1. Ad hoc
Audits are reactive, checklist-driven and heavily dependent on individual auditors. Evidence, review notes and follow-up are inconsistent.
Internal audit maturity is not how polished the report looks. It is whether the function has a clear mandate, risk-based plan, repeatable methodology, reviewable evidence, disciplined follow-up and a measurable improvement programme.
Download the Excel/PDF pack for maturity scoring, evidence requirements, QAIP actions, 30-60-90 day roadmap and future Internal Audit product data-model fields.
Audits are reactive, checklist-driven and heavily dependent on individual auditors. Evidence, review notes and follow-up are inconsistent.
Common templates exist for planning, RCMs, reports and ATR, but quality still varies by team, location or engagement.
Methodology, risk assessment, work programmes, supervision, evidence standards and reporting formats are documented and followed.
Dashboards, KPIs, quality review, issue ageing, resource capacity and continuous monitoring are measured and acted on.
Internal audit is risk-led, data-enabled, continuously improving and able to advise management without weakening independence.
Assessment question: Does internal audit have a clear charter, reporting line, independence safeguards and audit committee visibility?
Evidence: Charter, board/audit committee minutes, SOW approvals, reporting protocol and escalation rights.
Upgrade move: Refresh the charter and link every engagement to approved governance coverage.
Assessment question: Is the audit universe risk-ranked and converted into an executable annual plan?
Evidence: Audit universe, risk scoring, annual plan, capacity plan, quarter loading and deferral rationale.
Upgrade move: Move from calendar rotation to risk-based planning with documented capacity constraints.
Assessment question: Do cycles use a consistent methodology from walkthrough to RCM, test, evidence and observation?
Evidence: Methodology map, cycle RCMs, programme library, reviewer prompts and version history.
Upgrade move: Create one control repository and tailor it per engagement instead of rebuilding from old files.
Assessment question: Can every conclusion be traced to source reports, samples, test results, exceptions and reviewer conclusions?
Evidence: PBC tracker, sampling plan, fieldwork tracker, evidence references, exception log and review sign-off.
Upgrade move: Standardise source-report metadata and evidence escalation before report drafting.
Assessment question: Do reports separate condition, criteria, cause, effect, recommendation, rating, response and follow-up?
Evidence: Report pack, observation register, management response, audit committee summary and ATR ageing.
Upgrade move: Use one observation ID from fieldwork through report, dashboard and closure testing.
Assessment question: Are file reviews, supervision, methodology exceptions and improvement actions documented?
Evidence: Quality review checklist, review notes, coaching actions, methodology changes and QAIP tracker.
Upgrade move: Treat review comments as improvement data, not only engagement clean-up.
Assessment question: Are repeatable exception rules defined, validated and tied to workpapers before reporting?
Evidence: Monitoring rules, source fields, thresholds, false-positive clearing and validated issue handoff.
Upgrade move: Prioritise a small number of high-signal rules before building broad dashboards.
Assessment question: Is AI use by the IA team approved, documented and reviewed separately from AI risks in the business?
Evidence: AI strategy, approved-use register, data boundaries, prompt/tool records and AI governance workpapers.
Upgrade move: Separate "using AI for audit work" from "auditing AI used by the business".
Assessment question: Does the team have enough hours, skills and specialist coverage for the approved plan?
Evidence: Capacity planner, skills matrix, co-sourcing map, training log and workload dashboard.
Upgrade move: Make resource constraints visible before the plan is approved, not after slippage starts.
Assessment question: Does internal audit influence process owners and leadership through timely, usable insights?
Evidence: Management feedback, repeat-finding trend, closure ageing, committee actions and advisory requests.
Upgrade move: Measure whether audit actions close root causes, not only whether reports are issued.
Lock charter, SOW format, audit universe, current plan, report format and open ATR list.
Build the RCM repository, PBC tracker, sampling template, fieldwork tracker and quality review checklist.
Create committee dashboard KPIs, top continuous monitoring rules and capacity plan.
Run QAIP review, calibrate ratings, train reviewers and retire duplicated legacy templates.
Move mature repeatable areas into continuous monitoring and product workflow design.
Global reference for internal audit purpose, governance, professional practice, quality and performance expectations.
India reference point for Standards on Internal Audit and the 2026 SIA framework used by Indian internal auditors.
Reference point for assessing whether the internal audit function improves quality systematically instead of only reviewing individual files.
This website page is a public maturity resource. The reusable layer for the separate Internal Audit product build is the scoring model, evidence fields, roadmap states, QAIP tracker and analytics-readiness gates.
Product shape: Internal Audit setup assessment
Likely fields: Domain, level, evidence, gap, target state, owner, due date.
Product shape: Implementation planner
Likely fields: Milestone, dependency, effort, priority, owner, dashboard status.
Product shape: Quality management workflow
Likely fields: Review finding, root cause, methodology change, training need, closure evidence.
Product shape: Continuous monitoring rollout
Likely fields: Rule candidate, data readiness, owner, threshold, pilot status.
Use the lifecycle map to benchmark whether methodology is actually defined.
Use file-review gates as the engagement-level QA layer.
Use dashboards to measure managed and optimised maturity levels.
Use current risk themes to test whether planning is forward-looking.
Translate maturity gaps into hours, skills and co-sourcing needs.
Assess whether IA AI use is governed before scaling it.
An internal audit maturity assessment evaluates how consistently the function governs, plans, executes, reviews, reports and improves internal audit work. It should produce a practical improvement roadmap, not only a maturity score.
A practical maturity model should cover mandate, risk planning, methodology, RCMs, evidence, reporting, follow-up, QAIP, analytics, AI governance, talent, capacity and stakeholder impact.
No. File review checks whether one engagement is ready. QAIP looks across the internal audit activity and asks whether supervision, methodology, quality, training and improvement actions are systematic.
Use maturity results to prioritise a 30-60-90 day roadmap, assign owners, improve templates, train reviewers, fix evidence gaps and decide which activities are ready for analytics or continuous monitoring.