Assurance

What the Global Internal Audit Standards Mean for Internal Audit Transformation

A practical guide to what the Global Internal Audit Standards mean for internal audit transformation, quality, governance, reporting and audit committee oversight.

Assurance6 min readLast updated 18 July 2026By DisInnova Editorial Team
DisInnova assurance insight artwork

Executive summary

The Global Internal Audit Standards™ issued by The Institute of Internal Auditors reshape the expectations placed on internal audit functions — including governance of the function, strategic planning, methodology, quality assurance, reporting and the relationship with boards and audit committees. This article sets out what that means in practice for internal audit transformation, chief audit executives and audit committees.

The Global Internal Audit Standards™ issued by The Institute of Internal Auditors became effective on 9 January 2025. They replace the previous International Professional Practices Framework and reshape the expectations placed on internal audit functions across governance of the function, strategic planning, methodology, quality assurance, reporting and the working relationship with boards and audit committees. For chief audit executives, audit committee chairs and finance directors, the standards are now the reference point against which an internal audit function's design and behaviour are judged.

This guide sets out, in practical terms, what the Global Internal Audit Standards mean for internal audit transformation, how chief audit executives and audit committees should respond, and where independent internal audit advisory services add value. For broader governance, risk and control uplift that often runs alongside, see our governance, risk and controls advisory work. The official text is available from the Global Internal Audit Standards issued by The Institute of Internal Auditors.

DisInnova is an independent advisory firm and is not affiliated with, endorsed by or certified by The Institute of Internal Auditors. References to the Global Internal Audit Standards are for context only.

What are the Global Internal Audit Standards?

The Global Internal Audit Standards (GIAS) are a single, consolidated framework that brings together the previous Code of Ethics, Definition of Internal Auditing, Core Principles, Mission and standards into one document. They are organised around five domains covering the purpose of internal auditing, ethics and professionalism, governing the internal audit function, managing the function, and performing internal audit services. Each standard is supported by requirements, considerations for implementation and examples of evidence — making expectations more explicit than under the prior framework.

Why the 2025 effective date matters

The 1 January 2025 effective date (with formal conformance assessed from 9 January 2025) means external quality assessments, internal self-assessments and audit committee reporting now reference the new standards. Functions that have not refreshed their charter, methodology, quality programme and reporting are at risk of being assessed as only partially conforming. The standards also raise board and senior management responsibilities, meaning audit committees themselves should evidence how they have responded.

What GIAS means for chief audit executives

For chief audit executives, the standards consolidate accountability for the design, resourcing and performance of the internal audit function. CAEs are expected to articulate an audit strategy aligned with the organisation's strategy and risk profile, maintain an internal audit charter approved by the board, ensure adequate independence and authority, and demonstrate that the function has the competencies and technology required. Reporting to the board on conformance, performance and the quality assurance and improvement programme is now an explicit, recurring obligation rather than a periodic exercise.

What GIAS means for boards and audit committees

The standards place clearer expectations on the board (typically discharged through the audit committee) to support internal audit's independence, approve the charter, review the audit strategy and plan, oversee the CAE's performance, and confirm that resources are appropriate. Audit committees should expect a structured annual conversation covering the audit universe, risk coverage, methodology changes, quality assurance results, conformance with the standards and progress on transformation initiatives. A short, evidence-led briefing each year is usually sufficient to demonstrate active oversight.

GIAS and internal audit governance

Governance of the function is the area where most existing internal audit charters require refresh. The charter should now explicitly address the mandate, authority, independence, objectivity, scope of services, reporting lines and how the CAE interacts with the board and senior management. Functions should also document how potential impairments to independence are identified and managed, how the audit committee is involved in CAE appointment, performance review and remuneration, and how dual-hatted CAEs (for example, those also responsible for risk or compliance) preserve objectivity.

GIAS and internal audit strategy

GIAS makes an explicit, board-approved internal audit strategy a requirement. The strategy should describe the function's vision, the value it intends to deliver, how it will evolve its methodology, technology and people, and how it will measure performance. For many functions, this is the first time the strategy has been formalised as a standalone artefact rather than implied in an annual plan. A credible strategy typically covers a three-year horizon, links to the organisational strategy, and is reviewed annually with the audit committee.

GIAS and methodology / engagement execution

At engagement level, the standards reinforce expectations around planning, fieldwork, evaluation of evidence, supervision, documentation and reporting. Methodologies should make explicit how risk and control assessments are performed, how root cause analysis is applied, how findings are rated, and how recommendations are agreed with management. The standards also encourage proportionate use of data analytics and continuous auditing where these add insight. Methodology refresh is often the most visible change inside the function and the area where consistency across engagements matters most.

GIAS and quality assurance

The quality assurance and improvement programme (QAIP) is given renewed prominence. Functions are expected to operate ongoing monitoring (engagement-level reviews, supervisory review, key performance indicators), periodic internal self-assessments and external quality assessments at least every five years. Results — including identified opportunities for improvement and the CAE's response — should be reported to the board. A modern QAIP is light-touch but disciplined, with evidence captured as engagements progress rather than reconstructed at year-end.

GIAS and EQA readiness

External quality assessments performed after the effective date will assess conformance with the new standards. Functions should not wait for the EQA cycle to discover gaps. A pre-EQA readiness review — covering charter, strategy, methodology, QAIP, documentation, reporting and the audit committee's role — surfaces issues early and gives the CAE time to remediate. Readiness work also provides the audit committee with a credible, independent view of the function's maturity that can be shared with the board.

GIAS and internal audit transformation roadmap

For most functions, GIAS conformance and broader internal audit transformation are best run as a single coordinated programme rather than two parallel workstreams. A practical roadmap typically covers: a gap assessment against the standards; refresh of the charter, strategy and methodology; uplift of the QAIP; recalibration of the audit universe and risk-based plan; investment in audit technology and data analytics; targeted skills development; and refreshed reporting to the audit committee. Sequenced over twelve to eighteen months, this delivers conformance and capability uplift together.

Practical checklist for audit committees

  • Has the internal audit charter been refreshed and re-approved against the Global Internal Audit Standards?
  • Is there a documented, board-approved internal audit strategy covering at least the next three years?
  • Does the audit committee receive an annual conformance and QAIP report from the CAE?
  • Is the next external quality assessment scheduled, with a pre-EQA readiness review planned?
  • Are independence, objectivity and any dual-hatted CAE arrangements explicitly documented?
  • Does the audit plan demonstrate coverage of the organisation's most significant risks, including emerging risks?
  • Does the function have the methodology, technology and skills required to deliver the strategy?
  • Are findings, root causes and management action plans tracked through to closure with appropriate escalation?

How DisInnova supports GIAS-aligned transformation

DisInnova works with chief audit executives, audit committees and boards on independent, senior-led internal audit transformation aligned with the Global Internal Audit Standards. Typical engagements include GIAS gap assessments, charter and strategy refresh, methodology design, QAIP uplift, EQA readiness reviews and audit committee effectiveness reviews — typically sequenced as part of DisInnova's wider business advisory services for boards and executive teams. Where the underlying governance, risk and control environment also needs attention, this work is delivered alongside governance, risk and controls advisory and ongoing internal audit assurance advisory support. Engagements are scoped to the function's maturity and the audit committee's priorities, with a clear roadmap, evidence base and reporting cadence from the outset.

For boards and audit committees considering how GIAS alignment fits into wider oversight priorities, see our guide to business advisory services, and related advisory work across business advisory services, board advisory and financial services and fintech advisory.

Key takeaways

  • GIAS reshapes expectations across governance, strategy, methodology, quality and reporting
  • The 9 January 2025 effective date is the trigger for an honest read of where the function stands
  • Treat GIAS as the spine of internal audit transformation, not a compliance exercise
  • Embed quality assurance and EQA readiness as part of how the function operates

Written by

DisInnova Editorial Team

DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.

This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.

Explore DisInnova advisory services for governance, risk and transformation.

Need support with governance, risk, internal audit or AI transformation?

Our advisory services help Boards, Audit Committees and Executive Management strengthen governance, improve Internal Audit, manage risk and deliver responsible digital transformation.

Explore Our Services