,

GIAS Domain III: Governing the Internal Audit Function — the Board’s Job Description

Domain III of the Global Internal Audit Standards is the part of the framework written for people who are not internal auditors. Governing the Internal Audit Function sets out what the board and senior management have to provide, as “essential conditions”, for the function to be authorized, positioned independently and overseen, alongside what the chief audit executive has to do to make that governance real. It is three principles and nine standards, effective since 9 January 2025, and it is the domain most often found partially conforming in first quality assessments, because the evidence lives in board minutes, charters and reporting lines that nobody in the function controls alone. This guide takes the domain standard by standard, explains the essential-conditions idea and how a CAE evidences what the board is supposed to do, provides the conformance mapping, a charter outline and a board checklist, and works through a small function’s governance as it prepared for its first external quality assessment.

This guide was rewritten in September 2026 from a shorter version published in August 2026. Standard titles and numbering follow the Global Internal Audit Standards as published by The IIA on 9 January 2024; requirement summaries are paraphrases for orientation.

In this guide

The domain at a glance: three principles, nine standards

PrincipleStandardIn one lineWho acts
6. Authorized by the Board6.1 Internal Audit MandateThe board establishes the function’s authority, role and responsibilitiesBoard, with the CAE’s proposal
6.2 Internal Audit CharterThe mandate and the commitment to the Standards are written into a charter the board approvesCAE drafts, board approves
6.3 Board and Senior Management SupportThe board champions the function; senior management provides support and accessBoard and senior management
7. Positioned Independently7.1 Organizational IndependenceThe CAE reports functionally to the board, which owns the CAE’s appointment, evaluation, remuneration and the plan and budgetBoard
7.2 Chief Audit Executive QualificationsThe board ensures the CAE is qualified and stays soBoard
8. Overseen by the Board8.1 Board InteractionRegular, direct, private communication between the board and the CAEBoard and CAE
8.2 ResourcesThe board ensures resources are adequate; the CAE reports the effect of shortfallsBoard, CAE
8.3 QualityThe board oversees the quality program; the CAE builds and reports on itBoard, CAE
8.4 External Quality AssessmentAn independent external assessment at least every five years, with the board choosing the assessor and receiving the resultsBoard, CAE

The essential-conditions idea, and who it binds

The old Standards spoke to the internal audit activity and the CAE; the board appeared as the party the CAE reported to. Domain III reverses the camera. Each of its standards has two parts: the essential conditions, which describe what the board and senior management must do (establish the mandate, approve the charter, own the CAE’s appointment and evaluation, ensure resources, oversee quality, commission the external assessment), and the CAE’s responsibilities, which describe how the CAE informs, proposes, reports and acts on what the board decides. The Standards cannot bind a board, and they say so: the essential conditions are what the board must do for the function to be able to conform, and where the board does not provide them, the CAE’s obligation is to make the gap visible, to the board itself and, where it matters, in the function’s conformance statements. A CAE cannot be held nonconforming because the board declined to approve a charter; the CAE can be held nonconforming for not having asked, not having documented the answer and not having disclosed the consequence.

That structure decides how the domain is evidenced. The CAE’s evidence is the proposals, the reports and the disclosures; the board’s evidence is the minutes, the approvals and the decisions, and the CAE has to hold copies of both, because a quality assessor will ask for the minute in which the charter was approved and the minute in which the plan was, not for the CAE’s recollection that they were. The Standards also carry public-sector considerations throughout Domain III, recognizing that in government the “board” may be a legislature, an oversight body or a statutory arrangement, and that the mandate may sit in law rather than in a charter; the evidence is then the statute and the oversight body’s records, and the substance is unchanged. The Global Internal Audit Standards hub sets out where Domain III sits in the framework, and the audit committee presentation template shows the form the CAE’s communications to the board take.

Principle 6: Authorized by the Board

6.1 Internal Audit Mandate

The mandate is the function’s authority, role and responsibilities as the board establishes them, and the standard’s essential condition is that the board does so, in a way that gives the function the authority to access the information, people and property it needs, sets its role in relation to the organization’s governance, risk management and control processes, and defines its responsibilities including any it holds beyond assurance and advisory services. The CAE’s responsibility is to help the board understand what an effective mandate requires, to propose one, and to discuss with the board any constraint on it. The evidence is the board’s decision, which for most organizations is the charter approval, and the CAE’s proposal papers; where the mandate is limited (a function excluded from certain subsidiaries, or without authority over a joint venture), the limitation is documented and its effect disclosed in the function’s reporting.

The mandate also has to reach the whole organization. Where the group has subsidiaries with their own boards, joint ventures, regulated entities with statutory audit committees or operations in jurisdictions with local requirements, the CAE maps which board owns the mandate for each and where the group function’s authority stops, and the charter says so. The common gap is the acquired entity whose board never adopted the group charter and whose management therefore treats the group function as a visitor; the fix is a resolution of the acquired entity’s board adopting the mandate, obtained as part of integration, which the audit plan guide lists among the acquisition integration steps.

6.2 Internal Audit Charter

The charter is the written mandate. The CAE develops it, the board approves it, and it states the function’s purpose, the commitment to conform with the Global Internal Audit Standards, the mandate including authority and access, the scope and nature of services, the organizational position and reporting relationships, the board’s own responsibilities under the essential conditions, and any responsibilities beyond internal audit that the CAE holds and the safeguards over them. The standard requires the CAE to review the charter periodically with the board and senior management and to propose changes when the mandate or the organization changes; the consideration is an annual review. The charter outline later in this guide covers the contents; the evidence is the approved charter with its version history, the board minute approving it and each revision, and the review record in years when nothing changed.

6.3 Board and Senior Management Support

The essential conditions here are behavioral rather than documentary: the board champions the function, sets the expectation that management cooperates, and acts on the function’s reports; senior management provides the support, access and cooperation the mandate promises, including timely responses to findings and participation in remediation. The CAE’s responsibility is to build the relationships that make support real and to report to the board where it is withheld. The evidence is indirect but findable: management responses to reports within the agreed period, the record of access requests and any refusals, the board’s follow-up on overdue actions, and the tone of the board’s own communications about the function. A function whose findings are chronically overdue, whose access to a subsidiary was refused without consequence, or whose CAE has never briefed the board without management present has evidence against 6.3, and the assessment will say so.

Principle 7: Positioned Independently

7.1 Organizational Independence

Independence is positional: the CAE reports functionally to the board and administratively to a level of management that does not compromise the function’s work. The standard’s essential conditions list what functional reporting means in practice, and they are the items a quality assessor checks one by one: the board approves the charter, the internal audit plan and its significant changes, the budget and resource plan; the board appoints and removes the CAE, sets the CAE’s remuneration and evaluates the CAE’s performance; the board receives the CAE’s communications on the plan, results and quality; and the board makes appropriate inquiries of management and the CAE to determine whether scope or resource limitations exist. Where the CAE holds roles beyond internal audit, the standard requires safeguards, the Domain II guide describes them under objectivity, and the board approves and periodically reassesses them. Administrative reporting, to the chief executive, the chief financial officer or another executive, is permitted for day-to-day matters, but the assessment reads the CAE’s performance evaluation and remuneration decisions to see who actually made them; a CAE whose bonus is set by the CFO the function audits is not functionally independent whatever the charter says.

7.2 Chief Audit Executive Qualifications

The board must ensure that the CAE has the qualifications and competencies to fulfill the mandate, at appointment and on an ongoing basis, and the CAE must maintain them. The evidence is the appointment record with the criteria applied, the CAE’s own professional development record, and the board’s periodic consideration of whether the CAE’s competencies still match a mandate that may now include cybersecurity, data analytics and topical requirements it did not include five years ago. Functions where the CAE role was filled by rotation from the business without an assessment of audit competence, or where a CAE with a financial background leads a function whose plan is mostly technology, carry an observation here unless the board has considered the question and documented how the gap is covered.

The CAE’s other roles: when the board says yes

Many CAEs, especially in mid-sized organizations, hold responsibilities beyond internal audit: compliance, enterprise risk management, a transformation program, sometimes a second-line function outright. The Standards do not prohibit this; they require it to be governed. The board approves the arrangement with knowledge of what it means for independence, and the safeguards are documented in the charter and reassessed periodically. The safeguards that work are specific: the areas the CAE manages are excluded from the function’s assurance work and covered instead by an independent party, whether an external firm, a co-source partner or another organization’s audit function, whose reports go to the board; the CAE recuses from the risk assessment and planning decisions that touch those areas, with the audit committee chair or a designated committee member taking the decision; the function’s staff who work in the second role are ring-fenced from auditing it; and the arrangement is disclosed in the function’s reports and in the QAIP report as a matter the board has considered. The assessment tests each safeguard for operation, not existence, and the finding it makes most often is that the independent coverage of the CAE’s other area was arranged in year one and quietly lapsed in year three. The internal audit versus compliance guide works through the case where the CAE also leads compliance and how the boundary is drawn.

Principle 8: Overseen by the Board

Standard 8.1, Board Interaction, requires the board and the CAE to interact directly: the CAE communicates the plan, its rationale and changes, engagement results and the significant risks and control issues they reveal, resource matters, the quality program’s results, and any restrictions on scope or access; the board asks, decides and holds private sessions with the CAE without management present. The evidence is the schedule of interactions, the papers and minutes, and the record of private sessions, which is the item most often absent. Standard 8.2, Resources, places the essential condition on the board to ensure the function has the financial, human and technological resources to fulfill the mandate, and the responsibility on the CAE to develop the resource plan, to report the impact of any limitation and to propose alternatives; the evidence is the resource plan with its assumptions, the board’s approval, and the reports in which the CAE said what would not be covered and why. Standard 8.3, Quality, requires the CAE to develop, implement and maintain the quality assurance and improvement program that Domain IV’s Principle 12 defines and to report its results, and the board to oversee it, including the results of assessments and the actions taken; the QAIP playbook covers the program and the self-assessment template the annual internal assessment. Standard 8.4, External Quality Assessment, requires an assessment by a qualified, independent assessor or assessment team at least once every five years, with the board approving the scope, frequency and assessor (or the self-assessment with independent validation that the Standards allow as an alternative), receiving the results and overseeing the resulting action plan; the evidence is the engagement of the assessor, the report, the board’s discussion and the plan.

One further point about the domain’s timing. Domain III conformance is a property of a cycle, not of a moment: the charter review, the plan approval, the evaluation, the private sessions and the QAIP report each happen once or a few times a year, and a function assessed in month four may hold evidence for the current cycle on only two of the twelve items. The assessment therefore looks back across the last full cycle, usually the prior fiscal year, and the CAE keeps a governance calendar with the evidence reference for each item, which is the single document that makes a Domain III assessment short. A calendar with twelve rows, twelve dates and twelve minute references is a page; without it, the assessment is a week of searching board packs.

Public sector and small organizations: the same domain, different evidence

The Standards carry public-sector considerations in each Domain III standard because government audit functions are governed differently: the mandate often sits in legislation or regulation, the “board” may be an audit committee appointed by a council, a legislature’s oversight body or a ministerial arrangement, the CAE may be a statutory appointee, and the external assessment may be commissioned by an oversight body rather than by the entity. The substance is unchanged: someone independent of management has to establish the mandate, own the CAE’s appointment and evaluation, approve the plan and resources, receive the results and oversee quality, and the evidence is whatever record that body keeps. A public-sector CAE evidences Domain III with the statute, the oversight body’s terms of reference and minutes, and the appointment instrument, and discloses where the statutory arrangement falls short of the essential conditions, which happens most often on private sessions and on the CAE’s evaluation. Small organizations face the opposite problem: the board is real but meets rarely, has no audit committee and may consist partly of the executives the function audits. The Standards allow the essential conditions to be met by the full board where no committee exists, and the practical arrangements are a designated independent director as the CAE’s functional contact, a written annual cycle of the twelve checklist items compressed into two meetings, and a charter that says who does what; the small-company internal audit guide sets these out, and the disclosure duty applies where a two-person board cannot provide independence at all.

Evidence of conformance and the common gaps

StandardBoard-side evidenceCAE-side evidenceWhere functions usually fall short
6.1 MandateMinute establishing or confirming the mandate; statute in the public sectorProposal paper; documented limitations and their disclosureMandate assumed from custom; subsidiaries or joint ventures silently excluded
6.2 CharterApproval minutes for the charter and each revisionCharter with version history; annual review recordCharter last approved years ago; no commitment to the Standards; board responsibilities absent from it
6.3 SupportBoard follow-up on overdue actions; expectations set to managementResponse-time records; access refusals reported; relationship programOverdue actions tolerated; access issues resolved informally and never reported
7.1 IndependenceMinutes approving plan, budget, CAE appointment, evaluation and remunerationReporting-line documentation; safeguards for other rolesCAE evaluated and paid by the executive the function audits; plan approved by management only
7.2 CAE qualificationsAppointment criteria; periodic considerationProfessional development recordNo assessment at appointment; mandate outgrew the CAE’s competencies with no coverage plan
8.1 InteractionMeeting schedule; private session recordsBoard papers; communication logNo private sessions; the CAE presents only what management pre-reviewed
8.2 ResourcesApproved resource plan; response to shortfallsResource plan; impact-of-limitations reportingPlan sized to the team rather than the risk, with the gap never stated
8.3 QualityQAIP results discussed; actions overseenQAIP documentation; annual internal assessment; report to the boardQAIP exists on paper; results never reach the board
8.4 External assessmentAssessor and scope approved; report received; action plan overseenAssessment every five years; action planNever done, or done by a firm chosen and briefed by management

Scope limitations, resource shortfalls and the disclosure duty

Three of the domain’s standards converge on one CAE obligation: when the function cannot do what the mandate requires, say so, to the right people, in a form that survives. A scope limitation (a subsidiary refused, a system withheld, a management instruction not to look) is reported to the board under 6.3 and 8.1 with its effect on the assurance the function can give, and where it persists it is disclosed in the function’s conformance statements under Domain II’s Standard 4.1. A resource shortfall is reported under 8.2 as a statement of what the plan does not cover and what risk the board is therefore accepting, in terms the board can act on: not “we are under-resourced” but “the acquired distributors’ payables and the plant control networks will not be audited this year”. And a limitation on the CAE’s own independence, such as an executive setting the CAE’s pay, is a matter for the audit committee chair directly, because the executive is the counterparty. The evidence in every case is the communication and the board’s recorded response, and a function that has never reported a limitation has either an unusual organization or a CAE who has absorbed the gaps silently, which the assessment will test by comparing the plan to the risk universe in the risk assessment guide‘s terms.

The board’s annual checklist

Read as a list of things the audit committee should do each year, the essential conditions come to twelve items, and a CAE who puts them in front of the committee as a calendar has done most of the work of evidencing Domain III. The committee approves the charter or records its annual review. It approves the internal audit plan and its significant changes, and the budget and resource plan, after asking whether they cover the risks the committee cares about. It receives the CAE’s report on the impact of any resource or scope limitation and decides what to do about it. It appoints or confirms the CAE, evaluates the CAE’s performance and sets the CAE’s remuneration, on its own judgment. It considers whether the CAE’s qualifications still fit the mandate. It approves any roles the CAE holds beyond internal audit and the safeguards over them. It meets the CAE privately at least once a year, and usually at every meeting. It receives engagement results and the significant risk and control issues, and follows up on overdue management actions. It receives the quality program’s results, including the annual internal assessment. It approves the external quality assessment’s scope, frequency and assessor, receives the report and oversees the action plan. It makes inquiries of management about cooperation with the function. And it records all of the above in minutes the CAE can cite. The audit committee and board category collects the site’s guidance for the committee’s side of the relationship, and the presentation template is where the calendar is proposed.

The internal audit charter outline

A charter that conforms with Standard 6.2 covers the sections below. Most existing charters cover the first five and omit the sixth, the board’s own responsibilities, which is the section the Standards added and the one a quality assessor now looks for first.

Internal audit charter outline

1. Purpose. The purpose of internal auditing as the Standards state it, applied to the organization; the function’s role in governance, risk management and control.

2. Commitment to the Standards. The function will conform with the Global Internal Audit Standards, including Topical Requirements applicable to its engagements, and will disclose nonconformance where it affects the function or an engagement.

3. Mandate and authority. Authority to access records, personnel and physical property relevant to engagements; access to the board; allocation of resources; scope of the mandate across entities; any limitations and how they are disclosed.

4. Scope and nature of services. Assurance and advisory services; the risk-based plan; areas covered and the treatment of subsidiaries, joint ventures and outsourced activities; responsibilities beyond internal audit, if any, and their safeguards.

5. Organizational position and reporting. Functional reporting to the board; administrative reporting to a named executive; the CAE’s direct and unrestricted access to the board; private sessions.

6. Board responsibilities (essential conditions). Approval of the charter, plan and budget; appointment, evaluation and remuneration of the CAE; oversight of resources, quality and the external assessment; inquiries of management; support for the function’s authority.

7. Senior management responsibilities. Cooperation, access, timely responses and remediation.

8. Independence and objectivity. Safeguards; disclosure of impairments; the CAE’s other roles.

9. Quality. The quality assurance and improvement program; internal assessments; external assessment at least every five years; reporting of results.

10. Approval and review. Board approval with date; annual review; version history.

Worked example: MidState Beverage prepares for its first external assessment

MidState Beverage, the illustrative three-state drinks distributor used across this site, has a six-person internal audit function whose CAE reports functionally to the audit committee and administratively to the chief financial officer. When the function built its quality program in ninety days during FY27, as the QAIP playbook describes, the internal assessment of Domain III produced a clearer picture than the CAE expected of what the audit committee had and had not been doing, and the committee’s own reaction to that picture is the point of the example.

The charter had been approved in 2019 and reviewed annually by the CAE alone, with a note in the file each year that no changes were needed; it committed the function to the old International Standards, said nothing about the board’s responsibilities, and did not mention the two acquired distributors, over which the function’s authority had never been confirmed. The plan and budget had been approved by the committee each year, but the CAE’s performance evaluation and remuneration had been set by the CFO, with the committee chair informed after the fact. Private sessions had happened twice in four years. The committee had never been asked to approve an external assessment because there had never been one, and the resource plan had been sized to the six people rather than to the risk universe, with the gap visible in the plan’s reserve line and nowhere else. On the other side of the ledger, 6.3 was strong: the committee chair’s April 2026 request for a cybersecurity program audit after a peer distributor’s ransomware event, described in the cybersecurity program audit guide, was the kind of championing the standard describes, and management’s responses to the route cash report’s findings had arrived within the agreed period even though the chief operating officer disagreed with the opinion.

StandardAssessment findingAction agreed with the audit committee
6.1 / 6.2Charter dated 2019 on the old Standards; no board responsibilities; acquired distributors not addressedCharter rewritten on the outline above, with authority over all entities stated; approved by the committee in June 2026 with a standing annual review item
6.3Conforming: committee chair’s cyber audit request; management responses within periodNone; cited as evidence
7.1CAE evaluation and remuneration set by the CFO; plan and budget approved by the committeeCommittee charter amended so the committee evaluates the CAE and sets remuneration, with the CFO’s input limited to administrative matters; first committee-led evaluation in the FY27 cycle
7.2No documented consideration of CAE qualifications since appointment; mandate now includes cyber and analyticsCommittee recorded its assessment, noting the co-sourcing arrangement and the analytics auditor as coverage for the technology gap
8.1Two private sessions in four yearsPrivate session at every quarterly meeting, recorded in the minutes
8.2Resource plan sized to headcount; coverage gap unstatedFY28 resource plan presented against the risk universe with the uncovered areas named (see the audit plan guide); committee accepted two gaps explicitly and funded a third
8.3QAIP new; first internal assessment reportedAnnual QAIP report added to the committee calendar
8.4No external assessment in the function’s historyExternal assessment scheduled for FY28, assessor and scope to be approved by the committee, on the playbook’s rule of at least one honest internal assessment first

The committee’s reaction is the part worth recording. Shown the twelve-item checklist against what it had actually done, the committee did not treat the gaps as the CAE’s failure; it treated them as its own calendar, adopted the checklist as a standing agenda structure, and asked the CAE to report against it annually. That is Domain III working as designed: the essential conditions are the board’s to provide, the CAE’s job is to make the gap visible, and a board that sees the gap usually closes it. The inside the internal audit department guide describes the function’s operating model, and the small-company internal audit guide the version of these arrangements that fits an organization with a two-person function and a board that meets four times a year.

Common mistakes

Treating the charter as the function’s document rather than the board’s. Reviewing the charter without the board. Leaving the board’s responsibilities out of it. Letting the CAE’s evaluation and pay be set by the executives the function audits and calling the reporting line functional because the org chart says so. Sizing the resource plan to the team and never telling the board what is not covered. Holding no private sessions. Presenting only what management has pre-reviewed. Treating the external assessment as optional, or as a procurement exercise management runs. Evidencing Domain III from the CAE’s memory instead of from minutes. And assuming the domain does not apply because the organization is small or public, when the Standards provide for both. The Domain IV guide takes over where the board’s oversight ends and the CAE’s management begins, and the IPPF-to-GIAS mapping traces the old 1000 and 1100 series standards to their new homes in this domain.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading