All blog
Internal Audit· 2026-01-20 ·8 min read

Internal Audit Monitor 2025: the internal audit function at Dutch listed companies

The share of Dutch listed companies with an internal audit function rose from 52% in 2016 to around 72% in 2024, according to the Internal Audit Monitor 2025.

Internal Audit Monitor 2025: the internal audit function at Dutch listed companies

In less than ten years, the internal audit function (IAF) has grown into a fixed pillar of good governance at Dutch listed companies. The share of listed companies with an IAF rose from 52% in 2016 to around 72% in 2024. This emerges from the Internal Audit Monitor 2025, the periodic study by ONE Risk Advisory and Nyenrode Business University, commissioned by IIA Netherlands. This edition examines not only the presence and design of the IAF, but also its role in the new Risk Management Statement (Verklaring omtrent Risicobeheersing, VOR).

How many listed companies have an internal audit function?

Almost three quarters of the listed companies based in the Netherlands had an internal audit function in 2024. In absolute terms this grew from 50 functions in 2016 to 58 in 2024, while the total number of Dutch listed companies fell from 96 to 81 over the same period. Since 2021 the picture has been stable: around 60% of listed companies have an IAF.

Behind that average lie clear differences by stock index. AEX and AMX companies have an internal audit function almost without exception, a stable and consistent picture. The strongest relative growth is among the smaller companies: in the AScX the share rose from 39% in 2016 to 68% in 2024.

An important nuance is the increased transparency in annual reports. Companies that previously reported an IAF now more often state explicitly when audit work is placed with other functions and therefore does not meet the characteristics of a full function. From 2021 onwards it is therefore more accurate to speak of stabilisation than of decline. In practice we see that boards and supervisory directors do not regard the IAF as a mere statutory obligation, but as a partner in business that contributes to effective internal control.

Size doesn’t matter: smaller companies set up an IAF too

The most frequently cited reason for not having an internal audit function is the limited size of the organisation. The figures contradict this: it is precisely the smaller AScX companies that showed the strongest growth. The assumption that only large organisations can afford an effective audit function is therefore outdated.

Full outsourcing of the internal audit function remains an exception and ranged between four and eight companies over the period 2016 to 2024. The majority deliberately opt for an in-house function, which underlines the importance that boards and supervisory directors attach to a structurally embedded, independent third line. In practice we more often see co-sourcing: a dedicated Chief Audit Executive (CAE) within the organisation, supplemented with external expertise and capacity on a flexible basis. A proportionate IAF is feasible in several ways:

  • a phased build-up, step by step towards a full function;
  • a compact core team, supplemented with co-sourcing;
  • or, for the smallest companies, full outsourcing.

Transparency is increasing: five good practices

Listed companies explain the design and operation of their internal audit function in ever greater detail. By now, with one exception, no company leaves the absence of an IAF unexplained, which confirms how the comply-or-explain principle works. The analysis of annual reports reveals five good practices:

  • a clear positioning within the three lines model, including the division of responsibilities with the first and second line;
  • clear reporting lines, with the IAF reporting functionally to the audit committee and administratively to the board;
  • transparency about scope and approach, with concrete audit topics and the prioritisation by risk, including strategic and ESG-related risks;
  • application of the International Professional Practices Framework (IPPF) of the IIA;
  • reporting on an External Quality Assessment (a requirement in the Code since 2022) and its outcome.

What changes with the Risk Management Statement (VOR)?

The most important innovation in the Dutch Corporate Governance Code, updated in 2025, is the Risk Management Statement (VOR), mandatory for financial years from 1 January 2025. With the VOR the board publicly accounts for the design, operation and effectiveness of the risk management and internal control system, across four areas: the reliability of financial reporting, the reliability of non-financial reporting, operational risks and compliance risks.

According to the IIA Practice Guide, the internal audit function has no executive responsibility here. From its independent position it can contribute, however, for example with audits of specific risk areas, audits of the risk management process, an assessment of the quality of the second line, advice on the substantiation and implementation, and a review of the draft VOR.

What role does internal audit play in the VOR in practice?

For the Internal Audit Monitor 2025, a survey was conducted among heads of internal audit functions in August and September 2025. Of the 34 functions included in the analysis, 85% report being involved in the VOR. The contribution usually aligns with existing audit work: audits that provide input for the statement. The table below shows the reported contributions.

Contribution of the internal audit function to the VOR% of respondents
Audits of the control of specific risk areas68%
Audits of the risk management process65%
Audits of the quality of second-line functions62%
Review of the draft VOR44%
Advice on substantiation or implementation of the VOR44%
Formal assurance on (parts of) the VOR21%
No contribution or not involved15%
Respondents could give multiple answers. Source: Internal Audit Monitor 2025.

Formal assurance on the VOR or parts of it currently occurs at around one in five functions (21%). This is understandable: definitions, frameworks and evidence are still developing in many organisations, particularly for operational and compliance risks. For most respondents the VOR has not led to materially different work; no respondent reports a fundamental change to the audit work. The two biggest challenges that the heads of IAF cite are interpreting concepts such as assurance and effectiveness, and gathering sufficient and suitable evidence to substantiate the statement on a sound basis.

What does this mean for your organisation?

Three pieces of advice emerge from the study. Invest in in-house audit capacity, because the dominance of internal functions confirms the perceived added value of in-house expertise. Use outsourcing and co-sourcing strategically, particularly for smaller companies or scarce, specialist knowledge. And be transparent about the choices made and the safeguards for good governance under an alternative model.

For the VOR: treat the statement not solely as a formal reporting obligation, but as an opportunity to demonstrably strengthen risk management and internal control. By involving the internal audit function early and deliberately, the quality of the statement improves and a consistent, well-substantiated story emerges for stakeholders.

About the Internal Audit Monitor

The Internal Audit Monitor appears periodically, with earlier editions in 2017 and 2022. ONE Risk Advisory conducts the study in collaboration with Nyenrode Business University, commissioned by IIA Netherlands. The 2025 edition was written by Robert Bogtstra and Inge Garretsen (ONE Risk Advisory) and Remko Renes (Nyenrode Business University). The study is based on two sources: an analysis of public annual reports over the period 2016 to 2024, and a survey among heads of internal audit functions, conducted in August and September 2025.

Would you like to know what an internal audit function can mean for your organisation, or how co-sourcing, an external quality assessment or the substantiation of your VOR would work in your situation? Please get in touch with us.