Kwaliteit & EQA

Internal Audit Charter

A formal document defining the internal audit function's purpose, authority, and responsibility, including reporting structure, QAIP requirements, and confirmation of IIA Standards conformance. Periodically reviewed and submitted to the board and senior management for approval.

Source: IIA GIAS 2024, Domain III Governing the IA Function

The Internal Audit Charter is the formal document that sets out the purpose, authority and responsibility of the internal audit function. It describes the reporting lines, the access to people and information, the function's position within the organisation and the confirmation that the function operates in conformance with the Global Internal Audit Standards (GIAS) 2024 issued by the Institute of Internal Auditors (IIA). The charter is reviewed periodically and submitted for approval to the board and the supervisory board, usually through the audit committee.

For the board, the supervisory board and the audit committee, the charter is the foundation beneath the independence and mandate of internal audit. It makes explicit to whom the Chief Audit Executive (CAE) reports functionally and administratively, which topics fall within scope and which resources the function receives. Without a current and approved charter, the legal and governance basis to audit freely and without obstruction is missing. It is therefore also an instrument through which the audit committee keeps its own oversight role sharp.

A sound charter states at least the purpose and positioning of the function, the scope of work, the safeguards for independence and objectivity, the requirements for the Quality Assurance and Improvement Program (QAIP) and the way conformance with the Standards is confirmed. In the Global Internal Audit Standards 2024, the charter belongs to the standards on governing the audit function, where mandate and positioning are central. The document is kept alive: when strategy, structure or regulation changes, it is revised and re-approved.

ONE Risk Advisory helps organisations draft or sharpen a charter that aligns with the Global Internal Audit Standards 2024 and with their own context. The charter is for us a fixed reference point in every External Quality Assessment (EQA): does the text still hold, does it live in practice and does it genuinely give the CAE the mandate that is needed. We do not only draft the document, we make sure it works in the boardroom.

Last updated:

Related service Internal Audit

Frequently asked questions

Who approves the internal audit charter?

The charter is approved by the board and the supervisory board, in practice usually through the audit committee. This anchors it at the highest level rather than treating it as an internal arrangement within the audit function alone.

How often should the charter be reviewed?

The charter should be reviewed periodically, assessed at least annually and updated whenever strategy, structure or regulation changes. An outdated charter is a common finding in an External Quality Assessment (EQA).

What is the difference between the charter and the audit plan?

The charter sets out the permanent mandate, purpose and authority of the function. The audit plan translates that mandate each year into concrete topics based on risk. The charter is the framework, the plan is the execution.

Must conformance with the Standards be stated in the charter?

Yes. The Global Internal Audit Standards 2024 expect the charter to confirm that the function operates in conformance with the Standards and that a Quality Assurance and Improvement Program (QAIP) is in place. This also makes the charter a reference point for the audit committee.

← All terms