7.3 Ethics & Compliance Issues

Key Takeaways

  • Organizations face layered ethical, legal, and compliance requirements from laws, regulations, contracts, codes of conduct, and professional standards
  • An ethical framework typically includes values, a code of conduct, training, speak-up channels, investigation protocols, and consistent consequences
  • Internal audit evaluates the design and effectiveness of ethics and compliance programs and may advise, but management owns the programs and the board oversees them
  • Compliance failures and ethical breaches are governance issues when oversight, escalation, or accountability break down—not merely isolated HR events
  • When ethics or compliance concerns implicate senior management, internal audit's reporting line to the board becomes critical for independent communication
Last updated: July 2026

Ethics and Compliance in Syllabus C3

Syllabus topic C3 focuses on ethical, legal, and compliance requirements and on the role of internal audit within the organization's ethical framework. On the Internal Audit Practitioner exam, ethics is both a Domain II professionalism topic (the IIA Code of Ethics for auditors) and a Domain III organizational topic (how the entity governs ethics and compliance). This section emphasizes the organizational side: what the entity must follow, how ethics programs work, and what internal audit contributes without owning management's duties.

Ethical, Legal, and Compliance Requirements

Organizations operate under overlapping obligations:

Requirement typeExamplesGovernance implication
Legal / regulatorySecurities laws, privacy statutes, anti-bribery laws, licensing rules, labor and safety regulationsNoncompliance can trigger fines, sanctions, criminal exposure, and loss of license to operate
ContractualCustomer SLAs, lender covenants, vendor terms, government contract clausesBreaches create financial and reputational risk and may require disclosure
Internal ethical standardsCode of conduct, conflicts policy, gifts and entertainment rules, anti-harassment standardsDefine expected behavior beyond the legal minimum
Professional / industry standardsClinical standards, engineering codes, accounting frameworks, IIA Standards for the audit functionShape competence and quality expectations

Compliance is the process of adhering to applicable laws, regulations, contracts, and internal policies. Ethics goes further: it addresses right conduct, integrity, fairness, and organizational values even when the law is silent or lagging. Strong organizations treat ethics and compliance as connected—legal compliance without ethical culture still produces scandals; ethical aspiration without compliance infrastructure produces unmanaged legal risk.

Key program elements commonly expected in a mature ethics and compliance framework:

  1. Board-approved values and code of conduct communicated to all personnel and relevant third parties.
  2. Risk assessment focused on ethics and compliance exposures (bribery, conflicts, privacy, insider trading, product safety, etc.).
  3. Policies and controls tailored to those risks (approvals, disclosures, restricted-party screening, monitoring).
  4. Training and awareness that is role-based and refreshed.
  5. Speak-up channels (hotlines, ombudspersons) with anti-retaliation protections.
  6. Investigation capability that is competent, confidential, and fair.
  7. Consistent discipline and remediation, including root-cause fixes—not only punishing individuals.
  8. Monitoring and reporting to senior management and the board on trends, cases, and program effectiveness.

Governance Link: Who Owns Ethics and Compliance?

Role clarity mirrors C1:

  • The board oversees the ethical climate and compliance risk, receives independent reporting on serious issues, and holds the CEO accountable.
  • Senior management owns the ethics and compliance program's design and operation (often with a chief compliance officer or equivalent as a second-line leader).
  • First-line managers embed compliant, ethical behavior in operations.
  • Internal audit provides independent assurance and advice on whether the framework is designed well and working.

When these roles blur—especially if investigations of senior leaders are controlled only by those same leaders—governance fails. Exam scenarios often test whether the auditor recognizes the need to report to the audit committee when management integrity is in question.

Internal Audit's Role in the Ethical Framework

Internal audit contributes to organizational ethics in several concrete ways:

1. Assuring the ethics and compliance program

Engagements may evaluate whether the code is current and acknowledged, whether training completion is real, whether hotline cases are logged and investigated timely, whether conflicts disclosures are reviewed, and whether remediation closes control gaps. Criteria include laws/regulations, the organization's policies, and recognized program benchmarks.

2. Advising on program improvements

Advisory work might help management design escalation protocols, map compliance obligations, or facilitate a control self-assessment. Advisory support must not make internal audit the de facto compliance owner.

3. Modeling professional ethics

Auditors themselves must follow the IIA Code of Ethics—integrity, objectivity, confidentiality, and competency. An internal audit function that leaks confidential investigation details or soft-pedals findings about a powerful executive damages the organization's ethical framework.

4. Escalating ethical issues appropriately

If an engagement uncovers suspected fraud, bribery, harassment cover-ups, or regulatory breaches, auditors follow the charter, Standards, and investigation protocols. Evidence is preserved; scope may expand; communication goes to the appropriate level—including the board when senior management is implicated or unresponsive.

5. Coordinating with other assurance providers

Compliance, legal, HR, and external auditors may already be examining related issues. Internal audit should coordinate to avoid blind spots and duplicated noise, while protecting independence when evaluating second-line effectiveness.

Common Ethics and Compliance Risks Tested on Scenarios

Risk themeRed flagsControl / audit focus
Bribery and corruptionUnusual gifts, agent commissions, "facilitation" paymentsDue diligence, gift logs, payment testing, third-party audits
Conflicts of interestRelated-party vendors, undisclosed outside employmentDisclosure processes, procurement independence, board related-party oversight
Privacy / data misuseExcess access, shadow IT, weak retentionAccess reviews, DLP monitoring, incident response
Financial misconductEarnings pressure, late adjustments, override clustersJournal-entry testing, estimate challenge, tone assessment
Retaliation / speak-up failureDrop in hotline volume after a high-profile caseAnti-retaliation controls, case outcome quality, culture indicators
Regulatory noncomplianceExpired licenses, ignored exam findingsObligation inventory, control mapping, issue tracking to closure

Evaluating Program Effectiveness—Not Paper Compliance

A frequent IAP trap is equating existence with effectiveness. A code of conduct PDF on the intranet is not evidence that employees understand conflicts rules. Better evidence includes:

  • Sample testing of conflict disclosures against public or HR data.
  • Review of investigation files for timeliness, competence, documentation, and independence of investigators.
  • Analysis of whether similar offenses receive consistent consequences across ranks.
  • Verification that board packages include meaningful ethics metrics, not only vanity completion rates.
  • Walkthroughs of how a front-line employee would report a concern and what actually happens next.

When reporting results, connect ethics findings to risk and governance: explain how weaknesses increase fraud opportunity, regulatory exposure, or stakeholder trust erosion, and whether decision-makers have accepted risk knowingly or remain unaware.

When Compliance and Ethics Intersect with Culture (C2) and Governance (C1)

Ethics programs fail for cultural reasons as often as for technical ones. If leaders celebrate "win at all costs," training slides will not save the organization. Likewise, if the board never asks for independent ethics reporting, management can hide systemic issues. C3 questions may combine all three syllabus threads: a compliance breach, a cultural tolerance for exceptions, and a governance failure to oversee remediation.

Practical exam approach:

  1. Identify the requirement (law, policy, ethical standard).
  2. Identify who owns prevention, detection, and correction.
  3. Identify what internal audit should do (assure, advise, escalate)—and what it should not do (become the permanent compliance department or conceal issues to protect management).
  4. Choose the answer that preserves independence, board visibility, and management accountability.

Bottom Line for C3

Ethics and compliance are governance responsibilities executed through management systems and overseen by the board. Internal audit strengthens the ethical framework by independently evaluating whether that system works, by advising on gaps, and by communicating fearlessly when integrity risk threatens organizational value. Memorize the program components, keep role boundaries sharp, and always ask whether evidence shows real behavior—not just polished policy language.

Test Your Knowledge

Which statement best describes internal audit's appropriate role in the organization's ethical framework?

A
B
C
D
Test Your Knowledge

A code of conduct exists and annual training completion is 100%, but hotline cases about the same sales practice are closed without remediation and similar offenses are punished inconsistently by rank. What should internal audit emphasize?

A
B
C
D
Test Your Knowledge

During an engagement, internal audit obtains credible evidence that a senior executive directed concealment of a regulatory violation. What action best aligns with governance and ethics expectations?

A
B
C
D