On 9 January 2025, the Institute of Internal Auditors' 2024 Global Internal Audit Standards became effective, replacing the 2017 International Professional Practices Framework. For audit functions in Saudi Arabia, this is not a cosmetic update. The framework that used to live across four separate documents — Standards, Code of Ethics, Core Principles, and the Definition — is now a single, restructured rulebook.

5domains
15principles
52standards, in one document

The new structure

The Standards are organised into five domains, each holding principles and the standards beneath them.

Domain What it covers
I. Purpose of Internal Auditing Why the function exists and the value it delivers
II. Ethics and Professionalism The behaviour expected of every internal auditor
III. Governing the Internal Audit Function The board and CAE conditions for an effective function
IV. Managing the Internal Audit Function Strategy, planning, resources, and quality
V. Performing Internal Audit Services How engagements are planned, performed, and communicated

What actually changed

Beyond the reorganisation, a few changes matter in day-to-day practice:

  • Assurance and consulting are merged. The old .A and .C suffixes are gone; the guidance is now written into the primary content, so you apply one set of standards rather than toggling between two.
  • Governance moved to the centre. Domain III sets out the conditions a board must establish, and Chief Audit Executives are now explicitly responsible for actively engaging the board and senior management so they stay well-informed about the function.
  • Findings are no longer ranked the old way. The requirement to rank findings was removed; reports now communicate the significance and prioritisation of findings instead.
  • The risk assessment must be living. Under Standard 9.4, the risk assessment behind the plan must be documented and reviewed at least annually — and updated when the business changes materially.

What this means in the Kingdom

A short readiness checklist

If you are a CAE in Saudi mapping your function to the new Standards, the practical moves are:

  1. Re-map your methodology to the five domains, and retire the .A/.C mental model.
  2. Strengthen board engagement — make CAE-to-board communication a defined, evidenced process, not an ad-hoc update.
  3. Document the risk-based plan so you can show how risk drove it, and refresh the assessment on a real cadence.
  4. Re-frame reporting around significance and prioritisation rather than a fixed ranking scale.
  5. Plan for bilingual output so the same record serves an Arabic or English committee.

The Standards reward functions whose work is traceable by construction — risk to plan to engagement to opinion. That spine is exactly what ControlVista is built around, with VistaPlan keeping the risk assessment documented and refreshed the way Standard 9.4 now expects.

Explore the platform or request a demo.