Skip to main content
Category: Internal Audit and Assurance

International Professional Practices Framework

Also known as: IPPF, IPPF
Simply put

The International Professional Practices Framework (IPPF) is a structure created by The Institute of Internal Auditors (IIA) that organizes the authoritative guidance for the internal audit profession. It brings together standards, requirements, and guidance into a single blueprint that internal auditors can look to when carrying out their work.

Formal definition

The IPPF is the conceptual framework promulgated by The Institute of Internal Auditors (IIA) that organizes the authoritative body of knowledge for internal auditing, encompassing internal audit standards, requirements, and supporting guidance. It functions as a structural blueprint for the professional practice of internal audit. As guidance issued by a professional body rather than a legislature or regulator, the IPPF is generally a professional standard adopted by internal audit functions and IIA members rather than binding law; its applicability and the extent to which it is mandated depend on organizational policy, jurisdiction, sector, and any regulatory or listing requirements that may incorporate it by reference. This entry is educational and not legal, audit, or compliance advice.

Why it matters

The IPPF matters because it gives the internal audit profession a common reference point for what constitutes competent, consistent practice. Rather than leaving each internal audit function to define quality on its own terms, the framework organizes the authoritative guidance promulgated by The Institute of Internal Auditors into a single structure that practitioners can look to when planning, executing, and reporting on their work. This shared foundation supports comparability across organizations and helps the audit committee and other stakeholders understand the professional basis on which the internal audit function operates.

For boards and their audit committees, alignment of the internal audit function with the IPPF is often a signal of assurance quality, because it indicates the function is working against a recognized body of standards and guidance rather than ad hoc expectations. It is important to be precise about the framework's authority, however: the IPPF is guidance issued by a professional body, not a statute, regulation, or listing rule. Its applicability generally depends on organizational policy and on the extent to which any regulator, listing regime, or contractual arrangement chooses to incorporate it by reference. Whether and how it binds a particular function therefore varies by jurisdiction, sector, and entity type.

Because the IPPF sits within the assurance side of governance, its significance is tied to the role of internal audit as a function that provides independent, objective assurance and advice to the board and management. It does not transfer oversight duties from the board or operational risk management responsibilities from management; rather, it structures the professional practice of the assurance activity that supports both. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Chief Audit Executives and Internal Auditors
Internal audit leaders and practitioners are the primary users of the IPPF. They generally look to the framework to organize the standards, requirements, and guidance that inform how they plan, conduct, and report on their work, and to demonstrate that the function operates against a recognized professional structure. The extent to which they are required to conform depends on the audit charter and any applicable external requirements.
Audit Committees and Boards
Audit committees and boards oversee the internal audit function and often consider its alignment with the IPPF when evaluating the quality and credibility of the assurance they receive. Their interest is oversight-oriented; the framework informs their expectations of the function without transferring the function's operational responsibilities to the board.
IIA Members and the Professional Community
The IPPF is promulgated by The Institute of Internal Auditors, so IIA members and the broader internal audit profession rely on it as the organizing structure for the profession's authoritative body of knowledge. Membership and professional expectations may drive adoption even where no legal or regulatory requirement exists.
Regulators, Listing Authorities, and Standard-Setters
In certain jurisdictions or sectors, regulators or listing regimes may reference or incorporate the IPPF into their expectations for internal audit. Where this occurs, the framework's guidance can take on additional weight for affected entities, though this varies and should be confirmed against the specific applicable requirements.

Inside IPPF

Purpose of the Framework
The International Professional Practices Framework (IPPF) is the conceptual structure, typically issued by The Institute of Internal Auditors (IIA), that organizes authoritative guidance for the internal audit profession. It is designed to promote consistency and quality in internal audit practice globally, though it applies to organizations and practitioners that choose to adopt or represent conformance with IIA guidance rather than as binding law.
Mandatory Guidance
Historically the IPPF distinguished mandatory elements, generally including the Core Principles for the Professional Practice of Internal Auditing, the Definition of Internal Auditing, the Code of Ethics, and the Standards, which internal audit functions claiming conformance are expected to follow. 'Mandatory' here means required for conformance with IIA guidance, not a legal obligation imposed by statute or regulation.
Recommended Guidance
The Framework has also included recommended (non-mandatory) guidance, such as implementation and supplemental guidance, intended to help practitioners apply the mandatory elements. This material describes practices and approaches but does not carry the same conformance expectation as the mandatory components.
Standards for Professional Practice
A central component addressing attributes of internal audit functions and individuals as well as the nature and performance of audit engagements. The Standards articulate expectations around matters such as independence, objectivity, proficiency, due professional care, and quality assurance, and are principles-based rather than a detailed rulebook.
Code of Ethics
A component setting out principles and rules of conduct, commonly framed around concepts such as integrity, objectivity, confidentiality, and competency, relevant to the practice of internal auditing. It governs the conduct of internal auditors who represent conformance with IIA guidance.
Position of the Internal Audit Function
The IPPF frames internal audit as an assurance and advisory function that provides independent, objective assurance to the board and its audit committee, typically as part of the third line in the common three-lines model. It is distinct from management's own risk and control activities (first and second lines) and from external audit.

Common questions

Answers to the questions practitioners most commonly ask about IPPF.

Is the International Professional Practices Framework a legal or regulatory requirement?
Generally, no. The IPPF is issued by The Institute of Internal Auditors (IIA) as authoritative professional guidance for internal auditors, not as binding law. It becomes obligatory for individuals and functions that hold themselves out as conforming with IIA standards or that are contractually or by policy required to do so. Some jurisdictions, sectors, or organizational charters may reference or effectively mandate conformance for certain internal audit functions, so whether it applies as a requirement depends on the entity, its sector, and any governing rules or commitments. These entries are educational and not legal, audit, or compliance advice.
Does the IPPF cover the entire governance, risk, and compliance system?
No. The IPPF is focused on the practice of internal auditing, an assurance and advisory function, rather than on governance, risk management, or compliance as a whole. Internal audit typically provides independent assurance over the design and operating effectiveness of governance, risk, and control processes, but it does not own or operate those processes. Ownership of risk management and compliance activities generally sits with management, while oversight typically rests with the board and its committees. The IPPF guides how internal audit performs its role within that broader structure, not the structure itself.
How is the guidance within the IPPF structured, and which parts are considered mandatory?
The IPPF is generally organized into components that carry different weight. Certain elements, typically including core principles and the standards, are treated as mandatory guidance for those who assert conformance, while other elements are recommended or implementation guidance that supports application. Because the IIA periodically updates the framework's structure and terminology, functions should confirm the current composition directly from the IIA and clarify internally which components they treat as binding for their own conformance assertions.
How should an internal audit function demonstrate conformance with the IPPF?
Conformance is typically demonstrated through evidence that the audit function's charter, methodology, and practices align with the framework's mandatory elements, supported by documentation of engagements, planning, and reporting. Many functions confirm conformance through a periodic external quality assessment, often complemented by ongoing and periodic internal assessments. Whether and how frequently such assessments occur can depend on the function's commitments, its charter, and any applicable sector expectations, so the specifics should be set out in the function's own quality assurance and improvement program.
What is the relationship between the IPPF and the audit committee or board?
Under the IPPF, the internal audit function generally reports functionally to a board-level body, commonly the audit committee, which supports its independence and objectivity, while reporting administratively to management. The framework typically envisions the board or its committee approving the audit charter, the audit plan, and resourcing, and receiving the results of assurance work. This preserves the distinction between the board's oversight role and management's operational responsibility. The precise reporting lines and committee arrangements vary by entity, jurisdiction, and applicable listing or regulatory expectations.
How does the IPPF interact with risk frameworks such as COSO or ISO 31000?
The IPPF and enterprise risk frameworks address different responsibilities and are not substitutes for one another. Frameworks such as COSO's internal control and enterprise risk management frameworks or ISO 31000 generally provide models that management may use to design and operate risk and control processes. The IPPF guides how internal audit provides independent assurance over those processes. In practice, an audit function may assess whether management's chosen framework is applied effectively, but selecting and operating a risk framework remains management's responsibility, not internal audit's.

Common misconceptions

The IPPF is legally binding on all organizations.
The IPPF is professional guidance issued by a professional body, not statute, regulation, or listing rules. Its mandatory elements are 'mandatory' in the sense of being required for a function to claim conformance with IIA guidance; whether an organization is required to have an internal audit function or follow such guidance depends on jurisdiction, sector, listing status, and entity type.
Following the IPPF means internal audit owns the organization's risk management and controls.
The Framework positions internal audit as an independent assurance and advisory function, generally the third line. Ownership of risks and the design and operation of controls typically rests with management (the first and second lines), while the board and its audit committee provide oversight. Conflating these roles undermines internal audit's independence and objectivity.
The IPPF is a detailed checklist that dictates exactly how every audit must be performed.
The Standards are largely principles-based, setting expectations rather than prescribing step-by-step procedures. Applying them requires professional judgment tailored to the organization's size, complexity, and circumstances, supported by non-mandatory recommended guidance.

Best practices

Confirm which version and components of the IPPF apply to your function, and document how the internal audit charter, methodology, and quality program align with the mandatory elements before representing conformance.
Preserve internal audit's independence and objectivity by keeping assurance activities separate from management's ownership of risks and controls, and by reporting functionally to the board or audit committee.
Establish and maintain a quality assurance and improvement program, including periodic internal and external assessments, to support and evidence conformance claims rather than assuming conformance.
Apply the principles-based Standards using professional judgment scaled to the organization's size, complexity, and risk profile, and retain rationale for how requirements were interpreted and met.
Treat the IPPF as professional guidance and confirm any legal or regulatory obligations affecting internal audit separately, since requirements vary by jurisdiction, sector, and entity type.
Coordinate with other assurance providers and management, clarifying respective roles across the lines of the three-lines model to avoid gaps or overlaps in coverage.