Skip to main content
Category: Compliance & Audit

Internal Audit

Also known as: IA, Internal Auditing, Internal Audit Function
Simply put

Internal audit is an activity within an organization that independently reviews how well the organization manages its risks, controls, and operations, and offers assurance and advice to help improve them. As commonly defined, it is designed to add value and improve an organization's operations. It typically reports to management and governance bodies rather than serving external stakeholders directly.

Formal definition

Internal auditing is commonly defined by The IIA as an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. In practice it assesses risk management, control, and operational (governance) processes for alignment with business objectives, with internal auditors functioning as audit professionals who work within the organization. In model risk and AI governance contexts, internal audit is typically positioned as the third line of defense, providing independent assurance over the design and operating effectiveness of risk management and control activities carried out by the first and second lines; it does not itself own or operate those controls. The scope, standards, and independence arrangements vary by organization, jurisdiction, and applicable professional standards, and this entry does not address external audit, which serves different objectives and stakeholders.

Why it matters

In AI governance and model risk management, internal audit provides a layer of independent assurance that risk and control activities are actually working as intended, rather than merely existing on paper. Because internal audit is typically positioned as the third line of defense, its role is distinct from those who build models (commonly the first line) and those who set policy and independently challenge or validate them (commonly the second line). This separation matters: without an independent function assessing the design and operating effectiveness of controls, an organization may have no objective basis for confidence that its stated governance and model risk practices are being followed. As commonly defined by The IIA, internal audit is designed to add value and improve an organization's operations, and in the AI context that value often comes from surfacing gaps between documented controls and actual practice.

Internal audit also helps management and governance bodies discharge their oversight responsibilities. Because it typically reports to management and governance bodies rather than to external stakeholders, it serves as an internal source of assurance that boards, committees, and senior leaders can rely on when making decisions about model use and AI risk. It is important, however, not to overstate what internal audit can deliver: it assesses and advises on risk management and controls, but it does not eliminate risk, nor does it own or operate the controls it reviews.

The scope and authority of internal audit vary by organization, jurisdiction, and applicable professional standards, so its precise role in any given AI or model risk program depends on how that program is structured. This entry addresses internal audit as an internally-administered function and does not cover external audit, which serves different objectives and stakeholders.

Who it's relevant to

Internal auditors and audit leadership
As the audit professionals who work within the organization, internal auditors carry out the independent assurance and consulting work that defines the function. In AI and model risk contexts, they assess whether risk management and control activities are designed and operating effectively, while taking care not to assume ownership of the controls they review.
Model risk managers and second-line functions
Second-line functions, such as those responsible for oversight and independent challenge or validation, are among the activities internal audit assesses. Understanding that internal audit evaluates the effectiveness of their controls—rather than duplicating or replacing them—helps clarify the distinct roles across the lines of defense.
Management and governance bodies
Because internal audit typically reports to management and governance bodies, boards, committees, and senior leaders rely on its assurance and advice to support oversight of AI and model risk. It provides an internal source of assurance about whether stated controls are working, though it does not eliminate risk.
First-line model developers and control owners
Those who build and operate models and own the associated controls are subject to internal audit review of the design and operating effectiveness of those controls. Recognizing internal audit's independent, third-line position clarifies why the function assesses rather than performs their work.

Inside IA

Third Line of Defense Positioning
In the commonly cited three-lines model, internal audit typically functions as the third line, providing independent assurance over both the first line (business units that own and manage risk) and the second line (risk management and compliance functions). Its independence from the activities it reviews is a defining feature.
Independent Assurance
Internal audit provides objective evaluation of the design and operating effectiveness of governance, risk management, and control processes for AI systems and models, reporting findings to senior management and, in many organizational structures, to a board-level committee to preserve independence.
Scope Over AI Governance and Model Risk Management
Internal audit may assess both AI governance elements (policies, accountability structures, oversight, roles) and model risk management practices (identification, measurement, monitoring, and control of model risk). These are distinct domains that internal audit reviews without collapsing one into the other.
Assessment of Validation and Control Processes
Internal audit typically evaluates whether validation activities were performed and whether controls operate as intended; this is distinct from performing model validation itself, which is more commonly a second-line responsibility in many frameworks.
Reporting and Escalation
Internal audit communicates findings, issues, and recommendations through defined reporting channels, and tracks remediation. Its role is to inform and challenge, not to own or manage the underlying risks.

Common questions

Answers to the questions practitioners most commonly ask about IA.

Is internal audit the same as the model validation function?
No. In the three-lines model as commonly applied, model validation is typically situated in the second line of defense, while internal audit operates as the third line providing independent assurance. Internal audit does not usually re-perform validation itself; instead it assesses whether the validation function, and the broader model risk management framework, are designed and operating effectively. Conflating the two blurs the independence that internal audit is meant to provide, since the third line is expected to evaluate the work of the second line rather than duplicate it.
Does internal audit own or manage model risk?
No. Ownership and day-to-day management of model risk typically rest with the first line (model owners, developers, and users) and the second line (independent risk oversight and validation). Internal audit provides independent assurance over how those lines identify, measure, monitor, and control risk. Framing internal audit as an owner or manager of model risk undermines its independence; its role is to assess and report on the adequacy of controls, not to design or run them. Internal audit activity reduces the likelihood that control weaknesses go undetected, but it does not eliminate model risk.
How does internal audit typically scope a review of the model risk management framework?
Scoping commonly begins with an assessment of the organization's model inventory, the risk-tiering applied to models, and the areas where control weaknesses would have the greatest impact. Reviews are often prioritized using inherent risk and the maturity of existing controls. The scope may cover governance structures, policies, validation activities, ongoing monitoring, and issue remediation, though the precise boundaries vary by institution and by sector, since expectations differ between, for example, banking contexts and general enterprise AI settings.
What evidence does internal audit typically examine when assessing model governance?
Auditors commonly review documentation such as model development records, validation reports, the model inventory, policy and procedure documents, governance committee minutes, monitoring results, and records of how identified issues were tracked and remediated. They may also assess whether roles, responsibilities, and reporting lines are clearly defined and whether the independence of the second line is preserved in practice. The specific evidence examined depends on the framework in use and the maturity of the organization.
How can internal audit preserve its independence when reviewing models?
Independence is typically supported by keeping internal audit organizationally separate from the functions that develop, use, or validate models, and by having it report to a body such as an audit committee rather than to management responsible for model outcomes. Auditors generally avoid taking on first- or second-line responsibilities, such as building or signing off on models, that they would later need to assess. The particular arrangements that achieve independence can vary across organizations and governance structures.
How often should internal audit review models or the model risk management framework?
There is no single universally required frequency. Review cadence is commonly driven by risk tiering, so higher-risk models or higher-impact control areas may be examined more frequently than lower-risk ones. Some organizations align audit cycles with a multi-year plan that ensures coverage of the framework over time, adjusted for changes in the model landscape, regulatory expectations, or identified issues. Sector-specific supervisory expectations may also influence timing, and these vary by jurisdiction and context.

Common misconceptions

Internal audit performs model validation.
Validation and independent audit are distinct activities. In many frameworks, validation is a second-line function that assesses whether a model is conceptually sound and performs as intended, while internal audit as a third line independently assesses whether validation and other controls were carried out effectively. Blurring the two can compromise audit independence, though specific arrangements vary by organization and sector.
A clean internal audit means the AI system or model carries no risk.
Audit assurance addresses the effectiveness of governance and controls, not the elimination of risk. Controls reduce or manage risk rather than remove it, so residual risk can remain even after a favorable audit. Audit findings are also point-in-time and scope-limited.
Internal audit is the same as compliance or second-line risk oversight.
Compliance and risk management functions are commonly positioned in the second line and are involved in ongoing monitoring and challenge, whereas internal audit provides independent assurance over both the first and second lines. Combining these roles can undermine the independence that gives audit its value.

Best practices

Maintain organizational independence for internal audit, typically through reporting lines that reach a board-level committee, so that audit is not reviewing its own work or work it directs.
Clearly delineate audit's assurance role from validation, monitoring, and control-ownership activities to avoid conflating the third line with first- and second-line responsibilities.
Structure audit scope to cover both AI governance elements (policies, accountability, oversight) and model risk management practices (identification, measurement, monitoring, control) as distinct areas rather than a single undifferentiated review.
Frame audit conclusions in terms of control effectiveness and residual risk rather than implying risk elimination, and note the point-in-time and scope-limited nature of findings.
Track and follow up on remediation of identified issues through a defined escalation and reporting process, distinguishing audit's advisory input from management's ownership of the risks.
Where a term, framework, or requirement is contested or evolving, document assumptions and scope explicitly in audit work so conclusions are not overstated as settled or universally applicable.