IIA Global Internal Audit Standards
The professional standards for governing, managing, and performing internal audit. They assess the quality and conformance of an internal audit function; they are not criteria for certifying the audited company or its control environment.
2024 IPPF (effective 2025-01-09) · The Institute of Internal Auditors · published 2024-01-09
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
IIA Global Internal Audit Standards is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
The complete standards are publicly accessible but copyright-protected; confirm software incorporation, reproduction, and distribution rights before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Purpose of Internal Auditing · Ethics and Professionalism · Governing the Internal Audit Function · Managing the Internal Audit Function · Performing Internal Audit Services
- Applies to
- internal audit · professional services · all sectors · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 2017 IPPF | Superseded | date not published |
| 2024 IPPF (effective 2025-01-09) | Current edition · supersedes 2017 IPPF | 2024-01-09 |
05Change history
06Related frameworks
- ISO 223012019 (Amd 1:2024)
Also applies to all sectors · The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.
- OSCAL1.2.2
Also applies to all sectors · NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- ASD Essential EightMaturity Model (November 2023)
Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.