Key Components of Quality Assurance
In CIA Part 3, quality of the internal audit function centers on the Quality Assurance and Improvement Program (QAIP). The chief audit executive (CAE) must develop and maintain it, and it covers every aspect of internal audit activity. Its purpose is to evaluate conformance with the IIA Standards, … In CIA Part 3, quality of the internal audit function centers on the Quality Assurance and Improvement Program (QAIP). The chief audit executive (CAE) must develop and maintain it, and it covers every aspect of internal audit activity. Its purpose is to evaluate conformance with the IIA Standards, assess whether internal auditors apply the Code of Ethics (now the Ethics and Professionalism principles under the 2024 Global Internal Audit Standards), and measure the function's efficiency, effectiveness and opportunities for improvement. The program has several key components. First, internal assessments, which come in two forms: - Ongoing monitoring is built into routine operations. Examples include engagement supervision, standardized work programs, workpaper review, approval of reports, client feedback surveys and performance metrics such as budget versus actual hours and recommendation implementation rates. - Periodic self-assessments are conducted by members of the activity or other qualified people in the organization who know internal audit practices. They evaluate conformance with the Standards more comprehensively. Second, external assessments. These must occur at least once every five years. A qualified, independent assessor or team from outside the organization performs them. They take one of two approaches: - A full external assessment. - A self-assessment with independent external validation (SAIV). The CAE discusses the form, frequency, and the assessor's qualifications and independence with the board. Any potential conflicts of interest must be considered. Third, reporting. The CAE communicates QAIP results to senior management and the board. The report covers the scope and frequency of assessments, the assessors' qualifications and independence, conclusions, and corrective action plans. Ongoing monitoring results are reported at least annually. Fourth, conformance disclosure. The internal audit activity may state that it 'conforms with the Standards' only when QAIP results support that statement. If nonconformance affects the overall scope or operation of the activity, the CAE must disclose it to senior management and the board, along with its impact. Finally, continuous improvement. Findings from assessments drive action plans, training and methodology updates. This keeps the function aligned with stakeholder expectations and adds value to governance, risk management and control processes.
Key Components of Quality Assurance: A Complete CIA Exam Guide to the Quality Assurance and Improvement Program (QAIP)
Introduction
Quality is what turns an internal audit function from a group of people who check things into a trusted, value-adding assurance provider. In the CIA syllabus, the Quality Assurance and Improvement Program (QAIP) is the formal system the internal audit activity uses to evaluate and improve its own work. This guide explains what the key components of quality assurance are, why they matter, how they work in practice and how to answer exam questions on them.
Framework note: The concepts below come from the IIA's International Professional Practices Framework (IPPF), mainly Standards 1300 to 1322 of the 2017 Standards. The 2024 Global Internal Audit Standards (GIAS) keep the same core ideas under Principle 8 (Standards 8.3 and 8.4) and Principle 12 (Standards 12.1 to 12.3). Check which framework your exam window uses, but the concepts, frequencies and roles are almost identical.
1. Why Quality Assurance Is Important
Quality assurance matters for five main reasons:
• Credibility and trust: Senior management, the board, regulators and external auditors rely on internal audit's work. A QAIP gives them evidence that this reliance is justified.
• Conformance with the Standards: The internal audit activity may only say it conforms with the IIA Standards if the results of its QAIP support that claim.
• Continuous improvement: Quality assurance is not only a compliance exercise. It finds inefficiencies, skill gaps and outdated methods so the function can improve.
• Accountability to the board: The board oversees internal audit. QAIP results give the board objective information to judge the effectiveness of the function and of the Chief Audit Executive (CAE).
• Risk reduction: Poor-quality audits can miss significant risks, fraud or control failures. Quality processes reduce the risk of wrong conclusions and reputational damage.
2. What Quality Assurance Is: The QAIP Defined
A QAIP is designed to evaluate three things:
• The internal audit activity's conformance with the Standards.
• Whether internal auditors apply the Code of Ethics (or, under GIAS, the Ethics and Professionalism principles).
• The efficiency and effectiveness of the internal audit activity, and opportunities for improvement.
The CAE is responsible for developing and maintaining the QAIP, and it must cover all aspects of the internal audit activity. The board oversees it.
The QAIP has these key components:
• Internal assessments, made up of:
(a) ongoing monitoring
(b) periodic self-assessments
• External assessments, made up of:
(a) a full external assessment, or
(b) a self-assessment with independent external validation (SAIV)
• Reporting of QAIP results to senior management and the board.
• Use of the conformance statement and disclosure of nonconformance.
3. How Each Component Works
A. Internal Assessments
(a) Ongoing monitoring
Ongoing monitoring is built into the day-to-day supervision, review and measurement of the internal audit activity. It is part of normal operations, not a separate project. Examples include:
• Engagement supervision and review of workpapers by audit managers.
• Standardized audit methodology, policies, checklists and templates.
• Feedback surveys from audit clients after engagements.
• Key performance indicators (KPIs), such as completion of the audit plan, cycle time, budget versus actual hours and acceptance rate of recommendations.
• Review and sign-off of final reports before issuance.
Key exam phrase: ongoing monitoring is continuous and embedded in routine activities.
(b) Periodic self-assessments
Periodic self-assessments are done at intervals to evaluate conformance with the Standards and the Code of Ethics more broadly. Key points:
• They are performed by members of the internal audit activity who have sufficient knowledge of internal audit practices, or by other qualified people in the organization (for example, a compliance or quality team).
• They may include reviews of a sample of completed engagements, benchmarking against leading practices, and assessment of the audit charter, the plan and resources.
• They are often used to prepare for the external assessment.
• Results are reported to senior management and the board at least annually (GIAS also requires annual communication of internal assessment results).
B. External Assessments
External assessments must be conducted at least once every five years. They are performed by a qualified, independent assessor or assessment team from outside the organization.
Qualified means competent in internal audit professional practice and in the external assessment process. GIAS requires at least one assessor to hold an active CIA designation.
Independent means there is no actual, potential or perceived conflict of interest. The assessor must not be part of, or under the control of, the organization. Note these restrictions:
• Former employees within a recent period create independence concerns.
• Reciprocal peer reviews between two organizations are not considered independent.
• Arrangements among three or more organizations (for example, A reviews B, B reviews C, C reviews A) may be acceptable.
There are two acceptable approaches:
• Full external assessment: an outside team performs the whole review.
• Self-assessment with independent external validation (SAIV): the internal audit activity performs a thorough self-assessment, and a qualified, independent external assessor validates its conclusions.
Board involvement: the CAE must discuss with the board the form and frequency of the external assessment, the qualifications and independence of the assessor or team, and any potential conflicts of interest. Under GIAS, the board must also review and approve the plan for the external assessment.
C. Reporting on the QAIP
The CAE must communicate QAIP results to senior management and the board. The communication covers:
• The scope and frequency of internal and external assessments.
• The qualifications and independence of the assessors.
• The conclusions of the assessors.
• Corrective action plans.
Timing: results of ongoing monitoring and periodic self-assessments are reported at least annually. External assessment results are reported when the assessment is completed.
D. Conformance Statement and Disclosure of Nonconformance
• The internal audit activity may state that it conforms with the International Standards for the Professional Practice of Internal Auditing only if the results of the QAIP support that statement. This means an external assessment must have been completed within the last five years.
• If nonconformance with the Code of Ethics or the Standards affects the overall scope or operation of the internal audit activity, the CAE must disclose to senior management and the board:
- the nonconformance,
- the reason for it, and
- its impact.
• A newly established function may not claim conformance until it has had an external assessment. It may still state that it is designed to operate in accordance with the Standards.
4. Summary Table in Words
• Ongoing monitoring: continuous; done by internal audit management and staff; examples are supervision, KPIs and client surveys.
• Periodic self-assessment: periodic and reported at least annually; done by internal audit staff or other knowledgeable people in the organization.
• External assessment: at least every five years; done by a qualified, independent party from outside the organization; takes the form of a full external assessment or an SAIV.
• Reporting: the CAE reports to senior management and the board.
• Responsibility: the CAE develops and maintains the QAIP; the board oversees it.
5. Practical Illustration
Imagine a bank's internal audit function.
• Ongoing monitoring: every engagement is reviewed by a manager, and each client completes a feedback survey.
• Periodic self-assessment: each year, a senior auditor not involved in the sampled engagements reviews ten completed audits against the Standards, and the CAE reports the results to the audit committee.
• External assessment: in year four, the CAE proposes an SAIV. The audit committee approves the external validator, a CIA-certified consultant with no prior relationship with the bank.
• Reporting and follow-up: the validator finds that risk-based planning partially conforms. The CAE reports this and a corrective action plan to the board.
Exam Tips: Answering Questions on Key Components of Quality Assurance
1. Memorize the numbers. External assessments are required at least once every five years. Internal assessment results go to the board at least annually. Examiners love distractors such as three years, annually for external assessments, or every two years.
2. Classify the activity. Many questions describe an activity and ask which QAIP component it is:
• Supervision, workpaper review, KPIs and post-audit surveys are ongoing monitoring.
• A scheduled review of conformance by internal staff is a periodic self-assessment.
• A review by an outside qualified party is an external assessment.
3. Focus on independence of the external assessor. If an option shows a reciprocal review between two organizations, a recent former employee, or a team from another department of the same company, it is not a valid external assessment. Outside the organization plus no conflict of interest is the test.
4. Know who does what. The CAE develops, maintains and reports on the QAIP. The board oversees it and discusses or approves the external assessment arrangements. Senior management receives results. A common trap is an option saying the external auditor or senior management is responsible for the QAIP.
5. Know both external assessment options. A full external assessment and an SAIV are both acceptable. An internal self-assessment alone, without independent validation, never satisfies the external requirement.
6. Apply the conformance statement rule. Conformance can be claimed only when QAIP results support it, including a current external assessment. If a question says the last external assessment was six years ago, the activity should not use the conformance statement.
7. Apply the nonconformance disclosure trigger. Disclosure is required when nonconformance affects the overall scope or operation of the internal audit activity. The disclosure goes to senior management and the board and covers the nonconformance, the reason and the impact. Minor isolated lapses are handled through ongoing improvement.
8. Watch for the word BEST or MOST appropriate. Several options may be partly correct. Choose the one that matches the Standards exactly. For example, ongoing monitoring is best achieved through engagement supervision, rather than through an annual survey alone.
9. Remember the purpose of the QAIP. It evaluates conformance with the Standards, application of the Code of Ethics, and efficiency and effectiveness. If an option mentions only compliance and ignores improvement, it is probably incomplete.
10. Practice with scenarios. Sample question: A CAE plans to meet the external assessment requirement by having the internal audit team of a sister subsidiary review the department. Is this acceptable? Answer: No. A sister subsidiary is part of the same organization, so the assessor is not independent and from outside the organization.
11. Keep frameworks straight. If your exam uses the Global Internal Audit Standards, link the topics to these references:
• Standard 8.3 (Quality)
• Standard 8.4 (External Quality Assessment)
• Standard 12.1 (Internal Quality Assessment)
• Standard 12.2 (Performance Measurement)
• Standard 12.3 (Oversee and Improve Engagement Performance)
Two GIAS-specific points: at least one assessor must hold a CIA, and the board approves the external assessment plan.
Final Takeaway
The key components of quality assurance are:
• internal assessments (ongoing monitoring and periodic self-assessments),
• external assessments every five years by a qualified, independent outsider,
• transparent reporting to senior management and the board, and
• honest use of the conformance statement.
Master the roles, frequencies and independence rules, and you will answer most CIA quality assurance questions with confidence.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!