The internal audit charter has a reputation as a formality: a document drafted at the function's founding, approved by the committee, and revisited when somebody remembers it exists. Under the current framework in the Kingdom, that reading is out of date in a specific and uncomfortable way.
The charter is not a mission statement. It is a set of claims about authority and independence — and each one is testable against the function's own record. It is also the document where two of the three layers governing Saudi internal audit meet most directly.
What the two frameworks require
The 2024 Global Internal Audit Standards place the charter within Domain III, which sets out the conditions the board must establish for an effective function. It is grouped with board interaction and the function's mandate, not with methodology. That placement is the point: the charter is the instrument through which the board grants authority, and it belongs to the governance layer rather than the operating one.
SAMA's Principles of Internal Auditing for Local Banks ask for the same thing under Principle 5, and are specific about the contents.
Read as a table of contents, that list is unremarkable. Read as a set of controls, it is considerably more demanding — because each item implies evidence.
The clauses that get tested
Four of the six are where charters most often diverge from reality.
Organisational position. The charter will state that the head of internal audit reports functionally to the audit committee and administratively to the CEO. The test is not whether the sentence is there. It is whether the plan, findings and opinion actually travelled that route — or whether the committee only saw material that management had reviewed and softened first.
Authority. A charter typically grants the function unrestricted authority over the scope of its work. The test is what happened the last time an engagement's scope was inconvenient. If scope was negotiated down and no record exists of who asked or why, the clause is aspirational.
Right to access records. This is the clause most often asserted and least often evidenced. Access is either demonstrated by engagements that reached the systems and data they needed, or contradicted by a pattern of requests that went unanswered and were never escalated. A function with no record of access ever being obstructed has either extraordinary cooperation or no mechanism for capturing obstruction.
Right to escalate. The same problem in sharper form. Escalation is a control, and like any control it is tested by whether it operates — not by whether it exists. A charter granting escalation rights, alongside four years of findings in which nothing was ever escalated despite overdue high-risk actions, describes two different organisations.
Why this is an evidence problem
None of the above is really a drafting question. Any competent CAE can write a charter that satisfies both frameworks in an afternoon; templates are freely available and largely adequate.
The difficulty is that the charter makes promises about how the function behaves over years, and the five-yearly external quality assessment tests those promises against the record. A function whose evidence lives in email threads and workbook versions can produce the charter instantly and the proof slowly, if at all.
The functions that hold up are the ones where the charter's claims are structurally reflected in how the work is captured:
- Committee approval of the plan recorded as a state with version history, so the reporting line is evidenced rather than asserted.
- Scope changes captured as tracked changes against an approved engagement, so "authority over scope" has a trail.
- Findings carrying ownership, ageing and automatic escalation, so the escalation clause operates by default instead of by memory.
- Access issues logged as part of the engagement record rather than resolved in a corridor.
That is the case for running the lifecycle inside audit management software built around the 2024 Standards, where the governance claims in the charter and the operating record are the same artefact — VistaPlan holding the approved plan and its history, VistaResolve enforcing ageing and escalation on findings.
For functions in the Kingdom weighing that, the deployment and residency detail is on our audit management software for Saudi Arabia page, alongside the vendor comparison on best audit management software in Saudi Arabia.
Explore the platform or request a demo.