Skip to main content
Category: Internal Audit and Assurance

Audit Charter

Also known as: Internal Audit Charter, Internal Audit Activity Charter
Simply put

An audit charter is a formal document that sets out the purpose, authority, and responsibilities of an organization's internal audit function. It serves as the internal audit team's 'marching orders,' clarifying what they are empowered to do and how they operate. The charter helps establish and protect internal audit's role within the organization.

Formal definition

An internal audit charter is a formal, board-approved document that defines and articulates the internal audit activity's purpose, authority, scope, and responsibilities, and establishes its position within the organization. It typically empowers the internal audit function, provides guidance for its work, and helps protect its independence. Under professional guidance, internal auditing is generally expected to be performed by competent professionals in conformance with The IIA's Global Internal Audit Standards; the charter often references such conformance. The internal audit charter should be distinguished from an audit committee charter, which sets out the responsibilities of the board's audit committee rather than those of the internal audit function itself. Specific content, approval processes, and requirements vary by jurisdiction, sector, and entity type, and this entry is educational rather than legal or audit advice.

Why it matters

The audit charter is foundational to the internal audit function's ability to operate effectively and independently. Without a formal document that defines its purpose, authority, and responsibilities, an internal audit activity can find its mandate contested, its access to information restricted, or its independence compromised. The charter serves as the internal audit team's "marching orders," establishing in writing what the function is empowered to do and where it sits within the organization. This clarity matters most when internal audit examines sensitive areas or reports findings that management may find unwelcome.

Because the charter is typically board-approved, it anchors internal audit's authority in the governance structure rather than in management, which helps protect the function's independence and objectivity. It signals that internal audit derives its standing from the board or its audit committee, reinforcing the separation between the function performing assurance work and the management activities it reviews. The charter also often references conformance with professional standards, such as The IIA's Global Internal Audit Standards, which are set in the public interest and provide a recognized benchmark for how internal auditing is expected to be performed by competent professionals.

It is important not to conflate the internal audit charter with the audit committee charter. The former defines the responsibilities and authority of the internal audit function; the latter sets out the responsibilities of the board's audit committee. These are distinct documents serving distinct governance purposes, and specific content, approval processes, and requirements vary by jurisdiction, sector, and entity type.

Who it's relevant to

Board and Audit Committee Members
The board, often acting through its audit committee, typically approves the internal audit charter and thereby anchors the function's authority and independence in the governance structure. Members rely on the charter to understand what internal audit is empowered to do and to distinguish the internal audit function's responsibilities from those set out in the separate audit committee charter.
Chief Audit Executives and Internal Auditors
Internal audit leaders use the charter as their "marching orders," defining purpose, authority, scope, and responsibilities and helping protect the function's independence. Practitioners can also draw on professional resources, such as The IIA's practice guide and model template, to create and evaluate their charter, and often reference conformance with The IIA's Global Internal Audit Standards.
General Counsel and Governance Professionals
Those responsible for governance documentation help ensure the internal audit charter is properly drafted, board-approved, and distinguished from the audit committee charter. Because content and approval requirements vary by jurisdiction, sector, and entity type, these professionals tailor the document to the organization's circumstances and applicable expectations.
Management
Management is subject to internal audit review rather than the owner of internal audit's oversight role, and the charter clarifies the boundary between the two. Understanding the charter helps management appreciate the authority the function has been granted, including expectations around access and cooperation, while recognizing that internal audit's standing derives from the board or audit committee.

Inside Audit Charter

Purpose, Authority, and Responsibility Statement
A foundational section that establishes the internal audit function's mandate, its authority to access records, personnel, and physical property relevant to engagements, and the scope of its responsibilities. This typically defines what the function is empowered to do rather than describing specific audit procedures.
Position and Reporting Lines
A description of the function's placement within the organization, commonly including a functional reporting line to the board or its audit committee and an administrative reporting line to senior management. This dual arrangement is generally intended to support the objectivity and organizational independence of internal audit.
Independence and Objectivity Provisions
Language safeguarding the function from interference in determining audit scope, performing work, and communicating results. It may address the chief audit executive's access to the board and restrictions on assuming operational responsibilities that could impair objectivity.
Scope of Internal Audit Activities
A statement of the types of assurance and advisory activities the function may undertake, which can span governance, risk management, and internal control processes. The charter generally sets boundaries rather than prescribing a fixed annual plan.
Standards of Practice
A reference to the professional standards the function commits to follow, such as a recognized internal auditing framework or code of ethics. Adoption of such standards is typically a voluntary professional commitment rather than a universal legal requirement, though certain entities may face standards through listing rules or sector regulation.
Approval and Review Provisions
A clause identifying who approves the charter, commonly the audit committee or board, and how frequently it is reviewed and updated to remain aligned with the organization's needs and governance structure.

Common questions

Answers to the questions practitioners most commonly ask about Audit Charter.

Does the audit charter give internal audit the authority to manage or fix the risks and controls it reviews?
No. The charter typically establishes internal audit's mandate to provide independent assurance and advisory services, not to own, manage, or remediate risks and controls. Ownership of controls and remediation generally rests with management (commonly framed as the first and second lines), while internal audit evaluates their design and operating effectiveness. Blurring this distinction can compromise the independence and objectivity the charter is meant to protect. Where internal audit performs advisory work, charters generally set boundaries to preserve objectivity for future assurance engagements. This is educational and not audit or compliance advice; specific arrangements depend on the entity and its governance structure.
Is an audit charter a legally mandated document required of every organization?
Not universally. Whether a formal audit charter is required depends on jurisdiction, sector, entity type, and any applicable listing rules or regulatory expectations. A documented charter is a widely recognized professional practice and is expected under certain professional standards and governance codes, but these can function as principles-based or voluntary guidance rather than binding law in a given setting. Some regulated entities may face more specific expectations. Organizations should confirm what applies to them based on their own facts and obligations; this entry is educational and not legal advice.
Who typically approves the audit charter, and how often is it reviewed?
In many governance structures, the audit committee (or an equivalent board committee) approves the charter, reflecting internal audit's reporting relationship to the board for oversight purposes, while a senior executive such as the chief audit executive is often responsible for drafting and proposing it. Charters are commonly reviewed on a periodic basis, such as annually, and updated when there are significant changes to the organization, its structure, or relevant standards. Exact approval authority and review cadence vary by entity and any applicable rules.
What elements are commonly included in an audit charter?
Charters generally address internal audit's purpose and mandate, its authority (including access to records, personnel, and property), its scope of work, its independence and objectivity, and its reporting relationships to the board or audit committee and administratively to management. Many also reference the professional standards the function intends to follow, the nature of assurance and advisory services provided, and expectations around resourcing. The precise contents depend on the organization's needs, structure, and any applicable frameworks, so this list is illustrative rather than prescriptive.
How does the audit charter support internal audit's independence?
The charter typically reinforces independence by defining a functional reporting line to the audit committee or board for matters such as approval of the audit plan, the charter itself, and appointment or removal decisions, while administrative reporting often runs to management. It commonly grants unrestricted access to information needed to perform engagements and articulates that internal audit does not hold operational responsibility for the activities it reviews. These structural features are intended to protect objectivity, though independence in practice also depends on culture, resourcing, and how the arrangements are applied.
How does the audit charter relate to the annual audit plan and other governance documents?
The charter generally sets the foundational mandate and authority, while the audit plan operationalizes that mandate by identifying specific engagements over a period, typically informed by a risk assessment. The charter may cross-reference other documents such as the audit committee's terms of reference, relevant policies, and the professional standards adopted, but it does not usually duplicate their content. Keeping the charter distinct from the plan helps preserve the difference between the function's standing authority and its periodic, risk-based scheduling of work.

Common misconceptions

An audit charter is a legally mandated document that every organization must adopt in a prescribed form.
Whether a formal audit charter is required depends on jurisdiction, sector, and entity type. For some listed or regulated entities, listing rules or regulators may expect an internal audit function and a defining document, but the specific requirement and its form vary. In many organizations the charter reflects adoption of voluntary professional standards rather than a single universal legal obligation. Entries here are educational and not legal, audit, or compliance advice.
The audit charter and the audit committee charter are the same document.
These are generally distinct. An audit charter typically defines the internal audit function's purpose, authority, and responsibilities, whereas an audit committee charter defines the mandate and duties of a board committee that provides oversight. The board or audit committee often approves the internal audit charter, but the two documents serve different roles and owners.
Because the charter grants broad authority and independence, internal audit can take on management or operational responsibilities.
The charter's independence provisions are generally intended to keep internal audit objective. Assuming operational or management duties can impair that objectivity. Internal audit typically provides assurance and advisory input on governance, risk, and control, while management retains ownership of risks and controls and the board or committee retains oversight.

Best practices

Have the charter formally approved by the board or its audit committee and establish a schedule for periodic review so it remains aligned with the organization's structure and governance needs.
Clearly articulate both functional and administrative reporting lines to reinforce the internal audit function's independence and objectivity.
Define the scope of activities and the function's authority to access records, personnel, and property, while avoiding language that could draw internal audit into operational or management responsibilities.
Reference the professional standards and code of ethics the function commits to, and note that such adoption is generally a voluntary professional commitment unless a specific rule or regulation applies to the entity.
Distinguish the internal audit charter from the audit committee charter to keep ownership, purpose, and accountability clear across governance documents.
Ensure the charter delineates the respective roles of the board, its committees, management, and the internal audit function so oversight and operational duties are not conflated, and treat the document as tailored to the organization's own facts and jurisdiction.