Skip to main content
Category: Internal Audit

Global Internal Audit Standards

Also known as: The Standards, IIA Global Internal Audit Standards, 2024 Global Internal Audit Standards
Simply put

The Global Internal Audit Standards are a set of professional standards issued by The Institute of Internal Auditors (IIA) to guide how internal auditing is practiced worldwide. They set out basic requirements for doing internal audit work well and provide a basis for evaluating the quality and effectiveness of that work. They are principle-based, meaning they describe expected outcomes and requirements rather than prescribing every specific procedure.

Formal definition

Issued by The Institute of Internal Auditors (IIA), the Global Internal Audit Standards are principle-based statements of the basic requirements for the professional practice of internal auditing and for evaluating the effectiveness of its performance. The 2024 edition is organized into five domains: Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services. As applied within the IIA's definition, internal auditing is an independent, objective assurance and consulting activity intended to add value and improve an organization's operations; the Standards accordingly emphasize the independence and objectivity that distinguish this assurance function from the management activities and controls it evaluates. The Standards define requirements and expectations but do not, in themselves, prescribe audit tooling, detailed methodologies, or organization-specific implementation, and their adoption or mandatory status may vary by jurisdiction, sector, and organizational arrangement.

Why it matters

Internal auditing occupies a distinct position within an organization's governance and assurance arrangements: it is intended to provide independent, objective assurance and consulting that adds value and improves operations. Without a common professional benchmark, the quality and consistency of internal audit work would vary widely across organizations, sectors, and jurisdictions. The Global Internal Audit Standards, issued by The Institute of Internal Auditors (IIA), supply that benchmark by setting out the basic requirements for practicing internal auditing and for evaluating the effectiveness of its performance.

Because the Standards are principle-based, they describe expected outcomes and requirements rather than prescribing every procedure. This matters for practitioners and stakeholders alike: it allows the Standards to be applied across differing organizational structures while still providing a recognized reference against which the quality of an internal audit function can be assessed and elevated. Their emphasis on independence and objectivity also helps preserve the boundary between the assurance function and the management activities and controls it evaluates, which is central to the credibility of internal audit conclusions.

It is important to note that the Standards define requirements and expectations but do not themselves mandate specific audit tooling, detailed methodologies, or organization-specific implementation approaches. Whether adoption is mandatory, and how the Standards interact with other obligations, may vary by jurisdiction, sector, and organizational arrangement. Organizations should therefore consider the Standards alongside the legal and regulatory context in which they operate.

Who it's relevant to

Chief audit executives and internal audit functions
Those leading and staffing internal audit functions rely on the Standards as the professional benchmark for how internal auditing is governed, managed, and performed. The Standards inform how a function establishes its purpose, maintains independence and objectivity, and delivers assurance and consulting services, while leaving specific methodologies and tooling to be determined in context.
Boards, audit committees, and governing bodies
Governing bodies that provide oversight of internal audit can use the Standards as a reference for the expectations placed on the function, including the domains addressing governing and managing the internal audit function. They offer a recognized basis for assessing whether the internal audit function operates with appropriate independence and effectiveness.
Governance, risk, and compliance professionals
Risk managers, compliance officers, and governance specialists interact with internal audit as an independent assurance function. Understanding the Standards helps these professionals appreciate the distinct role of internal audit relative to management activities and the controls it evaluates, and how its conclusions are intended to add value and improve operations.
Quality assessors and reviewers
Those who evaluate the quality and effectiveness of an internal audit function use the Standards as the criteria against which performance is measured, consistent with their stated purpose as a basis for evaluating and elevating the quality of internal audit work.

Inside Global Internal Audit Standards

Purpose and Mission of Internal Auditing
Foundational content articulating why internal auditing exists, commonly framed around enhancing and protecting organizational value through independent, objective assurance and advisory services. This sets the overarching intent against which more detailed requirements are read.
Ethics and Professionalism Principles
Elements addressing the conduct expected of internal auditors, typically including integrity, objectivity, competency, due professional care, and confidentiality. These support the objectivity that distinguishes an assurance function from the management activities it reviews.
Governance of the Internal Audit Function
Provisions concerning the relationship between the internal audit function, the board or an equivalent oversight body, and senior management, including the establishment of a mandate and the reporting lines that support functional independence.
Managing the Internal Audit Function
Content on how the chief audit executive plans, resources, and oversees the function, commonly encompassing strategy, risk-based planning, quality management, and reporting on the function's performance and conformance.
Performing Internal Audit Services
Requirements governing the conduct of individual engagements, typically covering planning, gathering sufficient and appropriate evidence, evaluating findings, communicating results, and monitoring the disposition of agreed actions.
Independence and Objectivity Requirements
Provisions intended to keep the internal audit function free from undue influence and individual auditors unbiased, reinforcing the separation between third-line assurance activity and the first- and second-line functions being assessed.

Common questions

Answers to the questions practitioners most commonly ask about Global Internal Audit Standards.

Are the Global Internal Audit Standards the same as the older International Standards for the Professional Practice of Internal Auditing (the IPPF Standards)?
No. The Global Internal Audit Standards, issued by the Institute of Internal Auditors (IIA), represent a consolidation and restructuring of prior guidance that had been organized under the International Professional Practices Framework, including the earlier International Standards for the Professional Practice of Internal Auditing. While there is substantial continuity in underlying principles, the Global Internal Audit Standards reorganize the material and should not be treated as merely a renamed version of the prior standards. Practitioners should refer to the current text rather than assuming one-to-one equivalence with earlier requirements.
Do the Global Internal Audit Standards make internal audit responsible for designing and operating the organization's controls?
No. This conflates an assurance function with management activities. The Global Internal Audit Standards position internal audit as an independent and objective assurance and advisory function; designing, implementing, and operating controls is a management responsibility. Internal audit evaluates the adequacy and effectiveness of governance, risk management, and control processes but does not own or operate those controls. Preserving this distinction is central to the independence and objectivity the Standards emphasize.
Who within an organization is expected to conform with the Global Internal Audit Standards?
The Standards are commonly applied to the internal audit function and the individuals performing internal audit activities, with the chief audit executive typically accountable for overall conformance. The Standards also address the responsibilities of the board or an equivalent oversight body and senior management in supporting the function's mandate and independence. The precise application within a given organization may depend on its structure, sector, and how the internal audit function is established.
How is conformance with the Global Internal Audit Standards typically demonstrated?
Conformance is commonly evidenced through a quality assurance and improvement program that includes internal assessments and periodic external assessments, as described in the Standards. Documentation of audit methodology, engagement work, and the chief audit executive's reporting on the function's performance and conformance to the board and senior management may support this. The specific evidence and cadence can vary by organization; this entry does not prescribe implementation specifics or particular tooling.
How should an internal audit function transition from prior IIA guidance to the Global Internal Audit Standards?
A transition commonly involves comparing existing methodology, policies, and procedures against the current text of the Standards to identify areas requiring updating, and revising the internal audit charter or mandate where appropriate. Organizations may also reassess their quality assurance and improvement program against current requirements. The appropriate approach depends on the function's maturity, resources, and oversight arrangements, and this entry does not offer step-by-step implementation guidance or legal advice.
How do the Global Internal Audit Standards relate to the three lines model?
The Global Internal Audit Standards address the internal audit function, which is commonly associated with the third line in the IIA's three lines model, providing independent assurance. The three lines model is a broader conceptual model describing roles across management, risk and compliance functions, and internal audit, whereas the Standards set out requirements specific to the practice of internal auditing. The two are complementary but distinct, and the Standards do not govern the activities of first or second line functions.

Common misconceptions

The standards apply only to internal auditors, so other governance and risk professionals can disregard them.
While the standards are addressed primarily to the internal audit function, they describe expectations of the board and senior management for enabling independence, mandate, and resourcing. Governance and management stakeholders therefore have a role in supporting conformance, even though they do not perform the audit work themselves.
Conforming to the standards guarantees that risks are controlled and compliance failures will be prevented.
Internal auditing provides independent assurance and advice; it does not own or operate controls. Management remains responsible for designing and operating controls and for treating risk. Conformance can improve the quality and credibility of assurance, but it does not by itself prevent control failures or guarantee outcomes.
The standards prescribe specific tools, technologies, or a single mandatory audit methodology.
The standards are principles- and requirements-based rather than a step-by-step methodology or tooling specification. Implementation approaches vary by organization size, sector, and jurisdiction, and the standards leave methodological and technological choices to professional judgment.

Best practices

Establish and periodically reaffirm a documented internal audit mandate approved by the board or equivalent oversight body, clarifying authority, scope, and reporting lines that protect functional independence.
Base the audit plan on a structured, risk-based assessment aligned to organizational objectives, and revisit it as risks and priorities change rather than treating it as fixed.
Maintain the separation between assurance and management activities, ensuring auditors do not assess controls for which they hold operational responsibility, and disclose any impairments to objectivity.
Implement a quality management approach that includes ongoing monitoring and periodic assessment of both conformance with the standards and the function's overall performance.
Ensure engagements are supported by sufficient and appropriate evidence, with findings, conclusions, and agreed actions communicated clearly to the appropriate stakeholders.
Track the disposition of agreed management actions after reporting, so that the assurance value of engagements is followed through without the function assuming responsibility for remediation itself.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide