Skip to main content
Category: Internal Audit

Chief Audit Executive

Also known as: CAE, Director, Internal Audit, Head of Internal Audit
Simply put

The Chief Audit Executive (CAE) is the most senior person responsible for an organization's internal audit function. This individual leads the internal audit activity and typically reports to senior leadership and a board-level audit committee to help provide independent assurance over the organization's operations. The role commonly carries responsibility for how internal audit is resourced and directed.

Formal definition

The Chief Audit Executive (CAE) is the senior executive accountable for directing the internal audit activity within an organization. In many organizations the CAE is accountable both administratively and functionally through defined reporting lines, commonly reporting functionally to a board-level audit committee (or equivalent, such as a finance and audit committee) and administratively to senior management such as the president or chief executive, to preserve the independence and objectivity of the assurance function. The role commonly encompasses managing internal audit resources so that the activity fulfills its mandate, and is distinct from the management functions and controls that internal audit evaluates. This entry addresses the role and its positioning; it does not cover appointment, performance evaluation, and termination specifics, which are treated in dedicated guidance, nor jurisdiction- or sector-specific requirements that may apply.

Why it matters

The Chief Audit Executive occupies a distinctive position in an organization's governance structure because the role is designed to provide independent assurance over operations while remaining separate from the management functions and controls that internal audit evaluates. The value of the CAE role rests heavily on how it is positioned: reporting functionally to a board-level audit committee (or equivalent, such as a finance and audit committee) and administratively to senior management such as the president or chief executive. This dual reporting arrangement is intended to preserve the independence and objectivity of the assurance function, so that internal audit findings can be raised candidly without being subordinated to the operational areas under review.

When this positioning is weakened, for example, if the CAE reports solely into management without a functional line to the board, the assurance function's ability to escalate concerns independently can be compromised. Because the CAE directs how internal audit is resourced and mandated, the role also influences whether the internal audit activity has the capacity to fulfill its mandate across the organization. The role's importance therefore lies less in the individual's authority over operations, which is limited by design, and more in the credibility and independence of the assurance it provides to those charged with governance.

Who it's relevant to

Audit committees and boards
Board-level audit committees (or equivalents such as a finance and audit committee) commonly serve as the functional reporting line for the CAE. This relationship supports the independence of the internal audit activity and gives those charged with governance a direct channel to assurance findings.
Senior management
Senior leadership, such as the president or chief executive, typically serves as the CAE's administrative reporting line. Management interacts with the CAE while remaining aware that the internal audit activity is distinct from, and evaluates, the management functions and controls they oversee.
Internal audit professionals
The CAE leads the internal audit activity and directs how its resources are managed so the function can fulfill its mandate. Internal auditors operate within the direction and mandate the CAE establishes.
Governance and assurance practitioners
Professionals concerned with governance structures and independent assurance rely on the CAE role as a defined point of accountability for internal audit, positioned separately from the operations it reviews.

Inside CAE

Functional Reporting to the Board or Audit Committee
The CAE typically reports functionally to the board, commonly through its audit committee, which is intended to support the independence and objectivity of the internal audit function. This reporting line often covers approval of the internal audit charter, the audit plan, and decisions affecting the CAE's appointment, removal, and remuneration.
Administrative Reporting to Senior Management
In many organizations the CAE also has an administrative reporting line to a senior executive, frequently the chief executive officer, for day-to-day operational matters such as budgeting and internal communications. This dual-reporting arrangement is designed to balance operational integration with independence.
Third Line Responsibility
Under the IIA's three lines model, the CAE leads the internal audit function, which is generally positioned as the third line providing independent and objective assurance. This is distinct from first line operational management and second line risk and compliance functions.
Assurance and Advisory Scope
The CAE oversees an internal audit function that commonly provides assurance over governance, risk management, and control processes, and may also provide advisory services, provided that objectivity is maintained and management responsibilities are not assumed.
Internal Audit Charter and Plan
The CAE is typically responsible for establishing a charter that defines the internal audit function's purpose, authority, and responsibility, and for developing a risk-based audit plan that is often submitted for board or audit committee approval.

Common questions

Answers to the questions practitioners most commonly ask about CAE.

Does the Chief Audit Executive manage the organization's internal controls?
No. The CAE leads the internal audit function, which provides independent assurance over the design and operating effectiveness of controls. Designing, implementing, and operating controls is a management responsibility, typically residing in the first and second lines. Confusing these roles undermines the independence and objectivity that the CAE role is intended to preserve. In the three lines model articulated by the IIA, internal audit generally sits in the third line and does not own or operate the controls it evaluates.
Is the CAE the same as a compliance officer or head of risk?
No. Although these roles interact, they occupy different positions. A chief compliance officer and a chief risk officer are commonly second-line management functions that help design and monitor compliance and risk management activities. The CAE typically leads a third-line assurance function that independently evaluates the adequacy of governance, risk management, and control processes, including the work of those second-line functions. Combining these roles can compromise the independence expected of internal audit.
To whom should the CAE report to preserve independence?
In many governance frameworks and listing or regulatory expectations, the CAE reports functionally to the audit committee (or an equivalent oversight body of the board) and administratively to a senior executive such as the chief executive officer. This dual reporting is commonly used to protect the function's independence while enabling day-to-day operational support. Specific requirements vary by jurisdiction, sector, and organization size.
How is the internal audit plan typically developed and approved?
The CAE commonly develops a risk-based audit plan that allocates assurance resources to the areas of greatest risk to the organization's objectives. The plan is generally reviewed with senior management and approved by the audit committee, and it is often revisited periodically to reflect changes in the risk environment. The scope, frequency, and level of formality of this process may differ across organizations and regulatory contexts.
How can a CAE maintain independence when internal audit resources are limited?
Independence relates to organizational positioning and reporting lines, while objectivity relates to individual mindset; both should be maintained regardless of resource levels. Where resources are constrained, the CAE may prioritize higher-risk areas, consider co-sourcing or outsourcing certain engagements, and disclose any resource limitations and their potential effect on assurance coverage to the audit committee. Approaches vary and this does not constitute a recommendation for any specific staffing model.
What is the CAE's role when internal audit undertakes advisory or consulting work?
Internal audit functions sometimes perform advisory or consulting engagements in addition to assurance work. When they do, the CAE is commonly expected to safeguard objectivity, for example by avoiding assuming management responsibilities and by considering how prior advisory involvement may affect the ability to provide independent assurance over the same area later. Practices differ, and the boundary between advising and taking on management decisions should be managed carefully.
How does the CAE typically communicate results to governance bodies?
The CAE generally reports engagement results, significant findings, and the overall state of governance, risk management, and control to the audit committee and senior management, often through periodic reporting and escalation of significant matters. Reporting frequency, format, and content requirements vary by organization, sector, and applicable regulatory expectations.

Common misconceptions

The CAE is responsible for managing the organization's risks and controls.
The CAE leads an assurance function and does not own or manage risks and controls; that responsibility rests with management in the first and second lines. Assuming management responsibilities would compromise the independence and objectivity expected of internal audit.
The CAE is simply another member of senior executive management.
While the CAE may report administratively to a senior executive, the functional reporting line to the board or audit committee is intended to preserve independence. Positioning the CAE purely within executive management can undermine the objectivity of the third line.
Internal audit and the CAE serve the same purpose as compliance and external audit.
The CAE's internal audit function provides independent internal assurance over governance, risk management, and controls. This is distinct from second line compliance activities, which monitor adherence as a management function, and from external audit, which is an independent function typically focused on financial statements and mandated externally.

Best practices

Establish and periodically review an internal audit charter, approved by the board or audit committee, that clearly defines the CAE's purpose, authority, responsibility, and reporting lines.
Maintain a functional reporting line to the board or audit committee that covers appointment, removal, remuneration, and approval of the audit plan, in order to protect independence.
Develop a risk-based audit plan aligned to the organization's objectives and risk profile, and present it for board or audit committee approval.
Preserve objectivity by ensuring the internal audit function does not assume first or second line responsibilities for owning or managing risks and controls.
Clarify the distinction between the third line assurance role and second line compliance and risk functions to avoid overlap or gaps in coverage.
Communicate regularly and directly with the board or audit committee, including on significant findings and any restrictions on scope or resources that could impair the function.
Application Security Isn’t Optional Anymore.