Who Do Internal Auditors Report To: Functional vs. Administrative

Internal auditors report to two bosses at once, and that split is deliberate. The head of the function — the Chief Audit Executive, or CAE — reports functionally to the board of directors, usually through its audit committee, and administratively to a senior executive such as the CEO. The functional line protects independence: it decides what gets audited, what gets reported, and whether the CAE keeps the job. The administrative line handles the practical side: budget mechanics, HR paperwork, office logistics. The people internal auditors evaluate are often the same executives who control resources and access, so a direct line to the board is what stops the function from being quietly defunded, deprioritized, or pressured into softening findings.

The Two Reporting Lines and What Each Controls

The functional line connects the CAE to the board and governs everything tied to audit independence. The administrative line connects the CAE to a senior executive and handles operations.1The Institute of Internal Auditors. Global Internal Audit Standards 2024

The reason for the split is straightforward. If a single executive controlled both the audit team’s resources and its conclusions, nothing would stop that person from burying bad news. Separating the two roles means the executive who helps the audit team function day-to-day is not the same person who decides what the team investigates or how it reports results.

What the Board Decides Through the Functional Line

Under the Global Internal Audit Standards, the internal audit function must be independently positioned with direct accountability to the board.1The Institute of Internal Auditors. Global Internal Audit Standards 2024 In practice, the CAE answers to the audit committee, a subgroup of the board composed entirely of independent directors who hold no management roles at the company.

The audit committee’s authority over internal audit includes specific powers:

  • Approving the internal audit charter, which defines the function’s purpose, scope, and authority
  • Approving the risk-based audit plan each year, deciding which areas get scrutinized and how deeply
  • Approving the audit budget and staffing resources
  • Controlling the CAE’s appointment, removal, compensation, and performance evaluation2The Institute of Internal Auditors. 2017 Attribute Standards

That last point is where most reporting structures fail. When the CEO effectively controls whether the CAE gets a raise or keeps the position, the CAE has every incentive to avoid politically uncomfortable audits. Placing those decisions with the audit committee removes that pressure structurally. Auditor pay should also not be tied to corporate financial performance.

Through this line, the CAE communicates audit results on significant control weaknesses, high-risk operational areas, and any instance where management has limited the scope of an engagement or withheld cooperation. The committee also receives updates on whether the plan is being completed on schedule and whether the function has adequate resources. The board can then make “appropriate inquiries of management and the chief audit executive to determine whether there are inappropriate scope or resource limitations.”2The Institute of Internal Auditors. 2017 Attribute Standards

Executive Sessions

The CAE must have direct and unrestricted access to the board, including the ability to meet without management present.1The Institute of Internal Auditors. Global Internal Audit Standards 2024 These private meetings, called executive sessions, are where the most sensitive conversations happen: concerns about tone at the top, ethical lapses by senior leaders, whistleblower reports involving executives, or situations where management is interfering with audit scope.

Best practice is to make executive sessions a standing agenda item at every audit committee meeting, even when nothing urgent needs to be discussed. Normalizing the practice prevents the appearance that a private session signals a crisis, which can otherwise cause management to resist scheduling one precisely when it’s needed most.

What Senior Management Handles Through the Administrative Line

The administrative line runs to a senior executive and covers the operational side of running an audit department. The Global Internal Audit Standards say this line typically goes to the highest-ranking person in senior management, such as the CEO.1The Institute of Internal Auditors. Global Internal Audit Standards 2024 The charter should describe what falls under this line: approving the department’s operating budget, handling HR matters for non-CAE staff, approving the CAE’s expense reports, and facilitating access to records, personnel, and facilities needed for fieldwork.

The boundary is non-negotiable. The administrative executive cannot influence which areas get audited, alter the scope of an engagement, or change audit conclusions. If the CFO approves the audit department’s travel budget, that doesn’t give the CFO any say over what the auditors find when they arrive. The administrative relationship exists purely to keep the department running smoothly within the organization’s operational framework.

Why the CFO Is the Wrong Choice

Some organizations route the CAE’s administrative reporting to the CFO, and this creates a conflict experienced auditors recognize immediately. The CFO is directly responsible for financial reporting, internal controls over financial reporting, and the accounting function, all of which are core areas the internal audit team regularly evaluates. Having the person responsible for the books also serve as the audit team’s administrative boss undermines the independence the structure is designed to protect.

Moody’s Investors Service has flagged this arrangement, noting that while CFO reporting gives auditors exposure to financial processes, it can compromise the function’s independence. The preferred approach is for the administrative line to go to the CEO, which signals to the rest of the organization that senior management considers the audit function a high priority. Whoever holds the administrative line, the audit committee should still be directly involved in the CAE’s performance evaluations and compensation.

The Charter That Locks It In

The charter is the formal document that fixes the reporting structure in place. It defines the internal audit function’s purpose, authority, organizational position, and both reporting relationships.3The Institute of Internal Auditors. The Internal Audit Charter – A Blueprint to Assurance Success The charter must be approved by the board and agreed to by senior management.1The Institute of Internal Auditors. Global Internal Audit Standards 2024

The charter functions as the audit function’s constitution. It establishes that the CAE has unrestricted access to the board, authorizes access to any records or personnel needed for an engagement, and draws the line between what the administrative executive controls and what the audit committee controls. Without a well-drafted charter, the reporting structure exists only as an informal arrangement that can be quietly renegotiated when it becomes inconvenient for someone in power. The CAE must review the charter periodically and present it to both senior management and the board for re-approval.2The Institute of Internal Auditors. 2017 Attribute Standards

Rules for Public Companies

At publicly traded companies, the reporting structure carries regulatory weight. Federal securities law requires every member of a listed company’s audit committee to be an independent member of the board.4Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements Independent means the committee member cannot accept consulting or advisory fees from the company and cannot be an affiliated person of the company or its subsidiaries.

Sarbanes-Oxley Section 301 was written primarily around oversight of external auditors, the outside accounting firms that issue audit opinions on financial statements. The SEC explicitly considered and declined to mandate audit committee oversight of the internal audit function as a federal requirement.5Securities and Exchange Commission. Standards Relating to Listed Company Audit Committees Stock exchange listing rules fill that gap. The NYSE requires listed companies to maintain an internal audit function that provides ongoing assessments of risk management and internal controls, and the audit committee charter must address the committee’s role in overseeing that function.6Federal Register. Order Approving Proposed Rule Change Amending 303A.00

At public companies, the functional line to the audit committee is reinforced by both professional standards and exchange listing rules. It is not optional.

Private Companies, Nonprofits, and Government

Not every organization has a formal board of directors or audit committee. Private companies, government agencies, and nonprofits often operate with different governance structures, and the reporting model adapts.

In the public sector, the CAE may report to a legislative body that functions as a board, to the head of a government organization, or to a non-executive supervisory board.1The Institute of Internal Auditors. Global Internal Audit Standards 2024 Some of these arrangements fall short of full independence requirements. In those situations, the standards recommend establishing an audit committee composed of public members who are independent of management.

Private companies apply the same principles through different mechanisms. A private company might create an advisory board or independent audit committee to serve the functional reporting role, even without the regulatory mandate public companies face. The core question is the same for every entity type: does someone outside of management have the authority to protect the audit function’s independence, control the CAE’s tenure, and receive unfiltered audit results?

When the Structure Breaks Down

A compromised reporting structure does more than violate professional standards. It creates real legal and financial exposure.

The SEC has pursued enforcement actions against firms that violated independence requirements. In one case, the SEC censured RSM US LLP, imposed a $950,000 penalty, and ordered the firm to engage an independent consultant to evaluate its quality controls after finding the firm had violated auditor independence provisions of federal securities law.7Securities and Exchange Commission. RSM US LLP Charged With Violating Auditor Independence Rules

The stakes escalate when internal control failures lead to inaccurate financial reporting. Under federal law, a CEO or CFO who willfully certifies a financial report knowing it does not comply with requirements faces fines up to $5 million and up to 20 years in prison.8Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports A non-willful violation carries penalties of up to $1 million and 10 years. An internal audit function without independence is far less likely to catch the control weaknesses that lead to these certification failures in the first place.