Quality Assessment: Why Ticking the Box Isn’t Enough and Why Professional Judgment Is Key

Quality Assessment: Why Ticking the Box Isn’t Enough and Why Professional Judgment Is Key

I was recently asked a great question about the new Global Internal Audit Standards (GIAS) ratings: Do you have to rate every single requirement within a Standard? 

The new rating scale, Fully Achieves, Generally Achieves, Partially Achieves, Does Not Achieve gives clearer labels but also requires more discernment. You assess the underlying requirements to assign one final rating for the whole Standard. The labels help, but they do not replace judgment.

The core principle remains unchanged: ratings are a synthesis. They are not a mechanical tally. The assessor must weigh evidence, materiality, and consequence before landing on the most defensible conclusion for the Standard and, ultimately, for the internal audit function.

Competency in Focus: When a Shortfall Isn’t Minor

Consider Standard 3.1: Competency, auditors must continually develop their skills. In the scenario I was given, the team missed required annual training/CPE hours due to budget cuts. Some minimal training occurred, so the intent was not a total failure. The instinct might be to soften the impact because “something” happened.

My professional judgment is different. Failing to meet this requirement directly hinders an audit team’s ability to perform its job effectively. Even if the “spirit” of development was partially met, the severity of the miss should drive the result.

The Cascading Effect on the Overall Conclusion

In this case, I would rate Standard 3.1: Competency as Partially Achieves. That rating matters beyond the individual Standard. A severe, fundamental gap in competency cascades into Principle 3 – Demonstrate Competency and influences the overall conclusion of the internal audit function. 

Ratings do not live in isolation; they signal capability, reliability, and stakeholder confidence.

The takeaway is straightforward, a single, severe non-conformance, even if other parts of the Standard look acceptable, can be so consequential that it dictates the final rating. Severity and impact outrank volume. This is exactly where professional judgment earns its name.

Ratings That Reflect Reality

Good quality assessment is not a box-ticking exercise. It is a reasoned evaluation of evidence against what truly matters for effective assurance. 

When severity and consequence are high, the rating must reflect that reality, even when it is uncomfortable. This protects the credibility of internal audit and ensures leadership receives conclusions they can rely on.

Why Judgment Must Lead the Ratings

Labels guide us, but judgment leads. The profession’s standards expect assessors to weigh context, consequence, and competence. 

When we let professional judgment set the tone, our ratings become what they should be: clear signals of assurance quality that stakeholders can trust.