Internal auditors reviewing audit charter and quality review checklist in an office

Internal Audit Setup Process: 10 Steps From Charter to Quality Review

An internal audit setup process should create an independent, board-authorised and risk-based function—not merely recruit auditors and issue a plan. The essential sequence is to establish organisational need, agree the mandate, approve a charter, protect independence, appoint capable leadership, understand stakeholders and risk, design the methodology, secure resources, deliver a risk-based plan and operate a quality assurance and improvement programme.

The Institute of Internal Auditors’ Global Internal Audit Standards provide the authoritative foundation. Issued in January 2024 and effective from 9 January 2025, they require the function to be authorised by the board, positioned independently, overseen by the board, strategically planned, appropriately resourced and committed to quality.

Key takeaways

  • The board should approve the internal audit mandate, charter, chief audit executive appointment and risk-based plan.
  • Functional reporting to the board is central to independence; administrative reporting should not restrict access, scope, resources or communication.
  • The audit universe and plan must start with organisational objectives and risks, not a repeatable list of departments.
  • Methodology, technology, people and reporting should be designed as one operating model.
  • Quality assurance begins at setup and continues through supervision, performance monitoring, periodic assessment and external review.

Contents

Before creating an internal audit function

Internal audit provides independent and objective assurance and advice intended to strengthen governance, risk management and control. Its exact scope should reflect the organisation’s purpose, scale, complexity, risk profile and stakeholder expectations. A new function may be prompted by board demand, regulation, rapid growth, control failures, new investment, international expansion or the need for independent assurance over transformation.

Senior management can sponsor the business case and provide resources, but the governing body must protect the function’s authority and independence. In organisations without a formal board, an equivalent oversight body should fulfil the relevant responsibilities. Legal and regulatory requirements may add sector-specific obligations, so these should be identified at the outset.

Internal audit setup process: 10 steps

1. Assess organisational need and stakeholder expectations

Begin with objectives, governance arrangements, significant decisions, regulated activities and principal sources of uncertainty. Interview board members, executives, risk and compliance leaders, external auditors and other assurance providers. Identify where decision-makers lack reliable assurance and which risks could justify independent review.

The output should be a concise needs assessment covering expected value, preliminary scope, mandatory requirements, stakeholders, likely assurance gaps and constraints. Avoid promising complete coverage: internal audit provides risk-based assurance, not a guarantee that every control or transaction is effective.

2. Establish the internal audit mandate

The mandate defines the authority, role and responsibilities granted by the board and, where relevant, legislation or regulation. It should give internal audit unrestricted ability to communicate with the board and timely access to the records, systems, property and people necessary for its work, subject to lawful confidentiality and security controls.

Clarify the balance between assurance and advisory services and the conditions under which internal audit may advise on change without assuming management responsibility. Management owns objectives, risks, controls and action plans; internal audit evaluates and advises independently.

3. Draft and approve the internal audit charter

The charter translates the mandate into a formal operating document. The IIA’s Model Internal Audit Charter guidance explains that a charter includes the mandate, organisational position, reporting relationships, scope, service types and other specifications.

A strong charter addresses purpose; authority and access; board and chief audit executive responsibilities; independence and objectivity; scope; assurance and advisory services; coordination; confidentiality; quality; and review frequency. The chief audit executive should discuss it with the board and senior management, and the board should approve it. Revisit the charter when leadership, strategy, regulation or the operating model changes.

Ten steps in the internal audit function setup process
The setup process connects mandate, people, methodology, delivery and quality.

4. Design independent reporting and board oversight

Functional reporting to the board or audit committee ordinarily includes approval of the charter, plan, budget and resource plan; appointment and removal of the chief audit executive; performance evaluation and remuneration input; private meetings; and review of impairments to independence. Administrative support may sit with a senior executive, but it must not prevent internal audit from selecting subjects, determining scope, performing work or communicating results.

Define a route for the chief audit executive to raise urgent matters directly with the board. Also establish safeguards where the role has responsibilities beyond internal audit. Independence should be reviewed at least annually and whenever a real, potential or perceived impairment arises.

5. Appoint leadership and define the competency model

Select a chief audit executive with the credibility, organisational access and professional competence to build the function. Technical audit knowledge matters, but so do strategic thinking, communication, ethical judgement, stakeholder management and the ability to challenge constructively.

Translate the anticipated audit universe into a competency matrix. Consider financial, operational, technology, cyber, data, regulatory, fraud, project and sector knowledge. Decide which capabilities must be permanent, which can be developed and which can be obtained through specialists. Job descriptions should reinforce integrity, objectivity, confidentiality, competence and due professional care.

6. Build the risk and assurance view

Map strategic objectives, processes, legal entities, programmes, systems, third parties and emerging issues into an audit universe. Assess risk using relevant impact, likelihood, velocity, control confidence and stakeholder-concern factors. Then map existing assurance from management monitoring, risk and compliance functions, external audit, regulators and specialists.

Assurance mapping prevents duplication and reveals gaps, but internal audit should test whether it can rely on another provider’s work. Scope, competence, objectivity, methodology, evidence and reporting limitations all matter. EPW’s guide to governance, risk and compliance provides useful context for integrating these roles.

7. Define strategy, methodology and engagement governance

Create an internal audit strategy aligned with organisational objectives and stakeholder expectations. Establish methodology for risk assessment, annual and dynamic planning, engagement planning, evidence, sampling, documentation, findings, supervision, communication, action monitoring and records retention.

Templates should support consistent judgement without forcing every audit into the same shape. Define how teams assess design and operating effectiveness, rate findings and residual risk, identify root causes and handle disagreement. Include protocols for investigations, advisory work, urgent reviews and reliance on data analytics or automated tools.

8. Secure resources, technology and external expertise

Prepare a resource plan that connects required coverage to people, skills, time, technology and budget. Estimate capacity realistically after allowing for training, administration, quality review and unplanned work. Explain to the board what risks will remain outside the plan if resources are insufficient.

Audit technology may support planning, workpapers, evidence, analytics, issue tracking and reporting. Tool selection should consider information security, access, retention, interoperability and data quality. Co-sourcing or specialist support can fill capability gaps, but contracts must protect independence, confidentiality, workpaper ownership and service continuity.

Internal audit functional and administrative reporting relationships
Functional reporting to the board protects independence while management enables administration and access.

9. Approve and deliver the risk-based audit plan

Turn the risk and assurance view into a prioritised plan. For each proposed engagement, state the connection to objectives and risks, indicative timing, skills and capacity. Include flexibility for emerging risks and management requests. Present assumptions, exclusions and resource limitations transparently so the board can make an informed approval decision.

Pilot engagements can test methodology, stakeholder protocols and technology before scaling. Each engagement should establish objectives, scope, criteria, work programme and evidence needs; communicate conclusions clearly; agree proportionate actions; and monitor implementation. Significant unresolved exposure should be escalated according to the charter.

10. Establish quality assurance and improvement

A quality assurance and improvement programme, or QAIP, should evaluate conformance with the Global Internal Audit Standards, achievement of performance objectives and opportunities to improve. It includes ongoing monitoring, periodic self-assessments and external quality assessment. Under the Standards, an external assessment must be performed at least once every five years by a qualified, independent assessor or assessment team.

Design quality into the function through supervision, workpaper review, stakeholder feedback, performance measures, lessons learned and root-cause analysis. The chief audit executive reports internal and external assessment results to the board and senior management and develops action plans for deficiencies. Public claims of conformance should only be made when supported by the QAIP.

Choose an appropriate delivery model

Model Advantages Points to control
In-house Organisational knowledge, continuity and direct relationships Specialist gaps, fixed capacity and career development
Co-sourced Core leadership plus flexible specialist skills Role clarity, knowledge transfer, consistency and cost
Outsourced Rapid access to a broad capability pool Board access, independence, confidentiality and organisational understanding
Hybrid or group model Shared standards with local insight Authority, legal-entity coverage and cross-border data

No model removes the board’s oversight responsibility. The organisation still needs an accountable chief audit executive or equivalent leadership arrangement, a board-approved mandate and effective quality oversight. Independence threats and conflicts must be assessed, especially when a provider also supplies other services.

Common internal audit setup mistakes

  • Starting with an annual calendar: a list of departments is not a risk-based plan.
  • Using a generic charter: copied wording may not reflect legal structure, access or reporting reality.
  • Placing the function too low: limited status can inhibit access and challenge.
  • Confusing ownership and assurance: internal audit should not design, operate and then independently assure the same controls.
  • Underestimating technology risk: a function without IS audit capability may miss critical dependencies.
  • Measuring only completed audits: volume does not demonstrate coverage, quality, influence or improvement.
  • Postponing quality: weak files and inconsistent ratings become harder to correct after the function scales.

Readiness checklist for the new function

Area Minimum readiness evidence
Authority Board-approved mandate and charter
Independence Functional reporting, private access and impairment safeguards
Leadership Appointed chief audit executive and approved responsibilities
Risk basis Audit universe, risk assessment and assurance map
Delivery Methodology, templates, technology and records controls
Resources Competency matrix, capacity analysis, budget and specialist plan
Plan Board-approved risk-based plan with assumptions and exclusions
Quality QAIP design, measures, assessment timetable and reporting route

Early performance measures should balance delivery and value: priority-risk coverage, plan responsiveness, cycle time, stakeholder feedback, repeat findings, overdue high-risk actions, quality-review results and staff capability. Targets should not encourage superficial work or suppression of difficult findings.

Further professional development is available through EPW’s Auditing, Governance, and Risk Compliance training portfolio.

Develop an effective internal audit operating model with EPW

EPW’s five-day Internal Audit Function Setup and Optimization Course provides a practical roadmap for establishing and improving an internal audit function. It covers audit fundamentals, organisational needs and scope, team structure, charters and policies, resources and budgeting, stakeholder relationships, risk-based planning, evidence, reporting, data analytics, workflow improvement, performance measurement, quality assurance, independence and long-term capability.

The course is suitable for current or prospective heads of internal audit, audit managers, governance and risk professionals, and leaders responsible for creating or strengthening an assurance function. Participants can use the course to test their operating model, identify priority gaps and plan sustainable improvements.

Frequently asked questions

Who approves the internal audit charter?

The governing body or its delegated audit committee should approve the charter. The chief audit executive discusses it with the board and senior management and reviews it when circumstances change.

Can internal audit be fully outsourced?

Yes, where law and regulation permit, but outsourcing does not remove governance responsibilities. The board must protect authority, independence, access, competence, confidentiality, quality and direct communication.

When should the first external quality assessment occur?

The Standards require an external quality assessment at least once every five years. A new function should plan for it from the start while using ongoing monitoring and periodic self-assessment to identify issues earlier.

References