IIA Global Internal Audit Standards (2024 Edition, Effective January 9, 2025)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Global Internal Audit Standards are the mandatory component of The Institute of Internal Auditors' International Professional Practices Framework (IPPF). They guide the worldwide professional practice of internal auditing, are principle-based, and serve as a basis for evaluating and elevating the quality of the internal audit function. The Standards are organized into five domains, Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services, and around 15 principles, each supported by standards with requirements, considerations for implementation, and examples of evidence of conformance.
The Institute of Internal Auditors (The IIA) released the Standards on January 9, 2024 after a public consultation that drew nearly 19,000 comments, and they became effective on January 9, 2025 after a one-year implementation period during which early adoption was encouraged. All internal audit functions are expected to conform with them. They are complemented by Topical Requirements, a further mandatory component that sets a minimum baseline for assessing governance, risk management, and control in particular risk areas; Topical Requirements on cybersecurity, third-party management, organizational behavior, and organizational resilience have been issued, each effective twelve months after issuance.
Internal audit functions implement the Standards by securing a board-approved mandate and charter, positioning the function independently with a chief audit executive who reports to the board, building a strategy and risk-based plan, managing resources and quality, and performing engagements that are planned, executed, and communicated in line with the Performing Internal Audit Services domain. Conformance is assessed through the quality assurance and improvement program and periodic external assessment, and the results are reported to the board.
Why it Matters
Boards, regulators, and audit committees rely on internal audit for independent assurance over governance, risk management, and control, and the 2024 Standards set the expectation for how that assurance is organized and delivered. Because they consolidate the previous Standards, Code of Ethics, Core Principles, and Definition into one principles-based document and add mandatory Topical Requirements, they change both how functions are governed and what their engagements must cover.
Key benefits include:
- One mandatory framework
The Standards bring the profession's mandatory guidance into a single document organized by domain and principle, replacing separate elements of the earlier IPPF.
- Governance built in
The Governing the Internal Audit Function domain sets out the board's role in authorizing, positioning, and overseeing internal audit, making the function's independence a board responsibility.
- Strategy and performance expectations
Requirements to plan strategically, manage resources, communicate effectively, and enhance quality raise the management of the function to the same level as its engagements.
- Consistent coverage of key risks
Topical Requirements set minimum baselines for assessing areas such as cybersecurity and third-party management, so assurance on those risks is comparable across organizations.
- Guidance for every context
The Standards include considerations for the public sector and for small internal audit functions and are available in more than 40 languages.
How it Works
The Standards are organized in five domains. Domain I, Purpose of Internal Auditing, explains internal audit's value to stakeholders. Domain II, Ethics and Professionalism, sets the principles of integrity, objectivity, competency, due professional care, and confidentiality. Domain III, Governing the Internal Audit Function, requires that the function be authorized by the board, positioned independently, and overseen by the board, and sets the board's and chief audit executive's responsibilities. Domain IV, Managing the Internal Audit Function, requires the chief audit executive to plan strategically, manage resources, communicate effectively, and enhance quality. Domain V, Performing Internal Audit Services, requires engagements to be planned effectively, conducted with appropriate work, and communicated with results and monitoring of action plans. Each principle is supported by standards containing requirements, considerations for implementation, and examples of evidence of conformance.
A function implements the Standards by working through the domains: agreeing the mandate and charter with the board, establishing the chief audit executive's reporting lines, documenting the internal audit strategy and methodologies, developing a risk-based plan, and running engagements with documented planning, workpapers, supervision, findings, and follow-up. Topical Requirements are applied when the function provides assurance on the topic concerned, using the topic's baseline of governance, risk management, and control criteria. The quality assurance and improvement program, including external assessment, tests conformance, and the chief audit executive reports the results and any nonconformance to the board.
Within SmartSuite, internal audit teams manage the Standards as a working system: the charter, strategy, and risk-based plan are records the board approves, each engagement carries its objectives, scope, program, workpapers, and reviewer sign-off, Topical Requirement criteria are applied as reusable assessment sets, findings and management action plans are tracked to closure, and quality program results and board reporting are drawn from the same data.
Key Elements
- Five domains
Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services.
- Fifteen principles
From Demonstrate Integrity and Maintain Objectivity through Plan Strategically and Enhance Quality to Communicate Engagement Results and Monitor Action Plans.
- Standards with requirements, considerations, and evidence
Each standard states mandatory requirements, offers considerations for implementation, and gives examples of evidence of conformance.
- Board governance of internal audit
The board authorizes the mandate and charter, positions the function independently, and oversees its performance and the chief audit executive.
- Management of the function
Requirements for strategy, resources, communication, and a quality assurance and improvement program with external assessment.
- Performing engagements
Requirements for engagement planning, work performance, evidence and documentation, communicating results, and monitoring action plans.
- Topical Requirements
Mandatory minimum baselines for assurance on particular risk areas, including cybersecurity, third-party management, organizational behavior, and organizational resilience.
Framework Scope
The Global Internal Audit Standards apply to every internal audit function and internal auditor worldwide, in organizations of all sizes and sectors, and all internal audit functions are expected to conform with them. Topical Requirements must be applied when the function provides assurance services on the topic and are recommended for advisory services. The Standards govern the internal audit function and its work; they do not define the control frameworks that engagements assess against, which come from sources such as COSO, ISO/IEC 27001, and the NIST Cybersecurity Framework.
Framework Objectives
The Standards exist to guide the professional practice of internal auditing and to give organizations a basis for evaluating and improving their internal audit function.
Define the purpose of internal auditing and the ethics and professionalism expected of internal auditors.
Establish the board's responsibility for authorizing, positioning, and overseeing the internal audit function.
Require the chief audit executive to manage the function strategically, resource it, communicate, and enhance its quality.
Set requirements for planning, performing, and communicating internal audit engagements and monitoring action plans.
Provide a consistent minimum baseline for assurance on particular risk areas through Topical Requirements.
Serve as the basis for quality assessment and conformance reporting to the board.
Framework in Context
The Standards are the mandatory core of the IPPF and sit alongside The IIA's Topical Requirements and global guidance. Internal audit engagements under them commonly assess governance and control against the COSO Internal Control and Enterprise Risk Management frameworks, ISO 31000, ISO/IEC 27001, and the NIST Cybersecurity Framework, and IT audit work within internal audit draws on ISACA's ITAF and COBIT. Where internal audit supports the Sarbanes-Oxley program, its work is used by the external auditor under PCAOB AS 2201 and AS 2605. The Third-Party Topical Requirement, effective September 15, 2026, connects internal audit coverage to the EBA and U.S. interagency third-party risk frameworks.
Common Framework Mappings
The Standards are commonly mapped to the governance and control frameworks internal audit assesses against and to the audit and assurance standards it operates alongside.
Mapped frameworks include:
COSO IC 2013
COSO ERM 2017
ISO 31000:2018
ISO 27001:2022
NIST CSF 2.0
ISACA ITAF
COBIT 2019
SOX
PCAOB AS 2201
ISAE 3000
- ClassificationCategoryCompliance / Assurance StandardDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherThe Institute of Internal Auditors (The IIA)
- VersioningVersion2024 EditionEffective DateJanuary 9, 2025Issue DateJanuary 9, 2024
- AdoptionAdoption ModelIndustry RequirementImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The Global Internal Audit Standards are available free of charge from The IIA in more than 40 languages, and their domain and principle structure is included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports IIA Global Internal Audit Standards
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the Global Internal Audit Standards, SmartSuite holds the charter, strategy, risk-based plan, engagements, workpapers, findings, action plans, and quality program results in one workspace, so conformance across the five domains is evidenced continuously and reported to the board.
Standards and Topical Requirements Library
Hold the five domains, 15 principles, and each Topical Requirement's baseline criteria as reusable assessment sets linked to the audit universe.
Ownership, Cadence, and Accountability
Assign the chief audit executive, engagement leads, and reviewers, schedule the risk-based plan, and route charter and plan approvals to the board.
Evidence Collection and Audit Trail
Attach workpapers, interview notes, and analytics to each engagement procedure with timestamps and supervisory review.
Engagement Planning and Performance
Plan objectives, scope, and programs, track fieldwork and supervision, and document conclusions under Domain V.
Risk and Framework Alignment
Map engagement criteria to COSO, ISO 31000, ISO/IEC 27001, and NIST CSF so one engagement serves several assurance needs.
Board and Quality Reporting
Report engagement results, action plan status, and quality assurance and improvement program findings to senior management and the board.
Related frameworks

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.
Frequently Asked Questions For IIA Global Internal Audit Standards
They are the mandatory component of The IIA's International Professional Practices Framework. Principle-based, they guide the worldwide professional practice of internal auditing and serve as a basis for evaluating and elevating the quality of the internal audit function.
The IIA released them on January 9, 2024, and they became effective on January 9, 2025 after a one-year implementation period. Early adoption was encouraged, and all internal audit functions are now expected to conform.
Five domains, Purpose of Internal Auditing, Ethics and Professionalism, Governing the Internal Audit Function, Managing the Internal Audit Function, and Performing Internal Audit Services, contain 15 principles, each supported by standards with requirements, considerations for implementation, and examples of evidence of conformance.
Topical Requirements are a mandatory component of the IPPF that provide a minimum baseline and relevant criteria for assessing governance, risk management, and control in particular risk areas. Functions must apply them when providing assurance on the topic; they are recommended for advisory services and take effect twelve months after issuance.
Cybersecurity (effective February 5, 2026), Third-Party (effective September 15, 2026), Organizational Behavior (effective December 15, 2026), and Organizational Resilience (effective April 30, 2027), with Anti-Corruption and Talent Management to follow.
Yes. The Standards apply to all internal audit functions and include considerations for the public sector and for small internal audit functions.
SmartSuite holds the charter, strategy, risk-based plan, engagements, workpapers, findings, action plans, Topical Requirement criteria, and quality program results in one workspace so conformance is evidenced continuously and reported to the board.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

