When Unrestricted Access Is Not Permitted

When Unrestricted Access Is Not Permitted

Every internal auditor knows the moment: the room goes quiet, and a client looks you straight in the eye and says,

“That information? Oh, that’s confidential. You can’t have it.”

It’s a situation that plays out more often than many expect particularly when dealing with sensitive areas like executive payroll.

The Institute of Internal Auditors’ Global Internal Audit Standards are explicit about this: auditors must have full and unrestricted access to any information relevant to the audit scope.

According to Standards 6.1–6.3, the board must authorize internal audit to access all records, personnel, and physical properties.

This requirement is the  cornerstone of audit independence and objectivity.

Yet in reality, a single “no” can stall an engagement and quickly escalate into a governance issue.

When “Confidential” Becomes a Roadblock

Our team once faced this challenge during a payroll audit.

The client refused to release executive payroll data, citing confidentiality concerns.

Technically, we had every right to insist. But doing so could have strained the relationship and undermined trust, something every audit function needs to protect.

So instead of escalating the issue immediately to senior leadership, we sought a practical middle ground that preserved both integrity and cooperation.

Finding a Balanced Solution

The first step was clarity of purpose. We made it clear to the client that our intent wasn’t to pry into executive salaries, it was to verify the effectiveness of internal controls.

Next, we proposed a pragmatic compromise.

Our team would review the design of the payroll process across all employees.

For testing, we would sample a few staff records to assess operational consistency.

However, for the highly sensitive executive data, only I, as the Chief Audit Executive (CAE), would review the details personally.

This solution respected the client’s confidentiality concerns while allowing the audit to proceed in full compliance with standards.

The outcome was constructive: we obtained the evidence needed, completed the engagement, and avoided unnecessary escalation to the CEO or Audit Committee.

Balancing Respect and Rigor

Situations like these often shows that internal audit is not just about technical accuracy but about professional diplomacy.

Being pragmatic doesn’t mean compromising standards. It means showing that you respect the client’s perspective while still upholding the integrity of your work.

Audit success often hinges on this balance, where firmness in principle meets flexibility in approach.

When we combine both, we not only protect the governance process but also strengthen the trust that allows internal audit to be a genuine partner in organizational improvement.