Skip to content

Internal Audit

What is Internal Audit?

An independent, objective assurance activity within an organisation that evaluates the effectiveness of risk management, controls, and governance processes.

Risk Management

What the standards actually require on internal audit

Requirements naming internal audit across 6 standards, quoted from the control text.

Solvency II6 controls

Evaluate adequacy and effectiveness of the internal control system and other governance elements. Must be objective and independent from operational functions. Reports directly to the board (Article 47).

SII-P2-07 · Internal Audit Function

Operate Internal Audit per 12 CFR Part 30 Appendix D Section II.C.3. Internal Audit must (a) be a function independent of the front line units and Independent Risk Management with authority and independence to provide assurance to the Board on the design and o...

OCCHS-5 · Internal Audit: Independence, Scope, Methodology, and Reporting

Internal audit must review any proposed material arrangement that would outsource a critical operation, and must report regularly to the Board or Board Audit Committee on whether such arrangements comply with the entity service provider management policy.

CPS230-49 · Internal Audit Review of Proposed Critical Operation Outsourcing

Requirement defined in ISO/IEC 42001:2023, clause 9.2 (Internal audit). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-iec-42001-2023::9.2 · Internal audit
APRA CPS 2342 controls

Internal audit activities must include review of the design and operating effectiveness of information security controls, including those maintained by related parties and third parties.

CPS234-25 · Internal Audit Review of Information Security Controls

Organisation shall conduct internal audits at planned intervals to confirm the OR management system is effectively maintained.

4.5.5 · Internal Audit

Questions people ask about internal audit

What is Internal Audit?
An independent, objective assurance activity within an organisation that evaluates the effectiveness of risk management, controls, and governance processes.
Why is Internal Audit important for compliance?
Internal Audit is a key concept in Risk Management. Understanding internal audit helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Internal Audit?
Key concepts related to Internal Audit include Nonconformity. Understanding these interconnected concepts provides a more comprehensive view of Risk Management requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Internal Audit?
Internal Audit appears in the requirement text of Solvency II, OCC Heightened Standards (12 CFR Part 30, Appendix D), APRA CPS 230 Operational Risk Management, ISO/IEC 42001:2023, APRA CPS 234. Across these standards we have identified 20 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Internal Audit?
Explore our compliance framework pages to see how internal audit applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Internal Audit applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.