Stay connected: follow us on LinkedIn and explore more at
www.CherryHillAdvisory.com.

Subscribe now to join the Risk Register community:
Most chief audit executives know they need an external quality assessment. Fewer know what one actually tests until they are six weeks in and fielding document requests they weren't expecting.
That gap between knowing the requirement exists and understanding what satisfies it is where functions lose ground. And the requirement moved. The 2024 Global Internal Audit Standards took effect on January 9, 2025, so every assessment scheduled for 2026 and 2027 is being scoped against a framework most functions have never been assessed under.
This is what an assessor tests, domain by domain, and the order of work that gets you through it well.
An external quality assessment under the 2024 Standards evaluates conformance across the five domains of the framework, and the quality requirements themselves sit in Domain III, Governing the Internal Audit Function. Standard 8.3 requires the chief audit executive to maintain a quality assurance and improvement program with both external and internal assessments. Standard 8.4 requires the external one at least once every five years by a qualified, independent assessor or assessment team, with at least one active Certified Internal Auditor on it.
The rating scale changed with the 2024 edition of the IIA's Quality Assessment Manual. The IIA's quality services FAQ describes a four-level scale, and the top of it is now full conformance, a rating the 2017 framework's "generally conforms" ceiling never offered. If your last report topped out at generally conforms, the bar for the next one is higher, and it is explicit.
Assessors work through the domains in order, which means the first thing they examine is not your methodology. It is your governance.
Under Domain III, the assessor is testing whether internal audit is authorized by the board (Principle 6), positioned independently (Principle 7), and overseen by the board (Principle 8). In practice that means board meeting minutes, the audit committee charter, the internal audit charter, the chief audit executive's reporting line and evaluation process, and whether the function reaches the board without management filtering the message.
Independence is evaluated at two levels: organizational independence, which is structural, and individual objectivity, which is about who gets assigned to what. A function that looks independent on paper but operates under constant management pressure on findings is not independent in practice, and a rigorous assessment surfaces that distinction.
Standard 8.3 also makes the board's role explicit. The board is expected to discuss the quality program with the chief audit executive, approve the function's performance objectives at least annually, and assess the function's effectiveness and efficiency. Assessors look for evidence that those conversations happened, not for a policy saying they should.
Once governance clears, the assessor turns to Domain IV, Managing the Internal Audit Function, and the first requirement there is one many functions have never written down.
Standard 9.2 requires the chief audit executive to "develop and implement a strategy for the internal audit function that supports the strategic objectives and success of the organization." It must "include a vision, strategic objectives, and supporting initiatives," and it must be reviewed with the board and senior management periodically.
This is a fundamental addition in the 2024 Standards and it is not universally understood. A risk-based audit plan is not a strategy. The Standards describe the vision as the desired future state of the function over, for example, the next three to five years, with strategic objectives as achievable targets and supporting initiatives as the specific steps to reach them. An assessor will ask for the document, ask when the board last saw it, and ask how the audit plan connects to it.
If you cannot produce that today, it is the single highest-return piece of preparation on this list, and it shapes how the rest of the assessment reads.
The IIA is explicit on its Topical Requirements page: "quality assessments conducted after the effective date will assess conformance with effective Topical Requirements." For an assessment in 2026 or 2027, that list is moving.
The Cybersecurity Topical Requirement has been in effect since February 5, 2026. The Third-Party Topical Requirement becomes effective September 15, 2026, Organizational Behavior on December 15, 2026, and Organizational Resilience on April 30, 2027. Talent Management goes to public consultation in October 2026 and Anti-Corruption is slated for issue in Q4 2026, and each one becomes effective 12 months after it is issued.
So the scope of your assessment depends on its date. A function assessed in early 2027 will be tested on four Topical Requirements that did not exist in the framework its last assessment used. Most of the readiness work we are seeing now is against 2026 and 2027 proposals for exactly this reason: the requirement that applies to you is the one in effect on the day the assessor arrives, not the one that was in effect when you booked them.
Which parts of your current audit universe would need to change to show conformance with the Third-Party Topical Requirement by this time next year?
Domain IV also covers how the function builds its audit universe and prioritizes its plan, and Domain V covers how it performs the work. Assessors examine whether the risk assessment is systematic, whether it takes input from senior leadership and the board, and whether the resulting plan maps to the organization's highest-risk areas. The distance between what the plan said and what actually got done becomes visible here. Deferred high-risk audits become findings.
For execution, the assessment team pulls a sample of completed engagements across the function's range of work and tests them against the Standards' requirements for planning, fieldwork, communication, and supervision. Workpaper review is granular: whether objectives tie to the risk assessment, whether conclusions are supported by evidence, whether exceptions were escalated, and whether supervisory review is documented. "It's all in the reviewer's head" is not documented review. Full stop.
Report quality gets the same treatment. Findings buried in qualifications, recommendations too vague for management to act on, and ratings that don't match the evidence are recurring observations. The assessor is judging whether your reporting informs the board or just documents activity.
Then the assessor turns to the system behind all of that work.
An assessment does not only evaluate the function's output. It evaluates the system the function uses to monitor and improve itself. Standard 12.1 requires ongoing monitoring plus periodic self-assessments, with results and action plans communicated to the board and senior management. It also says that "internal assessments must be documented and included in the evaluation conducted by an independent third party as part of the organization's external quality assessment."
Read that as an instruction. Your internal assessment records are an input to the external one. Common gaps: the QAIP exists as a policy but was never operationalized, a self-assessment was done once and never repeated, metrics are tracked but never analyzed. The assessor will ask for evidence that the function uses its quality program, not just that it has one.
Which is why the order of work matters more than the volume of it.
The functions that get through an assessment cleanly are rarely the ones with the most sophisticated methodology. They are the ones whose documentation matches what actually happened, and who found their own gaps first.
Our sequence runs in three steps. Start with the self-assessment Standard 12.1 already requires, done honestly against the 2024 Standards rather than the 2017 framework. Then run a structured gap assessment: a readiness review that identifies Standards gaps, evaluates the QAIP documentation, and produces targeted recommendations before a formal opinion is on the line. Only then commission the external quality assessment. The gaps get closed on your timeline instead of appearing in a report your board reads.
Done in that order, the external assessment stops being a discovery exercise and becomes a validation of work you have already done.
Cherry Hill Advisory is an IIA Authorized Licensee, one of a small number of firms globally licensed to use the IIA's Global Internal Audit Standards and Quality Assessment Manual, and senior specialists lead every engagement. There is no layered delivery model.
Our Q360 methodology runs in four phases: fact-finding through leadership interviews, document review, and data analysis; benchmarking your function against leading practices and peer organizations; a 90-day action plan on the items that most strengthen the function's effectiveness and credibility; and the full evaluation of maturity and alignment with the 2024 Standards. Every external quality assessment we issue goes through an independent panel consistency review before the final opinion, and the result is verifiable through our certification portal, so your audit committee and your regulators can confirm the outcome directly.
The deliverables go beyond a conformance rating: a maturity assessment with benchmarking, organization-wide stakeholder insight, and a strategic improvement roadmap with prioritized recommendations, which doubles as the starting point for the internal audit strategy Standard 9.2 now expects you to have.
Boards are paying closer attention to internal audit quality than they were five years ago, and the 2024 Standards gave them the vocabulary to ask sharper questions. The next disruption, whether it arrives through AI governance, a third-party failure, or a new regulatory expectation, will find the functions with a current assessment and an active quality program in a much easier conversation than the ones that let the five-year clock run out. If your assessment is on the calendar for 2026 or 2027, reach out through our external quality assessment page and we will map the readiness work to your date.
Subscribe now to join the Risk Register community: