Skip to main content
Internal Audit ERM Charter TemplateEnterprise Risk Management
5 min readFor Internal Auditors

Internal Audit ERM Charter Template

When your board asks internal audit to "lead ERM," you need a document that defines exactly what that means. This charter template establishes boundaries, safeguards, and reporting lines to preserve audit independence while enabling meaningful risk oversight.

Purpose of This Template

This charter template addresses the governance challenge when internal audit assumes responsibilities beyond traditional assurance work in enterprise risk management (ERM). Use it to document the scope, safeguards, and accountability mechanisms required when the Chief Audit Executive takes on ERM leadership or coordination duties.

The template creates a formal agreement among the board, senior management, and the internal audit function. It distinguishes between three types of internal audit involvement: core assurance activities that require no special safeguards, expanded roles that demand documented protections, and management responsibilities that internal audit must not accept.

Prerequisites

Before implementing this template, ensure your organization meets these conditions:

Board Understanding: Your audit committee must recognize that combining ERM responsibilities with internal audit creates potential independence conflicts. They need to explicitly approve both the expanded role and the safeguards.

Separate Assurance Source: Identify who will provide independent assurance over any ERM processes that internal audit operates or coordinates. This cannot be internal audit itself.

Risk Appetite Documentation: Your board should have established and documented risk appetite and risk tolerance levels. Internal audit will assess alignment with these parameters, not set them.

Charter Authority: Your existing internal audit charter must permit amendments or supplements. Some organizations create a separate ERM responsibilities addendum rather than revising the core charter.

The Charter Template

Section 1: Scope of ERM Responsibilities

The Chief Audit Executive is assigned the following ERM coordination responsibilities:

  • Facilitate quarterly enterprise risk discussions with [specify: executive committee, risk council, business unit leaders]
  • Maintain the enterprise risk register and aggregation methodology
  • Coordinate risk reporting to the board on a [specify frequency] basis
  • Provide guidance on risk assessment frameworks and methodologies

These responsibilities are administrative and facilitative. All risk management decisions, including risk acceptance, mitigation strategy selection, and resource allocation for risk responses, remain with business unit management and the executive leadership team.

Section 2: Core Assurance Activities

Internal audit will continue to provide independent assurance over:

  • The design and operating effectiveness of the ERM framework
  • Alignment between stated risk appetite and actual risk-taking behavior
  • Reliability and completeness of risk identification and assessment processes
  • Adequacy of risk escalation and reporting mechanisms
  • Integration of risk considerations into strategic planning and decision-making

These assurance activities are performed independently of any ERM coordination responsibilities listed in Section 1.

Section 3: Safeguards for Independence

Separation of Duties: Internal audit team members who facilitate risk workshops or maintain the risk register will not lead assurance engagements over those same processes. [Name/title] will assign audit staff to ensure this separation.

External Assurance: Every [specify: two years, three years], an independent external party will assess the effectiveness of ERM processes that internal audit coordinates. The audit committee will select this external reviewer.

Transparent Reporting: The Chief Audit Executive will report separately to the audit committee on (a) assurance findings regarding ERM effectiveness and (b) administrative updates on ERM coordination activities. These will appear as distinct agenda items.

Decision Authority Limits: Internal audit will not determine which risks appear on the enterprise risk register, set risk ratings, or approve risk response plans. These decisions require executive management approval, documented in [specify: risk committee minutes, executive committee records].

Charter Review: The audit committee will review this charter annually to confirm that the combination of ERM coordination and assurance responsibilities remains appropriate.

Section 4: Prohibited Activities

Internal audit will not:

  • Own or manage enterprise risks on behalf of business units
  • Make risk acceptance decisions
  • Implement risk mitigation controls
  • Set risk appetite or tolerance levels (these are board and management responsibilities)
  • Allocate budgets for risk management initiatives

Section 5: Reporting and Accountability

The Chief Audit Executive reports to the audit committee on ERM coordination responsibilities and to the [specify: CEO, CFO, risk committee] on administrative ERM matters. Any conflicts between these reporting lines will be escalated to the audit committee chair within [specify timeframe].

Customization Guidance

Adjust Section 1 based on organizational maturity: If you're a smaller organization without dedicated risk management resources, you might expand the facilitation role. Larger organizations should limit internal audit to assurance and narrow coordination tasks.

Tailor Section 2 to your risk framework: If you use the COSO ERM Framework, reference specific components (governance and culture, strategy and objective-setting, performance, review and revision, information and communication). This makes the assurance scope more precise.

Modify Section 3 separation mechanisms: The template uses staff-level separation. Some organizations prefer time-based separation (advisory work in year one, assurance in year three) or function-based separation (different team members for coordination versus assurance).

Define "administrative" clearly: What counts as administrative versus management responsibility varies by organization. Add specific examples from your context: "Administrative includes scheduling risk committee meetings and consolidating risk reports; it does not include determining which risks require board attention."

Specify your external assurance approach: Some organizations use their external financial auditor for this; others engage a separate risk consulting firm. Document the selection criteria and scope expectations.

Validation Steps

Legal Review: Have your general counsel confirm that the charter language creates clear accountability boundaries and doesn't inadvertently assign fiduciary duties to the internal audit function.

Audit Committee Approval: Present the charter with a one-page summary explaining what internal audit will do, what safeguards protect independence, and what internal audit will not do. Get formal approval in committee minutes.

Management Acknowledgment: The CEO and business unit leaders should sign an acknowledgment that they retain risk management decision authority. This prevents future confusion about who owns risk responses.

Standards Compliance Check: Verify that the charter aligns with the Global Internal Audit Standards, particularly Standard 2.1 regarding independence and objectivity.

Annual Testing: Each year, the audit committee should review one or two specific examples of how the safeguards operated in practice. Did the external assurance provider actually review ERM processes? Did staff separation prevent conflicts? Document these validations.

The charter alone won't solve the fundamental tension between ERM leadership and audit independence. But it makes the boundaries visible, enforceable, and subject to board oversight.

You Might Also Like