Skip to main content
Framework library
Framework module · iia-global-internal-audit-standards-2024

IIA Global Internal Audit Standards

The professional standards for governing, managing, and performing internal audit. They assess the quality and conformance of an internal audit function; they are not criteria for certifying the audited company or its control environment.

2024 IPPF (effective 2025-01-09) · The Institute of Internal Auditors · published 2024-01-09

Standing today
Directory entry

00Answer

from the registry record
What is IIA Global Internal Audit Standards?
The professional standards for governing, managing, and performing internal audit. They assess the quality and conformance of an internal audit function; they are not criteria for certifying the audited company or its control environment.
Who does IIA Global Internal Audit Standards apply to?
IIA Global Internal Audit Standards applies to internal audit, professional services, all sectors, global, per The Institute of Internal Auditors.
What is the current version of IIA Global Internal Audit Standards?
The current edition is 2024 IPPF (effective 2025-01-09), issued by The Institute of Internal Auditors and published 2024-01-09. Source: https://www.theiia.org/en/standards/.
What does an assessment under IIA Global Internal Audit Standards require?
No control catalog has been ingested for IIA Global Internal Audit Standards yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

IIA Global Internal Audit Standards is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

The complete standards are publicly accessible but copyright-protected; confirm software incorporation, reproduction, and distribution rights before verbatim ingestion.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Purpose of Internal Auditing · Ethics and Professionalism · Governing the Internal Audit Function · Managing the Internal Audit Function · Performing Internal Audit Services
Applies to
internal audit · professional services · all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
2017 IPPFSupersededdate not published
2024 IPPF (effective 2025-01-09)Current edition · supersedes 2017 IPPF2024-01-09

05Change history

06Related frameworks

scored from registry facts
  1. ISO 223012019 (Amd 1:2024)

    Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.

  2. OSCAL1.2.2

    Also applies to all sectors · NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.

  3. Shared Assessments SIG2026 annual release

    Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  4. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

IIA Global Internal Audit Standards | ControlFrame