8.1 CAE Relationship with the Audit Committee & Board

Key Takeaways

  • GIAS Standard 11.1 mandates that the Chief Audit Executive (CAE) establish strong, candid relationships with the board and senior management, deriving functional authority directly from the governing body.
  • Under the dual reporting structure, the CAE reports functionally to the Audit Committee (approving charter, audit plan, budget, CAE appointment/compensation) and administratively to executive management (ideally the CEO).
  • Reporting administratively to subordinate executives like the CFO or General Counsel creates inherent conflicts of interest that compromise organizational independence.
  • Private executive sessions (in-camera meetings) between the CAE and the Audit Committee must occur at every regularly scheduled meeting with all executive management excused.
  • Executive session agendas focus on management override of controls, resource constraints, sensitive investigations, and unvarnished evaluations of tone at the top.
Last updated: September 2026

8.1 CAE Relationship with the Audit Committee & Board

[!NOTE] GIAS Standard 11.1 Mandate: Under GIAS Standard 11.1 (Building Relationships and Communicating with Stakeholders), the Chief Audit Executive (CAE) must establish strong, open, and candid relationships with the board and senior management. The internal audit activity derives its authority, independence, and operational mandate directly from the governing board, making the CAE-Audit Committee relationship the foundational safeguard of audit objectivity.

Effective corporate governance depends on the independence and vitality of the relationship between the Chief Audit Executive (CAE) and the board of directors, typically exercised through its Audit Committee. While internal audit interacts daily with executive management, its fiduciary loyalty belongs to the governing body representing shareholders and organizational stakeholders. If this relationship weakens, becomes passive, or is filtered through executive management, internal audit cannot challenge executive misconduct or systemic enterprise vulnerabilities.


The Governance Anchor: GIAS Standard 11.1 and Domain III

Under the 2024 Global Internal Audit Standards (GIAS), the relationship between the CAE and the board is governed by Domain III (Governing the Internal Audit Function) and Domain IV, Principle 11 (Communicate Effectively). Standard 11.1 requires the CAE to:

  • Foster Two-Way Dialogue: Establish formal and informal communication channels to understand board expectations, risk tolerance, and strategic priorities.
  • Maintain Direct Board Access: Ensure unrestricted, direct access to the Audit Committee chair without needing prior executive approval.
  • Deliver Unfiltered Insights: Provide objective evaluations of governance, internal controls, risk culture, and systemic vulnerabilities without political filtering.
  • Affirm Governance Conditions: Annually confirm to the board that essential conditions—such as an approved charter, unfettered access to records and personnel, and functional independence—remain intact.

The Dual Reporting Structure: Functional vs. Administrative Reporting

To preserve independence while maintaining operational viability, the IIA mandates a dual reporting structure. The CAE reports functionally to the Audit Committee / Board and administratively to executive management (ideally the Chief Executive Officer).

Governance DimensionFunctional Reporting Line (Audit Committee / Board)Administrative Reporting Line (Chief Executive Officer)
Primary PurposeUphold organizational independence, objectivity, and functional authority.Facilitate day-to-day departmental operations and organizational integration.
Charter & AuthorityFormally approves the Internal Audit Charter and all periodic revisions.Coordinates organizational recognition and distribution of the charter.
Audit Plan & ScopeApproves the annual risk-based audit plan, scope adjustments, and resource plans.Reviews proposed plan for operational alignment and scheduling conflicts.
Budget & ResourcesApproves the internal audit budget and evaluates resource adequacy.Administers routine budget tracking, expense reporting, and procurement.
CAE Personnel ActionsApproves the appointment, evaluation, compensation, and dismissal of the CAE.Conducts administrative feedback, coordinates payroll, and handles HR records.
Scope LimitationsInquires regarding improper scope or resource constraints.Ensures internal audit has office space, IT infrastructure, and enterprise access.
Executive SessionsConducts mandatory private in-camera sessions at every scheduled meeting.Interacts via regular executive operational meetings and weekly check-ins.

Why Administrative Reporting Belongs to the CEO

The IIA strongly recommends that the CAE report administratively to the Chief Executive Officer (CEO). Reporting administratively to a subordinate executive—such as the Chief Financial Officer (CFO), Chief Operating Officer (COO), or General Counsel—creates severe conflicts of interest. For example, if a CAE reports administratively to the CFO, the CFO controls the CAE's travel approvals, office resources, and operational performance feedback, creating an inherent incentive to avoid aggressively auditing finance, treasury, or accounting controls.


Mandatory Private Executive Sessions (In-Camera Meetings)

A cornerstone of modern board oversight is the private executive session (or in-camera session). These are mandatory closed-door meetings held between the Audit Committee and the CAE, with all executive management excused (including the CEO, CFO, external legal counsel, and operational directors).

Cadence and Timing

Leading governance practice and stock exchange listing standards dictate that private executive sessions occur at every regularly scheduled Audit Committee meeting (at minimum quarterly). If executive sessions are held only when a crisis erupts, the scheduling itself tips off management that an investigation is underway. Establishing private sessions as a standing agenda item normalizes confidential dialogue.

Mandatory Topics for Private Executive Sessions

Private sessions provide a secure forum where the CAE communicates sensitive intelligence without fear of executive retribution:

  1. Potential Management Override of Controls: Instances where executives bypassed approval hierarchies, overrode system limits, or pressured subordinates to alter records.
  2. Resource Constraints and Budget Pressures: Subtle management tactics to restrict internal audit capabilities, such as freezing audit travel, denying forensic tool budgets, or refusing head-count replacements.
  3. Impairments to Independence and Scope Limitations: Executive attempts to restrict audit scope, block access to cloud systems, or delay report issuance on sensitive failures.
  4. Executive Investigations and Whistleblower Allegations: Briefings on substantiated fraud allegations, bribery probes, or ethical misconduct involving C-suite leaders.
  5. Assessment of Tone at the Top: Unvarnished impressions of management's risk appetite, responsiveness to findings, and integrity in financial disclosures.

Cultivating Mutual Trust, Transparency, and Delivering Unvarnished Foresight

A successful relationship between the CAE and the Audit Committee transcends mechanical checklist compliance. It is rooted in mutual trust, proactive transparency, and actionable foresight:

  • The "No Surprises" Protocol: The CAE must establish a "no surprises" protocol with the Audit Committee chair. Critical control breakdowns or regulatory enforcement actions must be communicated immediately through interim briefings rather than waiting for quarterly board packets.
  • Communicating Without Filter: When senior executives attempt to soften, sanitize, or redact harsh findings before board submission, the CAE must resist. While the CAE reviews findings with management to verify factual accuracy and obtain management action plans, the CAE has an inviolable duty to present an unfiltered, objective assessment of risk to the Audit Committee.
  • Delivering Horizon Scanning and Foresight: Beyond reporting historical audit completions, the CAE provides thematic governance foresight: emerging regulatory shifts (e.g., ESG mandates, digital asset regulations), supply chain vulnerabilities, and industry benchmarks regarding artificial intelligence and cybersecurity threats.
Loading diagram...
Dual Reporting Architecture and Closed-Door Executive Session Dynamics
Test Your Knowledge

Under GIAS Standard 11.1 and the IIA's recommended dual reporting structure, which of the following responsibilities falls strictly under the functional reporting line between the Chief Audit Executive (CAE) and the Audit Committee?

A
B
C
D
Test Your Knowledge

The Chief Audit Executive of a global financial institution requests a private executive session with the Audit Committee at the upcoming quarterly meeting. The Chief Executive Officer objects, arguing that having the CAE meet alone with the board undermines executive leadership and creates distrust. How should the Audit Committee respond?

A
B
C
D
Test Your Knowledge

During an audit of capital project procurement, the internal audit team identifies significant evidence that the Chief Financial Officer repeatedly bypassed mandatory competitive bidding procedures to award contracts to a favored vendor. Prior to the upcoming Audit Committee meeting, the CFO demands that the CAE remove the finding from the board report, claiming the issue has been resolved internally. What is the CAE's professional obligation?

A
B
C
D