Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

global internal audit standards — Global Internal Audit Standards: The Complete 2026 Guide

Global Internal Audit Standards: The Complete 2026 Guide

The Global Internal Audit Standards are the IIA’s rulebook for internal auditing, and since 9 January 2025 they are the edition every internal audit function claiming conformance is measured against. They replaced the 2017 International Professional Practices Framework (IPPF) standards, and the change is not a renumbering exercise. The board now has written duties, the function needs a strategy and a performance methodology, and a new class of mandatory requirement, the Topical Requirements, sits alongside the core text.

This guide covers the structure, the changes from 2017, and a transition sequence that will stand up at your next quality assessment.

What this guide covers

global internal audit standards explained
The Global Internal Audit Standards at a glance: five domains, fifteen principles and 52 standards.

What the Global Internal Audit Standards are

The IIA issued the Global Internal Audit Standards on 9 January 2024 and gave functions a year to prepare: they took effect on 9 January 2025. The full text is free to read on the IIA website.

The Global Internal Audit Standards apply to anyone providing internal audit services, whether that is an in-house team, an outsourced provider, or a co-sourced mix. The chief audit executive (CAE) is accountable for the function’s conformance overall, but individual auditors are also responsible for the requirements that apply to their own work.

Within the IPPF, the Global Internal Audit Standards share the mandatory tier with the Topical Requirements. Global Guidance remains supplemental.

How the Global Internal Audit Standards are structured

The Global Internal Audit Standards are organised as 5 domains, 15 principles and 52 standards. Each standard is written in three layers: Requirements (the “must” statements), Considerations for Implementation (how to apply them), and Examples of Evidence of Conformance (what an assessor might look for). Standard 11.2 is the one exception, with no evidence-examples section.

  • Domain I, Purpose of Internal Auditing. A single statement of why the function exists. It has no numbered standards, but the charter must reflect it.
  • Domain II, Ethics and Professionalism. Principles 1 to 5 (integrity, objectivity, competency, due professional care, confidentiality), 13 standards. This is where the old Code of Ethics now lives.
  • Domain III, Governing the Internal Audit Function. Principles 6 to 8, 9 standards (6.1 to 8.4) covering mandate, charter, board support, independence, CAE qualifications, oversight, resources, quality and external assessment.
  • Domain IV, Managing the Internal Audit Function. Principles 9 to 12, 16 standards covering strategy, planning, resources, communication and quality.
  • Domain V, Performing Internal Audit Services. Principles 13 to 15, 14 standards covering engagement planning, fieldwork, communicating results and follow-up.

What changed from the 2017 IPPF

The 2017 framework split its standards into Attribute (1000 series) and Performance (2000 series) standards, with the Core Principles, the Definition and the Code of Ethics as separate mandatory elements. The Global Internal Audit Standards fold all of that into one principle-based structure. Several requirements are genuinely new rather than reorganised.

Essential Conditions for the board and senior management

Each of the nine Domain III standards carries a set of Essential Conditions: things the board and senior management are expected to do so that internal audit can work. Examples include approving the charter and plan, establishing a direct reporting line, and authorising the CAE’s appointment and removal. The CAE must walk the board and senior management through Domain III. If they decline a condition, the CAE has to explain the consequences with examples, and where all parties agree a condition is not needed, record why and what compensates for it.

A written internal audit strategy (Standard 9.2)

The function now needs its own strategy with a vision, strategic objectives and supporting initiatives, aligned to what the organisation and the board expect, and reviewed periodically with the board and senior management.

Performance measurement (Standard 12.2)

The CAE must set performance objectives informed by the board and senior management, build a methodology to measure progress, seek their feedback, and act on what it shows through an action plan. Under 8.3, the board approves those objectives at least annually.

Technological resources (Standard 10.3)

Technology is a standalone requirement. The CAE must keep the function’s tools under regular evaluation, train auditors when new tools arrive, work with IT and information security on implementation, and tell the board and senior management where technology gaps are holding the function back.

Topical Requirements and a CIA on the EQA team

Topical Requirements set a minimum baseline for auditing specific risk subjects; four have been issued so far. The external quality assessment cadence stays at least once every five years, but Standard 8.4 now requires at least one assessor on the team to hold an active Certified Internal Auditor designation.

2017 IPPF vs the Global Internal Audit Standards: side by side

Area 2017 IPPF 2024 Global Internal Audit Standards
Structure Attribute and Performance standards plus separate Core Principles, Definition and Code of Ethics 5 domains, 15 principles, 52 standards in one document
Board duties Requirements addressed to the CAE Essential Conditions on all nine Domain III standards
Strategy No standalone strategy standard Standard 9.2: vision, objectives, initiatives
Performance Covered through internal assessments Standard 12.2: objectives, methodology, feedback, action plan
Technology Considered under due professional care Standard 10.3: a dedicated resource requirement
Plan coverage Risk-based plan, annual risk assessment Standard 9.4 also names IT governance, fraud risk and compliance and ethics programs
Topic baselines None Mandatory Topical Requirements for assurance work
External assessment Every five years, qualified independent assessor Same cadence, plus an active CIA on the team and results sent straight to the board

How to transition to the Global Internal Audit Standards

The effective date has passed, so any unfinished transition is already overdue. A practical sequence:

  1. Run a gap assessment standard by standard. Map every existing policy, procedure and template to the 52 standards and mark each requirement as met, partly met or missing. Do not stop at the old-to-new number mapping; the new requirements above have no 2017 equivalent to map from.
  2. Hold the Domain III conversation. Take the Essential Conditions to the board and senior management, agree who does what, and record any condition they decline along with the compensating arrangement.
  3. Re-issue the charter. Standard 6.2 sets minimum contents, and 7.1 adds reporting lines and any CAE roles outside audit. Our guide to the internal audit charter walks through each element.
  4. Write the strategy and performance objectives. These may be new documents for your function, and the board’s approval of objectives is an annual cycle under 8.3.
  5. Rebuild the planning method. Check that the annual risk assessment takes board and senior management input and explicitly considers the three named coverage areas.
  6. Build Topical Requirements into planning. Every item in an applicable requirement has to be assessed for applicability, with exclusions justified in writing. See our overview of the IIA Topical Requirements for the dates and triggers.
  7. Update the quality program. Internal assessments, the five-year external assessment plan, and the CIA requirement for the assessor team all belong in it. Our piece on the quality assurance and improvement program covers how to structure it.

Where the Global Internal Audit Standards are most demanding

Reading the “must” statements in the Global Internal Audit Standards closely turns up obligations that are easy to miss inside a long standard:

  • The 12-month tail on CAE non-audit roles (7.1). If the CAE temporarily takes on a management responsibility, assurance over that area has to come from an independent third party during the assignment and for a further 12 months, and there must be a plan to hand the role back to management.
  • The 12-month look-back on objectivity (2.2). An auditor’s objectivity is presumed impaired when giving assurance over an activity they were responsible for within the past year.
  • Agreed significance criteria for errors (11.4). Whether an error in a communication is significant is judged against criteria agreed with the board, so those criteria have to exist.
  • Disagreement methods (13.1 and 14.4). Both standards expect an established way of handling disagreements with management in which each side can put its position on record.
  • Action plan detail (15.1). Final communications must name who is responsible for each action and the planned completion date.
  • Nonconformance disclosure (15.1). Where an engagement did not conform, the communication must say which standard was missed, why, and what effect that had.

Each needs a field on a form or a paragraph in a procedure.

Frequently asked questions

When did the Global Internal Audit Standards take effect?

They were issued on 9 January 2024 and became effective on 9 January 2025. From that date the 2024 edition replaced the 2017 IPPF standards as the basis for conformance.

Are the Global Internal Audit Standards free to read?

Yes. The IIA publishes the full text for public access on its complete Standards page. Some supporting tools and templates from the IIA are member resources, but the requirements themselves are open.

Can an internal audit function be certified to the Standards?

No. Individuals can hold IIA certifications such as the CIA, but a function is not certified to the Global Internal Audit Standards. Its conformance is evaluated through internal assessments and an external quality assessment at least once every five years, which can be a full external assessment or a self-assessment with independent validation.

Do small teams have to meet all the Global Internal Audit Standards?

The requirements apply regardless of size, but the Considerations for Implementation allow the approach to be scaled. A one-person function will need outside help to run its quality program, because nobody inside the team is independent of the work being assessed.

Getting the documentation in place

Conformance with the Global Internal Audit Standards is ultimately shown through documents: a charter the board approved, a strategy, a risk assessment with the board’s input visible in it, engagement records that carry the required fields, and a quality program that tests all of it.

Once the structure is clear, three practical guides follow from it: how to rate internal audit findings under Standard 14.3, and how to audit the two Topical Requirements already in force, the Cybersecurity Topical Requirement and the Third-Party Topical Requirement.

Our Internal Audit Toolkit provides 87 editable templates (60 Word, 27 Excel) built on all 52 standards and every item of the four issued Topical Requirements. For a transition, start with the 2017 IPPF to 2024 Standards Transition Gap Assessment, the Standards Conformance Register and the Roles and Essential Conditions RACI, then work through the Internal Audit Charter, Internal Audit Strategy and Performance Objectives and KPI Dashboard. It is $99, and every document is yours to adapt to your function.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.