---
# === IDENTITY ===
id: business/governance/internal-audit/2026
canonical_question: "How do I structure an internal audit function — three lines of defense and risk-based planning?"
aliases:
  - "internal audit function"
  - "three lines of defense"
  - "three lines model"
  - "risk-based audit planning"
  - "IIA standards"
entity_type: concept
domain: business > governance > Internal Audit
region: global
jurisdiction: global
temporal_scope: 2020-2026

# === VERIFICATION ===
last_verified: 2026-02-28
confidence: 0.91
version: 1.0
first_published: 2026-02-28

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: stable
  last_breaking_change: 2020-07-01
  next_review: 2026-08-27
  change_sensitivity: low

# === CONSTRAINTS ===
constraints:
  - "The Three Lines Model (2020) replaced the Three Lines of Defense (2013) — the updated model emphasizes value creation alongside protection, and removes the 'defense' framing"
  - "Internal audit must be organizationally independent — reporting to management (rather than the board/audit committee) compromises objectivity and violates IIA standards"
  - "Risk-based audit planning requires a current enterprise risk assessment — if ERM is immature, audit planning defaults to cyclical coverage, which is less effective"
  - "Small organizations (under 500 employees) may not justify a dedicated internal audit function — co-sourcing or outsourcing models are viable alternatives"
  - "Prerequisite: the organization must have a functioning governance body (board or audit committee) to which internal audit reports"

skip_this_unit_if:
  - condition: "User needs to build the overall risk management program, not just audit it"
    use_instead: "business/governance/erm-framework/2026"
  - condition: "User needs external audit or financial statement audit guidance"
    use_instead: "business/governance/internal-audit/2026"

inputs_needed:
  - key: "audit_need"
    question: "What is the user's internal audit objective?"
    type: choice
    options:
      - "Establishing an internal audit function from scratch"
      - "Understanding the Three Lines Model for risk governance"
      - "Building a risk-based audit plan"
      - "Evaluating whether to insource, co-source, or outsource internal audit"

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/business/governance/internal-audit/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-02-28)"

# === RELATED UNITS ===
related_kos:
  related_to:
    - id: "business/governance/erm-framework/2026"
      label: "Enterprise Risk Management Framework"
    - id: "business/governance/board-composition/2026"
      label: "Board Composition"
  often_confused_with:
    - id: "business/governance/erm-framework/2026"
      label: "ERM (risk management vs. risk assurance)"
  depends_on:
    - id: "business/governance/erm-framework/2026"
      label: "ERM Framework (risk-based audit planning depends on risk assessment)"
  solves: []
  alternative_to: []

# === SOURCES ===
sources:
  - id: src1
    title: "The IIA's Three Lines Model: An Update of the Three Lines of Defense"
    author: The Institute of Internal Auditors
    url: https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf
    type: official_docs
    published: 2020-07-01
    reliability: authoritative
  - id: src2
    title: "Three Lines of Defense in Risk Management: ERM Framework Guide"
    author: Diligent
    url: https://www.diligent.com/resources/blog/three-lines-of-defense
    type: industry_report
    published: 2025-01-01
    reliability: high
  - id: src3
    title: "How to Apply the Three Lines of Defense"
    author: IANS Research
    url: https://www.iansresearch.com/resources/all-blogs/post/security-blog/2025/06/25/how-to-apply-the-three-lines-of-defense
    type: industry_report
    published: 2025-06-25
    reliability: high
  - id: src4
    title: "The IIA's New Three Lines Model for Risk Assurance"
    author: Hyperproof
    url: https://hyperproof.io/resource/iia-three-lines-model-risk/
    type: technical_blog
    published: 2025-01-01
    reliability: moderate_high
  - id: src5
    title: "Three Lines Model Offers Logical Risk Management for Banks"
    author: Baker Tilly
    url: https://www.bakertilly.com/insights/three-lines-model-risk-management-for-banks
    type: industry_report
    published: 2025-01-01
    reliability: high
---

# Internal Audit Function

## Definition

The internal audit function is an independent, objective assurance and consulting activity that evaluates and improves the effectiveness of an organization's risk management, control, and governance processes. Under the IIA's Three Lines Model (2020), internal audit serves as the third line — providing independent assurance to the governing body on the adequacy of first-line (operational management) and second-line (risk management and compliance) activities. [src1] Risk-based audit planning aligns audit resources with the organization's highest-priority risks rather than cycling through all business units on a fixed rotation. [src2]

## Key Properties

- **Three Lines Model (2020)**: First line — management owns and manages risk; Second line — risk, compliance, and quality functions provide expertise and oversight; Third line — internal audit provides independent assurance [src1]
- **Reporting line**: Internal audit reports functionally to the audit committee/board and administratively to senior management (typically CEO or CFO) to preserve independence [src4]
- **Risk-based planning**: Annual audit plan is derived from enterprise risk assessment, focusing resources on areas of highest residual risk [src2]
- **IIA Standards**: Global Internal Audit Standards (updated 2024) govern professional practice, independence, proficiency, and quality assurance [src1]
- **Delivery models**: In-house (dedicated team), co-sourced (internal CAE + external specialists), or fully outsourced — choice depends on organization size and risk complexity [src3]

## Constraints

- Internal audit must be organizationally independent — if the Chief Audit Executive (CAE) reports to the CFO without a functional reporting line to the audit committee, objectivity is compromised. [src1]
- Risk-based audit planning is only as good as the underlying risk assessment — if ERM is immature, the audit plan will not cover the most important risks. [src2]
- Internal audit provides assurance, not management — auditors should not design controls, make operational decisions, or take ownership of risk responses. [src4]
- The Three Lines Model is a conceptual framework, not an organizational chart — the "lines" describe roles, not departments. One team may perform functions across multiple lines. [src1]
- Resource constraints in small organizations often mean the internal audit function cannot cover all significant risks in a single year — multi-year audit plans with annual rotation are common. [src3]

## Framework Selection Decision Tree

```
START — User needs governance/risk assurance guidance
├── What is the primary need?
│   ├── Independent assurance over risk management and controls
│   │   └── ✅ Internal Audit function (this unit)
│   ├── Build the risk management program itself
│   │   └── → ERM Framework (COSO)
│   ├── Financial statement audit (external)
│   │   └── → External audit standards (ISA/PCAOB)
│   ├── Regulatory compliance monitoring
│   │   └── → Second-line compliance function
│   └── Board governance structure
│       └── → Board Composition
├── Organization size?
│   ├── >500 employees → In-house internal audit function likely justified
│   ├── 100-500 → Co-sourced model (internal CAE + external specialists)
│   └── <100 → Outsourced internal audit or combined assurance approach
└── Is there a functioning audit committee?
    ├── YES → Internal audit reports functionally to it
    └── NO → Establish audit committee first (see Board Composition)
```

## Application Checklist

### Step 1: Establish the internal audit charter
- **Inputs needed**: Organizational structure, audit committee charter, regulatory requirements
- **Output**: Board-approved internal audit charter defining purpose, authority, and reporting lines
- **Constraint**: The charter must establish a functional reporting line to the audit committee — reporting solely to management violates IIA standards [src1]

### Step 2: Assess the risk universe and build the audit plan
- **Inputs needed**: Enterprise risk assessment (from ERM), prior audit findings, regulatory focus areas
- **Output**: Risk-based annual audit plan with prioritized engagements
- **Constraint**: If no enterprise risk assessment exists, conduct audit-specific risk assessment — do not default to a purely cyclical plan [src2]

### Step 3: Execute engagements and report findings
- **Inputs needed**: Audit plan, access to systems and personnel, testing methodology
- **Output**: Audit reports with findings, root causes, and management action plans
- **Constraint**: Findings must be communicated to appropriate levels of management and the audit committee — suppressing unfavorable findings destroys audit credibility [src4]

### Step 4: Monitor remediation and perform quality assurance
- **Inputs needed**: Outstanding management action plans, prior audit findings, quality metrics
- **Output**: Follow-up verification of remediation, annual quality self-assessment
- **Constraint**: IIA Standards require periodic external quality assessments (at least every 5 years) — this is not optional [src1]

## Anti-Patterns

### Wrong: Internal audit reports only to the CFO
The CAE reports to the CFO with no functional reporting line to the audit committee. The CFO can suppress findings about financial reporting risks. [src1]

### Correct: Dual reporting with audit committee primacy
The CAE reports functionally to the audit committee (who approves the charter, plan, and budget) and administratively to the CEO for day-to-day operations. [src4]

### Wrong: Cyclical audit plan ignoring risk
Every business unit gets audited on a three-year cycle regardless of risk. High-risk areas are underaudited while low-risk areas consume audit resources. [src2]

### Correct: Risk-based audit planning
Derive the audit plan from the enterprise risk assessment. High-risk areas are audited annually; low-risk areas are audited every 3-5 years or through continuous monitoring. [src3]

### Wrong: Internal audit designing controls
Auditors are asked to help design the controls they will later audit, destroying their independence and objectivity. [src4]

### Correct: Advise but do not manage
Internal audit can advise on control design as a consulting engagement but must not take responsibility for implementing or operating controls. [src1]

## Common Misconceptions

- **Misconception**: Internal audit is the same as external audit.
  **Reality**: Internal audit provides ongoing assurance to the board on risk management and controls. External audit provides an opinion on financial statements to shareholders. Different objectives, different standards, different reporting lines. [src1]

- **Misconception**: The Three Lines of Defense means three separate departments.
  **Reality**: The IIA's Three Lines Model (2020) explicitly states that the lines describe roles, not organizational structures. A single person or team may perform functions across multiple lines, especially in smaller organizations. [src1]

- **Misconception**: Internal audit only finds problems after the fact.
  **Reality**: Modern internal audit includes consulting, continuous auditing, and data analytics to provide real-time insights. Risk-based planning focuses on prevention as much as detection. [src3]

## Comparison with Similar Concepts

| Concept | Key Difference | When to Use |
|---|---|---|
| Internal Audit (Third Line) | Independent assurance over risk and controls | Board/audit committee needs objective risk assurance |
| ERM (Second Line) | Builds and operates the risk management framework | Organization needs to identify and manage risks |
| External Audit | Opinion on financial statement accuracy | Shareholders/regulators need financial statement assurance |
| Compliance Function (Second Line) | Monitors regulatory compliance | Organization needs to track regulatory obligations |

## When This Matters

Fetch this when a user asks about establishing an internal audit function, the Three Lines Model, risk-based audit planning, internal audit reporting lines, or the difference between internal and external audit. Also relevant when an organization is deciding between insourcing, co-sourcing, or outsourcing internal audit.

## Related Units

- [Enterprise Risk Management Framework](/business/governance/erm-framework/2026)
- [Board Composition](/business/governance/board-composition/2026)
