Skip to main content

      New standards, ESG requirements and technological developments demand a strategically orientated, efficient and transparent audit function. We support you in setting up your audit function to be future-proof, effective and flexible.

      Challenges for internal audit

      The demands on the internal audit function have never been as dynamic as in recent years. Regulatory requirements, technology and global risks are the main drivers here. In terms of regulation, the requirements are increasing due to ESG regulation: auditors have to audit requirements such as the Corporate Sustainability Reporting Directive (CSRD), EU taxonomy or the Supply Chain Due Diligence Act (LkSGs) or the Corporate Sustainability Due Diligence Directive (CSDDD) - and build up special expertise for this. Technological change requires the use of AI, process mining and data analytics. The selection of suitable tools and staff training are crucial. The risk landscape is also becoming more complex: cyber risks, forms of fraud and geopolitical uncertainties require a dynamic, risk-oriented audit strategy. In addition, the new Global Internal Audit Standards (GIAS) have been in force since January 2025 and bring with them 15 principles and 52 requirements. They demand greater transparency, efficiency and strategic alignment.

      Opportunities for your organisation

      However, current developments also open up new opportunities for internal auditing to position itself strategically and to optimise and therefore increase the efficiency of its audit work. It can establish itself as a value-adding partner that actively contributes to corporate strategy and the achievement of objectives - for example through ESG support. Modern technologies enable deeper analyses, faster audits and more precise risk assessments. The expansion of the audit universe to include topics such as sustainability, the use of AI and digital business models increases the relevance of auditing. The new standards also strengthen its role as an independent control body - for example through a clearly defined function within the scope of the effectiveness statement in accordance with recommendation A.5 of the German Corporate Governance Code (GCGC). This significantly increases the visibility and impact of internal auditing and strengthens its governance function in the long term.

      auto_stories

      The focus of this issue: How optimised internal control systems (ICS) strengthen strategic corporate governance.

      How can we support you and your internal audit department?

      • Further development of your internal audit

        In order to meet the new requirements, we support you in the strategic and operational development of your internal audit. Our modular approach integrates the audit as part of the overall control system and is based on a well-founded and sustainable risk analysis. We help you to align your organisation, processes and audit methods so that they comply with GIAS standards while integrating ESG and technology requirements.

      • Quality assessment of your audit function

        A quality assessment (QA) provides you with an objective evaluation of the effectiveness and efficiency of your audit - key evidence for supervisory bodies. We examine your function on the basis of the DIIR guidelines, IDW PS 983 and international benchmarks. This allows you to recognise whether your audit is compliant with regulations, strategically aligned and resource-efficient - and where there is potential for further development, for example in dealing with ESG or new technologies.

      • Selective audit support and coaching

        If your audit is faced with new topics or capacity limits, we can take on individual audit areas - e.g. ESG, cyber, tax or forensics. As part of joint audits, we can not only take topics off your hands, but also have our experts coach your own audit colleagues. You can concentrate on your core topics and at the same time ensure that complex or specialised topics are tackled professionally and in a risk-oriented manner. Our expertise helps you to manage new regulatory requirements efficiently.

      • Complete audit takeover

        For organisations that want to fully outsource their audit function, we offer a holistic solution: we take responsibility for personnel, IT and processes and ensure that your audit meets the highest standards. With global industry expertise and state-of-the-art tools, we organise your audit planning efficiently and strategically - and turn your audit into a real value driver. We are completely flexible for you and aligned with your current requirements and risk exposure.

      KPMG Insights on Internal Audit

      Your contacts

      Luisa v. Esterházy

      Partner, Audit, Regulatory Advisory, Sustainability Reporting & Governance, Risk Compliance

      KPMG AG Wirtschaftsprüfungsgesellschaft

      Marc Stauder

      Partner, Audit, Regulatory Advisory, Sustainability Reporting & Governance

      KPMG AG Wirtschaftsprüfungsgesellschaft

      An effective Internal Audit function provides an independent perspective on risks, controls and key business processes. As the only process-independent function within the organisation, it examines procedures impartially and neutrally, thereby serving as a cornerstone of sound corporate governance. For management, this provides a reliable early-warning and control tool: Audit findings are distilled into prioritised areas for action and can be directly translated into decisions, measures and the allocation of resources. In doing so, the internal audit function is increasingly taking into account not only financial and operational risks but also organisational behaviour and behavioural risks.

      Effectively embedding internal audit within the organisation

      The impact of internal audit does not depend solely on individual audits. Clear mandates, adequate resources, transparent reporting lines and a binding audit standard form the foundation. Equally important is coordinated collaboration with risk management, compliance and the internal control system, without compromising its independence.

      A well-established internal audit function also analyses how management structures, incentive schemes and the values put into practice shape organisational behaviour. This enables behavioural risks to be identified at an early stage and taken into account appropriately in risk-based audit planning. At the same time, overlaps can be reduced, control gaps identified and audit findings translated more quickly into concrete measures.

      Advice on a needs-based internal audit function

      KPMG supports companies in further developing the vision, governance and performance of their internal audit function. The starting point is a structured analysis of the audit universe, organisation, methodology, data base and competence profiles. In doing so, KPMG also assesses the extent to which the Internal Audit function’s working methods comply with the relevant auditing standards.

      Internal audit consultancy can encompass the further development of reporting systems, effective follow-up, data-driven audit procedures, and the integration of organisational behaviour and behavioural risks. KPMG combines technical expertise with a clear focus on feasibility and long-term impact.

      AI and Continuous Controls Monitoring in Internal Audit

      There is a growing focus on the use of artificial intelligence and data analytics in internal audit: AI-supported methods can be deployed in a traceable and quality-assured manner throughout the entire audit process – from risk assessment and audit planning, through the selection of risk-based samples, to the analysis of large volumes of documents and data, and the preparation of draft reports.

      KPMG provides step-by-step support on the path towards Continuous Controls Monitoring and Continuous Auditing. This ranges from the selection of suitable audit areas and the integration of relevant data sources, through the definition of automated control and audit rules, to the ongoing analysis of anomalies. In this way, the audit evolves from selective spot checks to broad, data-driven coverage. This enables control weaknesses to be identified earlier and audit cycles to be shortened; at the same time, it reduces the workload associated with recurring audit procedures. This requires clear guidelines for the responsible use of AI: robust data quality, transparent methodology, clear documentation of the models used, and ultimate professional responsibility resting with theauditors.

      Frequently asked questions

      Internal Audit examines business processes, controls and governance structures in an independent and risk-based manner. It identifies weaknesses, assesses opportunities for improvement and provides management with a robust basis for decision-making.

      An audit standard sets out binding requirements for organisation, audit planning, execution, documentation and reporting. It supports the Internal Audit function in conducting audits in a transparent, consistent and quality-oriented manner.

      Organisational behaviour influences how rules, controls and management principles are implemented in day-to-day working life. Internal Audit can investigate whether incentive schemes, communication channels or the prevailing corporate culture create conditions that facilitate risks.

      Behavioural risks arise when decisions or actions by employees and managers conflict with the organisation’s objectives, internal guidelines or regulatory requirements. These may include misaligned incentives, an inadequate culture of accountability or the deliberate circumvention of controls.

      Consultancy is particularly advisable when establishing or reorganising the internal audit function, as well as in the event of changes to business models and risk profiles. New audit standards, methodological weaknesses or a greater focus on organisational behaviour and behavioural risks may also necessitate external support.

      Artificial Intelligence can support internal audit throughout the entire audit process: in risk assessment and audit planning, the selection of risk-based samples, the analysis of large volumes of documents and data, and the preparation of draft reports. This requires reliable data quality, a transparent methodology and documentation of the models used. The professional judgement and responsibility for the audit opinion remain with the auditors.

      Continuous Controls Monitoring refers to the ongoing, largely automated monitoring of controls based on defined rules and connected data sources. Instead of ad hoc spot checks, this provides broad, data-driven coverage in which anomalies are continuously analysed. For Internal Audit, this enables control weaknesses to be identified earlier and audit cycles to be shortened. In conjunction with continuous auditing, audit procedures can be focused more closely on high-risk areas.