The IIA's Global Internal Audit Standards (GIAS) have been in effect since 2025 and are now the mandatory reference framework for any function seeking to maintain its certification or pass an External Quality Assessment. Yet many departments are still working with methodologies, templates, and dashboards designed for the previous framework. This guide explains what really changes, how to adapt your Audit Plan without rebuilding it from scratch, and which mistakes to avoid along the way.
What are the Global Internal Audit Standards and why do they replace the previous framework?
The GIAS represent the new International Professional Practices Framework (IPPF) published by the IIA Global. They replace the 2017 International Standards for the Professional Practice of Internal Auditing and its Code of Ethics, integrating both documents into a single coherent structure.
The change is not cosmetic. The IIA has moved from a model based on general principles to one based on verifiable requirements, organized into domains and principles, each with explicit conformance considerations. This means an Internal Audit function can no longer simply draw "inspiration" from the standards: it must be able to demonstrate, with documentary evidence, how it conforms to each requirement.
Origin and effective date
The GIAS were published in January 2024 following an international public consultation process and took full effect in January 2025, with a transition period for certified functions to adapt their methodologies. From that date onward, External Quality Assessments (QAs) and internal self-assessments are conducted against this new framework.
Key differences from the 2017 International Standards
| 2017 Framework | GIAS (2024) |
|---|---|
| Standards and Code of Ethics as separate documents | Single integrated framework |
| General principles | Verifiable requirements by domain |
| Interpretive application | Explicit, evidenceable conformance considerations |
| Structure by category (attribute/performance) | Structure across 5 sequential domains |
The five GIAS domains explained
The GIAS organize all professional practice into five domains. Understanding this structure is the first step to knowing where each policy, procedure, or piece of evidence your department already has fits in.
Domain I: Purpose of Internal Auditing
Defines the mission of the function: to provide independent and objective assurance and advisory services that add value and improve an organization's operations. This is the reference domain for justifying the Internal Audit role to the Board and Senior Management.
Domain II: Ethics and Professionalism
Replaces the former Code of Ethics. It establishes the principles of integrity, objectivity, competence and due professional care, confidentiality, and professional conduct that each auditor must meet, not just the department as a whole.
Domain III: Governance of the Internal Audit Function
Governs the relationship between the function, the Board, and the Audit Committee: mandate, organizational positioning, independence, and oversight. This is one of the domains where most functions identify gaps, particularly around formalizing the audit charter and the frequency of reporting to the governing body.
Domain IV: Management of the Internal Audit Function
Covers strategic planning, resources, team competencies, quality management, and the quality assurance and improvement program. This is where the requirements that most depend on having documented and traceable processes are concentrated.
Domain V: Performing Internal Audit Services
Details how individual engagements should be planned and executed: from risk identification through to communicating results and following up on action plans. This is the most operational domain and the one with the greatest day-to-day impact on the team.
How to adapt your Internal Audit Plan to the GIAS without starting from scratch
The good news is that most departments do not need to rebuild their methodology from the ground up. What they do need is to map what they already do against the new requirements and close the documentation and traceability gaps.
Step 1: Gap analysis
Review each of the five domains and assess, requirement by requirement, whether your department fully conforms, partially conforms, or does not conform. The outcome of this diagnosis must be documented: it is the foundation on which you will build your adaptation plan and the first piece of evidence an external assessor will request.
Step 2: Updating department policies and procedures
Prioritize the audit charter, the independence and objectivity policy, and the quality management procedure. These three documents concentrate a large share of the requirements from Domains III and IV, and are typically the first items reviewed in a QA.
Step 3: Documentary traceability for the External Quality Assessment
The GIAS require demonstrating conformance, not just declaring it. This means maintaining accessible evidence for each engagement: workpapers, communication of findings, follow-up on action plans, and records of team competencies. The more centralized and traceable this information is, the less manual effort each assessment demands.
Practical insight: in most recent QAs, the highest number of observations does not come from methodological non-conformances, but from a lack of accessible, consistent documentary evidence across engagements.
A centralized audit management tool directly reduces this risk: it standardizes the documentation of each engagement and maintains the full traceability that Domain IV requires, without relying on spreadsheets scattered across individual auditors.
Common mistakes when implementing the GIAS
- Treating it as a purely documentary change. Updating the audit charter is not enough if the day-to-day operational processes do not reflect the new requirements.
- Failing to involve the Audit Committee in the transition. Several Domain III requirements directly depend on how the function relates to the governing body; without their validation, the adaptation remains incomplete.
- Underestimating Domain II (Ethics and Professionalism). Now integrated with the rest of the framework, it is no longer an optional annex: it must be reflected in the individual training and evaluation of each auditor.
- Maintaining inconsistent finding rating criteria across auditors. The GIAS reinforce the requirement for objectivity and consistency in rating findings, a point that frequently generates observations in QAs.
How technology facilitates GIAS conformance
Many of the GIAS requirements (documentary traceability, consistency across engagements, action plan follow-up, quality assurance and improvement program) are much easier to demonstrate when the department works on a shared platform rather than on scattered files.
An audit management and GRC platform enables, among other things:
- Maintaining a single repository of workpapers, findings, and evidence for each engagement, with a history accessible for QA purposes.
- Applying consistent finding rating criteria across different auditors and teams.
- Automating action plan follow-up and flagging overdue deadlines, a point Domain V requires to be documented.
- Automatically generating the indicators that Domain IV requires to be reported to the Audit Committee.
Quick GIAS conformance checklist
- Is the audit charter up to date and approved by the Audit Committee in line with Domain III?
- Is there a documented quality assurance and improvement program (Domain IV)?
- Are finding rating criteria consistent across auditors and engagements?
- Does each engagement have traceable, externally reviewable workpapers?
- Is action plan follow-up documented with an owner and a closing date?
- Are team competencies and continuing professional development recorded in line with Domain II?
Conclusion
The GIAS do not require reinventing the Internal Audit function, but they do require being able to demonstrate, with evidence, that each of the five domains is met consistently. The most efficient path involves an honest gap analysis, updating the department's key documents, and above all, having a system that maintains documentary traceability without depending on each individual auditor's manual effort. The sooner this adaptation is addressed, the lower the risk of observations in the next External Quality Assessment.