One Auditor, Two Tribes: Reimagining Internal Audit Governance in the Age of AI
This article critically examines the long-standing division between the IIA and ISACA, arguing that the traditional two-body model for internal audit governance is increasingly obsolete in an era where audit work has converged, particularly with the rise of AI. It challenges audit professionals to consider whether the current dual-membership, dual-certification system still serves the profession's best interests or if it merely perpetuates inefficiency and a fragmented authority at a time when a unified approach is more critical than ever.
The Problem of Dual Governance in a Converged World
The author, an experienced internal audit manager, highlights a pervasive inefficiency: the annual division of professional development budgets between the IIA and ISACA. This split funds two memberships, two certification ladders (CIA and CISA), two sets of standards, and two conference ecosystems, despite the fact that modern internal auditors perform a single, integrated job. Auditors routinely blend financial, operational, and IT audit tasks, making the institutional separation between 'business' and 'technology' audit increasingly artificial. This duplication of effort and cost, multiplied across the profession, suggests a structural issue rather than a niche irritation, prompting the fundamental question: why are practitioners paying two organizations to govern one job?
The Evolution and Erosion of the Two-Body Model
Historically, the division between the IIA (focused on accounting and operations) and ISACA (emerging from the need to audit through, not around, computers) was rational. The scarcity of IT audit expertise in the 1960s necessitated a separate professional body, leading to distinct knowledge bases, credentials, and career paths. However, this article argues that the conditions justifying this split—scarcity of expertise, tooling, and shared technical language—are rapidly disappearing. The widespread availability of technical knowledge and, more decisively, the advent of AI, are dissolving the traditional boundaries. AI tools now enable auditors to quickly grasp complex technical architectures and identify control risks, making specialist knowledge more portable and decoupling it from the need for separate institutional housing. Both the IIA and ISACA's recent actions, such as the IIA's mandatory cybersecurity Topical Requirement and ISACA's AI audit credential accepting the CIA, demonstrate an institutional acknowledgment of this convergence, yet they often result in duplication rather than true integration.
The Cost of Fragmentation and the Path Forward
The article contends that the ongoing jurisdictional contest between the IIA and ISACA, where each body annexes the other's territory, leads to fragmented authority and a governance gap. While competition can foster innovation, in rapidly evolving areas like AI and cybersecurity, conflicting standards create confusion and reconciliation costs for practitioners and, ultimately, erode trust in the assurance provided. The author explores four potential futures: maintaining the status quo, federation (alliance without full merger), a unified body, or an open ecosystem. The unified body, offering a single standard and credential framework with specialized tracks, is presented as the most efficient and logical outcome, mirroring other mature professions like medicine and law. However, it is also the most challenging to achieve due to institutional inertia and the collective action problem faced by individual auditors. The article concludes that the power to drive change lies with the demand side—practitioners and, more importantly, employers—who, by consciously choosing to support rationalized credentials and challenge the dual-payment model, can exert the necessary pressure to reshape the profession's governance.
Read more