AI-generated illustration created to represent the article’s subject. It does not depict an actual EPW course, trainer, participant, client, event or venue.
An internal audit setup process should create an independent, board-authorised and risk-based function—not merely recruit auditors and issue a plan. The essential sequence is to establish organisational need, agree the mandate, approve a charter, protect independence, appoint capable leadership, understand stakeholders and risk, design the methodology, secure resources, deliver a risk-based plan and operate a quality assurance and improvement programme.
The Institute of Internal Auditors’ Global Internal Audit Standards provide the authoritative foundation. Issued in January 2024 and effective from 9 January 2025, they require the function to be authorised by the board, positioned independently, overseen by the board, strategically planned, appropriately resourced and committed to quality.
Key takeaways
- The board should approve the internal audit mandate, charter, chief audit executive appointment and risk-based plan.
- Functional reporting to the board is central to independence; administrative reporting should not restrict access, scope, resources or communication.
- The audit universe and plan must start with organisational objectives and risks, not a repeatable list of departments.
- Methodology, technology, people and reporting should be designed as one operating model.
- Quality assurance begins at setup and continues through supervision, performance monitoring, periodic assessment and external review.
Contents
- Before creating the function
- The 10-step setup process
- In-house, co-sourced or outsourced
- Common setup mistakes
- Evidence that the function is ready
- Develop the operating model with EPW
Before creating an internal audit function
Internal audit provides independent and objective assurance and advice intended to strengthen governance, risk management and control. Its exact scope should reflect the organisation’s purpose, scale, complexity, risk profile and stakeholder expectations. A new function may be prompted by board demand, regulation, rapid growth, control failures, new investment, international expansion or the need for independent assurance over transformation.
Senior management can sponsor the business case and provide resources, but the governing body must protect the function’s authority and independence. In organisations without a formal board, an equivalent oversight body should fulfil the relevant responsibilities. Legal and regulatory requirements may add sector-specific obligations, so these should be identified at the outset.
Internal audit setup process: 10 steps
1. Assess organisational need and stakeholder expectations
Begin with objectives, governance arrangements, significant decisions, regulated activities and principal sources of uncertainty. Interview board members, executives, risk and compliance leaders, external auditors and other assurance providers. Identify where decision-makers lack reliable assurance and which risks could justify independent review.
The output should be a concise needs assessment covering expected value, preliminary scope, mandatory requirements, stakeholders, likely assurance gaps and constraints. Avoid promising complete coverage: internal audit provides risk-based assurance, not a guarantee that every control or transaction is effective.
2. Establish the internal audit mandate
The mandate defines the authority, role and responsibilities granted by the board and, where relevant, legislation or regulation. It should give internal audit unrestricted ability to communicate with the board and timely access to the records, systems, property and people necessary for its work, subject to lawful confidentiality and security controls.
Clarify the balance between assurance and advisory services and the conditions under which internal audit may advise on change without assuming management responsibility. Management owns objectives, risks, controls and action plans; internal audit evaluates and advises independently.
3. Draft and approve the internal audit charter
The charter translates the mandate into a formal operating document. The IIA’s Model Internal Audit Charter guidance explains that a charter includes the mandate, organisational position, reporting relationships, scope, service types and other specifications.
A strong charter addresses purpose; authority and access; board and chief audit executive responsibilities; independence and objectivity; scope; assurance and advisory services; coordination; confidentiality; quality; and review frequency. The chief audit executive should discuss it with the board and senior management, and the board should approve it. Revisit the charter when leadership, strategy, regulation or the operating model changes.

4. Design independent reporting and board oversight
Functional reporting to the board or audit committee ordinarily includes approval of the charter, plan, budget and resource plan; appointment and removal of the chief audit executive; performance evaluation and remuneration input; private meetings; and review of impairments to independence. Administrative support may sit with a senior executive, but it must not prevent internal audit from selecting subjects, determining scope, performing work or communicating results.
Define a route for the chief audit executive to raise urgent matters directly with the board. Also establish safeguards where the role has responsibilities beyond internal audit. Independence should be reviewed at least annually and whenever a real, potential or perceived impairment arises.
5. Appoint leadership and define the competency model
Select a chief audit executive with the credibility, organisational access and professional competence to build the function. Technical audit knowledge matters, but so do strategic thinking, communication, ethical judgement, stakeholder management and the ability to challenge constructively.
Translate the anticipated audit universe into a competency matrix. Consider financial, operational, technology, cyber, data, regulatory, fraud, project and sector knowledge. Decide which capabilities must be permanent, which can be developed and which can be obtained through specialists. Job descriptions should reinforce integrity, objectivity, confidentiality, competence and due professional care.
6. Build the risk and assurance view
Map strategic objectives, processes, legal entities, programmes, systems, third parties and emerging issues into an audit universe. Assess risk using relevant impact, likelihood, velocity, control confidence and stakeholder-concern factors. Then map existing assurance from management monitoring, risk and compliance functions, external audit, regulators and specialists.
Assurance mapping prevents duplication and reveals gaps, but internal audit should test whether it can rely on another provider’s work. Scope, competence, objectivity, methodology, evidence and reporting limitations all matter. EPW’s guide to governance, risk and compliance provides useful context for integrating these roles.
7. Define strategy, methodology and engagement governance
Create an internal audit strategy aligned with organisational objectives and stakeholder expectations. Establish methodology for risk assessment, annual and dynamic planning, engagement planning, evidence, sampling, documentation, findings, supervision, communication, action monitoring and records retention.
Templates should support consistent judgement without forcing every audit into the same shape. Define how teams assess design and operating effectiveness, rate findings and residual risk, identify root causes and handle disagreement. Include protocols for investigations, advisory work, urgent reviews and reliance on data analytics or automated tools.
8. Secure resources, technology and external expertise
Prepare a resource plan that connects required coverage to people, skills, time, technology and budget. Estimate capacity realistically after allowing for training, administration, quality review and unplanned work. Explain to the board what risks will remain outside the plan if resources are insufficient.
Audit technology may support planning, workpapers, evidence, analytics, issue tracking and reporting. Tool selection should consider information security, access, retention, interoperability and data quality. Co-sourcing or specialist support can fill capability gaps, but contracts must protect independence, confidentiality, workpaper ownership and service continuity.

9. Approve and deliver the risk-based audit plan
Turn the risk and assurance view into a prioritised plan. For each proposed engagement, state the connection to objectives and risks, indicative timing, skills and capacity. Include flexibility for emerging risks and management requests. Present assumptions, exclusions and resource limitations transparently so the board can make an informed approval decision.
Pilot engagements can test methodology, stakeholder protocols and technology before scaling. Each engagement should establish objectives, scope, criteria, work programme and evidence needs; communicate conclusions clearly; agree proportionate actions; and monitor implementation. Significant unresolved exposure should be escalated according to the charter.
10. Establish quality assurance and improvement
A quality assurance and improvement programme, or QAIP, should evaluate conformance with the Global Internal Audit Standards, achievement of performance objectives and opportunities to improve. It includes ongoing monitoring, periodic self-assessments and external quality assessment. Under the Standards, an external assessment must be performed at least once every five years by a qualified, independent assessor or assessment team.
Design quality into the function through supervision, workpaper review, stakeholder feedback, performance measures, lessons learned and root-cause analysis. The chief audit executive reports internal and external assessment results to the board and senior management and develops action plans for deficiencies. Public claims of conformance should only be made when supported by the QAIP.
Choose an appropriate delivery model
| Model | Advantages | Points to control |
|---|---|---|
| In-house | Organisational knowledge, continuity and direct relationships | Specialist gaps, fixed capacity and career development |
| Co-sourced | Core leadership plus flexible specialist skills | Role clarity, knowledge transfer, consistency and cost |
| Outsourced | Rapid access to a broad capability pool | Board access, independence, confidentiality and organisational understanding |
| Hybrid or group model | Shared standards with local insight | Authority, legal-entity coverage and cross-border data |
No model removes the board’s oversight responsibility. The organisation still needs an accountable chief audit executive or equivalent leadership arrangement, a board-approved mandate and effective quality oversight. Independence threats and conflicts must be assessed, especially when a provider also supplies other services.
Common internal audit setup mistakes
- Starting with an annual calendar: a list of departments is not a risk-based plan.
- Using a generic charter: copied wording may not reflect legal structure, access or reporting reality.
- Placing the function too low: limited status can inhibit access and challenge.
- Confusing ownership and assurance: internal audit should not design, operate and then independently assure the same controls.
- Underestimating technology risk: a function without IS audit capability may miss critical dependencies.
- Measuring only completed audits: volume does not demonstrate coverage, quality, influence or improvement.
- Postponing quality: weak files and inconsistent ratings become harder to correct after the function scales.
Readiness checklist for the new function
| Area | Minimum readiness evidence |
|---|---|
| Authority | Board-approved mandate and charter |
| Independence | Functional reporting, private access and impairment safeguards |
| Leadership | Appointed chief audit executive and approved responsibilities |
| Risk basis | Audit universe, risk assessment and assurance map |
| Delivery | Methodology, templates, technology and records controls |
| Resources | Competency matrix, capacity analysis, budget and specialist plan |
| Plan | Board-approved risk-based plan with assumptions and exclusions |
| Quality | QAIP design, measures, assessment timetable and reporting route |
Early performance measures should balance delivery and value: priority-risk coverage, plan responsiveness, cycle time, stakeholder feedback, repeat findings, overdue high-risk actions, quality-review results and staff capability. Targets should not encourage superficial work or suppression of difficult findings.
Further professional development is available through EPW’s Auditing, Governance, and Risk Compliance training portfolio.
Develop an effective internal audit operating model with EPW
EPW’s five-day Internal Audit Function Setup and Optimization Course provides a practical roadmap for establishing and improving an internal audit function. It covers audit fundamentals, organisational needs and scope, team structure, charters and policies, resources and budgeting, stakeholder relationships, risk-based planning, evidence, reporting, data analytics, workflow improvement, performance measurement, quality assurance, independence and long-term capability.
The course is suitable for current or prospective heads of internal audit, audit managers, governance and risk professionals, and leaders responsible for creating or strengthening an assurance function. Participants can use the course to test their operating model, identify priority gaps and plan sustainable improvements.
Frequently asked questions
Who approves the internal audit charter?
The governing body or its delegated audit committee should approve the charter. The chief audit executive discusses it with the board and senior management and reviews it when circumstances change.
Can internal audit be fully outsourced?
Yes, where law and regulation permit, but outsourcing does not remove governance responsibilities. The board must protect authority, independence, access, competence, confidentiality, quality and direct communication.
When should the first external quality assessment occur?
The Standards require an external quality assessment at least once every five years. A new function should plan for it from the start while using ongoing monitoring and periodic self-assessment to identify issues earlier.
References
- The Institute of Internal Auditors, Global Internal Audit Standards, 2024 edition.
- The Institute of Internal Auditors, Complete Global Internal Audit Standards.
- The Institute of Internal Auditors, Model Internal Audit Charter Tool and User’s Guide.
- The Institute of Internal Auditors, Quality Assurance services and QAIP guidance.
- OECD, G20/OECD Principles of Corporate Governance 2023.
