,

The Global Internal Audit Standards: A Complete Reference Map

The Global Internal Audit Standards are organized as 5 domains, 15 principles, and 52 standards — and this page maps all of them: every principle, every standard by number and official name, and one line on what each governs. The Standards were released January 9, 2024, became effective January 9, 2025, and replaced the 2017 International Standards along with the separate Code of Ethics (ethics now lives inside the Standards as Domain II). Bookmark this as the one-page view of the whole rulebook; the deep dives hang off it.

Why a map matters: the GIAS numbering is principle-based, which is elegant once you see the system and disorienting until you do. Practitioners raised on “1312” and “2340” now navigate “8.4” and “12.3,” and the fastest way to fluency is seeing the whole architecture at once. Everything below is verified against the IIA’s official publication; the authoritative text lives at the IIA’s Global Internal Audit Standards pages, and our in-depth analysis of the 2024/2025 update covers what the changes mean in practice.

In this guide

How the Standards are built (and the numbering logic)

Three nesting levels. Domains are the five big territories: purpose, ethics, governance, managing the function, performing engagements. Principles — numbered 1 through 15 straight across the domains — state what must be true (“Demonstrate Integrity,” “Plan Strategically”). Standards implement the principles, and here is the numbering key that unlocks everything: a standard’s number is its principle’s number plus a sequence — Standard 8.4 is the fourth standard under Principle 8, Standard 13.6 the sixth under Principle 13. Learn the fifteen principles and you can locate any standard blind.

Each standard has the same internal anatomy, and the distinction is load-bearing: Requirements (the “musts” — what conformance is tested against), Considerations for Implementation (how-to guidance — helpful, not mandatory), and Examples of Evidence of Conformance (what demonstrating it can look like). When someone claims “the Standards require X,” check which layer X actually lives in — a surprising share of confident assertions turn out to be citing a consideration, not a requirement. Public-sector and small-function readers should also know the Standards include application guidance acknowledging their contexts; proportionate application is built into the design, not an excuse bolted on.

Domain I — Purpose of Internal Auditing

Domain I is the outlier: it contains no principles and no standards. It is a purpose statement — internal auditing strengthens the organization’s ability to create, protect, and sustain value by providing independent, risk-based, and objective assurance, advice, foresight, and insight. Do not skip it because it is short: the purpose statement is the framing the other four domains implement, and its vocabulary (assurance, advice, foresight, insight) is the cleanest answer the profession has to “what does internal audit actually do?” — the question our Role & Value guides spend a whole category on.

Domain II — Ethics and Professionalism (Principles 1–5)

The former Code of Ethics, absorbed and expanded — 13 standards across five principles, now fully testable in quality assessments like everything else. The headline addition: professional courage is no longer implied; it is named in Standard 1.1.

PrincipleStandardWhat it governs
1. Demonstrate Integrity1.1 Honesty and Professional CourageTruthful communication — including raising the messages stakeholders don’t want
1.2 Organization’s Ethical ExpectationsUpholding the organization’s ethics; reporting breaches through proper channels
1.3 Legal and Ethical BehaviorStaying inside law and profession-level ethics, in work and conduct
2. Maintain Objectivity2.1 Individual ObjectivityUnbiased judgment; no conflicting interests or undue influence
2.2 Safeguarding ObjectivityRecognizing and managing threats to objectivity (e.g., auditing your former area)
2.3 Disclosing Impairments to ObjectivityTelling the right people when objectivity is compromised in fact or appearance
3. Demonstrate Competency3.1 CompetencyHaving the knowledge and skills the work requires — or getting them before doing it
3.2 Continuing Professional DevelopmentMaintaining and advancing competence over a career
4. Exercise Due Professional Care4.1 Conformance with the Global Internal Audit StandardsApplying the Standards — the anchor that makes conformance itself an obligation
4.2 Due Professional CareCare and skill of a reasonably prudent auditor, calibrated to the engagement’s stakes
4.3 Professional SkepticismQuestioning mindset; evidence over assertion, however senior the asserter
5. Maintain Confidentiality5.1 Use of InformationUsing information only for legitimate professional purposes
5.2 Protection of InformationSafeguarding the information the function holds

Domain III — Governing the Internal Audit Function (Principles 6–8)

The domain written as much for the board as for auditors: nine standards defining the mandate, independence, and oversight that make everything else possible. If your audit committee reads one domain, it should be this one.

PrincipleStandardWhat it governs
6. Authorized by the Board6.1 Internal Audit MandateThe authority, role, and responsibilities the board grants the function
6.2 Internal Audit CharterThe written charter embodying the mandate, approved by the board and revisited periodically
6.3 Board and Senior Management SupportThe backing — access, cooperation, standing — that makes the mandate real
7. Positioned Independently7.1 Organizational IndependenceCAE reporting lines that keep the function outside the activities it audits
7.2 Chief Audit Executive QualificationsThe board’s duty to ensure the CAE is qualified — hiring, evaluating, and if needed replacing
8. Overseen by the Board8.1 Board InteractionDirect, unfiltered communication between board and CAE
8.2 ResourcesBoard’s role in ensuring the function is resourced to deliver the plan
8.3 QualityThe QAIP: board-discussed, covering the whole function, with results reported at least annually
8.4 External Quality AssessmentIndependent assessment at least every five years (self-assessment with independent validation allowed; at least one active CIA on the team)

Domain IV — Managing the Internal Audit Function (Principles 9–12)

The CAE’s operating manual and the largest domain: sixteen standards covering strategy, planning, resources, communication, and quality. This is where the annual risk assessment, the audit plan, and the QAIP all live.

PrincipleStandardWhat it governs
9. Plan Strategically9.1 Understanding Governance, Risk Management, and Control ProcessesKnowing the organization’s G/R/C landscape as the foundation for everything planned
9.2 Internal Audit StrategyA multi-year strategy for the function itself, aligned to organizational objectives
9.3 MethodologiesEstablished methodologies guiding how the function performs its work
9.4 Internal Audit PlanThe plan, built on a documented risk assessment, refreshed at least annually with board and management input — the full pipeline is in our annual risk assessment playbook
9.5 Coordination and RelianceCoordinating with other assurance providers and deciding when to rely on their work
10. Manage Resources10.1 Financial Resource ManagementThe function’s budget — sufficient, managed, escalated when inadequate
10.2 Human Resources ManagementRecruiting, developing, and deploying the audit team
10.3 Technological ResourcesThe tools and technology the function needs — and uses — to deliver
11. Communicate Effectively11.1 Building Relationships and Communicating with StakeholdersThe ongoing stakeholder relationships that make audit heard
11.2 Effective CommunicationAccurate, objective, clear, concise, constructive, complete, and timely communication — the craft our model report library puts on the page
11.3 Communicating ResultsReporting engagement and plan-level results to the right audiences
11.4 Errors and OmissionsCorrecting and recommunicating when a communication was wrong
11.5 Communicating the Acceptance of RisksEscalating when management accepts risk beyond appetite — ultimately to the board
12. Enhance Quality12.1 Internal Quality AssessmentOngoing monitoring plus periodic self-assessment of conformance and performance
12.2 Performance MeasurementObjectives and measures for the function, with board-approved performance objectives
12.3 Oversee and Improve Engagement PerformanceSupervision and review at the engagement level — the prepare/review trail in every good file

Domain V — Performing Internal Audit Services (Principles 13–15)

The engagement lifecycle in fourteen standards — plan it, do it, communicate it, confirm the fixes. This is the domain fieldwork teams live in.

PrincipleStandardWhat it governs
13. Plan Engagements Effectively13.1 Engagement CommunicationCommunication with management throughout the engagement — the no-surprises machinery
13.2 Engagement Risk AssessmentAssessing the risks of the specific area under review to focus the work
13.3 Engagement Objectives and ScopeWhat the engagement will answer, and its boundaries
13.4 Evaluation CriteriaThe standards the subject is measured against — where Topical Requirements plug in as a mandatory floor
13.5 Engagement ResourcesRight people, skills, and budget for the engagement
13.6 Work ProgramThe documented program of procedures that will meet the objectives
14. Conduct Engagement Work14.1 Gathering Information for Analyses and EvaluationCollecting sufficient, reliable, relevant information
14.2 Analyses and Potential Engagement FindingsComparing criteria and condition; analyzing cause and effect — the engine of the 5 C’s
14.3 Evaluation of FindingsRating significance — how bad, how urgent, how systemic
14.4 Recommendations and Action PlansAuditor recommendations and/or management action plans that address the findings
14.5 Engagement ConclusionsThe overall conclusion the evidence supports
14.6 Engagement DocumentationWorkpapers that let a stranger reperform the work — see our annotated model file
15. Communicate Engagement Results and Monitor Action Plans15.1 Final Engagement CommunicationThe report: results, conclusions, and management’s plans, delivered to the right readers
15.2 Confirming the Implementation of Recommendations or Action PlansFollow-up and validation that fixes actually happened — the discipline of issue validation

What moved from the 2017 Standards

For practitioners translating old muscle memory, the major crosswalks: the Code of Ethics became Domain II (with professional courage added); attribute standards 1000–1110 (purpose, charter, independence) became Principles 6–7; the quality series 1300/1310/1311/1312/1320 became Standards 8.3, 8.4, and 12.1–12.2 — with the EQA’s five-year cadence unchanged; planning standard 2010 grew into the strategy-and-plan pair 9.2/9.4; coordination 2050 became 9.5; and the engagement series 2200–2500 maps onto Principles 13–15. Two things are genuinely new rather than renumbered: the board’s responsibilities are now written to the board (Domain III reads as its job description, not audit’s), and the mandatory Topical Requirements layer sits alongside the Standards — topic-level baselines with their own effective dates, including Third-Party on September 15, 2026. For the change-by-change practitioner analysis, our GIAS update deep dive remains the companion read.

Conformance essentials: quality, EQA, and the Topical Requirements layer

Conformance runs on a small loop you can memorize from the map: Standard 4.1 obliges the function to apply the Standards; 8.3 and 12.1–12.3 make quality a continuous internal discipline (ongoing monitoring, periodic self-assessment, engagement supervision, results to the board at least annually); and 8.4 brings the external check at least every five years — performable as an independent assessment or a self-assessment with independent validation, with at least one active CIA on the assessing team. Applicable Topical Requirements ride along: assessors test them as part of conformance. If you want to know where your function stands before an assessor tells you, our free Self-Assessment Hub includes a GIAS readiness assessment built on exactly the domain-principle-standard structure mapped above — two items per principle, with the standard references attached.

Final Thoughts

Fifty-two standards sounds like a wall; seen as a map, it is a small city with five districts and a legible street grid. Learn the fifteen principles, remember that a standard’s first number names its principle, and keep the requirements-versus-considerations distinction sharp, and you can navigate the whole rulebook from this page. Use it as the trailhead: the risk assessment playbook for 9.4, the findings masterclass for 14.2–14.4, the model workpaper for 14.6, the report library for 11.2 and 15.1, and the Topical Requirements briefing for the layer that now rides alongside. The primary source — always — is the IIA’s official publication; this map is the fast way around it, not a substitute for reading the requirements you are about to test against.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading