The internal audit charter is the standing mandate for the function. It should make authority, independence, reporting line, access rights, scope-setting and escalation explicit before annual planning or fieldwork starts.
Download the Excel/PDF pack for charter fields, governance decisions, weak-mandate red flags, annual review triggers and future Internal Audit product onboarding fields.
Why internal audit exists and what assurance/advisory role it performs for the company.
Access rights to records, systems, people, locations, reports and evidence needed for fieldwork.
Reporting line, functional access to Audit Committee/Board and safeguards against management interference.
Business units, processes, locations, systems, subsidiaries and excluded areas.
Risk assessment, SOW, RCM, sampling, evidence, reporting, follow-up and quality review approach.
Annual plan, quarterly reviews, cycle frequency, continuous monitoring and committee cadence.
What internal audit does, what management owns and what statutory auditors separately conclude.
Route for evidence delays, access restriction, unresolved high-risk issues and management disagreement.
Is internal audit mandatory under Section 138/Rule 13, voluntary, group-mandated or lender/investor-driven?
Will the Audit Committee approve the charter, or the Board where no Audit Committee exists?
Who receives reports functionally, who handles administration, and how private access to committee members works.
Who can add, defer or remove audit areas from the approved annual plan.
Whether internal audit can access ERP reports directly or only through process-owner extracts.
Who reviews internal audit files, report quality, issue ratings and follow-up closure.
Scope can be narrowed by the same owners whose controls are being audited.
Fieldwork gets blocked when systems, logs, invoices, contracts or bank evidence are not provided.
Delayed PBC requests and disputed high-risk findings become informal negotiation.
Teams use inconsistent RCMs, samples, ratings, reports and ATR closure standards.
Charter becomes stale after ERP changes, new business lines, outsourced processes or AI adoption.
Management expects internal audit to issue statutory opinions or take over control ownership.
This is a public website resource. The reusable layer for the separate Internal Audit product build is the charter profile, mandate type, reporting-line model, evidence-access permissions, escalation workflow, methodology settings and annual-review trigger list.
Internal Audit onboarding: Mandate type, approver, reporting line, access rights, scope boundaries, review date.
Evidence and issue workflow: Blocker type, escalation owner, SLA, committee route, unresolved-impact flag.
Engagement setup: RCM standard, rating scale, sampling policy, report format, ATR cadence, QA review owner.
Governance dashboard: ERP change, acquisition, new process, outsourcing, AI deployment, repeat issue trend.
An internal audit charter is the approved document that defines the internal audit function purpose, authority, independence, reporting line, scope, methodology, responsibilities and escalation rights.
For companies with an Audit Committee, the charter should normally be approved through the Audit Committee. Where no Audit Committee exists, Board approval is the practical governance route. Section 138 and Rule 13 should be checked for the entity.
No. The charter defines the standing mandate and authority of the internal audit function. The SOW translates that mandate into a specific engagement or annual-plan scope, cycles, locations, timing and deliverables.
At least annually, and whenever there is a material change in business model, ERP, outsourced processes, regulation, reporting structure, acquisition, AI adoption or recurring scope limitation.