The internal audit function most valuable to leadership does more than report problems after the fact. It helps management see risk while decisions can still be shaped. That is the real test of a modern internal audit strategy, and it is a different test than conformance. 

The 2024 Global Internal Audit Standards raised the bar for the profession. Across 15 principles, the Standards define the purpose of internal auditing as strengthening an organization’s ability to create, protect, and sustain value through independent, risk-based, and objective assurance, advice, insight, and foresight.  

Three principles are especially relevant to that ambition: Principle 9, Plan Strategically; Principle 11, Communicate Effectively; and Principle 12, Enhance Quality. Conformance with them establishes a strong foundation. The real opportunity lies in how functions can use this foundation to deliver even greater strategic value. 

What the Global Internal Audit Standards require 

The Global Internal Audit Standards are the professional framework of the Institute of Internal Auditors (IIA). They require chief audit executives (CAEs) to align assurance activities with organizational strategy, risk, and governance, and the 2024 update raised expectations across ethics, board reporting, and quality management. 

Meeting those requirements is meaningful and reflects genuine professional rigor. But conformance is most valuable as a foundation, not a finish line. A function can satisfy every Standard and still leave real opportunity on the table if it has not translated that foundation into strategic relevance, proactive risk coverage, and insight leadership can act on. 

Why is this a leadership issue, not just an audit issue? 

Internal audit’s scope has grown well beyond financial controls. Technology risk, third-party exposure, ESG reporting, and AI governance are core areas of coverage, each carrying real strategic weight for finance, operations, and risk leadership alike.  

That makes the design of the assurance function a concern that reaches well beyond the audit team, because it shapes what leadership sees, and when.  

Audit committees feel this too: they are asking harder questions about coordination across audit, risk, compliance, and cyber teams, not just about individual findings.  

Five moves that turn assurance into foresight 

Two internal audit functions may both conform with the Standards yet differ significantly in how strategically they operate. The difference shows up in five behaviors, each one an expression of what the Standards make possible when a function commits to building on its foundation rather than resting on it.

Circular diagram titled "Five Ways to Put the Global Internal Audit Standards into Action." Five labeled boxes surround a central circle reading "Global Internal Audit Standards," connected by arrows showing a continuous cycle. The five elements are: Align (anchor audit work to enterprise strategy and risk), Connect (stay connected to business and functional leaders throughout the year), Evolve (continuously improve skills, methods, and capabilities), Integrate (connect risk intelligence, assurance coverage, reliance, and gaps across functions), and Anticipate (look ahead at emerging risks and opportunities).
  1. Align.
    Keeping the audit plan aligned to current and future business priorities is one of the clearest ways internal audit demonstrates strategic value. Standards 9.2 and 9.4 reinforce this directly: planning should reflect the organization’s strategic objectives, key initiatives, and evolving risk profile. Functions that build their plans around where the business is headed, rather than where it has already been, are better positioned to provide insight when it matters most. 
  1. Connect.
    Independence is essential; isolation is not. Standard 11.1 recognizes that ongoing communication is foundational to an effective internal audit function. That means staying connected to business and functional leaders throughout the year, not only during the annual risk assessment, or at the start of individual audits. Regular engagement lets internal audit see change as it forms, and adjust coverage before risk crystallizes into a finding. 
  1. Evolve.
    The same discipline applied to auditing the business should be applied to the audit function itself. Quality and maturity assessments create natural opportunities to evaluate whether the function is keeping pace, but so do strategy shifts, leadership changes, transformation initiatives, and new risk categories. Evolving also means asking whether the operating and resource models still fit: whether internal capabilities are being developed, whether technology is enabling the team, and whether the right mix of subject-matter specialists, guest auditors, co-sourcing, or targeted external expertise is in place. 
  1. Integrate.
    Coordination across assurance providers is the foundation, reinforced by Standard 9.5, but integrated assurance is the broader goal. That means actively connecting risk intelligence, coverage decisions, reliance opportunities, and identified gaps across internal audit, risk, compliance, cyber, and other assurance providers. When those views are integrated rather than parallel, leadership gets a clearer picture of where the organization stands and where blind spots remain. 
  1. Anticipate.
    The Standards’ emphasis on insight and foresight is not about predicting every risk before it arrives. It is about building the habits and connections that let internal audit recognize signals early and adjust assurance as the business changes. Stakeholder conversations, regulatory developments, and technology roadmaps all carry information about where risk is moving. Functions attuned to those signals reorient coverage proactively, giving leadership a view of what is coming, rather than an accounting of what has already occurred. 

Together, these five moves shift internal audit from a rear-view mirror to a forward view. That gives management and the board a function that can inform decisions as they are being made, and provide greater insight into what lies ahead. 

What a foresight-driven function looks like day to day 

Management, board, and audit committee stakeholders should expect specific, observable differences from a foresight-driven function: 

  • Dynamic planning tied to current strategy, emerging priorities, and evolving risk, rather than a static annual document. 
  • Ongoing business connectivity with management and functional leaders throughout the year. 
  • Integrated assurance across audit, risk, compliance, and cyber functions, with coverage gaps and overlaps actively identified and addressed. 
  • Enterprise-theme reporting that surfaces patterns and risk signals across engagements, not just findings from individual audits. 
  • Quality management embedded throughout the year, not only at scheduled review time. 

Certain moments naturally invite this kind of evolution: a new corporate strategy, a leadership transition, an acquisition, a major transformation, or a scheduled external quality assessment. Each is a chance to ask a harder question than “are we in conformance?” The better question is whether the assurance model is sound enough to trust with new technology, new risk, and new strategic bets. 

Organizational diagram showing how three lines of defense and external assurance connect under enterprise strategy to deliver an integrated view for leadership. The 1st line (Management/Business) owns and manages risk. The 2nd line (Risk and Oversight) provides oversight and risk management support across ERM, compliance, cyber, privacy, and SOX/controls. The 3rd line (Internal Audit) provides independent assurance and insight. External Assurance supports an additional independent perspective. Together, they feed connected risk information, assurance coverage, coordination and reliance, and visibility into gaps and overlaps into an integrated view for leadership, resulting in better coverage, less duplication, clearer insight, and better informed decisions.

The foundation, and what gets built on it 

The Standards give internal audit a foundation. The strategic value comes from what the internal audit function builds on top of it. Functions that stay connected to the business, evolve as the risk landscape shifts, integrate assurance across the enterprise, and anticipate risk early do more than produce clean assessments. They help management navigate change and make better decisions while there is still time to act. 

CrossCountry Consulting works with internal audit functions at every stage, whether the need is to evolve the operating model, strengthen assurance integration, or position internal audit to support leadership through strategic change. 

This is the first article in a three-part series on building a foresight-driven internal audit function. Part two examines integrated assurance in depth. Part three explores where AI fits, and where it does not. 

Connect with an expert

Mike Visconti

Integrated Risk Management

See Bio

Daniel Fornelius