

The Institute of Internal Auditors (IIA) introduced a major update to its standards in January 2024, replacing the 2017 International Standards for the Professional Practice of Internal Auditing. These Global Internal Audit Standards (GIAS) took effect January 9, 2025, and represent a significant shift in structure, terminology, and expectations for internal audit functions worldwide.
The new Standards redefine internal auditing’s purpose and introduce conditions for the Board and senior management engagement, emphasizing governance alignment, risk-based planning, and technology enablement.
For institutions, this is an opportunity to strengthen governance, enhance risk management, and elevate the strategic role of internal audit. Below are key lessons learned and practical steps for adoption.
The Standards call for a strategic plan that includes a vision, objectives, and supporting initiatives for the internal audit function, typically spanning three to five years. Consider:
Performance objectives should extend beyond simple budget compliance. Incorporate SMART goals (specific, measurable, achievable, relevant, and time-bound) to track progress effectively. Examples include increasing in-house compliance expertise or implementing new audit technology.
In addition, every audit engagement must include a documented risk assessment. This process should:
Document these assessments in audit files and link them to your audit platform for transparency and efficiency.
Final engagement communications must include:
When documenting findings and action plans, define the root cause so that corrective measures can adequately address the underlying issues. Auditors must also credit management for corrective actions implemented before the final communication is issued.
The Standards require Chief Audit Executives to regularly evaluate audit technology and report limitations to the Board. If your function relies solely on basic tools like Word and Excel, perform a documented analysis and present options for improvement. Consider outsourcing data-intensive audits as a mitigating control.
Finally, Domain III emphasizes the Board and senior management’s responsibility for meeting “Essential Conditions,” such as approving plans, budgets, resources, and charters, as well as confirming independence. To sustain an effective internal audit function, the Chief Audit Executive should engage in candid discussions with both parties about these requirements.
Adopting the Global Internal Audit Standards equips institutions that act now with the tools to drive organizational resilience.
Ready to start? Contact Elliott Davis for a comprehensive gap assessment and build a roadmap that aligns with your vision and strategic priorities.
The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.