Internal Audit · Governance · Frameworks
IIA Code of Practice: a new benchmark for internal audit
In September 2024, the Chartered Institute of Internal Auditors (CIIA) published a revised Code of Practice, applicable from January 2025. Designed for the UK and Ireland, this text has no regulatory scope in Luxembourg – but it serves as a useful maturity benchmark for any internal audit function wishing to measure and enhance its impact.
The CIIA, the UK and Irish branch of the Institute of Internal Auditors (IIA), published a revised version of its on 11 September 2024 Internal Audit Code of Practice, applicable from the 1ster January 2025. The text merges the two pre-existing codes — one dedicated to financial services, the other to the private and non-profit sectors — into a single reference framework.
CIIA Internal Audit Code of Practice, published on 11 September 2024, applicable from the 1er January 2025.
37 principles grouped into nine areas ; principles-based text, to be applied proportionally.
Aligned with the International Professional Practices Framework (IPPF) and the Global Internal Audit Standards (GIAS).
Merge the two old codes into a single document: financial services on the one hand, and the private and non-profit sectors on the other.
Refactored code, aligned with the new standards
It is explicitly designed to articulate with the new GSRs, which came into effect in January 2025, with the IIA's IPPF, and with the revised version of the UK Corporate Governance Code (UK Corporate Governance Code). The Code is based on principles — 37 principles divided into nine areas — and applies with proportionality, according to the size, risk profile and complexity of the organisation. It is not a binding standard: it is a benchmark of good practice, which External Quality Assessment (EQA) providers use as a reference.
What the Code Carries: From Cover to Impact
The Code shifts the focus from compliance to impact. Several guidelines are worth noting:
- A scope defined by enterprise risks. Internal audit forms its own judgement on the relevant coverage, based on the strategy and risk profile; its point of view is informed, but not determined, by that of management, the risk function or regulators.
- A dynamic audit plan. The plan, approved by the audit committee, is continuously reviewed to incorporate emerging risks and unforeseen events.
- A consolidated report and an annual opinion. At least once a year, internal audit provides an overall opinion on the effectiveness of the governance, risk management and control framework — as well as compliance with risk appetite — accompanied by a root cause analysis of significant weaknesses.
- Enhanced independence of the head of internal audit. The Code entrusts the chair of the audit committee with the appointment, target-setting, appraisal, remuneration and, where applicable, dismissal of the head of internal audit (Chief Audit Executive, CAE); after seven years of service, an annual review of their independence is expected.
- Resources matching the scale of the risks. The CAE reports regularly on the adequacy of skills and the budget; the audit committee approves this budget and states in the annual report whether it considers it sufficient.
Protecting value — and helping to create it
The purpose assigned to internal audit deserves to be clarified. According to the Code, it consists primarily in helping the board of directors and management protect the organisation's assets, reputation and long-term viability. The GIAS adopt a broader formulation: internal audit enhances the organisation's ability to create, protect and sustainably grow value.
From entity-based coverage to risk-based coverage
The Code reinforces a fundamental methodological shift: moving from a plan that systematically covers all auditable entities to one driven by the company's most significant risks. Internal audit does not need to cover its entire remit every year; it focuses its work where the risk is highest and designs its plan to support the overall annual opinion. This approach, which aligns audit work with the level and evolution of risks, requires a continuously updated plan and a regularly refreshed risk map.
What is the scope of a Luxembourgish internal audit function?
The Code targets the UK and Ireland; it has no regulatory status in Luxembourg. Nevertheless, three reasons make it a useful reference point for market participants:
- The IPPF, upon which the Code is based, is mandatory for internal auditors affiliated with the IIA worldwide, including in Luxembourg.
- The Commission de Surveillance du Secteur Financier (CSSF) already requires an internal audit function for certain of the entities it regulates — credit institutions and investment firms, alternative investment fund managers (AIFMs), professionals of the financial sector (PFS), payment institutions — with requirements regarding independence, reporting to the governing body or audit committee, and risk-based planning.
- The Code provides a common vocabulary and maturity model that can be used as a self-assessment mirror, without replacing local obligations.
The Code therefore constitutes a benchmark of good practice, rather than an additional obligation.
How to use it in practice
- Map current practices against the nine areas of the Code to identify maturity gaps.
- Review the internal audit charter: mandate, independence, reporting lines, and potential responsibilities for other control functions.
- Objectify the audit plan: starting point «business risks», continuous review, validation by the audit committee.
- Structure the reporting towards an overall annual opinion, supported by a root-cause analysis.
- Document the adequacy of resources and skills for the most significant risks.
Common pitfalls
- Treating the Code as a mere compliance checklist, when it calls for professional judgement applied with proportionality.
- Confusing it with a binding standard — or, conversely, dismissing it on the grounds that it is not locally applicable.
- Maintaining an entity-based plan that dilutes the effort instead of focusing on major risks.
- Reducing the purpose of internal audit to mere protection alone, while neglecting its contribution to decision-making and value creation.
The ARCAD approach
ARCAD supports internal audit functions — through establishment, assistance or outsourcing — to turn these frameworks into practical tools: maturity assessment, redesign of the charter and risk-based plan, structuring of reporting and the annual opinion, and quality assessment. ARCAD's approach favours independent and pragmatic internal audit, which protects value as much as it informs decision-making.
A targeted and pragmatic maturity assessment to identify your priority gaps.
References & further reading
- Internal Audit Code of Practice, Chartered Institute of Internal Auditors, September 2024 (applicable from January 2025).
- Global Internal Audit Standards (GIAS) and International Professional Practices Framework (IPPF), Institute of Internal Auditors.
- CSSF internal audit requirements applicable to concerned regulated entities (credit institutions and investment firms, AIFMs, professionals of the financial sector (PFS), payment institutions).
Note: good practice to be adapted to the profile, size and regulatory framework specific to each organisation. ARCAD illuminates and structures the approach; it does not replace the client's own analysis.