Independence Was Always a Proxy
Assurance Blog

Independence Was Always a Proxy

Global · · 17 min read

We have spent years signing off on internal audit's use of the word "independence." Here is the uncomfortable part: internal auditors are not independent in the sense the word carries, and AI is about to make that impossible to keep saying. The word was always a proxy for the thing we actually wanted, objectivity you can prove. On what the Standards really claim, how the IIA has quietly half-conceded, and the receipt-based architecture that should replace a borrowed word. #internalaudit #AI #IIA


What artificial intelligence reveals about internal audit's borrowed vocabulary

---

Start with a question that doesn't work

An AI agent performs the majority of control testing for an internal audit function. It samples populations, executes tests, evaluates exceptions, and drafts findings. A human reviews the output.

Is the agent independent?

The question doesn't make sense. Not because artificial intelligence is exotic, and not because the answer is obviously no. The reason is simple: independence, as internal audit uses the term, describes a relationship between a person and an employer. Remove the employment relationship and the concept has nothing to attach to. It simply falls off.

Notice what happens next. We still need to know whether the agent's work can be trusted, so we can ask:

Who trained it? Who controls the prompts? Can management suppress a finding before it reaches the board? Is the reasoning logged? Is the evidence immutable? Can the conclusions be reproduced by someone else? Who can alter the record, and does the record show that they did?

Every one of those questions is answerable. Not one of them is about independence.

That is the argument of this piece, and artificial intelligence is not the cause of it. AI is only the occasion. Those questions sound like machine questions but each has an exact human counterpart: who formed the auditor's judgment; who sets the scope and directs the work; whether the workpapers show the thinking; whether a second competent examiner would reach the same result. Asked of a person, they are the same questions, and they were always the right questions to ask. The profession never had to ask them, because it had a single word that stood in for all of them. Independence. 

That word has stopped working.

What the Standards actually say

The Global Internal Audit Standards define independence plainly and publicly. The glossary gives it in full: "the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner" [1]. That definition is printed in the guidance and has been since publication. Nothing has been concealed.

Read it carefully and notice what it is. It is a definition of working conditions. It says nothing about legal separation from the organization. Nothing about economic separation. Nothing about ownership, contract, or fee arrangement. Principle 7, "Positioned Independently," makes the location of the safeguards explicit. The board "establishes and protects" the function's independence, and the function can fulfill its purpose, in the Standards' words, only "when the chief audit executive reports directly to the board, is qualified, and is positioned at a level within the organization that enables the internal audit function to discharge its services and responsibilities without interference" [1].

Reporting line, access, and positioning. That is the whole apparatus.

This is a reasonable definition, but it is not what the word means anywhere else.

What the word carries

External audit independence is structural. An external auditor who holds an equity interest in the client is not independent. One who performs management functions is not independent. One who audits work they themselves produced is not independent. These are not matters of professional attitude. They are prohibitions, enforced by regulators, because external auditors serve capital markets rather than the organizations that pay them.

That is the picture that forms in a board member's mind when they hear the word. It forms in a regulator's mind. It forms in the mind of a journalist writing about a control failure, and in the mind of a jury.

Internal audit is not describing that. Internal audit is describing something considerably weaker and more conditional: an employment relationship with governance safeguards attached.

The lineage is not mysterious. Internal auditing emerged from accounting practice, and many of its early leaders came from public accounting. It would have been strange if the vocabulary had not come with them. Whether anyone chose the word deliberately is a question for historians, and the answer changes nothing. The mismatch exists either way.

The profession has already conceded

Here is what convinced me this is not just a semantic complaint. The profession's own most recent thinking has already moved, in everything but the label.

In July 2026 the IIA published the Three Lines Model as a Statement of Position, "Assurance and Advice in Support of Effective Governance," replacing the Three Lines Model position paper that had stood, with a 2024 update, since 2020 [3]. It is a more candid document than the Standards, and three things in it are worth reading closely.

It describes independence as existing along a continuum. The document states plainly that it "emphasizes independence of assurance providers along a continuum" [3]. That single phrase does more damage to the borrowed vocabulary than anything else here. External audit independence is not a continuum. It is binary, enforced by prohibitions: hold the equity and you are out. A concept that admits of degree is not the concept the word imports. The document's own comparison table makes the gradient explicit. The first line is "not independent (by design)," the second is part of management but may have organizational separation from operations, and the third has the "highest level of organizational independence" [3]. "Highest" is a comparative. Comparatives do not belong to binary concepts.

It decomposes independence into essential elements. The Statement of Position lists them by name: reporting lines and authority, autonomy over scope and planning, unrestricted access to assets and information, control over resources, and protection from retaliation or undue influence [3]. Something has happened here worth naming: once the parts are listed, the word adds nothing the list does not already say. The profession disassembled the thing, then reassembled it and kept the old label on the box. The parts are the reality; the word is the wrapping. What the parts are not, yet, is evidence. Every one of them is a condition the organization arranges, not a record it can produce. That distinction is the whole of the closing argument.

It sets a cooling-off period. At least twelve months between holding responsibility for a process and providing assurance over it is treated as sufficient to safeguard objectivity [3]. Compare the external audit treatment of the same threat. Self-review is not a waiting period there. It is a prohibition. The difference between a ban and a delay is exactly the difference between structural independence and managed objectivity, and the IIA has now documented that difference in its own guidance.

This is not the view of a single document. A second 2026 Statement of Position, on the internal audit function's role in enterprise risk management, makes the same shift on its own: the same twelve-month interval before an auditor may assure work they helped operate, and the same breaking-up of independence into a list of deliberate, board-visible safeguards rather than a single structural fact [4]. When two separate pieces of current guidance rely on the same conditions, it is the conditions, not the word, that the profession actually depends on.

This isn't a criticism of either document. Both documents are thoughtful, and both improve on what they replaced. It is evidence. The profession's most current thinking already treats independence as a gradient produced by nameable conditions and safeguarded by managed intervals. It has done everything except change the word.

One structural detail is worth noting. The July 2026 Statement of Position tells the reader outright that Statements of Position "are not part of The IIA's International Professional Practices Framework, because they are intended for an executive audience, rather than primarily for internal auditors" [3]. So the candid, decomposed, continuum-based account of independence lives in the non-mandatory document aimed at boards, while the mandatory guidance that internal auditors actually conform to retains the older and simpler treatment. The profession's clearest thinking on this question is the part that binds no one.

The gap is not harmless

A gap between a technical definition and a common connotation might be a curiosity. This one does damage.

It permits the profession to claim a form of credibility it has not structurally earned. When a board asks how it can rely on internal audit's conclusions, "independence" answers the question without answering it. It satisfies the asking without specifying a single mechanism. In the mandatory guidance the word still works as a stopping point, and in practice most conversations end there. That the Statements of Position have begun to open the term up is progress. It has not yet reached the guidance that binds.

It also lets the profession avoid the harder task. If independence is the guarantee, no one has to build anything else. The Standards do require a quality program, including a periodic external assessment, but it evaluates the function's conformance with the Standards, not the fate of any particular finding. Nothing requires an examinable record that a finding survived the review process intact, that a scope change was attributed to whoever ordered it, or that a second competent examiner, given the same evidence, would have reached the same conclusion. The review is required; a receipt of it is not.

And it forces the profession into a contradiction it is now trying to live with.

The advisory contradiction

The Three Lines Model presents internal audit as an active participant in governance rather than a detached observer of it. The Standards, which never mention the Three Lines Model by name, arrive at the same place by a different route: advisory services are a defined term running throughout the document, treated as ordinary internal audit work rather than as a contradiction requiring justification [1]. The profession has committed to collaboration in both its governance literature and its mandatory guidance. That is the right direction, and it deserves credit.

But the same documents insist the function remains independent.

To its credit, the IIA sees the tension. The Three Lines position paper and its 2026 replacement both state plainly that independence does not imply isolation [2][3], and the newer document goes further. It warns that the pursuit of independence can "unintentionally limit cross-functional communication or contribute to misalignment" among roles [3]. That is a genuine insight, and it is the profession diagnosing a problem caused by its own vocabulary.

But diagnosing is not resolving. To say that independence does not mean isolation is to say the word does not mean what it appears to mean, and then continue using it. The tension is named and absorbed rather than settled. What would settle it is specifying what an embedded, collaborative, advisory function does to make its conclusions trustworthy, given that structural detachment is no longer available and, by the profession's own account, no longer even desirable.

The answer is not to give up advisory work. Advisory work is valuable, and the profession is right to embrace it. The answer is to stop claiming a detachment that advisory work rules out, and instead show what makes an embedded function's conclusions trustworthy.

What would actually change

It is fair to ask whether any of this matters operationally, or whether it is a dispute about words. Here is what changes.

Conformance becomes falsifiable. A Chief Audit Executive can currently assert conformance with independence requirements by pointing to a reporting line and an approved charter. Both are real, and neither is evidence about any particular engagement. Under a mechanism-based framing, a reporting line is one input among several, and the CAE must demonstrate that the mechanisms operated. You cannot audit independence. You can audit a log.

Suppression becomes measurable. The Standards do address this, and the way they address it is instructive. Where an auditor and management disagree about engagement results, the CAE should work toward resolution, and a formal statement from each party may be attached to the final communication [1]. Both verbs are permissive, and the provision triggers only on declared disagreement. Nothing requires a record of findings that were softened, deferred, or dropped without anyone declaring a disagreement at all, which is how findings usually disappear. Once independence is understood as a proxy rather than a guarantee, the number of findings lost between draft and final becomes an obvious measure, and a revealing one.

Audit committees ask better questions. Every committee already asks "has management attempted to influence the scope or findings of any audit?" And every CAE answers it out loud, with or without management in the room. A better question is to ask for the record of every finding downgraded or removed between draft and issuance, with the requester named. That is a question with an answer. The other is a question with an assertion.

Machine-assisted work becomes assessable. Take the three documents that define this profession's posture: the Global Internal Audit Standards at roughly 120 pages, the Three Lines Model position paper as updated in September 2024, and the Statement of Position that replaced it in July 2026. Across all three, the phrase "artificial intelligence" appears zero times. So does "machine learning." So does "algorithm" [1][2][3]. (The 2026 Statement of Position on enterprise risk management does not use them either [4].) For the 2024 Standards this is forgivable; drafting closed well before publication. For a governance document issued in the middle of 2026 it is harder to explain. And it means a function that today delegates substantial testing to an AI agent has no framework at all for demonstrating that the resulting assurance is sound. The Standards address workpapers, supervision, and evidence sufficiency, all of which help. None of them answer whether a machine's conclusion can be relied upon, because the organizing concept the Standards would reach for breaks down the moment the examiner is a machine. Mechanism-based criteria apply to human and machine work identically. That is precisely what the next revision needs.

The profession stops being vulnerable to a fair attack. At present, any sufficiently motivated critic, a lawyer bringing a claim, a regulator, a reporter after a failure, can point out that the "independent" function reported to a CFO who set its budget. The profession has no good answer, because the answer requires explaining that its word means something narrower than everyone assumed. Better to have never claimed it.

What replaces it

Objectivity was always the objective. Credibility was the objective. Reliable assurance was the objective. Independence was an implementation, a good one for twentieth-century organizations, where the org chart was very nearly the only instrument available.

Better instruments now exist, and the profession has already laid part of the foundation. The Standards require that scope limitations be discussed with management and escalated to the board when unresolved, and that engagement documentation capture stakeholder requests to include or exclude items [1]. The 2026 Statement of Position goes further, naming autonomy over scope, unrestricted access, control over resources, and protection from retaliation as elements in their own right [3].

What follows is not a replacement for that work. It is the same list, framed differently. Every element the IIA names is a structural condition, something an organization arranges. Every element below is an evidentiary requirement, something an organization must be able to produce afterward. Autonomy over scope becomes a record of who changed the scope. Protection from retaliation becomes a record of what happened to the auditors who filed the hard findings. The difference between the two lists is the difference between a promise and a receipt.

I am building software that aims to produce these receipts, and I am building it ahead of any formal guidance from the IIA. That means making practical choices where the Standards say nothing yet, so read the list as a practitioner's attempt rather than a settled answer.

A governance architecture for objective assurance would specify, at minimum:

1. Mandate integrity. Scope cannot be narrowed, deferred, or redirected without a recorded decision attributable to a named individual. Not discussed. Not escalated. Recorded.
2. Evidence immutability. Workpapers are write-once. Alterations are appended, never overwritten, and the alteration record is itself part of the evidence.
3. Finding traceability. Every finding's path from first draft to final report is recorded, including each modification, each requester, and each stated rationale.
4. Reasoning transparency. For human and machine judgment alike, the basis for a conclusion is recorded in enough detail to be re-examined by someone who was not present.
5. Reproducibility. A second competent party, given the same evidence and criteria, reaches the same conclusion. Where they would not, the conclusion is disclosed as judgment rather than presented as fact.
6. Attributable authorship. Every finding records who or what produced it, with enough about that examiner to judge the work: for a person, their mandate and competence; for a model, its version, configuration, and the prompts that directed it.

None of this makes organizational placement obsolete. Reporting lines still matter, and so does protecting the auditors who file the hard findings. But these are mechanisms among several, each addressing one threat among several. The profession's error was never in using them. It was in treating them as the whole architecture and then calling that architecture by the wrong name.

A note on who should write it

The Standards are free to download, and the IIA deserves credit for that. They are not, however, free to use. The document is copyrighted, every page is marked "for individual personal use only," reproduction in any medium requires written permission from the IIA's Office of the General Counsel, and distribution for commercial purposes is prohibited outright [1].

Readable is not the same as open. A practitioner may read the Standards. They may not adapt them, extend them for their sector, publish a corrected version, or build tooling that embeds them. The profession's foundational text cannot be forked.

There is a tension in that. A framework built on inspectable mechanisms, reproducible conclusions, and transparent reasoning is asking organizations for a kind of openness the framework itself does not practice. If the argument here is right, that trust comes from architecture that can be examined rather than from a status taken on faith, then the architecture should be examinable in the same way. Specified openly. Implementable without permission. Open to being forked, criticized, and improved by the practitioners who have to live inside it.

That is a larger undertaking than one essay, and it is where this argument leads. It is also not the only place the profession's institutions have fallen behind the work they govern. A companion question is why one job is still run by two of everything, two bodies, two credentials, two standards.

The point

Internal auditors are not independent in the sense the word carries. They never have been, they cannot be, and, given what the profession has rightly become, they should not want to be.

Their legitimacy does not depend on it. It comes from something more durable and more demonstrable: governance structures deliberately designed to produce objective assurance, and to make it evident that they did.

The profession should stop defending a borrowed word and start specifying the architecture that will sustain assurance in the age of artificial intelligence.

Objectivity was always the goal. Independence was only ever one way to reach it.

References

1. The Institute of Internal Auditors, Global Internal Audit Standards (2024). Independence defined in the glossary as "the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner"; Principle 7, "Positioned Independently," and Standard 7.1, "Organizational Independence"; the copyright and permitted-use notice ("for individual personal use only"; permission from the Office of the General Counsel; commercial distribution prohibited); the disagreement-resolution and scope-limitation provisions.
2. The Institute of Internal Auditors, The IIA's Three Lines Model (position paper, 2020; updated September 2024). "Independence does not imply isolation."
3. The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance (Statement of Position, July 2026). Independence "along a continuum"; the first/second/third-line comparison table ("not independent (by design)" through "highest level of organizational independence"); the essential elements of independence; the twelve-month cooling-off period; the caution that pursuing independence can "unintentionally limit cross-functional communication or contribute to misalignment"; and the note that Statements of Position sit outside the International Professional Practices Framework as they are written for an executive audience.
4. The Institute of Internal Auditors, The Role of the Internal Audit Function in Enterprise Risk Management (Statement of Position, 2026). The same twelve-month interval before assuring work one helped operate, and the decomposition of independence into deliberate, board-visible safeguards.


Share

Comments

Subscribe

By email

Get the latest news and updates in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and tag.

View all feeds →
Feeds
Subscribe by email

Get the latest news and updates in your inbox.