CPA VIETNAM AUDITING COMPANY LIMITED
Qualified services, global understanding and vision

Implementation of Internal Audit Standards: From Compliance to Creating Corporate Value

17/09/2026 - 14:12      21 view
Implementing internal audit (IA) standards is not a “compliance burden” but rather a strong “shield” that helps enterprises remain resilient in the market. Enterprises that proactively transform and standardize their control systems in accordance with legal requirements and international practices can create competitive advantages and strengthen their credibility and transparency in the eyes of investors on the path toward sustainable integration.
Nội dung chính[ẩn][hiện]

The internal audit function must establish a performance measurement system and seek input from the Board of Directors to develop balanced and diverse performance objectives based on actual data. Illustrative photo.

Reshaping Corporate Governance

Against the backdrop of an increasingly volatile and complex global business environment, coupled with growing exposure to non-traditional risks, the role of corporate governance and legal compliance has been elevated to a new level. The new Global Internal Audit Standards (GIAS) issued by the IIA, effective from January 2025, are regarded as an entirely new operating philosophy that enhances the quality of internal audit activities while strengthening stakeholders’ confidence in the assurance role of internal audit in corporate governance.

According to the IIA, alongside five unified domains covering the entire lifecycle and activities of internal audit, 15 core principles, and approximately 50 mandatory standards, the key strength of GIAS lies in its requirement for Chief Audit Executives (CAEs) to establish a formal, long-term internal audit strategy spanning 3–5 years, clearly defining the vision, strategic objectives, and initiatives supporting the execution of the internal audit mandate.

To measure the performance of strategy implementation, the internal audit function must establish a performance measurement system, requiring CAEs to engage in dialogue with and seek input from the Board of Directors and executive management to develop balanced and diverse performance objectives based on actual data. Furthermore, to control specific risks, the IIA has incorporated topical requirements into the framework that must be applied when auditing areas involving significant risks.

Notably, in 2025, the IIA introduced a cybersecurity topical requirement, establishing a mandatory minimum baseline for auditing an organization’s cybersecurity governance, risk management processes, and control activities. Most recently, the third-party topical requirement, applicable from September 2026, sets stringent standards for internal audit in assessing supply chain and external partner risks.

The “Quantification Trap” and Regulatory Pressure

Although GIAS opens a promising new chapter for corporate governance, the practical transition during the initial period of 2025–2026 has encountered considerable obstacles. These challenges arise not only from organizations’ internal capabilities but also from misunderstandings about the nature of performance indicators and mounting pressure from new regulatory requirements.

According to the IIA’s professional guidance on performance measurement, developing evaluation criteria requires balance and practicality. However, many enterprises are falling into the “quantification trap” by over-relying on superficial indicators while overlooking qualitative aspects.

For example, the rate of implementation of audit recommendations is often used to assess the impact of internal audit. However, implementing recommendations is the responsibility and authority of executive management and falls outside the direct control of internal audit. Similarly, the level of management agreement with audit findings is an indicator that can seriously compromise the independence and objectivity of internal audit. Pressure to achieve a high level of agreement can create a precedent whereby audit findings become “negotiable,” undermining the integrity of the entire audit process.

In practice, fully complying with GIAS’s highly detailed and mandatory requirements presents a challenge for internal audit teams with limited resources. With a small number of personnel, internal audit functions may find it difficult to ensure absolute independence, develop a comprehensive long-term strategic documentation system in accordance with GIAS, operate a Quality Assurance and Improvement Program (QAIP), and conduct periodic independent external quality assessments at the same time.

In addition, changes in national laws and regulations create further pressure on internal audit, requiring organizations’ internal control and internal audit functions to continuously update their knowledge and respond promptly. This can create a significant compliance burden if enterprises have not made adequate preparations in advance.

Strengthening the Strategic Advisory Role

To overcome these barriers and turn internal audit into a driver for enhancing governance, the IIA recommends that enterprises reshape their performance measurement systems based on the SMART principles — specific, measurable, achievable, relevant, and timely — while avoiding excessive reliance on a few isolated quantitative indicators.

The measurement system should be designed to balance key dimensions, including risk coverage, stakeholder expectations, financial and operational effectiveness, human resource requirements, and learning and development activities. Instead of requiring auditors to focus on a “recommendation implementation rate” indicator, CAEs should focus on measuring the effectiveness of recommendations in genuinely reducing long-term risks for the organization, the proportion of audits focused on high-risk units, and the level of technology adoption in audit activities.

According to the IIA, the internal audit function should adopt a balanced and comprehensive approach in which performance indicators complement one another, with a focus on delivering recommendations that genuinely create added value rather than relying on simple quantitative measures.

In the digital era, cybersecurity and third-party risks are two major areas of concern for every enterprise. Therefore, internal audit must independently assess whether the organization has established a formal cybersecurity strategy and updates it periodically, whether control policies are communicated effectively, and whether incident response and recovery systems have been established and regularly tested. In particular, auditors must review controls ranging from internal controls to those implemented by technology solution providers in order to comprehensively protect the confidentiality, integrity, and availability of information systems.

The quality of an internal audit function is directly reflected in the reports submitted to the Board of Directors and the Board of Supervisors. An audit report that meets international standards must not merely provide a cursory list of violations but must fully incorporate the elements of the professional 5C model: Criteria — the standards and regulations used as benchmarks; Condition — the actual situation and deviations identified; Cause — the reasons for such deviations; Consequence — the risks or financial and non-financial losses to the organization resulting from the deviations; and Corrective Action — specific and feasible actions to comprehensively address the root causes.

Applying this reporting model helps eliminate the perception that internal audit merely “goes looking for faults” from an administrative perspective. Instead, this approach reinforces the strategic advisory role of internal audit, enabling executive management to clearly identify systemic bottlenecks, improve processes, and optimize operations.

02/10/2026 6
Based on the issues initially identified in the proposed revision of the State Audit Law (SAL), Nguyen Huu Nghia, Member of the Party Central Committee and State Auditor General, has called for further review and refinement to ensure that the amendments serve two objectives: addressing shortcomings and limitations in actual auditing practice, while establishing a legal foundation that enables innovation and the future development of the State Audit Office of Vietnam (SAV).
View details
02/10/2026 8
Approximately 180 information technology (IT) proposals are currently being reviewed and categorized by the State Audit Office of Vietnam (SAV) to identify “major challenges” that address urgent needs, have a broad impact and are practically implementable. In an interview with Audit Newspaper, Pham Huy Thong, Director General of the Department of Information Technology, said that the selected challenges would not only address individual operational needs but also tackle cross-sector issues, connect data and shared platforms, and lay the groundwork for digital auditing and modernized governance.
View details
01/10/2026 11
On the afternoon of September 30, State Auditor General Nguyen Huu Nghia chaired a meeting of the Steering Committee for reviewing the implementation of the Development Strategy of the State Audit Office of Vietnam (SAV) through 2030 and formulating orientations for the development of the SAV through 2035, with a vision to 2045. The meeting focused on providing comments on the first draft of the Scheme for the Development of the SAV through 2035, with a vision to 2045.
View details
01/10/2026 11
The update focuses on areas where enhancements to PCAOB standards could have the greatest impact on audit quality and investor protection

View details
30/09/2026 16
On the morning of September 25, at the headquarters of the State Audit Office of Vietnam (SAV), the SAV Steering Committee for the Development of Science, Technology, Innovation and Digital Transformation held its regular meeting under the chairmanship of Nguyen Huu Nghia, Member of the Party Central Committee, Secretary of the SAV Party Committee, State Auditor General and Head of the Steering Committee. The meeting focused on discussing and providing comments on the Draft Digital Architecture Framework of the SAV, conducting a comprehensive assessment of digital transformation implementation results in the third quarter, and reaching agreement on key tasks and directions for the fourth quarter of 2026.
View details
30/09/2026 14
The signing of new coordination regulations between the State Audit Office of Vietnam (SAV) and the Standing Committee of the Hanoi Party Committee/Son La Provincial Party Committee, the Standing People's Councils, and the People's Committees of Hanoi and Son La Province provides an important foundation for further strengthening and improving the quality of coordination in a more proactive, regular, substantive, and effective manner, meeting the operational requirements of the SAV as well as the management and administration requirements of each locality.
View details
29/09/2026 18
Member of the Party Central Committee, Secretary of the Party Committee, and Auditor General of the State Audit Office of Vietnam (SAV) Nguyen Huu Nghia asked SAV Area I to proactively propose audit tasks appropriate to its available resources, based on the actual situation in the localities under its jurisdiction. This would enable the unit to support, accompany, and facilitate local socio-economic development while effectively serving as a bridge between the SAV and local Party committees and authorities.
View details
29/09/2026 24
On the morning of September 25, at the headquarters of the State Audit Office of Vietnam (SAV), the Steering Committee for Science, Technology Development, Innovation and Digital Transformation of the SAV held a regular meeting.

View details
28/09/2026 27
The State Audit Office of Vietnam (SAV) is making a strong shift from compliance auditing toward assessing the economy, effectiveness, and efficiency of the management and use of public resources. For construction investment projects, the challenge is not only to identify irregularities in documentation, but also to detect unreasonable aspects that may exist even when design, acceptance, and final settlement procedures are all complete and compliant with regulations.
View details
28/09/2026 22
On September 25, a preliminary conference and signing of the Coordination Regulation between the State Audit Office and the Standing Committee of the City Party Committee/Provincial Party Committee, the Standing Committee of the People's Council, the People's Committee of Hanoi City and Son La City took place.

View details
26/09/2026 30
The State Audit Office of Vietnam (SAV) Party Committee requires that the designation “national-level scientific conference” be used only when approved by the competent authority. The designation must not be used for conferences that address issues solely within the scope of the SAV, or that are organized primarily as events, commemorations, promotional activities, or do not fully meet the prescribed criteria.
View details
26/09/2026 27
On the afternoon of September 24, at the headquarters of the State Audit Office of Vietnam (SAV), Member of the Party Central Committee, Secretary of the Party Committee and Auditor General of the State Audit Office of Vietnam Nguyen Huu Nghia chaired a conference of the SAV Party Committee Standing Committee to consider a number of important matters, with a focus on discussing directions for amending and supplementing the State Audit Law.
View details
Head Office
Representative Office
Northern Branch
Ho Chi Minh City Branch
Key thời gian làm việc
Copyright © 2026 CPA VIETNAM AUDIT. All rights reserved. Website designed by Tat Thanh
Access statistics
Total visits: 487958 Currently visiting: 325
Website Policy