What the IIA’s Latest Standards Say About Audit Quality and Workpapers
The Global Internal Audit Standards Raise the Bar: Quality Must Be Built Into Every Engagement
Internal Audit departments have always produced workpapers.
The more important question is:
Do those workpapers demonstrate that a high-quality audit was actually performed?
The Institute of Internal Auditors fundamentally updated the profession’s framework when the Global Internal Audit Standards™ became effective on January 9, 2025. The Standards are now the principal basis for evaluating and elevating the quality of an Internal Audit function.
For Chief Audit Executives, Audit Managers, and staff auditors, the message is significant.
Audit quality is not something that should be inspected into an engagement after fieldwork is finished.
Quality needs to be embedded throughout:
Planning → Risk Assessment → Fieldwork → Evidence → Workpapers → Supervision → Conclusions → Reporting → Follow-Up → Continuous Improvement
And the workpapers are where much of that quality becomes visible.
The First Big Change: Quality Is More Than Compliance With the Standards
The IIA's current framework takes a broader view of quality.
Under the new Standards, a Quality Assurance and Improvement Program—or QAIP—is intended to evaluate whether the Internal Audit function:
Conforms with the Global Internal Audit Standards.
Achieves its performance objectives.
Pursues continuous improvement.
That distinction matters.
An Internal Audit department should not define quality simply as:
“We complied with the Standards.”
Compliance is necessary.
But the IIA's current framework also asks whether the Internal Audit function is performing effectively and continuously improving.
That changes how CAEs should think about audit quality.
Principle 12: Enhance Quality
One of the most important areas of the new Global Internal Audit Standards is Principle 12 — Enhance Quality.
The IIA describes quality as combining two concepts:
Conformance with the Global Internal Audit Standards
Achievement of the Internal Audit Function's Performance Objectives
The QAIP becomes a primary mechanism for determining whether both are happening.
This means quality isn't solely the responsibility of whoever conducts the external quality assessment every five years.
Quality is an everyday management responsibility.
Standard 12.1: Internal Quality Assessment
The new Standards require internal quality assessment that includes both ongoing monitoring and periodic self-assessment of the Internal Audit function.
That should matter to every Audit Manager.
Ongoing monitoring can involve questions such as:
Are engagements properly supervised?
Are workpapers being reviewed?
Are engagement objectives being achieved?
Are findings supported by evidence?
Are methodologies being followed?
Are reports accurate and useful?
Are engagements completed efficiently?
Are review comments revealing recurring problems?
The IIA's current quality guidance also emphasizes ongoing monitoring, periodic internal quality assessments, meaningful performance measures, and external quality assessment as elements of a documented and functioning QAIP.
In other words:
Quality assurance should operate while Internal Audit is doing the work—not only after the work is finished.
Workpapers Are Where Audit Quality Becomes Evident
An Internal Audit report tells stakeholders what Internal Audit concluded.
The workpapers should demonstrate why those conclusions were reasonable.
Consider the evidence chain:
Engagement Objective
↓
Risk
↓
Control
↓
Audit Procedure
↓
Evidence Obtained
↓
Testing Results
↓
Exceptions
↓
Auditor's Analysis
↓
Conclusion
↓
Finding
↓
Final Communication
If that chain breaks anywhere, the quality of the engagement becomes questionable.
A polished audit report cannot repair inadequate underlying audit work.
Engagement Documentation Is Not an Administrative Afterthought
The current Global Internal Audit Standards explicitly address engagement documentation within the standards governing the performance of Internal Audit engagements.
This is important because auditors sometimes view documentation as something completed after the analysis:
“I finished the testing. Now I need to document it.”
That mindset is backwards.
Documentation should develop as the engagement develops.
The workpaper is where the auditor demonstrates the relationship among:
Risk, procedure, evidence and conclusion.
A well-designed Internal Audit methodology should therefore make documentation part of performing the audit—not clerical cleanup at the end.
A Workpaper Should Explain Why the Procedure Exists
Suppose an auditor tests 25 purchase transactions.
The workpaper says:
“Selected 25 invoices and tested for approval. No exceptions noted.”
That may document what happened.
But it doesn't necessarily demonstrate a high-quality audit.
A reviewer should be able to determine:
Why were purchase approvals important?
What risk was being addressed?
What control was expected to mitigate the risk?
How was the population determined?
Why was the testing approach appropriate?
What constituted an exception?
What did the results allow Internal Audit to conclude?
The better documentation model is:
Objective → Risk → Control → Procedure → Evidence → Results → Conclusion
That structure allows the reviewer to follow the auditor's reasoning.
Workpapers Need Sufficient Information to Support the Engagement
Documentation should support the engagement results and conclusions.
That doesn't mean documenting everything the auditor encountered.
More documentation isn't automatically better documentation.
The objective should be sufficient, relevant, reliable, and useful documentation that allows the work performed and conclusions reached to be understood.
A 40-page workpaper containing poorly organized information may be less useful than a five-page workpaper that clearly demonstrates:
Objective
Population
Procedure
Evidence
Exceptions
Analysis
Conclusion
Audit quality should not be measured by file size.
Evidence and Workpapers Are Not the Same Thing
This distinction is critical.
Suppose management gives the auditor a spreadsheet containing 10,000 transactions.
Saving that spreadsheet in the electronic workpaper system does not automatically make it persuasive evidence.
The auditor still needs to consider:
Where did the information come from?
Who prepared it?
Is the population complete?
Is it accurate?
Was the information altered?
Is it relevant to the procedure?
Does it actually support the conclusion?
The workpaper should document how the evidence was evaluated—not merely demonstrate that the auditor possessed the file.
Supervision Is Part of Audit Quality
Audit workpapers also provide the primary mechanism through which supervisors evaluate engagement quality.
A manager should not merely review workpapers for:
Spelling
Formatting
Cross-references
Tick marks
Sign-offs
Those are housekeeping matters.
A substantive quality review asks:
Does the procedure address the risk?
Was the procedure actually performed?
Is the evidence adequate?
Were exceptions properly investigated?
Does the evidence support the conclusion?
Does the proposed finding accurately represent what was found?
That is where workpaper review becomes quality assurance rather than administrative review.
Exceptions Are Where Professional Judgment Becomes Visible
Suppose the auditor tests 40 transactions and identifies four exceptions.
A weak workpaper might say:
“Four exceptions identified. Management stated these were isolated. No additional work considered necessary.”
That is a conclusion.
But where is the analysis?
A quality review should ask:
Were the exceptions similar?
What caused them?
Did the control fail?
Was the control overridden?
Are the exceptions evidence of a design deficiency?
Could the same problem exist elsewhere in the population?
Was additional testing warranted?
What evidence supports management's claim that they were isolated?
The auditor should document enough reasoning that another experienced professional can understand why the conclusion followed from the evidence.
Quality Means Separating Design From Operating Effectiveness
Another frequent documentation weakness involves control testing.
Suppose the auditor tests a monthly management review control and finds that it was performed every month.
The auditor concludes:
“Control operating effectively.”
Maybe.
But another question comes first:
Is the control appropriately designed to address the identified risk?
A control can be performed perfectly and still fail because it was poorly designed.
The workpapers should distinguish:
Design Effectiveness
If the control operates as intended, is it capable of addressing the identified risk?
Operating Effectiveness
Did the control actually operate as designed during the period under review?
Concluding on operating effectiveness without understanding design effectiveness can produce false assurance.
Quality Also Means Measuring the Internal Audit Function
The IIA's current framework places more explicit emphasis on performance objectives and measurement.
The QAIP is not merely about identifying nonconformance. It also evaluates whether Internal Audit is achieving its objectives and improving over time.
That suggests CAEs should look beyond simplistic measures such as:
“We completed 95% of the audit plan.”
Useful performance indicators might also consider:
Engagement cycle time
Timeliness of reporting
Stakeholder feedback
Repeat findings
Implementation of corrective actions
Quality-review results
Workpaper review comments
Staff competency
Achievement of engagement objectives
Audit Committee satisfaction
Improvement initiatives
The exact metrics should fit the Internal Audit function.
The objective is to determine whether the function is producing quality assurance that creates value.
The Board Has a Quality Role Too
The current Standards also strengthen the governance dimension of quality.
Under Standard 8.3 — Quality, the CAE must develop, implement, and maintain a QAIP covering all aspects of the Internal Audit function.
At least annually, the CAE must communicate internal quality-assessment results to the board and senior management. External quality-assessment results are reported when completed. Those communications include conformance with the Standards, achievement of performance objectives, relevant legal or regulatory compliance where applicable, and plans for addressing deficiencies and improvement opportunities.
That means QAIP should not be buried inside the Internal Audit department.
The Audit Committee or other appropriate board body should have visibility into Internal Audit's quality.
External Quality Assessment Remains a Major Requirement
The five-year external quality assessment remains an important element of the IIA framework.
Under Standard 8.4 — External Quality Assessment, the CAE must develop an external-assessment plan and discuss it with the board. An external assessment must occur at least once every five years and must involve a qualified, independent assessor or assessment team.
The important point is that an external assessment should not be the first time anyone seriously examines audit quality.
A mature QAIP should already be identifying:
Problems → Root Causes → Corrective Actions → Improvement
before the external assessor arrives.
Workpaper Review Can Become a Source of Quality Data
This creates an interesting opportunity for CAEs.
Review notes shouldn't simply disappear when the engagement closes.
Aggregate them.
Suppose workpaper reviews repeatedly identify problems involving:
Poorly defined objectives
Weak risk statements
Inadequate sampling documentation
Unsupported conclusions
Failure to investigate exceptions
Missing evidence
Poorly developed causes
Weak recommendations
Those aren't merely individual auditor mistakes.
They may reveal a systemic Internal Audit quality problem.
Perhaps the methodology is weak.
Perhaps training is inadequate.
Perhaps supervision is inconsistent.
Perhaps workloads are unreasonable.
Perhaps competency is insufficient.
A good QAIP should help the CAE identify those patterns.
AI Can Become a Powerful Workpaper Quality-Control Tool
The IIA's current emphasis on quality also arrives at an interesting moment: Internal Audit departments are rapidly adopting artificial intelligence.
AI can potentially help evaluate workpaper quality.
For example, an appropriately approved and secured AI environment could be prompted to:
“Identify conclusions in this workpaper that do not appear adequately supported by documented evidence.”
Or:
“Determine whether each audit procedure can be traced to an identified risk.”
Or:
“Identify exceptions for which the documented follow-up appears incomplete.”
Or:
“Act as an experienced Internal Audit Manager. Review this workpaper and develop the five most important review questions.”
Or:
“Identify management representations that have not been independently corroborated.”
That could make first-level quality review considerably more efficient.
But there is a critical limitation:
AI can review the documentation. It cannot magically fix inadequate audit evidence.
If the auditor never performed the necessary procedure, AI cannot make the workpaper compliant simply by improving the prose.
Don't Use AI to Make Bad Workpapers Look Good
This may become one of the biggest quality risks facing Internal Audit.
An auditor performs weak fieldwork.
Then the auditor uploads the notes to AI.
AI produces an impressive, professional-looking narrative.
The resulting workpaper looks excellent.
But the underlying evidence remains weak.
That creates a dangerous situation:
Poor Audit Work
Excellent AI Writing
=
Professional-Looking Poor Audit Work
CAEs and Audit Managers need to recognize this risk.
AI should improve analysis and documentation.
It should never be used to conceal deficiencies in the underlying audit work.
The Quality Test Every Audit Manager Should Apply
A reviewer should be able to take the workpapers and reconstruct the engagement:
What were we trying to accomplish?
What were the significant risks?
What controls addressed those risks?
What procedures did we perform?
What evidence did we obtain?
What exceptions did we identify?
How did we evaluate those exceptions?
What conclusions did we reach?
Does the report accurately reflect those conclusions?
If the reviewer cannot answer those questions from the engagement documentation, there is a quality problem.
The Bigger Message From the New IIA Standards
The most important lesson isn't that Internal Auditors need more documentation.
It is that Internal Audit functions need a systematic approach to quality.
The current IIA framework ties together:
Professional Standards
↓
Internal Audit Methodology
↓
Engagement Supervision
↓
Workpaper Quality
↓
Performance Measurement
↓
Internal Quality Assessment
↓
Board Oversight
↓
External Quality Assessment
↓
Continuous Improvement
That is considerably more powerful than treating QAIP as something the CAE worries about every five years.
The IIA describes an effective QAIP as essential for demonstrating performance, maintaining conformance, and focusing on continuous improvement.
The Bottom Line
The Global Internal Audit Standards send a clear message about audit quality:
Quality must be managed.
It should be visible in the methodology.
It should be visible in supervision.
It should be visible in the workpapers.
It should be visible in performance measures.
It should be visible to the Audit Committee.
And it should be continuously improved.
The workpaper remains one of the best places to determine whether that is actually happening.
A quality workpaper should demonstrate a defensible chain:
Objective → Risk → Control → Procedure → Evidence → Exception → Analysis → Conclusion
If that chain is strong, the audit report has a solid foundation.
If that chain is weak, better formatting and better writing will not solve the problem.
For Internal Audit leaders implementing the IIA's current Standards, that may be the most important quality lesson of all:
Don't inspect quality into the audit at the end. Design quality into the audit from the beginning.
For the authoritative source, see the IIA Global Internal Audit Standards and IPPF documents and the IIA's current Quality Assurance and Improvement Program guidance

Comments