The Global Internal Audit Standards 2024: What Software Can Evidence, Standard by Standard

How the IIA's Global Internal Audit Standards are built, which standards software can help evidence, which remain professional judgement, and an honest view of AuditEDMS today.

CS
Creodata Solutions Team
The Global Internal Audit Standards 2024: What Software Can Evidence, Standard by Standard

Short answer: The IIA's Global Internal Audit Standards, effective since 9 January 2025, end every standard with examples of evidence of conformance. Software cannot conform for you, but it can hold much of that evidence: engagement communications, information gathered and its source, supervision and sign-off, findings and the follow-up of agreed actions, documentation and its retention. Judgements about risk, sufficiency, the significance of findings and conclusions stay with internal auditors. Check each tool against the standards one by one.

This guide is for chief audit executives, heads of internal audit and quality assurance leads who are preparing for an external quality assessment, or choosing software and wanting to know what it will and will not evidence. It explains how the Standards are organised, then goes through the standards where software matters, and closes with where our own product stands today.

Creodata sells audit management software, including internal audit management software, so the last column of the main table is about our product, and it says "not yet" where that is the truth. The other columns apply to any tool. This is a practical guide, not professional advice: the Standards themselves, your charter and your regulator decide what conformance means for your function.

How the Standards are built

The IIA released the Global Internal Audit Standards on 9 January 2024, and they took effect on 9 January 2025. They sit in the IIA's International Professional Practices Framework (IPPF), alongside Topical Requirements and Global Guidance.

DomainPrinciplesStandards
I. Purpose of Internal Auditingnone (a statement of purpose)none
II. Ethics and Professionalism1 to 5: integrity, objectivity, competency, due professional care, confidentiality1.1 to 5.2
III. Governing the Internal Audit Function6 to 8: authorised by the board, positioned independently, overseen by the board6.1 to 8.4
IV. Managing the Internal Audit Function9 to 12: plan strategically, manage resources, communicate effectively, enhance quality9.1 to 12.3
V. Performing Internal Audit Services13 to 15: plan engagements, conduct engagement work, communicate results and monitor action plans13.1 to 15.2

That is 15 principles and, by our count of the table of contents, 52 standards. Each standard has three parts:

  • Requirements, which use "must" and are mandatory.
  • Considerations for Implementation, which use "should" and "may" and describe common and preferred practice.
  • Examples of Evidence of Conformance, which the Standards say are neither requirements nor the only ways to show conformance. They exist to help functions prepare for quality assessments.

The third part is where software earns its place. A quality assessment relies on demonstrable evidence, and much of that evidence is records: minutes, sign-offs, dated communications, documented supervision.

Topical Requirements

Topical Requirements are a mandatory part of the IPPF and take effect 12 months after they are issued. According to the IIA's topical requirements page, as at September 2026:

Topical RequirementEffective
Cybersecurity5 February 2026
Third-Party15 September 2026
Organizational Behavior15 December 2026
Organizational Resilience30 April 2027

The IIA also says an Anti-Corruption Topical Requirement is to be issued in the fourth quarter of 2026. Each one adds requirements for engagements on that topic, so check the IIA's page for the current list before planning.

What software can evidence, and what it cannot

A useful rule: software can prove that something happened, when, by whom and with what. It cannot prove the thing was right.

  • Software can hold: dated communications, the information received and its source, who completed and approved each stage, versions of documents, time spent, and retention of the file.
  • Software cannot decide: whether a risk assessment is sound, whether evidence is sufficient, whether a finding is significant, or whether a conclusion follows. Those are the auditor's judgement, and the Standards place them there.

A tool that claims to "make you conformant" is overclaiming. A tool that keeps the evidence where an assessor will look for it saves real time.

Standard by standard

The table covers the standards where software makes a practical difference. Titles are as in the IIA's published Standards. "AuditEDMS today" uses three labels: Supported (a fresh deployment holds this evidence), Partly (it holds some of it) and Not yet.

StandardEvidence software can holdWhat remains professional judgementAuditEDMS today
5.1 Use of InformationAccess controls and a record of who opened or changed whatWhether information is used appropriatelyPartly: Microsoft Entra ID sign-in, permissions checked on every request, audit trail; policy acknowledgements are not held
5.2 Protection of InformationCustody, retention and restricted access for engagement recordsWhat may be released, and to whomSupported: files in your SharePoint, retention dates by document type, legal hold, permissions
8.4 External Quality AssessmentAn engagement record an assessor can inspectThe assessment itself, by a qualified independent assessorPartly: a printable compliance view of each engagement and an audit trail
9.3 MethodologiesThe IIA's examples include documentation of a software program incorporating methodologiesDesigning the methodologySupported: an internal audit template of engagement stages and evidence gates, ready to use and adjusted to your methodology at implementation
9.4 Internal Audit PlanThe approved plan, risk assessment inputs, changesThe organisation-wide risk assessment and prioritisationNot yet
10.1 Financial Resource ManagementThe plan against budget and actual spendingWhether resources are adequatePartly: time against planned hours; approved travel and petty-cash requests; no function budget
11.3 Communicating ResultsReports and trend analysis for the boardThemes and the overall conclusionPartly: dashboards and reports with CSV export; a follow-up register of open and overdue actions across engagements; no thematic roll-up of findings
12.1 Internal Quality AssessmentCompleted review checklists and monitoring resultsThe self-assessment's conclusionsPartly: stage completions, sign-offs and the audit trail support workpaper-review checks; no quality programme module
12.2 Performance MeasurementMeasures such as days to report and hours against planChoosing the objectives and targetsPartly: time against plan, stage dates, dashboards
12.3 Oversee and Improve Engagement PerformanceDocumented supervision, retainedThe quality of the reviewSupported: stage sign-offs, approvals recording who approved and on whose behalf, audit trail
13.1 Engagement CommunicationNotification, meetings and requests, datedWhat to communicate and howSupported: notification and entrance meeting stages with their documents
13.2 to 13.6 Engagement planningThe planning memorandum and approved work programmeRisk assessment, objectives, scope, criteria, resources and the work programmePartly: planning memorandum as a stage and document; no structured risk assessment or work programme
14.1 Gathering InformationA description of information gathered: source, date and periodRelevance, reliability and sufficiencySupported: document request lists, auditee uploads, chasers, receipts
14.2 Analyses and Potential Engagement Findings; 14.3 Evaluation of Findings; 14.5 Engagement ConclusionsStructured findings with criteria, condition, cause, effect and their significanceEvery one of those judgementsPartly: findings recorded with severity and supporting evidence; the evaluation and the conclusions stay the auditor's judgement
14.4 Recommendations and Action PlansEach recommendation with management's agreed action, owner and due dateWhether the recommendation and action fit the riskSupported: each finding holds the recommendation, management's response and the agreed action plan with owner and due date
14.6 Engagement DocumentationDocumentation reviewed, approved by the chief audit executive, retainedWhether it would let another auditor repeat the workSupported for evidence received, sign-offs, retention and the archive stage; working papers stay in your working-paper tool
15.1 Final Engagement CommunicationThe final report and evidence of its review and approvalIts contentSupported as stages and documents: draft report, management responses, final report
15.2 Confirming the Implementation of Recommendations or Action PlansA tracking system with finding, action plan, status and confirmationWhether the action addresses the riskSupported: implementation status from agreed to implemented and verified, verification by someone other than the person who recorded it implemented, risk acceptance with a note, a dated follow-up log, and a follow-up register of open and overdue actions

Two rows deserve emphasis. Standard 15.2's own examples of evidence start with a routinely updated tracking system holding each finding, its action plan, its status and internal audit's confirmation. AuditEDMS holds that in the same system as the engagement: each action moves from agreed to implemented, and someone other than the person who recorded it implemented confirms it; action owners are recorded by name and are not emailed by the system, so follow-up with them is still yours. The gap is Standard 9.4, a plan resting on a documented assessment of the organisation's strategies, objectives and risks, which is outside the product.

Standard 10.3, Technological Resources, is different: it asks the chief audit executive to try to make sure the function has the technology its work needs, and to review that technology regularly. Whatever tool you use, keep the record of that evaluation.

Using the table before an external assessment

Standard 8.4 requires an external quality assessment at least once every five years. In Kenya's public sector, regulation 166 of the Public Finance Management (National Government) Regulations, 2015 asks for a professional assessment by a recognised body once every three to five years, and regulation 161 requires public-sector internal auditors to comply with the IPPF.

A practical sequence:

  1. List the evidence examples for each standard in scope, from the Standards document itself.
  2. Mark where each piece lives today: a system, a shared drive, email, or nowhere.
  3. Close the "nowhere" rows first. These are the ones an assessor will find.
  4. Decide what a tool should hold, using the table above as a starting point, and keep judgement records where your methodology puts them.
  5. Test a sample engagement end to end before the assessment: can you show the notification, the information received and its source, the supervision, the final report's approval, the status of each agreed action and the retention date in minutes, not days?

Where Creodata fits

AuditEDMS is audit management software that runs each internal audit engagement through its stages, with evidence gates that stop a stage completing until the document it depends on is filed, and stages that complete in order. Document request lists go to auditees, who upload through an expiring link after confirming their email with a one-time code, with no account. Every document is filed to your SharePoint by auditee, engagement and document type, versioned and checksummed, with retention dates and legal hold. Findings are recorded with severity, recommendation, management's response and an agreed action with owner and due date; each action is followed to implementation and confirmed by someone other than the person who recorded it implemented, and a follow-up register shows what is open and overdue across engagements. Time is recorded against engagement and stage, approvals are recorded, and every action is written to an audit trail. The internal audit template, from notification to final report and archiving, is ready to use and adjusted to your methodology at implementation.

It runs in your own Azure subscription, in the region you choose, with documents in your own SharePoint; Creodata operates it through standing management access recorded in your Azure activity log. It does not hold working papers, and it does not yet have an audit universe or a risk-based annual plan. If those are must-haves today, say so when you talk to us. Pilots are by invitation, and pricing is on request.

For the request list in detail, see our guide to the internal audit request for information.

Frequently asked questions

When did the Global Internal Audit Standards take effect?

On 9 January 2025. The IIA released them on 9 January 2024, with a year to prepare.

Can software make an internal audit function conform with the Standards?

No. Conformance depends on how the function is governed, managed and performs its work, much of which is judgement. Software can hold the evidence that the requirements were met, which is what quality assessments rely on.

Which standards matter most when choosing internal audit software?

Look first at 14.1 (information gathered), 14.6 (engagement documentation), 12.3 (supervision), 5.2 (protection of information) and 15.2 (confirming implementation). Then check 9.4 if you want the plan in the same tool.

Are the Topical Requirements optional?

No. They are a mandatory part of the IPPF, and each takes effect 12 months after it is issued. They apply to engagements on the topic they cover.


See how AuditEDMS internal audit management software holds the evidence for Standards 5.2, 12.3, 13.1, 14.1, 14.4, 14.6 and 15.2: request a pilot.

See Audit Management Software in action.