Reviewing and Revising Internal Audit Strategy
In the CIA Part 3 context of Internal Audit Operations, reviewing and revising the internal audit strategy is the process by which the Chief Audit Executive (CAE) keeps the function's long-term direction aligned with the organization's evolving objectives, risks and stakeholder expectations. Under … In the CIA Part 3 context of Internal Audit Operations, reviewing and revising the internal audit strategy is the process by which the Chief Audit Executive (CAE) keeps the function's long-term direction aligned with the organization's evolving objectives, risks and stakeholder expectations. Under the IIA's Global Internal Audit Standards (Principle 9, Plan Strategically, and Standard 9.2, Internal Audit Strategy), the CAE must develop and implement a strategy that supports the organization's strategic objectives and success. The strategy includes a vision, strategic objectives and supporting initiatives covering areas such as people, methodologies and technology. The strategy is not static. The CAE should review it periodically, typically at least annually, and whenever significant changes occur. Triggers for revision include new business strategies, mergers or restructuring, emerging risks such as cybersecurity or ESG, regulatory changes, technological disruption, and shifts in board or senior management expectations. Results from the Quality Assurance and Improvement Program, including internal assessments and external quality assessments, also inform revisions. Key steps in the review process include: (1) gathering stakeholder input through discussions with the board, audit committee and senior management; (2) reassessing the organization's risk landscape and strategic priorities; (3) evaluating internal audit's current capabilities, resources, competencies and use of technology such as data analytics; (4) measuring progress against strategic objectives using key performance indicators; and (5) identifying gaps and updating initiatives, timelines and resource needs. The revised strategy must be discussed with the board and senior management to gain their support. It should then be linked to the internal audit charter, the risk-based audit plan, the budget and staff development programs. For the exam, candidates should remember that strategy review ensures internal audit remains relevant, adds value, and continuously improves. The CAE owns the strategy, the board provides oversight and support, and revisions should be documented and communicated so that internal audit activities consistently reflect organizational needs.
Reviewing and Revising Internal Audit Strategy (CIA Part 3: Internal Audit Operations)
Overview
An internal audit strategy describes how the internal audit function will fulfil its mandate, support the organization's strategic objectives and deliver value over the medium to long term, typically three to five years. It is not a one-time document. The organization, its risks and its stakeholders keep changing, so the Chief Audit Executive (CAE) must periodically review and revise the strategy to keep it relevant, achievable and aligned.
In the IIA's Global Internal Audit Standards (effective January 2025), this falls under Domain IV, Managing the Internal Audit Function. Standard 9.2, Internal Audit Strategy, requires the CAE to develop and implement a strategy that supports the organization's strategic objectives and success and aligns with the expectations of the board, senior management and other key stakeholders. The strategy must include a vision, strategic objectives and supporting initiatives. The CAE must review it with the board periodically.
Why It Is Important
1. Strategic alignment: If the organization changes its strategy (for example digital transformation, expansion into new markets, mergers or new regulation), an unchanged audit strategy quickly becomes obsolete. Regular review keeps internal audit focused on what matters most to the organization.
2. Stakeholder expectations evolve: Boards and senior management may expect more advisory work, more assurance on emerging risks (cyber, ESG, AI) or faster reporting. Reviewing the strategy lets the CAE respond.
3. Resource stewardship: Strategy drives decisions on staffing, competencies, technology and budget. Outdated strategy leads to misallocated resources.
4. Credibility and value: A function that adapts its strategy shows it is forward-looking and relevant, which enhances its standing as a trusted advisor.
5. Conformance with the Standards: Periodic review with the board is a requirement. It is also evaluated in quality assurance and improvement programs (QAIP) and external quality assessments.
6. Continuous improvement: Strategy review closes the loop between performance measurement and future direction.
What It Is
Reviewing and revising internal audit strategy is the structured, periodic process of:
1. Assessing whether the strategy is still appropriate.
2. Evaluating progress against strategic objectives and initiatives.
3. Identifying internal and external changes that require adjustment.
4. Updating the vision, objectives, initiatives, resources and timelines.
5. Communicating and obtaining board support for the revised strategy.
Key components of an internal audit strategy:
- Vision: what internal audit aspires to be, for example a trusted advisor that anticipates risk.
- Strategic objectives: measurable, achievable goals, such as expanding data analytics coverage or increasing advisory engagements.
- Supporting initiatives: actions to achieve the objectives, such as training, technology adoption, talent recruitment, methodology updates or co-sourcing.
- Performance measures: key performance indicators (KPIs) to track progress.
- Resource and capability plan: people, skills, tools and budget.
Strategy vs. audit plan: The strategy is long-term and sets direction (how the function will evolve and add value). The internal audit plan (Standard 9.4) is risk-based, usually annual or rolling, and lists specific engagements. The plan should be consistent with, and derived from, the strategy. A frequent exam trap is confusing the two.
How It Works
Step 1: Establish the review frequency and triggers
Review the strategy at least annually, with a fuller refresh every few years. Some events should trigger an off-cycle review:
- changes in organizational strategy, structure or leadership;
- mergers, acquisitions or divestitures;
- significant new regulations;
- major emerging risks (cybersecurity, pandemics, geopolitical events, AI);
- results of quality assessments, internal or external;
- significant changes in internal audit resources or budget;
- changes in board or audit committee expectations.
Step 2: Gather inputs
- Organizational strategic plans, objectives and risk assessments, including enterprise risk management (ERM) outputs.
- Stakeholder feedback from interviews and surveys with board members, senior management and other key stakeholders.
- Internal audit performance data, such as KPIs, plan completion rates, stakeholder satisfaction and recommendation implementation rates.
- QAIP results and external quality assessment recommendations.
- Industry trends, peer benchmarking and professional guidance.
- Analysis of the internal audit mandate and charter.
Step 3: Analyze the gaps
Compare the current state with the desired future state. Tools include SWOT analysis (strengths, weaknesses, opportunities, threats), PESTLE analysis, capability maturity models, skills gap analysis and technology assessments. Ask:
- Are objectives being achieved?
- Are they still the right objectives?
- Does the function have the competencies needed for emerging risks?
Step 4: Revise the strategy
Update the vision if needed, refine strategic objectives, add, modify or retire initiatives, and adjust resource plans, timelines and KPIs. Typical revisions include:
- moving to continuous auditing;
- building analytics or IT audit capability;
- increasing advisory services;
- adopting agile auditing;
- strengthening coordination and reliance on other assurance providers (Standard 9.5);
- updating methodologies.
Step 5: Communicate, discuss and obtain support
The CAE discusses the revised strategy with senior management and presents it to the board for review and support. The board's role is to understand, provide input on and support the strategy. Under the Standards' Essential Conditions, the board collaborates with the CAE on the strategy and approves the budget and resource plan.
Step 6: Implement and monitor
Translate the strategy into annual plans, budgets, training programs and technology investments. Monitor progress through KPIs and report it periodically to the board. Feed lessons learned into the next review cycle.
Roles and Responsibilities
- CAE: owns the strategy and is responsible for developing, implementing, reviewing and revising it.
- Board or audit committee: reviews the strategy, provides input and supports it. The Standards require that the CAE review the strategy with the board periodically.
- Senior management: provides input on organizational direction and risks and supports implementation.
- Internal audit staff: may contribute ideas and help implement initiatives.
- External assessors: may evaluate the strategy and recommend improvements.
Common Pitfalls
- Treating the strategy as static or a paperwork exercise.
- Failing to involve the board and stakeholders.
- Confusing the strategy with the annual audit plan.
- Setting objectives that are not measurable.
- Ignoring resource constraints or skill gaps.
- Not linking the strategy to organizational objectives.
Illustrative Example
A retail company announces a shift to e-commerce and plans to close half its physical stores. The CAE's existing strategy emphasizes store operational audits. The CAE should:
1. Trigger a strategy review.
2. Gather input from management and the board on new risks, such as cybersecurity, data privacy and digital fraud.
3. Perform a skills gap analysis, which may reveal limited IT audit expertise.
4. Revise the objectives to build IT and data analytics capability through hiring, training or co-sourcing.
5. Present the revised strategy and resource needs to the audit committee.
6. Update the risk-based audit plan to match.
Exam Tips: Answering Questions on Reviewing and Revising Internal Audit Strategy
1. Know who owns it. The CAE develops and revises the strategy. The board reviews and supports it. If an option says senior management or the board develops the strategy, it is likely wrong.
2. Distinguish strategy from plan. Long-term direction, vision and capabilities belong to the strategy. Specific engagements based on risk assessment belong to the audit plan. Read stems carefully for keywords such as vision, long-term and capabilities versus engagements and annual.
3. Alignment is the anchor. The best answer usually links the internal audit strategy to the organization's strategic objectives and stakeholder expectations.
4. Recognize triggers. When a scenario describes major organizational change, new regulation, emerging risk or QAIP findings, the correct response often is to review and revise the strategy rather than just add an audit.
5. Communication with the board is critical. Choose answers involving discussion with the board or audit committee over answers where the CAE acts unilaterally.
6. Look for the most comprehensive or first step. In BEST or FIRST questions, gathering stakeholder input or assessing organizational changes usually comes before revising initiatives. Implementing comes last.
7. Measurability matters. Strategic objectives should be measurable and tracked with KPIs. Prefer options that include monitoring progress.
8. Resource implications. When strategy changes, the CAE should assess competencies and resources and communicate any shortfalls and their impact to the board.
9. Beware of extreme options. Options such as never changing the strategy or replacing it entirely every year are usually wrong. Periodic review, typically at least annually, plus event-driven updates is the sound approach.
10. Connect to QAIP. External and internal assessment results are key inputs to strategy revision. Questions may test this link.
11. Eliminate independence threats. Answers where management dictates audit strategy in ways that impair independence or objectivity are incorrect.
Quick Recall Summary
- What: periodic evaluation and update of internal audit's vision, objectives and initiatives.
- Who: the CAE leads, the board reviews and supports, and stakeholders provide input.
- When: at least annually and whenever significant changes occur.
- How: gather inputs, analyze gaps, revise, communicate to the board, implement and monitor.
- Why: to stay aligned, relevant and resourced, conform with the Standards and maximize value.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!