Both routes satisfy the letter of the Standard. For many years, however, the profession has tended to treat the fully external model as the gold standard — the option to which functions should aspire if they have the resources to afford it. I have previously made that argument myself.
But is that assumption still justified?
The fully external model undoubtedly has important strengths. It provides an independent perspective, removes the assessed function from the centre of the assessment process, and gives the board confidence that an outside party has formed its own view. Yet the quality assessment landscape is changing. SAIV has matured, internal quality processes have become more sophisticated, and artificial intelligence now offers the potential to transform how evidence is gathered, analysed, tested, and documented.
The question, therefore, is not whether external assessment has value. It clearly does. The more interesting question is whether the profession should continue to assume that a fully external EQA is inherently superior to a well-designed SAIV — or whether more internal audit functions should now be seriously considering the SAIV model.
This is an opinion piece. Reasonable CAEs will disagree with parts of it, and I address the strongest arguments for both models before I finish.
The Value of a Genuinely Outside View
The entire premise of an external quality assessment is that internal audit — an activity built around the discipline of independent, objective evaluation of everyone else in the organization — is rarely well positioned to evaluate itself with the same rigor it applies elsewhere. That is not a criticism of internal auditors' integrity; it is a structural observation about self-review of any kind.
A SAIV asks the function to conduct "a comprehensive and fully documented internal assessment" of its own conformance, with the independent assessor then sampling and validating that work rather than building the assessment from the ground up.[2] The IIA's own guidance on sampling illustrates the difference in depth: a full-scope EQA typically reviews 10–20% of engagement workpapers, while a validated self-assessment reviews a smaller, mixed sample — some workpapers already reviewed internally, some not.[3] The independent assessor in a SAIV is, by design, checking the checker's work rather than forming an entirely unmediated view of the function.
A fully external model therefore retains a clear advantage. The assessor forms judgments — about conformance, about the achievement of performance objectives, and about the quality of individual engagements — without relying on the internal team's assessment as the primary starting point.
For an internal audit function, whose entire value proposition to the board rests on the credibility of independent judgment, this matters.
But it is important to distinguish between independence and quality. Independence is an essential component of a credible assessment, but it is not necessarily the only determinant of its quality. The depth of evidence reviewed, the quality of the methodology, the competence of the assessor, the consistency of the assessment process, and the extent to which findings lead to meaningful improvement all matter as well.
That distinction may become increasingly important as the capabilities of SAIV evolve.
Boards Deserve Confidence — But Does That Require a Fully External Assessment?
GIAS requires that both internal and external assessment results be reported to the board or audit committee and senior management, and it requires that the board understand the robustness of the quality assessment process in order to build trust in the function.[4]
Historically, it has been easy to equate robustness with external independence. A board may reasonably feel more comfortable knowing that an outside assessor has reviewed the function rather than relying primarily on the function's own assessment.
But perhaps the better question is not simply who performed the assessment? It is how robust was the assessment process?
A well-designed SAIV does not eliminate independent scrutiny. It combines a comprehensive self-assessment by the internal audit function with independent validation. The model is explicitly recognised by GIAS as an acceptable route to meeting the external assessment requirement.
The difference, therefore, is one of degree and process rather than a simple distinction between independent and non-independent assessment.
The board should certainly understand the model used, the scope of the validation, the evidence reviewed, and the basis for the conclusions reached. But if a SAIV can demonstrate rigorous evidence gathering, comprehensive standards mapping, robust internal challenge, independent validation, and transparent reporting, should the board automatically regard it as inferior simply because the assessment was not performed entirely by an external party?
That is a question worth asking.
The Counterarguments, and Where They Fall Short
The strongest case for the fully external model remains independence.
An external assessor has no stake in the outcome and is less likely to be influenced by the internal team's interpretation of its own performance. The external assessor can challenge assumptions, identify blind spots, and see weaknesses that those inside the function may have normalised.
These are significant benefits, and they should not be understated.
The strongest case for SAIV, however, is not simply cost and disruption. A well-executed SAIV can build internal capability in a way that a fully external assessment may not. Requiring the function to conduct its own comprehensive self-assessment forces the team to understand the Standards at a level of detail that passively receiving an external assessor's findings may not achieve.
There is also a potential advantage in continuity. A function that understands how to assess itself rigorously may be better positioned to identify and address quality issues throughout the five-year cycle rather than waiting for an external assessment to expose them.
The historical response to these arguments has been that functions can and should conduct rigorous internal self-assessment under Standard 12.1 on an ongoing basis, while still commissioning a fully external EQA for the periodic Standard 8.4 requirement. There is considerable merit in that position.
But the question now is whether the distinction between the two models is changing.
Is AI Changing the SAIV Equation?
Artificial intelligence may be the development that most deserves to challenge the profession's traditional assumptions about quality assessment.
The historical weakness of self-assessment is not necessarily that internal auditors lack professional integrity or competence. It is that self-assessment is vulnerable to human limitations: incomplete evidence review, inconsistent application of criteria, confirmation bias, limited capacity to examine large volumes of documentation, and the tendency to focus attention on areas that are already familiar.
AI may not eliminate these risks, but it could help address some of them.
AI-enabled tools have the potential to assist with standards mapping, analyse larger volumes of engagement documentation, identify inconsistencies across workpapers, compare evidence against defined criteria, surface patterns and themes, and support more continuous monitoring of quality indicators.
That possibility changes the conversation.
If a function can use AI to examine a substantially larger body of evidence than would previously have been practical, identify potential gaps that human reviewers might miss, and maintain a structured evidence base throughout the assessment cycle, then one of the traditional arguments for the superiority of a fully external assessment may begin to weaken.
This does not mean that AI can independently assess quality. Nor should it.
AI does not possess professional judgment, contextual understanding, or accountability. It cannot replace the independence of an external assessor or the responsibility of the CAE and board. It can, however, potentially make the self-assessment process more systematic, more evidence-based, and more comprehensive.
The question for the profession is therefore not whether AI makes SAIV automatically better. It is whether AI makes it sufficiently better that more internal audit functions should now consider it as a credible alternative to a fully external assessment.
I believe that question deserves serious consideration.
The Case for Reconsidering the Default
The argument for a fully external EQA is strongest when the principal objective is to obtain the most independent possible outside perspective.
The argument for SAIV becomes stronger when the objective is to combine rigorous self-examination, continuous improvement, internal capability-building, independent validation, and cost-effective use of resources.
Perhaps the choice should therefore depend more explicitly on what the function and its board are trying to achieve.
A smaller internal audit function may choose SAIV because the cost and disruption of a full-scope EQA are disproportionate to its resources. A larger function may choose it because it has a mature QAIP, sophisticated internal quality assessment capabilities, and the ability to use technology to support comprehensive evidence review. Another function may prefer a fully external EQA because the board particularly values an entirely independent perspective.
All of these could be reasonable decisions.
The profession should be cautious about creating an implicit hierarchy in which full-scope EQA represents "gold standard" quality and SAIV represents the option chosen only when cost makes the preferred model unaffordable.
The 2024 Standards deliberately provide a choice. Perhaps the time has come to explore that choice more openly.
A Note on Cost as the Deciding Factor
I recognize that for some functions, the choice remains primarily about cost and disruption. A full-scope EQA is more resource-intensive for both the assessed function and the assessor, and GIAS itself frames SAIV as a way to balance the comprehensive nature of a full-scope EQA with the cost-effectiveness and reduced disruption of validated self-assessment.[5]
For smaller organizations, or internal audit functions competing for scarce budget against other governance priorities, this is a real constraint.
But if AI and other technologies can reduce some of the historical limitations of self-assessment, then cost may no longer be the only reason to consider SAIV.
The decision could increasingly become a genuine choice between two credible approaches, each with different strengths.
The question for CAEs and boards should therefore be: Which model gives us the greatest confidence that our internal audit function is being assessed rigorously, independently where it matters most, and continuously improved?
The answer may still be a fully external EQA.
But it may also be SAIV.
Conclusion
The 2024 Standards were careful, and rightly so, not to make the fully external EQA mandatory in every circumstance. The profession is too varied in size, maturity, and resourcing for a single mandatory model to work everywhere.
Both full-scope EQA and SAIV are recognised routes under Standard 8.4. The profession should therefore be cautious about treating one as inherently superior without continuing to examine the evidence and the changing context in which quality assurance is performed.
There remains a compelling case for the fully external model. The value of an independent assessor forming a view without relying on the function's own assessment is significant, particularly where the board places a premium on external challenge and independent credibility.
But that does not necessarily make the fully external model the only gold standard.
A rigorous SAIV, supported by mature internal quality processes, independent validation, continuous self-assessment, and increasingly sophisticated use of AI, may offer a compelling alternative. AI will not replace professional judgment, independence, or accountability. But it may enable internal audit functions to review more evidence, identify more patterns, and monitor quality more continuously than was previously possible.
Perhaps, then, the profession should stop asking whether SAIV is simply a cheaper or less disruptive version of a full EQA.
The more important question may be whether, in an increasingly technology-enabled profession, SAIV can become a genuinely robust model in its own right.
For CAEs and boards considering their next assessment, the decision should not be driven by tradition alone. The fully external model remains an important and valuable option. But SAIV deserves to be considered on its merits — and the arrival of AI may be the reason to look at it again with fresh eyes.
The future of quality assurance may not have a single gold standard. It may instead require us to choose the model that provides the strongest combination of independence, evidence, professional judgment, continuous improvement, and confidence for the particular internal audit function and the board it serves.
Endnotes
1. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment; TeamMate/Wolters Kluwer, "Maximizing Internal Audit Effectiveness through External Quality Assessments," April 2025.
2. Baker Tilly, "Preparing for Your External Quality Assessment under the [Global Internal Audit Standards]," July 2025.
3. The Institute of Internal Auditors, Quality Services, "Internal Audit Quality Frequently Asked Questions."
4. Wolters Kluwer, "Domain III: Governing the Internal Audit Function," June 2024, summarizing GIAS Standard 8.4 board-communication expectations.
5. TeamMate/Wolters Kluwer, "Maximizing Internal Audit Effectiveness through External Quality Assessments," April 2025.
6. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality, and Standard 12.1, Internal Quality Assessment.
7. The Institute of Internal Auditors, Quality Assessment Manual, 2024 Edition.






