The Global Internal Audit Standards are organized as 5 domains, 15 principles, and 52 standards — and this page maps all of them: every principle, every standard by number and official name, and one line on what each governs. The Standards were released January 9, 2024, became effective January 9, 2025, and replaced the 2017 International Standards along with the separate Code of Ethics (ethics now lives inside the Standards as Domain II). Bookmark this as the one-page view of the whole rulebook; the deep dives hang off it.
Why a map matters: the GIAS numbering is principle-based, which is elegant once you see the system and disorienting until you do. Practitioners raised on “1312” and “2340” now navigate “8.4” and “12.3,” and the fastest way to fluency is seeing the whole architecture at once. Everything below is verified against the IIA’s official publication; the authoritative text lives at the IIA’s Global Internal Audit Standards pages, and our in-depth analysis of the 2024/2025 update covers what the changes mean in practice.
In this guide
- How the Standards are built (and the numbering logic)
- Domain I — Purpose of Internal Auditing
- Domain II — Ethics and Professionalism (Principles 1–5, 13 standards)
- Domain III — Governing the Internal Audit Function (Principles 6–8, 9 standards)
- Domain IV — Managing the Internal Audit Function (Principles 9–12, 16 standards)
- Domain V — Performing Internal Audit Services (Principles 13–15, 14 standards)
- What moved from the 2017 Standards
- Conformance essentials: quality, EQA, and the Topical Requirements layer
How the Standards are built (and the numbering logic)
Three nesting levels. Domains are the five big territories: purpose, ethics, governance, managing the function, performing engagements. Principles — numbered 1 through 15 straight across the domains — state what must be true (“Demonstrate Integrity,” “Plan Strategically”). Standards implement the principles, and here is the numbering key that unlocks everything: a standard’s number is its principle’s number plus a sequence — Standard 8.4 is the fourth standard under Principle 8, Standard 13.6 the sixth under Principle 13. Learn the fifteen principles and you can locate any standard blind.
Each standard has the same internal anatomy, and the distinction is load-bearing: Requirements (the “musts” — what conformance is tested against), Considerations for Implementation (how-to guidance — helpful, not mandatory), and Examples of Evidence of Conformance (what demonstrating it can look like). When someone claims “the Standards require X,” check which layer X actually lives in — a surprising share of confident assertions turn out to be citing a consideration, not a requirement. Public-sector and small-function readers should also know the Standards include application guidance acknowledging their contexts; proportionate application is built into the design, not an excuse bolted on.
Domain I — Purpose of Internal Auditing
Domain I is the outlier: it contains no principles and no standards. It is a purpose statement — internal auditing strengthens the organization’s ability to create, protect, and sustain value by providing independent, risk-based, and objective assurance, advice, foresight, and insight. Do not skip it because it is short: the purpose statement is the framing the other four domains implement, and its vocabulary (assurance, advice, foresight, insight) is the cleanest answer the profession has to “what does internal audit actually do?” — the question our Role & Value guides spend a whole category on.
Domain II — Ethics and Professionalism (Principles 1–5)
The former Code of Ethics, absorbed and expanded — 13 standards across five principles, now fully testable in quality assessments like everything else. The headline addition: professional courage is no longer implied; it is named in Standard 1.1.
| Principle | Standard | What it governs |
|---|---|---|
| 1. Demonstrate Integrity | 1.1 Honesty and Professional Courage | Truthful communication — including raising the messages stakeholders don’t want |
| 1.2 Organization’s Ethical Expectations | Upholding the organization’s ethics; reporting breaches through proper channels | |
| 1.3 Legal and Ethical Behavior | Staying inside law and profession-level ethics, in work and conduct | |
| 2. Maintain Objectivity | 2.1 Individual Objectivity | Unbiased judgment; no conflicting interests or undue influence |
| 2.2 Safeguarding Objectivity | Recognizing and managing threats to objectivity (e.g., auditing your former area) | |
| 2.3 Disclosing Impairments to Objectivity | Telling the right people when objectivity is compromised in fact or appearance | |
| 3. Demonstrate Competency | 3.1 Competency | Having the knowledge and skills the work requires — or getting them before doing it |
| 3.2 Continuing Professional Development | Maintaining and advancing competence over a career | |
| 4. Exercise Due Professional Care | 4.1 Conformance with the Global Internal Audit Standards | Applying the Standards — the anchor that makes conformance itself an obligation |
| 4.2 Due Professional Care | Care and skill of a reasonably prudent auditor, calibrated to the engagement’s stakes | |
| 4.3 Professional Skepticism | Questioning mindset; evidence over assertion, however senior the asserter | |
| 5. Maintain Confidentiality | 5.1 Use of Information | Using information only for legitimate professional purposes |
| 5.2 Protection of Information | Safeguarding the information the function holds |
Domain III — Governing the Internal Audit Function (Principles 6–8)
The domain written as much for the board as for auditors: nine standards defining the mandate, independence, and oversight that make everything else possible. If your audit committee reads one domain, it should be this one.
| Principle | Standard | What it governs |
|---|---|---|
| 6. Authorized by the Board | 6.1 Internal Audit Mandate | The authority, role, and responsibilities the board grants the function |
| 6.2 Internal Audit Charter | The written charter embodying the mandate, approved by the board and revisited periodically | |
| 6.3 Board and Senior Management Support | The backing — access, cooperation, standing — that makes the mandate real | |
| 7. Positioned Independently | 7.1 Organizational Independence | CAE reporting lines that keep the function outside the activities it audits |
| 7.2 Chief Audit Executive Qualifications | The board’s duty to ensure the CAE is qualified — hiring, evaluating, and if needed replacing | |
| 8. Overseen by the Board | 8.1 Board Interaction | Direct, unfiltered communication between board and CAE |
| 8.2 Resources | Board’s role in ensuring the function is resourced to deliver the plan | |
| 8.3 Quality | The QAIP: board-discussed, covering the whole function, with results reported at least annually | |
| 8.4 External Quality Assessment | Independent assessment at least every five years (self-assessment with independent validation allowed; at least one active CIA on the team) |
Domain IV — Managing the Internal Audit Function (Principles 9–12)
The CAE’s operating manual and the largest domain: sixteen standards covering strategy, planning, resources, communication, and quality. This is where the annual risk assessment, the audit plan, and the QAIP all live.
| Principle | Standard | What it governs |
|---|---|---|
| 9. Plan Strategically | 9.1 Understanding Governance, Risk Management, and Control Processes | Knowing the organization’s G/R/C landscape as the foundation for everything planned |
| 9.2 Internal Audit Strategy | A multi-year strategy for the function itself, aligned to organizational objectives | |
| 9.3 Methodologies | Established methodologies guiding how the function performs its work | |
| 9.4 Internal Audit Plan | The plan, built on a documented risk assessment, refreshed at least annually with board and management input — the full pipeline is in our annual risk assessment playbook | |
| 9.5 Coordination and Reliance | Coordinating with other assurance providers and deciding when to rely on their work | |
| 10. Manage Resources | 10.1 Financial Resource Management | The function’s budget — sufficient, managed, escalated when inadequate |
| 10.2 Human Resources Management | Recruiting, developing, and deploying the audit team | |
| 10.3 Technological Resources | The tools and technology the function needs — and uses — to deliver | |
| 11. Communicate Effectively | 11.1 Building Relationships and Communicating with Stakeholders | The ongoing stakeholder relationships that make audit heard |
| 11.2 Effective Communication | Accurate, objective, clear, concise, constructive, complete, and timely communication — the craft our model report library puts on the page | |
| 11.3 Communicating Results | Reporting engagement and plan-level results to the right audiences | |
| 11.4 Errors and Omissions | Correcting and recommunicating when a communication was wrong | |
| 11.5 Communicating the Acceptance of Risks | Escalating when management accepts risk beyond appetite — ultimately to the board | |
| 12. Enhance Quality | 12.1 Internal Quality Assessment | Ongoing monitoring plus periodic self-assessment of conformance and performance |
| 12.2 Performance Measurement | Objectives and measures for the function, with board-approved performance objectives | |
| 12.3 Oversee and Improve Engagement Performance | Supervision and review at the engagement level — the prepare/review trail in every good file |
Domain V — Performing Internal Audit Services (Principles 13–15)
The engagement lifecycle in fourteen standards — plan it, do it, communicate it, confirm the fixes. This is the domain fieldwork teams live in.
| Principle | Standard | What it governs |
|---|---|---|
| 13. Plan Engagements Effectively | 13.1 Engagement Communication | Communication with management throughout the engagement — the no-surprises machinery |
| 13.2 Engagement Risk Assessment | Assessing the risks of the specific area under review to focus the work | |
| 13.3 Engagement Objectives and Scope | What the engagement will answer, and its boundaries | |
| 13.4 Evaluation Criteria | The standards the subject is measured against — where Topical Requirements plug in as a mandatory floor | |
| 13.5 Engagement Resources | Right people, skills, and budget for the engagement | |
| 13.6 Work Program | The documented program of procedures that will meet the objectives | |
| 14. Conduct Engagement Work | 14.1 Gathering Information for Analyses and Evaluation | Collecting sufficient, reliable, relevant information |
| 14.2 Analyses and Potential Engagement Findings | Comparing criteria and condition; analyzing cause and effect — the engine of the 5 C’s | |
| 14.3 Evaluation of Findings | Rating significance — how bad, how urgent, how systemic | |
| 14.4 Recommendations and Action Plans | Auditor recommendations and/or management action plans that address the findings | |
| 14.5 Engagement Conclusions | The overall conclusion the evidence supports | |
| 14.6 Engagement Documentation | Workpapers that let a stranger reperform the work — see our annotated model file | |
| 15. Communicate Engagement Results and Monitor Action Plans | 15.1 Final Engagement Communication | The report: results, conclusions, and management’s plans, delivered to the right readers |
| 15.2 Confirming the Implementation of Recommendations or Action Plans | Follow-up and validation that fixes actually happened — the discipline of issue validation |
What moved from the 2017 Standards
For practitioners translating old muscle memory, the major crosswalks: the Code of Ethics became Domain II (with professional courage added); attribute standards 1000–1110 (purpose, charter, independence) became Principles 6–7; the quality series 1300/1310/1311/1312/1320 became Standards 8.3, 8.4, and 12.1–12.2 — with the EQA’s five-year cadence unchanged; planning standard 2010 grew into the strategy-and-plan pair 9.2/9.4; coordination 2050 became 9.5; and the engagement series 2200–2500 maps onto Principles 13–15. Two things are genuinely new rather than renumbered: the board’s responsibilities are now written to the board (Domain III reads as its job description, not audit’s), and the mandatory Topical Requirements layer sits alongside the Standards — topic-level baselines with their own effective dates, including Third-Party on September 15, 2026. For the change-by-change practitioner analysis, our GIAS update deep dive remains the companion read.
Conformance essentials: quality, EQA, and the Topical Requirements layer
Conformance runs on a small loop you can memorize from the map: Standard 4.1 obliges the function to apply the Standards; 8.3 and 12.1–12.3 make quality a continuous internal discipline (ongoing monitoring, periodic self-assessment, engagement supervision, results to the board at least annually); and 8.4 brings the external check at least every five years — performable as an independent assessment or a self-assessment with independent validation, with at least one active CIA on the assessing team. Applicable Topical Requirements ride along: assessors test them as part of conformance. If you want to know where your function stands before an assessor tells you, our free Self-Assessment Hub includes a GIAS readiness assessment built on exactly the domain-principle-standard structure mapped above — two items per principle, with the standard references attached.
Final Thoughts
Fifty-two standards sounds like a wall; seen as a map, it is a small city with five districts and a legible street grid. Learn the fifteen principles, remember that a standard’s first number names its principle, and keep the requirements-versus-considerations distinction sharp, and you can navigate the whole rulebook from this page. Use it as the trailhead: the risk assessment playbook for 9.4, the findings masterclass for 14.2–14.4, the model workpaper for 14.6, the report library for 11.2 and 15.1, and the Topical Requirements briefing for the layer that now rides alongside. The primary source — always — is the IIA’s official publication; this map is the fast way around it, not a substitute for reading the requirements you are about to test against.
Leave a Reply