Internal auditing has transformed dramatically since the mid-20th century, guided in large part by the standards issued by The Institute of Internal Auditors (IIA). These IIA Standards, formally known as the International Standards for the Professional Practice of Internal Auditing, serve as the foundation for effective internal audit practices worldwide. Understanding the history of the IIA Standards – how they originated, evolved, and continue to adapt – is crucial for both seasoned internal auditors and newcomers to the profession. Over the decades, the standards have been revised multiple times to address changing business environments, regulatory demands, and the expanding role of internal audit in governance, risk management, and control. This in-depth exploration provides a full historical context of the IIA Standards, detailing key milestones, major revisions, and the driving forces behind each evolution. It also examines how these changes have shaped modern internal auditing methodologies and compliance structures, leading up to the very latest updates that will define the future of the profession.
This guide was rewritten in September 2026. The February 2025 version dated the Global Internal Audit Standards to 2023; they were released on 9 January 2024 and became effective on 9 January 2025, and every date in this guide has been re-checked against the IIA’s own record. The rewrite also adds the structure of the 2024 Standards and a mapping from the old numbering to the new, the Topical Requirements that began arriving in 2025 as a mandatory layer on top of the Standards, and a closing section on what each revision in the history still requires of a practitioner today.
In this guide
- Early foundations and the need for standards
- The 1978 introduction of formal IIA Standards
- Evolution in the late twentieth century
- The birth of the IPPF and global harmonisation
- 2015: Core Principles and the Mission of Internal Audit
- The 2024 Global Internal Audit Standards: a modern overhaul
- Impact of the 2024 Standards on internal audit practice
- Inside the 2024 Standards: five domains, and how the old numbering maps
- Topical Requirements: the mandatory layer added from 2025
- What each revision still requires of you
- Where to go next
Early Foundations and the Need for Standards
The roots of internal audit standards can be traced back to the 1940s when internal auditing was emerging as a distinct profession. The IIA was founded in 1941 amid a growing recognition that organizations needed a dedicated function to review financial records and internal controls. In the absence of formal standards, early internal auditors relied on basic principles and the guidance of pioneers like Victor Z. Brink and John B. Thurston, who helped establish internal auditing as a recognized field. By 1947, the IIA issued the first Statement of Responsibilities of the Internal Auditor, a document outlining what internal auditors were expected to do. This Statement was not a detailed set of rules, but it marked the first attempt to codify the purpose and scope of internal auditing. It emphasized internal audit’s role as an independent appraisal function within organizations, focused initially on financial and accounting matters.
As businesses grew more complex in the mid-20th century, the internal audit function began to expand beyond purely financial auditing. A significant update to the Statement of Responsibilities in 1957 reflected this shift. The revised 1957 Statement broadened the internal auditor’s remit to include operational areas, not just accounting records. This was a crucial evolution – internal auditors were now encouraged to examine the efficiency and effectiveness of business operations and not solely verify financial transactions. Still, the approach of internal auditing during this era remained largely compliance-oriented and centered on evaluating whether established procedures were being followed.
To put this evolution in perspective, the following table highlights some key differences between the early era of internal auditing and the modern approach:
| Aspect | Early Internal Auditing (Mid-20th Century) | Modern Internal Auditing (21st Century) |
|---|---|---|
| Scope | Focused mainly on financial records and compliance with accounting procedures. Operational auditing was limited in scope. | Covers a broad range of areas including financial, operational, strategic, and IT risks; emphasizes enterprise-wide coverage including governance and risk management. |
| Role | Primarily served management as an internal watchdog for errors and fraud. Little direct involvement with the board; internal audit was seen largely as a management tool. | Serves the entire organization, providing independent assurance to the board and senior management. Internal audit is viewed as a critical component of corporate governance and accountability. |
| Approach | Checklist-driven and compliance-oriented, verifying adherence to policies and procedures (a reactive approach to finding deviations). | Risk-based and consultative, focusing on areas of highest risk and providing forward-looking insights (a proactive approach to preventing issues and improving processes). |
| Outcomes | Audit reports highlighted instances of non-compliance or control failures for management to correct. Value-add beyond basic compliance was limited. | Audit reports deliver prioritized findings with clear ratings and recommendations. Management action plans are obtained for improvements. The focus is on adding value, enhancing processes, and aiding decision-making. |
By the 1960s, the need for professional conduct standards became apparent as the profession matured. In 1968, the IIA adopted its first Code of Ethics for internal auditors. The Code of Ethics laid down fundamental principles of integrity, objectivity, confidentiality, and competence – values that internal auditors must uphold. The introduction of a formal ethical code was a milestone in professionalizing internal auditing, ensuring that practitioners worldwide adhered to a common set of ethical guidelines. This development in the late 1960s set the stage for more comprehensive professional standards. By the mid-1970s, the internal audit profession had a solid footing – with an established code of ethics, a growing global membership, and even a Certified Internal Auditor (CIA) certification (the first examination was sat in 1974). This strong foundation paved the way for the creation of detailed professional standards.
The 1978 Introduction of Formal IIA Standards
The year 1978 marked a turning point in the history of internal auditing. After years of groundwork, the IIA formally approved the first set of Standards for the Professional Practice of Internal Auditing in 1978. These were the IIA’s inaugural comprehensive standards, often simply referred to as the “IIA Standards.” They provided internal auditors with authoritative guidance on how to carry out their duties, covering everything from organizational independence of the internal audit function to planning and executing audit engagements, managing audit departments, and communicating results. The 1978 Standards aimed to bring consistency and quality to internal audit activities across organizations and industries.
The introduction of these Standards was driven by several factors. By the late 1970s, the internal audit profession had grown substantially, and a common baseline of practice was needed to ensure consistency and effectiveness. Organizations were becoming larger and more complex, increasing the need for formal guidance to help internal auditors keep pace with evolving risks and controls. Additionally, internal auditing sought to solidify its credibility as a profession, similar to how external auditing had established authoritative standards.
The 1978 Standards covered key areas that remain familiar today. They addressed the independence of internal auditors (ensuring they have organizational authority and objectivity), the proficiency and due professional care required of auditors, and the importance of a systematic approach to auditing (including planning, examination, evaluation of evidence, and reporting). Notably, quality assurance was already an element of these early standards – the standards encouraged establishing a quality review program for the internal audit activity, including periodic external reviews of the function’s effectiveness. This showed that from the very beginning, the IIA Standards emphasized not only performing audits, but also continually improving the audit function itself.
The immediate impact of the 1978 Standards was significant. Internal audit departments worldwide began aligning their charters and procedures with the new Standards. Adoption spread quickly, even within the public sector (for example, in 1982 the state of California became the first state government to formally adopt the IIA Standards for its internal auditing). The IIA also published what became known as the “Red Book,” a handbook of the Standards and related guidance, which quickly became an essential reference for practitioners. Internal auditors reported greater clarity in their roles and higher recognition within their organizations, attributing this in part to the common language and expectations set by the 1978 Standards.
To summarize the milestones up to this point and beyond, the following table provides a timeline of key developments in the history of IIA standards:
| Year | Milestone | Significance |
|---|---|---|
| 1941 | IIA founded | Establishment of the Institute of Internal Auditors as the global professional body for internal audit. |
| 1947 | First “Statement of Responsibilities of the Internal Auditor” issued | Early formal guidance defining the scope and responsibilities of internal auditing (initially focused on financial auditing). |
| 1957 | Revision of the Statement of Responsibilities | Expanded internal audit scope to include operational areas, reflecting a broader role beyond accounting. |
| 1968 | First IIA Code of Ethics adopted | Introduced ethical principles (integrity, objectivity, confidentiality, competence) that all internal auditors worldwide must follow. |
| 1974 | First Certified Internal Auditor (CIA) examination | Professional certification for internal auditors established, marking the growing professionalism of the field. |
| 1978 | Inaugural IIA Standards for the Professional Practice of Internal Auditing issued | First comprehensive set of internal audit standards, providing uniform guidance on internal audit practices and function management. |
| 1981 & 1990 | Updates to the Statement of Responsibilities | Continued refinements to internal audit’s defined role (the 1990 update explicitly mentioned assessing risk management and control), paralleling the early years of standards adoption. |
| 1997 | Guidance Task Force convened | The review of the profession’s guidance that produced the 1999 definition, the revised Code of Ethics and the Professional Practices Framework. |
| 1999 | New Definition of Internal Auditing approved | Redefined internal auditing to emphasize value addition, and included assurance and consulting services; accompanied by an updated Code of Ethics. |
| 2001 (effective 2002) | Major revision of IIA Standards; launch of Professional Practices Framework (PPF) | Overhaul of the standards in light of the new definition; introduced the PPF to organize the definition, code, standards, and guidance in a structured framework. |
| 2009 | International Professional Practices Framework (IPPF) introduced | Updated framework replacing the PPF; reaffirmed mandatory guidance (definition, code, standards) and organized practice advisories and guides under one global framework. |
| 2011 and 2013 | Standards revisions effective 1 January 2011 and 1 January 2013 | Incremental updates to the 2009 Standards, including clarified requirements on communicating risk acceptance and on the quality programme, ahead of the 2015 framework refresh. |
| 2015 | IPPF refresh – Introduction of Core Principles and Mission of Internal Audit | Modernization of the framework adding an official Mission statement and ten Core Principles for effective internal auditing; practice advisories replaced by more practical implementation guides. |
| 2017 | Alignment of Standards (effective Jan 2017) | Minor revisions to the Standards to align with the new Core Principles (e.g., introduced Standard 1112 addressing CAE roles beyond internal auditing). |
| 2024 (effective 9 January 2025) | Global Internal Audit Standards released on 9 January 2024 | Comprehensive overhaul under the IPPF Evolution project: five domains, fifteen principles and fifty-two standards, absorbing the Definition, Code of Ethics, Core Principles and Mission; effective 9 January 2025 with early adoption encouraged. |
| 2025 | First Topical Requirements published: Cybersecurity (February 2025), Third-Party (15 September 2025), Organizational Behavior (December 2025) | A new mandatory layer of the IPPF setting minimum requirements for auditing specific risk topics whenever they are in scope, each effective one year after publication. |
| 2026 | Topical Requirements take effect: Cybersecurity (February 2026), Third-Party (15 September 2026), Organizational Behavior (December 2026) | External quality assessments from 2026 onward test conformance with the Topical Requirements as well as the Standards. |
Evolution in the Late 20th Century: Broadening Scope and Responsibility
Following the introduction of the initial Standards in 1978, the internal audit profession continued to evolve rapidly through the 1980s and 1990s. The Standards provided a solid baseline, but the business landscape was changing in ways that would soon necessitate further updates. During the 1980s, internal auditors increasingly looked beyond basic compliance checking and began adopting a more risk-focused approach. New technologies, globalization, and growing regulatory demands meant auditors had to adapt – using more sophisticated techniques (like computer-assisted auditing tools and better sampling methods) and considering whether key risks were being managed effectively, not just whether procedures were followed.
Even as the core Standards remained unchanged through the 1980s, the IIA supplemented them with guidance. The old Statement of Responsibilities was updated in 1981 and 1990 to reinforce expanding expectations (by 1990 it explicitly mentioned internal audit’s role in evaluating risk management and control). High-profile business failures and frauds in that era underscored that internal auditing needed to be more proactive and broad in scope, setting the stage for major changes.
By the late 1990s, it was clear that internal auditing’s traditional definition was too narrow. In 1999, the IIA approved a new Definition of Internal Auditing, which defines internal audit as “an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations.” This landmark change explicitly added consulting (advisory) services to internal audit’s remit and emphasized “adding value” and improvement, shifting the perception of internal audit from a compliance inspector to a value-adding partner of management and the board.
The IIA also revised the Code of Ethics in 1999 to align with this modernized definition, reinforcing core principles and addressing scenarios like consulting engagements. A strong ethical foundation was necessary as internal auditors took on broader advisory roles while needing to maintain independence.
All these changes paved the way for a comprehensive overhaul of the professional guidance. In late 1999, the IIA introduced the Professional Practices Framework (PPF), which took effect in 2001. The PPF provided a structured approach by bundling together the mandatory guidance (the new definition, the updated Code of Ethics, and the revised IIA Standards) and outlining recommended guidance (such as practice advisories) to help with implementation. The revised Standards, effective January 1, 2002, were one of the most significant updates in the IIA’s history.
The 2001/2002 Standards revision aligned with the new definition and contemporary practices. It formally extended internal audit’s scope to include consulting services, and it explicitly linked audit planning to risk assessment (establishing risk-based auditing as standard). The Standards elevated internal audit’s role in evaluating risk management, control, and governance processes within organizations. A major addition was the requirement for a Quality Assurance and Improvement Program (QAIP), including an external quality assessment at least every five years – a clear mandate for ongoing quality and accountability. The Standards were also reorganized for clarity: Attribute Standards (addressing the characteristics of the internal audit function and auditors) and Performance Standards (addressing how audits are executed), with further Implementation guidance for specific types of engagements. This structure made it easier to navigate the guidance and assess compliance.
The impact of the 2002 Standards revision was profound. Internal audit departments worldwide updated their charters to reflect the new definition and adopted risk-based audit plans. The five-year external review requirement prompted internal audit functions to institute formal quality assurance programs and peer reviews. Collectively, these changes helped transform internal auditing into a more strategic, risk-focused, and credible function. Notably, this evolution coincided with corporate scandals and the Sarbanes-Oxley Act of 2002, which brought internal controls and audit functions into sharp focus. The updated IIA Standards provided a timely and demanding framework for internal auditors to meet these heightened expectations.
The Birth of the IPPF and Global Harmonization (2000s)
In 2009, the IIA introduced the International Professional Practices Framework (IPPF), building on the PPF to organize its guidance on a truly global scale. The IPPF did not change the content of the Standards (the 2002 Standards remained the backbone), but it clarified the structure of guidance: mandatory guidance now explicitly comprised the Definition of Internal Auditing (1999 version), the Code of Ethics, and the IIA Standards, while recommended guidance included materials like Practice Advisories, Practice Guides, and Position Papers.
The IPPF’s goal was to ensure internal auditors around the world had a common framework and easy access to supporting guidance to interpret and implement the Standards, while still allowing flexibility for different industries and sizes of internal audit functions.
Over the next few years, the IIA continued to issue guidance and make minor tweaks. New Practice Guides were published on topics like IT auditing and fraud risk, and small amendments to the Standards clarified points such as how to communicate risks (Standard 2600) and how to safeguard independence if the CAE had operational responsibilities.
By the mid-2010s, following the lessons of the 2008 financial crisis, it was evident that while the Standards were fundamentally sound, the framework could be sharpened. Stakeholders were increasingly interested in what made an internal audit function truly “effective” beyond mere compliance with the Standards. This spurred the IIA to undertake another round of enhancements to the IPPF.
2015 Revisions: Core Principles and Mission of Internal Audit
In 2015, the IIA completed a major update to the IPPF, adding new elements to enhance the existing standards framework. A formal Mission of Internal Audit was introduced, succinctly stating internal auditing’s purpose as “to enhance and protect organizational value by providing risk-based and objective assurance, advice, and insight.” This mission statement reinforced internal audit’s focus on both protecting value (through assurance) and enhancing value (through advisory services and insights). In addition, the IIA defined ten Core Principles for the Professional Practice of Internal Auditing – fundamental principles that characterize effective internal audit performance (for example, demonstrating integrity; being objective and free from undue influence; aligning with the strategies, objectives, and risks of the organization; being appropriately resourced; and communicating results with impact). Collectively, the Core Principles offered a way to evaluate whether an internal audit function is achieving its intended outcomes and upholding the spirit of the standards, beyond mere compliance with checklists.
The 2015 enhancements did not overhaul the Standards themselves immediately, but they prompted alignment in subsequent years. For instance, a new standard (Standard 1112) was added in 2016 (effective 2017) to address cases where the chief audit executive has responsibilities beyond internal auditing, requiring safeguards to ensure independence and objectivity. The introduction of the Core Principles also meant that internal audit activities would self-assess not just on each standard, but on whether they met these broad criteria of effectiveness. Furthermore, the IPPF’s guidance structure was refreshed: the older Practice Advisories were replaced by more detailed Implementation Guides tied to specific standards, and additional Supplementary Guidance (like practice guides on specialized topics) was developed. These changes modernized the IPPF, ensuring that internal auditors had both high-level principles to aspire to and practical guidance to apply in their day-to-day work.
To illustrate how the framework changed with these enhancements, the following table contrasts the key elements of the IPPF before and after the 2015 update:
| Framework Element | IPPF (2009) | Enhanced IPPF (2015) |
|---|---|---|
| Definition of Internal Auditing | Adopted 1999 definition emphasizing assurance & consulting (remained the foundation). | Unchanged (1999 definition retained as the official definition). |
| Code of Ethics | 1999 Code of Ethics (integrity, objectivity, etc.) – mandatory. | Unchanged (1999 Code retained as mandatory ethical guidance). |
| Standards | 2002 Standards (with minor amendments through 2013) – mandatory. | Largely unchanged (same Standards, with minor 2016 tweaks to align with Core Principles). |
| Core Principles | Not included in framework. | Introduced 10 Core Principles for Effective IA (new mandatory element to underpin standards). |
| Mission of Internal Audit | Not formally defined in framework. | Introduced official Mission statement for Internal Audit (new guiding element). |
| Implementation Guidance | Practice Advisories (recommended guidance) for each standard; plus Practice Guides and Position Papers. | Practice Advisories replaced by detailed Implementation Guides for each standard; additional Supplemental Guides issued (recommended guidance). |
The 2024 Global Internal Audit Standards: a modern overhaul
The most recent chapter is the comprehensive overhaul the IIA branded the Global Internal Audit Standards. It is the largest change since the 2002 revision, and it is dated more precisely than most accounts give it: the International Internal Audit Standards Board developed the new Standards through the IPPF Evolution project over several years, exposed a draft for public comment in 2023, and the IIA released the final Standards on 9 January 2024, with an effective date of 9 January 2025 and early adoption encouraged in between. Calling them “the 2024 Standards”, as the earlier version of this guide did, mistakes the year of the exposure draft for the year of the Standards. The 2024 Standards replaced the 2017 International Standards, and they also absorbed the other mandatory elements of the old framework: the Definition of Internal Auditing became the Purpose statement in Domain I, the Code of Ethics became the five principles of Domain II, and the Core Principles and Mission of 2015 were folded into the fifteen principles that organise the whole document.
Several forces drove the overhaul. The business environment had grown more complex, with digital transformation, cybersecurity threats and third-party dependence demanding clearer expectations of auditors. Stakeholders wanted the Standards to be more prescriptive, so that “must” requirements replaced language that invited interpretation. The IIA wanted to consolidate guidance by placing considerations for implementation and evidence of conformance alongside each standard instead of in separate implementation guides. And the profession’s own quality assessments had shown gaps that the old structure did not address well: the board’s responsibilities toward internal audit, the way results are communicated and rated, and the rigour of the quality programme. The table summarises the most significant changes against the 2017 Standards.
| Key change | 2024 Global Internal Audit Standards | 2017 International Standards |
|---|---|---|
| Structure | Five domains, fifteen principles and fifty-two standards, each with requirements, considerations for implementation and examples of evidence of conformance in one document. Purpose, ethics, governance, management and performance are all inside the Standards. | Attribute Standards (1000 series) and Performance Standards (2000 series), with Implementation Standards for assurance (A) and consulting (C); the Definition, Code of Ethics, Core Principles and Mission sat alongside as separate mandatory elements. |
| Prescriptiveness | Requirements are stated as “must” statements with less room for interpretation in core areas; each standard says what conformance looks like. | More principles-based, with “should” language in guidance and greater reliance on auditor judgment and separate Implementation Guides. |
| Board responsibilities | Domain III assigns “essential conditions” to the board and senior management: approving the mandate and charter, ensuring independence, resources and unrestricted access, and overseeing the function’s performance and external quality assessment. | The board’s role was implicit; the Standards addressed the chief audit executive’s duty to communicate, not the board’s duties. |
| Engagement communication | Standard 15.1 requires final engagement communications to include the engagement’s objectives, scope and conclusions, findings with their significance, recommendations or action plans, and management’s responses, with conclusions expressed under the function’s methodology, including ratings where it requires them. | An overall opinion and ratings were at the chief audit executive’s discretion; recommendations and management responses were good practice rather than requirements. |
| Quality | Principle 8 and Standards 12.1 and 12.2 require internal assessments, external assessments at least every five years by qualified independent assessors (with an active Certified Internal Auditor on the team), and performance measurement against objectives, not only conformance. | External assessments were required every five years, with general requirements for assessor competence; the quality programme focused on conformance and improvement. |
| Public sector and small functions | Considerations for the public sector are written into the Standards, and the requirements are designed to be met by small functions with proportionate methods. | Separate guidance addressed public sector and small-function application. |
| Mandatory layers above the Standards | Topical Requirements, introduced from 2025, set minimum baselines for auditing specific risk topics and are mandatory when the topic is in scope; Global Guidance is recommended. | Practice Guides and Implementation Guides were recommended, not mandatory; there was no mandatory topic-level layer. |
The change in tone is as important as the change in structure. The 2017 Standards told a function what it should have; the 2024 Standards tell it what it must do and what evidence would show that it did. A function that conformed with the old Standards mainly by having a charter, a plan and a quality programme now has to show that the charter was approved by the board with the essential conditions in it, that the plan was built from a documented risk assessment and coordinated with other assurance providers, and that the quality programme measures performance and not only conformance. The full guide to the Global Internal Audit Standards walks the document domain by domain, and the 2024 to 2025 update analysis covers the transition year in detail.
Impact of the 2024 Standards on internal audit practice
The rollout of the 2024 Global Internal Audit Standards is expected to have far-reaching effects on internal audit functions, influencing their day-to-day operations, governance structure, and interactions with stakeholders. Internal audit departments—large and small—will need to assess their current practices against the new requirements and make adjustments to ensure full conformance. Below are several key areas of impact and how internal audit functions are responding:
Internal Audit Charters and Governance: Organizations may need to update their internal audit charter and governance arrangements in light of the new standards. The charter might be revised to explicitly reflect the board’s duties regarding internal audit (for instance, affirming the audit committee’s responsibility to ensure internal audit’s independence, authority, and sufficient resources). Many chief audit executives (CAEs) are briefing their boards or audit committees on the new standards, which in turn helps reinforce the board’s commitment to supporting a strong internal audit function. This heightened governance focus ultimately strengthens internal audit’s positioning within organizations.
Audit Planning and Scope: The enhanced standards put additional emphasis on risk-based planning and comprehensive scope. Internal audit plans are being revisited to verify that emerging risk areas—such as cybersecurity, data privacy, and ESG (environmental, social, governance) concerns—are adequately covered. The requirement to consider all significant risks means internal auditors are working closely with enterprise risk management teams (where they exist) and staying attuned to fast-changing risk profiles. In practice, many audit groups are increasing their use of risk assessment tools and updating their audit universe more frequently. The standards’ guidance for public sector and small audit functions also means that these teams can tailor risk-based planning to their scale while still aligning with best practices.
Audit Execution and Reporting: Perhaps the most visible changes for the internal audit staff are those affecting how audits are performed and reported. Audit methodologies and work programs are being adjusted to ensure every engagement results in an overall opinion or conclusion, and that individual findings are rated or prioritized. Auditors now know at the start of an engagement that they will need to categorize the importance of each observation—they are developing criteria to do so consistently. Additionally, internal audit departments are standardizing their report formats to include explicit recommendations for each finding and to capture management’s action plans. Some are introducing new report sections or appendices that clearly list high-risk issues and their ratings. Including a statement of conformance with the IIA Standards (or disclosing any areas of non-conformance) is also becoming a norm in annual reports from the CAE to the board, if not in each engagement report. Overall, these execution and reporting changes are driving internal auditors to be more rigorous in documentation and more impactful in communication.
Quality Assurance and Improvement: The new standards raise the bar for internal audit quality programs. CAEs are evaluating their existing Quality Assurance and Improvement Program (QAIP) against the updated requirements. Many are scheduling external quality assessments earlier than planned or ensuring that their chosen external reviewers meet the new criteria (for example, verifying that at least one team member has the CIA qualification and completed the IIA’s assessor training). Internally, audit teams are expanding their ongoing quality monitoring—some have introduced checklists or internal peer reviews for each engagement to confirm that all “must” statements in the standards (like having an engagement scope document, documented risk assessment, proper supervision, etc.) are met. The QAIP is also now focusing on performance metrics: internal audit functions are defining key performance indicators (such as audit cycle time, stakeholder satisfaction scores, and percentage of recommendations implemented) and will evaluate these as part of their self-assessment. Demonstrating continuous improvement on these metrics will be important in future external assessments, as the standards now emphasize not just compliance, but also the effectiveness and value delivered by internal audit.
Staffing and Skills Development: Because the new standards touch on advanced topics (like technology risks) and set expectations for a high level of professionalism, internal audit teams are looking closely at whether they have the right skills and resources. In some organizations, this means hiring or consulting subject matter experts to assist with complex areas like cybersecurity, or providing additional training to existing staff. There is renewed encouragement for auditors to obtain the Certified Internal Auditor designation, both to build credibility and because the standards’ QA requirements highlight the value of having certified professionals. Training programs are being updated to cover the nuances of the new standards—audit staff are being educated on how to apply more prescriptive requirements, how to document work to show conformance, and how to approach the new reporting elements. In smaller audit shops, where resources are limited, CAEs are leveraging the IIA’s guidance for small internal audit functions and seeking external support or co-sourcing for specialized audits to meet the standards without overburdening their teams. Overall, the focus is on building an internal audit team that is knowledgeable, agile, and equipped to meet the heightened expectations.
The table below outlines some of the key ways internal audit functions are being affected by the latest standards and summarizes common actions being taken to adapt:
| Area of Impact | Changes under the 2024 Standards | How Internal Audit Functions Are Adapting |
|---|---|---|
| Governance & Charter | Boards (audit committees) have explicit responsibility to support IA’s independence, status, and resources. Charters may need to reflect these enhanced governance expectations. | Updating audit charters to codify board oversight duties. Briefing boards on their roles in IA. Securing formal reaffirmation of audit committee support for internal audit’s mandate and resource needs. |
| Audit Planning & Scope | Audit plans must be firmly risk-based and include emerging and strategic risks (e.g., cyber, ESG). The standards stress comprehensive coverage of significant risks and coordination with other assurance providers. | Performing thorough risk assessments and updating audit plans more frequently. Incorporating specialist audits (IT, cybersecurity) into the plan. Coordinating with risk management and compliance functions to avoid gaps. Clearly documenting the risk rationale for each audit in the plan. |
| Execution & Reporting | Every audit engagement requires an overall opinion/conclusion with prioritized findings. All issues must include recommendations and (where appropriate) agreed management action plans. Audit reports should note conformance with the Standards. | Standardizing audit report templates. Defining rating criteria for findings (e.g., high/medium/low risk). Training auditors to write clear, actionable recommendations. Engaging management early to obtain action plans for issues. Including a statement in reports or annual communications affirming compliance with IIA Standards. |
| Quality & Conformance | QAIP expectations broaden to include measuring the audit function’s performance (not just compliance). External Quality Assessment teams must have certified and trained reviewers. Full conformance with all “must” statements is expected. | Enhancing internal quality reviews: using checklists to ensure each engagement meets all required elements. Tracking performance metrics (cycle time, stakeholder feedback, etc.) and reporting results to senior management. Planning external QARs with qualified reviewers (or training existing staff to be certified reviewers). Addressing any self-identified gaps before the next external review cycle. |
| Skills & Resources | Internal auditors need deeper expertise in specialized areas (technology, analytics) and strong professional credentials. Emphasis on continuous learning to keep up with new requirements. Small audit functions get tailored guidance but still must meet standards. | Investing in training programs focused on emerging risk areas and data analytics. Hiring or contracting experts for highly technical audits. Encouraging certifications like CIA for team members. Using the IIA’s small-audit-function guidance to prioritize efforts and, if needed, partnering with external firms to fill skill gaps. |
Taken together, the 2024 Standards push internal audit functions to be more structured, transparent, and aligned with organizational strategy than ever before. There may be challenges in the short term—such as increased documentation or the need for additional training—but the overall effect is to elevate the professionalism and value of internal audit. Many internal audit leaders view this as an opportunity to modernize their practices, demonstrating to stakeholders that the internal audit function not only conforms to global standards but is also a proactive contributor to organizational success.
Inside the 2024 Standards: five domains, and how the old numbering maps
Anyone who learned the profession on the 1000 and 2000 series needs a translation, because the 2024 Standards did not renumber the old ones so much as rebuild them around a different logic. The five domains run from purpose to performance: Domain I, Purpose of Internal Auditing; Domain II, Ethics and Professionalism; Domain III, Governing the Internal Audit Function; Domain IV, Managing the Internal Audit Function; and Domain V, Performing Internal Audit Services. Fifteen principles sit under them and fifty-two standards under the principles. Most of the old Attribute Standards landed in Domains II and III, most of the old Performance Standards in Domains IV and V, and the Code of Ethics became Domain II in its entirety. The table gives the crossings practitioners look up most often; the full IPPF-to-GIAS mapping table covers every standard.
| 2017 Standard | 2024 Standard | What moved, and what changed |
|---|---|---|
| Definition of Internal Auditing; Mission (2015) | Domain I, Purpose of Internal Auditing | The 1999 definition and the 2015 mission were rewritten as a single purpose statement inside the Standards rather than alongside them. |
| Code of Ethics (1968; 1999) | Domain II, Principles 1 to 5: Integrity, Objectivity, Competency, Due Professional Care, Confidentiality | The four ethical principles became five, with due professional care and competency each given standards of their own; 1120 Individual Objectivity became Standards 2.1 to 2.3. |
| 1000 Purpose, Authority and Responsibility; 1010 Recognizing Mandatory Guidance in the Charter | 6.1 Internal Audit Mandate; 6.2 Internal Audit Charter; 6.3 Board and Senior Management Support | The charter is now the board’s document as much as the chief audit executive’s, and the essential conditions the board must provide are listed. |
| 1100 and 1110 Independence; 1111 Direct Interaction with the Board; 1112 CAE Roles Beyond Internal Auditing | 7.1 Organizational Independence; 7.2 Chief Audit Executive Qualifications | Independence requirements are restated with the board’s role explicit; the 2017 safeguard for roles beyond internal auditing lives in 7.1. |
| 1300 series Quality Assurance and Improvement Program; 1310 to 1322 | 8.3 Quality; 8.4 External Quality Assessment; 12.1 Internal Quality Assessment; 12.2 Performance Measurement | The quality programme is split between what the board oversees (Principle 8) and what the chief audit executive runs (Principle 12), and performance measurement is now a requirement. |
| 2010 Planning; 2020 Communication and Approval; 2030 Resource Management | 9.4 Internal Audit Plan; 10.1 to 10.3 Financial, Human and Technological Resources | The plan must be built from a documented risk assessment and revisited when circumstances change; resources are addressed by type. |
| 2040 Policies and Procedures; 2050 Coordination and Reliance | 9.3 Methodologies; 9.5 Coordination and Reliance | Methodologies must now cover a stated list of matters; reliance on other assurance providers has its own standard. |
| 2060 Reporting to Senior Management and the Board; 2600 Communicating the Acceptance of Risks | 11.3 Communicating Results; 11.5 Communicating the Acceptance of Risks | The escalation duty when management accepts a risk that may be unacceptable is preserved almost unchanged. |
| 2200 series Engagement Planning | Principle 13, Standards 13.1 to 13.6: communication, risk assessment, objectives and scope, evaluation criteria, resources, work program | Six standards where the old series had four, with evaluation criteria and engagement communication now explicit. |
| 2300 series Performing the Engagement; 2400 series Communicating Results | Principle 14, Standards 14.1 to 14.6; Principle 15, Standards 15.1 and 15.2 | Findings, their evaluation, recommendations, conclusions and documentation each have a standard; 15.2 carries the old 2500 monitoring duty as confirming implementation of action plans. |
Two features of the structure explain most of the practical difference. First, every standard has three parts: requirements, considerations for implementation, and examples of evidence of conformance. The third part is new, and it is what an external assessor will ask to see, which is why functions that conformed comfortably in 2017 have found the 2024 Standards more demanding without any single requirement being unfamiliar. Second, Domain III addresses the board directly. Standards 6.3, 7.1, 8.1 to 8.4 describe what the board must do, and a function whose board has not done those things is not in conformance however good its own work is. The Domain III guide covers the conversation that follows from that, and the Domain IV and Domain V guides the management and performance standards respectively.
Topical Requirements: the mandatory layer added from 2025
The history did not stop at the effective date. The IPPF as restructured in 2024 has three layers: the Global Internal Audit Standards, which are mandatory; Topical Requirements, which are mandatory whenever the topic is within the scope of an assurance engagement (and recommended for advisory work); and Global Guidance, which is recommended. The Topical Requirements are the genuinely new instrument, and they mark the first time the IIA has told the profession what it must cover when it audits a particular risk rather than how it must audit in general. Each one sets out requirements across governance, risk management and control processes for its topic, and each carries a user guide with the considerations an auditor can use to decide which requirements apply and to document why any do not. The first three arrived on a roughly annual cadence with a year between publication and effect: the Cybersecurity Topical Requirement, published in February 2025 and effective from February 2026; the Third-Party Topical Requirement, published on 15 September 2025 and effective from 15 September 2026; and the Organizational Behavior Topical Requirement, published in December 2025 and effective from December 2026, with organisational resilience signalled to follow.
For a function, the Topical Requirements change the plan before they change the fieldwork. The first job is to identify which engagements in the plan touch each topic, because the requirement applies to any engagement where the topic is in scope, not only to the engagement named after it; a payables audit that looks at a payment processor is a third-party engagement for this purpose. The second is to map the function’s existing work programs to the requirements and record the gaps, which the Topical Requirements overview describes and the Third-Party Topical Requirement guide and cybersecurity workbook do requirement by requirement. The third is to be ready to document, in the file, which requirements were assessed as not applicable and why, because that documentation is what an external assessor will look for from 2026 onward. Functions that treated the 2024 Standards as a one-time transition will find that the framework now moves every year.
What each revision still requires of you
A history is only useful to a practitioner if it explains why the current requirements are shaped the way they are, and each revision left a requirement that is still in force. The 1947 Statement of Responsibilities established that internal audit is an independent appraisal function within the organisation, and that is why Standard 7.1 still asks where the chief audit executive reports and why an auditor cannot assess work they performed. The 1968 Code of Ethics is why Domain II exists, and why the confidentiality standards (5.1 and 5.2) constrain what you may do with information you obtain in an engagement. The 1978 Standards introduced quality review, and the 2002 revision made the external assessment every five years mandatory; the 2024 Standards added the assessor qualifications and the performance measures, so the quality assessment you are preparing for is the direct descendant of a 1978 idea. The 1999 definition added consulting and value, which is why the plan must include advisory work where the organisation needs it and why the function is judged on the value it adds rather than the findings it counts. The 2002 revision made planning risk-based, and Standard 9.4’s requirement for a documented risk assessment behind the plan is that revision still operating. The 2015 Core Principles became the fifteen principles of 2024, so the principles you cite in a charter today carry a ten-year pedigree. And the 2024 Standards themselves added the board’s essential conditions, the evidence of conformance, and the topical layer, which are the three things most likely to be tested in your next external assessment.
The pattern across eight decades is consistent: each revision widened scope (financial to operational to risk and governance to advisory), tightened proof (from principles to “should” to “must” to evidence of conformance), and moved responsibility upward (from the auditor to the chief audit executive to the board). A practitioner who understands that pattern can predict what the next revision will ask for, which is more of the same: broader mandatory coverage through Topical Requirements, and more explicit evidence that the board is doing its part. The CIA Part 1 syllabus tests exactly this history and structure, and the certification roadmap says when in a career it is worth sitting.
Where to go next
The history of the IIA Standards reflects a profession that has never stood still. Each era’s revisions, from the foundational statement of 1947 and the first Standards of 1978, through the turn-of-the-century overhaul and the introduction of the IPPF, to the Global Internal Audit Standards of 2024 and the Topical Requirements that followed, answered the problems organisations and auditors were actually facing, and together they turned a narrow accounting inspection function into a broad assurance and advisory profession with its own governance. Understanding that evolution gives context for why the current Standards emphasise what they do, and it prepares a function for the next revision, which will come. Start with the Global Internal Audit Standards guide for the current text, the mapping table if you still think in the old numbering, and the Topical Requirements overview for the layer that is still being built.
Related guides
- The Global Internal Audit Standards explained — the 2024 Standards, domain by domain
- IPPF to GIAS mapping table — every 2017 standard and where it went
- The 2024 to 2025 Standards update: what staff, leads and directors need to know — the transition year
- GIAS Domain II: ethics and professionalism — the Code of Ethics as it now stands
- GIAS Domain III: governing the internal audit function — the board’s essential conditions
- GIAS Domain IV: managing the internal audit function — planning, resources and methodologies
- GIAS Domain V: performing internal audit services — engagement planning through follow-up
- The QAIP playbook — the quality programme the 1978 Standards began
- IIA Topical Requirements — the mandatory topic layer from 2025
- The Third-Party Topical Requirement — effective 15 September 2026
- Cybersecurity Topical Requirement workbook — effective February 2026
- COSO’s seventeen principles — the control framework the Standards lean on
- CIA Part 1: essentials of internal auditing — where the history is examined
- A certification roadmap by career stage — when to sit it
- All IIA and standards guides and all history of internal audit guides
Leave a Reply