Description
The Internal Audit Toolkit is built on the Standards’ own structure
The IIA’s Global Internal Audit Standards took effect on 9 January 2025 and replaced the 2017 International Professional Practices Framework. They are organised in five domains, fifteen principles and 52 standards, and they added things the 2017 framework did not have: board and senior-management Essential Conditions, an internal audit strategy, formal performance measurement, and mandatory Topical Requirements.
The Internal Audit Toolkit follows that structure rather than a generic audit-manual template. Its sections are the Standards’ domains, so the pack is laid out the way an external quality assessor works through it. 87 editable templates: 60 Word documents and 27 Excel workbooks, in eight sections.
Every Word document opens with a Requirements addressed table naming the standards — or the Topical Requirement items — it answers, and the clause of the document that answers each one. The pack is built from a single register, and the build fails if any of the 52 standards or any Topical Requirement item is left without a document that answers it. That is a check we run, not a claim we make.
All four Topical Requirements, item by item
Topical Requirements are mandatory when internal audit gives assurance on the topic. The IIA requires the function to record, for every item, whether it applies — and to write down why for every item it excludes. Assessors check this item by item.
| Topical Requirement | Effective | In the Internal Audit Toolkit |
|---|---|---|
| Cybersecurity | 5 February 2026 | Audit program and testing workbook, every item |
| Third-Party | 15 September 2026 | Audit program and testing workbook, every item, including downstream parties |
| Organizational Behavior | 15 December 2026 | Audit program, testing workbook and a culture and behaviour survey |
| Organizational Resilience | 30 April 2027 | Audit program and testing workbook, every item |
An applicability and exclusions workbook comes pre-loaded with all 69 items across the four, with a live check that counts any exclusion recorded without a rationale. It must read zero before an assessment.
The board’s part, written down
Nine of the Domain III standards list duties for the board and senior management — the Essential Conditions. They are not the chief audit executive’s to perform, but the chief audit executive must discuss them with the board, and where a condition is agreed to be unnecessary, record why and what compensates for it.
Most charter templates stop at the charter. The Internal Audit Toolkit carries the board’s commitments in the charter the board approves, an audit committee terms of reference, a roles and Essential Conditions RACI with an agreement record for any condition the board decides it does not need, and a board oversight self-assessment.
Workbooks that arrive filled in
The Internal Audit Toolkit workbooks are not blank grids:
| Workbook | What it holds on arrival |
|---|---|
| Standards Conformance Register | All 52 standards and all 69 Topical Requirement items, each with the toolkit document that answers it and the evidence an assessor typically looks for |
| Periodic Conformance Self-Assessment | All 52 standards ready to score, with live summaries by principle and an action plan |
| 2017 IPPF to 2024 Transition Gap Assessment | Every standard, with its 2017 reference and the main changes noted, ready for your current-state and gap columns |
| Topical Requirements Applicability | All 69 items, with the exclusion-rationale check |
| Four Topical Requirement testing workbooks | Every item of each Topical Requirement, ready for procedures, evidence and results |
| Annual Risk Assessment and Audit Universe | A weighted scoring model with formulas, coverage flags for IT governance, fraud risk and compliance and ethics, and a starter universe |
| Performance Objectives and KPI Dashboard | A starter set of objectives and KPIs with RAG status calculated |
Summaries use live formulas, so they are right the moment the data is. Worked example rows are shown in grey and are never counted in the totals.
From engagement notice to follow-up
Section 04 runs the whole engagement: notification letter, planning memorandum with the engagement risk assessment, evaluation criteria guide, risk and control matrix, work program, information request list, walkthrough narrative, sampling workbook, test of controls workpaper, finding sheet, a likelihood-and-impact finding rating scale, recommendations and action plans, conclusion guide, closing meeting record, the final report for assurance and for advisory work, an action tracker and a follow-up procedure.
One worked example runs through them, so you can see how a finding moves from the risk and control matrix to the report and into follow-up.
Written for real functions
- Small and one-person functions. The Standards apply in full whatever the size of the function. The documents say how to meet them with a peer reviewer, a co-source provider or an external reviewer, and the quality program says plainly that a one-person function needs help from outside.
- The public sector. A separate charter for mandates set in law, and an implementation guide for the Standards’ public-sector chapter.
- The conformance statement. The pack controls when a report may say the work conformed with the Standards — only where supervision and the quality program support it — and how to disclose a nonconformance when they do not.
- Transition from 2017. If your manual was written for the 2017 framework, the transition workbook takes you standard by standard to the 2024 structure.
Where the Internal Audit Toolkit sits in the catalogue
The Topical Requirements reach into areas the rest of the catalogue covers in depth. The TPRM Toolkit is the third-party programme the Third-Party Topical Requirement audits. The ISO 22301 Toolkit is the continuity programme behind Organizational Resilience, and the ISO 27001 Toolkit and NIST CSF Toolkit are what the Cybersecurity audit tests against. For control frameworks, see the SOX Toolkit, COSO Toolkit and COBIT 2019 Toolkit.
Honest about the boundaries
- This pack is not published, affiliated with or endorsed by The Institute of Internal Auditors (the IIA). The IIA owns the trademarks “Global Internal Audit Standards” and “CIA”; we use them only to say what the pack is aligned to.
- It does not reproduce the IIA’s text. Requirement descriptions are our own summaries, written to help you navigate. Read the Standards and Topical Requirements themselves — the IIA publishes them free at theiia.org.
- Templates are not conformance. Conformance is shown by operating the function and is assessed by an independent external quality assessment at least once every five years. The pack gives you the documents, registers and evidence trail that assessment looks for.
- Topical Requirements keep coming. The pack covers the four issued by October 2026. Check theiia.org for any issued since.
What you get in the Internal Audit Toolkit
The Internal Audit Toolkit is 60 Word documents and 27 Excel workbooks.
| # | Section | Documents |
|---|---|---|
| 00 | Start Here | 4 |
| 01 | Ethics and Professionalism | 13 |
| 02 | Governing the Internal Audit Function | 12 |
| 03 | Managing the Internal Audit Function | 23 |
| 04 | Performing Internal Audit Services | 21 |
| 05 | Public Sector Application | 1 |
| 06 | Topical Requirements | 10 |
| 07 | Plan Coverage Audit Programs | 3 |
List of documents
00 Start Here
- Toolkit Guide and Implementation Roadmap
- Standards Conformance Register (Excel)
- 2017 IPPF to 2024 Standards Transition Gap Assessment (Excel)
- Roles and Essential Conditions RACI (Excel)
01 Ethics and Professionalism
- Internal Audit Code of Conduct
- Ethical Concerns Escalation Procedure
- Annual Ethics and Objectivity Declaration
- Objectivity Safeguards Policy
- Conflicts and Impairments Register (Excel)
- Impairment Disclosure Form
- Competency Framework and Skills Matrix (Excel)
- CPD Policy
- CPD Log (Excel)
- Conformance Statement and Nonconformance Disclosure Procedure
- Due Professional Care and Professional Skepticism Guide
- Information Handling and Confidentiality Procedure
- Confidentiality Undertaking
02 Governing the Internal Audit Function
- Internal Audit Mandate Paper
- Internal Audit Charter
- Internal Audit Charter – Public Sector
- Audit Committee Terms of Reference – Internal Audit Provisions
- Board and Senior Management Support Protocol
- Organizational Independence Annual Confirmation
- CAE Role Profile, Appointment and Removal Procedure
- Board Interaction Calendar (Excel)
- Resource Sufficiency Assessment
- Quality Assurance and Improvement Program Manual
- External Quality Assessment Plan and Assessor Selection
- Board Oversight Self-Assessment (Excel)
03 Managing the Internal Audit Function
- Governance, Risk and Control Understanding Assessment
- Internal Audit Strategy
- Internal Audit Methodology Manual
- Audit Universe (Excel)
- Annual Risk Assessment Workbook (Excel)
- Risk-Based Internal Audit Plan
- Internal Audit Plan Schedule and Change Log (Excel)
- Assurance Map (Excel)
- Reliance on Other Assurance Providers Assessment
- Internal Audit Budget (Excel)
- Resourcing, Co-Sourcing and Talent Plan
- Technology, Data Analytics and AI Use Plan
- Stakeholder Engagement Plan
- Report Writing Style Guide
- Periodic Board Report
- Overall Opinion and Thematic Conclusions Procedure
- Errors and Omissions Correction Procedure
- Risk Acceptance Escalation Procedure and Form
- Internal Quality Assessment Procedure
- Periodic Conformance Self-Assessment Workbook (Excel)
- Performance Objectives and KPI Dashboard (Excel)
- Post-Engagement Stakeholder Survey
- Engagement Supervision and Review Checklist
04 Performing Internal Audit Services
- Engagement Notification Letter
- Engagement Planning Memorandum
- Engagement Risk and Control Matrix (Excel)
- Evaluation Criteria Selection Guide
- Engagement Budget and Resource Plan (Excel)
- Work Program
- Advisory Engagement Terms of Reference
- Information Request List (Excel)
- Process Walkthrough Narrative
- Sampling Methodology and Sample Selection Workbook (Excel)
- Test of Controls Workpaper (Excel)
- Finding Sheet
- Finding Significance Rating Scale
- Recommendations and Management Action Plan
- Engagement Conclusion and Rating Guide
- Workpaper Standards and Retention Procedure
- Closing Meeting Agenda and Record
- Final Audit Report – Assurance
- Advisory Engagement Report
- Action Tracking Register (Excel)
- Follow-Up Validation Procedure
05 Public Sector Application
- Applying the Standards in the Public Sector – Implementation Guide
06 Topical Requirements
- Topical Requirements Applicability and Exclusions Assessment (Excel)
- Cybersecurity Audit Program
- Cybersecurity Requirement Testing Workbook (Excel)
- Third-Party Audit Program
- Third-Party Requirement Testing Workbook (Excel)
- Organizational Behavior Audit Program
- Organizational Behavior Requirement Testing Workbook (Excel)
- Culture and Behavior Survey (Excel)
- Organizational Resilience Audit Program
- Organizational Resilience Requirement Testing Workbook (Excel)
07 Plan Coverage Audit Programs
- Fraud Risk Audit Program
- IT Governance Audit Program
- Compliance and Ethics Program Audit Program
Frequently Asked Questions (FAQ)
What is the Internal Audit Toolkit?
The Internal Audit Toolkit is a set of 87 editable Microsoft Word and Excel templates for running an internal audit function under the IIA’s Global Internal Audit Standards (2024). It covers all 52 standards and every item of the four issued Topical Requirements, from the charter and audit plan to engagement working papers, reporting, follow-up and the quality assurance and improvement program.
Do I need to buy the Standards as well?
No. The IIA publishes the Global Internal Audit Standards and the Topical Requirements free on theiia.org. The toolkit cites standard numbers and Topical Requirement item identifiers and describes each requirement in our own words, so you can use it alongside the IIA’s documents.
Which edition does it follow?
The Global Internal Audit Standards, 2024 edition, effective 9 January 2025, and the Cybersecurity, Third-Party, Organizational Behavior and Organizational Resilience Topical Requirements. It is not built on the 2017 IPPF, though it includes a workbook for moving from it.
Will this make our function conform to the Standards?
No set of templates can. Conformance depends on how the function actually operates and is assessed by an independent external quality assessment. What the toolkit gives you is the documented charter, methodology, plans, working papers and quality program an assessor expects to see, a self-assessment workbook already loaded with every standard, and a register of where your evidence lives.
Is it suitable for a small internal audit team?
Yes. Documents that assume separate people for doing and reviewing work explain how a small or one-person function meets the same requirement — through a peer from another assurance team, a co-source provider or an external reviewer.
Does it cover the public sector?
Yes. There is a separate charter for functions whose mandate is set in legislation and an implementation guide for applying the Standards in government settings.
What formats are the documents in?
Microsoft Word (.docx) and Microsoft Excel (.xlsx) — 60 and 27 respectively. Every file is editable and unprotected. Workbooks carry drop-down validation, frozen headers, filters, live summary formulas and worked example rows flagged for deletion.
Guides for the Internal Audit Toolkit
Free articles that explain the requirements this toolkit covers.
- Internal Audit Findings Rating Scale: Examples and Template
- Cybersecurity Topical Requirement: How to Audit It in 2026
- Quality Assurance and Improvement Program (QAIP): 2026 Guide
- Risk Based Internal Audit Plan: A Step-by-Step 2026 Guide
- Internal Audit Charter: What It Must Contain in 2026
- IIA Topical Requirements: The Complete 2026 Guide
- Global Internal Audit Standards: The Complete 2026 Guide





































Reviews
There are no reviews yet