CORAA
Resources · Internal Audit Governance

Internal audit charter mandate.

The internal audit charter is the standing mandate for the function. It should make authority, independence, reporting line, access rights, scope-setting and escalation explicit before annual planning or fieldwork starts.

Open Word charterDraft SOW
Downloads

Charter review workbook review

Download the Excel/PDF pack for charter fields, governance decisions, weak-mandate red flags, annual review triggers and future Internal Audit product onboarding fields.

Charter fields

What the mandate should cover include

Purpose

Why internal audit exists and what assurance/advisory role it performs for the company.

Authority

Access rights to records, systems, people, locations, reports and evidence needed for fieldwork.

Independence

Reporting line, functional access to Audit Committee/Board and safeguards against management interference.

Scope

Business units, processes, locations, systems, subsidiaries and excluded areas.

Methodology

Risk assessment, SOW, RCM, sampling, evidence, reporting, follow-up and quality review approach.

Periodicity

Annual plan, quarterly reviews, cycle frequency, continuous monitoring and committee cadence.

Responsibilities

What internal audit does, what management owns and what statutory auditors separately conclude.

Escalation

Route for evidence delays, access restriction, unresolved high-risk issues and management disagreement.

Governance decisions

Decisions to make before fieldwork before

Appointment basis

Is internal audit mandatory under Section 138/Rule 13, voluntary, group-mandated or lender/investor-driven?

Approver

Will the Audit Committee approve the charter, or the Board where no Audit Committee exists?

Reporting line

Who receives reports functionally, who handles administration, and how private access to committee members works.

Scope authority

Who can add, defer or remove audit areas from the approved annual plan.

Data access

Whether internal audit can access ERP reports directly or only through process-owner extracts.

Quality review

Who reviews internal audit files, report quality, issue ratings and follow-up closure.

Red flags

What makes a charter weak weak

Charter says "as assigned by management"

Scope can be narrowed by the same owners whose controls are being audited.

No evidence access clause

Fieldwork gets blocked when systems, logs, invoices, contracts or bank evidence are not provided.

No escalation route

Delayed PBC requests and disputed high-risk findings become informal negotiation.

No methodology reference

Teams use inconsistent RCMs, samples, ratings, reports and ATR closure standards.

No annual review

Charter becomes stale after ERP changes, new business lines, outsourced processes or AI adoption.

No distinction from statutory audit

Management expects internal audit to issue statutory opinions or take over control ownership.

Authority anchors

Sources to check before approval verify

Companies Act, 2013 — Section 138

Section 138 requires prescribed classes of companies to appoint an internal auditor. Applicability and thresholds should be checked for the entity and period.

Companies (Accounts) Rules, 2014 — Rule 13

Rule 13(2) requires scope, functioning, periodicity and methodology of internal audit to be formulated with the Audit Committee or Board and the internal auditor.

ICAI Standards on Internal Audit publications

Use current SIA guidance for planning, risk assessment, internal controls, evidence, documentation, communication, reporting and follow-up.

IIA Global Internal Audit Standards

Useful anchor for mandate, governance, independence, due professional care, engagement performance, communication and quality expectations.

Product reuse

Website resource now, product onboarding later later

This is a public website resource. The reusable layer for the separate Internal Audit product build is the charter profile, mandate type, reporting-line model, evidence-access permissions, escalation workflow, methodology settings and annual-review trigger list.

Charter profile

Internal Audit onboarding: Mandate type, approver, reporting line, access rights, scope boundaries, review date.

Escalation model

Evidence and issue workflow: Blocker type, escalation owner, SLA, committee route, unresolved-impact flag.

Methodology settings

Engagement setup: RCM standard, rating scale, sampling policy, report format, ATR cadence, QA review owner.

Annual review trigger

Governance dashboard: ERP change, acquisition, new process, outsourcing, AI deployment, repeat issue trend.

Related resources

Build from mandate to workpapers next

Internal Audit Applicability Checker

Check Section 138 applicability before drafting the charter or SOW.

Internal Audit SOW Generator

Translate the mandate into cycle scope, cadence, deliverables and data requests.

Internal Audit Methodology Map

Connect charter to annual plan, RCM, fieldwork, reporting and ATR follow-up.

Internal Audit Maturity Assessment

Assess whether mandate, independence, methodology and QAIP are operating well.

Internal Audit Quality Review Checklist

Review whether work actually follows the approved mandate and methodology.

Internal Audit Charter Template

Download the editable Word charter format.

FAQs

Internal audit charter questions answered

What is an internal audit charter?

An internal audit charter is the approved document that defines the internal audit function purpose, authority, independence, reporting line, scope, methodology, responsibilities and escalation rights.

Who approves the internal audit charter in India?

For companies with an Audit Committee, the charter should normally be approved through the Audit Committee. Where no Audit Committee exists, Board approval is the practical governance route. Section 138 and Rule 13 should be checked for the entity.

Is an internal audit charter the same as an SOW?

No. The charter defines the standing mandate and authority of the internal audit function. The SOW translates that mandate into a specific engagement or annual-plan scope, cycles, locations, timing and deliverables.

How often should the internal audit charter be reviewed?

At least annually, and whenever there is a material change in business model, ERP, outsourced processes, regulation, reporting structure, acquisition, AI adoption or recurring scope limitation.