Enterprise Risk Management

Internal Audit Runs ERM. Who Audits It?

The IIA's new position does not stop internal audit from helping build ERM. It draws a much clearer line around when that involvement compromises the assurance that follows.

By Eric Kennedy · Tue Aug 11 2026 · 8 min read

Internal Audit Runs ERM. Who Audits It?

TL;DR

When a chief audit executive takes responsibility for ERM activities, the IIA's July 2026 Statement of Position calls for specific independence safeguards: documented responsibilities, formal board approval, disclosure of potential impairments, and independent assurance where internal audit has operational involvement. The most concrete boundary is twelve months. An auditor should not provide assurance over a process they were responsible for designing or operating during the prior year. Separately, where internal audit performs or supervises an ERM activity at all, assurance over that area should come from another qualified and independent party. Roughly a third of audit leaders now have some second-line involvement, so this is not a niche structural question.

On July 8, 2026, the IIA published two Statements of Position, one on the Three Lines Model and one on the role of the internal audit function in enterprise risk management. They replace the position papers that came before them.

Most of the coverage focused on the headline, which is that internal audit's involvement in ERM is now openly acknowledged rather than treated as an aberration. That is true and it is not the part that changes anyone's audit plan.

This is. The statement draws a line, and the line is not where most people assume it is.

The line is not advisory versus assurance

The intuitive reading is that advising on ERM is fine and auditing it afterward is fine, and the trouble starts somewhere in between. That is not what the document says.

The statement is generous about advice. Internal audit may facilitate risk workshops and training, advise on the clarity and usability of risk language and methodologies, challenge the assumptions and data underlying risk assessment and reporting, and share good practices observed across the organization. None of that is treated as a problem. It is described as a contribution.

The line falls somewhere more specific: responsibility. The moment internal audit stops advising on a process and starts designing, operating, or maintaining it, the independence position changes.

Advisory activities such as facilitating a risk workshop and challenging assessment assumptions, against activities that make internal audit responsible for the process, such as designing the assessment methodology and maintaining the enterprise risk register.

That gives a CAE a usable diagnostic that does not require a lawyer. Did we advise on this, or did we become responsible for it?

The two independence tests

The statement contains two related tests that are easy to blur together, and they trigger on different things.

The individual test. Assurance work should be conducted by individuals who were not responsible for designing or operating the process under review within the last twelve months. In the Scenario A discussion the wording is that internal auditors should not provide assurance over activities they have designed, operated, or managed until twelve months have passed since their last action or responsibility. This is about the person, and it has a date attached.

The functional test. Where internal auditors perform or supervise ERM activities, assurance over those areas should be provided by another suitably qualified and independent party, whether internal or external. This one does not have a clock. It applies for as long as the arrangement exists.

The individual test asks whether the auditor was responsible for designing or operating the process in the last twelve months. The functional test asks whether the internal audit function performs or supervises the activity at all.

The practical difference matters. The individual test can often be solved by reassigning work inside a team. The functional test usually cannot, because the whole function is the thing with the involvement.

A note on what this document is

Worth being precise, because it is the kind of thing a CAE will check.

The statement uses mandatory language throughout. Safeguards "must ensure," internal auditors "must not" provide assurance in defined circumstances. But the IIA also states plainly in the same document that Statements of Position are principles-based, do not prescribe organizational structures, should be applied using professional judgment, and are not part of the International Professional Practices Framework, because they are written for an executive audience rather than primarily for internal auditors.

So this is not a new mandatory Standard that took effect on July 8. It is the profession's official articulation of where the line sits, written to be handed to a board. Which, if you are trying to get an arrangement documented in your charter, may be more useful than a Standard would have been.

Where the line falls in each ERM activity

The IIA defines ERM as a coordinated, organizationwide approach through which risks are identified, assessed, managed, monitored, and reported. Internal audit's role is defined separately for each of those five, in three columns: what it may advise on, what it may provide assurance over, and what it must not do.

What internal audit may advise on, may provide assurance over, and must not do across the five ERM activities of identify, assess, manage, monitor, and report.

The third column is consistent across all five. Internal audit can shape how the work is done and can evaluate whether it was done well. It cannot make the decision. It cannot determine or own risk responses, prioritize them, select or implement them, own management's follow-up, or own reporting to external parties.

That reads as obvious written down. It is considerably harder to hold in a company where the same person is doing both jobs on a Tuesday afternoon.

The seven safeguards

Where the CAE takes on ERM responsibility, the statement says safeguards should be "deliberate, proportionate, and visible to the board in the internal audit charter." Seven are named.

Seven safeguards named in the IIA statement: documented responsibilities, formal board approval, advisory separated from assurance, disclosure of impairments, the right to challenge, independent assurance, and periodic external review.

Three carry real operational weight.

Formal board approval, in the charter. Not an understanding with the CFO. The board should formally approve the arrangement and acknowledge the associated risks and mitigations. The statement also notes that internal audit may need the board to approve additional resources to deliver the work with safeguards intact, which is a useful sentence to have during budget conversations.

Independent assurance over the affected areas. For a mid-market company without another qualified internal assurance provider, that will often mean external assurance.

The right to refuse. The CAE should be able to challenge a proposed assignment of responsibilities that would significantly impair independence, and should discuss safeguards with the board. Making the assignment temporary, with a transition plan, is offered as a mitigation. That is a professional body putting language behind a conversation many audit leaders have not felt able to start.

Two structures, two different problems

The statement works through two arrangements.

Scenario A is where the internal audit function performs second-line ERM activities directly. The IIA describes this as most common in "smaller or evolving" organizations, which is the mid-market. Internal audit builds the methodology, maintains the register, monitors the indicators, and then audits its own work. The statement is direct about the arrangement's status: it "may be transitional or exceptional, rather than permanent."

Scenario B is where the CAE supervises a separate risk management function while internal audit stays organizationally distinct. Execution is genuinely separated.

Scenario A creates the more obvious independence problem. Scenario B creates the subtler one: the work is technically separated, but the same executive ultimately supervises both the process and the assurance evaluating it. The statement is careful here, noting that stakeholders may question whether internal auditors can fully challenge the effectiveness of processes supervised within the same reporting structure, even where the technical separation is intact.

What this means below $750M

Most mid-market companies do not have a second-line risk function. The CAE inherits ERM because there is nobody else, and it works, right up to the point where someone asks who checked it.

The statement anticipates exactly this. In organizations without dedicated second-line roles, it says management may benefit from relying on internal audit's processes, and the CAE may help management establish ERM activities as the organization grows. That is permission, not a problem. But it arrives attached to the same safeguards, and one of them calls for an independent party that a company of this size usually does not have on staff.

The sequence here has nothing to do with hiring anyone. Document what internal audit actually does across the five ERM activities, at the activity level rather than in general terms. Take the expanded scope to the board and get it into the charter. Work out which areas are affected by the two tests and adjust the plan, because otherwise the planned assurance may conflict with the independence safeguards the statement now lays out. Then decide, deliberately, whether the arrangement is transitional or whether it has quietly become permanent.

That last question is the one the statement is really asking.

What to do in the next ninety days

Four things, in order.

Map your own involvement across identify, assess, manage, monitor, and report. Not "internal audit supports ERM." Which of the five, at what depth, by whom, and whether it was advice or responsibility. The statement is built on this taxonomy and your charter should be too.

Apply both tests. For every ERM process internal audit helped design or operate, identify who was responsible and the date of their last involvement. Do not automatically pull the whole area out of the plan. First work out whether another qualified and sufficiently independent person or function can provide that assurance instead.

Get it in the charter and in front of the board. Formal approval, documented scope, acknowledged risks. If the board has never discussed the arrangement, that is a governance gap worth correcting.

Decide who provides the assurance you cannot. Another internal function if you have one, an external party if you do not. The statement also mentions periodic external quality assessments or targeted independent reviews where the CAE supervises ERM activities.

None of this requires a restructure. It requires writing down what is already true and then following the consequences.

If your ERM program is what the assurance would be pointed at, the questions in how to run a risk assessment that changes a decision and the difference between a register and a program determine whether there is anything there to assure.

Where to Start

If you own both functions and are working out what the safeguards mean for your charter and your plan, the useful first step is a clear read on where the ERM program itself actually stands.

The KRG scorecard gives you a tier-level assessment in seven questions and about two minutes, with no email required to see your score.

If you need independent assurance over ERM activities your own team designed or operates, that is a specific engagement rather than a general one. The ERM Program Diagnostic is a one-to-two-week review built for mid-market organizations, and the fee is credited toward a larger engagement.

Take the Board-Reporting Scorecard{.cta-primary} Explore the ERM Diagnostic{.cta-secondary}

Frequently Asked Questions

Can internal audit own enterprise risk management?

Not in the sense of owning management's risk decisions. The IIA's July 2026 Statement of Position says internal audit may advise on ERM and, in some organizational structures, may perform or supervise certain ERM activities with appropriate safeguards. Management must remain accountable for risk responses and decisions. Internal audit must not determine or own risk responses, prioritize them, select or implement them, own management's follow-up, or own reporting to external parties.

How long must internal audit wait before auditing ERM work it performed?

Twelve months. The IIA's 2026 Statement of Position says assurance work should be conducted by individuals who were not responsible for designing or operating the process under review within the last twelve months, and that internal auditors should not provide assurance over activities they have designed, operated, or managed until twelve months have passed since their last action or responsibility. The test attaches to responsibility for designing or operating a process, not to advisory work in general.

What is the difference between advising on ERM and running it?

Advising covers facilitating risk workshops and training, advising on risk language and methodologies, challenging the assumptions behind risk assessments, and sharing good practices. The IIA treats all of that as a legitimate internal audit contribution. Responsibility begins where internal audit designs the assessment methodology, sets scoring criteria, maintains the enterprise risk register, aggregates organizationwide risk ratings, develops or monitors risk indicators for management, or prepares enterprise risk reports on management's behalf. The second set changes what assurance internal audit can later provide.

What are the five ERM activities in the IIA statement?

Identify, assess, manage, monitor, and report. The IIA defines enterprise risk management as a coordinated, organizationwide approach through which risks, meaning both threats and opportunities, are identified, assessed, managed, monitored, and reported. The statement defines internal audit's permitted advisory role, permitted assurance role, and prohibited activities separately for each of the five.

Who should provide assurance over ERM when internal audit runs it?

Another suitably qualified and independent party, either internal or external. The IIA statement says that where internal auditors perform or supervise ERM activities, assurance over those areas should come from someone else. In organizations with a second internal assurance function, that function may be able to provide it. In mid-market organizations without one, the practical options are an external provider or a targeted independent review, which the statement mentions alongside periodic external quality assessments as a way to mitigate perception risk.