requirements and on the role of internal audit within the organization's ethical framework. On the Internal Audit Practitioner exam, ethics is both a Domain II professionalism topic (the IIA Code of Ethics for auditors) and a Domain III organizational topic (how the entity governs ethics and compliance). This section emphasizes the organizational side: what the entity must follow, how ethics programs work, and what internal audit contributes without owning management's duties.
Ethical, Legal, and Compliance Requirements
Organizations operate under overlapping obligations:
| Requirement type | Examples | Governance implication |
|---|---|---|
| Legal / regulatory | Securities laws, privacy statutes, anti-bribery laws, licensing rules, labor and safety regulations | Noncompliance can trigger fines, sanctions, criminal exposure, and loss of license to operate |
| Contractual | Customer SLAs, lender covenants, vendor terms, government contract clauses | Breaches create financial and reputational risk and may require disclosure |
| Internal ethical standards | Code of conduct, conflicts policy, gifts and entertainment rules, anti-harassment standards | Define expected behavior beyond the legal minimum |
| Professional / industry standards | Clinical standards, engineering codes, accounting frameworks, IIA Standards for the audit function | Shape competence and quality expectations |
Compliance is the process of adhering to applicable laws, regulations, contracts, and internal policies. Ethics goes further: it addresses right conduct, integrity, fairness, and organizational values even when the law is silent or lagging. Strong organizations treat ethics and compliance as connected—legal compliance without ethical culture still produces scandals; ethical aspiration without compliance infrastructure produces unmanaged legal risk.
Key program elements commonly expected in a mature ethics and compliance framework:
- Board-approved values and code of conduct communicated to all personnel and relevant third parties.
- Risk assessment focused on ethics and compliance exposures (bribery, conflicts, privacy, insider trading, product safety, etc.).
- Policies and controls tailored to those risks (approvals, disclosures, restricted-party screening, monitoring).
- Training and awareness that is role-based and refreshed.
- Speak-up channels (hotlines, ombudspersons) with anti-retaliation protections.
- Investigation capability that is competent, confidential, and fair.
- Consistent discipline and remediation, including root-cause fixes—not only punishing individuals.
- Monitoring and reporting to senior management and the board on trends, cases, and program effectiveness.
Governance Link: Who Owns Ethics and Compliance?
Role clarity mirrors C1:
- The board oversees the ethical climate and compliance risk, receives independent reporting on serious issues, and holds the CEO accountable.
- Senior management owns the ethics and compliance program's design and operation (often with a chief compliance officer or equivalent as a second-line leader).
- First-line managers embed compliant, ethical behavior in operations.
- Internal audit provides independent assurance and advice on whether the framework is designed well and working.
When these roles blur—especially if investigations of senior leaders are controlled only by those same leaders—governance fails. Exam scenarios often test whether the auditor recognizes the need to report to the audit committee when management integrity is in question.
Internal Audit's Role in the Ethical Framework
Internal audit contributes to organizational ethics in several concrete ways:
1. Assuring the ethics and compliance program
Engagements may evaluate whether the code is current and acknowledged, whether training completion is real, whether hotline cases are logged and investigated timely, whether conflicts disclosures are reviewed, and whether remediation closes control gaps. Criteria include laws/regulations, the organization's policies, and recognized program benchmarks.
2. Advising on program improvements
Advisory work might help management design escalation protocols, map compliance obligations, or facilitate a control self-assessment. Advisory support must not make internal audit the de facto compliance owner.
3. Modeling professional ethics
Auditors themselves must follow the IIA Code of Ethics—integrity, objectivity, confidentiality, and competency. An internal audit function that leaks confidential investigation details or soft-pedals findings about a powerful executive damages the organization's ethical framework.
4. Escalating ethical issues appropriately
If an engagement uncovers suspected fraud, bribery, harassment cover-ups, or regulatory breaches, auditors follow the charter, Standards, and investigation protocols. Evidence is preserved; scope may expand; communication goes to the appropriate level—including the board when senior management is implicated or unresponsive.
5. Coordinating with other assurance providers
Compliance, legal, HR, and external auditors may already be examining related issues. Internal audit should coordinate to avoid blind spots and duplicated noise, while protecting independence when evaluating second-line effectiveness.
Common Ethics and Compliance Risks Tested on Scenarios
| Risk theme | Red flags | Control / audit focus |
|---|---|---|
| Bribery and corruption | Unusual gifts, agent commissions, "facilitation" payments | Due diligence, gift logs, payment testing, third-party audits |
| Conflicts of interest | Related-party vendors, undisclosed outside employment | Disclosure processes, procurement independence, board related-party oversight |
| Privacy / data misuse | Excess access, shadow IT, weak retention | Access reviews, DLP monitoring, incident response |
| Financial misconduct | Earnings pressure, late adjustments, override clusters | Journal-entry testing, estimate challenge, tone assessment |
| Retaliation / speak-up failure | Drop in hotline volume after a high-profile case | Anti-retaliation controls, case outcome quality, culture indicators |
| Regulatory noncompliance | Expired licenses, ignored exam findings | Obligation inventory, control mapping, issue tracking to closure |
Evaluating Program Effectiveness—Not Paper Compliance
A frequent IAP trap is equating existence with effectiveness. A code of conduct PDF on the intranet is not evidence that employees understand conflicts rules. Better evidence includes:
- Sample testing of conflict disclosures against public or HR data.
- Review of investigation files for timeliness, competence, documentation, and independence of investigators.
- Analysis of whether similar offenses receive consistent consequences across ranks.
- Verification that board packages include meaningful ethics metrics, not only vanity completion rates.
- Walkthroughs of how a front-line employee would report a concern and what actually happens next.
When reporting results, connect ethics findings to risk and governance: explain how weaknesses increase fraud opportunity, regulatory exposure, or stakeholder trust erosion, and whether decision-makers have accepted risk knowingly or remain unaware.
When Compliance and Ethics Intersect with Culture (C2) and Governance (C1)
Ethics programs fail for cultural reasons as often as for technical ones. If leaders celebrate "win at all costs," training slides will not save the organization. Likewise, if the board never asks for independent ethics reporting, management can hide systemic issues. C3 questions may combine all three syllabus threads: a compliance breach, a cultural tolerance for exceptions, and a governance failure to oversee remediation.
Practical exam approach:
- Identify the requirement (law, policy, ethical standard).
- Identify who owns prevention, detection, and correction.
- Identify what internal audit should do (assure, advise, escalate)—and what it should not do (become the permanent compliance department or conceal issues to protect management).
- Choose the answer that preserves independence, board visibility, and management accountability.
Bottom Line for C3
Ethics and compliance are governance responsibilities executed through management systems and overseen by the board. Internal audit strengthens the ethical framework by independently evaluating whether that system works, by advising on gaps, and by communicating fearlessly when integrity risk threatens organizational value. Memorize the program components, keep role boundaries sharp, and always ask whether evidence shows real behavior—not just polished policy language.
Which statement best describes internal audit's appropriate role in the organization's ethical framework?
A code of conduct exists and annual training completion is 100%, but hotline cases about the same sales practice are closed without remediation and similar offenses are punished inconsistently by rank. What should internal audit emphasize?
During an engagement, internal audit obtains credible evidence that a senior executive directed concealment of a regulatory violation. What action best aligns with governance and ethics expectations?