The internal audit function is changing, driven partly by the evolving expectations of boards and regulators, and partly by the recognition that a function with genuine access to every corner of the organisation is poorly used if it only tells leadership what happened last quarter. The IIA's Global Internal Audit Standards, effective from January 2025, formalise this shift explicitly. Understanding what has changed, and what it demands in practice, matters for any organisation that wants its internal audit function to deliver what boards now expect from it.
The IIA published its revised Global Internal Audit Standards in January 2024, with an effective date of January 2025. The revision was the most substantial overhaul of the standards in many years and reflected a fundamental rethinking of the relationship between internal audit and the board, the function's scope, and its purpose within an organisation.
The new Global Internal Audit Standards are organised around six domains covering purpose, ethics and professionalism, governance, audit management, audit services, and communication and reporting. The structure represents a deliberate shift from a process-focused set of rules toward a more principles-based framework that places the function's value and purpose at the centre.
Several changes are particularly significant for organisations assessing whether their internal audit function is meeting the new standard.
The 2024 standards place the relationship between the chief audit executive and the board at the centre of how the function is governed. The CAE is expected to have direct, meaningful access to the board, not access mediated primarily through management. The board's input into the audit risk assessment is explicitly required, not optional.
This is a higher standard than many organisations currently meet. A CAE who presents to the audit committee four times a year and incorporates the committee's priorities into the plan is meeting the floor. A CAE who has ongoing dialogue with the board chair, whose risk assessment is genuinely shaped by board-level concerns, and who is seen as an independent source of organisational insight by board members, is meeting the intent of the new standards.
The 2024 standards explicitly include governance risk within internal audit's scope. This is not new in practice for mature functions, but its explicit inclusion in the foundational standards signals that governance assurance, covering the effectiveness of board structures, management behaviour, and the integrity of the tone at the top, is a legitimate and expected part of what internal audit does.
The standards introduce more rigorous requirements around quality assurance. Internal audit functions are expected to have a quality assurance and improvement programme (QAIP) covering both ongoing monitoring of quality and periodic self-assessments. External assessments against the standards are expected at least once every five years.
The traditional internal audit model was fundamentally retrospective. Examine what happened during a past period, test whether controls operated correctly, identify exceptions, and report on findings. This remains a core and legitimate function. The organisation needs to know whether its controls are working and whether its processes are being followed.
What has changed is the expectation that internal audit also contributes to the organisation's understanding of where risk is building, not just where it has already materialised. This means different things for different organisations, but some consistent patterns characterise the functions doing it well.
An internal audit function with access to operations across the whole organisation is well positioned to identify emerging risks that may not yet be visible to management or the board from their vantage point. A pattern of incidents in a particular area, a process that is showing signs of strain under increased volume, a technology dependency that is becoming more fragile over time: these are signals that a forward-looking internal audit function notices and brings to the board's attention before they become significant failures.
The IIA's guidance on the role of internal audit in enterprise-wide risk management makes the distinction between audit activities that compromise independence, where internal audit takes on risk management ownership, and legitimate activities that support enterprise risk management by providing assurance and insight. Emerging risk identification sits firmly in the legitimate category.
Thematic reviews, examining a particular risk or governance topic across multiple business areas rather than conducting a traditional audit of a specific process, are increasingly common in strategically engaged internal audit functions. A thematic review of how AI governance is being applied across business units, or how data quality is managed across different functions, provides insight that a conventional audit engagement cannot.
The IIA's definition of internal audit describes it as an "independent, objective assurance and consulting activity designed to add value and improve an organisation's operations." The consulting dimension has always been there in the definition. What has changed is the degree to which well-run functions are actively using it.
Advisory work includes being involved in major projects and change programmes at an early stage, providing input on risk and control design before commitments are made rather than only reviewing outcomes after implementation. It includes providing management with views on the risk and control implications of strategic decisions before those decisions are finalised. And it includes facilitating risk workshops and control self-assessment processes in ways that build risk management capability in the business.
The distinction from assurance work is important. When internal audit provides advice on the design of a process or control, it should not subsequently provide assurance over the effectiveness of that same process or control. The IIA's standards on independence and objectivity are explicit on this point: where advisory work creates a threat to independence, that threat must be managed, disclosed, or the work declined.
The chief audit executive role is evolving in organisations that take internal audit seriously. The most effective CAEs are not simply heads of a technical function. They are trusted advisers to the board who bring a distinctive, evidence-based perspective on how the organisation is actually operating, as distinct from how management believes it to be operating. This perspective is valuable precisely because it is independent and grounded in direct observation rather than in management reporting.
Strategic relevance and greater board engagement only add value if the independence that makes internal audit's perspective credible is preserved. An internal audit function that is genuinely too close to management, that avoids difficult findings, or that allows its scope to be shaped by the preferences of the people it is auditing, has lost the thing that makes its work worth having.
Independence is partly a structural matter. The CAE should report functionally to the audit committee or board, not to the CEO or CFO, even if they report administratively to a senior executive for operational purposes. The IIA's Position Paper on the Three Lines is explicit that placing internal audit within a reporting line that includes management responsibility for risk or control activities compromises its independence.
Structural independence is necessary but not sufficient. A CAE who is structurally independent but who in practice softens findings, avoids challenging senior management, or allows access restrictions to go unchallenged is not operationally independent. Behavioural independence requires willingness to report what is found, to the board if necessary, regardless of how uncomfortable the finding may be for management.
The board's role in protecting internal audit's independence is crucial. An audit committee that actively shields the CAE from management pressure, that ensures the function is adequately resourced, and that takes audit findings seriously rather than deferring to management responses, is one of the most important governance factors in determining whether internal audit adds genuine value.
Understanding internal audit's strategic role requires understanding the governance architecture within which it operates. The IIA's Three Lines Model, updated in 2020, describes how organisations govern risk and control through three distinct roles.
The first line encompasses operational management, the people responsible for running the business and managing its day-to-day risks. The second line covers risk management and compliance functions that set frameworks, provide guidance, and exercise oversight without taking operational ownership. The third line is internal audit, providing independent assurance that the first and second lines are functioning as intended.
What the updated model makes clearer than its predecessor is that all three lines, and the governing body above them, have responsibilities for the overall quality of governance. Internal audit's strategic value is not just in finding problems. It is in providing the board with confidence that the governance architecture on which they rely is genuinely working.
The practical question for any organisation is whether its internal audit function meets the standard the 2024 Global Internal Audit Standards describe. Several indicators are useful.
The audit plan should be visibly connected to the organisation's most significant strategic risks, not primarily a reflection of what was audited last time. The CAE should have genuine, ongoing dialogue with board members, not a formal quarterly presentation. The function should be raising issues that management has not already identified, not confirming what everyone already knows. Advisory work should be an active part of the function's contribution, not an occasional addition to a predominantly assurance-focused programme. And findings should be followed through to genuine resolution, with the board informed where management's remediation falls short or is not completed on time.