2.3 The IIA Global Internal Audit Standards (IPPF)
Key Takeaways
Internal auditing is an independent, objective assurance and consulting activity designed to add value, strengthen governance, and enhance risk management and internal controls.
The 2024 Global Internal Audit Standards organize professional internal audit practice across Five Domains: Purpose, Ethics and Professionalism, Governing, Managing, and Performing.
The Chief Audit Executive (CAE) must maintain a dual reporting line: functional reporting to the governing body (board or audit committee) for independence, and administrative reporting to executive leadership for daily operations.
The IIA Three Lines Model clearly delineates operational delivery (first line), complementary risk management and compliance monitoring (second line), and independent internal audit assurance (third line).
In the European Commission, the Internal Audit Service (IAS) operates with full operational autonomy, reporting functionally to the Audit Progress Committee (APC) and administratively to the Director-General.
2.3 The IIA Global Internal Audit Standards (IPPF)
While external audit bodies such as the European Court of Auditors provide independent oversight to external stakeholders (citizens and parliament), internal audit functions operate within an institution to evaluate and strengthen governance, risk management, and internal controls from within. In the European Union institutional framework, robust internal auditing is mandated by the EU Financial Regulation and operationalized by the European Commission's Internal Audit Service (IAS).
1. The IIA and the Evolution of the Global Internal Audit Standards
The Institute of Internal Auditors (IIA), established in 1941, is the recognized global standard-setter and professional authority for the internal audit profession. For decades, the profession was governed by the International Professional Practices Framework (IPPF). In 2024, the IIA completed a comprehensive overhaul, condensing and modernizing its architecture into the Global Internal Audit Standards.
The Official Definition of Internal Auditing
According to the Global Internal Audit Standards:
"Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes."
Assurance Services vs. Consulting Services
Internal auditors provide two distinct categories of professional engagements:
- Assurance Services: An objective examination of evidence for the purpose of providing an independent assessment on governance, risk management, and control processes. Assurance engagements always involve three distinct parties:
- The process owner (the person or group directly responsible for the operational activity being reviewed).
- The internal auditor (the professional conducting the assessment).
- The user (the governing body, audit committee, or senior management relying on the evaluation).
- Consulting Services: Advisory, training, and facilitation activities intended to add value and improve an organization's governance, risk management, and control without the internal auditor assuming management responsibility. Consulting engagements involve two parties: the internal auditor and the engagement client. Internal auditors must never make management decisions during consulting assignments, as doing so impairs subsequent audit objectivity.
2. The Five Domains of the Global Internal Audit Standards
The 2024 Global Internal Audit Standards are structured across Five Core Domains, uniting 15 fundamental principles:
Domain I: Purpose of Internal Auditing
Defines the core mandate and societal value of the profession. Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the governing body and executive management with objective, risk-based assurance, advice, and foresight.
Domain II: Ethics and Professionalism
Mandates adherence to the core ethical tenets required of internal audit practitioners: Integrity, Objectivity, Competence, Due Professional Care, and Confidentiality. Internal auditors must actively avoid conflicts of interest and maintain unbiased judgment.
Domain III: Governing the Internal Audit Function
Establishes the governance conditions that executive management and the governing body must satisfy to ensure internal audit can operate effectively:
- The Internal Audit Charter: A formal, written document approved by the governing body defining internal audit's purpose, authority, scope, and responsibility.
- Dual Reporting Relationship: To preserve independence, the Chief Audit Executive (CAE) must report functionally to the governing body (or audit committee) and administratively to executive leadership:
- Functional Reporting: The audit committee approves the internal audit charter, the risk-based audit plan, the internal audit budget, and decisions regarding the appointment, remuneration, and removal of the CAE.
- Administrative Reporting: Executive leadership (e.g., CEO, Secretary-General, or Director-General) facilitates day-to-day administrative support, budgeting logistics, internal communication flows, and personnel administration.
Domain IV: Managing the Internal Audit Function
Outlines the CAE's leadership responsibilities: developing a dynamic, risk-based internal audit plan aligned with organizational strategy; securing adequate financial, human, and technological resources; and maintaining an ongoing Quality Assurance and Improvement Program (QAIP), incorporating internal ongoing monitoring, periodic annual reviews, and an external quality assessment conducted by an independent qualified validator at least once every five years.
Domain V: Performing Internal Audit Services
Governs the end-to-end execution of specific audit engagements:
- Engagement Planning: Conducting a preliminary engagement risk assessment, setting objectives and scope, and establishing the audit work program.
- Fieldwork & Testing: Gathering, analyzing, and documenting sufficient, reliable evidence to evaluate internal control effectiveness.
- Developing Findings: Structuring audit observations using the classic four-part framework: Condition (what is), Criteria (what should be), Cause (why the gap occurred), and Effect (the operational or financial impact).
- Engagement Communication: Issuing balanced, formal audit reports containing actionable, risk-prioritized recommendations.
- Monitoring Progress: Systematically tracking management's implementation of agreed corrective action plans until deficiencies are resolved.
3. The IIA Three Lines Model
The IIA Three Lines Model (which replaced the older "Three Lines of Defense" framework) provides a clear governance structure for identifying risk management roles, responsibilities, and coordination across an institution:
| Level | Component | Primary Roles & Responsibilities |
|---|---|---|
| Oversight | Governing Body (Board / Audit Committee) | Accountable to stakeholders for organizational oversight; ensures integrity, transparency, and strategic alignment; oversees internal audit. |
| First Line | Operational Management | Leads and manages the day-to-day delivery of products, services, and operational processes; directly owns, designs, and executes internal controls to manage operational risks. |
| Second Line | Risk, Compliance & Quality Functions | Provides specialized expertise, frameworks, monitoring, and constructive challenge to support first-line operations; ensures compliance with laws, ethical rules, and internal standards. |
| Third Line | Internal Audit | Provides independent and objective assurance and advice to the governing body and senior management on the adequacy and effectiveness of both first- and second-line governance and controls. |
| External | External Assurance Providers (e.g., ECA, SAIs) | Operates outside the organization's governance structure to satisfy statutory, legal, or parliamentary accountability mandates. |
┌──────────────────────────────────────────────┐
│ Governing Body / Audit Committee │
└──────┬────────────────────────────────┬──────┘
│ Accountability │ Functional
│ & Oversight │ Reporting
▼ ▼
┌──────────────┐ ┌──────────────┐
│ Senior Exec │ │ Third Line: │
│ Management │ │ Internal │
└──────┬───────┘ │ Audit │
Administrative│ └──────────────┘
Reporting │ (Logistics)
┌──────────────┴──────────────┐
▼ ▼
┌──────────────┐ ┌──────────────┐
│ First Line: │ │ Second Line: │
│ Operational │ │ Compliance, │
│ Management │◄─────────────┤ Risk & QC │
└──────────────┘ (Facilitates)└──────────────┘
4. Internal Audit Architecture in EU Institutions
Within the European Union, internal audit underwent radical modernization following the 2000 Kinnock Administrative Reforms, which led to the creation of the Internal Audit Service (IAS) in 2001:
Mandate of the Internal Audit Service (IAS)
The Commission's Internal Audit Service (IAS) is an independent Commission service providing assurance and advice across Commission departments and executive agencies. Its authority and access derive from the current Financial Regulation and its charter. Independence means that audit scope, procedures and conclusions are protected from inappropriate interference; it does not mean the IAS is outside the Commission's institutional and legal accountability arrangements.
The IAS reports its significant results through the Commission's governance structure and coordinates with auditees without allowing them to approve the audit plan or conclusions.
The Audit Progress Committee (APC)
To ensure functional independence in line with Domain III of the Global Standards, the Commission created the Audit Progress Committee (APC):
- The APC acts as the Commission's audit committee, consisting of members of the College of Commissioners and external independent experts.
- The APC reviews the annual internal audit plan, ensures the IAS remains adequately resourced, monitors the implementation of audit recommendations across Commission DGs, and reports directly to the College of Commissioners.
Historically, individual DGs maintained localized Internal Audit Capabilities (IACs). To eliminate conflicts of interest, avoid audit duplication, and enforce professional rigor, the Commission centralized all internal audit activities into the single, unified IAS structure.
Under Domain III of the IIA Global Internal Audit Standards, what constitutes the correct reporting relationship for a Chief Audit Executive (CAE) to safeguard organizational independence?
Reporting exclusively to the Chief Operating Officer for all performance reviews and audit plan approvals
Reporting directly to the external state audit institution for all budgetary and operational approvals
Reporting functionally to the governing body or audit committee, and reporting administratively to executive management
Reporting directly to operational department heads whose processes are subject to audit
In the IIA Three Lines Model, which of the following responsibilities belongs squarely to Second Line roles?
Delivering public services and executing core transactional controls on daily grant payments
Issuing independent, objective audit opinions directly to the external parliamentary oversight committee
Approving the annual statutory financial accounts and deciding the external audit scope
Establishing enterprise risk management frameworks, conducting compliance monitoring, and providing specialized guidance to operational managers
How does an internal audit assurance engagement differ from an internal audit consulting engagement under IIA standards?
Assurance services involve a three-party relationship providing an objective assessment of controls, whereas consulting involves a two-party advisory relationship where the auditor assists the client without assuming management responsibility
Assurance services are performed exclusively by external accounting firms, whereas consulting services are performed by the governing board
Assurance services allow internal auditors to assume temporary managerial decision-making powers, whereas consulting strictly forbids executive interviews
Assurance services result in informal oral presentations, whereas consulting produces binding legal directives
Within the European Commission's internal governance architecture, what role does the Audit Progress Committee (APC) fulfill in relation to the Internal Audit Service (IAS)?
The APC manages day-to-day procurement files and signs operational grant agreements for Commission directorates
The APC acts as the Commission’s audit committee: it helps safeguard IAS independence, considers planning and reporting, and monitors critical recommendations without approving the audit plan
The APC represents the external Supreme Audit Institution responsible for issuing the annual Statement of Assurance (DAS)
The APC investigates criminal fraud allegations on behalf of the European Public Prosecutor's Office
Sections you finish are checked off in the contents.