Market signals | Audit leadership

Chief Audit Executive (CAE)

Giving the board assurance grounded in evidence, clear scope and independent judgement.

Overview

The CAE’s remit: independent assurance and useful insight

The Chief Audit Executive leads an internal audit function that provides independent assurance and advisory insight on governance, risk management and control. The role serves the board or audit committee and management through an informed assessment of how the organization is governed and operated. Independence distinguishes its contribution from management's responsibility to run the business.

Today, the CAE must translate an understanding of the organization into a credible audit plan. That involves selecting coverage, allocating specialist capability and keeping the plan responsive to material developments. The remit includes the quality of engagements, communication of conclusions and follow-up on agreed actions, with appropriate access and reporting relationships.

The work requires constructive relationships without taking over the decisions being assessed. Internal audit can advise on a developing process or programme, but management remains responsible for design, operation and corrective action. The CAE must preserve that distinction while ensuring that findings are sufficiently clear and useful for leaders to act.

For a practitioner, the strategic overview asks what assurance the function can credibly provide and where its coverage is limited. Do the board and management understand those boundaries? A strong CAE connects the audit plan to organizational priorities, maintains professional discipline and provides conclusions supported by evidence rather than implying certainty beyond the work performed.

Role signals

What is shaping the role now

Remit, independence and board relationships

An agreed internal audit remit

~86% oversee at least one area beyond internal audit.

What this asks of the role

Agree internal audit's purpose, authority and scope with the board so the function has a clear basis for its work.

2026 | North American audit leaders.

Audit priorities and assurance coverage

Choosing audit priorities

47% also have responsibility for fraud investigations.

60% share risk information across risk, compliance and internal audit.

What this asks of the role

Direct audit work toward activities and exposures most relevant to the organization's objectives.

2026 | North American audit leaders; 2025 | Enterprise risk management survey | Separate findings; not parts of a total.

The role today

  • An agreed internal audit remit

    Agree internal audit's purpose, authority and scope with the board so the function has a clear basis for its work.

  • Independence and access

    Maintain the reporting relationships and access needed for audit to form an objective view of the organization's activities.

  • Choosing audit priorities

    Direct audit work toward activities and exposures most relevant to the organization's objectives.

  • Coordinating assurance work

    Understand what other assurance teams examine so audit can make informed coverage decisions without assuming their work is interchangeable.

  • Clear scope for each audit

    State the questions an audit will examine, the criteria it will use and the boundaries of its conclusions.

  • Following up on management actions

    Track progress on agreed actions while keeping management responsible for making and sustaining the changes.

Pressure Points

The CAE’s pressure: wider assurance needs, finite coverage

The CAE faces pressure to provide assurance across a changing business with finite time and specialist capability. Technology programmes, supplier relationships and established operations can all warrant attention. The difficult task is to set out which work will be undertaken, what it can establish and which areas will receive less coverage as priorities change.

Independence can become harder to maintain when the organization wants early advice. Participation may improve understanding and reveal practical concerns before implementation, but excessive involvement can blur responsibility for management decisions. The CAE needs clear engagement boundaries and transparent communication with the audit committee about the function's role and any limitations.

Evidence and follow-up create further demands. Inconsistent records can extend fieldwork, while recurring findings may reflect unresolved ownership or competing operating priorities. An action marked complete does not necessarily establish that the underlying control is effective. Internal audit must assess the evidence without becoming the team responsible for implementing the solution.

The strategic response is to make coverage choices and assurance limits explicit. Review the plan against material developments, agree how advisory work will preserve objectivity and focus follow-up on whether actions address the underlying concern. This gives the CAE a defensible account of the function's contribution while avoiding the impression that a broad remit guarantees comprehensive assurance.

Common pressure points

Independence and useful business relationships

  • Expectations beyond the remit

    Management may ask audit to take on responsibilities that change the function's agreed role.

    What to look atCompare requests with the approved remit and board expectations.

  • Advice becoming management ownership

    An advisory engagement can drift into designing or operating the control later subject to audit.

    What to look atReview responsibility boundaries and safeguards for objective assurance.

Coverage and changing business priorities

  • Plans overtaken by business change

    An annual audit schedule can remain fixed while significant activities or exposures change.

    What to look atCompare planned coverage with recent business developments.

  • Specialist needs exceeding availability

    An engagement can require technical knowledge beyond the available audit team's experience.

    What to look atCompare planned scope with specialist capability and review arrangements.

Evidence and understandable conclusions

  • Evidence without clear traceability

    Findings can take longer to review when the connection to underlying records is incomplete.

    What to look atTrace selected conclusions through workpapers to supporting evidence.

  • Findings unclear to responsible leaders

    A technically accurate report can still leave management unsure what requires action and why.

    What to look atCheck understanding of the consequence and agreed response with the action owner.

Follow-up and audit function capacity

  • Completion reported without evidence

    Management may report an action complete before audit has enough evidence to confirm the change.

    What to look atReview the records supporting action closure.

  • Capacity committed beyond realistic coverage

    The audit plan can assume more engagement and review time than the team can provide.

    What to look atCompare available capacity with the full delivery and review workload.

Selected external benchmarks

Research note: These figures describe the groups studied. They do not measure your organization’s performance or set goals for it.

  • Budget pressure
    19%

    of audit functions reported budget reductions in 2025.

    2026 – North American audit leaders

  • Audit team size
    18%

    of audit functions reported smaller teams in 2025.

    2026 – North American audit leaders

  • Annual-only coordination
    50%

    coordinate only during annual risk assessments.

    2025 – Enterprise risk management survey

  • Technology change exposure
    48%

    rank digital disruption among their five leading business exposures.

    2026 report – Global audit leaders

Conditions to Deliver

Independence with timely access

The Chief Audit Executive contributes best with direct access to the audit committee, an unrestricted view of relevant records and the organizational standing to raise difficult matters. Independence is strengthened when the board protects the function’s scope and resources while management engages openly with evidence and agreed actions.

The role also needs a risk-based plan that can change as the business changes. Skilled audit teams, appropriate analytical tools and constructive relationships across functions help assurance arrive while decisions can still be influenced. Clear boundaries preserve management ownership: audit can assess and advise without taking responsibility for the controls it later reviews.

Reflection questions

Is independent assurance close enough to a changing business?

  1. How quickly can the audit plan shift when strategy, technology or operating exposure changes during the year?

  2. Where does the function still depend on management-curated evidence rather than direct, timely access to relevant records?

  3. Are advisory requests framed clearly enough to preserve management ownership and audit independence?

  4. Which capabilities does the team need to assess automated decisions, data lineage and technology-enabled controls with confidence?

  5. What does the audit committee need to understand now that is not visible through findings, ratings and action counts alone?

Future Evolution

The CAE’s evolution: timely assurance with clear boundaries

The CAE's role may develop toward more timely, integrated use of evidence while retaining internal audit's independent perspective. Analytical tools can help identify patterns and direct attention, but they do not replace engagement design, professional scepticism or the judgement needed to support a conclusion. Assurance remains bounded by the work performed and the evidence available.

Closer coordination with other assurance providers can help the audit committee understand coverage across the organization. This requires clarity about what each function does, how its work can be used and where further examination is needed. Coordination should improve the overall picture without making internal audit responsible for management's controls or monitoring.

Technology and AI also create new subjects for assurance. The CAE needs access to appropriate expertise to examine governance, accountability and the operation of relevant controls. At the same time, the audit function's own use of analytical or generated outputs needs review, traceable evidence and a clear account of limitations.

Preparation begins with an engagement where better information could change timing or focus. Test the analytical approach, validate what it identifies and retain the reasoning behind the conclusion. Alongside technical capability, develop auditors who can articulate significance and practical consequences. The aim is more useful assurance for the board, not an automated substitute for independent judgement.

Role evolution

Independence within an evolving business

  • Remit reflecting business change

    New business models and AI uses may require more frequent board dialogue about internal audit's expected coverage.

    What to watchRemits reflecting material business and technology changes.

  • Independence in new advisory work

    Earlier advice on emerging technology may require clearer boundaries between audit's contribution and management's decisions.

    What to watchAdvisory work preserving management ownership.

Coverage responsive to changing exposure

  • Plans adapting between cycles

    Changing conditions may require deliberate mid-year audit-plan adjustments with a clear rationale for resulting coverage choices.

    What to watchPlan changes identifying work reshaped or deferred.

  • Earlier specialist preparation

    Fast-changing technology may require specialist audit learning or support before relevant engagements begin.

    What to watchSpecialist capability arranged ahead of planned work.

Evidence in a more digital audit practice

  • Traceable digital evidence

    More analytical tools may require clearer links between source records, transformations, professional review and audit conclusions.

    What to watchConclusions traceable through the supporting evidence.

  • AI within professional review

    AI may support audit preparation while people remain accountable for evidence quality, confidentiality and conclusions.

    What to watchAI-assisted work receiving documented professional review.

Audit capability and enduring assurance

  • Follow-up in practice

    Better operating access may extend audit follow-up from recorded completion to evidence that intended changes are working.

    What to watchRevised practices demonstrated in actual operation.

  • Business and technology fluency

    Digital business activity may require deeper audit understanding of service operations, data and AI alongside established professional capability.

    What to watchLearning linked to the activities being audited.

Selected external benchmarks

Research note: These figures describe the groups studied. They do not measure your organization’s performance or set goals for it.

  • Audit plan funding
    59%

    of audit functions closely aligned with business strategy report sufficient funding.

    2026 – North American audit leaders

  • Cybersecurity and IT audits
    ~20%

    of audit effort goes to cybersecurity and IT across most sectors.

    2026 – North American audit leaders

  • AI in audit work
    40%

    use generative AI in audit activities, up from 15% a year earlier.

    2025 report – North American audit leaders

  • Auditing technology change
    32%

    rank digital disruption among their five leading audit priorities.

    2026 report – Global audit leaders