{"id":2465,"date":"2026-09-09T14:09:35","date_gmt":"2026-09-09T14:09:35","guid":{"rendered":"https:\/\/www.epw.com\/blog\/?p=2465"},"modified":"2026-09-13T08:34:18","modified_gmt":"2026-09-13T08:34:18","slug":"internal-audit-setup-process","status":"publish","type":"post","link":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process","title":{"rendered":"Internal Audit Setup Process: 10 Steps From Charter to Quality Review"},"content":{"rendered":"<p class=\"epw-featured-image-caption\"><em>AI-generated illustration created to represent the article\u2019s subject. It does not depict an actual EPW course, trainer, participant, client, event or venue.<\/em><\/p>\n<p><strong>An internal audit setup process should create an independent, board-authorised and risk-based function\u2014not merely recruit auditors and issue a plan.<\/strong> The essential sequence is to establish organisational need, agree the mandate, approve a charter, protect independence, appoint capable leadership, understand stakeholders and risk, design the methodology, secure resources, deliver a risk-based plan and operate a quality assurance and improvement programme.<\/p>\n<p>The <a href=\"https:\/\/www.theiia.org\/en\/standards\/2024-standards\/global-internal-audit-standards\/\">Institute of Internal Auditors\u2019 Global Internal Audit Standards<\/a> provide the authoritative foundation. Issued in January 2024 and effective from 9 January 2025, they require the function to be authorised by the board, positioned independently, overseen by the board, strategically planned, appropriately resourced and committed to quality.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd0808;color:#dd0808\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd0808;color:#dd0808\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 eztoc-toggle-hide-by-default' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Key_takeaways\" >Key takeaways<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Contents\" >Contents<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Before_creating_an_internal_audit_function\" >Before creating an internal audit function<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Internal_audit_setup_process_10_steps\" >Internal audit setup process: 10 steps<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#1_Assess_organisational_need_and_stakeholder_expectations\" >1. Assess organisational need and stakeholder expectations<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#2_Establish_the_internal_audit_mandate\" >2. Establish the internal audit mandate<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#3_Draft_and_approve_the_internal_audit_charter\" >3. Draft and approve the internal audit charter<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#4_Design_independent_reporting_and_board_oversight\" >4. Design independent reporting and board oversight<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#5_Appoint_leadership_and_define_the_competency_model\" >5. Appoint leadership and define the competency model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#6_Build_the_risk_and_assurance_view\" >6. Build the risk and assurance view<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#7_Define_strategy_methodology_and_engagement_governance\" >7. Define strategy, methodology and engagement governance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#8_Secure_resources_technology_and_external_expertise\" >8. Secure resources, technology and external expertise<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#9_Approve_and_deliver_the_risk-based_audit_plan\" >9. Approve and deliver the risk-based audit plan<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#10_Establish_quality_assurance_and_improvement\" >10. Establish quality assurance and improvement<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Choose_an_appropriate_delivery_model\" >Choose an appropriate delivery model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Common_internal_audit_setup_mistakes\" >Common internal audit setup mistakes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Readiness_checklist_for_the_new_function\" >Readiness checklist for the new function<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Develop_an_effective_internal_audit_operating_model_with_EPW\" >Develop an effective internal audit operating model with EPW<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Frequently_asked_questions\" >Frequently asked questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Who_approves_the_internal_audit_charter\" >Who approves the internal audit charter?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#Can_internal_audit_be_fully_outsourced\" >Can internal audit be fully outsourced?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#When_should_the_first_external_quality_assessment_occur\" >When should the first external quality assessment occur?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\/#References\" >References<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Key_takeaways\"><\/span>Key takeaways<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>The board should approve the internal audit mandate, charter, chief audit executive appointment and risk-based plan.<\/li>\n<li>Functional reporting to the board is central to independence; administrative reporting should not restrict access, scope, resources or communication.<\/li>\n<li>The audit universe and plan must start with organisational objectives and risks, not a repeatable list of departments.<\/li>\n<li>Methodology, technology, people and reporting should be designed as one operating model.<\/li>\n<li>Quality assurance begins at setup and continues through supervision, performance monitoring, periodic assessment and external review.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Contents\"><\/span>Contents<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><a href=\"#before\">Before creating the function<\/a><\/li>\n<li><a href=\"#steps\">The 10-step setup process<\/a><\/li>\n<li><a href=\"#models\">In-house, co-sourced or outsourced<\/a><\/li>\n<li><a href=\"#pitfalls\">Common setup mistakes<\/a><\/li>\n<li><a href=\"#evidence\">Evidence that the function is ready<\/a><\/li>\n<li><a href=\"#course\">Develop the operating model with EPW<\/a><\/li>\n<\/ul>\n<h2 id=\"before\"><span class=\"ez-toc-section\" id=\"Before_creating_an_internal_audit_function\"><\/span>Before creating an internal audit function<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Internal audit provides independent and objective assurance and advice intended to strengthen governance, risk management and control. Its exact scope should reflect the organisation\u2019s purpose, scale, complexity, risk profile and stakeholder expectations. A new function may be prompted by board demand, regulation, rapid growth, control failures, new investment, international expansion or the need for independent assurance over transformation.<\/p>\n<p>Senior management can sponsor the business case and provide resources, but the governing body must protect the function\u2019s authority and independence. In organisations without a formal board, an equivalent oversight body should fulfil the relevant responsibilities. Legal and regulatory requirements may add sector-specific obligations, so these should be identified at the outset.<\/p>\n<h2 id=\"steps\"><span class=\"ez-toc-section\" id=\"Internal_audit_setup_process_10_steps\"><\/span>Internal audit setup process: 10 steps<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_Assess_organisational_need_and_stakeholder_expectations\"><\/span>1. Assess organisational need and stakeholder expectations<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Begin with objectives, governance arrangements, significant decisions, regulated activities and principal sources of uncertainty. Interview board members, executives, risk and compliance leaders, external auditors and other assurance providers. Identify where decision-makers lack reliable assurance and which risks could justify independent review.<\/p>\n<p>The output should be a concise needs assessment covering expected value, preliminary scope, mandatory requirements, stakeholders, likely assurance gaps and constraints. Avoid promising complete coverage: internal audit provides risk-based assurance, not a guarantee that every control or transaction is effective.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Establish_the_internal_audit_mandate\"><\/span>2. Establish the internal audit mandate<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The mandate defines the authority, role and responsibilities granted by the board and, where relevant, legislation or regulation. It should give internal audit unrestricted ability to communicate with the board and timely access to the records, systems, property and people necessary for its work, subject to lawful confidentiality and security controls.<\/p>\n<p>Clarify the balance between assurance and advisory services and the conditions under which internal audit may advise on change without assuming management responsibility. Management owns objectives, risks, controls and action plans; internal audit evaluates and advises independently.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_Draft_and_approve_the_internal_audit_charter\"><\/span>3. Draft and approve the internal audit charter<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The charter translates the mandate into a formal operating document. The IIA\u2019s <a href=\"https:\/\/www.theiia.org\/en\/content\/guidance\/recommended\/supplemental\/practice-guides\/model-internal-audit-activity-charter\/\">Model Internal Audit Charter guidance<\/a> explains that a charter includes the mandate, organisational position, reporting relationships, scope, service types and other specifications.<\/p>\n<p>A strong charter addresses purpose; authority and access; board and chief audit executive responsibilities; independence and objectivity; scope; assurance and advisory services; coordination; confidentiality; quality; and review frequency. The chief audit executive should discuss it with the board and senior management, and the board should approve it. Revisit the charter when leadership, strategy, regulation or the operating model changes.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"800\" src=\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps.webp\" alt=\"Ten steps in the internal audit function setup process\" class=\"wp-image-2726\" style=\"max-width:100%;height:auto\" srcset=\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps.webp 1200w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps-300x200.webp 300w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps-1024x683.webp 1024w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps-768x512.webp 768w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09135650\/epw-internal-audit-setup-10-steps-600x400.webp 600w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><figcaption>The setup process connects mandate, people, methodology, delivery and quality.<\/figcaption><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"4_Design_independent_reporting_and_board_oversight\"><\/span>4. Design independent reporting and board oversight<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Functional reporting to the board or audit committee ordinarily includes approval of the charter, plan, budget and resource plan; appointment and removal of the chief audit executive; performance evaluation and remuneration input; private meetings; and review of impairments to independence. Administrative support may sit with a senior executive, but it must not prevent internal audit from selecting subjects, determining scope, performing work or communicating results.<\/p>\n<p>Define a route for the chief audit executive to raise urgent matters directly with the board. Also establish safeguards where the role has responsibilities beyond internal audit. Independence should be reviewed at least annually and whenever a real, potential or perceived impairment arises.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_Appoint_leadership_and_define_the_competency_model\"><\/span>5. Appoint leadership and define the competency model<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Select a chief audit executive with the credibility, organisational access and professional competence to build the function. Technical audit knowledge matters, but so do strategic thinking, communication, ethical judgement, stakeholder management and the ability to challenge constructively.<\/p>\n<p>Translate the anticipated audit universe into a competency matrix. Consider financial, operational, technology, cyber, data, regulatory, fraud, project and sector knowledge. Decide which capabilities must be permanent, which can be developed and which can be obtained through specialists. Job descriptions should reinforce integrity, objectivity, confidentiality, competence and due professional care.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_Build_the_risk_and_assurance_view\"><\/span>6. Build the risk and assurance view<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Map strategic objectives, processes, legal entities, programmes, systems, third parties and emerging issues into an audit universe. Assess risk using relevant impact, likelihood, velocity, control confidence and stakeholder-concern factors. Then map existing assurance from management monitoring, risk and compliance functions, external audit, regulators and specialists.<\/p>\n<p>Assurance mapping prevents duplication and reveals gaps, but internal audit should test whether it can rely on another provider\u2019s work. Scope, competence, objectivity, methodology, evidence and reporting limitations all matter. EPW\u2019s guide to <a href=\"https:\/\/www.epw.com\/blog\/courses\/what-is-governance-risk-and-compliance\">governance, risk and compliance<\/a> provides useful context for integrating these roles.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_Define_strategy_methodology_and_engagement_governance\"><\/span>7. Define strategy, methodology and engagement governance<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Create an internal audit strategy aligned with organisational objectives and stakeholder expectations. Establish methodology for risk assessment, annual and dynamic planning, engagement planning, evidence, sampling, documentation, findings, supervision, communication, action monitoring and records retention.<\/p>\n<p>Templates should support consistent judgement without forcing every audit into the same shape. Define how teams assess design and operating effectiveness, rate findings and residual risk, identify root causes and handle disagreement. Include protocols for investigations, advisory work, urgent reviews and reliance on data analytics or automated tools.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"8_Secure_resources_technology_and_external_expertise\"><\/span>8. Secure resources, technology and external expertise<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Prepare a resource plan that connects required coverage to people, skills, time, technology and budget. Estimate capacity realistically after allowing for training, administration, quality review and unplanned work. Explain to the board what risks will remain outside the plan if resources are insufficient.<\/p>\n<p>Audit technology may support planning, workpapers, evidence, analytics, issue tracking and reporting. Tool selection should consider information security, access, retention, interoperability and data quality. Co-sourcing or specialist support can fill capability gaps, but contracts must protect independence, confidentiality, workpaper ownership and service continuity.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"800\" src=\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines.webp\" alt=\"Internal audit functional and administrative reporting relationships\" class=\"wp-image-2727\" style=\"max-width:100%;height:auto\" srcset=\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines.webp 1200w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines-300x200.webp 300w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines-1024x683.webp 1024w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines-768x512.webp 768w, https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/09140129\/epw-internal-audit-governance-reporting-lines-600x400.webp 600w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><figcaption>Functional reporting to the board protects independence while management enables administration and access.<\/figcaption><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"9_Approve_and_deliver_the_risk-based_audit_plan\"><\/span>9. Approve and deliver the risk-based audit plan<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Turn the risk and assurance view into a prioritised plan. For each proposed engagement, state the connection to objectives and risks, indicative timing, skills and capacity. Include flexibility for emerging risks and management requests. Present assumptions, exclusions and resource limitations transparently so the board can make an informed approval decision.<\/p>\n<p>Pilot engagements can test methodology, stakeholder protocols and technology before scaling. Each engagement should establish objectives, scope, criteria, work programme and evidence needs; communicate conclusions clearly; agree proportionate actions; and monitor implementation. Significant unresolved exposure should be escalated according to the charter.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"10_Establish_quality_assurance_and_improvement\"><\/span>10. Establish quality assurance and improvement<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A quality assurance and improvement programme, or QAIP, should evaluate conformance with the Global Internal Audit Standards, achievement of performance objectives and opportunities to improve. It includes ongoing monitoring, periodic self-assessments and external quality assessment. Under the Standards, an external assessment must be performed at least once every five years by a qualified, independent assessor or assessment team.<\/p>\n<p>Design quality into the function through supervision, workpaper review, stakeholder feedback, performance measures, lessons learned and root-cause analysis. The chief audit executive reports internal and external assessment results to the board and senior management and develops action plans for deficiencies. Public claims of conformance should only be made when supported by the QAIP.<\/p>\n<h2 id=\"models\"><span class=\"ez-toc-section\" id=\"Choose_an_appropriate_delivery_model\"><\/span>Choose an appropriate delivery model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th>Model<\/th>\n<th>Advantages<\/th>\n<th>Points to control<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>In-house<\/td>\n<td>Organisational knowledge, continuity and direct relationships<\/td>\n<td>Specialist gaps, fixed capacity and career development<\/td>\n<\/tr>\n<tr>\n<td>Co-sourced<\/td>\n<td>Core leadership plus flexible specialist skills<\/td>\n<td>Role clarity, knowledge transfer, consistency and cost<\/td>\n<\/tr>\n<tr>\n<td>Outsourced<\/td>\n<td>Rapid access to a broad capability pool<\/td>\n<td>Board access, independence, confidentiality and organisational understanding<\/td>\n<\/tr>\n<tr>\n<td>Hybrid or group model<\/td>\n<td>Shared standards with local insight<\/td>\n<td>Authority, legal-entity coverage and cross-border data<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>No model removes the board\u2019s oversight responsibility. The organisation still needs an accountable chief audit executive or equivalent leadership arrangement, a board-approved mandate and effective quality oversight. Independence threats and conflicts must be assessed, especially when a provider also supplies other services.<\/p>\n<h2 id=\"pitfalls\"><span class=\"ez-toc-section\" id=\"Common_internal_audit_setup_mistakes\"><\/span>Common internal audit setup mistakes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><strong>Starting with an annual calendar:<\/strong> a list of departments is not a risk-based plan.<\/li>\n<li><strong>Using a generic charter:<\/strong> copied wording may not reflect legal structure, access or reporting reality.<\/li>\n<li><strong>Placing the function too low:<\/strong> limited status can inhibit access and challenge.<\/li>\n<li><strong>Confusing ownership and assurance:<\/strong> internal audit should not design, operate and then independently assure the same controls.<\/li>\n<li><strong>Underestimating technology risk:<\/strong> a function without IS audit capability may miss critical dependencies.<\/li>\n<li><strong>Measuring only completed audits:<\/strong> volume does not demonstrate coverage, quality, influence or improvement.<\/li>\n<li><strong>Postponing quality:<\/strong> weak files and inconsistent ratings become harder to correct after the function scales.<\/li>\n<\/ul>\n<h2 id=\"evidence\"><span class=\"ez-toc-section\" id=\"Readiness_checklist_for_the_new_function\"><\/span>Readiness checklist for the new function<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th>Area<\/th>\n<th>Minimum readiness evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Authority<\/td>\n<td>Board-approved mandate and charter<\/td>\n<\/tr>\n<tr>\n<td>Independence<\/td>\n<td>Functional reporting, private access and impairment safeguards<\/td>\n<\/tr>\n<tr>\n<td>Leadership<\/td>\n<td>Appointed chief audit executive and approved responsibilities<\/td>\n<\/tr>\n<tr>\n<td>Risk basis<\/td>\n<td>Audit universe, risk assessment and assurance map<\/td>\n<\/tr>\n<tr>\n<td>Delivery<\/td>\n<td>Methodology, templates, technology and records controls<\/td>\n<\/tr>\n<tr>\n<td>Resources<\/td>\n<td>Competency matrix, capacity analysis, budget and specialist plan<\/td>\n<\/tr>\n<tr>\n<td>Plan<\/td>\n<td>Board-approved risk-based plan with assumptions and exclusions<\/td>\n<\/tr>\n<tr>\n<td>Quality<\/td>\n<td>QAIP design, measures, assessment timetable and reporting route<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Early performance measures should balance delivery and value: priority-risk coverage, plan responsiveness, cycle time, stakeholder feedback, repeat findings, overdue high-risk actions, quality-review results and staff capability. Targets should not encourage superficial work or suppression of difficult findings.<\/p>\n<p>Further professional development is available through EPW\u2019s <a href=\"https:\/\/www.epw.com\/courses\/auditing-governance-and-risk-compliance\">Auditing, Governance, and Risk Compliance training portfolio<\/a>.<\/p>\n<h2 id=\"course\"><span class=\"ez-toc-section\" id=\"Develop_an_effective_internal_audit_operating_model_with_EPW\"><\/span>Develop an effective internal audit operating model with EPW<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>EPW\u2019s five-day <a href=\"https:\/\/www.epw.com\/training\/internal-audit-function-setup-and-optimization\"><strong>Internal Audit Function Setup and Optimization Course<\/strong><\/a> provides a practical roadmap for establishing and improving an internal audit function. It covers audit fundamentals, organisational needs and scope, team structure, charters and policies, resources and budgeting, stakeholder relationships, risk-based planning, evidence, reporting, data analytics, workflow improvement, performance measurement, quality assurance, independence and long-term capability.<\/p>\n<p>The course is suitable for current or prospective heads of internal audit, audit managers, governance and risk professionals, and leaders responsible for creating or strengthening an assurance function. Participants can use the course to test their operating model, identify priority gaps and plan sustainable improvements.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Who_approves_the_internal_audit_charter\"><\/span>Who approves the internal audit charter?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The governing body or its delegated audit committee should approve the charter. The chief audit executive discusses it with the board and senior management and reviews it when circumstances change.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Can_internal_audit_be_fully_outsourced\"><\/span>Can internal audit be fully outsourced?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Yes, where law and regulation permit, but outsourcing does not remove governance responsibilities. The board must protect authority, independence, access, competence, confidentiality, quality and direct communication.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"When_should_the_first_external_quality_assessment_occur\"><\/span>When should the first external quality assessment occur?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The Standards require an external quality assessment at least once every five years. A new function should plan for it from the start while using ongoing monitoring and periodic self-assessment to identify issues earlier.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"References\"><\/span>References<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li><a href=\"https:\/\/www.theiia.org\/en\/standards\/2024-standards\/global-internal-audit-standards\/\">The Institute of Internal Auditors, Global Internal Audit Standards, 2024 edition<\/a>.<\/li>\n<li><a href=\"https:\/\/www.theiia.org\/en\/content\/standards\/complete-global-internal-audit-standards\/\">The Institute of Internal Auditors, Complete Global Internal Audit Standards<\/a>.<\/li>\n<li><a href=\"https:\/\/www.theiia.org\/en\/content\/guidance\/recommended\/supplemental\/practice-guides\/model-internal-audit-activity-charter\/\">The Institute of Internal Auditors, Model Internal Audit Charter Tool and User\u2019s Guide<\/a>.<\/li>\n<li><a href=\"https:\/\/www.theiia.org\/en\/group-services\/quality-assurance\/\">The Institute of Internal Auditors, Quality Assurance services and QAIP guidance<\/a>.<\/li>\n<li><a href=\"https:\/\/www.oecd.org\/en\/publications\/g20-oecd-principles-of-corporate-governance-2023_ed750b30-en.html\">OECD, G20\/OECD Principles of Corporate Governance 2023<\/a>.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A practical 10-step process for establishing an independent, risk-based internal audit function\u2014from board mandate and charter to quality assurance and improvement.<\/p>\n","protected":false},"author":1,"featured_media":2939,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"class_list":["post-2465","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-auditing-governance-and-risk-compliance-articles"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Internal Audit Setup Process: 10 Steps | EPW<\/title>\n<meta name=\"description\" content=\"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Internal Audit Setup Process: 10 Steps | EPW\" \/>\n<meta property=\"og:description\" content=\"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\" \/>\n<meta property=\"og:site_name\" content=\"Blog Categories - EPW Training\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T14:09:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T08:34:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"EPW Training Blog\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"EPW Training Blog\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\"},\"author\":{\"@type\":\"Organization\",\"name\":\"EPW Training Blog\",\"url\":\"https:\/\/www.epw.com\/blog\/\",\"@id\":\"https:\/\/www.epw.com\/blog\/#organization\"},\"headline\":\"Internal Audit Setup Process: 10 Steps From Charter to Quality Review\",\"datePublished\":\"2026-09-09T14:09:35+00:00\",\"dateModified\":\"2026-09-13T08:34:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\"},\"wordCount\":1992,\"publisher\":{\"@id\":\"https:\/\/www.epw.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp\",\"articleSection\":[\"Auditing, Governance, and Risk Compliance Articles\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\",\"url\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\",\"name\":\"Internal Audit Setup Process: 10 Steps | EPW\",\"isPartOf\":{\"@id\":\"https:\/\/www.epw.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp\",\"datePublished\":\"2026-09-09T14:09:35+00:00\",\"dateModified\":\"2026-09-13T08:34:18+00:00\",\"description\":\"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage\",\"url\":\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp\",\"contentUrl\":\"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp\",\"width\":1024,\"height\":576,\"caption\":\"Internal auditors reviewing audit charter and quality review checklist in an office\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.epw.com\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Internal Audit Setup Process: 10 Steps From Charter to Quality Review\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.epw.com\/blog\/#website\",\"url\":\"https:\/\/www.epw.com\/blog\/\",\"name\":\"Blog Categories - EPW Training\",\"description\":\"Expert Insights and Updates in Professional Training\",\"publisher\":{\"@id\":\"https:\/\/www.epw.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.epw.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.epw.com\/blog\/#organization\",\"name\":\"Blog Categories - EPW Training\",\"url\":\"https:\/\/www.epw.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.epw.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.epw.com\/blog\/wp-content\/uploads\/2025\/08\/epw-training-blog-logo.png\",\"contentUrl\":\"https:\/\/www.epw.com\/blog\/wp-content\/uploads\/2025\/08\/epw-training-blog-logo.png\",\"width\":746,\"height\":256,\"caption\":\"Blog Categories - EPW Training\"},\"image\":{\"@id\":\"https:\/\/www.epw.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.epw.com\/blog\/#person\",\"name\":\"EPW Training Blog\",\"sameAs\":[\"https:\/\/www.epw.com\/blog\/\"],\"url\":\"https:\/\/www.epw.com\/blog\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Internal Audit Setup Process: 10 Steps | EPW","description":"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process","og_locale":"en_US","og_type":"article","og_title":"Internal Audit Setup Process: 10 Steps | EPW","og_description":"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.","og_url":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process","og_site_name":"Blog Categories - EPW Training","article_published_time":"2026-09-09T14:09:35+00:00","article_modified_time":"2026-09-13T08:34:18+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp","type":"image\/webp"}],"author":"EPW Training Blog","twitter_card":"summary_large_image","twitter_misc":{"Written by":"EPW Training Blog","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#article","isPartOf":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process"},"author":{"@type":"Organization","name":"EPW Training Blog","url":"https:\/\/www.epw.com\/blog\/","@id":"https:\/\/www.epw.com\/blog\/#organization"},"headline":"Internal Audit Setup Process: 10 Steps From Charter to Quality Review","datePublished":"2026-09-09T14:09:35+00:00","dateModified":"2026-09-13T08:34:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process"},"wordCount":1992,"publisher":{"@id":"https:\/\/www.epw.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage"},"thumbnailUrl":"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp","articleSection":["Auditing, Governance, and Risk Compliance Articles"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process","url":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process","name":"Internal Audit Setup Process: 10 Steps | EPW","isPartOf":{"@id":"https:\/\/www.epw.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage"},"image":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage"},"thumbnailUrl":"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp","datePublished":"2026-09-09T14:09:35+00:00","dateModified":"2026-09-13T08:34:18+00:00","description":"Follow a 10-step internal audit setup process covering mandate, charter, independence, staffing, risk-based planning, reporting, follow-up and quality review.","breadcrumb":{"@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#primaryimage","url":"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp","contentUrl":"https:\/\/assets.epw.com\/blog\/wp-content\/uploads\/2026\/09\/13083337\/internal-audit-setup-process-featured.webp","width":1024,"height":576,"caption":"Internal auditors reviewing audit charter and quality review checklist in an office"},{"@type":"BreadcrumbList","@id":"https:\/\/www.epw.com\/blog\/auditing-governance-and-risk-compliance-articles\/internal-audit-setup-process#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.epw.com\/blog"},{"@type":"ListItem","position":2,"name":"Internal Audit Setup Process: 10 Steps From Charter to Quality Review"}]},{"@type":"WebSite","@id":"https:\/\/www.epw.com\/blog\/#website","url":"https:\/\/www.epw.com\/blog\/","name":"Blog Categories - EPW Training","description":"Expert Insights and Updates in Professional Training","publisher":{"@id":"https:\/\/www.epw.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.epw.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.epw.com\/blog\/#organization","name":"Blog Categories - EPW Training","url":"https:\/\/www.epw.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.epw.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.epw.com\/blog\/wp-content\/uploads\/2025\/08\/epw-training-blog-logo.png","contentUrl":"https:\/\/www.epw.com\/blog\/wp-content\/uploads\/2025\/08\/epw-training-blog-logo.png","width":746,"height":256,"caption":"Blog Categories - EPW Training"},"image":{"@id":"https:\/\/www.epw.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.epw.com\/blog\/#person","name":"EPW Training Blog","sameAs":["https:\/\/www.epw.com\/blog\/"],"url":"https:\/\/www.epw.com\/blog\/"}]}},"_links":{"self":[{"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/posts\/2465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/comments?post=2465"}],"version-history":[{"count":3,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/posts\/2465\/revisions"}],"predecessor-version":[{"id":2731,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/posts\/2465\/revisions\/2731"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/media\/2939"}],"wp:attachment":[{"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/media?parent=2465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/categories?post=2465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.epw.com\/blog\/wp-json\/wp\/v2\/tags?post=2465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}