Skip to main content
Category: Internal Audit

Internal Audit Charter

Also known as: Internal Audit Activity Charter
Simply put

An internal audit charter is a formal document that sets out the purpose, authority, and responsibilities of an organization's internal audit function. It acts as a foundational reference that explains what internal audit is meant to do and where its authority comes from. It is typically approved at a senior governance level, such as a board or audit committee.

Formal definition

An internal audit charter is a formal governing document that establishes the internal audit function's purpose, authority, position within the organization, scope of activities, and reporting relationships. In many organizations it defines internal audit's role in providing independent, objective assurance and advisory services intended to strengthen the organization's ability to create, protect, and sustain value, and it commonly affirms conformance with recognized professional standards, such as The IIA's Global Internal Audit Standards. The charter typically requires approval by the board or its audit committee and is periodically reviewed; it establishes internal audit's independence and objectivity relative to management, and does not itself perform or substitute for the audit work or the controls being audited. The IIA offers a model charter template to help internal auditors create and evaluate their charters; specific content, approval arrangements, and reporting lines vary by organization, jurisdiction, and sector.

Why it matters

The internal audit charter is the foundational document that establishes the legitimacy and boundaries of the internal audit function. Without a formal charter approved at a senior governance level, internal audit's authority to access records, personnel, and processes can be ambiguous, and its independence from the management activities it examines can be difficult to defend. By setting out purpose, authority, and responsibilities in writing, the charter helps ensure that internal audit can provide independent, objective assurance rather than being drawn into operational decision-making or having its scope quietly constrained by the very functions it is meant to evaluate.

The charter also anchors internal audit's independence and objectivity relative to management. Because it is typically approved by the board or its audit committee, it gives internal audit a reporting relationship and a mandate that does not depend on the goodwill of the executives whose areas may be audited. This governance arrangement is central to internal audit's credibility: the charter clarifies that internal audit assesses controls but neither designs nor operates them, keeping the assurance function distinct from the activities being audited.

Many charters also affirm conformance with recognized professional standards, such as The IIA's Global Internal Audit Standards, which signals to stakeholders that the work is performed by competent professionals against an accepted public-interest benchmark. Periodic review of the charter allows the function's mandate to keep pace with changes in the organization, its risk profile, and applicable expectations, though the specific arrangements vary by organization, jurisdiction, and sector.

Who it's relevant to

Chief Audit Executives and Internal Auditors
The charter defines the internal audit function's mandate, authority, and scope, giving auditors a formal basis for their access rights and independence. The IIA's model charter template is a practical starting point for drafting or evaluating a charter against professional standards.
Audit Committees and Boards
Because the charter is typically approved at this governance level, audit committees and boards use it to establish and oversee internal audit's purpose, independence, and reporting relationships, and to review it periodically as the organization and its risk profile change.
Governance and Compliance Professionals
The charter clarifies where internal audit sits within the organization's governance structure and how its independent assurance role is distinguished from management activities and from the controls being audited, which supports a clear separation of responsibilities.
Executive Management
The charter sets out internal audit's authority and independence relative to management, helping clarify the boundary between the functions management operates and the assurance internal audit provides over them.

Inside Internal Audit Charter

Purpose and Mission
A statement establishing why the internal audit function exists, typically framing its role in providing independent, objective assurance and advisory services designed to add value and improve the organization's operations.
Authority
A description of the internal audit function's mandate to access records, personnel, and physical property relevant to engagements, commonly granting unrestricted access necessary to fulfill its responsibilities.
Independence and Objectivity
Provisions safeguarding the function's organizational independence, often through a reporting relationship to the board or audit committee, and requiring individual auditors to maintain an objective, unbiased attitude free from conflicts of interest.
Scope of Activities
A definition of the range of assurance and consulting activities the function may perform, which may span governance, risk management, and control processes, while clarifying boundaries relative to management's own responsibilities.
Reporting Lines
Specification of both functional reporting (commonly to the board or audit committee) and administrative reporting (commonly to senior management), reflecting the dual relationships that support independence.
Roles and Responsibilities
Delineation of the responsibilities of the chief audit executive, the board or audit committee, and management in relation to the internal audit function.
Professional Standards Reference
A commitment to conform with recognized professional standards, such as those issued by the Institute of Internal Auditors, where the organization adopts them.
Approval and Review
A provision for periodic review of the charter and its approval by the board or audit committee, establishing its formal, authoritative status.

Common questions

Answers to the questions practitioners most commonly ask about Internal Audit Charter.

Does the internal audit charter give the internal audit function authority to manage or fix the risks and controls it reviews?
No. The charter typically establishes internal audit's purpose, authority, and responsibility as an independent and objective assurance and advisory function; it does not transfer ownership of risks or controls to internal audit. Managing and remediating risks and controls generally remains the responsibility of management (commonly the first and second lines under the IIA's three lines model), while internal audit provides assurance over those activities. Confusing the two would compromise the independence and objectivity that the charter is intended to protect.
Is the internal audit charter the same thing as an audit plan or audit program?
No. The charter is a foundational governance document that defines the internal audit function's mandate, authority, scope, reporting relationships, and standing over time. An audit plan (often risk-based and periodic) sets out which engagements will be performed in a given period, and an audit program details the procedures for a specific engagement. The charter provides the authority under which plans and programs are developed and executed, but it does not itself list individual audits or test steps.
Who typically approves the internal audit charter, and to whom does internal audit report under it?
In many governance arrangements the charter is approved by the board, commonly through its audit committee, which reinforces internal audit's independence from management. The charter typically documents a dual reporting relationship: a functional reporting line to the board or audit committee and an administrative reporting line to senior management (often the chief executive). Specific approval and reporting arrangements vary by organization, jurisdiction, and sector, so the charter should reflect the entity's actual governance structure.
What elements are commonly included in an internal audit charter?
Charters commonly address the function's purpose and mission; its authority, including rights of access to records, personnel, and property relevant to engagements; its scope of work covering assurance and advisory services; its position and reporting lines within the organization; requirements for independence and objectivity; responsibilities of the head of internal audit; and reference to the professional standards the function intends to follow. The precise contents may vary, and organizations often align them with recognized professional guidance rather than a single fixed template.
How often should the internal audit charter be reviewed?
The charter is typically reviewed periodically to confirm it remains appropriate and to reflect changes in the organization, its governance structure, or applicable professional standards. Many functions present the charter to the board or audit committee for periodic review and reaffirmation. This entry does not prescribe a specific frequency; organizations should set a review cadence consistent with their governance practices and any applicable requirements.
How does the charter support internal audit's independence and objectivity in practice?
By formally documenting reporting lines to the board or audit committee, defining authority and rights of access, and clarifying that internal audit does not hold operational responsibility for the areas it reviews, the charter helps insulate the function from undue influence. It sets expectations that engagements can be planned and conducted without management restricting scope. The charter supports these attributes but does not by itself guarantee them; independence and objectivity also depend on how the function is staffed, resourced, and operated.

Common misconceptions

The internal audit charter and the internal audit plan are the same document.
They are distinct. The charter is a foundational document that establishes the function's purpose, authority, and independence and is typically approved by the board or audit committee. The audit plan is a periodic, risk-based schedule of specific engagements. The charter provides the mandate under which plans are developed.
The charter gives internal audit responsibility for designing and operating the organization's controls.
Internal audit is an assurance function and is generally kept independent of the controls it evaluates. Designing, implementing, and operating controls are management responsibilities. Conflating the two would compromise the independence and objectivity the charter is meant to protect.
Every internal audit charter is essentially identical across organizations.
While charters share common components, their content varies with organizational structure, jurisdiction, sector, and the standards the organization chooses to adopt. Reporting lines, scope, and authority may be tailored to the specific governance context.

Best practices

Have the charter formally approved by the board or audit committee to reinforce the function's authority and independence, and record the approval date.
Review the charter periodically and after significant organizational or governance changes to confirm it remains accurate and relevant.
State reporting relationships explicitly, distinguishing functional reporting to the board or audit committee from administrative reporting to senior management.
Define the scope of both assurance and any advisory activities clearly, and articulate the boundary between internal audit's role and management's responsibility for controls.
Reference the professional standards the organization has adopted so that expectations for conduct, competence, and quality are unambiguous.
Ensure the authority section grants the access to records, personnel, and property that engagements require, while noting any jurisdictional or contractual constraints on that access.
Promotional banner for the Penetration Report Template Kit