One Auditor, Two Tribes
My internal audit team's training budget splits in half every year: half to the IIA, half to ISACA. Two memberships, two certifications, two of everything, for a job that has fused into one while the institutions stayed split. Why does the profession still run two tribes? On how the split made sense once, why AI is ending the case for it, the four futures ahead, and who really holds the power to change it. #internalaudit #IIA #ISACA #AI #GRC
Rethinking professional governance for internal audit in the age of AI
1. The problem, from where I sit
I have managed internal audit teams for years. Every year, I was responsible for a small piece of administrative work that had started to bother me more than it should as of late. I created my team's professional-development budget, and I watched it split almost perfectly, down the middle. Half of it went to The Institute of Internal Auditors. The other half went to ISACA.
Two memberships. Two sets of annual dues. Two certification ladders, the CIA on one side and the CISA on the other, each with its own exam fees, its own maintenance fees, and its own continuing-education regime that we had to track separately. Two standards frameworks we were expected to know: the IIA's Global Internal Audit Standards and ISACA's IT Audit Framework. Two conference ecosystems. Two research libraries. Two of nearly everything.
Here is the part that nags: these days, my auditors are not two kinds of people doing two kinds of work. They are one kind of person doing one kind of job. On any given engagement, the same auditor will trace a revenue-recognition control through configuration, test the access model behind it, read the SOC report on the cloud service it runs on, and write up the business impact for an audit committee that does not care which "tribe" the finding came from. The work has fused. The institutions that certify, train, and govern the work have not.
If this were a niche irritation, it would not be worth writing about. It is not niche. The IIA reports roughly 260,000 members and has awarded more than 200,000 CIA certifications [1]; ISACA counts around 185,000 members [2], with more than 150,000 people holding the CISA [3]. In a modern internal audit function at a technology company, carrying both is not the exception; it is common. Multiply my split budget across the profession and you are looking at a structural feature, not a personal quirk.
So this paper starts with a practitioner's question: why am I paying two organizations to govern one job?
The question worth asking
The lazy version ends at "the IIA and ISACA should merge." I want to resist that ending, because it assumes the answer before examining the evidence, and because a merger is only one of several ways the profession could organize itself. The more useful question is a design question:
If internal audit were being invented today, with today's technology, today's risk landscape, and today's tools for building institutions, what governance model would we choose? And how far is that from the one we actually have?
That reframing matters for a reason I will spend the rest of the paper defending, and it turns on a distinction: between the work and the institutions that govern it.
The work has already converged. The auditor who traces a control through an ERP, tests the access model, and reads the SOC report is doing one blended job, not two adjacent jobs. The institutions have not converged. They still run the two parallel tracks they laid down decades ago. Lately each has been expanding to cover the other's ground rather than ceding it. The IIA is reaching into technology and cyber risk; ISACA is reaching into governance, privacy, risk, and enterprise assurance. That is not two organizations moving toward each other. It is two organizations independently trying to own the whole field, which produces more duplication, not less, and leaves practitioners paying twice for a body of knowledge that overlaps more every year.
So the interesting question is not whether the work will converge. It already has. The question is whether the institutions governing audit ever will. If they won't do it themselves, who is going to make them? Decades of parallel operation have given both organizations enormous inertia to keep two duplicate structures standing. Inertia like that does not yield to a good argument alone. It yields to pressure from the people who fund it.
A disclosure, up front
I should be straight about my position. Outside of my day job, I build software and platforms for the audit and GRC profession, and my design instincts run toward federation, open standards, and data sovereignty. When I get to the section on possible futures, two of the models I describe will look a lot like the way I already think the world should work. A reader would be right to be suspicious of that.
So I will hold myself to a rule for the rest of this post: I will make the strongest case I can against my own leanings before I make the case for them. The status quo has real arguments in its favor, and so does the idea that specialization should endure rather than dissolve. If those arguments survive contact with the evidence, I will say so. If they do not, that conclusion will have been earned rather than assumed.
This post is written as an exploration. The world is changing quickly, and the impact on the audit profession has yet to be seen. My hypothesis is that the two-body model persists on inertia rather than merit: it made sense once and has simply never been made to justify itself since. My hope is that setting the argument out plainly gives practitioners like me the standing to ask that the justification be reexamined. The institutions have decades of momentum behind keeping things as they are. Changing that will take pressure from the people who pay for both. This paper is meant to be a small piece of that pressure, an honest piece, which is why I will argue the other side first.
2. Why the split was rational
Before arguing that the wall between the IIA and ISACA has outlived its purpose, I want to acknowledge that it had purpose. The two-body model was not a turf grab or a historical accident. It was a sensible answer to the conditions of its time.
The IIA came first, established in 1941 for a profession rooted in accounting and operations: the internal auditor who examined financial records, tested business processes, and reported to management on whether the organization's own controls held. That auditor's raw material was ledgers, transactions, and people.
Then the computer moved into the enterprise and broke the model. Through the early 1960s, auditors could still work "around" the computer: treat the machine as a black box, reconcile what went in against what came out, and assume the middle behaved. That was tenable only while the middle stayed simple and the stakes stayed low.
The Equity Funding fraud ended that comfort. Over roughly a decade, managers booked large volumes of fictitious insurance policies directly into the company's systems to inflate its stock, and auditors checking outputs against inputs saw nothing wrong, because the fraud lived inside the machine, in records that looked clean from the outside. It took two years to unwind after a whistleblower surfaced it. The lesson landed hard: you could no longer audit around the computer. You had to audit through it, and almost no financial auditor had the skills to do that [4].
The scarcity was real and specific. In the 1960s, few people could read a system's internals. The people who could were clustered in places like Southern California's aerospace firms, where mainframes such as the IBM System/360 were running the business. The discipline barely existed; its first practitioners later recalled having nowhere to turn for guidance and no established body of knowledge at all. In 1969, seven of them incorporated the Electronic Data Processing Auditors Association, the organization that would eventually become ISACA [5][6][7]. Tellingly, they were neither programmers nor financial auditors. They were building a new profession, and they knew it.
From there, everything forked, and for defensible reasons. A new profession needed its own body of knowledge, so EDPAA began codifying one: Control Objectives in 1977, which decades later grew into COBIT [8]. It needed its own mark of credibility, so it introduced the CISA in 1978 [5]. Meanwhile the business-audit world consolidated its own foundations: the IIA's standards and, by 1992, the COSO framework for internal control [9]. Two professions, two knowledge bases, two credentials, two career ladders, two conference circuits. The wall between "business" and "technology" audit was not drawn out of ego. It was drawn because, at the time, the two kinds of work genuinely required two kinds of people, and no single institution could have served both well.
The rest of the paper argues the arrangement has outlived its usefulness. Specialization was the correct response to scarcity: scarce expertise, scarce tooling, scarce shared language. When a skill is rare, costly, and hard to transfer, the efficient move is to concentrate it, credential it, and build an institution around it. That is not bureaucratic instinct. It is good economics.
Which is precisely why the next question carries weight. Every condition that justified the split was a form of scarcity. So what happens to the justification when the scarcity disappears?
3. What changed
The two-body model rested on three scarcities: expertise, tooling, and a shared technical language. Each was a load-bearing pillar, and all three are now giving way: first eroded by the general spread of technical knowledge, now, decisively by AI.
The auditor's side of it
For most of the profession's history, the boundary between business and technology audit was enforced by a simple fact: the financial auditor could not read the system. Understanding what a piece of infrastructure did, whether a configuration was sound, or how data moved through a pipeline took someone who had spent years learning to do exactly that. So you hired that someone, or you sent the work over the wall to the other tribe.
That is no longer true, and any auditor who has worked through the last two years has felt it. The specialist knowledge that used to sit behind the wall is now available on demand. An auditor can put an unfamiliar system in front of an AI, ask it to explain the architecture in plain terms, get a first read on where the control risks likely sit, and be usefully oriented in minutes instead of waiting two weeks for a specialist's calendar to open.
One example from my own recent work makes the shift concrete, and it is deliberately not a story about a clever tool, but about a boundary dissolving:
Recently I ran an AI governance review from end to end. While my background includes both the CIA and the CISA, I spent more time on the business process side of audit. The first half of the review was familiar ground: confirming an oversight committee exists, that a RACI matrix assigns clear ownership, that the controls the stakeholders rely on are actually being evaluated. That is textbook business audit. The second half was not: reading the system's own code repository, with AI alongside, to find where the technical implementation drifts from the policy, where the control gaps sit, and where risk keeps living past what the governance documents claim. Finding those gaps in the code would once have meant pulling in a technical specialist. Here it took minutes. Not long ago this was two people's engagement: a business auditor for the policy layer and a technical auditor for the implementation. This time it was one person, and the handover I would once have made to a technical specialist simply never happened.
None of this turns an auditor into a software engineer. What it does is make the specialist's knowledge portable in a way it never was, decoupling it from the specialist's career. And that decoupling is the whole game, because the career separation is exactly what the two-body model was built to institutionalize.
The institutions' side of it
A skeptic can fairly say: your daily work changed, but that is your anecdote. So set the anecdote aside. The stronger evidence is that the two organizations are themselves behaving as though the boundary is collapsing, and that is observable to anyone.
Watch the IIA march into technology. Its 2024 Global Internal Audit Standards modernized the profession's core framework [10][11], and on top of them the IIA began issuing mandatory Topical Requirements. For its very first one (issued February 2025), it chose cybersecurity [12]. Not culture, not fraud, not any of the business-audit topics that are the IIA's own heritage. Cybersecurity: the most iconic square of ISACA's founding turf, planted as the flagship of the IIA's new mandatory regime. The second requirement, third-party risk, sits in the same cyber-and-vendor borderland. Only after that do the topics turn back toward the IIA's native ground [14]. And when it comes to how a cyber audit is actually performed, the requirement's user guide points outward: it crosswalks the requirement to three frameworks auditors already use, the NIST Cybersecurity Framework 2.0, NIST 800-53, and COBIT 2019 [15]. Two are the US government's; the third, COBIT, is ISACA's. The coverage is the IIA's; the testing maps belong to other organizations, one of them its rival's.
Let's look at what kind of instrument a Topical Requirement is, because this is where the move gives itself away. By the IIA's own definition it is a minimum baseline [13]: a consistent floor of things an audit must address in a given risk area. That is breadth, not depth; coverage, not mastery. Even the requirement's most technical passage bears this out. Where it names specifics, it names domains: configuration, encryption, patching, user-access management, network segmentation [12]. A list of domains is the broadest instruction there is. It marks out scope areas to examine; it does not descend to the control objectives beneath them, let alone the controls themselves or the skill required to test any one of them. It tells an auditor where to look, not how to see. Requiring every internal audit function to assess cybersecurity is not remotely the same as producing auditors who deeply understand it.
The Topical Requirement does not pretend otherwise. Its own user guide says as much: a function that lacks the required knowledge may outsource the work, while the chief audit executive stays responsible for conformance [15]. That is the mechanism laid bare: mandate the coverage, import the depth. The two halves are not even the same kind of thing: the assessment the IIA requires is compulsory, while the technical yardsticks it points auditors to, NIST and COBIT, are voluntary, and not its own. It is coverage, not mastery, that a Topical Requirement actually requires. Which means the IIA's expansion into ISACA's territory takes the shallowest available form: more scope, not more specialization. Breadth is the last thing internal audit is short of. Its mandate already sprawls across more risk areas than any one team can cover in depth. Another required topic just stretches coverage wider while adding no mastery at all.
Watch ISACA move toward everything else. The association founded to serve EDP auditors has repositioned itself around "digital trust" and now ships a Digital Trust Ecosystem Framework with dedicated audit, privacy, risk, and quality packages [16]: a full assurance stack, not an IT-audit niche.
Then watch them collide exactly where the future is being contested: AI. ISACA launched its Advanced in AI Audit (AAIA) credential in 2025, and the detail every practitioner should sit with is the eligibility list. To sit for ISACA's flagship AI-audit exam, you do not need an ISACA credential at all. You can qualify with the IIA's CIA, or with a CPA [17], and in mid-2025 ISACA widened the gate further to admit a slate of international accounting credentials [18]. Read that plainly: the IT-audit body now accepts the business-audit body's flagship certification as an equivalent entry ticket to the most important new frontier in the field.
That is convergence, declared by the institutions themselves. But look at the form it takes. ISACA did not merge anything or retire a duplicate structure. It built a new credential on top of the existing ones, and AAIA holders have to keep both the AAIA and the underlying credential they qualified with (their CISA, CIA, or CPA) active at once, each carrying its own maintenance fee and its own continuing-education hours [19]. The lines are being crossed and duplicated at the same time. Convergence in substance; multiplication in structure. It is the exact inefficiency this paper opened with, now playing out on the newest and most visible part of the profession.
Notice what the eligibility list actually admits. AI assurance is not the old IT-audit scope drawn slightly larger. It is a genuinely new domain (model risk, data governance, bias, the behavior of agentic systems), and it belongs cleanly to neither heritage, blended from the start. That is why ISACA's flagship AI-audit credential has to accept the CISA, the CIA, and the CPA as equivalent entry tickets. The institutions are conceding, in their own rulebooks and at the exact frontier where the future is being decided, that the 1978 carve-up no longer maps the work. The newest domain refuses the oldest boundary.
There is a name for what we are watching, and it is not cooperation. The sociologist Andrew Abbott [20] described the professions as a system in which each body's territory is defined by its ability to claim jurisdiction over particular work, and in which the natural response to contested ground is not to divide it but for each claimant to reach across and assert the whole. That is precisely the behavior on display: not two organizations converging toward a shared center, but two organizations independently annexing each other's territory. Abbott's warning, and the one practitioners should sit with, is that these jurisdictional contests are rarely settled by merit or efficiency. They are settled by who can hold the ground, which means they can persist, wastefully and unresolved, for exactly as long as both claimants have the resources to continue doing so.
Worse than paying twice
It would be easy to file all of this under waste (two invoices for one profession) and stop there. But duplication is only the visible symptom. Abbott's lens shows the deeper symptom: when two bodies contest the same jurisdiction, the first casualty is authority itself.
A professional standard exists to answer one question cleanly: what does competent practice require here? On the frontier, two bodies answer it. The IIA and ISACA both issue authoritative guidance over cybersecurity, third-party risk, and AI assurance, from different heritages and under no obligation to agree. Where they align, as on the cyber frameworks, it is voluntary; where they diverge, no one adjudicates. On the fastest-growing, highest-stakes part of the work, the profession no longer has a single source of truth. It has a jurisdictional dispute.
Here the strongest defense of the two-body model deserves its hearing, because it is real: competition between standards bodies can be a virtue, not a defect. A monopoly standard-setter ossifies; rivalry keeps both bodies sharp and forces innovation neither would attempt alone. This is not hypothetical: COBIT itself, now indispensable, was an ISACA innovation the business-audit world would never have produced [8], and the profession is richer for it. Pluralism has paid real dividends. But the dividend and the danger are not evenly distributed across the field.
Where a body of knowledge is mature and slow-moving, two competing standards can refine each other for decades at little cost. Where it is new, fast, and high-stakes (which is exactly the AI-and-cyber frontier both bodies are now racing to claim), the calculus inverts: the profession needs a settled answer faster than rivalry can produce one. Two clashing standards arriving at once cost more to the profession than the competition's innovation is worth. Standards competition is a virtue in the mature core and a liability at the volatile edge. The trouble is that the edge is where all the growth now lives.
But whatever competition's merits at the core, notice who pays for the dispute at the edge. Not the institutions, which issue their guidance and collect their dues either way. It is the practitioner in the middle, left to reconcile two overlapping regimes and decide, engagement by engagement, which authority governs: integration work that neither body performs for her, because neither body owns the whole. Each reaches into the center from its own edge and answers only for its slice. The fused engagement that actually defines modern audit ends up covered by both and owned by neither. Divided authority on the ground, becomes no authority at all. That is not merely inefficient. It is a governance gap sitting precisely where the profession can least afford one.
The reconciliation cost does not stop at the practitioner. Internal audit exists to manufacture something other people consume: assurance. Boards, audit committees, regulators, and, indirectly, everyone who trusts that an organization's controls were independently checked all rely on "we audited it" meaning something consistent. When the authority behind that sentence fragments at the frontier, the fragmentation is silently inherited by the people relying on the opinion. An audit committee told its AI governance was assessed has no way to know whether that assessment was scoped to the IIA's baseline, ISACA's framework, both, or the seam between them where each assumed the other was prominent. The profession's entire product is independent assurance; a governance gap at the frontier is therefore not an internal housekeeping problem but a slow leak in the one thing it ultimately sells. Trust.
The honest objection
AI does not erase the need for specialists; it raises the bar for them.
The argument runs like this. When an auditor asks an AI to explain a cloud access misconfiguration, the model answers with equal confidence whether it is right or wrong. Catching the moment AI is wrong takes enough genuine expertise to know better. AI lowers the cost of looking competent while raising the stakes of actually being competent. The judgment required to supervise the tool is deeper than the judgment required to do the old task by hand. Judgment about technical systems is precisely what specialization produces. Accountability compounds the point: when an audit opinion is wrong, no regulator accepts "the model said so." Someone has to have understood. On this reading, specialization is not a relic of scarcity at all; it is how a profession manufactures the people who can tell when the confident answer is the wrong one.
This is the best case against my thesis, and I do not think it fails. But it argues for something narrower than it first appears. This is a case for preserving deep expertise, not a case for preserving two separate institutions to house it. The auditor who can catch the model's mistake needs real competence; nothing about that competence requires she be credentialed by a different organization, governed by a different standard, and renewed through a different CPE regime than the rest of her work. The objection defends specialization as a human capability. It does not defend the two-body model as an institutional arrangement. Those are different claims, and only the second one is what this paper is contesting.
4. Four futures
If the two-body model is duplication dressed as tradition, what should replace it? There are four broad possibilities. I will judge them all by the same question, the one this paper has been building toward: Who would apply the pressure to get there, and does that pressure actually exist? A future with no way to reach it is a wish, not a scenario.
I also owe the reader more honesty here. Two of these futures flatter my instincts and two do not. So I will make the strongest case I can for the two I like least, and turn my sharpest scrutiny on the two I like most. If my preferred models survive that, they will have earned it.
Future 1: The status quo
The parallel tracks simply persist: two bodies, two standards, two credential ladders, two sets of dues, forever.
It is easy to dismiss this as inertia, but inertia undersells its strengths. The current arrangement carries decades of accumulated trust: employers recognize the CIA and the CISA, regulators accept them, audit committees know what they mean. That recognition took fifty years to build and could be destroyed quickly by a botched consolidation. The redundancy is costly but not fatal; no audit fails because its author holds two certifications from two organizations instead of one. Two competing bodies keep each other sharp: a real virtue in the mature core, whatever it costs at the frontier. A monopoly credential-issuer would carry its own pathologies and have less reason to improve.
Here is the uncomfortable part, seen through the agency lens: the status quo is the only future that requires no pressure at all. It is the default. It survives precisely because the pressure to change is diffuse, spread thinly across hundreds of thousands of mildly annoyed dues-payers, while the pressure to preserve is concentrated in two organizations whose existence depends on it. That asymmetry is the whole story. The status quo wins unless something shifts the balance, and every other possible future has to overcome that.
Future 2: Federation
The bodies stay independent but bolt themselves together: a shared body of knowledge, cross-recognized credentials, joint standards, perhaps a common platform. Alliance, not merger.
This one is not hypothetical; the adjacent accounting profession has already done exactly this. In 2017 the AICPA and CIMA formed the Association of International Certified Professional Accountants, spanning public and management accounting, while both founding bodies remained intact and kept serving their members [21][22]. It is proof the model works at scale.
But precisely because it is the path of least resistance, federation deserves suspicion, including from those of us inclined to like it. It works by not forcing either body to dissolve, which means it can preserve the underlying duplication while draping a banner of unity over it. Two dues, two staffs, two CPE regimes can all survive a federation. We have already seen a micro-version of it here: ISACA accepting the CIA toward its AI-audit credential, and it added cost rather than removing it. Federation is the most likely of the change scenarios and the least transformative. Unless it actually retires duplicate machinery, it risks being convergence in name only. Its agency is real but weak: the bodies would have to earnestly want it, and they have little reason to cannibalize their own dues without an outside push.
Future 3: The unified body
One organization. One standards regime. One certification ladder, built as a common core with specialization tracks stacked on top: audit, IT, AI, and whatever comes next.
This is the cleanest possible answer to the complaint this paper opened with. Under a unified body the duplication simply ends: one membership, one CPE regime, one standard, one credential family. It also answers the objection from Section 3 directly: deep expertise is preserved because specialization lives inside the structure rather than requiring a second institution to house it. And this is not a speculative arrangement; it is how the most demanding expert professions already organize themselves.
Medicine runs on a single licensing spine, the physician, with board specialties from cardiology to radiology stacked on top [23]; a cardiologist and a family doctor are both physicians, and no one imagines the specialist needs a rival institution to the generalist to prove her depth. Law does the same, with a unified bar and practice specialization layered above it [24]. Deep specialization and a single governing structure are not in tension; the professions that stake lives and liberty on expertise resolved that question in favor of one house long ago. Audit's own neighbor is now following: the accounting profession's CPA Evolution model, launched in 2024, rebuilt licensure around a common core plus a chosen discipline [22]. That is precisely how a unified audit credential could hold generalists and specialists under one roof without flattening anyone. For the practitioner, this is unambiguously the most efficient outcome, and it maximizes the profession's collective voice.
It is also the hardest future to reach, by a wide margin. True unification requires one body to absorb or dissolve the other, an existential demand no incumbent leadership volunteers for. Worse, no obvious actor has the power to impose it: individual members cannot force a merger, employers can lobby but not mandate, and regulators almost never legislate the structure of a profession's private associations. The unified body is the best destination and the least feasible route. The tension is real and cannot be wished away.
Future 4: The open ecosystem
Not a membership association at all, but an open, community-governed commons: open standards, a publicly maintained body of knowledge, portable and vendor-neutral credentials, updated by the practitioner community that uses them. The governance model of open-source infrastructure, the foundations that steward Linux and the cloud-native stack, pointed at the audit profession.
This is my own strongest instinct, which is exactly why I have to be hardest on it. Three honest problems. First, credentials rest on enforceable trust: a certification is worth something because a recognized authority stands behind it and can take it away, and open governance struggles to supply the accountability that regulators and audit committees lean on. Auditing is, above all, a trust profession. Second, "open" does not imply "unified." The security field is already open in the sense of many competing bodies and vendor certificates, and the result there is more fragmentation, not less; openness can multiply credentials as easily as it consolidates them. Third, the agency question is the least answered of any model: the open ecosystems that actually work tend to be underwritten by deep-pocketed corporate backers, and it is not clear who funds a vendor-neutral audit commons, or whether it stays vendor-neutral once someone does. It is the most exciting model and the least proven for a profession whose entire product is independent trust.
The pattern underneath
Line the four up and an uncomfortable shape appears. The future that best cures the duplication, the unified body above all, is the hardest to reach. The futures easiest to reach, the status quo and federation done lightly, are the ones that preserve the waste. Efficiency and feasibility point in opposite directions, and the variable that decides which future actually arrives is not the merit of the idea. It is where the pressure comes from.
Which returns us to the question the whole paper has been circling: if the institutions will not move themselves, and no regulator is coming to move them, who is left?
5. What would have to be true
I am not going to tell you which future arrives. I am sharing my thoughts on what each future requires, and then point out what all four requirements have in common.
For the status quo to hold, nothing has to happen at all. That is its defining feature. The parallel tracks persist for exactly as long as the people paying for both keep paying without objection: renewing two memberships, listing two certifications on the same job posting, approving the split training budget as a line item too small to question. The status quo needs no defenders. It needs only that no one who pays the bills decides it is a problem.
For federation to mean anything, the bodies would have to be rewarded for actually retiring duplication rather than for merely announcing partnership. Cross-recognition that stacks a new credential on top of the existing two, the path we are already on, is not convergence; it is accumulation. Real federation would require buyers to understand the difference and pay only for the version that consolidates. That signal has to originate somewhere.
For a unified body to become reachable, the merger would have to cost the institutions less than the alternative, and today it costs them far more. The status quo is comfortable. That only inverts if employer demand makes division the expensive option, if the market begins to reward the rationalized credential over the doubled one. Unification does not start in a boardroom of the two bodies. It starts when their customers make staying divided the costlier choice.
For an open ecosystem to earn its place, practitioners and firms would have to adopt and fund it in enough numbers to give an open credential the one thing it cannot generate on its own: recognition. An open standard nobody hires against is a hobby. What would make it real is exactly what would make any of these real: a critical mass of the people who pay deciding to pay differently.
Read those back and the pattern is unmistakable. Four futures, four preconditions, and every one of them routes through the same actor. Not the IIA. Not ISACA. Not a regulator. The demand side: practitioners, and the employers who fund them. In every scenario, the institutions turn out to depend on the people who buy what they sell, not the other way around.
Why the lever sits unused
If the demand side holds the power in every scenario, the obvious question is why it has never used the power. The answer is not that practitioners are asleep. It is that they are caught in a trap. A certification is a signal: it is worth carrying because employers screen on it [25], and in a market that screens on credentials the rational move for any individual is to accumulate them, not shed them. Holding both the CIA and the CISA is career insurance. The first auditor to drop one does not strike a blow against duplication; she simply looks less qualified than the colleague who kept both. So the collective interest, one rationalized credential, runs exactly opposite to each individual's incentive. The wall stands, not through inattention, but because everyone is rationally declining to disarm first. That is a collective-action problem [26], and collective-action problems do not dissolve because the participants are annoyed. They dissolve when someone with different incentives changes the payoff.
Which is why it matters to pull apart the two actors this paper has so far bundled together. The individual auditor is trapped in the signaling game and cannot escape it alone. The employer is not. The chief audit executive building that split budget is the one party who feels the double cost directly, hires against the credential, and could, by treating a single rationalized qualification as the thing worth paying for and promoting. This can begin to change what the market screens on. Pressure to consolidate cannot originate with the people selling their labor, because they are individually punished for moving first. It can only originate with the people who buy it.
There is one more beam holding the wall up that no budget line captures, the one this paper's title has been pointing at all along. The two tracks are not only two invoices; they are two identities. An auditor who came up through the CISA and one who came up through the CIA often understand themselves as different kinds of professional, and identity is far stickier than economics. Same with the CPA backed auditor. It is why the purely rational case for consolidation understates the resistance it would meet: you are not asking people to cancel a subscription, you are asking a profession to stop being two things it has believed itself to be for half a century. Any future that requires the wall to come down has to move not just money but self-identity. That is another deep reason the demand side's leverage, though real and decisive, has stayed something practitioners hold rather than something they use.
The open question
Which is where this paper has to leave you, because the ending is genuinely not mine to announce. It is ours to make, and mostly we are not making it.
We are the ones holding the leverage. We renew both memberships on autopilot. We write job postings that ask for the CIA and the CISA as though they named two different species of auditor. We sign off on the two-column training budget and file the mild irritation away until next year. The wall between business audit and technology audit, the one the work itself stopped believing in years ago, does not stand because the institutions are strong. It stands because the people who could push it over are, so far, holding it up.
I do not know which future the profession will choose. I know that it is a choice; that it belongs to us and not to them; and that "us" includes the version of me who, last year, approved the split budget. This time, I had a second thought that I share publically with you now.
So the uncomfortable question is not whether the two-body model can survive the age of AI. It is whether we will keep paying to hold it together long after we have stopped believing in it.
Sources
Numbered in order of first appearance in the text and cited inline as [N].
- [1] The IIA, press release on the Standards' effective date (January 2025; 260,000+ members and 200,000+ CIAs awarded)
- [2] ISACA, home and certifications (≈185,000 members; "digital trust" positioning)
- [3] ISACA, IT certifications (CISA: 151,000+ holders; ≈US$149,000 average salary)
- [4] Wikipedia, History of information technology auditing (auditing "around" vs. "through" the computer; Equity Funding; Control Objectives → COBIT)
- [5] ISACA, 50th-anniversary history (EDPAA incorporated 1969; seven founders; CISA introduced 1978)
- [6] Wikipedia, EDPAA (1967 origins; 1969 incorporation; Stuart Tyrnauer)
- [7] ISACA, "55 Years of Impact" (EDPAA 1969 → ISACA name 1994 → rebrand 2008; The EDP Auditor first published 1973)
- [8] ISACA, COBIT: developed by ISACA, evolved from Control Objectives (1977) into COBIT (1996). EBSCO Research Starter, "COBIT (Control Objectives for Information and Related Technologies)"; ISACA: https://www.isaca.org/
- [9] COSO, Internal Control–Integrated Framework: COSO was formed in 1985 (to sponsor the National Commission on Fraudulent Financial Reporting); the framework was released in 1992 and updated in 2013 (2013 version effective 15 Dec 2014). Independent sources: University of Wisconsin–Madison; CapinCrouse, http://capincrouse.com/C7Jnc . Official: https://www.coso.org/
- [10] The IIA, Global Internal Audit Standards (2024; effective 9 January 2025)
- [11] ACUA, overview of the new Standards and forthcoming Topical Requirements (cybersecurity, third-party management, IT governance)
- [12] The IIA, Cybersecurity Topical Requirement (official requirement document, February 2025): sets "a minimum baseline for assessing cybersecurity," states that "internal auditors must assess" the organization's cybersecurity governance, risk management, and control processes, and enumerates control domains to assess (configuration, encryption, patching, user-access management, network segmentation, and others). PDF. Landing page ("Issued: February 5, 2025 | Effective: February 5, 2026," confirming Cybersecurity as the first Topical Requirement; each requirement becomes effective 12 months after issuance)
- [13] The IIA, Topical Requirements (official). Defines a Topical Requirement as providing "a minimum baseline and relevant criteria for a consistent, comprehensive approach," and lists the requirements
- [14] Sequence beyond the first (Third-Party Risk second; Organizational Behaviour in consultation), IIA Australia
- [15] The IIA, Cybersecurity Topical Requirement User Guide (official PDF; read first-hand). Appendix B, "Mapping to Frameworks": "The chart below maps the Cybersecurity Topical Requirement to three commonly used frameworks: NIST Cybersecurity Framework 2.0, COBIT 2019, and NIST 800-53" (followed by multi-page crosswalk tables). The guide (p. 2) also states that if the internal audit function "does not have the required knowledge to perform audit engagements on a Topical Requirement subject, the engagement work may be outsourced," while "the chief audit executive retains the ultimate responsibility for ensuring conformance."
- [16] ISACA, Digital Trust Ecosystem Framework packages (audit, privacy, risk, quality)
- [17] ISACA, AAIA credential + eligibility pages (CISA universally qualifying; CIA/CPA and international accounting credentials qualify under role-focus conditions)
- [18] ISACA, "Expands Eligibility of First-ever Advanced AI Audit Certification" (July 2025; original trio CISA, CIA, US CPA, plus six global credentials added: ACCA, FCCA, Canadian CPA, CPA Australia, FCPA, Japanese CPA)
- [19] ISACA, "Maintain AAIA Certification." Dual maintenance: keep the prerequisite credential active and pay the AAIA annual maintenance fee (US$20 member / US$35 non-member) + earn AAIA CPEs (10/yr; 30 over 3 years)
- [20] Andrew Abbott, The System of Professions: An Essay on the Division of Expert Labor (University of Chicago Press, 1988): jurisdictional competition; professions compete over work rather than cleanly dividing it into permanent boxes.
- [21] AICPA & CIMA, Association of International Certified Professional Accountants (formed 2017; both founding bodies retained)
- [22] Wikipedia, American Institute of Certified Public Accountants (AICPA–CIMA Association 2017; CPA Evolution "Core + Discipline" model, new exam 2024)
- [23] American Board of Medical Specialties, Guide to Medical Specialties 2024. The "one spine, many specialties" model: a single state medical license, then board certification and subspecialization layered on top (24 member boards, 40 specialties, 89 subspecialty areas): PDF (context: HTML)
- [24] Law: unified bar admission first, then optional post-licensure specialization (not separate entry licenses by specialty). ABA, "Specialization resources for the public"; concrete state example, North Carolina State Bar Legal Specialization
- [25] Michael Spence, "Job Market Signaling," Quarterly Journal of Economics 87(3), 1973, pp. 355–374: credentials as signals employers screen on, and the individual incentive to accumulate them.
- [26] Mancur Olson, The Logic of Collective Action (Harvard University Press, 1965): why diffuse interests fail to organize against concentrated ones.
Comments