Blog

How Often Internal Audit Should Be Assessed for Quality

Subscribe now to join the Risk Register community:

Ask most audit leaders how often their function needs a quality assessment and you will get one number back: five years. It is the right number and the wrong mental model, and the gap between those two things is where the scramble comes from.

A function that treats quality as something that happens once every five years spends four years accumulating drift and one year trying to document its way out of it. The Standards describe something continuous, with the external assessment sitting on top as confirmation rather than discovery.

The Five-Year Rule for Internal Audit Quality Assessment Is a Floor, Not a Schedule

Under the 2024 Global Internal Audit Standards, effective 9 January 2025, Standard 8.4 requires that an external assessment be performed at least once every five years by a qualified, independent assessor or assessment team.

Two words in that sentence carry most of the weight. At least sets a floor rather than a schedule. And qualified has a floor written into the Standard: at least one member of the assessment team must hold an active CIA designation. Beyond that, the IIA describes the attributes a strong team brings, such as experience applying the Standards, CAE-level management background, relevant industry knowledge, and prior external quality assessment experience. Those are marks of a credible team, not requirements, and not every qualified assessor carries all of them.

So the honest answer to how often is not five years. It is at least every five years, and more often when something has changed enough to make the last one stale. Some functions choose a shorter interval on purpose, and we have seen it work well in practice, particularly where a board or regulator wants a fresher read than the minimum gives them.

Which brings us to the part of the cadence that runs continuously underneath it.

Internal Audit Quality Assessment Runs Continuously, Not on the Same Five-Year Clock

Standard 12.1 sits underneath the external requirement and describes two distinct activities: ongoing monitoring of the function's conformance with the Standards and progress toward its performance objectives, and periodic self-assessments. Those results are communicated to the board and senior management.

Ongoing means what it says. It is not an annual exercise with a different label. Standard 12.2 covers performance measurement and Standard 12.3 covers overseeing and improving engagement performance, and together with 12.1 they form the Quality Assurance and Improvement Program that the external assessment eventually evaluates.

That is the structural point worth sitting with. The external assessor is not assessing your function directly so much as assessing whether your own quality program works. A function with no functioning internal assessment has already failed the external one before the assessor arrives.

The next question is what actually resets that clock early.

Three Triggers That Pull an Internal Audit Quality Assessment Forward Early

The five-year floor assumes a reasonably stable function. Several changes make a longer gap hard to defend.

A change in chief audit executive is the clearest one. A new CAE inheriting a function has every reason to want an independent read on what they have taken on, and doing that early is far easier than discovering it in year four. There is a timing point too. Conformance issues surfaced in the first months belong to the prior regime, and fixing them is a win the new CAE gets to own. After a year, even the ones that predate them are theirs. A significant change in the organization is the second: an acquisition, a new regulator, a move into a new jurisdiction, or a restructure that changes what the audit universe even contains.

The third is a material shift in methodology. A function that has rebuilt its risk assessment, adopted new audit management technology, or substantially changed how it staffs engagements is running a different operating model than the one last assessed. The certificate on the wall describes a function that no longer exists.

Full stop: an assessment that describes a function you have since rebuilt is a document, not assurance.

Each of those triggers is internal. There is a fourth category that moves on its own schedule regardless of what you do.

The Quality Assessment Framework Keeps Moving, and Internal Audit Conformance Follows

The 2024 Standards became the basis on which external quality assessments are now conducted, which means conformance is measured against a framework that has itself changed recently.

The Topical Requirements are the live example, and the IIA states that quality assessments conducted after a requirement's effective date will assess conformance with it. Cybersecurity took effect on 5 February 2026, and Third-Party Risk takes effect on 15 September 2026, with Organizational Behavior following on 15 December 2026 and Organizational Resilience on 30 April 2027. A function assessed before 9 January 2025 was measured against the 2017 framework, which contained none of them, and one assessed during 2025 predates every Topical Requirement's effective date. That is not a criticism of those assessments. It is arithmetic about what was in scope at the time.

There is a broader version of this problem. The framework moves on a multi-year cadence while risk moves continuously, and the space between those two clocks is the exposure. It belongs to the function, not to the framework. A function waiting for the framework to name a risk before covering it has misread the mandate, because risk-based planning under the Standards already requires coverage of the risks that matter.

That gap between the two clocks is also the practical argument for not letting the assessment interval stretch to its maximum.

Annual Board Reporting Is the Internal Audit Quality Cadence Most Functions Underuse

Standard 8.3 sets what goes to the board, and it is more than a conformance statement. The communication covers conformance with the Standards, achievement of performance objectives, compliance with laws and regulations relevant to internal audit where applicable, and plans to address deficiencies and opportunities.

Delivered annually and honestly, that communication does something a five-yearly report cannot. It keeps the board's picture of audit quality current, and it means no finding in the eventual external assessment arrives as a surprise to the people who oversee the function.

It also changes the character of the external assessment when it comes. An assessor walking into a function that has been reporting candidly on its own gaps for four years is validating a self-aware program. An assessor walking into silence is doing discovery, and discovery is where uncomfortable findings live.

The Internal Audit Quality Cadence Looks Like Four Layers, Not One Date

Put together, the Standards describe a rhythm rather than an event.

Ongoing evaluation happens continuously, built into how engagements are supervised and reviewed. Periodic self-assessment happens on a defined internal schedule. Board communication happens at least annually and carries the honest version. External assessment happens at least every five years, and sooner when a trigger fires.

Functions that run all four rarely find the external assessment difficult, because by the time the assessor arrives there is nothing in the file they have not already told the board about. Functions that run only the last one experience the assessment as an audit of themselves, which is exactly the dynamic the Quality Assurance and Improvement Program was designed to prevent.

What to Do When Your Last Internal Audit Quality Assessment Is Overdue

Start by establishing the actual date rather than the remembered one. Then check it against the triggers above: has the CAE changed, has the organization changed materially, has the methodology changed, and has the framework moved underneath you since then. If two or more of those are yes, the interval is doing less work than the calendar suggests. The framework question now has a concrete shape. If your last assessment predates the Cybersecurity Topical Requirement, it never tested your coverage of that area, and the Third-Party, Organizational Behavior, and Organizational Resilience requirements arrive over the next eight months. An assessment scheduled for 2027 will be scoped against all four, so that readiness work belongs in the gap assessment, not in the assessor's report.

From there the useful step is a gap assessment rather than a full external assessment, particularly if you are more than a year out. It gives you a defensible remediation plan and turns the eventual assessment into confirmation instead of discovery. We have written about what an external quality assessment actually includes if you want the scope detail before deciding which one you need.

The framework is going to keep moving, and the next Topical Requirement will land whether or not the function is ready for it. Building the internal cadence now is what makes the five-year date a formality rather than a deadline.

If you are working out where your function sits against Standard 8.4, or what the interval should realistically be given what has changed, our internal audit quality assessment work starts with exactly that question. Reach out and we can look at it with you.

Subscribe now to join the Risk Register community: