Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Internal Controls & Audit

Global Internal Audit Standards

Also known as: The Standards, IIA Global Internal Audit Standards, 2024 Global Internal Audit Standards
Simply put

The Global Internal Audit Standards are a set of professional guidelines issued by The Institute of Internal Auditors (IIA) that direct how internal auditing should be practiced around the world. They provide a common basis for evaluating and improving the quality of an internal audit function's work. Because they are principle-based, they describe expectations for professional practice rather than serving as a law or regulation.

Formal definition

The Global Internal Audit Standards, published by The Institute of Internal Auditors (IIA), are principle-based statements of basic requirements for the professional practice of internal auditing and for evaluating the effectiveness of its performance. According to the IIA, internal auditing is defined as an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. The 2024 edition is organized into five domains, including the Purpose of Internal Auditing, Ethics and Professionalism, and Governing the Internal Audit function, among others noted by the IIA. As a voluntary professional standard rather than a binding legal requirement, applicability and the extent of adoption typically vary by organization, sector, and jurisdiction; practitioners should consult the primary IIA source for the complete and current set of domains, principles, and requirements.

Why it matters

Internal auditing operates across a vast range of organizations, sectors, and jurisdictions, and without a common frame of reference the quality and scope of audit work could vary widely from one function to another. The Global Internal Audit Standards, issued by The Institute of Internal Auditors (IIA), provide that shared foundation. By articulating principle-based expectations for professional practice, they give internal audit functions, their stakeholders, and oversight bodies a consistent basis for evaluating and elevating the quality of audit work worldwide.

For governance purposes, the Standards matter because internal audit is a key element of the assurance an organization's board and senior management rely upon. Internal auditing is defined by the IIA as an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. Standards that address the purpose of internal auditing, ethics and professionalism, and the governing of the internal audit function help support the independence and objectivity on which the credibility of that assurance depends.

It is important to recognize that the Standards are a voluntary professional standard rather than a binding law or regulation. Their authority derives from professional adoption and, in some cases, from being referenced by regulators, standard-setters, or organizational policy. The extent to which they are adopted and enforced typically varies by organization, sector, and jurisdiction, and practitioners should treat them as a benchmark for professional practice rather than as a legal obligation in themselves.

Who it's relevant to

Internal auditors and audit function leaders
Internal auditors and chief audit executives rely on the Standards as the primary reference for how their work should be planned, conducted, and evaluated. The Standards inform expectations around independence, objectivity, and professional practice, and provide a basis against which the quality and effectiveness of the audit function can be assessed.
Boards and audit committees
Those charged with governance depend on internal audit for independent, objective assurance about an organization's operations. Familiarity with the Standards helps boards and audit committees understand what they can reasonably expect from the internal audit function and how its performance may be evaluated, particularly with respect to the governing of the internal audit function.
Senior management
Executives who receive internal audit assurance and consulting services benefit from understanding the Standards because they set expectations for how internal auditing adds value and supports the improvement of an organization's operations, while preserving the independence that underpins the function's credibility.
Compliance and risk professionals
Compliance officers and risk managers often coordinate with internal audit as part of an organization's broader assurance activities. Understanding the principle-based nature of the Standards, and that they are a voluntary professional standard rather than a binding regulation, helps these professionals position internal audit appropriately alongside other lines of assurance and regulatory obligations that vary by jurisdiction and sector.

Inside Global Internal Audit Standards

Purpose and Mission of Internal Auditing
A foundational articulation of why the internal audit function exists, typically framing it as an activity intended to enhance and protect organizational value by providing independent and objective assurance, advice, and insight. This element sets the overarching intent against which the more detailed elements are read.
Ethics and Professionalism Principles
Principles addressing the conduct expected of internal auditors, commonly encompassing integrity, objectivity, confidentiality, and competency. These elements are generally intended to underpin the trust that stakeholders place in audit work; specific requirements should be verified against the primary source.
Governance of the Internal Audit Function
Provisions concerning the relationship between the internal audit function and the board (or an equivalent oversight body) and senior management, including matters such as the audit charter, mandate, and reporting lines. This element sits at the governance pillar, addressing decision rights and oversight structures rather than the conduct of individual engagements.
Managing the Internal Audit Function
Elements addressing how the chief audit executive plans, resources, and directs the function, including strategy, risk-based planning, and quality assurance. This component connects the function's mandate to its operational delivery.
Performing Internal Audit Services
Elements covering how individual engagements are planned, executed, and communicated, including engagement scoping, evidence gathering, and reporting of results and follow-up. These provisions govern the day-to-day methodology of assurance and advisory work.
Independence and Objectivity
Requirements intended to preserve the function's freedom from conditions that could impair the ability to carry out responsibilities in an unbiased manner. Independence typically refers to organizational positioning, while objectivity refers to the individual auditor's mental attitude; the Standards generally treat these as related but distinct concepts.

Common questions

Answers to the questions practitioners most commonly ask about Global Internal Audit Standards.

Do the Global Internal Audit Standards replace the earlier International Standards for the Professional Practice of Internal Auditing?
The Global Internal Audit Standards represent a consolidated and restructured successor to the prior body of guidance issued by the Institute of Internal Auditors, which historically included the International Standards for the Professional Practice of Internal Auditing (often referenced as part of the International Professional Practices Framework). Rather than viewing the newer Standards as an entirely unrelated document, it is more accurate to understand them as a reorganization that brings previously separate elements into a more unified structure. Practitioners should confirm the current effective arrangement and transition expectations directly against the primary source issued by the standard-setter, since the precise scope of what was superseded and when should be verified rather than assumed.
Does conforming with the Global Internal Audit Standards satisfy an organization's regulatory compliance obligations?
No. The Global Internal Audit Standards are professional standards for the internal audit activity, not a binding legal or regulatory instrument in themselves. Conformance addresses the quality and professionalism of the internal audit function; it does not, on its own, discharge an organization's obligations under applicable laws, regulations, or sector-specific supervisory requirements. In some jurisdictions or sectors, regulators or listing rules may reference or expect adherence to recognized internal audit standards, but that linkage varies by context. Conformance with these Standards and compliance with external legal obligations are distinct matters, and the latter typically requires separate assessment, often with legal advice.
How should an internal audit function begin assessing its current state against the Standards?
A common starting point is a structured gap assessment that maps existing practices, charters, methodologies, and quality arrangements against the requirements and expectations expressed in the Standards. Many functions document where practices already align, where partial alignment exists, and where changes are needed, then prioritize remediation based on significance and feasibility. Because interpretations can be context-dependent, functions often reference the standard-setter's own supporting and implementation guidance and confirm how specific provisions apply to their size, sector, and operating model. The scope of any assessment, and any conclusions about conformance, should be defined explicitly.
What role does the board or audit committee play in supporting conformance with the Standards?
The Standards generally emphasize the relationship between the internal audit function and those charged with governance, which typically includes a board or an audit committee. In many organizations, this body is expected to support internal audit's independence and objectivity, approve or endorse elements such as the internal audit mandate or charter, and engage on resourcing and the audit plan. The precise governance arrangements vary by jurisdiction, organizational form, and sector, so functions should confirm how the Standards' expectations map to their own governance structure and any applicable legal or listing requirements that shape the audit committee's responsibilities.
How does a function demonstrate conformance, and what is the role of a quality assessment?
Demonstrating conformance typically involves ongoing internal monitoring together with periodic assessments of the internal audit activity's quality, which may include external evaluation. Many functions maintain evidence such as methodologies, working papers, and quality program records to support statements about conformance. Where a function wishes to represent that it conforms with the Standards, it is generally expected to have a basis for that representation grounded in its quality arrangements. The specific frequency, form, and independence expectations for such assessments should be verified against the current text of the Standards, as these requirements are detailed there rather than assumed.
How can a smaller internal audit function apply the Standards proportionately?
The Standards are intended to apply across internal audit activities of differing sizes and complexity, and proportionate application is a common practical concern for smaller functions or those with limited resources. In practice, smaller functions often focus on meeting the substance of the requirements while scaling the formality of processes to their context, for example through streamlined documentation or by drawing on external support for certain assessments. Because expectations around scalability and how requirements apply to small teams can be nuanced, functions should consult the standard-setter's guidance and confirm how specific provisions are intended to operate in their circumstances rather than assuming exemptions.

Common misconceptions

The Global Internal Audit Standards are a binding law that all organizations must follow.
The Standards are professional standards issued by a standard-setting body for the internal audit profession, not a statute or regulation. Their applicability often derives from adoption by an organization, professional membership, or a regulator or listing rule that references them, rather than from the Standards themselves being law. Whether and how they apply varies by jurisdiction, sector, and organization, and legal obligations should be confirmed against applicable local requirements.
Following the Standards guarantees that risks are eliminated or that the organization is compliant.
Internal auditing typically provides assurance, advice, and insight; it is an oversight and evaluation activity rather than a control that itself removes risk or ensures compliance. Conformance with the Standards is intended to improve the quality and reliability of audit work, but no framework can guarantee outcomes, and audit findings are subject to the limitations of scope, evidence, and judgment.
Internal audit and the risk management or compliance functions are the same thing.
These functions occupy different roles. Risk management concerns identifying, assessing, and treating uncertainty against objectives, and compliance concerns adherence to laws, regulations, and policies, whereas internal audit typically provides independent evaluation of the effectiveness of governance, risk management, and control processes. Blurring these roles can compromise the independence and objectivity the Standards seek to protect.

Best practices

Establish and periodically review an internal audit charter approved by the board or equivalent oversight body, clearly documenting the function's mandate, authority, and reporting lines to support independence.
Maintain a risk-based audit plan that links engagements to the organization's significant risks and objectives, and revisit it as those risks change rather than treating it as fixed.
Safeguard independence and objectivity by managing reporting relationships and by identifying and addressing potential impairments, such as auditing areas for which an auditor previously held operational responsibility.
Implement a quality assurance and improvement program, including internal monitoring and, where applicable, periodic external assessment, and confirm the expected form and frequency against the primary source.
Clearly distinguish internal audit's assurance role from the risk management and compliance functions in charters, plans, and communications to avoid role conflation that could undermine objectivity.
Verify specific requirements, defined terms, and effective dates directly against the current published edition of the Standards, since framework language evolves across editions and applicability varies by jurisdiction and sector.
Promotional banner for the Penetration Report Template Kit