Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Certifications & Roles

Chief Audit Executive

Also known as: CAE, Director, Internal Audit, Head of Internal Audit
Simply put

The Chief Audit Executive (CAE) is the most senior person in charge of an organization's internal audit function. This individual leads and directs the internal audit activity, which is intended to help enhance and protect the value of the organization. The role also involves managing the resources and staff needed to carry out internal audit work effectively.

Formal definition

The Chief Audit Executive (CAE) is the most senior executive with overall responsibility for an organization's internal audit activities, including establishing, leading, and directing an internal audit function positioned to enhance and protect organizational value. The role typically encompasses management of internal audit resources to help ensure that the internal audit activity fulfills its mandate. Governance considerations relating to the CAE role commonly include appointment, performance evaluation, and termination, reflecting the position's distinct standing within organizational oversight structures. The specific reporting lines, authority, and scope of the CAE role vary by organization and jurisdiction, and detailed requirements should be verified against applicable professional standards and the organization's own governance arrangements.

Why it matters

The Chief Audit Executive occupies a distinctive position within an organization's governance structure because the internal audit function it leads is intended to enhance and protect organizational value through independent assurance. The seniority and standing of the role reflect the importance many organizations place on having an internal audit activity that can operate with sufficient authority to examine risks and controls across the enterprise. Where the CAE role is well established, it can serve as a focal point for objective evaluation that supports the board, audit committee, and senior management in their oversight responsibilities.

Because of this distinct standing, governance considerations surrounding the CAE, including how the individual is appointed, how performance is evaluated, and how termination is handled, receive particular attention in professional guidance. These matters are often treated differently from those affecting other management positions, reflecting the position's role within organizational oversight structures. Careful attention to these arrangements is commonly viewed as important to preserving the objectivity that gives internal audit work its value.

The specific authority, reporting lines, and scope attaching to the CAE role vary by organization and jurisdiction. As a result, the practical significance of the role in any given setting depends on the organization's own governance arrangements and any applicable professional standards, which should be verified against primary sources rather than assumed.

Who it's relevant to

Boards and Audit Committees
Those charged with oversight often have a direct interest in the CAE role, given that appointment, performance evaluation, and termination of the CAE are commonly treated as governance matters. Understanding the role helps oversight bodies establish arrangements that support the internal audit function's ability to enhance and protect organizational value.
Internal Audit Professionals
Members of the internal audit activity report into the CAE, who leads and directs their work and manages the resources needed to fulfill the function's mandate. Aspiring and current internal auditors benefit from understanding the seniority and responsibilities the role carries.
Senior Management
Executives interact with the CAE as the individual responsible for internal audit activities across the organization. Clarity on the role supports effective working relationships while respecting the distinct standing of the internal audit function within oversight structures.
Governance, Risk, and Compliance Professionals
GRC practitioners work alongside the internal audit function and benefit from understanding how the CAE role is positioned and how its associated governance considerations, such as appointment and evaluation, fit within broader organizational oversight arrangements, which vary by organization and jurisdiction.

Inside CAE

Role Definition
The Chief Audit Executive (CAE) is the senior individual responsible for leading and directing the internal audit function, providing independent and objective assurance and advisory services regarding an organization's governance, risk management, and control processes. The title and precise scope may vary by organization.
Organizational Independence
The CAE typically holds a dual reporting relationship, reporting functionally to the board or its audit committee and administratively to senior management (often the CEO). This structure is intended to support the objectivity and independence of the internal audit function, though specific arrangements vary by organization and jurisdiction.
Assurance and Advisory Scope
The CAE oversees the delivery of assurance activities that evaluate the effectiveness of governance, risk management, and internal control, and may also provide advisory services. This spans all three GRC pillars but does not make the CAE the owner of those risks or controls, which typically rests with management.
Audit Planning and Prioritization
The CAE is commonly responsible for developing a risk-based internal audit plan, allocating resources, and prioritizing engagements according to the organization's risk profile. The plan is often reviewed or approved by the audit committee.
Reporting and Communication
The CAE communicates audit results, significant findings, and the overall state of the control environment to the board, audit committee, and senior management, and often confirms the internal audit function's independence to the board.
Function Governance and Quality
The CAE is generally accountable for the internal audit charter, conformance with applicable professional standards and internal policies, and maintaining a quality assurance and improvement program, subject to the frameworks and standards adopted by the organization.

Common questions

Answers to the questions practitioners most commonly ask about CAE.

Does the Chief Audit Executive design and operate the organization's controls?
No. The CAE typically leads the internal audit function, which provides independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and control processes. Designing, implementing, and operating controls is generally a management responsibility. If the CAE were to own controls, it would compromise the independence and objectivity that internal audit is expected to maintain. In many governance models, this separation reflects the distinction between those who manage risk and those who provide assurance over how it is managed.
Is the Chief Audit Executive the same as the compliance officer or the head of risk?
Not typically. These roles address different, though related, responsibilities. A compliance function generally focuses on adherence to external laws, regulations, and internal policies; a risk function generally focuses on identifying, assessing, and treating uncertainty against objectives; and internal audit, led by the CAE, generally provides independent assurance over the effectiveness of both, along with governance and control processes more broadly. Conflating these roles can undermine the independence internal audit is expected to preserve. The precise allocation of responsibilities varies by organization, sector, and jurisdiction.
To whom should the Chief Audit Executive report to protect independence?
Many governance frameworks and professional standards emphasize a dual reporting relationship to protect independence: a functional reporting line to the audit committee or equivalent governing body, and an administrative reporting line to a member of senior management. The functional line, often to the board or audit committee, is generally intended to reinforce the CAE's ability to report findings without undue management influence. Specific arrangements vary by organization size, structure, and applicable regulatory expectations, and should be confirmed against the relevant standards and any binding requirements in the applicable jurisdiction.
How does the Chief Audit Executive establish an audit plan?
In common practice, the CAE develops a risk-based audit plan that prioritizes areas according to their significance to the organization's objectives and risk profile, rather than auditing all areas equally. This often involves input from management, the risk function, and the audit committee, and is typically reviewed and approved by the governing body. Many frameworks suggest the plan remain flexible so it can respond to emerging risks during the period. The methodology and cadence vary by organization and should align with applicable professional standards.
How can a Chief Audit Executive provide advisory services without impairing objectivity?
Internal audit functions often provide both assurance and advisory (consulting) services. To help preserve objectivity, many professional standards suggest that the CAE avoid assuming management responsibilities, clearly distinguish advisory work from assurance work, and consider whether prior involvement in a process could affect the objectivity of later assurance over that same process. Some organizations document safeguards, such as disclosing potential impairments to the audit committee. The appropriate approach depends on the nature of the engagement and applicable standards.
What is the Chief Audit Executive's role in reporting findings to the governing body?
The CAE commonly communicates audit results, significant findings, and the status of remediation to senior management and the audit committee or equivalent governing body. Many frameworks emphasize timely, candid reporting, including matters where management's response to identified issues may be inadequate. The CAE often also reports on the internal audit function's own performance, resourcing, and conformance with applicable professional standards. Reporting formats and frequency vary by organization and are typically set in coordination with the audit committee.

Common misconceptions

The CAE owns and manages the organization's risks and controls.
In many governance models, ownership of risks and controls rests with management (often described as the first and second lines), while the CAE and internal audit provide independent assurance over how those risks and controls are managed. The CAE evaluates rather than owns these processes; conflating the two can undermine the function's independence.
Internal audit and the CAE are part of the compliance function.
Compliance concerns adherence to external laws, regulations, and internal policies and is typically a management responsibility, whereas internal audit provides independent assurance that may include evaluating the compliance function itself. Positioning the CAE within compliance can compromise the objectivity expected of the audit role.
The CAE's reporting line to management makes internal audit management-controlled.
The CAE typically maintains a functional reporting line to the board or audit committee alongside an administrative line to management. This dual arrangement is intended to preserve independence; the functional relationship generally governs matters such as the audit plan, results, and the CAE's appointment or removal, though specifics vary by organization.

Best practices

Establish and periodically reaffirm a functional reporting line from the CAE to the board or audit committee, with an administrative line to senior management, to support organizational independence.
Maintain a board-approved internal audit charter that clearly defines the function's purpose, authority, scope, and responsibilities, and review it periodically.
Develop a risk-based audit plan aligned to the organization's risk profile, and present it to the audit committee for review or approval.
Communicate significant findings, the overall state of governance, risk, and control, and any impairments to independence directly to the board or audit committee.
Preserve the distinction between assurance and management ownership by ensuring the CAE evaluates rather than assumes responsibility for the risks and controls being audited.
Operate a quality assurance and improvement program to assess conformance with the professional standards and internal policies the organization has adopted, verifying specific requirements against the primary source.
Promotional banner for the Penetration Report Template Kit