A new chief audit executive inherits a charter last updated in 2011. It authorizes audits of "financial and operating controls," says nothing about advisory work, and never mentions access to subsidiary records. Three quarters later the board asks why cybersecurity was never audited. The answer sits in the mandate.
The internal audit mandate is the grant of authority, role, and responsibilities that the board gives the internal audit function. It answers three questions: what the function is allowed to reach, what it is expected to do, and what it is accountable for delivering. The mandate lives in the internal audit charter, a written document the board approves.
Nothing in the mandate is self-assumed. The function cannot expand its own reach, and management cannot narrow it. The board grants it, the chief audit executive proposes and shapes it, and both revisit it as the organization changes.
KEY: Authority, role, and responsibilities are three distinct components. Authority is access and standing. Role is the type of work (assurance, advisory, or both).
Common mistakes
- Letting management approve the charter or plan. Input yes, approval never. A stem where the CFO or CEO signs off on the plan is a governance defect regardless of how reasonable the plan looks.
- Assuming advisory work is automatically authorized. If the mandate is silent on advisory services, the function needs a charter amendment before accepting them.
- Treating a coverage gap as a planning problem. A risk outside the authorized role or coverage requires a mandate change, not a plan line item. The Corvane logistics provider is the pattern: outside the entity, outside the role.
Bottom line
- Mandate: the board's grant of authority, role, and responsibilities to internal audit, documented in a board-approved charter.
- Authority means unrestricted access to records, people, systems, and property, direct board access, freedom from interference, and standing to escalate.
- Role covers work types (assurance, advisory, or both) and coverage (entities, geographies, risk domains); silence in the charter means not authorized.
- Responsibilities include the risk-based plan, engagement execution, communication of results, follow-up, quality and conformance, and coordination with other assurance providers.
Exam shortcut
Scan the stem for the verb attached to each party. "Approves" belongs to the board for charter, plan, budget, and CAE appointment; seeing it next to CEO, CFO, or general counsel is the defect. "Provides," "supports," and "responds" belong to management. "Assesses," "drafts," "proposes," "reports," and "escalates" belong to the CAE. Then classify the gap. Access blocked is authority. Work type or entity outside the charter is role.
The full lesson (about 2,699 words, 18 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 2
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.