CORAA
Resources · Internal Audit Maturity

Internal audit maturity assessment.

Internal audit maturity is not how polished the report looks. It is whether the function has a clear mandate, risk-based plan, repeatable methodology, reviewable evidence, disciplined follow-up and a measurable improvement programme.

Open quality checklistOpen dashboard KPIs
Downloads

Maturity scorecard and improvement plan roadmap

Download the Excel/PDF pack for maturity scoring, evidence requirements, QAIP actions, 30-60-90 day roadmap and future Internal Audit product data-model fields.

Maturity levels

Five levels for a practical assessment scale

1. Ad hoc

Audits are reactive, checklist-driven and heavily dependent on individual auditors. Evidence, review notes and follow-up are inconsistent.

2. Repeatable

Common templates exist for planning, RCMs, reports and ATR, but quality still varies by team, location or engagement.

3. Defined

Methodology, risk assessment, work programmes, supervision, evidence standards and reporting formats are documented and followed.

4. Managed

Dashboards, KPIs, quality review, issue ageing, resource capacity and continuous monitoring are measured and acted on.

5. Optimised

Internal audit is risk-led, data-enabled, continuously improving and able to advise management without weakening independence.

Assessment domains

Score only what can be evidenced evidence

DOMAIN 1

Mandate and governance

Assessment question: Does internal audit have a clear charter, reporting line, independence safeguards and audit committee visibility?

Evidence: Charter, board/audit committee minutes, SOW approvals, reporting protocol and escalation rights.

Upgrade move: Refresh the charter and link every engagement to approved governance coverage.

DOMAIN 2

Risk-based planning

Assessment question: Is the audit universe risk-ranked and converted into an executable annual plan?

Evidence: Audit universe, risk scoring, annual plan, capacity plan, quarter loading and deferral rationale.

Upgrade move: Move from calendar rotation to risk-based planning with documented capacity constraints.

DOMAIN 3

Methodology and RCM library

Assessment question: Do cycles use a consistent methodology from walkthrough to RCM, test, evidence and observation?

Evidence: Methodology map, cycle RCMs, programme library, reviewer prompts and version history.

Upgrade move: Create one control repository and tailor it per engagement instead of rebuilding from old files.

DOMAIN 4

Fieldwork and evidence

Assessment question: Can every conclusion be traced to source reports, samples, test results, exceptions and reviewer conclusions?

Evidence: PBC tracker, sampling plan, fieldwork tracker, evidence references, exception log and review sign-off.

Upgrade move: Standardise source-report metadata and evidence escalation before report drafting.

DOMAIN 5

Reporting and ATR

Assessment question: Do reports separate condition, criteria, cause, effect, recommendation, rating, response and follow-up?

Evidence: Report pack, observation register, management response, audit committee summary and ATR ageing.

Upgrade move: Use one observation ID from fieldwork through report, dashboard and closure testing.

DOMAIN 6

Quality assurance and improvement

Assessment question: Are file reviews, supervision, methodology exceptions and improvement actions documented?

Evidence: Quality review checklist, review notes, coaching actions, methodology changes and QAIP tracker.

Upgrade move: Treat review comments as improvement data, not only engagement clean-up.

DOMAIN 7

Analytics and continuous monitoring

Assessment question: Are repeatable exception rules defined, validated and tied to workpapers before reporting?

Evidence: Monitoring rules, source fields, thresholds, false-positive clearing and validated issue handoff.

Upgrade move: Prioritise a small number of high-signal rules before building broad dashboards.

DOMAIN 8

AI governance in internal audit

Assessment question: Is AI use by the IA team approved, documented and reviewed separately from AI risks in the business?

Evidence: AI strategy, approved-use register, data boundaries, prompt/tool records and AI governance workpapers.

Upgrade move: Separate "using AI for audit work" from "auditing AI used by the business".

DOMAIN 9

Talent and capacity

Assessment question: Does the team have enough hours, skills and specialist coverage for the approved plan?

Evidence: Capacity planner, skills matrix, co-sourcing map, training log and workload dashboard.

Upgrade move: Make resource constraints visible before the plan is approved, not after slippage starts.

DOMAIN 10

Stakeholder impact

Assessment question: Does internal audit influence process owners and leadership through timely, usable insights?

Evidence: Management feedback, repeat-finding trend, closure ageing, committee actions and advisory requests.

Upgrade move: Measure whether audit actions close root causes, not only whether reports are issued.

Roadmap

Turn maturity gaps into work sequence

1

First 30 days

Lock charter, SOW format, audit universe, current plan, report format and open ATR list.

2

Days 31-60

Build the RCM repository, PBC tracker, sampling template, fieldwork tracker and quality review checklist.

3

Days 61-90

Create committee dashboard KPIs, top continuous monitoring rules and capacity plan.

4

Quarter 2

Run QAIP review, calibrate ratings, train reviewers and retire duplicated legacy templates.

5

Quarter 3 onwards

Move mature repeatable areas into continuous monitoring and product workflow design.

Authority anchors

Use maturity scoring with standards, not slogans sources

IIA Global Internal Audit Standards

Global reference for internal audit purpose, governance, professional practice, quality and performance expectations.

Source ->

ICAI Internal Audit Standards Board

India reference point for Standards on Internal Audit and the 2026 SIA framework used by Indian internal auditors.

Source ->

IIA Quality Assurance and Improvement Program resources

Reference point for assessing whether the internal audit function improves quality systematically instead of only reviewing individual files.

Source ->
Product reuse

Website scorecard now, product assessment later separate

This website page is a public maturity resource. The reusable layer for the separate Internal Audit product build is the scoring model, evidence fields, roadmap states, QAIP tracker and analytics-readiness gates.

Maturity scorecard

Product shape: Internal Audit setup assessment

Likely fields: Domain, level, evidence, gap, target state, owner, due date.

Improvement roadmap

Product shape: Implementation planner

Likely fields: Milestone, dependency, effort, priority, owner, dashboard status.

QAIP tracker

Product shape: Quality management workflow

Likely fields: Review finding, root cause, methodology change, training need, closure evidence.

Analytics maturity map

Product shape: Continuous monitoring rollout

Likely fields: Rule candidate, data readiness, owner, threshold, pilot status.

Related resources

Move from maturity score to operating model operating model

Internal Audit Methodology Map

Use the lifecycle map to benchmark whether methodology is actually defined.

Open ->
Quality Review Checklist

Use file-review gates as the engagement-level QA layer.

Open ->
Dashboard KPIs

Use dashboards to measure managed and optimised maturity levels.

Open ->
Priority Risk Areas 2026

Use current risk themes to test whether planning is forward-looking.

Open ->
Resource Capacity Planner

Translate maturity gaps into hours, skills and co-sourcing needs.

Open ->
AI Strategy Template

Assess whether IA AI use is governed before scaling it.

Open ->
FAQ

Maturity assessment FAQs questions

What is an internal audit maturity assessment?

An internal audit maturity assessment evaluates how consistently the function governs, plans, executes, reviews, reports and improves internal audit work. It should produce a practical improvement roadmap, not only a maturity score.

What domains should an internal audit maturity model cover?

A practical maturity model should cover mandate, risk planning, methodology, RCMs, evidence, reporting, follow-up, QAIP, analytics, AI governance, talent, capacity and stakeholder impact.

Is QAIP the same as internal audit file review?

No. File review checks whether one engagement is ready. QAIP looks across the internal audit activity and asks whether supervision, methodology, quality, training and improvement actions are systematic.

How should internal audit maturity results be used?

Use maturity results to prioritise a 30-60-90 day roadmap, assign owners, improve templates, train reviewers, fix evidence gaps and decide which activities are ready for analytics or continuous monitoring.