ControlVista

—IIA 2024 · Self-Assessment

IIA 2024 self-assessment, your conformance in ten minutes.

28 yes/no questions on the requirements of the IIA Global Internal Audit Standards that assessors test most. Get a readiness score by domain and a list of gaps, each linked to a practical guide. Free, no signup — your answers stay in your browser.

Answer each question for your internal audit function as it operates today. Use Partly where the practice exists but isn't consistent or evidenced, and N/A only where a requirement genuinely doesn't apply. When you're done, print the result or save it as a PDF for your quality assurance file.

Ethics and professionalism

Domain II — objectivity, competency, conformance and confidentiality.

0/5
  1. Standard 2.2

    Are auditors kept off activities they were responsible for in the previous twelve months — and is there a methodology for handling impairments, gifts and conflicts of interest?

  2. Standard 2.3

    Are impairments to objectivity disclosed promptly to the CAE or a supervisor — and does the CAE disclose their own impairments to the board?

  3. Standard 3.2

    Do auditors keep up continuing professional development, with certified staff meeting their certification's CPE requirements?

  4. Standard 4.1

    When a requirement of the Standards can't be met, does the CAE document the circumstance, the alternative actions taken, the impact and the rationale?

  5. Standard 5.2

    Are engagement records protected — with defined custody, retention and disposal that follow your security and privacy requirements?

Governing the function

Domain III — charter, independence, the board relationship and quality.

0/7
  1. Standard 6.2

    Is there a charter covering purpose, commitment to the Standards, mandate, scope and reporting lines — approved by the board?

  2. Standard 6.3

    Does the board approve the audit plan, budget and resource plan — and meet the CAE without senior management present?

  3. Standard 7.1

    Does the CAE report directly to the board and confirm the function's organizational independence to the board at least annually — with the board approving the CAE's appointment and removal?

  4. Standard 8.1

    Does the CAE report to the board on the plan and budget, changes to the mandate, any impairments to independence, engagement results and quality-programme results?

  5. Standard 8.2

    Does the board discuss the sufficiency of internal audit's resources at least once a year — and is it told when resources fall short?

  6. Standard 8.3

    Is there a quality assurance and improvement program with internal and external assessments, and are internal assessment results reported to the board at least annually?

  7. Standard 8.4

    Has an external quality assessment been completed in the last five years by a qualified, independent assessor or team including someone with an active CIA — with the board approving the plan and receiving the results?

Managing the function

Domain IV — strategy, the risk-based plan, resources and quality.

0/10
  1. Standard 9.1

    Does the CAE have a documented understanding of governance, risk management and control processes across reporting, operations, safeguarding of assets and compliance?

  2. Standard 9.2

    Is there a documented internal audit strategy — vision, strategic objectives and initiatives — reviewed periodically with the board and senior management?

  3. Standard 9.3

    Are internal audit methodologies documented, kept up to date and trained on across the team?

  4. Standard 9.4

    Is the plan based on a documented assessment of the organization's strategies, objectives and risks, performed within the last twelve months?

  5. Standard 9.4

    Is the plan kept dynamic — updated as risks change — with the board approving the plan and any significant changes to it?

  6. Standard 9.5

    Where you rely on other assurance providers, is the basis for that reliance documented?

  7. Standard 10.3

    Is the technology the function relies on evaluated regularly, are auditors trained on it, and are its limitations reported to the board?

  8. Standard 12.1

    Do you run ongoing monitoring and periodic self-assessments of conformance, with action plans and reporting?

  9. Standard 12.2

    Are performance objectives for internal audit set with input from the board, with a way of measuring them and action plans when they're missed?

  10. Standard 12.3

    Is engagement supervision evidenced on file — with reviewers confirming that working papers support the conclusions?

Performing engagements

Domain V — engagement planning, documentation, reporting and follow-up.

0/6
  1. Standard 13.2

    Does every assurance engagement include a documented risk assessment of the activity under review, including fraud risk?

  2. Standard 13.6

    Is each engagement's work program documented and approved by the CAE before it's used — with changes approved too?

  3. Standard 14.3

    Is each potential finding evaluated for significance using the CAE's rating methodology — with root cause identified with management where possible?

  4. Standard 14.6

    Could an informed, competent person re-perform the work from your working papers and reach the same results — with supervisor review and CAE approval on file?

  5. Standard 15.1

    Do final engagement reports state conformance only when supervision and quality-programme results support it — and disclose any nonconformance with its reason and impact?

  6. Standard 15.2

    Is there a methodology and tracking system for confirming action plans are implemented, with documented explanations for delays?

—Frequently Asked

About the self-assessment.

Is this an external quality assessment?

No. It is a quick self-check against key requirements of the IIA 2024 Standards. Standard 8.4 requires an external quality assessment at least once every five years by a qualified, independent assessor; a self-check like this helps you prepare for one.

Is my data stored or sent anywhere?

No. Your answers are saved only in this browser so you can come back to them. Nothing is sent to ControlVista.

How is the score calculated?

Each Yes counts 1, Partly counts ½ and No counts 0. N/A answers are left out, so the readiness percentage reflects only the requirements that apply to you.

Does it cover every Standard?

No — it covers 28 of the requirements most often tested, across Domains II to V. The Standards contain 52 Standards in total; read the official text at theiia.org for the full requirements.

Last reviewed October 2026. Standards references paraphrase The IIA's Global Internal Audit Standards (2024); they are not a substitute for the official text.

—Request a demo

See ControlVista run your audit lifecycle, end to end.

A 30-minute walkthrough with the team that built it — from the audit universe to the board-ready committee pack, in English and Arabic.

A product of Vantage Technologies.

We respond within one business day.