Internal audit performance results

Publication type
Audit
Date

Departments with internal audit functions are required to publish key attributes of compliance as per section A.2.2.3.1 of the Treasury Board Directive on Internal Audit.

The Directive supports the objectives of the Policy on Internal Audit by setting out the responsibilities for Chief Audit Executives related to internal audit and providing the mandatory procedures for internal auditing in the Government of Canada that supplement the Institute of Internal Auditors Professional Practices Framework.

These key attributes demonstrate that, at a minimum, the fundamental elements necessary for oversight are in place, are operating as intended, and are achieving results.

Please visit the TBS website for further information on the posting requirements of internal audit compliance attributes.

Internal audit key compliance attributes as of August 2025

  • % of staff with an internal audit or accounting designation (Certified Internal Auditor (CIA), Chartered Professional Accountant (CPA))
    • 89% of staff hold an internal audit or accounting designation
  • % of staff with an internal audit or accounting designation (CIA, CPA) in progress
    • 0% of staff have an internal audit or accounting designation in progress
  • % of staff holding other designations (CGAP, CISA, etc.)
    • 67% of staff hold other designations
  • Date of last comprehensive briefing to the Departmental Audit Committee on the internal processes, tools, and information considered necessary to evaluate conformance with the IIA Code of Ethics and the Standards and the results of the quality assurance and improvement program (QAIP)
    • June 25, 2025
  • Date of last external assessment
    • August 29, 2022
  • Average overall usefulness rating of areas audited.
    • 89% of respondents rated the overall usefulness of the audits as “Strongly Agree” to the following statement: “Overall, the engagement added value to our area”.

Internal audit status

Audit title Audit status Report approved date Report published date Original planned Management Action Plan (MAP) completion date Management Action Plan (MAP) implementation status (%)
Audit of Regulatory Approvals Published - MAP fully implemented 2024-06-24 2024-10-25 2025-06-31 100%
Audit of Cybersecurity – Governance and Risk Management Approved – Not published 2025-05-01 N/A N/A N/A
Audit of Supervisory Processes - Insurance Published - MAP not fully implemented 2025-06-25 2025-08-18 2027-09-30 0%
Audit of Budgeting and Financial Management Published - MAP not fully implemented 2025-07-17 2025-08-18 N/A 0%
Audit of Cloud Cybersecurity Effectiveness In Progress N/A N/A N/A N/A
Audit of Supervisory Processes: Use of Non-Financial Risk Specialists In Progress N/A N/A N/A N/A
Audit of Workforce Planning Planned N/A N/A N/A N/A
Audit of Supervisory Processes: Small and Medium-Sized Banks Planned N/A N/A N/A N/A