| Title | Chief Audit Executive (CAE) |
|---|---|
| Department | Internal Audit |
| Reports to | [Board Audit Committee / Chief Executive Officer] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Chief Audit Executive (CAE) provides executive leadership for [Company]'s internal audit function. This role delivers independent, objective assurance and advisory services designed to add value and improve the effectiveness of governance, risk management, and control across the enterprise.
The CAE reports functionally to the Board Audit Committee and administratively to executive leadership, safeguarding the independence of the audit function. The role owns the risk-based audit plan, the professional practice of audit, and clear reporting of findings and remediation.
As organizations adopt AI, cloud, and automated decisions, the Chief Audit Executive extends assurance to these areas, evaluating whether AI governance, model controls, and data practices operate as intended alongside risk, compliance, and AI governance leaders.
Key responsibilities
Audit strategy and planning
- Own the internal audit strategy, charter, and operating model.
- Develop the annual risk-based audit plan and resource strategy.
- Align audit coverage with the enterprise risk profile.
- Maintain the professional practice, methodology, and quality program.
- Present the audit plan, results, and opinions to the Audit Committee.
Assurance and audit execution
Direct the execution of assurance engagements across the enterprise, including:
- Financial, operational, and compliance audits
- Technology, cybersecurity, and data audits
- Third-party, project, and process audits
- Emerging areas such as AI, model, and automated-decision assurance
Governance and independence
- Serve as a trusted advisor to the Board Audit Committee.
- Safeguard the independence and objectivity of the function.
- Coordinate with external audit and other assurance providers.
- Support the combined assurance and three-lines model.
Reporting and remediation
Deliver clear reporting of audit findings, root causes, and recommendations, and track management action plans and remediation of issues to closure with appropriate escalation.
Risk and control advisory
Provide advisory input on control design for new initiatives, systems, and AI deployments, and offer objective challenge on emerging risks without impairing audit independence.
Special investigations and fraud
- Oversee or support investigations of fraud and significant issues.
- Coordinate with legal, compliance, and human resources as needed.
- Evaluate anti-fraud controls and lessons learned.
- Report material matters to the Audit Committee.
Function leadership and quality
Build and develop the internal audit team, maintain conformance with recognized internal audit standards, run the quality assurance and improvement program, and adopt data analytics and audit technology.
Required qualifications
- Bachelor's degree in Accounting, Finance, Business, Information Systems, or a related discipline. Master's degree or MBA preferred.
- 15 to 20+ years of progressive experience in internal audit, external audit, risk, or controls.
- 5+ years leading an internal audit function or major audit portfolio.
- Experience reporting to and advising a Board Audit Committee.
- Deep knowledge of internal audit standards, governance, risk, and control frameworks.
- Experience auditing technology and, increasingly, AI and data environments.
Preferred certifications
One or more of: CIA, CISA, CPA, CRMA, CFE, CISSP, and CGAP in public-sector settings.
Technical knowledge
Internal audit standards and methodology, risk-based audit planning, governance, risk, and control frameworks, financial, operational, and compliance auditing, IT and cybersecurity auditing, data analytics for audit, fraud investigation, combined assurance and the three-lines model, quality assurance and improvement programs, and assurance over AI, models, and automated decisions.
Essential competencies
Executive leadership, independence and objectivity, Audit Committee communication, sound professional judgment, influence and diplomacy, analytical rigor, program management, and integrity under pressure.
Success measures: first 12 months
- Assess and refresh the internal audit strategy and charter.
- Deliver a risk-based annual audit plan.
- Strengthen audit methodology and quality program.
- Improve findings reporting and remediation tracking.
- Build the combined assurance relationship with the Audit Committee.
- Extend coverage to technology, AI, and data.
- Advance data analytics in audit.
- Develop the audit team and capabilities.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in internal audit and assurance rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC leadership jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC leadership jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Chief Audit Executive (CAE) do?
The Chief Audit Executive leads the internal audit function. They own the risk-based audit plan and deliver independent, objective assurance over governance, risk management, and control, reporting findings and opinions to the Board Audit Committee and tracking remediation to closure.
What qualifications and certifications does a Chief Audit Executive need?
Most CAEs bring 15 to 20 or more years in internal or external audit, risk, or controls, including at least 5 years in leadership, often with a Master's degree or MBA. Common certifications include CIA, CISA, CPA, CRMA, and CFE.
Who does a Chief Audit Executive report to?
The CAE reports functionally to the Board Audit Committee and administratively to executive leadership, commonly the Chief Executive Officer. This dual reporting line protects the independence and objectivity of internal audit.
How does AI affect the Chief Audit Executive role?
AI and automated systems create new areas that require assurance, from model controls and data quality to AI governance itself. The CAE extends the audit plan to cover these areas, evaluating whether AI controls operate as intended using references such as the NIST AI Risk Management Framework and ISO/IEC 42001, while preserving audit independence.