The Global Internal Audit Standards and the Architecture of Quality Assurance

Five Domains, One Continuous Thread

GIAS organizes the Standards into five domains: Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services.[3] Quality assurance is not confined to a single domain. It is introduced in Domain III (Governing the Internal Audit Function), developed further in Domain IV (Managing the Internal Audit Function), and ultimately tested against the work performed under Domain V (Performing Internal Audit Services). Taken together, the Standards comprise 15 guiding principles and 52 individual standards, and a full external quality assessment examines conformance across all of them.[4]

Standard 8.3: The Quality Assurance and Improvement Program

The foundational requirement sits in Domain III, under Standard 8.3, Quality. It requires the chief audit executive (CAE) to develop, implement, and maintain a quality assurance and improvement program (QAIP) that covers all aspects of the internal audit function.[5] GIAS defines the QAIP in its glossary as a program established by the CAE "to evaluate and ensure the internal audit function conforms with the Global Internal Audit Standards, achieves performance objectives, and pursues continuous improvement."[6] The QAIP is deliberately broad in scope: it is not limited to individual engagements but extends to the strategy, resourcing, methodology, and reporting of the function as a whole.

Standard 8.4: The External Quality Assessment

Sitting alongside Standard 8.3 in Domain III is Standard 8.4, External Quality Assessment (EQA). This standard requires the CAE to develop a plan for an external quality assessment and to discuss that plan with the board or audit committee.[7] The external assessment must be performed at least once every five years by a qualified, independent assessor or assessment team, and at least one member of that team must hold an active Certified Internal Auditor (CIA) credential.[8]

GIAS explicitly permits two routes to satisfying this requirement. The first is a full-scope external quality assessment, in which an independent assessor comprehensively reviews the internal audit function's conformance with every standard. The second is a self-assessment with independent validation (SAIV), in which the CAE's team completes a comprehensive, fully documented internal assessment, and the independent assessor then selects and validates a sample of that work to confirm it was conducted completely and accurately.[9] Both routes satisfy Standard 8.4; the choice between them is a matter of organisational judgment, cost, and disruption tolerance, which later articles in this series examine in more detail.

The requirement applies universally. Every internal audit function is subject to Standard 8.4, regardless of its size, its sector, or whether the function is performed in-house, outsourced, or co-sourced.[10] For internal audit functions of only one person, GIAS acknowledges that an adequate QAIP will require assistance from outside the function, since internal self-assessment alone cannot substitute for independent perspective.[11]

Standard 12.1: Internal Quality Assessment

Where Standard 8.4 governs the external, periodic dimension of quality assurance, Standard 12.1, Internal Quality Assessment, governs the continuous, internal dimension. It sits in Domain IV, under Principle 12, which makes the CAE responsible for the internal audit function's conformance with GIAS and its continuous performance improvement.[12] Standard 12.1 requires the CAE to develop and conduct internal assessments of the function's conformance with the Standards and its progress toward performance objectives, comprising two elements: ongoing monitoring of engagement performance, and periodic self-assessment of the function as a whole.[13] At least annually, the CAE must communicate the results of the internal quality assessment to the board or audit committee and to senior management.[14]

Standard 12.2: Performance Measurement

Adjacent to internal assessment sits Standard 12.2, Performance Measurement, which requires the CAE to establish performance objectives — typically expressed as key performance indicators — designed to evaluate the function's performance, taking into account the input and expectations of the board and senior management.[15] Where those objectives are not met, the CAE must develop an action plan to address the shortfall. Guidance accompanying the standard offers CAEs a range of performance categories to consider when building these indicators, spanning efficiency, effectiveness, stakeholder satisfaction, and talent development.

Standard 12.3: Oversee and Improve Engagement Performance

The third element of the Domain IV quality principle is Standard 12.3, Oversee and Improve Engagement Performance, which requires the CAE to establish and implement methodologies for engagement supervision, quality assurance at the engagement level, and the development of staff competencies.[16] This standard is the connective tissue between the function-level QAIP and the individual engagements conducted under Domain V; it ensures that supervisory review, coaching, and quality checks occur while engagements are in progress, not only after the fact.

How the Pieces Fit Together

Read together, Standards 8.3, 8.4, 12.1, 12.2, and 12.3 describe a layered system rather than a single control point:

- Engagement-level supervision (Standard 12.3) provides real-time quality control during fieldwork.

- Ongoing monitoring and periodic self-assessment (Standard 12.1) evaluate the function's conformance and progress on a continuous, internally driven basis.

- Performance measurement (Standard 12.2) tracks the function's effectiveness against objectives agreed with the board and senior management.

- The QAIP (Standard 8.3) binds these internal mechanisms into a single, documented program.

- The external quality assessment (Standard 8.4), conducted at least every five years, provides the independent, outside perspective that internal mechanisms alone cannot supply.

The IIA's Quality Assessment Manual, updated for the 2024 edition of GIAS and effective for assessments from January 9, 2025, operationalises this structure. It provides assessors and CAEs with domain-level fieldwork templates, models for concluding on the overall quality of the function, and guidance for interpreting maturity against the Standards.[17] A successful quality assessment — defined as a rating of Full Achievement or General Achievement — is a precondition for an internal audit function to be considered in full conformance with GIAS.[18]

Governance and Reporting

GIAS also assigns explicit responsibilities to the board and senior management in this architecture. The board, with input from senior management, is expected to review and approve the CAE's QAIP, including the most effective and efficient approach to periodic assessment of the function.[19] Both internal and external assessment results must be reported to the board and senior management when completed, and the results of the internal quality assessment must be communicated at least annually.[20] This reporting obligation reflects a broader theme in the 2024 Standards: that conformance with GIAS is not solely a function of internal audit's own diligence, but is embedded in — and overseen by — the governance structures of the organization it serves.

Conclusion

The 2024 Global Internal Audit Standards do not treat quality assurance as a compliance exercise conducted once every five years and otherwise set aside. They construct a continuous system — engagement supervision, internal monitoring, performance measurement, a documented improvement program, and periodic independent validation — in which each layer supports and is tested by the others. Understanding this architecture is a necessary foundation for the articles that follow in this series, which examine the two routes to satisfying the external assessment requirement, the QAIP in operational detail, the case for more frequent self-assessment, and the emerging role of artificial intelligence within this quality framework.

Endnotes

1. RSM US LLP, "IIA Issues 2024 Global Internal Audit Standards to Guide the Profession's Future," March 2024.

2. The Institute of Internal Auditors, "Global Internal Audit Standards," IPPF Framework, effective for quality assessments January 9, 2025.

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards (Lake Mary, FL: The IIA, January 9, 2024).

4. The Institute of Internal Auditors, Quality Services, "Maximizing Internal Audit Effectiveness through External Quality Assessments."

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.

6. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "quality assurance and improvement program."

7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

8. Ibid.

9. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

10. Ibid.

11. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Considerations for Implementation, cross-reference to Standards 10.1, 12.1, and 12.3.

12. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Principle 12.

13. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

14. Ibid.

15. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.

16. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.3, Oversee and Improve Engagement Performance.

17. The Institute of Internal Auditors, Quality Assessment Manual, 2024 Edition.

18. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

19. Plante Moran, "IIA Global Internal Audit Standards Update: Value for Executive Management & Boards," October 2024, summarizing GIAS Standard 8.4 board-approval expectations.

20. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

The Global Internal Audit Standards and the Architecture of Quality Assurance

Five Domains, One Continuous Thread

GIAS organizes the Standards into five domains: Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services.[3] Quality assurance is not confined to a single domain. It is introduced in Domain III (Governing the Internal Audit Function), developed further in Domain IV (Managing the Internal Audit Function), and ultimately tested against the work performed under Domain V (Performing Internal Audit Services). Taken together, the Standards comprise 15 guiding principles and 52 individual standards, and a full external quality assessment examines conformance across all of them.[4]

Standard 8.3: The Quality Assurance and Improvement Program

The foundational requirement sits in Domain III, under Standard 8.3, Quality. It requires the chief audit executive (CAE) to develop, implement, and maintain a quality assurance and improvement program (QAIP) that covers all aspects of the internal audit function.[5] GIAS defines the QAIP in its glossary as a program established by the CAE "to evaluate and ensure the internal audit function conforms with the Global Internal Audit Standards, achieves performance objectives, and pursues continuous improvement."[6] The QAIP is deliberately broad in scope: it is not limited to individual engagements but extends to the strategy, resourcing, methodology, and reporting of the function as a whole.

Standard 8.4: The External Quality Assessment

Sitting alongside Standard 8.3 in Domain III is Standard 8.4, External Quality Assessment (EQA). This standard requires the CAE to develop a plan for an external quality assessment and to discuss that plan with the board or audit committee.[7] The external assessment must be performed at least once every five years by a qualified, independent assessor or assessment team, and at least one member of that team must hold an active Certified Internal Auditor (CIA) credential.[8]

GIAS explicitly permits two routes to satisfying this requirement. The first is a full-scope external quality assessment, in which an independent assessor comprehensively reviews the internal audit function's conformance with every standard. The second is a self-assessment with independent validation (SAIV), in which the CAE's team completes a comprehensive, fully documented internal assessment, and the independent assessor then selects and validates a sample of that work to confirm it was conducted completely and accurately.[9] Both routes satisfy Standard 8.4; the choice between them is a matter of organisational judgment, cost, and disruption tolerance, which later articles in this series examine in more detail.

The requirement applies universally. Every internal audit function is subject to Standard 8.4, regardless of its size, its sector, or whether the function is performed in-house, outsourced, or co-sourced.[10] For internal audit functions of only one person, GIAS acknowledges that an adequate QAIP will require assistance from outside the function, since internal self-assessment alone cannot substitute for independent perspective.[11]

Standard 12.1: Internal Quality Assessment

Where Standard 8.4 governs the external, periodic dimension of quality assurance, Standard 12.1, Internal Quality Assessment, governs the continuous, internal dimension. It sits in Domain IV, under Principle 12, which makes the CAE responsible for the internal audit function's conformance with GIAS and its continuous performance improvement.[12] Standard 12.1 requires the CAE to develop and conduct internal assessments of the function's conformance with the Standards and its progress toward performance objectives, comprising two elements: ongoing monitoring of engagement performance, and periodic self-assessment of the function as a whole.[13] At least annually, the CAE must communicate the results of the internal quality assessment to the board or audit committee and to senior management.[14]

Standard 12.2: Performance Measurement

Adjacent to internal assessment sits Standard 12.2, Performance Measurement, which requires the CAE to establish performance objectives — typically expressed as key performance indicators — designed to evaluate the function's performance, taking into account the input and expectations of the board and senior management.[15] Where those objectives are not met, the CAE must develop an action plan to address the shortfall. Guidance accompanying the standard offers CAEs a range of performance categories to consider when building these indicators, spanning efficiency, effectiveness, stakeholder satisfaction, and talent development.

Standard 12.3: Oversee and Improve Engagement Performance

The third element of the Domain IV quality principle is Standard 12.3, Oversee and Improve Engagement Performance, which requires the CAE to establish and implement methodologies for engagement supervision, quality assurance at the engagement level, and the development of staff competencies.[16] This standard is the connective tissue between the function-level QAIP and the individual engagements conducted under Domain V; it ensures that supervisory review, coaching, and quality checks occur while engagements are in progress, not only after the fact.

How the Pieces Fit Together

Read together, Standards 8.3, 8.4, 12.1, 12.2, and 12.3 describe a layered system rather than a single control point:

- Engagement-level supervision (Standard 12.3) provides real-time quality control during fieldwork.

- Ongoing monitoring and periodic self-assessment (Standard 12.1) evaluate the function's conformance and progress on a continuous, internally driven basis.

- Performance measurement (Standard 12.2) tracks the function's effectiveness against objectives agreed with the board and senior management.

- The QAIP (Standard 8.3) binds these internal mechanisms into a single, documented program.

- The external quality assessment (Standard 8.4), conducted at least every five years, provides the independent, outside perspective that internal mechanisms alone cannot supply.

The IIA's Quality Assessment Manual, updated for the 2024 edition of GIAS and effective for assessments from January 9, 2025, operationalises this structure. It provides assessors and CAEs with domain-level fieldwork templates, models for concluding on the overall quality of the function, and guidance for interpreting maturity against the Standards.[17] A successful quality assessment — defined as a rating of Full Achievement or General Achievement — is a precondition for an internal audit function to be considered in full conformance with GIAS.[18]

Governance and Reporting

GIAS also assigns explicit responsibilities to the board and senior management in this architecture. The board, with input from senior management, is expected to review and approve the CAE's QAIP, including the most effective and efficient approach to periodic assessment of the function.[19] Both internal and external assessment results must be reported to the board and senior management when completed, and the results of the internal quality assessment must be communicated at least annually.[20] This reporting obligation reflects a broader theme in the 2024 Standards: that conformance with GIAS is not solely a function of internal audit's own diligence, but is embedded in — and overseen by — the governance structures of the organization it serves.

Conclusion

The 2024 Global Internal Audit Standards do not treat quality assurance as a compliance exercise conducted once every five years and otherwise set aside. They construct a continuous system — engagement supervision, internal monitoring, performance measurement, a documented improvement program, and periodic independent validation — in which each layer supports and is tested by the others. Understanding this architecture is a necessary foundation for the articles that follow in this series, which examine the two routes to satisfying the external assessment requirement, the QAIP in operational detail, the case for more frequent self-assessment, and the emerging role of artificial intelligence within this quality framework.

Endnotes

1. RSM US LLP, "IIA Issues 2024 Global Internal Audit Standards to Guide the Profession's Future," March 2024.

2. The Institute of Internal Auditors, "Global Internal Audit Standards," IPPF Framework, effective for quality assessments January 9, 2025.

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards (Lake Mary, FL: The IIA, January 9, 2024).

4. The Institute of Internal Auditors, Quality Services, "Maximizing Internal Audit Effectiveness through External Quality Assessments."

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.

6. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "quality assurance and improvement program."

7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

8. Ibid.

9. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

10. Ibid.

11. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Considerations for Implementation, cross-reference to Standards 10.1, 12.1, and 12.3.

12. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Principle 12.

13. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

14. Ibid.

15. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.

16. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.3, Oversee and Improve Engagement Performance.

17. The Institute of Internal Auditors, Quality Assessment Manual, 2024 Edition.

18. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

19. Plante Moran, "IIA Global Internal Audit Standards Update: Value for Executive Management & Boards," October 2024, summarizing GIAS Standard 8.4 board-approval expectations.

20. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

Editor's Introduction - Edition 3, Q3, 2026

Quality assurance has sometimes been treated as a periodic compliance exercise: something that happens internally on an ongoing basis, with a more formal assessment every five years. The Standards, however, invite us to think more broadly. They provide a framework that encompasses governance, conformance, performance, continuous improvement, and external assurance. The challenge now is to turn that framework into a quality culture that genuinely strengthens internal audit functions and increases the confidence of the boards and audit committees they serve.

This edition of Internal Audit Review explores that challenge from five different perspectives.

We begin by examining the architecture of quality assurance created by the Global Internal Audit Standards and what it means for internal audit leaders seeking to build an effective and credible quality framework.

We then consider a question that deserves more debate: is the fully external model still the unquestioned gold standard for quality assessment? There is a strong case for independent external scrutiny, but the profession should also be willing to examine whether a well-designed Self-Assessment with Independent Validation (SAIV), particularly as technology develops, might deliver greater value than it has traditionally been given credit for.

The discussion then moves from the periodic assessment to the Quality Assurance and Improvement Program itself. A QAIP should be much more than paperwork or evidence assembled for an assessment. Properly designed, it is a defence for the internal audit function — helping demonstrate its value, identify weaknesses before they become significant, and provide the board with confidence that quality is being actively managed.

That leads to the question of time. Five years is a long time to wait for an independent view of quality. Our fourth article explores the case for continuous self-assessment within the SAIV model and asks whether internal audit should be thinking about quality as a continuous discipline rather than a point-in-time event.

Finally, we turn to artificial intelligence. AI has the potential to transform how quality assurance is performed — from analysing evidence and identifying patterns to supporting standards mapping and continuous monitoring. But technology brings its own risks. There is an argument for AI augmentation, not autonomy. AI can strengthen the quality assessment process, but professional judgment, accountability, and independence must remain firmly with people.

Taken together, these articles are not intended to argue for one single model of quality assurance. Rather, they ask whether the profession should be prepared to challenge some of its assumptions about how quality is assessed, demonstrated, and improved.

The future of quality assurance may not be about choosing between internal and external assessment, or between human judgment and technology. It may instead be about combining them intelligently: continuous internal scrutiny, meaningful independent validation, appropriate external challenge, and technology that enables professionals to examine more evidence and identify more insight without surrendering their judgment.

The 2024 Standards provide the architecture. It is now up to the profession to decide how ambitious we want to be in building upon it.

Jul 23, 2026

2 min read

Augmentation, Not Autonomy: Why AI Must Never Replace Professional Judgment in Quality Assurance

This final article in the series looks forward, but it makes a case that is deliberately conservative about where the line between human and machine responsibility must sit: AI can and should be embedded throughout the quality assurance options GIAS provides — the QAIP, internal quality assessment, and both models of external quality assessment — but it must never be permitted to make autonomous decisions about conformance, findings, or improvement. Every one of those judgments must remain the responsibility of a qualified human professional, exercised under governance robust enough to prove it.

Where AI Genuinely Belongs in the GIAS Quality Framework

There is a substantial, legitimate role for AI across every quality assurance mechanism GIAS establishes, and the profession should not shy away from it.

Within the QAIP (Standard 8.3), AI can consolidate evidence continuously across the fifty-two standards, maintaining a current picture of the function's documented conformance rather than one reconstructed periodically.[3] Within internal quality assessment (Standard 12.1), AI can support ongoing monitoring by flagging engagements whose documentation appears to depart from methodology or from a specific standard's requirements, giving human reviewers a prioritized list of items to examine rather than requiring them to review everything with equal, undifferentiated attention.[4] Within performance measurement (Standard 12.2), AI can track key performance indicators in something close to real time, surfacing drift from board-agreed objectives well before an annual reporting cycle would otherwise reveal it.[5] And within external quality assessment — whether full-scope or self-assessment with independent validation (SAIV) — AI can accelerate the evidence-gathering and cross-referencing work that has historically consumed the bulk of an assessment's timeline, as the preceding article in this series argued in more detail.[6]

In each case, the value AI adds is the same: it compresses the labour of finding, organizing, and surfacing relevant information. That is a genuine and, I would argue, an increasingly necessary contribution as the volume of data an internal audit function generates continues to grow.

Where AI Must Stop

The line we want to draw is equally simple to state, even though holding it in practice will require real discipline: AI may surface evidence, patterns, and anomalies. It must never be the entity that decides what those things mean for conformance, for a finding's significance, or for whether the function — or an individual engagement — has met the Standards.

This is not a technological limitation I am describing; it is a governance choice, and it needs to be an explicit one, because the technological limitation is eroding. AI systems are becoming more capable of producing plausible-sounding conclusions, not merely flagged anomalies, and the temptation to let a sufficiently confident system's output stand in for a human conclusion will only grow. GIAS's own definition of internal auditing describes it as a discipline that helps organizations achieve their objectives through "professional judgments" applied without compromise, and its glossary defines objectivity itself as the "unbiased mental attitude that allows internal auditors to make professional judgments, fulfil their responsibilities, and achieve the Purpose of Internal Auditing without compromise."[7] Professional judgment, by definition, is judgment exercised by a professional — a human being accountable to a code of ethics, a licensing or certification body, and ultimately to the board. An AI system has none of those things. It cannot be held to the IIA's Code of Ethics. It cannot lose a CIA credential for negligence. It cannot be asked, in the way a human assessor can, to explain the reasoning behind a judgment call in circumstances the training data did not anticipate. Whatever role AI plays in quality assurance, it cannot inherit the accountability that makes a conclusion about conformance mean anything.

This applies with particular force to quality assurance specifically, because quality assurance is the mechanism that is supposed to catch failures everywhere else in the function — including, potentially, failures in how the function itself is using AI in its audit engagements. A quality assurance process that has delegated its own judgment to an autonomous system has no independent means of catching that system's own errors, blind spots, or drift. It would be, in effect, asking AI to grade its own homework.

The Governance Structure This Requires

If AI is to be embedded across the QAIP, internal assessment, and external assessment processes without ever making autonomous decisions, that boundary needs to be actively governed, not just assumed. I would propose that internal audit functions adopting AI within their quality assurance processes commit to several concrete practices:

Every AI-surfaced finding requires human sign-off before it becomes a conclusion. An AI tool that flags a potential nonconformance is producing a lead for a human reviewer to investigate, not a finding. The distinction should be documented and auditable — literally, since the QAIP itself is subject to assessment — so that an external assessor reviewing the function's quality process can see exactly where AI's contribution ended and human judgment began.

The independent assessor role in a full-scope EQA or SAIV validation must remain unambiguously human, and specifically must continue to include at least one individual holding an active Certified Internal Auditor credential, as Standard 8.4 already requires.[8] Whatever AI tools an assessment team uses to accelerate its own evidence review, the conclusion the assessor signs — the rating of Full Achievement, General Achievement, or Partial/Non-Achievement — must remain a human professional's attestation, made on that professional's own accountability.

Boards and audit committees should ask, as a standing governance question, how AI is used within the function's QAIP — not only how AI is used in audit engagements themselves. GIAS already requires the board to understand the robustness of the quality assessment process in order to build trust in the function; in an AI-embedded environment, that robustness question now has a new dimension, and boards should not assume the answer is satisfactory without asking.[9]

CAEs should treat AI governance within quality assurance as itself a component of the QAIP, subject to the same continuous monitoring, documentation, and improvement discipline as every other aspect of the function. An AI tool that quietly changes its own flagging thresholds, or that is updated by a vendor without internal audit's own review, is a conformance risk in exactly the sense Standard 8.3 exists to catch.

A Deliberately Conservative Position

We recognize this is a more conservative position than some in the profession will want to adopt, particularly as AI tools become demonstrably better at tasks that currently require human review. Our argument is not that AI will remain incapable of producing reliable conformance judgments — it may well become very good at this, sooner than many expect. Our argument is that internal audit's value to the organizations it serves rests specifically on the fact that its conclusions are the product of accountable human professional judgment, exercised by people who can be questioned, challenged, and held responsible in a way no software system can be. Quality assurance is the mechanism that is supposed to guarantee that judgment was actually applied, carefully, throughout the function's work. If quality assurance itself becomes an autonomous process, the guarantee it is meant to provide disappears, even if the AI making the decisions turns out, most of the time, to be right.

Conclusion

The IIA's own guidance already points toward deep AI integration across internal audit's data analytics and assurance capabilities, and quality assurance will be no exception.[10] The five articles in this series have examined the architecture GIAS builds for quality — the QAIP, internal assessment, performance measurement, and the two paths to external validation — and this final piece argues that AI belongs everywhere in that architecture as a tool for gathering, organizing, and surfacing evidence, and nowhere in it as an autonomous decision-maker. The profession should embrace the efficiency AI offers without ever mistaking that efficiency for a substitute for the accountable human judgment that gives internal audit's conclusions their meaning. Robust, explicit, human-centric governance of AI within quality assurance is not a constraint on the profession's future — it is the condition on which that future remains worth trusting.


Endnotes

1. The Institute of Internal Auditors, Global Practice Guides, "Understanding Data Analytics for Internal Auditors" and "Data Analytics Skills for Internal Auditors," issued May 8, 2026.

2. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Domain IV, technology-related CAE responsibilities.

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.

4. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.

6. Internal Audit Review Quarterly, "Five Years Is Too Long to Wait: The Case for Continuous Self-Assessment Within the SAIV Model," External Quality Assurance Series, Article 4.

7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "internal auditing" and "objectivity."

8. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

9. Wolters Kluwer, "Domain III: Governing the Internal Audit Function," June 2024.

10. The Institute of Internal Auditors, IPPF & Global Internal Audit Standards Documents, Global Guidance suite, 2026.

Jul 23, 2026

8 min read

Five Years Is Too Long to Wait: The Case for Continuous Self-Assessment Within the SAIV Model

This article makes a narrower, and we believe uncontroversial, argument: the self-assessment half of SAIV should not wait five years for its next iteration. GIAS already requires ongoing monitoring and periodic self-assessment under Standard 12.1, separate from the Standard 8.4 external cycle — but "periodic" has too often, in practice, meant "annual at best, and often only in the year before the external assessment is due."[3] I will argue that internal audit functions should run comprehensive self-assessments against the full body of GIAS far more frequently than that — quarterly or even continuously — and that artificial intelligence tools, applied carefully and under human oversight, make this newly practical in a way it simply was not when the current five-year model was designed.

The Standards Already Separate the Two Clocks — the Profession Just Hasn't Used That Freedom

It is worth being precise about what GIAS actually requires, because the case for more frequent self-assessment does not require any change to the Standards at all. Standard 12.1 requires the CAE to develop and conduct internal assessments of the function's conformance and progress, comprising both ongoing monitoring and periodic self-assessment reviews, and to communicate the results to the board and senior management at least annually.[4] Standard 8.4's five-year clock governs only the independent validation — the point at which an outside assessor tests a sample of the self-assessment's conclusions.[5] Nothing in the text ties the frequency of the self-assessment itself to the five-year external cycle. The profession has simply drifted toward treating them as the same clock, largely because a comprehensive, function-wide self-assessment against 52 standards has historically been labour-intensive enough that doing it more than once every few years felt impractical.

That practical constraint is the thing that has changed.

What a Full Self-Assessment Actually Involves — and Why It Has Been Rare

A comprehensive self-assessment under SAIV requires the CAE's team to document, standard by standard, how the function conforms — the same fifty-two standards a full-scope EQA would examine, evidenced through policies, engagement files, board communications, and performance data.[6] Done manually, this is a substantial undertaking: gathering evidence across every domain, cross-referencing it against the Standards' requirements, and identifying gaps takes weeks of dedicated staff time even for a moderately sized function. It is not hard to see why CAEs have historically reserved this effort for the run-up to the mandated external validation, treating the intervening years as a lower-intensity monitoring exercise rather than a repeat of the full assessment.

What AI Changes

Artificial intelligence tools — the same category of data analytics and AI capability the IIA has itself begun formally addressing through recent Global Practice Guides on data analytics and AI skills for internal auditors[7] — change the economics of this exercise substantially. Applied to the self-assessment process specifically, AI can:

- Continuously cross-reference engagement documentation against Standards requirements, flagging where a completed engagement's working papers appear to fall short of a specific standard's evidentiary expectations, rather than waiting for a periodic manual review to catch the same gap months later.

- Track performance indicators established under Standard 12.2 in real time, surfacing drift from board-agreed objectives as it happens rather than at the next scheduled reporting interval.

- Maintain a living conformance record that consolidates evidence for each of the 52 standards as it is generated throughout the year, so that a "self-assessment" becomes a continuously updated artefact rather than a periodic reconstruction project.

- Reduce the marginal cost of each additional self-assessment cycle close to zero once the underlying documentation pipeline exists, because the heavy lifting — gathering and organizing evidence — no longer needs to be repeated from scratch each time.

None of this replaces the judgment of the CAE or the internal audit team. It replaces the labour of assembling and cross-referencing evidence, which is precisely the labour that made frequent self-assessment impractical in the first place. The professional judgment about whether the evidence actually demonstrates conformance remains, as it must, a human determination.

Why More Frequent Self-Assessment Strengthens — Rather Than Duplicates — the SAIV Model

A sceptic might ask why this matters if the independent validation still only happens every five years regardless. The answer is that the value of SAIV depends entirely on the quality of the self-assessment the independent assessor is validating. The IIA's own guidance on how a SAIV validation is conducted — reviewing a sample of working papers already assessed internally, alongside a sample not previously reviewed — makes clear that the assessor's confidence in the whole self-assessment rests on how rigorously and recently that self-assessment was actually performed.[8] A self-assessment substantially reconstructed in the months before the external validation is a weaker foundation than one built continuously, with each quarter's evidence gathered and evaluated close to when the underlying engagement work actually occurred, while memories are fresh and documentation gaps are still fixable.

There is a second, more immediate benefit that has nothing to do with the five-year cycle at all. GIAS requires the CAE to communicate internal assessment results and any related action plans to the board and senior management at least annually.[9] A CAE running quarterly, AI-assisted self-assessments has something far more substantive to report at each of those checkpoints than a CAE relying on a lighter-touch annual review: a current, evidenced picture of exactly where the function stands against all 52 standards, with gaps identified and remediation already underway well before the next external validation is due. That is not a compliance nicety. It is the difference between a board that learns about a conformance gap in year four of a five-year cycle, with limited time to see it fixed before the external assessor arrives, and a board that has been tracking remediation in near-real time since the gap first appeared.

Guardrails: What This Proposal Does Not Argue For

To be clear about the limits of this argument: nothing here suggests that AI-assisted frequency should be used to argue for reducing the five-year independent validation requirement, substituting AI output for the independent assessor's judgment, or allowing AI tools to reach conclusions about conformance without human review. The point of more frequent self-assessment is to make the evidence base better and more current — not to change who is accountable for judging it. The CAE remains accountable for every conclusion the self-assessment reaches, and the independent assessor's role in testing that self-assessment against a sample of evidence every five years remains exactly as GIAS prescribes it. The next article in this series addresses, more broadly, why that human accountability must remain non-negotiable as AI's role in internal audit expands.

Conclusion

The five-year cycle for independent validation under Standard 8.4 is sound and should not change. What should change is the assumption, more habit than requirement perhaps, that the self-assessment component of SAIV needs to wait for that same five-year clock. GIAS already permits — and its Standard 12.1 requirement for ongoing monitoring arguably already expects — a far more frequent rhythm of self-assessment than the profession has typically delivered. AI tools now make that frequency achievable without a proportional increase in staff burden. Internal audit functions that continue to treat self-assessment as a once-every-few-years reconstruction exercise are leaving real quality-assurance value on the table, not because the Standards prevent them from claiming it, but because the tools to claim it affordably have only recently become available.


Endnotes

1. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

2. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

4. Ibid.

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

6. Baker Tilly, "Preparing for Your External Quality Assessment under the [Global Internal Audit Standards]," July 2025.

7. The Institute of Internal Auditors, Global Practice Guides, "Understanding Data Analytics for Internal Auditors" and "Data Analytics Skills for Internal Auditors," issued May 8, 2026.

8. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

9. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

Jul 23, 2026

7 min read

Editor's Introduction - Edition 3, Q3, 2026

Quality assurance has sometimes been treated as a periodic compliance exercise: something that happens internally on an ongoing basis, with a more formal assessment every five years. The Standards, however, invite us to think more broadly. They provide a framework that encompasses governance, conformance, performance, continuous improvement, and external assurance. The challenge now is to turn that framework into a quality culture that genuinely strengthens internal audit functions and increases the confidence of the boards and audit committees they serve.

This edition of Internal Audit Review explores that challenge from five different perspectives.

We begin by examining the architecture of quality assurance created by the Global Internal Audit Standards and what it means for internal audit leaders seeking to build an effective and credible quality framework.

We then consider a question that deserves more debate: is the fully external model still the unquestioned gold standard for quality assessment? There is a strong case for independent external scrutiny, but the profession should also be willing to examine whether a well-designed Self-Assessment with Independent Validation (SAIV), particularly as technology develops, might deliver greater value than it has traditionally been given credit for.

The discussion then moves from the periodic assessment to the Quality Assurance and Improvement Program itself. A QAIP should be much more than paperwork or evidence assembled for an assessment. Properly designed, it is a defence for the internal audit function — helping demonstrate its value, identify weaknesses before they become significant, and provide the board with confidence that quality is being actively managed.

That leads to the question of time. Five years is a long time to wait for an independent view of quality. Our fourth article explores the case for continuous self-assessment within the SAIV model and asks whether internal audit should be thinking about quality as a continuous discipline rather than a point-in-time event.

Finally, we turn to artificial intelligence. AI has the potential to transform how quality assurance is performed — from analysing evidence and identifying patterns to supporting standards mapping and continuous monitoring. But technology brings its own risks. There is an argument for AI augmentation, not autonomy. AI can strengthen the quality assessment process, but professional judgment, accountability, and independence must remain firmly with people.

Taken together, these articles are not intended to argue for one single model of quality assurance. Rather, they ask whether the profession should be prepared to challenge some of its assumptions about how quality is assessed, demonstrated, and improved.

The future of quality assurance may not be about choosing between internal and external assessment, or between human judgment and technology. It may instead be about combining them intelligently: continuous internal scrutiny, meaningful independent validation, appropriate external challenge, and technology that enables professionals to examine more evidence and identify more insight without surrendering their judgment.

The 2024 Standards provide the architecture. It is now up to the profession to decide how ambitious we want to be in building upon it.

Augmentation, Not Autonomy: Why AI Must Never Replace Professional Judgment in Quality Assurance

This final article in the series looks forward, but it makes a case that is deliberately conservative about where the line between human and machine responsibility must sit: AI can and should be embedded throughout the quality assurance options GIAS provides — the QAIP, internal quality assessment, and both models of external quality assessment — but it must never be permitted to make autonomous decisions about conformance, findings, or improvement. Every one of those judgments must remain the responsibility of a qualified human professional, exercised under governance robust enough to prove it.

Where AI Genuinely Belongs in the GIAS Quality Framework

There is a substantial, legitimate role for AI across every quality assurance mechanism GIAS establishes, and the profession should not shy away from it.

Within the QAIP (Standard 8.3), AI can consolidate evidence continuously across the fifty-two standards, maintaining a current picture of the function's documented conformance rather than one reconstructed periodically.[3] Within internal quality assessment (Standard 12.1), AI can support ongoing monitoring by flagging engagements whose documentation appears to depart from methodology or from a specific standard's requirements, giving human reviewers a prioritized list of items to examine rather than requiring them to review everything with equal, undifferentiated attention.[4] Within performance measurement (Standard 12.2), AI can track key performance indicators in something close to real time, surfacing drift from board-agreed objectives well before an annual reporting cycle would otherwise reveal it.[5] And within external quality assessment — whether full-scope or self-assessment with independent validation (SAIV) — AI can accelerate the evidence-gathering and cross-referencing work that has historically consumed the bulk of an assessment's timeline, as the preceding article in this series argued in more detail.[6]

In each case, the value AI adds is the same: it compresses the labour of finding, organizing, and surfacing relevant information. That is a genuine and, I would argue, an increasingly necessary contribution as the volume of data an internal audit function generates continues to grow.

Where AI Must Stop

The line we want to draw is equally simple to state, even though holding it in practice will require real discipline: AI may surface evidence, patterns, and anomalies. It must never be the entity that decides what those things mean for conformance, for a finding's significance, or for whether the function — or an individual engagement — has met the Standards.

This is not a technological limitation I am describing; it is a governance choice, and it needs to be an explicit one, because the technological limitation is eroding. AI systems are becoming more capable of producing plausible-sounding conclusions, not merely flagged anomalies, and the temptation to let a sufficiently confident system's output stand in for a human conclusion will only grow. GIAS's own definition of internal auditing describes it as a discipline that helps organizations achieve their objectives through "professional judgments" applied without compromise, and its glossary defines objectivity itself as the "unbiased mental attitude that allows internal auditors to make professional judgments, fulfil their responsibilities, and achieve the Purpose of Internal Auditing without compromise."[7] Professional judgment, by definition, is judgment exercised by a professional — a human being accountable to a code of ethics, a licensing or certification body, and ultimately to the board. An AI system has none of those things. It cannot be held to the IIA's Code of Ethics. It cannot lose a CIA credential for negligence. It cannot be asked, in the way a human assessor can, to explain the reasoning behind a judgment call in circumstances the training data did not anticipate. Whatever role AI plays in quality assurance, it cannot inherit the accountability that makes a conclusion about conformance mean anything.

This applies with particular force to quality assurance specifically, because quality assurance is the mechanism that is supposed to catch failures everywhere else in the function — including, potentially, failures in how the function itself is using AI in its audit engagements. A quality assurance process that has delegated its own judgment to an autonomous system has no independent means of catching that system's own errors, blind spots, or drift. It would be, in effect, asking AI to grade its own homework.

The Governance Structure This Requires

If AI is to be embedded across the QAIP, internal assessment, and external assessment processes without ever making autonomous decisions, that boundary needs to be actively governed, not just assumed. I would propose that internal audit functions adopting AI within their quality assurance processes commit to several concrete practices:

Every AI-surfaced finding requires human sign-off before it becomes a conclusion. An AI tool that flags a potential nonconformance is producing a lead for a human reviewer to investigate, not a finding. The distinction should be documented and auditable — literally, since the QAIP itself is subject to assessment — so that an external assessor reviewing the function's quality process can see exactly where AI's contribution ended and human judgment began.

The independent assessor role in a full-scope EQA or SAIV validation must remain unambiguously human, and specifically must continue to include at least one individual holding an active Certified Internal Auditor credential, as Standard 8.4 already requires.[8] Whatever AI tools an assessment team uses to accelerate its own evidence review, the conclusion the assessor signs — the rating of Full Achievement, General Achievement, or Partial/Non-Achievement — must remain a human professional's attestation, made on that professional's own accountability.

Boards and audit committees should ask, as a standing governance question, how AI is used within the function's QAIP — not only how AI is used in audit engagements themselves. GIAS already requires the board to understand the robustness of the quality assessment process in order to build trust in the function; in an AI-embedded environment, that robustness question now has a new dimension, and boards should not assume the answer is satisfactory without asking.[9]

CAEs should treat AI governance within quality assurance as itself a component of the QAIP, subject to the same continuous monitoring, documentation, and improvement discipline as every other aspect of the function. An AI tool that quietly changes its own flagging thresholds, or that is updated by a vendor without internal audit's own review, is a conformance risk in exactly the sense Standard 8.3 exists to catch.

A Deliberately Conservative Position

We recognize this is a more conservative position than some in the profession will want to adopt, particularly as AI tools become demonstrably better at tasks that currently require human review. Our argument is not that AI will remain incapable of producing reliable conformance judgments — it may well become very good at this, sooner than many expect. Our argument is that internal audit's value to the organizations it serves rests specifically on the fact that its conclusions are the product of accountable human professional judgment, exercised by people who can be questioned, challenged, and held responsible in a way no software system can be. Quality assurance is the mechanism that is supposed to guarantee that judgment was actually applied, carefully, throughout the function's work. If quality assurance itself becomes an autonomous process, the guarantee it is meant to provide disappears, even if the AI making the decisions turns out, most of the time, to be right.

Conclusion

The IIA's own guidance already points toward deep AI integration across internal audit's data analytics and assurance capabilities, and quality assurance will be no exception.[10] The five articles in this series have examined the architecture GIAS builds for quality — the QAIP, internal assessment, performance measurement, and the two paths to external validation — and this final piece argues that AI belongs everywhere in that architecture as a tool for gathering, organizing, and surfacing evidence, and nowhere in it as an autonomous decision-maker. The profession should embrace the efficiency AI offers without ever mistaking that efficiency for a substitute for the accountable human judgment that gives internal audit's conclusions their meaning. Robust, explicit, human-centric governance of AI within quality assurance is not a constraint on the profession's future — it is the condition on which that future remains worth trusting.


Endnotes

1. The Institute of Internal Auditors, Global Practice Guides, "Understanding Data Analytics for Internal Auditors" and "Data Analytics Skills for Internal Auditors," issued May 8, 2026.

2. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Domain IV, technology-related CAE responsibilities.

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.

4. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.

6. Internal Audit Review Quarterly, "Five Years Is Too Long to Wait: The Case for Continuous Self-Assessment Within the SAIV Model," External Quality Assurance Series, Article 4.

7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "internal auditing" and "objectivity."

8. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

9. Wolters Kluwer, "Domain III: Governing the Internal Audit Function," June 2024.

10. The Institute of Internal Auditors, IPPF & Global Internal Audit Standards Documents, Global Guidance suite, 2026.

Five Years Is Too Long to Wait: The Case for Continuous Self-Assessment Within the SAIV Model

This article makes a narrower, and we believe uncontroversial, argument: the self-assessment half of SAIV should not wait five years for its next iteration. GIAS already requires ongoing monitoring and periodic self-assessment under Standard 12.1, separate from the Standard 8.4 external cycle — but "periodic" has too often, in practice, meant "annual at best, and often only in the year before the external assessment is due."[3] I will argue that internal audit functions should run comprehensive self-assessments against the full body of GIAS far more frequently than that — quarterly or even continuously — and that artificial intelligence tools, applied carefully and under human oversight, make this newly practical in a way it simply was not when the current five-year model was designed.

The Standards Already Separate the Two Clocks — the Profession Just Hasn't Used That Freedom

It is worth being precise about what GIAS actually requires, because the case for more frequent self-assessment does not require any change to the Standards at all. Standard 12.1 requires the CAE to develop and conduct internal assessments of the function's conformance and progress, comprising both ongoing monitoring and periodic self-assessment reviews, and to communicate the results to the board and senior management at least annually.[4] Standard 8.4's five-year clock governs only the independent validation — the point at which an outside assessor tests a sample of the self-assessment's conclusions.[5] Nothing in the text ties the frequency of the self-assessment itself to the five-year external cycle. The profession has simply drifted toward treating them as the same clock, largely because a comprehensive, function-wide self-assessment against 52 standards has historically been labour-intensive enough that doing it more than once every few years felt impractical.

That practical constraint is the thing that has changed.

What a Full Self-Assessment Actually Involves — and Why It Has Been Rare

A comprehensive self-assessment under SAIV requires the CAE's team to document, standard by standard, how the function conforms — the same fifty-two standards a full-scope EQA would examine, evidenced through policies, engagement files, board communications, and performance data.[6] Done manually, this is a substantial undertaking: gathering evidence across every domain, cross-referencing it against the Standards' requirements, and identifying gaps takes weeks of dedicated staff time even for a moderately sized function. It is not hard to see why CAEs have historically reserved this effort for the run-up to the mandated external validation, treating the intervening years as a lower-intensity monitoring exercise rather than a repeat of the full assessment.

What AI Changes

Artificial intelligence tools — the same category of data analytics and AI capability the IIA has itself begun formally addressing through recent Global Practice Guides on data analytics and AI skills for internal auditors[7] — change the economics of this exercise substantially. Applied to the self-assessment process specifically, AI can:

- Continuously cross-reference engagement documentation against Standards requirements, flagging where a completed engagement's working papers appear to fall short of a specific standard's evidentiary expectations, rather than waiting for a periodic manual review to catch the same gap months later.

- Track performance indicators established under Standard 12.2 in real time, surfacing drift from board-agreed objectives as it happens rather than at the next scheduled reporting interval.

- Maintain a living conformance record that consolidates evidence for each of the 52 standards as it is generated throughout the year, so that a "self-assessment" becomes a continuously updated artefact rather than a periodic reconstruction project.

- Reduce the marginal cost of each additional self-assessment cycle close to zero once the underlying documentation pipeline exists, because the heavy lifting — gathering and organizing evidence — no longer needs to be repeated from scratch each time.

None of this replaces the judgment of the CAE or the internal audit team. It replaces the labour of assembling and cross-referencing evidence, which is precisely the labour that made frequent self-assessment impractical in the first place. The professional judgment about whether the evidence actually demonstrates conformance remains, as it must, a human determination.

Why More Frequent Self-Assessment Strengthens — Rather Than Duplicates — the SAIV Model

A sceptic might ask why this matters if the independent validation still only happens every five years regardless. The answer is that the value of SAIV depends entirely on the quality of the self-assessment the independent assessor is validating. The IIA's own guidance on how a SAIV validation is conducted — reviewing a sample of working papers already assessed internally, alongside a sample not previously reviewed — makes clear that the assessor's confidence in the whole self-assessment rests on how rigorously and recently that self-assessment was actually performed.[8] A self-assessment substantially reconstructed in the months before the external validation is a weaker foundation than one built continuously, with each quarter's evidence gathered and evaluated close to when the underlying engagement work actually occurred, while memories are fresh and documentation gaps are still fixable.

There is a second, more immediate benefit that has nothing to do with the five-year cycle at all. GIAS requires the CAE to communicate internal assessment results and any related action plans to the board and senior management at least annually.[9] A CAE running quarterly, AI-assisted self-assessments has something far more substantive to report at each of those checkpoints than a CAE relying on a lighter-touch annual review: a current, evidenced picture of exactly where the function stands against all 52 standards, with gaps identified and remediation already underway well before the next external validation is due. That is not a compliance nicety. It is the difference between a board that learns about a conformance gap in year four of a five-year cycle, with limited time to see it fixed before the external assessor arrives, and a board that has been tracking remediation in near-real time since the gap first appeared.

Guardrails: What This Proposal Does Not Argue For

To be clear about the limits of this argument: nothing here suggests that AI-assisted frequency should be used to argue for reducing the five-year independent validation requirement, substituting AI output for the independent assessor's judgment, or allowing AI tools to reach conclusions about conformance without human review. The point of more frequent self-assessment is to make the evidence base better and more current — not to change who is accountable for judging it. The CAE remains accountable for every conclusion the self-assessment reaches, and the independent assessor's role in testing that self-assessment against a sample of evidence every five years remains exactly as GIAS prescribes it. The next article in this series addresses, more broadly, why that human accountability must remain non-negotiable as AI's role in internal audit expands.

Conclusion

The five-year cycle for independent validation under Standard 8.4 is sound and should not change. What should change is the assumption, more habit than requirement perhaps, that the self-assessment component of SAIV needs to wait for that same five-year clock. GIAS already permits — and its Standard 12.1 requirement for ongoing monitoring arguably already expects — a far more frequent rhythm of self-assessment than the profession has typically delivered. AI tools now make that frequency achievable without a proportional increase in staff burden. Internal audit functions that continue to treat self-assessment as a once-every-few-years reconstruction exercise are leaving real quality-assurance value on the table, not because the Standards prevent them from claiming it, but because the tools to claim it affordably have only recently become available.


Endnotes

1. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

2. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

4. Ibid.

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.

6. Baker Tilly, "Preparing for Your External Quality Assessment under the [Global Internal Audit Standards]," July 2025.

7. The Institute of Internal Auditors, Global Practice Guides, "Understanding Data Analytics for Internal Auditors" and "Data Analytics Skills for Internal Auditors," issued May 8, 2026.

8. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

9. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

The Quality Assurance and Improvement Program As the Internal Audit Function's Defence

The QAIP Is the Only Thing Standing Between "Trust Us" and "Verify Us"

Internal audit's entire mandate rests on a single premise: that when internal audit says a control is effective, a risk is managed, or a process is compliant, the board and senior management can rely on that conclusion without independently re-checking it. That premise only holds if internal audit's own work is itself subject to the same discipline it applies to everyone else. GIAS does not leave this to good intentions. Standard 8.3 requires the CAE to develop, implement, and maintain a QAIP covering all aspects of the internal audit function, and the Standards define the QAIP as a program to "evaluate and ensure the internal audit function conforms with the Global Internal Audit Standards, achieves performance objectives, and pursues continuous improvement."[2] That is a demanding brief. It is not a request for a periodic self-congratulatory review; it is a mandate for continuous, evidenced self-scrutiny.

A CAE who treats the QAIP as a once-every-five-years exercise, assembled in the months before an external quality assessment, is not implementing what Standard 8.3 requires. They are implementing a much weaker thing that happens to share the same name.

Three Standards, One Program, No Room to Pick and Choose

GIAS makes the QAIP's scope explicit by binding three separate standards into it. Standard 12.1, Internal Quality Assessment, requires ongoing monitoring of engagement performance and periodic self-assessment of the function.[3] Standard 12.2, Performance Measurement, requires the CAE to set performance objectives — key performance indicators agreed with input from the board and senior management — and to build action plans when those objectives are not met.[4] Standard 12.3, Oversee and Improve Engagement Performance, requires methodologies for engagement supervision, quality assurance, and competency development.[5] The IIA's own quality guidance is unambiguous that these three standards, together with the external assessment requirement in Standard 8.4, together constitute the QAIP.[6]

We raise this structural point because it forecloses a common evasion: the CAE who says "we have a QAIP" while pointing only to the external assessment every five years, or only to an annual internal audit satisfaction survey, is describing a fragment of the requirement, not the requirement itself. A QAIP that lacks continuous engagement supervision, that lacks documented performance measurement against board-informed objectives, or that lacks ongoing internal monitoring is not partially compliant — it is not a QAIP as GIAS defines the term. The profession should stop granting itself partial credit for partial implementation.

What a Neglected QAIP Actually Costs

The cost of treating the QAIP as an occasional exercise is not abstract. Consider what a genuine QAIP is supposed to catch, continuously, rather than once every five years: engagements delivered without adequate supervision; a function whose performance has quietly drifted from the objectives the board thought it had agreed to; conformance gaps that accumulate for years before an external assessor happens to find them. GIAS requires the CAE to communicate the results of the internal quality assessment to the board and senior management at least annually, precisely because the Standards' authors understood that quality problems discovered only once every five years are quality problems that went unmanaged for most of that period.[7]

There is also a reputational cost that becomes visible only in hindsight. When an external quality assessment surfaces significant non-conformance, the first question a serious board should — and increasingly will — ask is not "what went wrong in the audit engagements?" but "what was the QAIP doing for the years in between assessments?" A CAE who cannot answer that question with evidence of continuous monitoring, documented performance tracking, and active engagement supervision has no good answer to give. The QAIP is, in this sense, the function's defence file — the record that demonstrates the CAE was managing quality actively, not waiting for someone else to discover its absence.

The QAIP as a Source of Value, Not Just Risk Mitigation

It would be a mistake to frame the QAIP purely as a defensive necessity, because doing so undersells its constructive purpose. Standard 12.2's requirement for performance objectives developed with board and senior management input is, properly used, a mechanism for internal audit to demonstrate its value in terms the organization's leadership actually cares about — not just conformance with the Standards, but efficiency, stakeholder satisfaction, and contribution to organizational objectives.[8] A CAE who takes this requirement seriously has, built into the mandatory framework, a continuous feedback loop with the board about what the function is delivering and where it is falling short. Functions that resist building this loop are not avoiding bureaucracy; they are declining a structured opportunity to prove their worth on an ongoing basis, and leaving that proof to happen, if at all, only once every five years.

The Objection: "We Are Too Small for This"

The most sympathetic objection to a demanding QAIP comes from small internal audit functions, sometimes staffed by a single person, for whom continuous monitoring, formal performance measurement, and engagement supervision can seem like requirements written for a Fortune 500 audit shop. GIAS itself acknowledges this tension and states plainly that if a function comprises only one member, an adequate QAIP will require assistance from outside the function.[9] We take this seriously, but it does not weaken the argument — it reinforces it. GIAS did not respond to small-function constraints by lowering the bar on what a QAIP must achieve; it responded by requiring small functions to bring in outside help to meet that bar. The Standards treat a rigorous QAIP as non-negotiable regardless of headcount, which tells the profession something about how central the drafters considered it to be.

Conclusion

The QAIP is not a document produced for an assessor's benefit once every five years. It is the continuous mechanism by which internal audit earns, and re-earns, the trust the board places in it every time the function issues an opinion. Standards 8.3, 12.1, 12.2, and 12.3 do not describe a periodic compliance task; they describe an operating discipline. CAEs who build that discipline — ongoing monitoring, documented performance measurement, active engagement supervision, and an internal assessment cycle that reports to the board at least annually — are not doing more than GIAS requires. They are, finally, doing what it always asked of them. The profession should stop treating the QAIP as paperwork, because the alternative is a quality assurance program that exists mostly in name, discovered to be missing only when it is too late to matter.


Endnotes

1. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.

2. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "quality assurance and improvement program."

3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

4. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.

5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.3, Oversee and Improve Engagement Performance.

6. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."

7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.

8. Wolters Kluwer, "How Internal Quality Assessment Enhances Internal Audit Performance," 2026.

9. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Considerations for Implementation, cross-reference to Standards 10.1, 12.1, and 12.3.

Global Internal Audit Standards via CIA Exam Type MCQs – 05

Standard 1.2 Organization's Ethical Expectations

Before speaking about Standard 1.2, I have to declare that standards are interrelated. So it is possible that an MCQ can be solved based on more standards.

Standard 1.2 requires internal auditors to understand, respect, meet, and contribute to the legitimate and ethical experctaion of the organization. 

This standard is a core component of the CIA Exam Part 1 (Internal Audit Fundamentals) under Section B: Ethics and Professionalism. Let’s look at a practical application from Zain Academy’s CIA Part 1 (2026).

MCQ 1002 (p. 5677) Objectivity is an ethical requirement for all persons engaged in the professional practice of internal auditing. One aspect of objectivity requires:

A. Performance of professional duties in accordance with relevant laws.

B. Avoidance of conflict of interest.

C. Refraining from using confidential information for unethical or illegal advantage.

D. Maintenance of an appropriate level of professional expertise.

Correct answer is B. Commitment to independence from conflicts of economic or professional interest is an aspect of objectivity. It requires that internal auditors do not subordinate their judgment on audit matters to others, which is why avoiding conflicts of interest—whether real or perceived—is a mandatory safeguard.

Why the others are not appropriate?

🔴 Option A – This is an Integrity issue.

🔴 Option C – This is a Confidentiality issue.

🔴 Option D – This is a Competency issue.

We also can see another MCQ from Zain reflecting the "appearance" of bias:

MCQ 152 (p. 3977) Which of the following most accurately describes why the appearance of objectivity impairment matters even if an auditor believes they can remain unbiased?

A. Appearance concerns only matter for external audit relationships, not internal functions.

B. Perceived lack of objectivity undermines stakeholder trust in audit findings and recommendations.

C. Professional standards only require addressing actual bias, not perceived bias.

D. Perceptions of bias are easily corrected through proper documentation of procedures.

Correct answer is B. Perceived lack of objectivity undermines stakeholder trust in audit findings and recommendations. Even when an auditor maintains actual objectivity, the appearance of bias can damage credibility and reduce acceptance of audit conclusions, limiting the function's effectiveness and value.

Why the others are not appropriate?

❌ Option A - Appearance concerns matter for both internal and external functions, as both rely on stakeholder trust. ❌ Option C - Standards address both actual AND perceived impairments, as appearance directly affects audit effectiveness. ❌ Option D - Documentation alone cannot resolve appearance issues. Perceptions of bias often require structural safeguards like reassignment or recusal.

Global Internal Audit Standards via CIA Exam Type MCQs – 04

Standard 1.1: Honesty and Professional Courage

As we see in Domain II: Ethics and Professionalism, Principle 1 requires internal auditors to Demonstrate Integrity. This domain establishes the essential ethical requirements and professional expectations to ensure trust and reliability in our work.

Principle 1 establishes integrity as the fundamental bedrock of the profession, requiring auditors to act with honesty and courage even under significant external pressure.

Standard 1.1: Honesty and Professional Courage – Internal auditors must perform their work with honesty and professional courage. This mandates maintaining absolute truthfulness in all communications and ensuring they are free from the omission of material facts.

This standard is a core component of the CIA Exam Part 1 (Internal Audit Fundamentals) under Section B: Ethics and Professionalism. Let’s look at a practical application from Zain Academy’s CIA Part 1 (2026).

MCQ 974 (p. 5621) Which of the following situations is a violation of The IIA’s Standards of Ethics and Professionalism?

A. An internal auditor, with the knowledge and consent of management, accepted a token gift from a customer of the organization that was not presumed to impair and did not impair judgment.

B. Knowing that management was aware of the situation, an internal auditor purposely left a description of an unlawful practice out of the final engagement communication.

C. An internal auditor shared techniques with internal auditors from another organization.

D. Based upon knowledge of the probable success of the employer’s business, an internal auditor invested in a mutual fund that specialized in the same industry.

Correct Answer: B

The Explanation: Standard 1.1 states that “Internal auditors must disclose all material facts known to them that, if not disclosed, could affect the organization’s ability to make well-informed decisions”. Choosing to omit an unlawful practice—even if management already knows about it—is a failure of professional courage and honesty.

Why the others are NOT violations:

Choice A: Acceptance of a gift is only prohibited if it impairs (or is presumed to impair) professional judgment. Token gifts with management's consent usually do not cross this line.

Choice C: Sharing audit techniques is encouraged under the Competency principle, as it helps auditors continually improve their proficiency and the quality of their services.

Choice D: While using confidential information for personal gain is prohibited (e.g., buying specific company stock), investing in a broad mutual fund is generally acceptable as the auditor does not control the specific holdings within that fund.



Global Internal Audit Standards via CIA Exam Type MCQs – 03

We are concluding Domain I: Purpose of Internal Auditing. First, let's summarize the key differences between assurance and advisory services based on our previous MCQs:

Scope Determination: In assurance, the auditor decides; in advisory, the auditor and client agree together.

Parties Involved: Assurance is a three-party relationship (auditor, auditee, user), while advisory involves only two parties (auditor and client).

Let’s look at a practical MCQ from Zain Academy’s CIA Part 1 (2026):

MCQ 1752 (p. 3558): Which of the following is an example of an advisory engagement?

A. The internal audit function is asked to verify that the organization adheres to policy requirements. 

B. The director engages internal audit to review and recommend improvements for cash controls at an offsite location. 

C. The board requests an opinion on management’s claim that a segment was profitable in Q1. 

D. The CAE is asked by the board to evaluate the effectiveness of operations.

Correct answer: B. Explanation: Reviewing and recommending improvements for controls is an advisory service because it focuses on providing guidance without assuming management responsibilities or providing formal assurance.

Option A is a compliance audit (Assurance).

Option C is a financial audit/opinion (Assurance).

Option D is an operational audit (Assurance).

Since I have some characters left, I would like to call your attention to something. Keep in mind, the question can be worded differently.

Watch out for the "Negative Question" trap! MCQs can be tricky. A common "trap" format is: 

"The internal audit function provides assurance services, including the following examples, except:"

In these cases, the "wrong" answer is the correct one. Exam-takers often see "assurance service," and jump to Option A right away, and lose points by not noticing the exception. Always read the full question, and find key words!



Global Internal Audit Standards via CIA Exam Type MCQs – 02

We continue with Domain I: Purpose of Internal Auditing. Before jumping to the numbered standards, we must focus on assurance and advisory services.

As discussed, both are core to the definition of Internal Auditing. It is highly advisable to study these in detail and solve numerous MCQs to distinguish between them effectively. These concepts are explained deeply in Section A: Foundations of Internal Auditing.

Let’s check two MCQs from Zain Academy’s CIA Part 1 (2026). Note: other test banks likely feature similar questions.

MCQ 1523 (p. 3097): When the internal audit function performs an assurance engagement, how many parties are involved?

A. One 

B. Two 

C. Three 

D. The entire organization

Correct answer: C. Explanation: Assurance engagements involve three parties: the process owner (directly involved), the internal auditor (the assessor), and the user of the assessment. The internal audit function determines the scope and provides an objective opinion based on evidence.

In contrast, advisory engagements (consulting) are typically requested by a client. The nature and scope are agreed upon together. There are only two parties involved: the internal auditor (advisor) and the client (advisee).

(note: explanations are shortened so as to keep character limit)

MCQ 1609 (p. 3271): Which of the following criteria would be most useful to a sales department manager in evaluating the performance of the manager’s customer-service group?

A. The customer is always right. 

B. Customer complaints should be processed promptly. 

C. Employees should maintain a positive attitude. 

D. All customer inquiries should be answered within 7 days of receipt.

Correct answer: D. Explanation: A criterion requiring answers within 7 days allows for accurate measurement. This quantitative standard avoids the vagueness and subjectivity of the other options. Other options lack the measurable criteria necessary to form a conclusion in a performance engagement.

Next time, we continue with this topic.

Reach the global Internal Audit community with published articles

Reach the global Internal Audit community with published articles

Reach the global Internal Audit community with published articles

Internal Audit industry news and coverage across the areas of banking, funds, insurance, payments, cryptocurrencies and fintech.

Submit an article

Documentation lies at the heart of internal audits, particularly in the area of data protection. While strong controls and processes are vital, auditors rely on documentation to validate whether these practices are consistent, effective, and sustainable. Preparing robust documentation strategies is therefore one of the most critical steps in audit readiness.

The foundation of documentation is a well-structured policy framework. Organizations should ensure that their data protection policies are current, clearly written, and accessible. These policies must cover data classification, access management, incident response, retention, and disposal. Preparing with documented updates demonstrates that the organization not only establishes but also regularly reviews its controls.

Equally important are records of compliance activities. For instance, training logs, risk assessments, breach reports, and vendor due diligence files all provide concrete evidence of compliance. Maintaining these in a centralized and easily retrievable repository ensures auditors can validate claims efficiently.

Data processing registers form another key area. Internal auditors will expect to see detailed records of what personal data is collected, where it is stored, who has access, and how long it is retained. Preparing such registers in advance not only aids audits but also ensures readiness for regulatory inspections.

Change management documentation is often overlooked but highly relevant. Organizations that implement new systems, migrate to cloud platforms, or alter processes must maintain records of privacy assessments, approval workflows, and testing results. Preparing with these records demonstrates a proactive stance toward risk management.

Incident documentation is also crucial. Even organizations with strong defenses face occasional data breaches or near misses. Preparing with detailed incident reports, root cause analyses, and remediation evidence shows auditors that lessons are learned and improvements applied.

To streamline preparation, organizations should establish standardized templates for documenting compliance activities. This consistency reduces errors, saves time, and ensures uniform quality across departments. Automating document management with compliance software can further reduce the administrative burden while improving accuracy.

Finally, organizations should conduct internal reviews of documentation before the audit begins. Verifying completeness, clarity, and accessibility ensures that evidence supports audit findings effectively. It also prevents delays that could arise from missing or disorganized records.

In conclusion, effective documentation strategies transform audit preparation from a reactive scramble into a proactive process. By maintaining policies, compliance records, processing registers, incident logs, and standardized templates, organizations strengthen their data protection audits and build resilience against regulatory scrutiny.

Documentation lies at the heart of internal audits, particularly in the area of data protection. While strong controls and processes are vital, auditors rely on documentation to validate whether these practices are consistent, effective, and sustainable. Preparing robust documentation strategies is therefore one of the most critical steps in audit readiness.

The foundation of documentation is a well-structured policy framework. Organizations should ensure that their data protection policies are current, clearly written, and accessible. These policies must cover data classification, access management, incident response, retention, and disposal. Preparing with documented updates demonstrates that the organization not only establishes but also regularly reviews its controls.

Equally important are records of compliance activities. For instance, training logs, risk assessments, breach reports, and vendor due diligence files all provide concrete evidence of compliance. Maintaining these in a centralized and easily retrievable repository ensures auditors can validate claims efficiently.

Data processing registers form another key area. Internal auditors will expect to see detailed records of what personal data is collected, where it is stored, who has access, and how long it is retained. Preparing such registers in advance not only aids audits but also ensures readiness for regulatory inspections.

Change management documentation is often overlooked but highly relevant. Organizations that implement new systems, migrate to cloud platforms, or alter processes must maintain records of privacy assessments, approval workflows, and testing results. Preparing with these records demonstrates a proactive stance toward risk management.

Incident documentation is also crucial. Even organizations with strong defenses face occasional data breaches or near misses. Preparing with detailed incident reports, root cause analyses, and remediation evidence shows auditors that lessons are learned and improvements applied.

To streamline preparation, organizations should establish standardized templates for documenting compliance activities. This consistency reduces errors, saves time, and ensures uniform quality across departments. Automating document management with compliance software can further reduce the administrative burden while improving accuracy.

Finally, organizations should conduct internal reviews of documentation before the audit begins. Verifying completeness, clarity, and accessibility ensures that evidence supports audit findings effectively. It also prevents delays that could arise from missing or disorganized records.

In conclusion, effective documentation strategies transform audit preparation from a reactive scramble into a proactive process. By maintaining policies, compliance records, processing registers, incident logs, and standardized templates, organizations strengthen their data protection audits and build resilience against regulatory scrutiny.

Documentation lies at the heart of internal audits, particularly in the area of data protection. While strong controls and processes are vital, auditors rely on documentation to validate whether these practices are consistent, effective, and sustainable. Preparing robust documentation strategies is therefore one of the most critical steps in audit readiness.

The foundation of documentation is a well-structured policy framework. Organizations should ensure that their data protection policies are current, clearly written, and accessible. These policies must cover data classification, access management, incident response, retention, and disposal. Preparing with documented updates demonstrates that the organization not only establishes but also regularly reviews its controls.

Equally important are records of compliance activities. For instance, training logs, risk assessments, breach reports, and vendor due diligence files all provide concrete evidence of compliance. Maintaining these in a centralized and easily retrievable repository ensures auditors can validate claims efficiently.

Data processing registers form another key area. Internal auditors will expect to see detailed records of what personal data is collected, where it is stored, who has access, and how long it is retained. Preparing such registers in advance not only aids audits but also ensures readiness for regulatory inspections.

Change management documentation is often overlooked but highly relevant. Organizations that implement new systems, migrate to cloud platforms, or alter processes must maintain records of privacy assessments, approval workflows, and testing results. Preparing with these records demonstrates a proactive stance toward risk management.

Incident documentation is also crucial. Even organizations with strong defenses face occasional data breaches or near misses. Preparing with detailed incident reports, root cause analyses, and remediation evidence shows auditors that lessons are learned and improvements applied.

To streamline preparation, organizations should establish standardized templates for documenting compliance activities. This consistency reduces errors, saves time, and ensures uniform quality across departments. Automating document management with compliance software can further reduce the administrative burden while improving accuracy.

Finally, organizations should conduct internal reviews of documentation before the audit begins. Verifying completeness, clarity, and accessibility ensures that evidence supports audit findings effectively. It also prevents delays that could arise from missing or disorganized records.

In conclusion, effective documentation strategies transform audit preparation from a reactive scramble into a proactive process. By maintaining policies, compliance records, processing registers, incident logs, and standardized templates, organizations strengthen their data protection audits and build resilience against regulatory scrutiny.

2 min read

About Internal Audit Review

A multidisciplinary review board providing independent, forward-thinking guidance alongside leadership to enhance audit quality, anticipate emerging risks, and drive organizational resilience.

Newsletter

Subscribe now to get timely updates and in-depth insights designed to keep you ahead of the curve.

© 2026

All Rights Reserved

About Internal Audit Review

A multidisciplinary review board providing independent, forward-thinking guidance alongside leadership to enhance audit quality, anticipate emerging risks, and drive organizational resilience.

Newsletter

Subscribe now to get timely updates and in-depth insights designed to keep you ahead of the curve.

© 2026

All Rights Reserved

About Internal Audit Review

A multidisciplinary review board providing independent, forward-thinking guidance alongside leadership to enhance audit quality, anticipate emerging risks, and drive organizational resilience.

Newsletter

Subscribe now to get timely updates and in-depth insights designed to keep you ahead of the curve.

© 2026

All Rights Reserved