An internal audit function without a charter is operating on borrowed authority. The audit charter is the formal document that establishes why internal audit exists, what it is allowed to do, who it answers to, and how its independence is protected. This guide explains what belongs in a charter, who approves it, and why the IIA's standards treat it as non-negotiable.
What You'll Learn
This article explains the purpose of an audit charter, the core sections it should contain, how it establishes internal audit's authority and independence, who approves it, the IIA standards that require it, and how often it should be reviewed. A sample charter outline is included.
What Is an Audit Charter?
An internal audit charter is a formal, written document approved by the board (usually through its audit committee) that defines the purpose, authority, and responsibility of the internal audit function. It is the foundational mandate from which everything else derives its legitimacy: the audit plan, individual engagements, and reporting all trace back to it.
Think of the charter as internal audit's constitution. It is short, often three to six pages, but it settles the questions that, left ambiguous, undermine the whole function. Can the auditors access any record they need? Who do they report to? Who can change their scope? What stops management from quietly shutting down an inconvenient audit? The charter answers these in writing, in advance, and with board authority behind it.
Why a Charter Matters
The charter exists to protect both the organisation and the audit function. It serves several purposes:
- Grants authority: it gives auditors the right of access to people, records, and assets they need to do their work.
- Defines scope: it sets the boundaries of what internal audit covers, so neither the auditors nor management is guessing.
- Protects independence: it establishes reporting lines that keep audit free from the operational management it reviews.
- Sets expectations: it tells the rest of the organisation what internal audit is, and is not, responsible for.
- Provides accountability: it commits internal audit to professional standards and to reporting honestly to the board.
Pro Tip
The most valuable clause in many charters is the access clause, the explicit, board-backed right to "full, free, and unrestricted access to all records, property, and personnel." When a manager stalls an audit, that sentence is what you point to.
Want the full framework with worked examples?
What an Audit Charter Contains
While charters vary, a complete one covers the following elements:
| Section | What it establishes |
|---|---|
| Mandate / Purpose | Why internal audit exists and the value it provides (independent, objective assurance and advisory) |
| Authority | Right of access to records, systems, assets, and people; authority to allocate resources and set scope |
| Scope | The range of activities covered: governance, risk management, and control across the organisation |
| Independence & Objectivity | Organisational positioning, freedom from operational responsibility, and conflict-of-interest rules |
| Reporting Lines | Functional reporting to the audit committee; administrative reporting to executive management |
| Responsibilities | Planning, executing, and reporting engagements; following up on findings; coordinating assurance |
| Standards | Commitment to conform with the IIA's professional standards and code of ethics |
| Quality Assurance | Internal and external assessments of the function's effectiveness |
Mandate and Scope
The mandate states, in a sentence or two, that internal audit provides independent, objective assurance and advisory services designed to add value and improve operations. The scope clause then makes clear that no part of the organisation is off-limits: internal audit can examine any activity, system, or record relevant to governance, risk, and control.
Authority
The authority section is the operative heart of the charter. It typically grants unrestricted access to all functions, records, property, and personnel; the authority to obtain assistance from staff in areas being audited; and the freedom to determine the scope of work and apply the techniques required, without management curtailing it.
Responsibilities
This section commits internal audit to develop a risk-based plan, execute engagements professionally, report results to the audit committee, follow up on agreed actions, and coordinate with other assurance providers. It often clarifies what internal audit does not do: it does not own controls, make management decisions, or take operational responsibility for the areas it reviews.
How the Charter Establishes Independence
Independence is the quality that makes internal audit credible, and the charter is where it is secured. Independence is established structurally, through reporting lines, and personally, through objectivity rules.
The charter sets a dual reporting relationship: internal audit reports functionally to the audit committee and administratively to a senior executive (often the CEO or CFO). The functional line is the protective one. It means the audit committee, not operational management, approves the audit plan, approves the budget, appoints and removes the Chief Audit Executive, and receives the audit results directly.
| Decision | Functional (Audit Committee) | Administrative (Management) |
|---|---|---|
| Approve the audit plan | Yes | No |
| Approve the budget | Yes (oversight) | Day-to-day |
| Appoint / remove the CAE | Yes | No |
| Receive audit results | Directly | Informed |
| HR administration / facilities | No | Yes |
Important
If the Chief Audit Executive can be hired, fired, or have their pay set solely by the executives they audit, independence is compromised on paper no matter what the charter says. The charter must place those decisions with the audit committee for independence to be real.
The charter also addresses objectivity at the individual level: auditors must not assess areas where they recently worked, must disclose conflicts of interest, and must not take on operational duties that they would later audit. Independence is the function's positioning; objectivity is the auditor's mindset. The charter protects both.
Who Approves the Charter
The audit charter is approved by the board, acting through the audit committee. The Chief Audit Executive drafts it, but board-level approval is what gives it force, because management cannot grant internal audit authority over management itself. The audit committee chair typically signs alongside the Chief Audit Executive.
Approval at this level is deliberate. Because the charter constrains what management can do to internal audit (it cannot block access, cannot quietly remove the CAE, cannot veto the plan), the authority to set those rules must sit above management with the board.
IIA Standards Context
The requirement for a charter is not optional good practice; it is embedded in the Institute of Internal Auditors' professional standards. The IIA's Global Internal Audit Standards require that the purpose, authority, and responsibility of internal audit be formally defined in a charter, that the charter be approved by the board, and that it be reviewed periodically. The standards also require the charter to reference internal audit's mandate to conform with the standards and the IIA's code of ethics.
A charter that conforms to the standards is also a signal to regulators, external auditors, and the board that the function is professionally constituted. Where internal audit claims to operate "in conformance with the IIA standards," an external quality assessment will check that the charter exists, is approved, and reflects the standards.
Sample charter outline
1. Purpose and Mission. Internal audit provides independent, objective assurance and advisory services to add value and improve the organisation's operations.
2. Authority. Full, free, and unrestricted access to all records, property, and personnel relevant to any engagement.
3. Independence and Objectivity. Functional reporting to the Audit Committee; administrative reporting to the CEO; conflict-of-interest rules.
4. Scope. Governance, risk management, and internal control across all entities and functions.
5. Responsibilities. Risk-based planning, engagement execution, reporting, follow-up, and assurance coordination.
6. Standards and Quality. Conformance with the IIA standards and code of ethics; internal and external quality assessments.
7. Approval and Review. Approved by the Audit Committee; reviewed at least annually.
Review Cadence
A charter is not a write-once document. The IIA standards call for the Chief Audit Executive to review it periodically and present it to the board for reaffirmation. Most functions review the charter at least annually, and always when something material changes: a new regulatory regime, a restructuring, a change in reporting lines, or an update to the professional standards themselves.
Even when no change is needed, taking the charter back to the audit committee each year is valuable. It reaffirms internal audit's mandate in front of the board, refreshes everyone's memory of the access and independence provisions, and creates a documented record that the function's authority remains current.
Common Mistakes to Avoid
1. Letting management approve the charter
If the document granting authority over management is approved only by management, it is structurally toothless. Board-level approval is essential.
2. A vague or missing access clause
Without an explicit, unrestricted access provision, auditors can be stonewalled. Spell access out in plain language.
3. Confusing functional and administrative reporting
If the audit committee does not control the plan, budget, and CAE appointment, the dual-reporting model collapses and independence is lost.
4. Copying a template without tailoring it
A generic charter that does not reflect your structure, entities, and regulatory environment will not hold up under scrutiny.
5. Never reviewing it
A charter approved years ago, referencing superseded standards or an obsolete org structure, undermines the function's credibility. Review annually.
Summary
- The audit charter is internal audit's formal mandate, its constitution
- It defines purpose, authority, scope, independence, reporting lines, and responsibilities
- Independence is secured through functional reporting to the audit committee
- The board, through the audit committee, must approve it, not management alone
- The IIA standards require a board-approved charter that is reviewed periodically
- Review the charter at least annually and whenever the environment changes
Frequently Asked Questions
Who writes the audit charter?
The Chief Audit Executive drafts the charter, but the board, usually through its audit committee, approves it. Drafting and approval are deliberately separated so that the authority granted to internal audit comes from above management.
What is the difference between functional and administrative reporting?
Functional reporting is to the audit committee, which approves the plan and budget, appoints the CAE, and receives results. That is what protects independence. Administrative reporting is to a senior executive for day-to-day matters such as HR and facilities.
How is the charter different from the audit plan?
The charter is the standing mandate. It defines authority and independence and rarely changes. The audit plan is the schedule of engagements for a period and is refreshed at least annually. The plan operates under the authority the charter grants.
Is an audit charter legally required?
It is required by the IIA's professional standards, and in many sectors, financial services in particular, regulators expect a board-approved charter. Even where not strictly mandated by law, it is considered an essential element of a credible internal audit function.
How often should the charter be reviewed?
At least annually, and whenever something material changes: a restructuring, new regulation, a change in reporting lines, or an update to the professional standards. Reaffirming it each year keeps internal audit's mandate current and visible to the board.
Can the charter restrict what internal audit can examine?
A well-written charter does the opposite. It grants unrestricted access across the organisation. Any scope limitation imposed on internal audit is itself a governance concern that should be reported to the audit committee, because it impairs the function's ability to provide assurance.
Save this guide for later
Download the PDF version to read offline or share with your team.

