Misconception 1: “QAIP is a policy.”
No, QAIP is a programme. It does not describe what the policy is, but how you continuously test whether the IA function complies with its own policy. A policy says “we conduct audits in accordance with IIA Standards.” QAIP says “we test every quarter whether we actually did so, and where we deviated we record why.”
Misconception 2: “It is an annual check.”
The five-year external quality assessment (EQA) is what the IIA mandates. QAIP is what you do in between. It is continuous: ongoing monitoring (peer review per engagement, quality metrics per quarter) plus periodic self-assessment (annually, structured). Not “pick up once a year.”
Misconception 3: “It is a tool.”
Audit management suites do offer QAIP modules. Useful, not necessary. We have seen mid-cap functions run QAIP perfectly with an Excel template and a SharePoint folder. The point is the ritual: peer review after every engagement, quarterly reporting, annual self-assessment. The tool is secondary.
Misconception 4: “It is for the external assessor.”
That is the misframe that does the most damage. If QAIP is run for the EQA five years out, it loses its value. The primary audience is internal: the Chief Audit Executive (CAE) who wants ongoing oversight of the quality of their own team. The EQA assessor checks that, but it is not designed for the check.
What it actually is.
A structured memory of what went well and what should change. Small. Routine. Directly applicable. The CAE who feels calm about it says at quarter-end: “We did these three engagements, here are three peer-review notes, here are the three KPIs, here is the action for next quarter.” No paginated paper.