CORAA

SIA 130 — Risk Management

ICAI Internal Audit Standards Board · October 2022 compendium · 100 series
Reviewed 1 October 2026

SIA 130 sets out risk-management terminology and the responsibilities of the Board, the risk department and management under law. It then states the internal auditor's responsibilities in assessing, evaluating and reporting on the risk management framework and giving assurance over it.

This page covers SIA 130 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

Same number, different title in the current set
In ICAI’s February 2026 compendium, the current set, SIA 130 is titled Managing the Internal Audit Function. This page covers SIA 130 as it stands in the October 2022 compendium: Risk Management. Only the titles of the February 2026 set are listed here; its text is not summarised on this site. The October 2022 compendium has a standard with that exact title: SIA 210 — Managing the Internal Audit Function. A matching title does not mean the text is the same. See both title lists side by side.

What the internal auditor has to do

  • Use the standard's risk-management terminology consistently.
  • Understand what the Board, the risk department and management are each responsible for under the law that applies to the entity.
  • Assess and evaluate the risk management framework, report on it, and give assurance over it.

How SIA 130 shows up in the internal audit file

  • Working papers for the assessment of the entity's risk management framework and the conclusion reached.
  • The report or section of the report that gives the result of that assessment.

Common mistakes in practice

  • Treating the audit team's own planning risk assessment (SIA 220 and SIA 310) as if it were the assessment of the entity's risk management framework that this standard is about.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Related standards

SIA 120 · Internal ControlsSIA 140 · GovernanceSIA 220 · Conducting Overall Internal Audit Planning

How this relates to global frameworks

This is a COSO link rather than an IIA one. COSO's Enterprise Risk Management framework (2017) is the forward-looking, strategy-level framework; it is separate from COSO's 2013 internal control framework and does not replace it.

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. The effective-date clause in each 2019 standard said it applied to internal audits beginning on or after a date to be notified by the Council of ICAI.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 130

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 130 into practice. Free to use.

Internal Audit Risk Assessment Matrix →Internal audit risk scorer →Audit universe and risk taxonomy →

SIA 130 — frequently asked

What is SIA 130?

SIA 130, Risk Management, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 130 sets out risk-management terminology and the responsibilities of the Board, the risk department and management under law. It then states the internal auditor's responsibilities in assessing, evaluating and reporting on the risk management framework and giving assurance over it.

Is SIA 130 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 130 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 130 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 130?

Working papers for the assessment of the entity's risk management framework and the conclusion reached. The report or section of the report that gives the result of that assessment.

Is SIA 130 the same standard in the February 2026 compendium?

The number is the same but the title is not. In ICAI's February 2026 compendium, which ICAI lists as applicable from 1 April 2026, SIA 130 is titled "Managing the Internal Audit Function". This page covers SIA 130 as it stands in the October 2022 compendium, titled "Risk Management". Only the titles of the February 2026 set are listed here; check its text in that compendium before citing it.

← Previous
SIA 120 — Internal Controls
Next →
SIA 140 — Governance