,

Old IPPF to New GIAS: The Complete Mapping Table

The 2017 International Professional Practices Framework was not revised in January 2024. It was replaced. The Global Internal Audit Standards reorganised everything the old framework said into five domains, fifteen principles and fifty-two numbered standards, absorbed the Code of Ethics and the ten Core Principles into that structure, and retired the four-digit numbering that every methodology manual, charter, engagement template and quality programme had cited for two decades. Any document in your function that still says 1312 or 2060 now points at a number that no longer exists in mandatory guidance, and since 9 January 2025 the conformance statement in your reports has referred to a set of standards your manual may never mention.

This guide is the crosswalk. It maps every 2017 Attribute and Performance Standard to the 2024 standard or standards where its requirements now live, maps the Code of Ethics and the ten Core Principles onto the domains and principles that replaced them, lists the requirements The IIA itself identifies as new with no 2017 counterpart, and then shows how to use the map to update a methodology manual without missing the places where a one-line 2017 requirement became a three-party essential condition. The correspondences follow The IIA’s own two-way mapping of the 2017 mandatory elements to the 2024 Standards, a 166-page working document that maps the old text sentence by sentence; this guide condenses it to the standard level and adds the practitioner notes the official document deliberately leaves out.

It ends with a worked example: MidState’s internal audit function mapping its 2019 methodology manual clause by clause during the 90-day quality-programme build described in the QAIP playbook, the twelve requirements it found no clause for, the nine it closed inside the 90 days, and why the three partial-conformance ratings in its first self-assessment came from clauses that existed but fell short (9.4 and 15.2) or could not yet show a cycle of evidence (12.2).

This guide was rewritten in September 2026 from a shorter version published in August 2026. Standard numbers and titles follow the Global Internal Audit Standards as published by The IIA on 9 January 2024 and effective from 9 January 2025; the 2017-to-2024 correspondences follow The IIA’s two-way mapping document; the notes in the right-hand columns are practitioner commentary, not IIA text, and requirement summaries are paraphrases for orientation.

In this guide

What changed in the framework itself

The 2017 framework had a Mission at the top, four mandatory elements beneath it (the Core Principles, the Definition of Internal Auditing, the Code of Ethics and the Standards) and two layers of recommended guidance (Implementation Guidance and Supplemental Guidance). The Standards themselves were split into Attribute Standards in the 1000 series, which described the characteristics of the function and the people in it, and Performance Standards in the 2000 series, which described the work. Each standard could carry Implementation Standards for assurance (.A1, .A2) and consulting (.C1, .C2), and an italicised Interpretation that was part of the mandatory text.

The 2024 framework has three parts. The Global Internal Audit Standards are mandatory and organised into Domain I (Purpose of Internal Auditing), Domain II (Ethics and Professionalism, Principles 1 to 5), Domain III (Governing the Internal Audit Function, Principles 6 to 8), Domain IV (Managing the Internal Audit Function, Principles 9 to 12) and Domain V (Performing Internal Audit Services, Principles 13 to 15). Topical Requirements are mandatory for assurance engagements on the topics they cover, a category that did not exist in 2017; the first, on cybersecurity, took effect on 5 February 2026, and the Topical Requirements explainer explains how the series works. Global Guidance is recommended. The Global Internal Audit Standards guide walks the whole structure; the table below is the element-by-element move list.

2017 IPPF elementWhere it lives in the 2024 frameworkWhat to change in your documents
Mission of Internal AuditDomain I: Purpose of Internal AuditingReplace the mission quotation in the charter with the Purpose statement or a reference to Domain I.
Definition of Internal AuditingDomain I and the GlossaryCharters and job descriptions that quote the 1999 definition should quote the Purpose instead.
Core Principles (10)The 15 Principles across Domains II to V (see the mapping table below)Delete references to the Core Principles as a separate element; cite the principle numbers.
Code of Ethics (4 principles, 12 rules of conduct)Domain II: Ethics and Professionalism (Principles 1 to 5, Standards 1.1 to 5.2)The ethics policy becomes a Domain II policy; annual attestations should cite Standards 1.1 to 5.2.
Attribute Standards 1000 to 1322Domains II and III, with quality moving to Principles 8 and 12Charter, independence confirmation and quality programme documents.
Performance Standards 2000 to 2600Domains IV and VMethodology manual, planning memo, work program, report and follow-up templates.
Implementation Standards (.A and .C)Folded into the standard text; advisory exceptions are stated inline (for example 13.4, 14.2 and 14.4)Remove the separate assurance and consulting sections; state advisory variations inside each procedure.
Interpretations (mandatory in 2017)Mostly Considerations for Implementation (not mandatory) and the GlossaryCheck whether a clause you treated as mandatory now rests on a consideration only.
Implementation Guides and Supplemental Guidance (recommended)Global Guidance (recommended)Refresh citations as The IIA reissues guidance against the 2024 numbering.
No equivalentTopical Requirements (mandatory for in-scope assurance engagements)Add a topical-requirement check to engagement planning; see the Cybersecurity Topical Requirement workbook.
No equivalentEssential Conditions in Domain III (board and senior management responsibilities)Charter and board calendar must carry the conditions; the manual cannot conform on the board’s behalf.
Conformance wording (“conforms with the International Standards for the Professional Practice of Internal Auditing”)Standards 4.1, 8.3 and 15.1 (“conforms with the Global Internal Audit Standards”)Every report template, charter and QAIP statement.

Two structural changes matter more than the renumbering. First, the Standards now describe three parties’ obligations rather than one: the CAE and internal auditors carry the requirements, but Domain III adds essential conditions that the board and senior management must provide for the function to be effective, and the Domain III introduction requires the CAE to discuss those conditions with both parties. Second, every 2024 standard is written in the same three-part shape: Requirements (the “musts”), Considerations for Implementation (non-mandatory ways to meet them) and Examples of Evidence of Conformance. When you map a 2017 clause, you have to know which of the three parts it landed in.

How to read the mapping: requirements, considerations and essential conditions

Five reading rules keep the tables honest. One: one-to-many is normal. Standard 2060 alone maps to eleven 2024 standards because each item on its reporting list now lives with the standard that generates it. Two: the map runs one way. It tells you where a 2017 requirement went; it does not tell you that the receiving 2024 standard is satisfied by the old clause, because most receiving standards added requirements (9.4 receives 2010 and then asks for more). Three: the destination column matters. If a 2017 “must” landed in a Considerations paragraph it stopped being mandatory, and if a 2017 Interpretation sentence became a Requirement it started being mandatory. Four: some sentences were deleted with no successor; The IIA’s mapping marks them “Not applicable”, and they are explanatory or consulting-specific text rather than requirements you would have documented. Five: the primary destination in the tables below is the standard whose Requirements paragraph holds the operative “must”; secondaries are where fragments went.

Text type in a 2024 standardMandatory?What it isWhat to do with it in the manual
RequirementsYesThe “must” statements for the CAE and internal auditorsEvery requirement needs a clause, an owner and an artefact that evidences it.
Considerations for ImplementationNoCommon and preferred ways to meet the requirementsAdopt the ones that fit; record the choice; do not cite them as conformance obligations.
Examples of Evidence of ConformanceNoDocuments and actions that demonstrate a requirement is metUse as the starting list for the evidence column of the mapping worksheet.
Essential Conditions (Domain III only)Yes, for the board and senior managementResponsibilities of the board and senior management that the function depends on but does not controlPlace in the charter and the board calendar; document the Domain III discussion required by the domain introduction.

Attribute Standards (1000 to 1322) to the 2024 Standards

The Attribute Standards described the function and its people, so most of them landed in Domain II (the people) and Domain III (the function’s position and oversight), with the quality programme splitting between the board’s oversight role in Principle 8 and the CAE’s internal programme in Principle 12. The Domain II guide and the Domain III guide cover the receiving standards in depth.

2017 standard2024 primary2024 secondaryWhat actually moved
1000 Purpose, Authority, and Responsibility6.1 Internal Audit Mandate; 6.2 Internal Audit CharterPrinciple 6; GlossaryThe charter survives. The new mandate standard adds a duty to discuss the mandate with the board and revisit it when circumstances change. Board approval of the charter is now an essential condition.
1010 Recognizing Mandatory Guidance in the Internal Audit Charter6.2 Internal Audit Charter6.1 essential conditionsThe charter must state the function’s commitment to the Standards; the discussion of mandatory guidance with the board sits under 6.1.
1100 Independence and Objectivity7.1 Organizational Independence; 2.1 Individual ObjectivityPrinciple 2; 2.2 Safeguarding ObjectivityThe 2017 pairing is split: independence is a governance matter in Domain III, objectivity an individual ethics matter in Domain II.
1110 Organizational Independence7.1 Organizational Independence6.3, 8.1, 13.3The list of things the board approves (charter, plan, budget, CAE appointment and remuneration) is redistributed into essential conditions under 6.2, 7.1, 8.2 and 9.4. Annual confirmation of independence to the board stays in 7.1; freedom from interference in scope moves to 13.3.
1111 Direct Interaction with the Board8.1 Board Interaction6.3Unchanged in substance; the board’s side, including meeting the CAE without senior management present, is written as an essential condition.
1112 Chief Audit Executive Roles Beyond Internal Auditing7.1 Organizational Independence2.2 Safeguarding ObjectivitySafeguards for additional CAE roles sit in 7.1; periodic independent assurance over those roles appears under 2.2.
1120 Individual Objectivity2.1 Individual Objectivity2.2 ConsiderationsThe conflict-of-interest definition moved from a mandatory Interpretation into non-mandatory Considerations.
1130 Impairment to Independence or Objectivity (with .A1 to .A3, .C1, .C2)2.3 Disclosing Impairments to Objectivity; 2.2 Safeguarding Objectivity7.1The twelve-month rule on assessing areas of prior responsibility, the advisory carve-outs and the disclosure duty all survive, mostly in 2.2; independence impairments (as opposed to objectivity) sit in 7.1.
1200 Proficiency and Due Professional CarePrinciple 3 Demonstrate Competency; Principle 4 Exercise Due Professional CareNoneHeading-level standard; the substance is in 3.1, 3.2, 4.2 and the new 4.3.
1210 Proficiency (with .A1 to .A3, .C1)3.1 Competency10.2 Human Resources ManagementFraud and IT knowledge expectations moved from the mandatory Interpretation into 3.1 Considerations; the function-level competency mix is in 10.2. One 2017 sentence is deleted.
1220 Due Professional Care (with .A1 to .A3, .C1)4.2 Due Professional Care3.1, 13.2, Principle 4The list of things to weigh (extent of work, complexity, materiality, cost against benefit, technology-based techniques) is intact; alertness to significant risks now also feeds 13.2 Engagement Risk Assessment.
1230 Continuing Professional Development3.2 Continuing Professional DevelopmentNoneUnchanged in substance.
1300 Quality Assurance and Improvement Program8.3 QualityPrinciple 12; 12.2 Performance MeasurementThe QAIP is split between the board’s oversight role (8.3) and the CAE’s internal programme (12.1 to 12.3); the “efficiency and effectiveness” purpose becomes 12.2.
1310 Requirements of the QAIP8.3 QualityNoneInternal and external assessments both remain required.
1311 Internal Assessments12.1 Internal Quality Assessment9.3, 3.1Ongoing monitoring plus periodic self-assessment survives; day-to-day supervision is treated as methodology (9.3) and 12.1 Considerations.
1312 External Assessments8.4 External Quality Assessment12.1, 8.1, 8.3The five-year cycle, the qualified-and-independent assessor test and the self-assessment-with-independent-validation option are retained; the board’s involvement in scope and assessor selection is an essential condition. Two 2017 Interpretation sentences are deleted.
1320 Reporting on the QAIP8.3 Quality8.1, 8.4, 12.1Results still go to the board and senior management: external results on completion, internal results through the QAIP reporting under 12.1, with action plans for deficiencies.
1321 Use of “Conforms with the International Standards for the Professional Practice of Internal Auditing”4.1 Conformance with the Global Internal Audit Standards; 8.3 Quality15.1, 12.1, 8.4The statement still requires supporting QAIP results; the engagement-level wording sits in 15.1; the phrase itself changes.
1322 Disclosure of Nonconformance12.1 Internal Quality Assessment8.3Nonconformance that affects the overall scope or operation of the function must be disclosed to the board and senior management with its impact.

Performance Standards 2000 to 2130: managing the function and nature of work

The 2000 series described how the CAE runs the function and what the function covers. It maps almost entirely into Domain IV, and the Domain IV guide explains each receiving standard. Two things to notice: a single 2017 sentence on resources became three standards, and the 2100 “nature of work” standards, which used to enumerate governance, risk management and control topics the function must assess, collapse into one standard about understanding those processes.

2017 standard2024 primary2024 secondaryWhat actually moved
2000 Managing the Internal Audit ActivityDomain IV introduction; Principles 9 and 109.2, 9.4, 12.2, 10.1 to 10.3, Domain IThe “adds value” test becomes the Purpose in Domain I and 12.2 Performance Measurement; the “effectively managed” test becomes the whole of Domain IV.
2010 Planning (with .A1, .A2, .C1)9.4 Internal Audit Plan9.1, 9.2, 11.1, 11.3The risk-based plan survives with more content requirements. The plan’s link to organisational strategy grows into a standalone standard, 9.2 Internal Audit Strategy. Stakeholder input to the plan moves to 11.1.
2020 Communication and Approval9.4 Internal Audit Plan8.2, 10.1, 10.2, 10.3Plan and budget approval are now board essential conditions under 8.2 Resources and 9.4; the duty to communicate the impact of resource limitations sits in 10.1.
2030 Resource Management10.1 Financial Resource Management; 10.2 Human Resources Management; 10.3 Technological ResourcesNoneOne sentence becomes three standards. 10.3 carries a new duty to collaborate with IT and information security when implementing technology.
2040 Policies and Procedures9.3 Methodologies12.3, 9.4“Policies and procedures” becomes “methodologies”, a term the 2024 Standards use for the whole documented approach; the supervision aspect feeds 12.3.
2050 Coordination and Reliance9.5 Coordination and Reliance9.3Retained, with a new requirement to raise concerns with senior management and, if necessary, the board when appropriate coordination cannot be achieved.
2060 Reporting to Senior Management and the Board11.3 Communicating Results8.1, 12.2, 6.1, 6.2, 7.1, 8.2, 8.3, 9.2, 9.4, 11.1, 11.5The most scattered 2017 standard. Each item on the 2060 list (purpose and authority, plan status, conformance, resources, significant risks, risk acceptance) now lives with the standard that generates it; the periodic report itself is 11.3. See the trap section for the item-by-item map.
2070 External Service Provider and Organizational Responsibility for Internal AuditingDomain III introduction; Domain IV introductionNoneNo standalone standard. The principle that the organisation retains responsibility for an effective function even when a provider delivers it is stated in the domain introductions.
2100 Nature of Work9.1 Understanding Governance, Risk Management, and Control ProcessesDomain IGovernance, risk management and control remain the scope of the function; the requirement to understand them, and to use that understanding in planning, is 9.1.
2110 Governance (with .A1, .A2)9.19.4, 14.4The enumerated governance topics (ethics, performance management, IT governance) are no longer “must assess” items; they inform the risk assessment and plan under 9.1 and 9.4 and the recommendations under 14.4.
2120 Risk Management (with .A1, .A2, .C1 to .C3)9.19.4, 13.2, 14.4, Domain VFraud-risk evaluation persists through 13.2 and the plan; several Interpretation sentences are deleted.
2130 Control (with .A1, .C1)9.114.4Same treatment as 2110 and 2120: the “nature of work” list becomes a single understanding standard plus the engagement standards.

Performance Standards 2200 to 2600: the engagement standards

The engagement standards map into Domain V with two exceptions that catch people: supervision (2340) moves into the quality principle in Domain IV as 12.3, and the CAE-level communication standards (2420 quality of communications, 2421 errors and omissions, 2440 dissemination, 2450 overall opinions, 2600 risk acceptance) move into Principle 11 because they apply to everything the function communicates, not only engagement reports. The Domain V guide covers Standards 13.1 to 15.2 one by one.

2017 standard2024 primary2024 secondaryWhat actually moved
2200 Engagement Planning13.2 Engagement Risk Assessment; 13.3 Engagement Objectives and Scope; 13.5 Engagement ResourcesNoneThe planning elements each get a standard; timing and the work program follow in 13.6.
2201 Planning Considerations (with .A1, .C1)13.2 Engagement Risk Assessment13.3, Domain VThe “consider strategies, objectives, risks and controls” list becomes the engagement risk assessment; a documented risk assessment per engagement is now explicit. Some Interpretation sentences are deleted.
2210 Engagement Objectives (with .A1 to .A3, .C1, .C2)13.3 Engagement Objectives and Scope13.2, 13.4Evaluation criteria get their own standard, 13.4; for advisory engagements criteria may be unnecessary by agreement with stakeholders.
2220 Engagement Scope (with .A1, .A2, .C1, .C2)13.3 Engagement Objectives and Scope13.6Scope, and changes to it, sit in 13.3 with the work program in 13.6.
2230 Engagement Resource Allocation13.5 Engagement ResourcesNoneUnchanged in substance.
2240 Engagement Work Program (with .A1, .C1)13.6 Work ProgramNoneWork programs must be documented and approved before work starts, with adjustments approved promptly.
2300 Performing the EngagementPrinciple 14 Conduct Engagement WorkNoneHeading-level standard.
2310 Identifying Information14.1 Gathering Information for Analyses and EvaluationNoneThe sufficient, reliable, relevant and useful test is retained; one Interpretation sentence is deleted.
2320 Analysis and Evaluation14.2 Analyses and Potential Engagement Findings; 14.3 Evaluation of Findings; 14.4 Recommendations and Action Plans; 14.5 Engagement ConclusionsNoneOne 2017 sentence becomes four standards: findings are built from criteria, condition, cause and effect, rated for significance, paired with recommendations or action plans, and rolled into an engagement conclusion. See the finding severity ratings guide for the 14.3 rating step.
2330 Documenting Information (with .A1, .A2, .C1)14.6 Engagement Documentation5.2, 9.3, 11.3Documentation requirements stay; retention rules become methodology (9.3) and control over release of records to outside parties sits with 5.2 Protection of Information and 11.3.
2340 Engagement Supervision12.3 Oversee and Improve Engagement PerformanceNoneSupervision leaves the engagement domain for the quality principle: it is now the CAE’s oversight of engagement performance, and supervision evidence is quality evidence.
2400 Communicating Results15.1 Final Engagement CommunicationNoneHeading-level standard.
2410 Criteria for Communicating (with .A1 to .A3, .C1)15.1 Final Engagement Communication; 14.5 Engagement Conclusions11.3, 14.2, 14.3, 13.1, 5.2Objectives, scope, conclusions, findings, recommendations and action plans remain the required content; the rules on releasing results outside the organisation sit in 11.3 and 5.2.
2420 Quality of Communications11.2 Effective Communication15.1, 13.1The seven qualities (accurate, objective, clear, concise, constructive, complete, timely) apply to all communications, not only reports.
2421 Errors and Omissions11.4 Errors and OmissionsNoneUnchanged in substance.
2430 Use of “Conducted in Conformance with the International Standards for the Professional Practice of Internal Auditing”15.1 Final Engagement Communication4.1The engagement-level conformance statement survives with the new wording.
2431 Engagement Disclosure of Nonconformance15.1 Final Engagement CommunicationNoneDisclosure of the standard not conformed with, the reason and the impact continues.
2440 Disseminating Results (with .A1, .A2, .C1, .C2)11.3 Communicating Results15.1, 14.3The CAE’s responsibility for distribution, and the assessment of risk before releasing results outside the organisation, are in 11.3; some Interpretation sentences are deleted.
2450 Overall Opinions11.3 Communicating ResultsNoneOverall opinions no longer have a standard of their own; the content requirements for an overall opinion sit inside 11.3.
2500 Monitoring Progress (with .A1, .C1)15.2 Confirming the Implementation of Recommendations or Action PlansNoneFollow-up becomes confirmation: the CAE must establish a process to confirm that recommendations or action plans were implemented, and results feed 11.3 and 11.5 where management chooses not to act.
2600 Communicating the Acceptance of Risks11.5 Communicating the Acceptance of Risks15.2Unchanged in substance: discuss with senior management, escalate to the board if unresolved, and it is not the CAE’s job to resolve the risk.

Code of Ethics and Core Principles to Domains I and II

The 2017 Code of Ethics was a separate mandatory document with four principles and twelve rules of conduct. In 2024 it becomes Domain II, and the rules become standards with requirements, considerations and evidence examples like every other standard, which is the practical change: an ethics attestation can now be tested against 1.1 to 5.2 in the same way a plan is tested against 9.4. Confidentiality, a principle with two rules in 2017, becomes Principle 5 with two standards of its own. Competency splits between Principle 3 (competency and development) and Principle 4 (conformance, due care and the new professional scepticism standard).

2017 Code of Ethics element2024 destinationNote
Integrity (principle and rules 1.1 to 1.4)Principle 1 Demonstrate Integrity: 1.1 Honesty and Professional Courage; 1.2 Organization’s Ethical Expectations; 1.3 Legal and Ethical BehaviorRule 1.4 (not engaging in acts discreditable to the profession) is absorbed into the Domain II introduction and 1.3.
Objectivity (principle and rules 2.1 to 2.3)Principle 2 Maintain Objectivity: 2.1 Individual Objectivity; 2.2 Safeguarding Objectivity; 2.3 Disclosing Impairments to ObjectivityRule 2.3 (disclose all material facts known) maps to 2.2 Safeguarding Objectivity.
Confidentiality (principle and rules 3.1, 3.2)Principle 5 Maintain Confidentiality: 5.1 Use of Information; 5.2 Protection of InformationBoth rules become standards; 5.2 also receives the record-access sentences from 2330.
Competency (principle and rules 4.1 to 4.3)Principle 3 Demonstrate Competency: 3.1 Competency; 3.2 Continuing Professional Development. Principle 4 Exercise Due Professional Care: 4.1 Conformance with the Global Internal Audit Standards; 4.2 Due Professional CareRule 4.2 (perform services in accordance with the Standards) becomes Standard 4.1, which is why “conformance” is now an individual ethics obligation as well as a function-level one.
No 2017 counterpart1.1 (CAE work environment); 4.3 Professional SkepticismListed by The IIA as new requirements; see the next section.

The ten Core Principles for the Professional Practice of Internal Auditing were introduced in 2015 as the articulation of what an effective function looks like. They do not survive as a list, but each one maps to a principle or domain, and the map is useful when a charter or audit committee paper quotes them.

2017 Core Principle2024 destination
1. Demonstrates integrityPrinciple 1 Demonstrate Integrity
2. Demonstrates competence and due professional carePrinciple 3 Demonstrate Competency; Principle 4 Exercise Due Professional Care
3. Is objective and free from undue influence (independent)Principle 2 Maintain Objectivity; Principle 7 Positioned Independently
4. Aligns with the strategies, objectives, and risks of the organizationPrinciple 9 Plan Strategically
5. Is appropriately positioned and adequately resourcedPrinciple 7 Positioned Independently; Principle 10 Manage Resources
6. Demonstrates quality and continuous improvementPrinciple 12 Enhance Quality
7. Communicates effectivelyPrinciple 11 Communicate Effectively
8. Provides risk-based assuranceDomain I; 9.4 Internal Audit Plan; 13.2 Engagement Risk Assessment
9. Is insightful, proactive, and future-focusedDomain I
10. Promotes organizational improvementDomain I

What is new: the requirements with no 2017 counterpart

The end of The IIA’s mapping table lists the 2024 requirements that do not align with any 2017 mandatory guidance. The list is shorter than most transition presentations suggest, because The IIA traces several standards that feel new (9.2 Internal Audit Strategy, 12.2 Performance Measurement, 13.1 Engagement Communication) back to fragments of 2000, 2010, 2060, 2410 and 2420. The official list, condensed, is below, with the artefact a reviewer will ask for.

New requirement (IIA reference)What it requiresArtefact to build
Domain IThe Standards are “set in the public interest”None; a statement of purpose.
1.1-a and 1.1-bInternal auditors must exhibit professional courage; the CAE must maintain a work environment where auditors feel supported when expressing legitimate, evidence-based results, favourable or notA speak-up clause in the manual, a dispute-escalation route for report findings, and evidence the route has been used or tested.
4.3-a and 4.3-bProfessional scepticism when planning and performing services: inquisitiveness, critical assessment of information reliability, straightforward questioning of inconsistencies, seeking additional evidence when information may be incomplete or misleadingPrompts in the work program and review checklist; training records; workpaper examples of evidence reliability assessment.
Domain III introductionThe CAE must discuss Domain III and its essential conditions with the board and senior management, and where either disagrees, explain with examples how the absence of a condition affects the functionA board agenda item, a paper and minutes.
6.3-a to 6.3-cThe CAE coordinates board communications with senior management; the board champions the function; senior management supports its recognition across the organisationCharter clauses and a communications protocol.
7.2-a to 7.2-dThe CAE helps the board understand the qualifications a CAE needs and maintains their own; the board approves the CAE’s roles and identifies the necessary qualifications and engages with senior management to appoint a qualified CAE; senior management enables appointment, development and remuneration through HR processesA CAE role profile approved by the board; CAE development record; the appointment process in the charter.
8.3 essential conditionsSenior management provides input on the function’s performance objectives and participates with the board in an annual assessment of the CAE and the functionPerformance objectives with senior-management input on file; an annual assessment record.
9.5If appropriate coordination with other providers cannot be achieved, raise concerns with senior management and, if necessary, the boardAn escalation clause in the coordination procedure.
10.3Collaborate with IT and information security to implement technological resources properlyA record of that collaboration for audit tools (data access, analytics platforms, audit management systems).
13.4 and 14.2For advisory services, evaluation criteria and evidence gathering to develop findings may not be necessary, depending on the agreement with stakeholdersAn advisory-engagement variant of the planning memo and work program.
14.4When auditors and management disagree about recommendations or action plans, follow an established methodology that lets both express their position and reach a resolutionA disagreement-resolution procedure and a record of its use.
15.1-a to 15.1-cThe final communication must name the individuals responsible for addressing findings and the planned completion dates; must acknowledge management actions already initiated or completed; must be reviewed and approved by the CAE before issueReport template fields for owner and date; a CAE sign-off record; see the internal audit report template.

Add to that list the standards that are new as documents even though their sentences have ancestors: a written internal audit strategy (9.2), a performance-measurement framework with objectives reported to the board (12.2), an engagement communication standard covering the whole engagement rather than the report (13.1), a technological-resources standard (10.3) and confidentiality standards that can be tested (5.1 and 5.2). MidState’s mapping, in the worked example, found no clause for six of these, which is why the QAIP self-assessment template is worth running before the manual is rewritten rather than after.

Where the mapping misleads: eight traps

A crosswalk invites a find-and-replace, and a find-and-replace is exactly how functions end up with a manual that cites 9.4 in the place where it used to cite 2010 and still fails a self-assessment against 9.4. The eight traps below are the places where the number moved and the substance moved further.

1. The board’s side of the ledger

Standard 1110 listed the things the board must approve or receive: the charter, the risk-based plan, the budget, communications on performance, decisions on the CAE’s appointment, removal and remuneration. The 2024 Standards keep every item but move most of them into essential conditions under 6.2, 7.1, 8.1, 8.2 and 9.4. The CAE cannot conform on the board’s behalf, so the manual is the wrong document for them; they belong in the charter and the audit committee’s annual calendar, and the Domain III discussion the introduction requires is the evidence that the board has accepted them. The audit committee presentation template is built around that calendar.

2. Standard 2060 in eleven pieces

The annual report to the audit committee was written against the 2060 list. Each item now has a different home, and a report that still follows the 2060 structure will miss the items the receiving standards added (performance objectives and results under 12.2; the strategy under 9.2; the independence confirmation wording under 7.1).

2060 reporting item2024 standard that now generates it
Purpose, authority and responsibility of the function6.1 Internal Audit Mandate; 6.2 Internal Audit Charter
Performance relative to the plan9.4 Internal Audit Plan; 12.2 Performance Measurement; 11.3 Communicating Results
Conformance with the Code of Ethics and the Standards8.3 Quality; 12.1 Internal Quality Assessment; 8.4 External Quality Assessment
Significant risk exposures and control issues, including fraud and governance issues11.3 Communicating Results
Resource requirements and the impact of limitations8.2 Resources; 10.1 Financial Resource Management
Risk accepted by management11.5 Communicating the Acceptance of Risks
Organizational independence confirmation7.1 Organizational Independence
Strategy and how the plan supports it9.2 Internal Audit Strategy (new content)

3. Conformance statements in three places

Standards 1321 and 2430 governed two sentences: the function-level “conforms with” statement and the engagement-level “conducted in conformance with” statement. Both survive with new wording, but they are now governed by three standards (4.1 for the individual auditor, 8.3 for the function, 15.1 for the engagement), and 8.3 ties the function-level statement to the results of the quality programme. A report template that changed the wording but kept a conformance sentence the QAIP results do not support is nonconformant twice.

4. Supervision became quality evidence

Standard 2340 sat among the engagement standards, so most manuals put supervision in the fieldwork chapter and evidenced it with review sign-offs on workpapers. Standard 12.3 puts the same activity under Principle 12 Enhance Quality, which changes what a reviewer expects to see: not only sign-offs but the CAE’s oversight of engagement performance, the resulting improvements to methodology, and their link to the internal assessment under 12.1. The workpaper best practices guide still applies to the sign-offs; the quality chapter needs the rest.

5. Overall opinions without a standard

Standard 2450 had specific content rules for an overall opinion: the scope and time period, the basis, the summary of information supporting it, the framework used, and the expectations of senior management and the board. The rules did not disappear; they are inside 11.3. Functions that issue an annual opinion should keep the 2450 content list and cite 11.3, not conclude that the requirement went away.

6. Follow-up became confirmation

Standard 2500 asked for a system to monitor the disposition of results. Standard 15.2 asks the CAE to establish a process to confirm implementation of recommendations or action plans, and 15.1-a asks the final communication to name the responsible individuals and planned dates that the confirmation process will test against. A tracker that records “closed per management” without the function’s own confirmation was arguable under 2500 and is not under 15.2. MidState’s first self-assessment rated 15.2 partially conformant for a different reason, past-due actions never escalated to the committee, which shows the standard has more than one edge.

7. Outsourced and co-sourced functions

Standard 2070 told an external service provider acting as the function to make the organisation aware that the organisation retains responsibility for an effective internal audit function. There is no 2024 standard with that number or title; the point is made in the Domain III and Domain IV introductions. Provider contracts and charters for outsourced functions should say it explicitly, because a reviewer will not find a standard to cite. The co-sourcing vs outsourcing comparison covers the governance side.

8. Interpretations that stopped being mandatory, and considerations that started

The 2017 Interpretations were mandatory. Many of them (the conflict-of-interest definition in 1120, the fraud and IT knowledge expectations in 1210, the “consider” lists in 1220) now sit in Considerations for Implementation, which are not. The opposite also happened: the link between the plan and strategy that 2010 mentioned in passing is now a requirement to have a written strategy (9.2), and the stakeholder input that 2010’s Interpretation suggested is a requirement under 11.1. A manual that treated Interpretations as optional in 2017 gains nothing; a manual that treated them as mandatory can simplify, but only after checking which sentences moved up rather than down.

The methodology-manual update procedure and worksheet template

The update is a mapping exercise, not a rewrite, until the mapping says otherwise. Done in the order below it takes a mid-sized function forty to sixty hours of a manager’s time plus CAE review, and it produces the evidence a self-assessment or external assessor will ask for first: a clause-level record of where every requirement is met. The steps assume the manual exists as numbered clauses; if it does not, numbering it is step zero.

Step 1: inventory the citations. Extract every reference to a 2017 element from the manual, the charter, the engagement templates, the report template, the QAIP documents and the audit committee reporting pack. Record the document, the clause number and the 2017 reference. Expect between one hundred and two hundred citations in a manual of normal size, most of them in the planning, reporting and quality chapters.

Step 2: map each citation forward. Using the tables above, record the 2024 primary and secondary destinations for each citation, and the text type it landed in (requirement, consideration, essential condition, deleted). Do this at the sentence level for the standards with one-to-many destinations (1110, 1300 to 1322, 2010, 2020, 2060, 2320, 2410) and at the standard level for the rest.

Step 3: map backward. List all fifty-two standards and, for each requirement paragraph, find the clause that meets it. This is the step the forward map cannot do for you, and it is where the gaps appear: a requirement with no clause is either new (check the list above) or a requirement the 2017 standard implied and the manual never wrote down. Use the Examples of Evidence of Conformance in each standard as the checklist of artefacts.

Step 4: sort the gaps. Each gap is one of four kinds: a clause to write (the requirement is met in practice but undocumented); a practice to build (the requirement is not met, and a clause alone will not fix it); an essential condition to take to the board (not the CAE’s to close); or a deliberate nonconformance to disclose under 12.1 with its impact. Assign an owner and a date to every gap; the self-assessment will ask for them.

Step 5: rewrite by domain, not by search-and-replace. Restructure the manual to follow Domains II to V so that a reviewer can walk the standards in order and find the clauses in order. Retire the assurance and consulting sub-sections in favour of inline advisory variations. Replace every conformance sentence with the 2024 wording and tie the function-level one to the QAIP results.

Step 6: update the artefacts the manual points to. The planning memo needs an engagement risk assessment (13.2) and criteria (13.4); the report template needs owners and dates (15.1-a), acknowledgement of actions already taken (15.1-b) and a CAE approval field (15.1-c); the follow-up tracker needs a confirmation step (15.2); the audit committee pack needs the 2060 remap above. The audit planning memo template and the internal audit plan template already carry the 2024 fields.

Step 7: take Domain III to the board. Present the essential conditions, the charter changes and the CAE role profile in one paper; minute the discussion the Domain III introduction requires; record any condition the board or senior management declines and the CAE’s explanation of the effect.

Step 8: run the self-assessment against the new manual. Not against the old one. The QAIP self-assessment template is built for this, and the result is the baseline the first internal quality assessment under 12.1 reports to the board.

Methodology mapping worksheet (one row per citation, then one row per 2024 requirement)

Forward sheet columns: Document | Clause number | Clause text (first line) | 2017 reference cited | 2024 primary | 2024 secondary | Text type at destination (Requirement / Consideration / Essential condition / Deleted) | Change needed (renumber only / rewrite clause / new artefact / board item) | Owner | Target date | Status.

Backward sheet columns: Domain | Principle | Standard | Requirement paragraph (summarised) | Clause(s) that meet it | Artefact that evidences it | Evidence located (Y/N) | Gap type (clause to write / practice to build / essential condition / disclosed nonconformance) | Owner | Target date | Self-assessment rating.

Transition sign-off checklist: All 2017 citations inventoried and mapped (count agreed to the citation extract). All fifty-two standards have at least one clause or a recorded gap. Conformance wording replaced in charter, report template and QAIP statement. Advisory variations stated inline; .A and .C sub-sections retired. Essential conditions placed in the charter and board calendar; Domain III discussion minuted. Report template carries owner, date, prior-action acknowledgement and CAE approval. Follow-up procedure includes confirmation of implementation. Audit committee pack restructured to the 2060 remap. Self-assessment completed against the new manual; results and action plan reported under 12.1. Manual version, approval date and next review date recorded on the cover.

Worked example: MidState maps a 2019 manual in 46 hours

MidState Beverage, the illustrative three-state drinks distributor used across this site, has a six-person internal audit function: a chief audit executive, a manager, two seniors, a staff auditor and an analytics auditor. Its charter was written in 2019 and rewritten in June 2026; its methodology manual dated from the same year as the original charter and cited the 2017 Standards throughout. When the audit committee asked, after the FY27-01 route cash report, whether the function conformed with the Standards, the CAE built a quality programme in ninety days, as the QAIP playbook describes. The clause-by-clause map of the manual ran in the same ninety days as a separate workstream owned by the manager, because the CAE reasoned that a self-assessment against a manual that cited 2017 numbers would produce findings about numbering rather than about practice.

The manual had eleven chapters and 168 numbered clauses, and the citation inventory found 143 references to 2017 elements across the manual, the charter, four engagement templates, the report template and the audit committee pack. The forward map took the manager 22 hours over two weeks. Ninety-six citations mapped one-to-one and needed renumbering only. Thirty-one mapped one-to-many, all of them in the planning, reporting and quality chapters, and each needed the clause split or rewritten so that a reader could follow it to the right standard. Nine mapped to essential conditions, which the CAE moved out of the manual into a Domain III board paper. Seven mapped to deleted Interpretation sentences, mostly consulting-specific text in a chapter on advisory work the function had rarely used.

The backward map took a further 24 hours and produced the list that mattered: twelve 2024 requirements with no clause anywhere in the manual. Six were the “new as documents” standards from the section above: 9.2 (no written strategy), 12.2 (plan-completion and hours metrics existed, but no objectives with targets aligned to a strategy), 13.1 (no clause on communication during the engagement, only on the report), 10.3 (nothing on technological resources, although the analytics tooling was in place) and 5.1 and 5.2 (a confidentiality sentence in the charter and nothing in the manual). Four were items from The IIA’s new-requirements list: 7.2 (no CAE role profile), 4.3 (no mention of professional scepticism), 14.4 (no procedure for disagreements over recommendations; in practice the CAE decided) and 1.1-b (no route for an auditor who believes a finding is being softened under pressure). The last two were 9.5 (no escalation route when coordination with the external auditor failed, which had happened in 2024) and the Domain III discussion itself, which had never taken place.

GapKindAction inside the 90 daysStatus at first self-assessment
9.2 Internal Audit StrategyPractice to buildThree-year strategy with five objectives written; reviewed with the audit committee in June 2026Closed; generally conforms, first annual review due FY28
12.2 Performance MeasurementPractice to buildMeasures adopted from the strategy’s objectives with targets, with senior-management input (an 8.3 essential condition)Partially conforms: targets set, quarterly reporting starts FY28, no cycle of results yet
13.1 Engagement CommunicationClause to writeCommunication plan added to the planning memo templateClosed
10.3 Technological ResourcesClause to writeAnalytics and audit-management tools inventoried; IT security consulted on data accessClosed
5.1 and 5.2 ConfidentialityClause to writeInformation-handling clauses added; the records-access rule from old 2330.A1 moved hereClosed
7.2 CAE QualificationsEssential conditionRole profile drafted; approved by the committee with the June charterClosed
4.3 Professional SkepticismClause to writeScepticism prompts added to the work program and review checklistClosed
14.4 Disagreement methodologyPractice to buildTwo-step resolution procedure written; used once before the assessmentClosed
1.1-b Work environmentClause to writeSpeak-up route written: to the CAE, or to the committee chair if the CAE is the source of the pressure; explained at the staff meetingClosed
9.5 Escalation of coordination concernsClause to writeEscalation sentence added to the coordination procedureClosed
Domain III discussionEssential conditionHeld at the June committee meeting; minuted, with two conditions deferredClosed

Eleven rows for twelve gaps because 5.1 and 5.2 were closed together. Nine gaps were closed by writing the clause and producing the artefact inside the ninety days; 12.2 could not be, because a performance-measurement framework needs a reporting cycle before it can be evidenced. The two other partial-conformance ratings in the first self-assessment came from clauses that existed and fell short. The 2010 plan clause, renumbered to 9.4, said nothing about stating the plan’s limitations or communicating significant in-year changes to the committee, and the FY27 plan followed the clause: no limitations section, and a 540-hour cyber programme audit added mid-year on the committee chair’s email approval. The 2500 follow-up clause, renumbered to 15.2, had no rule for escalating past-due actions, and at the assessment date three of the function’s fourteen open actions were past due with nothing said to the committee. Neither would have been caught by a find-and-replace, and both were fixed with a clause and a report. The external quality assessment is scheduled for FY28, and the mapping worksheet, both sheets, is the first document the CAE plans to hand the assessor.

The total was 46 hours of the manager’s time plus roughly ten hours of CAE review, against a manual rewrite the function had originally scoped at three months of elapsed time. The rewrite still happened, but it happened knowing which forty clauses needed thought and which hundred needed a new number.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading