I think it depends on your role in the organization. If you are a true compliance officer, where you assess risk, write policies, do QA reviews and provide help to departments you can really report to anyone.
If you are serving as a formal audit function there is only one area you should report to, and that is the BOD. If you are to be independent you should never be reporting to an internal employee. Additionally, if you are a true auditor, you are serving as a representative of the board and only the board.
_________________________
If your tagline references disclaimers regarding the nature of political posts, then you should just hit notify.