Internal Audit Charter: Purpose, Scope & Responsibilities
Table of Contents:-
An internal audit charter is a formal document that defines the purpose, authority, position, scope and responsibilities of an organisation’s internal audit function.
It establishes the mandate under which internal audit operates and clarifies its relationship with the Board, Audit Committee and senior management. A properly designed charter is important for maintaining the independence and objectivity of internal audit and ensuring that auditors have sufficient authority and access to perform their responsibilities effectively.
The Institute of Internal Auditors (IIA) addresses the internal audit charter under its Global Internal Audit Standards, which became effective from January 9, 2025. The Standards require the chief audit executive to develop, implement and periodically review an internal audit charter that specifies, among other matters, the internal audit mandate, organisational position, reporting relationships and scope and types of services.
Companies establishing or strengthening their internal audit function may also refer to our Internal Audit Services in India.
What Is an Internal Audit Charter?
The internal audit charter is the formal foundation for the internal audit function.
It helps answer fundamental questions such as:
- Why does the internal audit function exist?
- What is internal audit authorised to examine?
- To whom does internal audit report?
- What access does the internal auditor have?
- How is independence maintained?
- What are the responsibilities of the internal audit function?
- What assurance and advisory services can internal audit perform?
- How does internal audit communicate its findings?
The charter therefore provides clarity to management, employees, the Audit Committee and internal auditors regarding the role and authority of internal audit.
Purpose of an Internal Audit Charter
The primary purpose of the charter is to formally establish the internal audit function and provide it with the authority necessary to carry out its responsibilities.
A well-designed internal audit charter can help an organisation:
- establish a clear internal audit mandate;
- define internal audit’s authority and responsibilities;
- protect the independence of the internal audit function;
- establish appropriate reporting relationships;
- provide unrestricted access to relevant information and personnel;
- define the scope of assurance and advisory services;
- clarify accountability to the Board or Audit Committee;
- strengthen risk management, governance and internal controls; and
- avoid confusion between internal audit and operational management.
For a practical review of areas commonly covered during an internal audit, see our Internal Audit Checklist for Companies in India.
Internal Audit Mandate
The internal audit mandate establishes the authority, role and responsibilities of the internal audit function.
Depending upon the organisation, the mandate may arise from:
- applicable laws and regulations;
- Board or Audit Committee requirements;
- corporate governance arrangements;
- management requirements;
- organisational policies; and
- professional internal audit standards.
In India, companies should also evaluate the applicability of Section 138 of the Companies Act, 2013 and Rule 13 of the Companies (Accounts) Rules, 2014 relating to internal audit.
The Ministry of Corporate Affairs provides access to the Companies Act, rules and other corporate regulatory information.
Authority of the Internal Audit Function
An internal audit function cannot operate effectively unless it has adequate authority.
Subject to appropriate confidentiality and governance requirements, the charter should ordinarily provide internal audit with access necessary for carrying out approved audit work.
This may include access to:
- books and accounting records;
- contracts and agreements;
- policies and procedures;
- information systems;
- physical assets;
- employees and management;
- Board and committee records relevant to the engagement;
- statutory and regulatory records; and
- other information necessary for performing internal audit procedures.
The charter should make it clear that management and employees are expected to cooperate with legitimate internal audit requests.
However, such access does not give internal audit responsibility for operating the processes being reviewed.
Organisational Position of Internal Audit
The organisational position of internal audit has a direct impact on its effectiveness.
The internal audit function should be positioned at a sufficiently senior level within the organisation to enable it to perform its work objectively and communicate significant matters appropriately.
The reporting structure should enable internal audit to communicate with the Board or Audit Committee without inappropriate management interference.
A clearly documented reporting structure also helps distinguish the internal audit function from accounting, finance, compliance and other operational departments.
Independence of Internal Audit
Independence is fundamental to an effective internal audit function.
Internal audit should be free from conditions that could impair its ability to perform its responsibilities objectively.
The charter should therefore establish appropriate safeguards against interference in matters such as:
- determining the scope of internal audit;
- selecting areas for review;
- performing audit procedures;
- communicating with employees;
- evaluating audit evidence;
- determining audit conclusions; and
- communicating audit results.
Internal auditors should not be prevented from reporting significant issues merely because the findings may be inconvenient to operational management.
Functional and Administrative Reporting
An internal audit charter should clearly establish reporting relationships.
Depending upon the organisation’s governance structure, functional oversight may involve the Board or Audit Committee, particularly in matters relating to:
- approval of the internal audit charter;
- internal audit plan;
- significant changes in audit scope;
- appointment or removal of the head of internal audit;
- internal audit resources;
- significant audit findings;
- independence issues; and
- performance of the internal audit function.
Administrative reporting may be structured through appropriate senior management to facilitate day-to-day matters such as logistics, information and organisational coordination.
The precise structure should reflect the organisation’s size, legal requirements and governance arrangements.
Objectivity of Internal Auditors
In addition to organisational independence, individual internal auditors should maintain objectivity.
Objectivity means approaching audit work without bias and making professional judgments based on appropriate evidence.
Internal auditors should therefore:
- avoid conflicts of interest;
- disclose circumstances that may impair objectivity;
- evaluate evidence impartially;
- avoid auditing activities for which they presently have operational responsibility;
- avoid allowing management pressure to influence conclusions; and
- communicate findings fairly and accurately.
The existing audit process should also provide mechanisms for addressing actual or perceived impairments to independence or objectivity.
Scope of Internal Audit
The internal audit charter should broadly establish the scope and types of internal audit services.
Depending on the organisation’s requirements, internal audit may cover:
- financial controls;
- operational processes;
- statutory compliance;
- risk management;
- corporate governance;
- procurement;
- sales and receivables;
- inventory;
- payroll;
- fixed assets;
- information technology;
- cybersecurity;
- fraud risks;
- related-party transactions;
- regulatory compliance;
- internal financial controls; and
- other areas requested by the Board or management.
The actual annual audit coverage should ordinarily be determined through an appropriate risk assessment and internal audit planning process.
Read our guide on Internal Audit Planning for further details.
Assurance and Advisory Services
Internal audit may provide both assurance and advisory services, subject to maintaining independence and objectivity.
Assurance Services
Assurance engagements may evaluate whether controls and processes relating to areas such as risk management, governance, financial reporting, operations and compliance are appropriately designed and operating effectively.
Advisory Services
Internal audit may also provide advice on controls, processes, risk management and governance.
However, internal audit should not assume management responsibility while providing advisory services.
Management remains responsible for decision-making, implementation and operation of business controls.
Responsibilities of the Internal Audit Function
The internal audit charter should clearly establish the responsibilities of the internal audit function.
Depending upon the organisation, these may include the following.
Evaluating Risk Management
Internal audit may assess whether significant risks affecting the organisation’s objectives have been appropriately identified, evaluated and managed.
This can include financial, operational, compliance, technology, fraud and strategic risks.
Evaluating Internal Controls
Internal audit may examine whether internal controls are appropriately designed and functioning effectively.
Examples include:
- segregation of duties;
- approval controls;
- maker-checker controls;
- reconciliations;
- access controls;
- physical safeguards;
- exception reporting; and
- management review controls.
Evaluating Governance
Internal audit may assess aspects of the organisation’s governance framework, including accountability, communication, oversight, ethics and decision-making processes.
Reviewing Compliance
Internal audit may evaluate systems established for compliance with:
- laws and regulations;
- internal policies;
- contracts;
- licences;
- regulatory requirements; and
- other applicable obligations.
Safeguarding Assets
Internal audit may evaluate controls designed to safeguard assets against:
- theft;
- misuse;
- unauthorised access;
- damage;
- fraud; and
- improper disposal.
Where appropriate, audit procedures may also verify the existence of assets.
Evaluating Reliability of Information
Internal audit may review the reliability, completeness and integrity of financial and operational information and the systems used for recording and reporting such information.
Evaluating Efficiency and Effectiveness
Internal audit may evaluate whether organisational resources are being used efficiently and whether business processes support the achievement of organisational objectives.
Fraud Risk
Internal audit may evaluate fraud risks and the effectiveness of controls designed to prevent or detect fraudulent activity.
Internal audit, however, does not relieve management of its primary responsibility for establishing appropriate fraud prevention and detection controls.
Responsibilities of Management
The internal audit charter should not create the impression that internal audit is responsible for operating internal controls.
Management remains responsible for:
- establishing business objectives;
- identifying and managing risks;
- designing and implementing controls;
- maintaining books and records;
- statutory compliance;
- safeguarding assets;
- preventing and detecting fraud;
- implementing corrective actions; and
- managing day-to-day operations.
Internal audit independently evaluates and provides assurance or advice regarding these activities.
Access to the Board and Audit Committee
An effective internal audit function should have appropriate access to the Board or Audit Committee.
This is particularly important when the internal auditor needs to communicate matters relating to:
- significant control weaknesses;
- fraud;
- regulatory non-compliance;
- management override;
- unresolved high-risk findings;
- limitations imposed on audit scope;
- inadequate internal audit resources; or
- impairment of independence.
The charter should therefore establish a mechanism for direct communication where circumstances require it.
Internal Audit Planning
The internal audit function should prepare an appropriate audit plan considering the organisation’s risks and priorities.
The plan may consider:
- significant financial exposure;
- regulatory requirements;
- previous audit findings;
- fraud risk;
- new business activities;
- technology changes;
- management concerns;
- control weaknesses;
- organisational changes; and
- emerging risks.
The audit plan should remain sufficiently flexible to respond to significant new risks arising during the year.
For more details, see Conducting the Overall Internal Audit Planning.
Internal Audit Reporting
Internal audit should communicate the results of its work to appropriate stakeholders.
An internal audit report may ordinarily contain:
- audit objective;
- scope;
- period covered;
- procedures performed;
- observations;
- risk implications;
- root causes;
- recommendations;
- management responses;
- responsible persons; and
- agreed timelines for corrective action.
Significant matters should be communicated to an appropriate level of management and, where required, the Audit Committee or Board.
Monitoring Corrective Actions
Internal audit should establish a mechanism for monitoring whether agreed corrective actions have been implemented.
Follow-up procedures may consider:
- outstanding audit observations;
- management action plans;
- responsible persons;
- target completion dates;
- evidence of implementation;
- overdue actions; and
- recurring findings.
High-risk observations remaining unresolved should be appropriately escalated.
Coordination With External Auditors and Other Assurance Providers
Where appropriate, internal audit may coordinate with:
- statutory auditors;
- compliance teams;
- risk-management functions;
- quality assurance teams;
- information-security functions; and
- other assurance providers.
Such coordination can help reduce unnecessary duplication and improve overall assurance coverage.
However, the responsibilities and independence of each assurance provider should remain clearly defined.
Internal Audit Resources and Competence
The internal audit function should have sufficient resources and appropriate competencies to fulfil its mandate.
Depending upon the scope, relevant expertise may include:
- accounting and finance;
- taxation;
- regulatory compliance;
- information technology;
- cybersecurity;
- operations;
- fraud risk;
- data analytics; and
- industry-specific knowledge.
Where specialist expertise is unavailable internally, external specialists may be considered.
Quality of the Internal Audit Function
The internal audit charter should support a commitment to quality and continuous improvement.
The organisation should periodically consider whether:
- audit methodology remains appropriate;
- internal auditors possess adequate competencies;
- audit work is properly supervised;
- documentation supports conclusions;
- reports are clear and useful;
- audit plans address significant risks;
- stakeholders receive appropriate communication; and
- improvement opportunities are identified and implemented.
Review and Approval of the Internal Audit Charter
The charter should not remain unchanged indefinitely.
It should be reviewed periodically and whenever significant changes occur in areas such as:
- organisational structure;
- internal audit leadership;
- legal or regulatory requirements;
- business model;
- risk profile;
- governance arrangements; or
- professional internal audit standards.
Changes should be submitted for appropriate approval in accordance with the organisation’s governance structure.
What Should an Internal Audit Charter Contain?
A practical internal audit charter may contain the following sections:
- Purpose of internal audit
- Internal audit mandate
- Authority
- Organisational position
- Reporting relationships
- Independence and objectivity
- Scope of internal audit activities
- Assurance services
- Advisory services
- Access to records, systems, personnel and assets
- Responsibilities of internal audit
- Responsibilities of management
- Internal audit planning
- Reporting and communication
- Follow-up of observations
- Coordination with other assurance providers
- Professional standards
- Quality assurance and improvement
- Periodic review of the charter
- Approval of the charter
The precise contents should be customised according to the organisation’s size, structure, industry and regulatory environment.
Internal Audit Charter vs Internal Audit Plan
An internal audit charter and an internal audit plan serve different purposes.
The charter establishes the permanent framework within which internal audit operates—including its mandate, authority, position and responsibilities.
The internal audit plan determines the specific areas or processes proposed to be audited during a particular period based on risk assessment and organisational priorities.
Therefore:
Internal Audit Charter = Authority and framework
Internal Audit Plan = What will be audited and when
Internal Audit Charter vs Internal Audit Checklist
An internal audit charter establishes the authority and framework of the internal audit function.
An internal audit checklist, on the other hand, assists auditors in reviewing specific processes, risks and controls during an audit.
For a practical checklist covering procurement, sales, GST, TDS, inventory, payroll, banking, fixed assets, IT controls and other areas, see our Internal Audit Checklist for Companies in India.
Internal Audit Charter for Companies in India
For Indian companies, the charter should be designed considering the organisation’s applicable legal and governance requirements.
Where Section 138 of the Companies Act, 2013 applies, the company should also ensure compliance with the statutory requirements concerning appointment and conduct of internal audit.
Foreign-owned Indian subsidiaries may additionally need to align their internal audit framework with global group requirements, delegation-of-authority policies and reporting requirements of overseas headquarters.
Frequently Asked Questions
What is an internal audit charter?
An internal audit charter is a formal document defining the internal audit function’s purpose, mandate, authority, organisational position, scope and responsibilities.
Why is an internal audit charter important?
It formally establishes the authority of internal audit, protects its independence, clarifies reporting relationships and provides a framework within which internal auditors perform assurance and advisory work.
Who approves the internal audit charter?
Approval should be consistent with applicable governance requirements and professional standards. Under the IIA Global Internal Audit Standards, the Board has an important role in approving the charter.
What is included in an internal audit charter?
It generally covers purpose, mandate, authority, organisational position, reporting relationships, independence, scope, responsibilities, access rights, professional standards and review arrangements.
How often should the internal audit charter be reviewed?
It should be reviewed periodically and when significant changes occur in the organisation, governance structure, risks, regulations or professional standards.
Is an internal audit charter the same as an internal audit checklist?
No. The charter establishes internal audit’s mandate and authority, whereas an Internal Audit Checklist provides procedures and areas that may be examined during individual audits.
Does an internal audit charter give the auditor unrestricted access?
The charter should provide the access reasonably necessary for internal audit to fulfil its approved responsibilities, subject to appropriate confidentiality, legal and governance requirements.
Can an outsourced internal auditor operate under an internal audit charter?
Yes. An organisation may outsource internal audit subject to applicable requirements. The charter can define the mandate, authority, reporting relationships and scope applicable to the outsourced internal audit arrangement.
For professional support, see our Internal Audit Services in India.
Internal Audit Services in India
EzyBiz India Consulting LLP assists Indian and foreign-owned companies with internal audits, internal control reviews, risk assessments, process audits and compliance reviews.
Our internal audit approach focuses on identifying control weaknesses, understanding their root causes and recommending practical corrective actions to management.
Learn more about our Internal Audit Services in India and broader Audit and Assurance Services in India.
Related Services
- Internal Audit Services in India
- Internal Audit Checklist for Companies in India
- Audit and Assurance Services in India
- Statutory Audit Services in India
- Tax Audit Services in India
Authoritative References
- The Institute of Internal Auditors – Global Internal Audit Standards
- Institute of Chartered Accountants of India – Internal Audit & Assurance Standards Board
- Ministry of Corporate Affairs
Prepared By: EzyBiz India Consulting LLP
Reviewed By: Anil Agrawal, Chartered Accountant
Last Updated: August 2026
Disclaimer: This article is intended for general informational purposes only. The internal audit charter and internal audit framework should be designed considering the organisation’s particular circumstances, applicable laws, governance arrangements and professional standards. Professional advice should be obtained before implementing an internal audit framework.