Measuring and Monitoring Internal Audit’s Performance — And the Red Flags
1. The measure that matters: risk coverage, not effort
Every assurance function reports on itself. The trouble is that most of what it reports tells you how busy it was, not whether anyone is safer as a result. Audit hours delivered, plan completion percentages, cost as a percentage of revenue, utilization rates — these are measures of activity.
- They answer the question "did the function do what it said it would do?" and then stop.
- None of them answers the question the Board is actually asking: is risk being reduced, and can we prove it?
This blog sets out a different measurement philosophy, one that prices assurance against risk rather than headcount. It is built on four dimensions:
- coverage (are the material risks actually covered, by someone accountable, without duplication?),
- timeliness (how quickly does a control failure become a finding?),
- outcomes (are findings closed, sustained, and not recurring?), and
- behavior (what is assurance actually costing the first line, and is the Audit Committee spending its scarce time on risk or on theatre?).
The shift echoes the direction of travel in the IIA's Three Lines Model, which emphasizes coordinated, risk-based assurance rather than each provider defending its own turf.
The section closes with the red flags that Management and External Auditors should watch for — the patterns that reliably signal when a measurement framework has become a scoreboard for effort rather than an instrument of governance.
If you are a C-suite leader, this is about the cost of assurance you are already paying for — often twice, in duplicated coverage and in first-line hours absorbed by overlapping requests. The metrics here make that cost visible for the first time.
If you sit on a Board or Audit Committee, this is about the quality of the information reaching you. A function that can demonstrate risk coverage, falling repeat findings, and zero externally escalated surprises is a function you can rely on. One that reports only plan completion is asking for your confidence without earning it.
If you are an External Audit Partner, this is about the tells. The red flags in this section — severity downgrades concentrated at close-out, control issues you raise that were never known internally, remediation declared complete without independent re-testing — are the same patterns you look for in the field, described from the inside.
Measurement is where assurance programs quietly succeed or fail. Here's how to tell the difference.
A meaningful measurement framework combines coverage, timeliness, outcome, and behavioral indicators.
|
Dimension |
Metric |
Target direction |
Why it matters |
|
Coverage |
Percentage of material risks with at least one accountable assurance provider and a test in the last 12 months |
Increase |
Directly exposes duplication and gaps |
|
Coverage |
Assurance coverage per provider, mapped on one grid |
Balanced, non-overlapping |
Removes duplicated effort and audit fatigue |
|
Timeliness |
Average days from control failure to finding raised |
Decrease |
Latency is where value leaks |
|
Outcome |
Percentage of findings closed within the agreed due date |
Increase |
Measures ownership, not administration |
|
Outcome |
Percentage of findings recurring from a prior cycle (repeat findings) |
Decrease |
The single best indicator of whether root cause was addressed |
|
Outcome |
Findings escalated externally (by external audit, regulator, or customer) that internal assurance missed |
Decrease to zero |
The clearest test of internal assurance quality |
|
Outcome |
Verified remediation sample rate (re-testing closed items) |
Maintain high |
Prevents 'closed in the system, unchanged in reality' |
|
Behavior |
First-line hours absorbed by assurance requests |
Decrease |
The cost of duplication, made visible |
|
Behavior |
Audit Committee discussion time on risk versus on activity reporting |
Shift to risk |
Evidence that reporting is decision-grade |
|
Efficiency |
Cost per material risk covered (not cost per audit) |
Decrease |
Price assurance against risk, not headcount |
2. The red flags Management and External Auditors must watch
|
Red flag |
What it usually signals |
|
Plan completion high, risk coverage low |
Activity is being managed; risk is not |
|
The same root cause appears in three consecutive cycles |
Findings are being closed individually instead of systemically |
|
Severity downgrades concentrated at close-out |
Findings are negotiated, so the register no longer reflects reality |
|
Overdue items aging with 'in progress' and no root-cause analysis |
Ownership is nominal; nothing will change |
|
Maturity scores improving while loss, near-miss, or incident data worsen |
Controls are documented but not operating |
|
Internal audit reports to the CFO, a risk owner, or the second line |
Independence is compromised — a governance failure, not an audit failure |
|
External auditor raises control issues not previously known internally |
Coverage gaps, under-resourcing, or scope limited by management |
|
AI in production with no inventory and no post-deployment monitoring |
Unmanaged risk with an unquantified downside |
|
Critical vendors with no right-to-audit and no tested exit |
Concentration risk with no mitigation and no leverage |
|
Remediation declared complete without a period of independent operation testing |
A prior material weakness likely to recur |
|
The Board needs multiple reports to reach a conclusion |
Reporting architecture is broken, whatever the content quality |
|
Frequent CAE turnover, or a CAE with no direct Audit Committee access |
The function lacks standing to deliver uncomfortable conclusions |
From Scoreboard to Instrument: The uncomfortable truth about assurance metrics is that almost any of them can be gamed, and most of them will be, eventually, by someone under pressure to demonstrate value.
- Plan completion is gamed by re-scoping the plan.
- Findings closed on time are gamed by negotiating severity at close-out.
- Maturity scores are gamed by documenting controls that do not operate.
- The defense is not a perfect metric — none exists, but a portfolio of metrics that game each other: you cannot simultaneously inflate coverage, hide repeat findings, suppress escalations, and keep first-line absorption low, because each one exposes the others.
That is the real test of the framework in this section. A function confident in its measurement welcomes re-testing of closed items, publishes its coverage map, and invites the combined assurance view that exposes its own gaps. A function that resists those things has told you something no metric could.
Whether you are commissioning assurance, overseeing it, or providing it independently of it, the following three questions will tell you more in ten minutes than a full reporting cycle:
- Show me your coverage map — which material risks have no accountable provider, and which have two or more? If the answer is a plan completion percentage, you are buying activity, not risk reduction. Every material risk should have a named owner and a test within the last twelve months; duplication on the same grid is as much a defect as a gap, because it breeds audit fatigue and cost with no added confidence.
- What percentage of your closed findings recurred in the last cycle, and when did you last independently re-test a 'closed' item? Repeat findings are the single most honest metric in assurance: they reveal whether root causes were addressed or whether items were closed individually in the system while unchanged in reality. A function that cannot answer, or that declares remediation complete without a period of independent operating testing, is likely carrying a prior material weakness back into the next cycle.
- What did external parties — the external auditor, a regulator, or a customer — raise that your internal assurance missed, and what did you change as a result? Externally escalated findings that internal providers missed are the clearest available test of internal assurance quality. The target is close to zero, and, just as importantly, the follow-up matters: a function that treats every external escalation as a coverage review rather than a one-off embarrassment is worth what you are paying for.
Ask these three questions of your own function, your co-sourced providers, or the assurance you receive. The answers, or the discomfort in giving them, are the measurement.
To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com
