The Four Ethical Principles Every Internal Auditor Must Protect: Integrity, Objectivity, Confidentiality and Competency
- John Blackshire
- 15 hours ago
- 8 min read
Internal Audit Cannot Provide Assurance Without Trust
Internal Auditors spend a great deal of time discussing methodology.
Risk assessments. Internal controls. Walkthroughs. Sampling. Data analytics. Workpapers. Findings. Recommendations. Audit reports.
All of those matter.
But underneath the entire Internal Audit profession is something more fundamental:
Can stakeholders trust the auditor?
An Internal Auditor can understand COSO, perform excellent data analytics, write technically sophisticated findings, and produce impressive reports. None of that compensates for an auditor who lacks integrity, allows personal interests to influence conclusions, mishandles confidential information, or accepts assignments the auditor is not competent to perform.
The Institute of Internal Auditors historically expressed this ethical foundation through four familiar principles in its Code of Ethics:
Integrity
Objectivity
Confidentiality
Competency
These principles remain an excellent framework for thinking about the behavior expected of an Internal Auditor.
They also raise a harder question:
What do these principles actually require when an auditor encounters pressure, disagreement, sensitive information, or an assignment beyond the auditor's expertise?
That is where ethics moves from theory to audit practice.
1. Integrity: Will You Tell the Truth When the Truth Is Uncomfortable?
The first principle is Integrity.
Integrity establishes trust in the auditor and provides the foundation for reliance on the auditor's judgment.
That sounds obvious.
Almost everyone describes themselves as having integrity.
The real test comes when integrity becomes expensive.
Imagine an auditor discovers a significant control deficiency involving a senior executive.
Management responds:
“This doesn't need to be in the report.”
Or:
“You're making this sound much worse than it is.”
Or:
“Change the risk rating and we'll take care of it internally.”
Now integrity has become an audit issue.
The auditor must decide whether the report will reflect the evidence or organizational pressure.
Integrity Means Following the Evidence
Internal Auditors should be able to explain the chain supporting their conclusions:
Objective
↓
Risk
↓
Procedure
↓
Evidence
↓
Finding
↓
Conclusion
The conclusion should follow the evidence.
It should not follow:
Management preference
Organizational politics
Personal relationships
Fear of confrontation
Career considerations
Pressure from the auditee
If the evidence supports a finding, the auditor should not bury it.
If the evidence does not support a finding, the auditor should not manufacture one.
Both require integrity.
Integrity Also Means Admitting When You Are Wrong
Auditors are human.
They can misunderstand a process.
They can misinterpret evidence.
They can reach a preliminary conclusion that later proves incorrect.
Integrity therefore includes being willing to say:
“The additional evidence changed my conclusion.”
That isn't weakness.
That is auditing.
An auditor who becomes emotionally invested in proving an initial finding may stop objectively evaluating contradictory evidence.
The objective isn't to win the argument.
The objective is to get the conclusion right.
2. Objectivity: The Auditor Must Be Willing to Follow Evidence in Either Direction
Objectivity is closely related to integrity, but it presents a different challenge.
Internal Auditors are expected to make balanced assessments of relevant circumstances without being unduly influenced by their own interests or those of others.
That means objectivity has two enemies:
External pressure
and
Internal bias.
Auditors tend to recognize the first.
They sometimes overlook the second.
Management Pressure Can Threaten Objectivity
Suppose an audit identifies a serious problem.
The process owner explains:
“We're understaffed.”
That may be true.
But it doesn't necessarily change the condition.
Management says:
“We've never had a loss.”
That may also be true.
It doesn't necessarily mean the control is adequately designed.
Management says:
“Everyone in the industry does it this way.”
Again, perhaps.
That doesn't prove the risk is appropriately controlled.
Objectivity requires the auditor to distinguish between:
Explanation
and
Evidence.
Confirmation Bias Can Affect Auditors Too
Auditors need to be careful about assuming bias exists only on the other side of the table.
Suppose an auditor begins an engagement believing:
“This department has terrible controls.”
The auditor may unconsciously give more weight to evidence supporting that belief and less weight to evidence contradicting it.
That is confirmation bias.
AI can make this problem worse if used badly.
An auditor who asks an AI tool:
“Find everything wrong with this process.”
has already biased the analytical assignment.
A better approach is:
“Identify evidence supporting and contradicting the preliminary conclusion. Develop the strongest reasonable argument against the proposed finding.”
That's a much stronger use of AI—and a much stronger application of objectivity.
Auditors Should Red-Team Their Own Findings
Before issuing a significant finding, ask:
What evidence contradicts my conclusion?
What would management's strongest argument be?
Have I investigated that argument?
Am I treating management's explanation fairly?
Does the evidence support the risk rating?
Would another experienced auditor reach a similar conclusion from these workpapers?
Objectivity does not require the auditor to compromise.
It requires the auditor to be fair.
There is a major difference.
3. Confidentiality: Access Creates Responsibility
Internal Auditors often have extraordinary access within an organization.
They may see:
Payroll records
Employee information
Investigation files
Legal matters
Cybersecurity vulnerabilities
Customer information
Vendor banking information
Executive communications
Strategic plans
Fraud allegations
Financial forecasts
Audit Committee communications
Access is necessary to perform Internal Audit work.
But access creates responsibility.
The principle of Confidentiality requires auditors to respect the value and ownership of information and avoid inappropriate disclosure.
“I Have Access” Does Not Mean “I Can Share It”
Internal Auditors sometimes possess information that would be extremely interesting to other people.
That doesn't make disclosure appropriate.
An auditor should continually distinguish between:
Need to know
and
Want to know.
Sensitive audit information should be communicated to people who have an appropriate business, governance, professional, or legal reason to receive it.
Not everyone who asks qualifies.
Confidentiality Becomes More Complicated With AI
Generative AI has made this principle considerably more important.
An auditor may be tempted to paste sensitive information into an AI system and ask:
“Summarize this investigation.”
or:
“Write this finding.”
or:
“Analyze these employee transactions for fraud.”
Before doing so, the auditor needs to understand the organization's AI governance requirements.
Questions should include:
Is this AI system approved?
What information can be entered?
Is confidential information permitted?
Is personally identifiable information permitted?
How is submitted information retained?
Can it be used for model training?
Who can access it?
What contractual protections exist?
Does organizational policy permit this use?
The fact that AI can analyze the information does not mean the auditor is authorized to provide it.
Confidentiality obligations do not disappear because a new technology is convenient.
Workpapers Require Confidentiality Too
Audit workpapers can contain some of the organization's most sensitive information.
That means Internal Audit should think carefully about:
Access rights
Retention
Distribution
Electronic security
Report distribution
Third-party access
Disposal
Good evidence management is part of ethical auditing.
4. Competency: Knowing What You Don't Know Is an Audit Skill
The fourth principle may be the most underestimated: Competency.
Internal Auditors are expected to apply the knowledge, skills, and experience necessary to perform Internal Audit services.
That doesn't mean every auditor needs to know everything.
Nobody does.
It means the audit function must recognize when an assignment requires expertise it does not possess.
The Dangerous Auditor Isn't Always the Inexperienced Auditor
Sometimes the most dangerous auditor is the person who doesn't know that they don't know enough.
Consider assignments involving:
Cybersecurity
Artificial intelligence
Complex derivatives
Actuarial estimates
Cloud computing
AML
Insurance regulation
Federal grants
Construction
Tax
Healthcare regulation
An auditor may understand risk and controls extremely well and still lack the technical expertise necessary to evaluate a specialized subject.
The ethical response isn't to bluff.
It is to obtain the necessary competence.
That could mean:
Additional training
Technical research
Subject-matter specialists
Co-sourcing
External expertise
Changes to the audit team
Competency Includes Communication Skills
Technical knowledge alone does not make someone a competent Internal Auditor.
Auditors also need to know how to:
Interview people
Conduct walkthroughs
Ask follow-up questions
Recognize evasive answers
Evaluate contradictory evidence
Document conclusions
Communicate findings
Handle disagreement
Present to executives
Explain risk to an Audit Committee
A technically brilliant auditor who cannot get to the facts has a competency problem.
An auditor who identifies the right issue but cannot communicate it effectively also has a competency problem.
AI Changes the Definition of Auditor Competence
AI is creating another dimension of competency.
Increasingly, Internal Auditors need to understand how to use AI without becoming dependent upon it.
That includes knowing:
How to construct effective prompts
How to verify AI-generated information
How to protect confidential data
How to recognize hallucinations
How to challenge AI conclusions
How to document AI-assisted work
When AI should not be used
An auditor who blindly accepts an AI-generated answer has not delegated professional judgment.
The auditor has abandoned it.
AI can increase auditor competence by helping analyze information, identify patterns, generate questions, challenge conclusions, and improve communication.
But the professional remains responsible for the work.
The Four Principles Work Together
These principles should not be viewed as four separate boxes on an ethics checklist.
They reinforce one another.
Consider a difficult audit finding involving a senior executive.
Integrity requires the auditor to report what the evidence supports.
Objectivity requires the auditor to fairly evaluate both supporting and contradictory evidence.
Confidentiality requires the auditor to protect sensitive information obtained during the investigation.
Competency requires the auditor to possess—or obtain—the expertise necessary to reach a defensible conclusion.
Remove any one of the four and the audit can fail.
Ethics Gets Hard When Organizational Pressure Appears
Most ethics training uses situations where the correct answer is obvious.
Real organizational ethics is frequently more subtle.
Nobody necessarily tells the auditor:
“Violate your professional ethics.”
Instead, the pressure sounds like:
“Could you soften the wording?”
“Do we really need to tell the Audit Committee?”
“Let's give management another quarter.”
“That isn't really within your scope.”
“You're technically right, but you don't understand the politics.”
“Don't make this bigger than it needs to be.”
Some of those statements may occasionally reflect legitimate considerations.
Others may represent attempts to influence the audit.
The auditor has to know the difference.
That's why ethics requires judgment.
The Audit Committee Has a Role in Auditor Ethics
Internal Auditor ethics cannot depend solely upon the courage of an individual auditor.
Governance matters.
An effective Audit Committee should help create an environment in which Internal Audit can exercise:
Integrity
Objectivity
Confidentiality
Competency
without inappropriate management interference.
That includes protecting Internal Audit's organizational independence and providing a path for escalation when significant disagreements cannot be resolved with management.
A technically strong Internal Audit function operating under weak governance can still be compromised.
Ethical auditing therefore requires both ethical auditors and an effective governance structure.
Ask Four Questions Before Issuing the Report
Before completing a significant audit, the auditor might perform a simple ethical quality-control review.
Integrity
Does this report say what the evidence actually supports?
Objectivity
Have we fairly considered evidence and arguments that contradict our conclusion?
Confidentiality
Have we appropriately protected and distributed the information obtained during the audit?
Competency
Did the audit team possess the knowledge, skills, experience, and technical expertise necessary to perform this work?
If the answer to any of those questions is no, the engagement may not be ready to close.
The Bottom Line: Internal Audit Sells Trust
Internal Auditors do not manufacture products.
They provide assurance.
And assurance has value only when stakeholders trust the people providing it.
That's why these four principles remain so powerful:
Integrity establishes whether stakeholders can trust the auditor's character.
Objectivity establishes whether they can trust the auditor's judgment.
Confidentiality establishes whether they can trust the auditor with sensitive information.
Competency establishes whether they can trust the auditor's professional ability.
Internal Audit can have sophisticated software, advanced analytics, AI tools, excellent methodologies, and beautifully designed reports.
But none of those substitutes for ethical behavior.
When an Audit Committee receives an Internal Audit report, its members ultimately need to believe something very simple:
These auditors told us what they found, evaluated it fairly, protected the information entrusted to them, and knew what they were doing.
That is the foundation upon which Internal Audit's credibility is built.
And once that credibility is lost, it can be extraordinarily difficult to get back.
Comments