Internal Audit and TEQSA's Quality Assurance Standards

📕
Free planner
Download the Darlo Threshold Standards Map

— a one-page map of the Standards by domain with the evidence each typically requires, drawn from our TEQSA registration and governance work with private providers. Get the map

An auditor checking records against a standards checklist, illustrating the internal audit TEQSA expects under its quality assurance standards
Updated: 2026-09-20

The internal audit TEQSA will credit as quality assurance evidence is a planned, independent test of whether the provider is actually meeting specific Threshold Standards, reported to the governing body, with findings that change the risk register and the self-assurance report. TEQSA does not require a provider to have an internal audit function, and it does not conduct audits itself in the sense ASQA does. But Standard 5.3 requires monitoring, review and improvement, and Standard 6.2 requires the governing body to satisfy itself that the provider is compliant. Internal audit is the mechanism that lets a board say how it knows.

This article describes how to scope such a function, keep it independent, and connect it to the two documents that matter most at renewal. It reflects fifteen years of TEQSA registration and renewal work in which the providers with the fewest surprises were the ones that had tested themselves first.

Why a provider needs to test its own compliance

Self-assurance changed what TEQSA asks for. Since the retirement of Confirmed Evidence Tables for higher education registration, the provider tells TEQSA which standards it meets and points to the evidence in a report of no more than ten pages. That is a statement to a regulator, and it has to be true. A governing body that signs it on the basis of management's assurance alone has no independent basis for the claim. A governing body that signs it on the basis of an audit programme has one.

TEQSA's renewal of registration guide describes a risk-based assessment that weighs the strength of a provider's evidence. Evidence that has been independently tested inside the provider is stronger than evidence that has not. That is the whole case for internal audit in this sector, and our article on achieving quality assurance through TEQSA sets it in the wider quality framework.

Scope: audit against the Standards, not the policies

The mistake I see is auditing whether the policy was followed. That has its place, but the Threshold Standards are the test, and a provider can follow a deficient policy perfectly. An audit programme should pick a small number of standards each year and test them directly: does Standard 1.1 hold, in the sense that admission decisions for this cohort followed published criteria and the records show it; does Standard 3.2 hold, in the sense that every unit this semester was taught by someone qualified as the staffing policy and the Standards require.

Pick the standards by risk. A provider growing fast should audit admissions and staffing. A provider with third-party delivery should audit Standard 5.4. A provider whose integrity register looks thin should audit Standard 5.2 and find out whether referrals are reaching it. Over a registration period the programme should cover the standards the self-assurance report will rely on most, so that the report's claims have been tested before they are made.

Independence, proportionate to size

A private provider with three hundred students will not have an internal audit department, and TEQSA does not expect one. What it expects is that whoever tests compliance is not the person responsible for it. In practice that means the compliance manager audits academic operations, an external academic audits the compliance function, the finance function is tested by the external auditor, and none of them reports the result only to the person whose work was examined.

The report goes to the governing body, or to an audit and risk committee of it, with management's response attached. Some providers combine this with the independent governance reviews TEQSA requires at renewal, which is sensible, provided the reviewer's independence is real. A review conducted by the provider's own consultant is not an audit; it is advice, and TEQSA will read it that way.

Internal audit TEQSA reads as evidence feeds the risk register

An internal audit TEQSA reads as evidence produces findings that go somewhere. Each finding should be rated, assigned an owner and a date, and entered on the risk register as either a new risk or a change to an existing one. The register review at the next governing body meeting should then show the finding being considered and the control adjusted. That is the chain that turns an audit report into evidence of Standard 6.2 operating.

The failure is the audit report that is noted and filed. In my experience most providers that have internal audit at all have this failure, and it is a costly one, because the record now shows the board choosing not to act on a finding. Our guide to preparing for a TEQSA quality assessment explains how assessors read that gap.

Reporting that feeds the self-assurance report

The second destination is the self-assurance report. Every claim in it should be traceable to evidence, and the strongest evidence is a tested claim: "Standard 1.1 was audited in 2027 against the 2026 intake; two findings were made, both closed by March 2028; the register records the closure." That sentence, with the audit report indexed behind it, does more for a renewal application than a page of description.

Building the report that way requires the audit programme to be planned around the renewal cycle. Our TEQSA compliance guide for private providers sets out the annual calendar into which an audit programme fits, typically two or three standards tested each year with the results indexed as they arrive.

Keep it honest and keep it small

Internal audit in a private provider works when it is modest in scope, genuinely independent, reported to the board and acted on. TEQSA does not require it, but TEQSA rewards the evidence it produces, and a governing body that can say how it knows the provider is compliant is in a different position at renewal from one that can only say it believes so.

Free download

Download the Darlo Threshold Standards Map

— a one-page map of the Standards by domain with the evidence each typically requires, drawn from our TEQSA registration and governance work with private providers. Get the map

Keep reading — free

Want the full article?

Enter your email for free access to the rest of this guide and our TEQSA resource library.

Frequently asked questions

Does TEQSA require an internal audit function?

No. The Threshold Standards require monitoring, review and improvement (Standard 5.3) and corporate monitoring and accountability (Standard 6.2), but they do not prescribe internal audit. It is a mechanism providers use to show those standards operating.

Does TEQSA audit providers?

Not in the ASQA sense. TEQSA conducts assessments at registration, accreditation and renewal, compliance assessments where risk indicates, site visits and requests for further information. Renewal is risk-based and weighs the strength of the provider's own evidence.

Who should conduct an internal audit at a small provider?

Someone independent of the area being tested: the compliance manager for academic operations, an external academic for the compliance function, the external auditor for finance. Results should go to the governing body or its audit and risk committee, not only to the person audited.

How does internal audit connect to the self-assurance report?

A tested claim is stronger evidence than a described one. Audit findings, their closure and the register entries behind them can be cited directly in the ten-page self-assurance report and indexed in the evidence index TEQSA requires at renewal.

BM
Dr Brendan MoloneyCEO, Darlo Higher Education

Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.

Not sure where to start? Talk to us.

A short conversation tells you where you stand and what it takes — no cost, no obligation.

Talk to us →