,

Internal Audit’s Role in ERM: Assurance, Advice, and Limits

Every few years a board asks internal audit to “own risk management for a while,” and every few years a chief audit executive discovers what that costs. The function that builds the enterprise risk register cannot audit it; the function that sets the risk appetite cannot give assurance that management stays within it; the function that facilitates every risk workshop becomes the reason the business never learned to run its own. The opposite failure is quieter and more common: internal audit treats ERM as someone else’s department, audits it once every five years as a documentation exercise, and never tells the board whether the risk picture it receives each quarter is true. Between those two lies the actual role, which the IIA has described since 2004 and rewrote for the Three Lines Model in 2020: assurance over risk management as its core, advice with safeguards where the organization needs it, and a short list of things it must never do.

This guide sets out that role in usable form: the roles table with the safeguard for every legitimate advisory role, the charter language that makes the boundaries enforceable, a five-level ERM maturity rubric across six dimensions, a fifteen-row ERM audit work program, an annual ERM assurance calendar, a worked maturity assessment with two findings at the site’s running example company, and the failures that recur. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, the Three Lines Model, and COSO’s Enterprise Risk Management framework (2017), and it sits alongside the site’s guides on risk appetite, the RCSA process, and the risk register, which cover the instruments this guide audits.

In this guide

What ERM is, and what internal audit is auditing when it audits it

Enterprise risk management is the set of practices by which an organization identifies the risks to its objectives, decides how much of each it will accept, responds to them, and reports on them, across the whole enterprise rather than one function at a time. COSO’s 2017 framework organizes it into five components (governance and culture; strategy and objective-setting; performance; review and revision; information, communication, and reporting) and twenty principles, and its main departure from the 2004 version was to tie risk to strategy: the framework asks how risk is considered when strategy is chosen, not only how risks to a chosen strategy are managed. ISO 31000:2018 covers similar ground with a principles-framework-process structure and is the reference in many non-US organizations. Neither is a checklist; both are descriptions of what a mature organization does, and an audit against either is an audit of practice, not of documents.

What internal audit audits, therefore, is not whether a risk register exists but whether the organization’s risk management changes decisions. The evidence of that is specific: a strategy paper that shows the risk analysis behind the option chosen; a risk appetite statement with metrics that have breached and produced a response; a risk register whose ratings moved after an event and whose owners can say what they did; a board that receives a risk report and minutes a decision on it. The COSO 17 principles guide covers the internal control framework that ERM sits on top of, and the distinction matters for scoping: an audit of controls over a process is not an audit of ERM, and an audit of ERM that only tests the register has audited a document.

The roles table: core, legitimate with safeguards, and never

The IIA’s 2004 position paper drew the picture as a fan: core assurance roles in the center, legitimate consulting roles with safeguards around them, and roles internal audit should not undertake at the edge. The 2020 Three Lines Model and the Global Internal Audit Standards keep the substance and change the vocabulary: the third line provides independent assurance over the first and second lines’ management of risk, may provide advice, and must not assume management responsibilities. The table below is the fan, updated, with the safeguard that makes each middle-column role legitimate written next to it, because the safeguard is the part functions forget.

Core assurance roles (do these)Legitimate advisory rolesSafeguard that keeps the advisory role legitimateRoles internal audit must not take
Give assurance on the design and operation of the ERM framework and processFacilitate risk identification and assessment workshopsManagement owns the outputs and signs them; audit records that it facilitated, and does not rate the risks itself; audit does not assure the workshop outputs in the same cycleSet the risk appetite
Give assurance that key risks are correctly identified and evaluated by managementCoach management on responding to risksAdvice is documented as advice; the decision and the response are management’s; audit tests the response later as management’sDecide the response to a risk, or implement it
Give assurance that key risks are managed within appetiteCoordinate ERM activities across functions where no second line existsTime-limited, with a plan to transfer to management; the audit committee approves the arrangement and the end date; disclosed in the charterOwn the risk management process, or manage risks on management’s behalf
Evaluate the reporting of key risks to the board and executivesConsolidate risk reporting where management asks for help building itAudit builds the format, management supplies and owns the content; audit does not present the risk report as its own viewTake accountability for risk management, in the charter or in fact
Review the management of key risks, including the effectiveness of controls and responsesMaintain and develop the ERM framework as a consulting engagementFramework design is advisory; management adopts and owns it; audit does not audit its own design for at least one full cycle, or another party doesProvide assurance on risks it managed or on a framework it designed within the cooling-off period
Report on the maturity of ERM to the boardChampion the establishment of ERM in an organization that lacks itChampioning is advocacy, not ownership: audit makes the case to the board, and the board assigns ownership to a managerBe the risk management function

The test for whether a role has drifted from the middle column to the right one is a single question: if this risk materializes, who will the board hold accountable? If the answer is internal audit, the function has taken a management responsibility. A second test is time: a “temporary” coordination role that is entering its third year is not temporary, and the audit committee should be told that the third line has become the second.

Making the safeguards real: charter language and practice

Safeguards that live in a position paper protect nobody. They protect the function when they are in the audit charter, agreed by the audit committee, and applied in the engagement letters. The clauses below are model language; the Domain III guide covers the Standards’ independence requirements they implement.

Charter clause on risk management roles. Internal audit provides independent assurance on the effectiveness of the organization’s risk management, including whether significant risks are identified, evaluated, and managed within the board’s appetite, and whether risk reporting to the board is reliable. Internal audit may provide advisory services in support of risk management, including facilitation of risk assessments and advice on the design of the risk management framework, provided that management retains responsibility for identifying, assessing, and responding to risks, and for the risk management framework and its outputs. Internal audit will not set risk appetite, decide or implement risk responses, or assume ownership of the risk management process. Where internal audit provides advisory services on the design of the risk management framework, it will not provide assurance on that design for a period of [twelve months] or until [another party] has done so, and the audit committee will be informed.

Engagement letter clause for a facilitated risk assessment. Internal audit will facilitate the workshop and document the risks, ratings, and responses identified by the participants. The risks, ratings, and responses are management’s and will be approved by [executive]. Internal audit will not rate risks or determine responses. The outputs will be assured by internal audit in a subsequent engagement no earlier than [date], and the facilitation will be disclosed in that engagement’s report.

In practice the safeguards show up as small disciplines. The facilitator writes what the room said, in the room’s words, and the ratings column is filled in by the risk owners after the session, not by the auditor tidying up. Advisory work carries a different report template, unrated, with a limitations paragraph that says it is not assurance; the report template set has that memo format. And the annual plan states which ERM work is assurance and which is advisory, so the coverage map the committee sees is honest.

The ERM maturity rubric

A maturity rubric turns “how good is our ERM” into a scored answer the board can track over years. The one below uses five levels across six dimensions; the descriptors are written as observable facts, so that two assessors would score the same organization the same way, and each cell is something an auditor can inspect or trace. Score each dimension separately and never average them, because an organization at level 4 on reporting and level 1 on appetite has a reporting framework, not a risk management one.

Dimension1 Initial2 Developing3 Defined4 Managed5 Optimized
Governance and ownershipNo policy; risk discussed ad hoc; nobody owns the processPolicy drafted; a coordinator named part-time; board receives an annual listApproved policy; named risk owners for every top risk; a risk committee with a charter that meets quarterlyBoard-level oversight with minuted decisions; second-line function independent of the business; roles enforcedRisk governance integrated with strategy and performance governance; board challenges the risk profile, not just receives it
Risk identification and assessmentRisks listed from memory; no criteriaRegister exists; ratings inconsistent across units; refreshed annuallyCommon scale with impact and likelihood criteria; refreshed quarterly; RCSAs in major unitsRatings challenged by the second line; emerging risks and scenarios assessed; ratings move after eventsAssessment uses data (loss, KRI, external) alongside judgment; interdependencies between risks assessed
Appetite and toleranceNone statedA qualitative statement exists; not cascadedAppetite by risk category with some measurable limits; breaches reportedMeasurable limits for all major categories; breaches escalated and decided; appetite reviewed annually with strategyAppetite drives capital, budget, and product decisions, and the trail shows it
Response and controlResponses implicit; controls undocumentedResponses recorded in the register; owners named; completion untrackedResponses tracked with dates; control effectiveness assessed by ownersResponse effectiveness tested by the second line or audit; residual risk compared to appetiteResponses optimized for cost against residual risk; insurance, controls, and acceptance chosen deliberately
Monitoring and reportingNo regular reportingAnnual register presented to the boardQuarterly risk report with top risks, changes, and actions; some KRIsKRIs with thresholds for major risks; exception-based reporting; decisions minutedNear-real-time indicators where data allows; reporting integrated with performance reporting
Integration with strategy and decisionsRisk not considered in planningRisk section added to major proposals after the decisionRisk assessment required before major decisions; strategic risks in the registerStrategy options evaluated against appetite; risk analysis visible in the strategy paperRisk-adjusted metrics used in performance evaluation and incentives

Scoring rules that keep the rubric honest: a level is achieved only when every descriptor in the cell is evidenced, not most of them; the evidence is a document, a minute, a trace, or an observation, never an interview alone; and the score is accompanied by the two or three facts that placed it, so that next year’s assessor can see what would have to change to move up. Report the six scores as a profile, with last year’s beside them, and resist the single composite number the board will ask for.

Auditing ERM: a work program

An ERM audit is an audit of the framework’s design and use, distinct from the process audits that test controls over individual risks. The program below runs 250 to 350 hours for a mid-size organization and follows the site’s work program conventions. It produces the maturity profile as one output and findings as another; the two are reported together.

#AreaObjectiveProcedureEvidenceHours
1GovernanceERM is approved, owned, and overseenInspect the ERM policy, its approval date, and the risk committee charter; read four quarters of board and committee minutes for risk decisions; confirm the second-line owner’s reporting line and independencePolicy; charters; minutes; org chart16
2GovernanceRoles are defined and followedCompare documented roles for the first, second, and third lines with what interviews and artifacts show; identify any management responsibility held by the second or third lineRole descriptions; interviews; charter12
3IdentificationThe risk universe is completeCompare the register with the strategy, the audit universe, external loss and incident data, regulatory correspondence, and peer disclosures; list candidate risks absent from the register and ask whyRegister; strategy; incident log; peer filings24
4AssessmentRatings are consistent and evidence-basedTest 25 risk ratings against the criteria; compare ratings across units for the same risk; for 10 risks with events in the period, check whether ratings changedRegister history; criteria; events24
5AssessmentSecond-line challenge operatesInspect challenge records for 25 register entries; interview three risk owners on the challenge they receivedChallenge log; interviews12
6AppetiteAppetite is stated, measurable, cascaded, and enforcedInspect the appetite statement; map each category to a metric and a limit; test all breaches in four quarters to escalation and decision; trace appetite into two budget or product decisionsAppetite statement; breach reports; decision papers24
7ResponseResponses exist, are owned, and are completedFor 25 top-risk responses, inspect the owner, date, and status; test 15 completed responses to evidence; compare residual ratings to appetiteRegister; response evidence24
8ResponseControls over top risks are effective (coordination with process audits)For the ten highest risks, map the controls relied on to the audit plan’s coverage and to the last test result; identify controls relied on that have never been testedRCM; audit plan; prior reports16
9MonitoringKRIs are leading, thresholded, and acted onInspect the indicator set for the top risks; trace all breaches in four quarters to decisions; identify top risks with no indicatorKRI reports; minutes16
10ReportingBoard risk reporting is complete, accurate, and produces decisionsInspect four quarterly reports against the register and events; trace five reported items to decisions; test the accuracy of three reported metrics to sourceReports; minutes; source data20
11Strategy integrationRisk informs strategic decisionsFor the three largest decisions in the period (acquisition, product, capital project), inspect the decision paper for risk analysis against appetite; interview the decision ownerDecision papers; interviews20
12Emerging riskEmerging and scenario risks are assessedInspect the emerging-risk process and the last two scenario exercises; trace outputs to register changes or decisionsScenario records; register changes12
13CultureRisk culture supports the frameworkRead the whistleblowing and incident statistics; test whether reported near misses and issues were welcomed or penalized in three cases; review incentive design for risk adjustmentStatistics; case files; incentive plans16
14MaturityScore the six dimensionsApply the rubric with the evidence gathered in 1 to 13; record the facts behind each scoreRubric workpaper12
15Use testRisk management changes decisionsAcross the year, identify five decisions that were different because of risk information, with evidence; where fewer than three exist, report itTraces; interviews16
Planning, reporting, review50

The annual ERM assurance calendar

Assurance over ERM is not one engagement every four years. It is a set of activities across the year whose sum lets the CAE say something to the board each year about risk management, which the Standards expect the CAE to be able to do. The calendar below is for a function with a modest budget; the ERM framework audit itself runs on a two- to three-year cycle, and the other lines run annually.

ActivityTimingHoursOutput
ERM framework audit (the program above)Every 2 to 3 years, Q1250–350Maturity profile; findings; opinion on the framework
Annual risk-report reliability testQ4, before the year-end board report30Three reported metrics and five reported risks traced to source; exceptions reported to the CAE and, if material, the committee
Appetite breach reviewQuarterly, 4 hours each16Breaches traced to decisions; unresolved breaches escalated in the CAE’s quarterly report
Top-risk coverage mapWith the annual plan20Each top risk mapped to assurance obtained (audit, second line, external) and to gaps; feeds the plan; see the annual plan template
Post-event reviewWithin 60 days of any major loss or near miss20–40 eachWhether the risk was on the register, rated correctly, with a response that operated; changes to the framework
Advisory: facilitation or framework adviceAs requested, within safeguardsVariableAdvisory memo, unrated; disclosed in the plan and the charter
CAE’s annual statement on risk managementYear-end16One page: what assurance was obtained, the maturity profile, the open findings, the CAE’s view

Worked example: the maturity assessment at MidState Beverage

MidState Beverage is the site’s running example: a three-state distributor with 12 depots, 300 routes, two acquired distributors not yet integrated, a lean finance team, and a six-person internal audit function whose FY27 plan included an ERM framework assessment for the first time. The company has no second-line risk function; the CFO’s office maintains a risk register that the board sees annually. The assessment ran 220 hours in Q2 and produced the profile below.

DimensionScoreFacts that placed it
Governance and ownership2A one-page risk policy approved in 2023; the controller maintains the register alongside other duties; the board sees it once a year and the minutes record “noted” for three consecutive years
Risk identification and assessment2Register of 31 risks with high/medium/low ratings and no criteria; no rating changed after the FY26 Dayton cash loss or after the two acquisitions; the acquisitions themselves are not on the register as an integration risk
Appetite and tolerance1No appetite statement; the credit policy and the fleet safety policy contain the only limits, and neither is described as appetite
Response and control3Each register entry names an owner and a response; 9 of 12 responses tested were in place; the controls behind the top risks are tested by internal audit through the process audits
Monitoring and reporting2No KRIs; the annual register is the only report; the monthly operations pack contains route shortage and breakage metrics that function as indicators but are not connected to the register
Integration with strategy and decisions1The two acquisitions were approved on financial papers with no risk section; the ERP replacement decision pending in FY28 has no risk analysis attached

Two findings came out of the assessment, both rated Medium under the severity scale, because the immediate exposure sat in the process controls that were separately tested rather than in the framework. The first: the board approves strategic decisions without a risk analysis against any stated appetite, evidenced by the two acquisition papers and the ERP replacement proposal, with the cause that no appetite exists to analyze against and no step in the board paper template asks for it. Agreed action: the CFO to draft a risk appetite statement for board approval by Q4, and the corporate secretary to add a mandatory risk section to the board paper template, with the ERP replacement paper as the first to use it. The second: the risk register does not reflect events or changes in the business, evidenced by the unchanged ratings after the Dayton loss and the absence of integration risk, with the cause that the register is refreshed annually by one person with no challenge. Agreed action: quarterly refresh by the executive team with the operations pack metrics connected to the register entries, and the register presented to the board quarterly with changes highlighted.

The CAE declined the CFO’s request that internal audit draft the appetite statement, offered to facilitate the executive workshop that would produce it under the safeguards above, and wrote both the request and the answer into the report. The profile went to the audit committee with a note that scores of 1 and 2 were expected for a company of MidState’s size and history, that the response dimension at 3 reflected process controls tested elsewhere, and that the assessment would be repeated in FY29 against the same rubric.

The top-risk coverage map, worked

The coverage map is the artifact that connects the ERM audit to the annual plan, and it is the one the audit committee understands fastest. For each top risk on the register it records what assurance exists from each line and when it was last obtained, and the gap column is the plan’s input. MidState’s map for its six highest-rated risks, after the assessment, looked like this.

Top risk (register)First-line control evidenceSecond lineInternal audit, last testExternalGap and plan response
Route cash diversionDepot settlement controls; HQ reconciliation since MayNoneFY27-01 route cash audit, Unsatisfactory, five findings, validation in progressExternal audit substantive work on cashCovered; validation of the two High findings due Q3
Acquisition integration failureIntegration lead’s monthly certificationsNoneFY27-02 integration engagement, Q3NoneNot on the register until the assessment; added; engagement scheduled
ERP obsolescence and replacementIT roadmap; vendor support contract to FY28NoneITGC coverage annually; no review of the replacement programNoneGap: pre-implementation review added to the FY28 plan; risk section required in the board paper
Product loss and shrink at depotsCycle counts; breakage sign-offsNoneFY27 warehouse inventory engagement, Q2External audit inventory counts at year-endCovered; cycle-count module finding open
Fleet and DOT complianceFleet manager’s compliance trackerNoneFY27 advisory only, unratedInsurer’s annual fleet reviewGap: no assurance; a rated engagement added to FY28
Key-person dependency in financeNone documentedNoneObserved in the close engagement; no finding raisedNoneGap: raised as an observation to the CFO; succession plan requested; re-assessed at the quarterly refresh

Three answers to “will internal audit run ERM for us?”

When the board asks. “No, and here is what I can do instead. If internal audit owns risk management, nobody independent can tell you whether it works, and that is the one thing you most need to know. I will help you assign it to an executive, facilitate the first cycles so it starts well, and audit it once it is theirs. The charter clause I am proposing says exactly that, with a date.”

When the CFO asks for the appetite statement to be drafted. “I will facilitate the session where the executive team writes it, and I will bring the structure and the questions. The numbers in it have to be yours, because you are the ones who will be held to them, and because I will be the one testing whether you stayed inside them.”

When the request is to keep coordinating “just until the risk manager is hired.” “Agreed, with three conditions: the audit committee approves it with an end date, the plan shows the hours as advisory rather than assurance, and I do not audit the risk register until a full cycle after the hand-over. If the hire slips past the date, I come back to the committee rather than extend quietly.”

Reporting to the board on risk management

Boards receive risk reports from management and assurance on those reports from internal audit, and the two should not be confused. Management’s report says what the risks are; internal audit’s says whether that report can be believed and whether the process behind it works. The CAE’s annual statement on risk management is one page: the assurance activities performed (from the calendar), the maturity profile with movement, the open findings on the framework, the top risks where assurance coverage is thin, and the CAE’s view in one paragraph, written in the plainest language available. A board that receives that page each year can track whether risk management is improving; one that receives only management’s register cannot. Where the organization has a risk committee of the board, the CAE presents the statement there and the audit committee receives it; where it does not, the audit committee is the forum, and the CAE should say so, because the absence of a risk committee is itself a governance observation in an organization of any size. The Domain IV guide covers the CAE’s broader reporting obligations that the statement sits within.

Common failures

FailureWhat it looks likeWhy it mattersFix
Audit owns ERMThe CAE maintains the register, runs the workshops, and presents the risk reportNo independent assurance exists over the organization’s most important governance processBoard assigns ownership to a manager; audit facilitates under safeguards and exits on a date
Auditing the documentThe ERM audit tests whether the register exists, has owners, and was refreshedA complete register that changes no decisions passesUse test (procedure 15) and strategy integration (procedure 11) in every ERM audit
Composite maturity score“ERM maturity is 3.2”A 5 in reporting hides a 1 in appetiteSix-dimension profile, no averaging, facts behind each score
Facilitation without safeguardsAudit facilitates, rates the risks “to save time,” and assures the register the same yearIndependence gone in fact, whatever the charter saysEngagement letter clause; management enters ratings; cooling-off before assurance
Appetite that cannot breachA qualitative statement with no metrics, or metrics nobody measuresNothing can be enforced; the board cannot know whether management stayed within itMetrics and limits for every category; breach reporting tested quarterly
Ratings that never moveThe same high/medium/low profile for five years through two losses and an acquisitionThe register is a document, not an assessmentCompare ratings to events in every ERM audit; report the non-movement
Coverage assumedTop risks reported as “covered by controls” with no test of those controls in yearsThe board’s comfort rests on untested controlsTop-risk coverage map with the last test date, feeding the plan
No post-event reviewA major loss occurs; the register is updated; nobody asks why the framework missed itThe framework does not learnPost-event review within 60 days, reported to the committee

Adapting: small companies, financial services, and the facilitation question

In a small company with no second line, internal audit is usually the only function that knows what ERM is, and the pressure to run it is strong. The right answer is the championing role: make the case to the board, help it assign ownership to an executive, facilitate the first two cycles under written safeguards with an exit date, and audit the third. The small-company internal audit guide covers the charter language for a function that has to do this. In financial services the second line exists, is regulated, and reports to a CRO; the third line’s ERM role is the assurance column of the table almost entirely, with a specific regulatory expectation that internal audit assess the risk management framework’s effectiveness and the independence of the risk function, which the financial services guide sets out by regulator. The operational risk guide and the GRC framework guide cover the adjacent frameworks that an ERM audit touches. On facilitation, the decision rule is the one from the roles table: if the board would hold internal audit accountable for the outcome, do not do it; if management would sign the output and be accountable for it, facilitate, disclose, and wait before assuring.

The Risk Library holds the risk-stripe guides an ERM audit’s coverage map points at, and every guide on the site is indexed at All Guides.

Related guides

Comments

One response to “Internal Audit’s Role in ERM: Assurance, Advice, and Limits”

  1. […] audit’s role often involves verifying that internal controls are designed to detect misrepresentations—like inflated invoices or manipulated […]

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading