KITE 2025 New Product Award — Local IT | SACEEC

What Is an Audit Charter? Purpose, Contents and How It Establishes Independence

The audit charter is the single document that grants internal audit its authority, defines its scope, and protects its independence. Here is what belongs in one.

Free PDF GuideDownload this guide as a PDF

An internal audit function without a charter is operating on borrowed authority. The audit charter is the formal document that establishes why internal audit exists, what it is allowed to do, who it answers to, and how its independence is protected. This guide explains what belongs in a charter, who approves it, and why the IIA's standards treat it as non-negotiable.

Watch: What is an audit charter Watch: Writing an internal audit charter (short tutorial)
i

What You'll Learn

This article explains the purpose of an audit charter, the core sections it should contain, how it establishes internal audit's authority and independence, who approves it, the IIA standards that require it, and how often it should be reviewed. A sample charter outline is included.

What Is an Audit Charter?

An internal audit charter is a formal, written document approved by the board (usually through its audit committee) that defines the purpose, authority, and responsibility of the internal audit function. It is the foundational mandate from which everything else derives its legitimacy: the audit plan, individual engagements, and reporting all trace back to it.

Think of the charter as internal audit's constitution. It is short, often three to six pages, but it settles the questions that, left ambiguous, undermine the whole function. Can the auditors access any record they need? Who do they report to? Who can change their scope? What stops management from quietly shutting down an inconvenient audit? The charter answers these in writing, in advance, and with board authority behind it.

Why a Charter Matters

The charter exists to protect both the organisation and the audit function. It serves several purposes:

  • Grants authority: it gives auditors the right of access to people, records, and assets they need to do their work.
  • Defines scope: it sets the boundaries of what internal audit covers, so neither the auditors nor management is guessing.
  • Protects independence: it establishes reporting lines that keep audit free from the operational management it reviews.
  • Sets expectations: it tells the rest of the organisation what internal audit is, and is not, responsible for.
  • Provides accountability: it commits internal audit to professional standards and to reporting honestly to the board.
i

Pro Tip

The most valuable clause in many charters is the access clause, the explicit, board-backed right to "full, free, and unrestricted access to all records, property, and personnel." When a manager stalls an audit, that sentence is what you point to.

Want the full framework with worked examples?

What an Audit Charter Contains

While charters vary, a complete one covers the following elements:

Section What it establishes
Mandate / Purpose Why internal audit exists and the value it provides (independent, objective assurance and advisory)
Authority Right of access to records, systems, assets, and people; authority to allocate resources and set scope
Scope The range of activities covered: governance, risk management, and control across the organisation
Independence & Objectivity Organisational positioning, freedom from operational responsibility, and conflict-of-interest rules
Reporting Lines Functional reporting to the audit committee; administrative reporting to executive management
Responsibilities Planning, executing, and reporting engagements; following up on findings; coordinating assurance
Standards Commitment to conform with the IIA's professional standards and code of ethics
Quality Assurance Internal and external assessments of the function's effectiveness

Mandate and Scope

The mandate states, in a sentence or two, that internal audit provides independent, objective assurance and advisory services designed to add value and improve operations. The scope clause then makes clear that no part of the organisation is off-limits: internal audit can examine any activity, system, or record relevant to governance, risk, and control.

Authority

The authority section is the operative heart of the charter. It typically grants unrestricted access to all functions, records, property, and personnel; the authority to obtain assistance from staff in areas being audited; and the freedom to determine the scope of work and apply the techniques required, without management curtailing it.

Responsibilities

This section commits internal audit to develop a risk-based plan, execute engagements professionally, report results to the audit committee, follow up on agreed actions, and coordinate with other assurance providers. It often clarifies what internal audit does not do: it does not own controls, make management decisions, or take operational responsibility for the areas it reviews.

How the Charter Establishes Independence

Independence is the quality that makes internal audit credible, and the charter is where it is secured. Independence is established structurally, through reporting lines, and personally, through objectivity rules.

The charter sets a dual reporting relationship: internal audit reports functionally to the audit committee and administratively to a senior executive (often the CEO or CFO). The functional line is the protective one. It means the audit committee, not operational management, approves the audit plan, approves the budget, appoints and removes the Chief Audit Executive, and receives the audit results directly.

Decision Functional (Audit Committee) Administrative (Management)
Approve the audit plan Yes No
Approve the budget Yes (oversight) Day-to-day
Appoint / remove the CAE Yes No
Receive audit results Directly Informed
HR administration / facilities No Yes
!

Important

If the Chief Audit Executive can be hired, fired, or have their pay set solely by the executives they audit, independence is compromised on paper no matter what the charter says. The charter must place those decisions with the audit committee for independence to be real.

The charter also addresses objectivity at the individual level: auditors must not assess areas where they recently worked, must disclose conflicts of interest, and must not take on operational duties that they would later audit. Independence is the function's positioning; objectivity is the auditor's mindset. The charter protects both.

Who Approves the Charter

The audit charter is approved by the board, acting through the audit committee. The Chief Audit Executive drafts it, but board-level approval is what gives it force, because management cannot grant internal audit authority over management itself. The audit committee chair typically signs alongside the Chief Audit Executive.

Approval at this level is deliberate. Because the charter constrains what management can do to internal audit (it cannot block access, cannot quietly remove the CAE, cannot veto the plan), the authority to set those rules must sit above management with the board.

IIA Standards Context

The requirement for a charter is not optional good practice; it is embedded in the Institute of Internal Auditors' professional standards. The IIA's Global Internal Audit Standards require that the purpose, authority, and responsibility of internal audit be formally defined in a charter, that the charter be approved by the board, and that it be reviewed periodically. The standards also require the charter to reference internal audit's mandate to conform with the standards and the IIA's code of ethics.

A charter that conforms to the standards is also a signal to regulators, external auditors, and the board that the function is professionally constituted. Where internal audit claims to operate "in conformance with the IIA standards," an external quality assessment will check that the charter exists, is approved, and reflects the standards.

Example

Sample charter outline

1. Purpose and Mission. Internal audit provides independent, objective assurance and advisory services to add value and improve the organisation's operations.

2. Authority. Full, free, and unrestricted access to all records, property, and personnel relevant to any engagement.

3. Independence and Objectivity. Functional reporting to the Audit Committee; administrative reporting to the CEO; conflict-of-interest rules.

4. Scope. Governance, risk management, and internal control across all entities and functions.

5. Responsibilities. Risk-based planning, engagement execution, reporting, follow-up, and assurance coordination.

6. Standards and Quality. Conformance with the IIA standards and code of ethics; internal and external quality assessments.

7. Approval and Review. Approved by the Audit Committee; reviewed at least annually.

Review Cadence

A charter is not a write-once document. The IIA standards call for the Chief Audit Executive to review it periodically and present it to the board for reaffirmation. Most functions review the charter at least annually, and always when something material changes: a new regulatory regime, a restructuring, a change in reporting lines, or an update to the professional standards themselves.

Even when no change is needed, taking the charter back to the audit committee each year is valuable. It reaffirms internal audit's mandate in front of the board, refreshes everyone's memory of the access and independence provisions, and creates a documented record that the function's authority remains current.

Common Mistakes to Avoid

1. Letting management approve the charter

If the document granting authority over management is approved only by management, it is structurally toothless. Board-level approval is essential.

2. A vague or missing access clause

Without an explicit, unrestricted access provision, auditors can be stonewalled. Spell access out in plain language.

3. Confusing functional and administrative reporting

If the audit committee does not control the plan, budget, and CAE appointment, the dual-reporting model collapses and independence is lost.

4. Copying a template without tailoring it

A generic charter that does not reflect your structure, entities, and regulatory environment will not hold up under scrutiny.

5. Never reviewing it

A charter approved years ago, referencing superseded standards or an obsolete org structure, undermines the function's credibility. Review annually.

Key Takeaways

Summary

  • The audit charter is internal audit's formal mandate, its constitution
  • It defines purpose, authority, scope, independence, reporting lines, and responsibilities
  • Independence is secured through functional reporting to the audit committee
  • The board, through the audit committee, must approve it, not management alone
  • The IIA standards require a board-approved charter that is reviewed periodically
  • Review the charter at least annually and whenever the environment changes

Frequently Asked Questions

Who writes the audit charter?

The Chief Audit Executive drafts the charter, but the board, usually through its audit committee, approves it. Drafting and approval are deliberately separated so that the authority granted to internal audit comes from above management.

What is the difference between functional and administrative reporting?

Functional reporting is to the audit committee, which approves the plan and budget, appoints the CAE, and receives results. That is what protects independence. Administrative reporting is to a senior executive for day-to-day matters such as HR and facilities.

How is the charter different from the audit plan?

The charter is the standing mandate. It defines authority and independence and rarely changes. The audit plan is the schedule of engagements for a period and is refreshed at least annually. The plan operates under the authority the charter grants.

Is an audit charter legally required?

It is required by the IIA's professional standards, and in many sectors, financial services in particular, regulators expect a board-approved charter. Even where not strictly mandated by law, it is considered an essential element of a credible internal audit function.

How often should the charter be reviewed?

At least annually, and whenever something material changes: a restructuring, new regulation, a change in reporting lines, or an update to the professional standards. Reaffirming it each year keeps internal audit's mandate current and visible to the board.

Can the charter restrict what internal audit can examine?

A well-written charter does the opposite. It grants unrestricted access across the organisation. Any scope limitation imposed on internal audit is itself a governance concern that should be reported to the audit committee, because it impairs the function's ability to provide assurance.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.