Free · No sign-up required · Results in 5 minutes

Could your audit function evidence every review it owes?

Answer 15 questions across four domains. Get an instant maturity score against the IIA IPPF and the review obligations SAMA and the NCA impose — including the CSCC independent review on a three-year clock that most functions are not counting.

Under 5 minutes
15 questions. Instant results. No signup required to start.
4 domains scored
Independence, planning, engagement, and the regulated reviews — all benchmarked.
IPPF + Saudi obligations
IIA standards plus the SAMA and NCA reviews that carry fixed frequencies.
Prioritised gaps
Leave with your top 3 gaps ranked and specific first steps.
IIA IPPF + Saudi regulator obligations · Readiness self-assessment

How ready is your internal audit function?

15 questions across 4 control domains. One at a time. Keyboard-driven. You'll get an instant maturity score and a prioritised remediation roadmap in under five minutes.

15
Questions
4
Domains
< 5 min
Complete
After the questions

What happens when you finish

Your full results are instant — score, domain breakdown and priority gaps, no email required. Optionally enter your email on the results screen to receive the report in your inbox.

01Instant maturity score

See your overall readiness percentage and where the function sits — Initial, Developing, Defined or Managed.

02Domain-by-domain breakdown

Understand whether independence, planning, engagement quality or the regulated reviews is your weakest link.

03Prioritised remediation plan

Walk away with your top 3 gaps ranked, including any fixed-frequency obligation that has slipped its window.

Beyond the assessment

Run the audit function on connected data

Universe, annual plan, engagements, working papers, recommendations and committee reporting in one place — with the SAMA and NCA control libraries already mapped, so a compliance audit draws on evidence you have already collected.

Universe to committee pack

One connected chain — auditable unit, risk rating, plan, engagement, finding, recommendation, committee report.

Regulated review tracker

The fixed-frequency obligations held with owners and next-due dates, counted from the last completion rather than intent.

Evidence collected once

Working papers captured against control references, so an audit of SAMA CSF and one of NCA ECC share the same evidence store.

FAQ

Frequently asked questions

What is the Internal Audit Readiness Assessment?
A free, interactive self-assessment that measures an internal audit function's maturity against the IIA International Professional Practices Framework (IPPF) and the specific review obligations SAMA and the NCA impose on Saudi entities. It covers 4 domains — Charter and Independence, Audit Universe and Planning, Engagement and Reporting, and Regulated Reviews and QAIP — and returns your full results instantly — with an optional email report.
Which regulator obligations does the assessment cover?
NCA CSCC control 1-4-1, which requires the cybersecurity function to review CSCC implementation at least annually, and control 1-4-2, which requires a review by parties independent of that function at least every three years. It also covers NCA ECC subdomain 1-8 on periodical cybersecurity review and audit, DCC 1-1, OTCC 1-6, the SAMA CSF internal audit requirement, and the IPPF external quality assessment due at least every five years.
Who is the assessment for?
Heads of Internal Audit and audit managers at Saudi organisations — banks and insurers supervised by SAMA, government entities and critical national infrastructure operators regulated by the NCA, and large private enterprises running an internal audit function against the IPPF.
Why does the reporting line matter to the score?
Independence is both an IPPF requirement and a precondition for satisfying NCA CSCC control 1-4-2, which requires reviewers independent of the cybersecurity function. An internal audit function reporting through IT or through the CISO cannot satisfy that control regardless of the quality of its work, so the assessment weights the reporting line heavily.
How long does the assessment take?
The assessment has 15 questions and takes approximately 4 to 5 minutes to complete. Your full results appear instantly with no signup; you can optionally enter your email to receive the report in your inbox.
Get started

Start your internal audit assessment — it takes under 5 minutes.

Free. Instant results. No commitment. Built for Heads of Internal Audit at Saudi organisations.

Take the assessment