Board / Executive Advisory

When Did the Audit Committee Last Reassess Whether Its Chief Audit Executive Is Still Fit for the Role?

Why Audit Committees should periodically reassess the competence, independence, professional currency and continuing suitability of the Chief Audit Executive.

Board / Executive Advisory9 min readLast updated 22 August 2026By DisInnova Editorial Team
Editorial illustration accompanying the DisInnova insight on board / executive advisory

Executive summary

Appointing a qualified Chief Audit Executive is only the beginning. As risks, regulation and technology change, Audit Committees should periodically reassess whether the CAE still has the competence, professional currency, independence, authority and leadership capability the organisation now requires — and whether the organisation enables the CAE to succeed.

Appointing a qualified Chief Audit Executive is only the beginning. The more difficult question for an Audit Committee is whether the person appointed several years ago continues to have the competence, independence, authority and professional currency required for the organisation's risk environment today.

Organisations change. Risks change. Regulations change. Technology changes. The capabilities required from the Chief Audit Executive must therefore evolve as well. A CAE who was highly suitable for the organisation five years ago should not automatically be assumed to remain equally suitable today, and the original appointment should not become permanent evidence of continuing competence.

The CAE role is changing

The modern Chief Audit Executive operates in a fundamentally different environment. Audit Committees increasingly expect Internal Audit to provide meaningful assurance and insight across areas including:

  • Artificial intelligence
  • Cybersecurity
  • Digital transformation
  • Data governance
  • Technology risk
  • Digital and AI-enabled fraud
  • Third-party and outsourcing risk
  • Regulatory change
  • Operational resilience
  • Geopolitical uncertainty

This does not mean the CAE must personally be the organisation's leading specialist in every emerging risk. It does mean the CAE must possess sufficient current knowledge, judgement and leadership capability to understand those risks, challenge management, direct the Internal Audit function appropriately and ensure the function has access to the expertise it needs. The themes explored in AI governance for Boards increasingly sit inside the CAE's remit rather than alongside it.

Appointment is not the end of the Audit Committee's responsibility

Audit Committees often devote considerable attention to selecting a new CAE. Qualifications are reviewed. Experience is assessed. References are obtained. Independence and reporting arrangements are considered.

But what happens five years later? The organisation may have transformed significantly while the assessment of the CAE has remained largely unchanged. Effective governance requires the Audit Committee to periodically ask whether its CAE remains equipped for the role — a discipline that sits at the heart of our board and audit committee advisory work, alongside the wider assurance architecture described in the three lines of defence model.

What should the Audit Committee reassess?

1. Professional competence

Does the CAE continue to possess the technical and professional competence necessary to lead a modern Internal Audit function? Consider knowledge of Internal Audit standards, governance, risk, controls, technology and relevant regulatory expectations. The expectations set out in the Global Internal Audit Standards provide a useful reference point for that discussion.

2. Professional qualifications and their currency

Relevant professional qualifications can provide important evidence of technical foundations and commitment to the profession. Depending on the organisation, role and risk environment, credentials such as CIA, CISA, CFE, accounting qualifications or other relevant certifications may be important. No single combination is universally required.

However, qualifications should not simply be treated as historical achievements. Audit Committees should understand whether relevant certifications are current, maintained where applicable, and supported by continuing professional education. Relevant qualifications matter; maintaining professional currency matters even more.

3. Continuous and updated education

The CAE's education should not have stopped when the original qualification was obtained. Audit Committees should ask:

  • What has the CAE learned during the last 12–24 months?
  • How is the CAE maintaining relevant professional education?
  • How is the CAE developing knowledge of AI, cyber, data, fraud and emerging risks?
  • Is professional development aligned with changes in the organisation's risk profile?

There is an important difference between accumulating continuing professional education hours and genuinely maintaining relevant professional competence. Hours evidence attendance; competence is evidenced by the quality of challenge the CAE brings to the Committee.

4. Understanding of the organisation's changing risk profile

Can the CAE credibly challenge management on the risks that matter today? The CAE does not need to personally perform every specialist audit, but must understand the risk environment sufficiently to determine where assurance is required and whether the Internal Audit function has the right capabilities.

5. Independence, authority and credibility

Assess whether the CAE continues to have:

  • Direct and effective access to the Audit Committee
  • Organisational standing
  • Independence from management
  • The confidence to raise difficult issues
  • Credibility with the Board and Executive Management
  • The authority required to protect Internal Audit's independence

Related service

Board Advisory

DisInnova supports Boards and Audit Committees in strengthening governance, oversight, challenge and the effectiveness of key assurance functions.

Explore Board Advisory →

6. Leadership and transformation capability

Today's CAE should not merely administer an audit plan. The Audit Committee should consider whether the CAE is capable of evolving the Internal Audit function through:

  • Data analytics
  • Appropriate use of AI
  • Continuous auditing
  • Dynamic risk assessment
  • Better use of specialist expertise
  • More effective reporting
  • Improved productivity
  • Stronger focus on emerging risks

Technology adoption itself is not the objective. The objective is a more effective, efficient and insightful Internal Audit function — the outcome pursued through Internal Audit transformation and reinforced by our Internal Audit advisory services.

Experience alone is not enough

Experience remains extremely valuable. But years of experience should not become a substitute for current competence. Twenty years in Internal Audit can represent twenty years of continuous learning and development. It can also represent twenty years of repeatedly applying approaches that are becoming outdated. The Audit Committee needs to distinguish between the two, as argued in AI won't replace internal auditors.

Experience matters. Qualifications matter. But current competence matters even more.

Should CAE assessment become more structured?

Audit Committees should consider a structured, periodic assessment of the CAE rather than relying on impressions formed over time. There is no universal mandatory frequency; unless an applicable regulatory requirement specifies otherwise, the cadence should reflect the organisation's size, sector, risk profile and pace of change. Many Committees align it with the annual evaluation cycle already used for other governance reviews, and it can be integrated with the structured evaluation approaches used in our Board Advisory services and in board effectiveness reviews.

The assessment could consider:

  • Professional competence
  • Relevant and maintained qualifications
  • Continuing education
  • Understanding of emerging risks
  • Leadership effectiveness
  • Independence and authority
  • Stakeholder credibility
  • Internal Audit transformation
  • Quality of Board and Audit Committee reporting
  • Succession readiness

The purpose is not to create unnecessary bureaucracy. It is to provide the Audit Committee with evidence that the person leading the third line remains capable of providing the assurance the Board requires.

The Audit Committee should also look beyond the individual

CAE effectiveness cannot be evaluated in isolation. The Audit Committee should consider whether the organisation itself enables the CAE to succeed. Ask whether the CAE has:

  • Sufficient resources
  • Appropriate budget
  • Access to specialist expertise
  • Unrestricted access to information
  • Appropriate technology
  • Direct access to the Audit Committee
  • Support for professional development
  • Authority to challenge management

A highly capable CAE cannot compensate indefinitely for an Internal Audit function that is structurally under-resourced or constrained. Where the constraint is systemic, the remedy usually sits in the wider control environment addressed through governance, risk and controls advisory.

Succession planning matters

CAE assessment should also connect to succession planning. Audit Committees should understand:

  • What capabilities will the next CAE require?
  • Is there credible internal succession?
  • Which emerging competencies are becoming essential?
  • How would the organisation respond to an unexpected CAE departure?
  • Is the current CAE developing the next generation of Internal Audit leadership?

Succession planning should begin before a vacancy exists. The capability profile of the next CAE is often visible in the direction of travel described in Internal Audit transformation.

Audit Committee checklist

Questions Audit Committees should be asking

  1. When did we last formally reassess our CAE's continuing suitability for the role?
  2. Are the CAE's professional qualifications relevant, current and maintained?
  3. What meaningful professional development has the CAE completed recently?
  4. Does the CAE understand the organisation's emerging AI, cyber, data, fraud and regulatory risks?
  5. Does the CAE have sufficient independence and authority to challenge management?
  6. Is the CAE transforming Internal Audit as the organisation itself transforms?
  7. Does Internal Audit have the specialist capabilities required for today's risk environment?
  8. What is our succession plan for the CAE?

Conclusion

The appointment of a Chief Audit Executive should never be treated as permanent evidence of continuing suitability. The risk environment continues to evolve, and so must the CAE.

Effective Audit Committees should periodically challenge whether the individual leading Internal Audit continues to possess the competence, independence, authority, leadership capability and professional currency required to provide meaningful assurance in today's environment.

The question is simple: when did your Audit Committee last reassess whether its CAE is still fit for the role? If the answer is “when we appointed them”, it may be time to ask the question again.

Frequently asked questions

What should an Audit Committee consider when assessing a Chief Audit Executive?

Good practice is to consider professional competence, the relevance and currency of qualifications, continuing professional education, understanding of the organisation's emerging risks, independence and authority, credibility with the Board and Executive Management, leadership and transformation capability, the quality of reporting to the Committee, and succession readiness. The assessment should also consider whether the organisation gives the CAE the resources, access and standing needed to succeed.

How often should an Audit Committee reassess the Chief Audit Executive?

There is no universal mandatory frequency. Unless a specific regulatory requirement applies to the organisation, the cadence is a matter of good governance judgement. Many Audit Committees fold a structured CAE assessment into their annual evaluation cycle, with a deeper review after significant change such as a transformation programme, a major shift in the risk profile or a change in regulatory expectations.

What qualifications should a Chief Audit Executive have?

No single set of qualifications is universally required. Depending on the organisation, sector and risk environment, credentials such as CIA, CISA, CFE, accounting qualifications or other relevant certifications can provide useful evidence of technical foundations. What matters most is that the qualifications held are relevant to the role, maintained where continuing education is required, and supported by demonstrable current competence.

Why is continuous professional development important for a Chief Audit Executive?

Because the risks Internal Audit must cover change faster than any original qualification anticipated. AI, cyber, data governance, digital fraud, operational resilience and regulatory change all require current knowledge. Continuing development is what allows a CAE to direct the function credibly, challenge management effectively and determine where specialist expertise is needed. Accumulating training hours is not the same as maintaining relevant competence.

Should the Audit Committee consider succession planning for the Chief Audit Executive?

Yes. Succession planning is widely regarded as good governance practice rather than a universal regulatory obligation. The Committee should understand what capabilities the next CAE will require, whether credible internal successors are being developed, and how the organisation would maintain assurance coverage in the event of an unexpected departure.

Strengthen Audit Committee oversight

DisInnova supports Boards and Audit Committees in assessing governance effectiveness, strengthening oversight and ensuring that Internal Audit leadership and capabilities remain aligned with the organisation's evolving risk environment.

Strengthen Audit Committee oversight

Partner-led support across board effectiveness, Audit Committee oversight, Internal Audit leadership and assurance quality.

Explore Board Advisory Services →

Key takeaways

  • Appointment is not permanent evidence that a CAE remains suitable for the role
  • Reassess competence, qualification currency, continuing education, emerging-risk understanding, independence and leadership
  • Relevant qualifications matter; maintaining professional currency matters even more
  • Experience is valuable but must not substitute for current competence
  • CAE effectiveness depends on resources, access and authority provided by the organisation
  • Structured periodic assessment should connect to succession planning

Written by

DisInnova Editorial Team

DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.

This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.

Explore DisInnova advisory services for governance, risk and transformation.

Need support with governance, risk, internal audit or AI transformation?

Our advisory services help Boards, Audit Committees and Executive Management strengthen governance, improve Internal Audit, manage risk and deliver responsible digital transformation.

Explore Our Services