Article

Internal Audit Dashboards: what KPIs to report to the Audit Committee

Three indicator levels to stop reporting activity and start demonstrating value.

The number of audits completed in a year says very little about the real value the department delivers. Yet it remains the most repeated indicator in many Internal Audit dashboards. This article proposes a three-level indicator structure (coverage, quality, and impact) and the specific KPIs worth bringing to the next Audit Committee session.

Why the Internal Audit dashboard matters more than ever

The Audit Committee and Senior Management do not need to know how many hours the team spent on each engagement. They need to know whether the function is covering the right risks, whether it does so with sufficient quality, and whether its recommendations translate into real improvements. A well-designed dashboard is the tool that turns the department's activity into a defensible value argument.

From reported activity to demonstrated value

Reporting "audits completed: 24 out of 26 planned" is informative, but it does not say whether those 24 audits covered the highest-impact risks for the organization or whether they were simply the easiest to execute. The qualitative leap that current reporting demands is moving from measuring activity to measuring real risk coverage and effective closure of findings.

GIAS requirements on performance indicators

Domain IV of the Global Internal Audit Standards requires the function to have a quality assurance and improvement program that includes measurable performance indicators. This makes the dashboard more than a management best practice: it is part of the evidence reviewed in an External Quality Assessment.

The three indicator levels your dashboard should include

Coverage and planning indicators

Measure whether the Audit Plan is aligned with the organization's risk map: percentage of the audit universe covered in the cycle, percentage of critical risks audited in the last twelve months, degree of compliance with the plan approved by the Audit Committee.

Execution and quality indicators

Reflect how fieldwork is performed: average execution time per engagement against plan, percentage of engagements reviewed through the quality assurance program, consistency of finding rating criteria across auditors.

Impact and value-added indicators

These are the ones the Audit Committee cares most about: percentage of action plans closed on time, percentage of critical findings reopened due to inadequate remediation, estimated savings or risk mitigation derived from implemented recommendations.

Specific KPIs you should report to the Audit Committee

KPI What it measures Why it matters
% audit universe coverage Proportion of auditable entities reviewed in a defined period Evidence of whether resources are allocated according to actual risk
% Audit Plan compliance Engagements executed versus those approved by the Committee Detects deviations that must be formally justified and approved
Average action plan closure time Days between management commitment and effective closure Measures whether recommendations translate into real changes
% critical findings reopened Findings that recur after being considered closed Signals weaknesses in follow-up or in the original remediation
Quality assurance program results Percentage of engagements meeting internal quality standards Direct evidence required by Domain IV of the GIAS
Auditee satisfaction Audited areas' rating of the process and engagement with the team Qualitative indicator of how the function's added value is perceived

Common mistakes when building the dashboard

  • Reporting only activity indicators. The number of audits or hours spent does not demonstrate value; at best, it demonstrates effort.
  • Using the same dashboard for all audiences. The Audit Committee needs a different view from the one the Internal Audit team itself needs for day-to-day management.
  • Not tracking results over time. A KPI from a single period says little; what matters is the trend and how it evolves relative to prior periods.
  • Building the dashboard manually each quarter. When data is collected by hand from scattered spreadsheets, the risk of inconsistency and the time cost increase considerably.

How to structure reporting by audience

Reporting to the Audit Committee

Prioritize impact and risk coverage indicators, using decision-oriented language: which critical risks are covered, which high-severity findings remain open, and what the department needs from the Committee itself to move forward (resources, support, or escalation of an issue to Senior Management).

Reporting to Senior Management

Combine impact indicators with a brief narrative on the areas of greatest exposure identified in the period, avoiding the methodological detail that interests the Audit Committee but not the operational management of the business day-to-day.

Internal reporting within the department

Here execution and productivity indicators do make sense: workload per auditor, time variances by engagement type, internal quality program results. This is the level of detail that helps manage the team, not communicate value externally.

Key control point: if building the quarterly dashboard requires more than a day of manual work consolidating data from different sources, the dashboard is mostly measuring the department's lack of centralization.

An audit management platform that integrates planning, execution, and finding follow-up in a single system generates these indicators automatically and in real time, without relying on a manual process repeated each period.

Checklist for your next dashboard

  1. Does it include at least one risk coverage indicator, not just an activity metric?
  2. Does it measure the effective closure of action plans, not just their creation?
  3. Does it differentiate content by audience (Committee, Senior Management, internal team)?
  4. Does it include the quality assurance program results required by the GIAS?
  5. Does it allow comparing each indicator's evolution against prior periods?
  6. Is it generated automatically or does it depend on manual data collection each time?

Conclusion

A strong Internal Audit dashboard does not aim to impress with activity figures, but to demonstrate with data that the function is covering the right risks, executing with quality, and generating real closure of agreed action plans. Designing it across three levels (coverage, quality, and impact) and adapting it to each audience is what turns a quarterly report into a real management tool and a means of defending the department's value before the Audit Committee.