The question at hand
EU regulators have flagged a troubling pattern for fund managers: compliance and internal audit functions often lack independence, have insufficient resources, and vary in effectiveness based on organizational size and jurisdiction. This raises a longstanding debate: where should the internal audit function report?
Traditionally, internal audit reports to the CFO or another C-suite executive. However, governance frameworks increasingly favor reporting directly to the board or audit committee. Both structures have their advocates and create different risk profiles for your organization.
If you're restructuring your audit function or evaluating your current reporting line, it's essential to understand what each model delivers in practice.
The case for CFO reporting
The argument for CFO reporting is practical. Internal audit needs operational access. You can't audit what you can't see, and finance leaders control budget allocation, system access, and coordination. Reporting through the CFO allows for faster approvals, smoother coordination with finance teams, and direct insight into financial controls important for SOC 1 readiness or Sarbanes-Oxley compliance.
This structure suits smaller organizations where the board meets quarterly and can't handle weekly updates. The CFO is available, understands the business, and can translate audit findings into actionable steps.
There's also a talent aspect. For mid-sized fund managers, reporting to the CFO signals that internal audit is integrated into operations, not isolated. Auditors who want to understand business operations often prefer this model.
CFO reporting simplifies resource allocation during high-stakes projects. When preparing for a SOC 2 Type II audit or responding to regulatory inquiries, the CFO can quickly redirect resources. This speed is crucial when regulators question control effectiveness.
The case for board reporting
Independence is a strong argument for board reporting. When internal audit reports to the CFO, it evaluates controls the CFO owns, creating a structural conflict. Consider financial reporting controls under the COSO Framework, treasury operations, or third-party payment processing. If the CFO directs the audit plan, independence is compromised.
ISO/IEC 27001 Annex A.18.2.1 requires independent review of information security. The NIST Cybersecurity Framework emphasizes governance structures separating oversight from execution. Independence isn't about doubting ethics; it's about removing pressure that influences audits and findings.
Board reporting changes the dynamic when control failures are found. Reporting a deficiency to the CFO affects their performance evaluation. Reporting to the audit committee shifts the focus to governance.
Regulators have highlighted independence gaps. A CFO reporting structure raises questions during examinations that board reporting doesn't. This is a real concern.
Board reporting also protects resources differently. Audit committees face fiduciary duties, not quarterly targets. This creates different budget priorities when resources are tight.
Where practitioners actually land
Many organizations use a hybrid model. Internal audit reports administratively to the CFO for budget and operational support but functionally to the audit committee for planning, findings, and evaluation. This approach, supported by the Institute of Internal Auditors' Standards, balances operational effectiveness with governance independence.
The hybrid model works when boundaries are clear. The CFO handles logistics, while the audit committee approves plans and reviews findings. Document this split in your audit charter and enforce it.
However, the hybrid fails if lines blur. If the CFO edits reports before they reach the committee, independence is compromised. If the audit committee only sees summaries, the model is undermined. Respecting boundaries is crucial.
Smaller organizations struggle with models requiring active board engagement. If the audit committee meets infrequently and lacks audit expertise, board reporting becomes ceremonial. In such cases, CFO reporting ensures findings are addressed.
Our take
Regulators rightly flag independence as a vulnerability. If internal audit reports solely to the CFO, there's structural risk that will be questioned during reviews, especially as scrutiny intensifies across EU jurisdictions.
Independence isn't binary. The question is whether your structure allows internal audit to escalate findings without filtering and execute a risk-based plan without interference.
If operating under a CFO model, implement compensating controls. Document escalation rights to the audit committee, have the committee approve the annual plan, and protect audit independence in scope and reporting.
If moving to board reporting, ensure operational access, budget authority, and an engaged committee. Board reporting without active engagement just creates distance without delivering independence.
The real vulnerability isn't the reporting line. It's under-resourcing and passive governance. Address these, and your reporting structure becomes less critical. Ignore them, and no org chart will save you when regulators question control function effectiveness.



