Beyond conformance: Build an internal audit (IA) function that truly delivers
Expectations of IA are rising. Boards, Senior Management and regulators want clear evidence that the function is effective, not just compliant. The Global Internal Audit Standards (GIAS) guide the worldwide professional practice of IA and serve as a basis for evaluating and elevating the quality of the IA function, with all IA functions expected to conform. As part of a Quality Assurance and Improvement Programme (QAIP) under the GIAS, IA functions are expected to undertake an External Quality Assessments (EQA) at least once every five years, and Internal Quality Assessments (IQA) in the intervening years. IQAs and EQAs are therefore increasingly important as they help organisations demonstrate conformance to the GIAS, identify improvement opportunities and build confidence that IA is equipped to address today’s evolving risks.
PwC helps IA functions turn quality assessment requirements into a practical opportunity to strengthen conformance, maturity and impact. Depending on your needs, we can support IQA, EQA, advisory reviews of your GIAS Quality Assessment and Improvement Programme (QAIP), GIAS readiness reviews, and maturity assessments. Our quality assessment approach combines independent assessment with practical improvement advice, covering four key areas:
Assess conformance with the GIAS across all five domains, 15 principles and 52 standards, reviewing your charter, mandate, strategy, methodology, QAIP, audit planning, execution, reporting, follow-up and performance measures.
Gather robust evidence through stakeholder interviews, surveys and audit file reviews, testing both conformance with the Standards and how IA is experienced in practice.
Assess maturity using our maturity model to pinpoint current-state maturity and prioritise the enhancements that will most elevate the function.
Report with clarity, setting out strengths, improvement areas and a practical action plan, applying the GIAS rating scale and drawing on real-time insights from recent engagements on the areas Boards focus on most, including IA strategy, QAIP, performance objectives, coordinated assurance and the use of technology.
We look past a simple pass or fail. Alongside confirming conformance, we assess how effective IA is in practice, evaluate its maturity against leading practice, and provide a prioritised roadmap of enhancements that lift audit quality, efficiency and stakeholder value.
Our specialists work with the GIAS every day. We assess against all five domains, 15 principles and 52 standards, apply the new four-tier rating scale with separate ratings for conformance and achievement of the principles, and bring ready enhancement talking points from recent assessments on the areas Boards ask about most, including IA strategy, QAIP, performance objectives, coordinated assurance and the use of technology and AI.
We bring deep experience in highly regulated markets, including financial institutions such as banks, insurers and asset managers, where Boards, Audit Committees and regulators often have heightened expectations of the IA function. Our recommendations are grounded in a clear understanding of sector-specific risks, regulatory expectations and practical operating realities, giving Boards and Audit Committees independent, credible assurance.
A quality assessment shouldn’t just tick a box. It should move your function forward. We help you turn conformance into confidence, and insight into impact, so your IA function is trusted, effective and ready for what’s next.