An internal audit charter is the formal document, approved by the board, that sets out what internal audit is for, what it may look at, who it reports to, and what the board and management have agreed to do in support. Under the Global Internal Audit Standards it is not a formality to file and forget. Standard 6.2 fixes its minimum contents, Standard 6.1 requires it to carry the mandate, and Standard 7.1 requires it to record reporting lines and any roles the chief audit executive holds outside audit.
This guide covers each required element, the board’s side of the arrangement, and the review triggers.
What this guide covers
- What the internal audit charter must contain (Standard 6.2)
- The mandate inside the internal audit charter (Standard 6.1)
- Reporting lines and independence in the internal audit charter (Standard 7.1)
- CAE non-audit roles and the 12-month tail
- What the board commits to: the Essential Conditions
- Internal audit charter elements and gaps to check
- When to review the internal audit charter
- Frequently asked questions

What the internal audit charter must contain (Standard 6.2)
The chief audit executive (CAE) is responsible for drafting and maintaining the charter. At a minimum, Standard 6.2 requires it to cover four things:
- The Purpose of Internal Auditing, as set out in Domain I of the Standards.
- A commitment to conform with the Global Internal Audit Standards.
- The mandate, including the scope of internal audit, the types of service it provides, and what the board expects in terms of management’s support for the function.
- The function’s organisational position and reporting relationships.
Before the board approves it, the CAE must talk the draft through with the board and senior management so that both confirm it matches how they understand the function and what they expect from it. That conversation is itself evidence: the minutes of the meeting where the charter was discussed and approved, and the approval date, are what an assessor will look for.
Beyond the minimum, the implementation guidance suggests the internal audit charter also describe administrative arrangements: who approves the function’s budget and HR matters, who signs off the CAE’s expenses, and who reviews the CAE’s performance. It lists further topics worth including, such as independence safeguards, rights of access to records, people and premises, how and when results are communicated, how disagreements with management are handled, and the quality program.
The mandate inside the internal audit charter (Standard 6.1)
The mandate is the function’s authority, role and responsibilities. Standard 6.1 puts the CAE in an advisory position: the CAE supplies the information the board and senior management need, and the board establishes the mandate. The CAE must then document the mandate in the internal audit charter, or reference where it is documented.
Three points in 6.1 shape what the charter says:
- Legal mandates. Where a law or regulation prescribes all or part of the mandate, the statutory terms have to appear in the internal audit charter.
- Coordination first. To help the board decide scope and service types, the CAE must work with the organisation’s other assurance providers, inside and outside it, so roles are understood before the mandate is fixed.
- Scope precision. Scope can be the whole organisation or a defined part of it, and it can restrict the nature of services, for example assurance only. Whatever the board decides, write it down plainly.
Reporting lines and independence in the internal audit charter (Standard 7.1)
Standard 7.1 requires the CAE to record in the charter the reporting relationships and organisational positioning that the board has determined. The guidance treats a functional reporting line to the board as the most effective arrangement, and calls an administrative line to the chief executive or equivalent leading practice, because it gives the CAE the standing to challenge senior management.
The same standard adds three duties that touch the charter directly:
- Annual confirmation. The CAE must confirm the function’s organisational independence to the board at least once a year, including any incidents where it may have been impaired and what was done about them.
- Structural limits. If the governing structure does not support independence, the CAE must document what limits it and the safeguards in place.
- Discussion of risky roles. Any current or proposed role that could impair independence, in fact or in appearance, must be discussed with the board and senior management, along with suitable safeguards.
CAE non-audit roles and the 12-month tail
CAEs are sometimes asked to run risk management, compliance or a similar function. The Standards permit this, but the internal audit charter has to reflect it.
For an ongoing non-audit role, the charter must document the responsibilities, the nature of the work and the safeguards. If the area is itself subject to internal audit, a separate route to assurance is needed, such as a competent external provider that reports to the board independently.
For a temporary non-audit role, assurance over the area must come from an independent third party both during the assignment and for the following 12 months, and the CAE must set up a plan to hand the responsibility back to management. The 12 months run from when the temporary assignment ends. The guidance adds that the perception of impairment can last longer, so the CAE should discuss with the board whether 12 months is enough in the circumstances.
This links to the auditor-level rule in Standard 2.2: objectivity is presumed impaired if an auditor gives assurance on an activity they were responsible for within the previous 12 months.
What the board commits to: the Essential Conditions
Domain III of the Standards attaches Essential Conditions to each governance standard. These are the board’s and senior management’s side of the bargain, and they belong in, or alongside, the internal audit charter. For the charter and mandate, the board is expected to:
- Discuss with the CAE and senior management what the charter should cover beyond the minimum.
- Approve the charter, including the mandate and the scope and types of service.
- Review the charter with the CAE when circumstances change, such as a new CAE or a shift in the type, severity or interconnection of the organisation’s risks.
- Under 7.1, set up a direct reporting line to the CAE, authorise the CAE’s appointment and removal, give input on the CAE’s performance evaluation and pay, and meet the CAE without senior management present.
- Under 6.3, approve the audit plan, budget and resource plan, and work with senior management so internal audit has unrestricted access to data, records, people and property.
Senior management’s conditions run in parallel: feed expectations into the charter, support the mandate across the organisation, and position the function so it can work without interference.
If the board or senior management decline a condition, the CAE must explain with examples how its absence affects the function. Where they agree a condition is unnecessary, the CAE documents the reasons and the compensating arrangements. Recording that agreement alongside the charter keeps the evidence in one place for the next quality assurance and improvement program review.
Internal audit charter elements and gaps to check
| Charter element | Standard | Gap to watch for |
|---|---|---|
| Purpose of Internal Auditing | 6.2 | Charter still carries the 2017 mission or definition wording |
| Commitment to the Standards | 6.2 | Refers to the IPPF generally, or to the 2017 Standards |
| Mandate, scope and service types | 6.1, 6.2 | Statutory mandate not reflected; scope limits not written down |
| Board expectations of management support | 6.2 | Silent on what management owes the function |
| Reporting lines and positioning | 7.1 | Administrative line described, functional line to the board missing |
| Ongoing CAE non-audit roles | 7.1 | Role mentioned but no safeguards or alternative assurance route |
| Temporary CAE non-audit roles | 7.1 | No 12-month independent assurance tail or handover plan |
| Access rights | 6.3 (guidance in 6.2) | Access to records named, but not people or premises |
| Review arrangements | 6.1, 6.2 | No agreed review frequency or list of trigger events |
When to review the internal audit charter
Standard 6.1 requires the CAE to assess periodically whether circumstances justify a fresh discussion of the mandate with the board and senior management, and to hold that discussion if they do. The guidance names the events that may justify it:
- A notable change in the Standards themselves.
- A significant acquisition or reorganisation.
- Significant changes in the board or senior management.
- Significant changes in strategy, objectives, risk profile or operating environment.
- New laws or regulations affecting the nature or scope of internal audit.
The guidance also says the CAE should formally consider such changes at least once a year, and that the CAE and the board should agree how often the charter is reviewed and reaffirmed. The move from the 2017 IPPF to the Global Internal Audit Standards is the first trigger on that list: a charter written under the 2017 framework lacks the commitment Standard 6.2 now requires, so it needs revising and re-approving.
A charter review is also the natural moment to revisit the annual planning cycle; our guide to the risk based internal audit plan covers how the mandate feeds the plan.
Frequently asked questions
Who approves the internal audit charter?
The board, or a committee such as the audit committee where the board has delegated that oversight. The CAE drafts it and discusses it with the board and senior management first. The IIA’s Standards page publishes the full requirements.
Can a law replace the internal audit charter?
The implementation guidance allows it where laws or regulations cover the charter requirements comprehensively. Where they cover only part, the charter carries the statutory terms and fills the rest.
Does the internal audit charter need to mention the CAE’s other roles?
Yes, for ongoing roles: the responsibilities, nature of work and safeguards must be documented in it. Temporary roles bring the 12-month independent assurance requirement and a handover plan.
How often should the internal audit charter be updated?
The Standards do not fix a frequency. The CAE and the board agree one, the CAE considers trigger events at least annually, and the charter is revised whenever one of them occurs.
Our Internal Audit Toolkit provides 87 editable templates built on the Global Internal Audit Standards. For the charter and its governance surround, it includes the Internal Audit Charter, an Internal Audit Charter – Public Sector version for statutory mandates, the Internal Audit Mandate Paper, the Audit Committee Terms of Reference – Internal Audit Provisions, the Roles and Essential Conditions RACI, the Organizational Independence Annual Confirmation, and the CAE Role Profile, Appointment and Removal Procedure. It is $99.