We study how internal auditors manage their role to meet different situational realities, and how and what type of internal audit function emerges from such practice. We contribute to the understanding of the development of internal audit as temporally emergent rather than a consequence of enduring causes.
We conducted 29 semi-structured interviews (27 with Chief Audit Executives in Swedish public sector agencies and 2 with senior internal auditors representing the IIA Sweden) and utilised NVivo to analyse the interview transcripts with a theoretical coding inspired by Pickering's framework of temporal emergence through the mangle of practice in the three lines model (TLM).
Internal audit emerges as a practice in which practitioners employ modelling, safeguarding and augmenting tactics to address challenges and defend their role as independent assurance providers. In this process, internal audit emerges as a pedagogical function that accommodates resistances to safeguard its independence and educate organisational members about the value of an independent internal audit.
Our findings contradict prior research, which suggests that internal auditors manage the ambiguity of the role with a bias towards management. We highlight their understanding of independence and its significance in providing assurance and recommendations for the organisation instead, while also providing support from the bottom up. Furthermore, we demonstrate that internal auditors effectively address threats to independence by utilising three tactics within the confines of the TLM.
1. Introduction
Internal audit provides independent assurance and thereby assists governing bodies in overseeing management teams (Abbott et al., 2010; D'Onza et al., 2015; Stewart and Subramaniam, 2010). Such a task is not without complications because internal auditors are part of the control structure that they are assigned to audit (Nickell and Roberts, 2014). Along with the provision of assurance, their services include consultancy advice aimed at adding value to management (Cantù et al., 2024; Chambers and Odar, 2015; D'Onza et al., 2015; Ferry et al., 2017; IIA, 2020a; Lenz and Sarens, 2012; Leung et al., 2011). Research on the role of internal auditors reflects this issue. Insofar as there is no consensus as to what the “appropriate mix” of internal audit activities is (Abbott et al., 2010), the role of the internal auditor is both to be a warden who provides ex-post assurance and a consultant to management that delivers ex ante advisory services (Ahmad and Taylor, 2009; Mihret, 2014; Mihret and Grant, 2017; Roussy, 2013; Van Peursem, 2005). Research suggests that this variation is problematic because it presents internal auditors with institutional ambiguity (Page and Spira, 2005; Sinha et al., 2025) regarding their core mandate (Lenz and Sarens, 2012), ethical issues and dilemmas (Brivot et al., 2024) and conceptions of independence (Eklöv Alander, 2023). Internal auditors consequently risk undermining their independence (Ahmad and Taylor, 2009; Everett and Tremblay, 2014; Ferry et al., 2017; Neu et al., 2013; Roussy, 2013, 2015) as well as the function's role and relevance (Lenz and Hahn, 2015) by becoming “jacks of all trades” (Roussy and Perron, 2018), while simultaneously facing a stigma as watchdogs that affects their ability to add value (Eulerich et al., 2021).
Within this context, there is a budding stream of literature that points to the different tactics used by internal auditors to manage ambiguity (Ferry et al., 2017; Gustafsson Nordin, 2023; Roussy, 2015; Roussy and Rodrigue, 2018; Van Peursem, 2005). Studies show that internal auditors use coping strategies (Roussy, 2013, 2015), impression management (Roussy and Rodrigue, 2018) and different forms of ethical judgment (Brivot et al., 2024). In doing so, internal auditors compromise their ability to contribute to effective governance because these practices erode their independence and reposition them as protectors of management and promoters of organisational performance (Roussy, 2013, 2015; Roussy and Rodrigue, 2018; Brivot et al., 2024). A similar yet more radical perspective suggests that the quest for independence is already lost and follows a tragic trajectory (Gustafsson Nordin, 2023). From this viewpoint, internal auditors manage ambiguities by relocating them through narration across time (e.g. through quarantine practices) and space (by maintaining professional distance), thereby rendering them less paradoxical. Other studies adopt a less emphatic stance, showing that internal auditors manage conflicts by building consensus and developing shared ideas and language (Van Peursem, 2005) or, as Ferry et al. (2017) argue, that any role internal auditors assume, whether as watchdogs or protectors of management, depends on their ability to legitimise their actions through professional experience and communicate suggestions that may carry emancipatory potential.
Based on these identified strands in the literature, we study the tactics internal auditors use to handle conflicting issues to uphold their independence. Our research question is: How do internal auditors manage their role to meet different situational realities, and what type of internal audit function (IAF) emerges from such practice? This is of particular interest because, as Roussy and Perron (2018, p. 373) conclude, “scholars know very little about how internal auditors behave or how they address conflictual situations and ethical issues”. Moreover, all of the 13 papers they identified of the day-to-day practices of internal auditors, except one, “cast doubt on internal auditors' ethics when internal audit is considered to be an oversight governance pillar that must remain independent” (p. 376). In essence, we argue that Van Peursem's (2005) insight still holds; an important contribution remains to be made by understanding the complexities of the role. On a more general level, other scholars have also pointed to the need for studies focusing on internal audit at the micro level (Behrend and Eulerich, 2019; Santonastaso et al., 2023).
Based on 29 semi-structured interviews, 27 with Chief Audit Executives (CAEs) in Swedish public sector agencies (PSAs) and two with senior internal auditors representing the IIA Sweden, we focus on internal auditor's everyday work in relation to other actors in the three lines model (TLM) (IIA, 2020b) and answer general calls for research on the IAF as a line of defence (Roussy and Rodrigue, 2018) and its “core business role” (Roussy and Perron, 2018, p. 347). Specifically, we contribute with an understanding of the development of internal audit as temporally emergent (Pickering, 1995) rather than as a consequence of enduring causes. The study reveals that internal auditors employ three tactics to counter resistance to their practice: modelling, safeguarding and augmenting moves. These tactics are utilised to achieve their objective of conducting a high-standard, independent internal audit, thereby defending their position in the TLM. In this way, we contribute to the budding internal audit practice literature by indicating the ways in which internal auditors evoke tactics in the temporal emergence of their practice to deal with role ambiguity.
This is particularly relevant to the literature on internal audit in the public sector, where research on governance has largely relied on quantitative approaches (Cordery and Hay, 2025; Mattei et al., 2021; Nerantzidis et al., 2022), while an emerging stream of qualitative studies has begun to examine internal audit practice more closely (Brivot et al., 2024; Ferry et al., 2017; Gustafsson Nordin, 2023; Roussy, 2013, 2015; Roussy and Rodrigue, 2018; Van Peursem, 2005). Furthermore, as Christ et al. (2021, p. 470) propose, “internal auditing should be considered a worthy research topic in and of itself” rather than being primarily examined in relation to external auditing in the public sector. By examining it more closely, we contribute to an understanding of an internal audit that emerges as a mechanism that needs to be defended by internal auditors in order to preserve its capacity for accountability, governance and public value creation. This study also contributes to the literature by examining internal audit within a European setting. As Arena and Jeppesen (2016) argue, this perspective is important because most research focuses on Anglo-American or Asia-Pacific contexts, where public administration tends to be less influenced by regulation.
Next, we present a more detailed literature review and an analytical framework based on Pickering's (1993) conceptual apparatus and the TLM (IIA, 2013, 2020b). We then describe our method and the empirical setting of internal audit in Swedish PSAs, followed by our findings. Finally, we present a discussion of the findings and contributions.
2. Literature review
The debate in the literature regarding the diversity of internal audit roles persists. This debate is prevalent in scholarly literature across both the public and private sectors in various economies (Cordery and Hay, 2025; Mattei et al., 2021; Sicilia et al., 2025), even though the literature on internal audit in public sector organisations is still scant (Kotb et al., 2020; Nerantzidis et al., 2022; Roussy and Perron, 2018; Roussy, 2022). Nevertheless, there is a growing emphasis on governance mechanisms within the public sector, which is more vulnerable to fraud and corruption than the private sector, leading to demands for internal audit in various jurisdictions (Almquist et al., 2013; Neu et al., 2013). Following Roussy's (2022) advice, we review research on the diversity of the role in both the private and public sectors before focusing on studies of internal audit practice, which have primarily been conducted in the public sector.
Most research on internal audit adopts the premise that it is a governance mechanism used to mitigate agency problems (Roussy and Perron, 2018). Research has shown that internal auditing helps detect and prevent internal control weaknesses and financial fraud (Norman et al., 2010) and aids risk management (Kotb et al., 2020; Mihret and Grant, 2017; Spira and Page, 2003; Zakaria et al., 2026). These areas of internal auditing often benefit the board and its audit committee in terms of their oversight function. However, some studies question the idea of governance oversight as the premise of internal auditing because advisory aspects often take precedence (Chambers and Odar, 2015; Everett and Tremblay, 2014; Leung et al., 2011; Mihret and Grant, 2017; Nickell and Roberts, 2014; Roussy, 2015). Roussy and Brivot (2016) indicate that three of their four interpretative schemes, including the audit committee, regard governance oversight as less important, prioritising the creation of value through advisory services rather than audits. Internal auditors seem to understand and practice internal auditing as both an assurance and consulting activity and as a compliance activity (Arena and Jeppesen, 2016; Mihret and Grant, 2017). Moreover, Soh and Martinov-Bennie (2011) contend that internal auditing is a complex and evolving practice, with its role in organisations being difficult to ascertain; it cannot be limited to governance oversight.
The literature also identifies role disparity as arising from the duality of the relationship between internal auditors and boards, audit committees and managers (Lenz and Sarens, 2012). Page and Spira (2005) find that internal auditors navigate multilayered relationships with governance, peers and subordinates; hence, they need to balance their roles in the organisational hierarchy. Roussy (2013) highlights that internal auditors may face situations in which they must choose their role under limited resources, sometimes acting as “protectors” and “helpers” of managers to the detriment of the interests of the board and/or audit committee. The question, as Fazli Aghghaleh et al. (2014) point out, is then how involved internal auditors may become before ex ante participation becomes a burden rather than a benefit. In effect, the auditor cannot participate in management's decision-making without threatening independence at a later stage when auditing the results of these decisions (Gendron et al., 2001).
Overall, there is no consensus on the role(s) internal auditors play in organisations (Kotb et al., 2020; Nerantzidis et al., 2022; Parker and Johnson, 2017; Roussy and Perron, 2018; Santonastaso et al., 2023). The literature shows a variety of roles (Lenz and Sarens, 2012; Mihret and Grant, 2017; Mihret, 2014; Roussy and Brivot, 2016; Roussy, 2013, 2015; Soh and Martinov-Bennie, 2011) to the point that internal audit “is still puzzling” (Kotb et al., 2020, p. 1985), making it far from clear what the core business role of internal auditors is, who their customers are (Lenz and Sarens, 2012; Parker and Johnson, 2017), how involved they should be in management control (Mihret and Grant, 2017; Mihret, 2014; Roussy, 2015) or risk management (Fazli Aghghaleh et al., 2014). The position that internal auditors find themselves in both the private and the public sectors appears, to say the least, to be complex. They face multiple expectations from different parties, which puts them in precarious and vulnerable positions (Chambers and Odar, 2015; Everett and Tremblay, 2014; Norman et al., 2010; Parker and Johnson, 2017; Stewart and Subramaniam, 2010; Van Peursem, 2005) and although ambiguity can present them with possibilities (c.f. Power, 1997), it seems to be mostly something they need to cope with (Roussy, 2013, 2015; Van Peursem, 2005) in ways that may be nefarious to independence (Ahmad and Taylor, 2009; Roussy, 2013, 2015) and ethics overall (Everett and Tremblay, 2014; Ferry et al., 2017; Roussy and Perron, 2018).
Hence, it is relevant to examine how internal auditors manage the difficulties caused by this mixture of role attributes and demands. Only a limited number of studies on internal audit practice have addressed this issue, and these have been conducted primarily in the public sector. Van Peursem (2005) examines the conditions under which internal auditors are able to maintain their independence and finds that effective communication is the most important feature of success. This communication may take the form of a clear formal reporting structure or more informal discussions towards consensus building or clarifying the internal auditor's role for auditees.
A substantial body of research on audit practices has been conducted in the Quebec public sector (Roussy, 2013, 2015). These studies were conducted after a reform that made IAFs functionally dependent on the audit committee. Before this reform, IAFs reported directly and exclusively to the top manager. According to Roussy (2013, 2015), internal auditors continue to show allegiance to top managers even after the reform, which affects how they manage role conflicts. Roussy (2013, p. 565) finds that internal auditors in the Quebec public sector act as “keepers of secrets” to protect the top manager and thus impede their watchdog role in supporting the audit committee. To facilitate ensuing role conflicts, they adopt coping strategies such as “grey independence”, negotiating tactics and internalising behaviour. Further exploring these findings, Roussy (2015) reveals that internal auditors employ coping tactics of both proactive and reactive kinds that help them handle and solve role conflicts that arise during their engagements through the different stages of the audit process and concludes that internal audit is perceived and implemented more as a tool for managerial control rather than as a traditional audit function. Roussy and Rodrigue (2018) examine the impression management techniques employed by internal auditors in their interactions with the audit committee. They highlight a bias favouring management, noting that internal auditors often polish reports to present top managers in a favourable light, thereby enhancing both their own and the managers' reputations in reports to audit committees. Roussy and Rodrigue (2018) suggest that the IAF is integrated into the management team, encompassing the first and second lines of defence rather than aligning with the audit committee, which is tasked with overseeing management as the third line.
In addition, Gustafsson Nordin (2023) characterizes the quest for independence as inherently unattainable, highlighting how internal auditors have to navigate the paradoxes that arise from the need to adhere to others' expectations of their independence. This is achieved, for example, through narratives of quarantine practices and the maintenance of professional distance, which serve as narrative spatio-temporal strategies to make their practice appear less paradoxical.
Contrary to the research presented above, Ferry et al. (2017) reach conclusions about the practice of internal auditors that differ from much of the previous research, suggesting that internal auditors are not colonised by governance rules and managerial influence. Rather, these structures enable auditors to perform communicative action that is potentially emancipative, achieved by legitimising their own professional status. Similarly, Cantù et al. (2024) show how internal auditors may assist in improving the integration and coordination of internal controls and enabling organisational learning. In addition, Eklöv Alander (2023) studies internal audit as a situated practice and finds four different independence archetypes that together form a basis towards which to understand internal auditors' power relations within corporate governance.
In summary, the extant internal audit literature can be broadly categorised into two streams: those examining functional role conflicts and those conceptualising the role as a site of continuous identity work, where internal auditors navigate the expectations of both mandated independence in providing assurance to the board and the pursuit of organisational relevance through partnerships with management. In this study, we draw on Pickering's (1995) performative idiom to view the internal auditor's role not as a static set of mandates but as a dynamic “mangle” of practice (Pickering, 1993). In this view, auditors must navigate a de-centred world of “becoming”, where the dual expectations of mandated independence and organisational relevance are constantly negotiated in situ. While previous studies have mapped the structural origins of these tensions (Kotb et al., 2020; Nerantzidis et al., 2022; Roussy and Perron, 2018), there is a paucity of research into the interpretive tactics practitioners utilise to manage this inherent ambivalence. A budding literature studies this ambiguity (Brivot et al., 2024; Ferry et al., 2017; Gustafsson Nordin, 2023; Roussy, 2013, 2015; Roussy and Rodrigue, 2018; van Peursem, 2005) and finds that independence is lost more often than not. Specifically, the literature lacks a thorough account of how internal auditors reconcile these role conflicts in their everyday practice to uphold their independence, leaving the nuanced tactics they employ to navigate the “mangle” of their professional roles underexplored.
3. Analytical framework
3.1 Temporal emergence through the “mangle of practice”
Our theoretical framework is grounded in the interdisciplinary tradition of accounting research, which recognises that accounting practices are deeply embedded in social action (Guthrie and Parker, 2004). To contribute novel insights to the internal auditing literature, we employ Pickering's (1995) sociotechnical framework. Pickering (1993, 1995) describes the mangle of practice as a “dialectic of resistance and accommodation” that enables “a view of science as a field of emergent human and material agency” (Pickering, 1993, p. 559). Pickering exemplifies the dialectic of the mangle by relating and analysing Donald Glaser's invention and development of the bubble chamber – an instrument for experimental research in elementary-particle physics. Through the description of events, Pickering shows how Glaser fails to realise his intentions – his plans of a working bubble chamber – and describes such failures as a sequence of resistances or “block[s] on the path to some goal” (Pickering, 1993, p. 569). In view of the failure to realise a bubble chamber, Glaser responded by devising new approaches towards his goal. This is what Pickering calls accommodation: the response to resistance through tentative approaches to circumvent the obstacles encountered towards a goal or target. In essence, this is the dialectic of resistance and accommodation, that is, the play of agencies that are both material and human (Pickering, 1993). Pickering presents two responses to blocks or resistances. The first is a mangling of the knowledge acquired during the process, which results in a conceptual account of resistances and reasons for failure, and the second is goal revision. Goal revision, as an effect of the interplay between agencies in the dialectic of resistance and accommodation, means that goals are emergent. Pickering explains that to reach “the future states of affairs at which practice aims” (Pickering, 1993, p. 578), human actors model their goals on existing things and accepted views. Modelling is an open-ended process from a source to a target, without restrictions on what it may become or emerge into. The formulae used for accommodation design can be subject to different actions: correction, modification or revision. At the forefront of the analysis lies the constant modification of the structure of human agency brought about by the temporal emergence of resistances.
Pickering views machines as phenomena set in motion and made to provide power through human practices, with their performativity hinging on the human realm. The analysis of practice that Pickering suggests is not conditional upon the material, as he argues that “my overall analysis of practice is applicable even to situations where material agency is absent” (Pickering, 1995, p. 11). One such instance is Pickering's accord of the mangle in conceptual practice. In such practice, the question is how concepts determine the mangling process. Conceptual practice has the capacity of “disciplinary agency – the sedimented, socially sustained routines of human agency that accompany conceptual structures as well as machines” (Pickering, 1995, p. 29) and “leads us through a series of manipulations within an established conceptual system” (Pickering, 1995, p. 115). Here, it is the play of agency between human and discipline that is in focus, showing that disciplinary agency can have the same role in provoking resistance upon the projects of human agents as material agency in the development of the Bubble Chamber.
Pickering describes the process as starting with bridging, meaning establishing a bridgehead, which “defines a point to which attributes of the base model can be transferred, a destination for modelling” (Pickering, 1995, p. 129). The bridgehead is the first creative idea of the target that the modelling aims to develop from the source, hence the verb bridging between the source and the target. The function of the bridgehead is to limit the unbounded nature of modelling. Pickering (1995) presents two additional types of moves that human agents perform to accommodate to resistances: filling and transcription. Filling is a free move of discretionary choices and involves actively assigning values to undefined terms in order to accommodate resistance. Transcription is a forced move, a machine-like human agency disciplined by manifest programs that work through authoritative establishments of disciplinary agency. Under the influence of disciplinary agency, human agents must undertake forced moves, which “carr[y] scientists along, where scientists become passive in the face of their training and established procedures” (Pickering, 1995, p. 116). Transcription involves the disciplined copying of moves from the old system or source into the target. We understand transcription akin to the human actor's embodiment of Foucault's notion of discipline: “A good discipline tells you what you must do at every moment” (Foucault, 2007, p. 46). This characteristic of transcription being sourced from a body of knowledge already established in the source also makes the work possible to be monitored by outsiders to the mangling process. Through the mangle, disciplinary agency meets resistance, which must be met with transcription towards the production of the target.
3.2 Three lines model
We view the IIA's TLM (IIA, 2020b) as a basis for internal auditors to enact the goal of their practice. In this sense, the model can be seen as a bridgehead towards the ultimate goal of internal auditors: conducting high-quality audits that require independence. The TLM (IIA, 2020b; IIA, 2013), a tool used to ensure effective governance, has gained widespread acceptance and implementation as a recommended practice for companies listed on stock exchanges and has been embraced by financial market regulators. Despite its popularity, there is a scarcity of research examining this model and its predecessor (Bantleon et al., 2021). In the model, the division of roles and delegated responsibilities is organised in three lines. Eulerich (2021, p. 6) argues that one of the reasons the model has been widely disseminated is that “the structuring into clearly separated lines of defence with neatly separated tasks supports the clear definition of functions and responsibilities”. The first line comprises management responsible for operations, internal controls and risks to achieve the company's objectives (Bantleon et al., 2021; Van Staveren, 2021). The proper functioning of the first line is a prerequisite for the second and third lines to fulfil their roles (Van Staveren, 2021). The second line consists of specialists, such as controllers and risk officers, who provide expertise to support the organisation (Van Staveren, 2021) as a form of compliance oversight by management over operations (Bantleon et al., 2021). Other functions of the second line are to provide analysis and reports on internal controls and risk management, thereby facilitating the continuous improvement, development and implementation of the internal control system (IIA, 2020b) and assurance regarding a variety of tasks such as management control, strategic control, anti-corruption, quality management and cybersecurity (Cantù et al., 2024). The third line comprises internal auditors who independently assure the quality of the activities performed in the two previous lines (Bantleon et al., 2021; Roussy and Rodrigue, 2018; Van Staveren, 2021).
In the TLM, the board is not delineated as a “line”: “Logically, governing body roles also constitute a ‘line’ but this convention has not been adopted to avoid confusion” (IIA, 2020b, p. 5), where the board is tasked with assigning authority and allocating resources to the management team, enabling them to pursue the entity's objectives while ensuring adherence to legal, regulatory and ethical requirements. The board is also responsible for establishing and overseeing the IAF, endorsing its independence, objectivity and competence, so that it can achieve its objectives. Eulerich (2021) argues that board members and audit committees need to demonstrate integrity, sound governance practices and uphold high standards of transparency for the model to work. The TLM pinpoints the dual role of internal auditors in providing support to management and independent assurance to those in charge of governance. This underscores the dilemma of the internal auditor's unclear role (Fazli Aghghaleh et al., 2014; Everett and Tremblay, 2014; Lenz and Sarens, 2012; Mihret and Grant, 2017; Mihret, 2014; Roussy and Brivot, 2016; Roussy and Perron, 2018; Roussy, 2013, 2015; Soh and Martinov-Bennie, 2011) and raises questions about the efficacy of internal audits as the prescribed third line of defence (Roussy and Rodrigue, 2018). Therefore, there is room for studies of their role and function. Following Pickering, internal auditors' responses to resistances to their role and function can be studied through their accommodations to conceptualise what goes wrong and revise their goals. This perspective allows us to view the role of internal audit as emerging from the temporal play of agencies in organisations and the ensuing dialectic of resistances and accommodations.
In summary, we follow Pickering (1993, 1995, 2008) in the TLM (IIA, 2020b), not because the model and its forerunner are rarely studied by scholars (Bantleon et al., 2021), but because of their capacity to facilitate the study of practice. The TLM presents a distinction between the roles of internal auditors as being part of audit in the third line or advisory to the first and second lines, where authoritative policy, including ethical requirements such as those expressed in the International Professional Practices Framework (IPPF), gives rise to a disciplinary agency that influences internal auditors' interactions at work with their organisational counterparts. We study how internal auditors deploy different tactics – conceptual bridging, transcriptions that follow disciplinary agency, and filling moves – to accommodate the resistances they face and deliver services according to internal auditors' idea of their professionalism, expressed in terms of independence.
4. Methodology
4.1 Internal audit in Swedish PSAs
This study draws on interviews with CAEs in Swedish PSAs. The focus is on the internal operations of these PSAs, specifically their auditing management's internal governance and control. This distinguishes it from studies that address assurance for a broader public audience, such as performance audits conducted by national Supreme Audit Institutions (SAIs) (Grossi et al., 2023; Ferry et al., 2025), which are based on public management principles such as economy, efficiency and effectiveness (Almquist et al., 2013; Guthrie and Parker, 1999; Mattei et al., 2021). Hence, this study examines “a public audit function” (Grossi et al., 2023, p. 420) from the perspective of internal auditors (Roussy, 2022). In this section, we describe the internal audit setting in Swedish PSAs.
While the global demand for public sector internal auditing is increasing (Kotb et al., 2020), except, notably, in Denmark, where it has been virtually terminated (Skærbæk and Themsen, 2022), Sweden established its framework as early as 1995 in response to fiscal instability and governance deficiencies. The Swedish model illustrates how IAFs are implemented to enhance accountability, public governance and fiscal efficiency (cf. Cordery and Hay, 2025; Roussy, 2013). In contrast to the findings of Alzeban and Gwilliam (2014), where internal audit is used for traditional financial reporting and compliance, the Swedish public sector internal audit focuses broadly on governance and control in the PSAs in relation to their goals (c.f. Arena and Jeppesen, 2016; Liston-Heyes and Juillet, 2019). The Internal Audit Ordinance (the regulatory framework of internal audit in the Swedish government) has been updated several times since 1995 to tighten the requirements for internal governance and control (Riksrevisionen, 2017). The government decides which PSAs should have an IAF based on risk and materiality criteria (Riksrevisionen, 2017). Of the approximately 365 Swedish PSAs, around 70 are required to have an IAF, pertaining to PSAs administering large funds. Together, these PSAs comprise approximately 90% of the governmental budget (Riksrevisionen, 2017). Furthermore, in line with the IPPF's statement that boards are necessary to secure internal auditor independence, the government has judged that PSAs subject to the Internal Audit Ordinance need a board of directors to ensure better working conditions for internal auditors and maintain their independence when auditing the management of the Director-General (DG). Despite this ambition, the Internal Audit Ordinance has no such requirement, and half of the PSAs required to have an IAF are governed by a board, while the other half are single-council PSAs led solely by a DG. In PSAs without a board, the DG assumes responsibility for the IAF. In a board-led agency, the DG serves as a board member (SFS, 2007a). This means that the DG of a single-council agency acts as both an agent and a principal in relation to the internal auditor. Both DGs and board members of Swedish PSAs are appointed by the government, and the DG is directly accountable to the government for the agency's operations.
In the Swedish public administration model, PSAs are not independent but are organizationally autonomous. The government is responsible for their operations; however, the governmental ministries and PSAs are not organizationally connected and “ministerial rule” is prohibited. Instead, the government manages PSAs through ordinances, yearly appropriation directions (including goals, budgets and assignments) and appointments of heads of PSAs (DGs) and boards, except in universities and colleges, where the government appoints the DG (i.e. vice-chancellor or president) on the recommendation of the board. Since 2008, these PSAs have been subject to the Internal Control Ordinance, which requires, among other things, that the PSAs management conduct structured risk analyses and carry out controls and follow-ups based on these (SFS, 2007b). The management of the PSA also has to follow the requirements of the PSA Ordinance (SFS, 2007a), which includes the rules of procedure, including directives for the organisation of the agency, the division of work between those in charge of governance and the Director-General and ensuring adequate internal control and risk management (SFS, 2007a). According to the PSA ordinance, the board appoints the CAE, and in single-council PSAs, the DG. However, to secure the independence of CAEs, neither the board nor the DG can dismiss them from their positions.
The internal audit in the Swedish government is regulated by the Internal Audit Ordinance (SFS, 2006), where the assignment of the CAE is to audit and provide suggestions for improvements to the agency's processes for internal governance and control, as set forth in these two ordinances pertaining to managerial duties (SFS, 2007a; SFS, 2007b). This task includes performing a risk analysis as a basis to independently audit whether the management's internal governance and control is designed to, with reasonable assurance, achieve its responsibilities and objectives and is fit to fulfil the requirements of the PSA Ordinance (SFS, 2006). The Internal Audit Ordinance also establishes that it is the board/DG that decides on the guidelines and audit plan for the internal audit and the measures to be taken regarding the internal audit's observations and recommendations. According to the Internal Audit Ordinance, the IAF is headed by a CAE employed by the agency (SFS, 2006). The Swedish National Financial Management Authority (Ekonomistyrningsverket) has overall administrative responsibility for governmental internal audits (Riksrevisionen, 2017). Similar to other countries (Cordery and Hay, 2025; Grossi et al., 2023; Mattei et al., 2021), Swedish public administration has a body that performs independent oversight of government spending and performance from an external perspective, Riksrevisionen (an SAI). However, the internal audit of PSAs and the external audits performed by Riksrevisionen are disconnected.
Hence, governmental regulation institutionalises the structural position of internal auditors in Swedish PSAs, making them subservient and dependent on the DG in single council PSAs. Additionally, they are placed in a position where they must evaluate DGs in board-led PSAs. Notably, the Swedish governance model diverges from IIA standards, exposing internal auditors in single-council PSAs to role and relationship challenges because the DG is both a principal and an agent. Despite a general consensus on the supportive role of audit committees in ensuring internal audit quality (IIA, 2020b; Roussy and Perron, 2018), only a few board PSAs have established audit committees. This trend follows other jurisdictions, where the absence of a mandate for such bodies has led to the limited voluntary adoption of audit committees (c.f. Alzeban and Gwilliam, 2014), resulting in Swedish PSAs often lacking a crucial ally for internal auditors. Thus, the complexity that governance presents in this context offers opportunities to study the independence work of internal auditors.
4.2 Data collection and analysis
This study comprises semi-structured interviews with CAEs working in Swedish PSAs as of January 2020. Contact was established after receiving an invitation from the governmental CAEs to present our project and research in March 2020. After the initial interviews were obtained through this contact, the strategy evolved into snowball sampling, supplemented by direct contact with CAEs. The sample includes 27 CAEs from board-led and single-council PSAs and two senior internal auditors representing the IIA Sweden. A number of 21 interviews were conducted between April and May and eight interviews between September and November 2020. Owing to COVID-19, the interviews were conducted remotely, allowing us to reach internal auditors across Sweden. Interviews were conducted via Zoom, Skype or Teams and video recorded, except for five conducted by phone calls.
The interviews were analytical (Kreiner and Mouritsen, 2005) and semi-structured in nature. The project and interview themes were presented to each interviewee via email beforehand. The interviews lasted 60–110 minutes, averaging 72 minutes, with a total recording time of 2097 minutes. This project does not involve the processing of sensitive personal data. All interviewees provided informed consent for participation and approved it in accordance with the GDPR. All the audio files of the interviews were comprehensively transcribed. The interviewees, PSAs, names, titles and organisational tokens were pseudonymised to ensure confidentiality. Interviews are referenced using the interview date, known only to the authors and interviewees.
A qualitative analysis of the interview transcripts (Charmaz, 2006) was conducted using NVivo to support the interpretations during qualitative coding. The empirical material was initially coded and organised into empirical categories, followed by theoretical coding using Pickering's (1995) framework into three main categories related to internal auditors' work in the TLM (IIA, 2020b): resistances from the first and second lines in (1) audit work, (2) advisory work and (3) governance. Based on the identified accommodations to internal audit resistance, we outlined the emergent practice of internal audit to develop our theoretical contributions.
A respondent validation was performed in several steps during the analytical process to evaluate whether our findings were genuine and recognisable, providing correspondence between the findings and the experiences (Guba, 1981) of respondents and senior officials in the Swedish government and its PSAs: with the Academy of Management Accounting and Control in Central Government (AES); a research day in 2022 and a meeting in 2024; and workshops arranged by the IIA Sweden in 2020 and 2024. During these occasions, comments were received that helped refine our analysis, particularly where “outliers” or extreme cases could further refine our understanding of internal auditors' everyday practices and struggles (Parker and Northcott, 2016). We find that these activities improved the study's respondent validity.
5. Analysis and results
This study focuses on the emergence of the internal auditor role, particularly how the TLM is utilised in internal audit practice as a device for addressing oppositions, shaped by the actions and expectations of actors above and below them in the organisational hierarchy. We draw from the interview analysis and the TLM (IIA, 2020b) regarding its pronouncements on structures and processes to guide organisations in facilitating governance. We present our findings according to the analytical framework. We demonstrate how the TLM is mobilised as an apparatus to accommodate the resistances that CAEs encounter in their daily work. Here, we delineate how CAEs conceive of their role as a “bridgehead” (Pickering, 1995) to bridge the gap between the initial situation (source) and their goal of conducting high-quality audits (target). We further show how CAEs use the TLM in their audit and advisory practices, employing tactics of transcription and filling to accommodate resistances and strive towards their goal.
5.1 Bridgehead: a focus on independence
The interviewees view their role in accordance with the IIA's definition, which entails providing objective assurance and offering advice through additional services. Furthermore, they devote considerable efforts to establishing their primary function as audit providers, as expressed by one of the interviewees: “My insistence on precise titling stems not from arrogance, but from a commitment to accurately convey my designated responsibilities” (I2020-10-14). To accomplish these objectives, they particularly accentuate their approach to the role and their independence, primarily in relation to management, but also to auditees lower in the organisational hierarchy. This is their stance, or bridgehead in Pickering's (1995) words, which is produced to maintain their direction towards their target in modelling their assignment. It is not easy to keep the bridgehead in sight, as CAEs face resistance to their practice due to a lack of knowledge of their role, similar to the audit expectation gap discussed in the external audit literature (cf., Power, 1997).
Many people here [Name of the PSA] do not know what internal auditing is or what our role is. Thus, the gap regarding what we are expected to do, one never gets done with it. What is an internal audit, and what can it contribute to the PSA? (I2020-11-30)
As they see it, CAEs must continuously watch over their role, comprising first of all the provision of assurance, which requires independence. The difficulty experienced by CAEs relates to resistances in the form of a seizing mentality towards their role; they are perceived as skilled professionals with a diffuse role that can be exploited for a diverse set of managerial needs. CAEs mobilise the TLM as a model describing independence, a bridgehead towards their target, to stress their placement in the third line of the organisation:
We are careful to stress that we were not part of this administration. We are employed by the agency but are not part of the organisation. (I2020-05-07)
CAEs create a conceptual distance between themselves and others to manifest their independence, emphasising their position within the organisational hierarchy rather than their integration within it. To clarify their role, they use the TLM and explain that its absence in PSAs poses a significant impediment to their work. In other words, they bridge their role towards their target by mobilising the TLM to clarify their organisational position and pointing to the need to strengthen internal controls:
… it is a common observation that we need to strengthen the second defence line. We must create controls and strengthen them. […] If one had that, I think, it could have been more clear-cut, with independence, what role one plays. (I2020-05-18b)
The TLM is not thoroughly implemented in the PSAs: “Quite often, wherever I look, the entire defence line is lacking” (I2020-05-18b). This contrasts with Bantleon et al. (2021), whose study of German, Swiss and Austrian companies showed widespread TLM adoption, especially among listed and financial companies. Their research indicated that most sampled companies had implemented the model, with non-listed and non-financial companies exhibiting lower adoption rates. Notwithstanding the weak implementation of the TLM in the PSAs, the CAEs utilise the model in diverse situations to interpret challenges arising in their daily work. Thus, the TLM serves to establish the ideal of the internal auditor role as independent, the bridgehead, aligning with the TLM's first principle. This principle underscores the importance of clear roles and responsibilities in organizational governance, providing structures and processes for organisational oversight, managerial actions and the internal audit itself.
Independence is the marker of the role, and CAEs draw on the TLM as a resource to help others understand it. The second TLM principle outlines the board's role as a safeguard for the independence of CAEs and their function. Our interviewees describe situations in which neither the DG nor the board fulfilled this principle, when the CAEs had to undertake accommodations.
This is where it gets a bit backward sometimes, in which you have to strengthen your own platform instead of your client providing the right conditions. (I2020-05-06)
The internal auditor establishes the bridgehead and then defends it. As part of this, a fundamental starting point for internal auditors to do their job is to clarify their mission to their superiors.
If we are to be present in these organisations, they must be mature in this area, or we cannot do our job. One must have respect. Respect, engagement, and operational understanding, it is paramount that the DG knows this too. They should know that our function is to perform internal audits. It is in our standards, we are obliged to inform the DG, the board, and everyone else about our mission. (I2020-10-12b)
The baseline of internal auditor independence is drawn at the top, which is where they must begin. An internal audit charter is recognised as an important baseline for setting the role and is agreed upon by those in charge of governance (Lenz et al., 2014). In addition, a strong audit committee, professional association or additional policies are important sources of internal audit influence on management (Van Peursem, 2005). The obstacles to the IAF described by the interviewees are that audit committees are rare in PSAs and that managers lack knowledge regarding the role of internal auditors. There is sometimes a lack of understanding of internal control systems and management's responsibilities in internal control work. There are many sources of resistance to the internal auditor role. CAEs mobilise the TLM as a resourceful ally to accommodate these resistances. The next section shows how CAEs accommodate resistances when providing audit work in their organisations.
5.2 Performing audits – the third line
Here, we outline how internal auditors face resistances from both management and governance superiors, which they must accommodate in their daily work. They referred to these obstacles as follows: (1) a lack of knowledge about managers' roles in the first and second lines, (2) a lack of knowledge about the IAF (third line) and (3) a failure to understand the importance of the IAF's independence. These resistances arise from a lack of awareness among organisational members of the differences between the three lines, their individual roles within the internal control system, and the IAF's mission.
One CAE worked in an agency where the DG was abusive and bullying towards the CAE. The DG left the agency, but the new DG shared the same cultural view towards the IAF, “s/he was also shaped by the former DG's viewpoint that the internal audit is to be put aside” (I2020-10-14). The CAEs recurringly point to such challenges from management and how they use their skills to both resurrect their professional standing and establish auditee motivation to cooperate and work with the audit findings. One CAE in a single-council agency argues that “if you are to be a successful internal audit [function], you must be relevant” (I2020-11-30), and another provides a concrete example:
We reviewed the effects of culture on internal governance and control. It went really well. The organisation was immensely interested in participating. We got lots of interviews and focus groups and so on, but when it came to reporting, management was not too happy about the results. But after a while, when they worked with the measures, the insights began to grow. I can say that the review we conducted was extremely well-received. When we worked with the questions and explained what it was about, what we expected, and what we were thinking. (I2020-05-15a)
This example shows the management's initial dissatisfaction with the internal audit report. However, by working with the recommendations, the IAF achieved a turnaround in its managerial approach towards the audit. This underscores that when internal auditors face managerial resistance to their audit results in the third line, they need to remain diligent, focusing on explaining their recommendations to help the organisation understand the added value of implementing them; otherwise, the IAF will have no impact. To achieve this, they employ filling moves through educational efforts to ensure that organisations understand and pursue the recommendations. By following up on these measures, the third line demonstrates a tangible example of how it generates added value for management.
When internal auditors face resistance regarding their reports, with managers intending to restrict or erase particular observations or recommendations, auditors attempt to avoid accommodating their independence through a transcription move. They often employ a more strategic accommodation – the softer filling move – by tuning their message to explain the organizational value of the recommendations. In other studies, internal auditors side with managers (Liston-Heyes and Juillet, 2022; Roussy, 2013); however, our case shows that these practitioners protect their independence by effectuating a response rooted in the “mangle” of practice; they use their skills to craft reports in a manner that leaves no room for interpretations beyond those carefully delineated by the CAE.
If the IAF has decided that it is ‘red’ based on the criteria, it is necessary to have very clear criteria so that all agree about it on the scale; ‘this is red’. Once you have at least one red in the report, it is a red report, even though all the rest are green. Or if you have two oranges, the report turns red and so on, to implement this clear scale and discuss it within the organisation so that all agree. Because it is an assessment report without precedent and everyone must agree on the assessment criteria. You cannot smash a red dot in the head of someone who does not understand the background of that judgment. (I2020-03-26)
The TLM framework is clear regarding reporting lines; nevertheless, precautions must be taken regarding how to consider the reactions of managers subject to an audit.
Hence, there is a technique to deal with independence. The professional role requires that these types of comments be raised and brought to the audit committee. There are well-developed strategies to ensure that observations from a review go to the audit committee. But you cannot pull the boss' pants down. No. Instead that boss must really carefully be taken care of for these observations to be remedied. (I2020-03-26)
The CAE must avoid a situation where there is an unsolved dispute over the report between the CAE and the manager, not only because the CAE needs to defend their own standing vis-à-vis the manager but also for the sake of employees who have just completed their jobs. However, it is not only that the manager would exert pressure on the CAE to change their report, which also needs to be accommodated with transcription, but the CAE needs to make the manager understand the observations and recommendations framed in a way that facilitates the manager's insights from the audit through filling. The impact of internal audits hinges on CAEs' capacity to employ appropriate reporting practices to engage management effectively and defend their role by adding value. Hence, in Pickering's (1995) terms, CAEs use transcription to defend their independent standing to report to the audit committee despite an unwilling manager, to accommodate the risk of unjust consequences, and filling to make the organisation understand the objectives of the IAF and the value of the audit.
The TLM stipulates that internal auditors should not assume management responsibilities through a managerial role or operational decision-making. One scenario in which CAEs encounter a situation that contravenes this stipulation is when they provide recommendations based on their findings conveyed to the auditee. For instance, one agency lacked a controller, and its CAE needed to step in and manage the action points.
Interviewee: In [Agency], it could happen that I had to be the one to push and ensure that the action points were performed.
Interviewer: Who decided which actions should be taken?
Interviewee: Well, that is my point; I nearly became operative because they were my recommendations. No one did anything about them. I am of the opinion that if we give a recommendation, one must explain this to the auditee: ‘these are just recommendations’. There may have been some things that we missed. There may be issues that should be prioritised or downplayed. The auditee knows this better than we do. (I2020-04-14)
This CAE was concerned about the lack of action on the recommendations given to the first line. Instead, these recommendations were implemented without reflection, consideration or other work by the organisation. We find two resistances to this neglect that internal auditors must accommodate. First, there is a lack of action on the recommendations by the first-line organisation. The drawback of such an auditee (non) action is that the organisation becomes devoid of learning or development from the findings and recommendations given by the CAE. Then, the CAE cannot execute their filling move to establish the value of internal audit through their recommendations to deliver organisational learning capacity because this is executed when the organisation needs to tailor the changes based on a thorough analysis of the report given. Second, the risk of acting, or being perceived to act, as a first-line manager and making managerial decisions because then the CAE can no longer perform audits. The CAE transcribes this situation as a lateral movement in the TLM, conveyed by auditees as a driver to change their place from the third to the first line. CAEs must accommodate their position and independence through a transcription move, clarifying their respective lines, roles and responsibilities to themselves and auditees to defend their discipline.
I must remind people that ‘you made the decision in this matter [and] you cannot delegate it to someone else’. This is something that I constantly watch over, what the organisation should be like. (I2020-04-02)
Communication of role differences between the internal auditor and other lines is a continuous endeavour, with the TLM functioning as an anchor in this ongoing task of transcribing resistances against their discipline: “I feel that I need to be the one who has control over the structures; I need to be the one to make sure the boundaries do not move around” (I2020-04-02). The role of internal auditors in conducting audits is unambiguous in their eyes; they perform their work as part of the third line. However, from the perspective of the organisation, their skills can be mobilised for various needs. This is a necessary part of the internal auditor role, but one that may be cumbersome, as another interviewee remarked, “it can be easy to step into the role of the line manager” (I2020-05-08). Transcribing such drivers of organisational mobilisation is a concern at all levels to defend their independence:
… we want to make it [clear] at all times that it is the line manager who should do it … It is not an internal audit issue to make a judgment about how to deal with representation expenses. It is big as well as small, from participating in a management group at the leadership level to investigating gender equality to handling representation expenses. (I2020-05-08)
Another tactic is to use reporting transparency as an extension of the internal auditor's educative and supportive role, especially for managers in charge of units subject to audits.
I send everything. This is a way to involve them and make them understand the way I think, and they are welcome to comment on the findings if something is wrong. They may also comment on the recommendations if they think things can be solved more effectively than in my recommendations. I also send them my risk assessments and conclusions and respond to their enquiries. This is based on my standards. This is a form of dialogue that includes education over time. (I2020-05-06)
By being transparent to auditees and presenting them with not only a factual check of the findings but also recommendations, risk assessments and conclusions, the internal auditor opens up daily practice to scrutiny. Although such reporting procedures take more time, with this filling move, they establish the value of their observations and recommendations. The reward in the long run is greater because they produce enlightened auditees who understand the practice and role of internal auditing and can become future allies. A transcription move is not required here because the CAE has not experienced an unjust request to change their findings or recommendations; therefore, there is no threat to their discipline.
An audit possesses the potential to improve operations once acknowledged; thus, an auditor can help even marginalised units through their findings and recommendations.
We shall help and support; that is my premise. I often say that we stand in two positions at once. For instance, when we embark on departmental visits, we are here to exercise control. If we find something, we will report it; we do not withhold that, but we are also here to help, “give us all that you have, raise your problems and issues”. We can reach the management team and highlight structural issues; it is a two-way communication, which is important. (I2020-05-04)
When CAEs encounter auditees who find control work exhausting, they respond with compassion [1], a filling move whereby the CAE can draw attention to organisational malfunctions and risks. This compassionate side of auditing can be understood as an attitude to help through the audit. For example, by bringing management's attention to the risk of being fined for not following procurement rules, which is particularly important in the government, as it handles taxpayers' money. The CAE exemplified a follow-up audit that revealed the need for administrative changes and learning.
It is a borderline between advice and audit. Advice to the leadership: They gain an idea of the state of procurement in the units. (I2020-04-15a)
Thus, the interviewees departed from the common notion that internal audit provides value primarily through consultancy services to management. Instead, they viewed audit work as a compassionate practice in which audit-based recommendations add value to the organisation and distinguish it from consultancy work (see also Brady, 2019). Recommendations involve providing the organisation with insights gained during the audit, while consultancy entails hazards later, as Gramling et al. (2018) show; identifying internal control deficiencies as material weaknesses in an audit is less likely for controls that have previously been subject to consultancy. The value of an internal audit lies not in exposing a unit and its manager but, more importantly, in its capacity to display issues for resolution. Thus, the IAF serves as a space for organisational healing and development. From this perspective, independence is defended through filling moves, representing a productive accommodation of the resistances encountered during the audit process. Internal audit practitioners transform these challenges into opportunities for value creation. By navigating the “mangle” of practice in this way, internal auditors simultaneously construct a robust value base from which to contribute to the organisation's overall success.
Through recommendations based on audits, as opposed to advice from consulting, internal audit is described as a practice that is important for organisational development. The IAF's value lies in its ability to instil reflexivity within the organisation, enabling it to view itself from a third-line perspective. The TLM helps CAEs clarify their positions in relation to others. This is feasible only if independence is conferred upon the IAF, allowing it to function as a reliable and trusted party in which organisational members confide. By demonstrating consistency in this manner, trust is established, ensuring that organisational members will continue to cooperate in future endeavours.
5.3 Performing advisory services – with the first and second lines
Performing advisory services often contributes additional value to the organisation, performed as consultancy services in the traditional sense (cf. IIA, 2020a; IIA, 2020a). We find that such services are performed as free moves with spin-offs from audit work, including workshops on audit recommendations or ad hoc reviews. A resistance CAEs face is a lack of knowledge on how the IAF is organised, especially the failure to recognise the independence of the third line. An example is the seemingly logical action of inviting the CAE to join the management team.
Typically, a review is conducted, and the [DG] responds with actions, such as starting a commission by establishing a project group, and then [the group] is eager to include the internal auditor, partly because we performed a review and gathered a lot of knowledge in that area. Indeed, it is natural to use the knowledge that we have. (I2020-05-08)
As the resistances described above act as obstacles to the goal of CAEs achieving independent audits, they must investigate their consequences and relate to and accommodate them in their work. Regarding managers, controllers and risk specialists, the interviewees emphasised the need for a bridging move to clarify the differences between the three lines, their functions and the problem at hand in relation to internal audit. First-line managers often lack an understanding of their responsibility to ensure and monitor internal control efficiency (see also Christ et al., 2021). In such situations, internal auditors explain that they need to accommodate their role by clarifying their positions, including their boundaries.
My job requires mature leadership and integrity, and that you understand the limits of ‘I cannot take part and make decisions in these matters’. This is a clear boundary. I can never participate in making an operational decision because then I would become responsible for the design, but I can participate by advising the one making the decision. (I2020-05-06)
This CAE points to the risk of participating in operational decision-making from the perspective that it compromises the auditor's ability to perform an audit (Power, 1997). Such resistance requires transcription because the line between the role of the internal auditor and manager becomes blurred when internal auditors' advice is followed indifferently. If internal auditors' advice is conflated with decisions, potentially leading to unreflected implementation, responsibility and accountability may shift from the manager to the internal auditor, creating an obstacle to internal audit independence. Consequently, internal auditors must be wary of becoming entangled in managerial responsibilities (Brady, 2019). As mentioned in Section 5.2, similar resistance arises when an auditee wants to follow the recommendations given in an audit when the CAE uses filling to explain the recommendations and transcription to defend the discipline. Another obstacle is the well-recognised problem of performing audits of previous advisory work; for example, from the second line:
Now it is the case that we would review our risk analysis work and after discussion, first with the chairman and then with the [DG] and then with the administrative head, we have actually been involved in the risk and impact assessments that the entire organisation has produced. So, we have assisted in that part, which means that we cannot review it afterwards. We will have to ask someone else to do it. (I2020-04-21)
This resistance must be met with the forced move, transcription, because it threatens the requirement of the discipline of professional independence. CAEs in organisations with larger IAFs rotate internal auditors who have worked on projects resulting from IAF reviews, ensuring that other auditors conduct follow-up audits. Conversely, organisations with smaller IAFs often engage exterior auditors for this purpose. It is easier to accept an advisory role when on the Board's mandate; however, even then, the CAE ensures not to override the TLM.
We have been part of some groups where we have been commissioned by the board to serve as advisors. In such cases, we are tasked by the board to have an advisory role, and one must be careful not to step into the role of line managers. (I2020-05-08)
The CAE can build trust and contribute value by providing knowledge through workshops on topics such as risk management or internal control (see also Cantù et al., 2024). This filling move helps them contribute to the organisation with their knowledge from the third line without the risk of overstepping into the first or second lines. It is highly appreciated, with the CAE receiving applause and comments like: “This was professional and nice” (I2020-10-14). The purpose of the internal audit is also to create dialogue based on their third-line expertise.
I have been given ad hoc assignments like ‘Now something has happened here, can you go in and map out what has happened?’. I had one of those in the spring, I completed it with a memo in a week and a half, and then they got a number of action proposals, and it was pretty serious too, I think. Then you are a support to the DG who gets another view of things when the line managers at the same time go ‘We have done what we could’, but really have not done it. (I2020-10-14)
The filling move to address advisory services is explaining clearly to the organisation what they will receive from the CAE, should they choose to accept the terms.
This happens to me all the time. The organisation develops a new guideline in some area or updates an existing guideline and sends it to me: ‘Hey, could you read this and tell me what you think?’. As an internal auditor, you might feel a little nervous: Am I a hostage now? If the internal audit says it is okay, that is a pretty good stamp. So, I say, ‘I will read through this guideline, I have half an hour, I will give you my best thoughts, but I have not reviewed this guideline’. (I2020-05-15b)
Advisory services are often used as a filling move to bring value to the organisation and act as a lubricant while maintaining freedom of action for future audits. The CAE makes an agreement with organisational actors about the service content and an additional disclaimer that the guideline has not been reviewed, where regulations would be part of the comparison for guideline content.
5.4 Governance level – relations with the board and DG
In addition to resistance regarding the function of the third line in relation to the first and second lines in the provision of both audit and advice, we also identified resistances consisting of (1) the board-like status assigned to DGs in single-council PSAs, (2) the inclusion of the DG in the boards of board-led PSAs and (3) the general power position of DGs in Swedish PSAs. As described in Section 4.1, this governance form risks impairing the IAF, and we find different accommodations used by CAEs. This issue is crucial for public sector internal auditors and is mentioned by numerous interviewees, including those in board-led PSAs. A CAE in a single-council agency stated, “it also applies that DG must respect the internal audit and not see it as a threat” (I2020-10-14). An example from a single-council agency shows internal auditors' frustration with this governance form, indicating the control and direction over the work experienced by CAEs.
This is where the DG enters at both positions: the DG sits on the board and as the principal. As an internal auditor, one needs to ask, ‘Why do you not want me to conduct this audit? In what capacity are you making this decision’? This is difficult because if the DG says no, then it means no, because the decision to accept or reject the audit plan is the prerogative of the DG. (I2020-04-24)
As the principal in single-council PSAs, the DG assigns the internal auditor and makes the final decision about the audit plan. The internal auditor is in a unique situation, as inspecting the DG, who holds the highest operational responsibility for the PSA, is naturally a part of internal audits. The CAE must avoid any appearance of bias and demonstrate impartiality towards both the auditees and management. Otherwise, it jeopardises the validity of the IAF. This is a problem because the power granted to DGs in relation to the internal auditor by the Swedish Internal Audit Ordinance (SFS, 2006) structurally places DGs outside the IAF's reach and weakens the auditor's independence.
It is clear that in such a case, you have to try to raise it with the board. However, I had no one to turn to. Therefore, it becomes very dependent on the DG, taking this in a positive way. (I2020-04-15b)
Internal auditors not only rely on the DG in single-council PSAs for the assignment and final decision on the audit plan but also as employees.
You are employed by the DG and cannot be independent from the DG. The point is to have a board and an audit committee and be able to communicate with them. In a single-council agency, one is independent in relation to the organisation but not to the DG; this is a different form of governance. (I2020-05-15b)
Another internal auditor argues that in situations where one is at the mercy of the DG, transcriptions that follow the disciplinary agency of regulation and professional ethics are all that remains to defend one's independence: “One might as well leave” (I2020-05-18b) because fighting is not worth it. Concurrently, it is clear who can fire internal auditors.
According to the Internal Audit Ordinance, neither the board nor the DG can fire me; instead, the Government Disciplinary Board (Statens ansvarsnämnd) can fire me. (I2020-05-13b)
Issues with DGs are not limited to single-council PSAs. The Swedish PSA Ordinance (SFS, 2007a) specifies that a board-led agency's DG should be on its board but cannot be the chairperson or vice-chair. Despite structures safeguarding the internal auditor's independence, DGs' membership in a board-led agency's board may become an obstacle to the CAE, as the DG's presence may be a deterrent enough.
Yes, that is a difficult area. […] I can feel independent of everyone beneath, but I do not want to step in and audit the DG. There goes the limit. In our case, it is a bit difficult because the DG sits on the board, and how should one relate to the DG? (I2020-10-19)
The PSA board depends on the DG for information about operations, which affects its ability to take on responsibility. An interviewee described a situation where the chairperson of the board and the DG were extremely close, and the chairperson prevented the CAE from presenting their report to the board.
Interviewee: I have seen an extremely close symbiosis between the board chairperson and the DG, that is, when ‘things’ happen. It is important that the board chairperson is a professional with high integrity who understands their mission. But it is easy to ally with the DG because they provide information and input.
Interviewer: Do I correctly understand that the board chairperson said that the internal auditor could not come and report?
Interviewee: Yes, the DG said this to the board chairperson. (I2020-04-20b)
In this case, the board chairperson and DG schemed to dismiss the CAE by requiring the internal auditor to abstain from reporting critical findings to the board, arguing that they would handle the matter. The internal auditor transcribed this resistance by drawing on the autonomous role of reporting findings and recommendations to the board, despite the order to abstain. Reporting to the board audit committee is also an internal auditor's task. This indicates how the presence of the DG as a board member can become an obstacle for the CAE. One accommodation used by CAEs is to reject any organisational dependencies on DGs and simply pursue the internal audit mission, as this internal auditor did. While management controls the salary, this can be stressful, especially in single-council PSAs; “… one must be independent and detached, but the financial aspect involves receiving my salary from the agency” (I2020-04-02). Inadequate support from those in charge of governance frequently suggests that the second principle of the TLM is not effectively implemented. In some single-council PSAs, internal auditors face difficulties in discussing their remuneration with the DG. For example, a DG refused to attend a salary meeting with their internal auditor and delegated it to the administrative manager.
I said, ‘The head of staff cannot set my salary because I may have to audit their area’.
[The DG said:] ‘The head of staff has no area.’ ‘Well yes,’ I said, ‘s/he is responsible for the managerial process', which is one of the most important processes, and then the DG turned and said, ‘Oh well’. However, the consequence was that my salary development stopped entirely. (I2020-10-14)
Here, the internal auditor accommodates this resistance by drawing on their title to defend their right to a salary discussion with the DG and to transcribe the CAEs independent standing. Accommodations include utilising a transcription move to relieve the stress caused by organisational dependencies by rethinking both the CAE's personal economic situation and the reach of internal audit. As observed in the aforementioned instance, the CAE refrains from including the DG in their audits owing to the DG's position as a board member. This would also be the case in single-council PSAs, where DGs fulfil the function of the board. The argument entails not only avoiding personal costs for the internal auditor but also safeguarding independent assurance challenged by organisational dependencies. The reframing of the IAF objective reduces the reach of the function but only to uphold its feasibility. However, this creates a divide between internal auditors. An interviewee addressed a colleague's predicament and the subsequent professional debate during a publicised scandal to demonstrate approaches for addressing a challenging situation with a DG:
When the operations do not function appropriately and the board fails to listen, what do you do? Half the profession thought this was self-evident: to bring change to a dysfunctional organisation, one approaches the media, the ministry, or others. The other half believes in loyalty to the employer, and if you cannot fulfil your assignment, you must leave the job. (I2020-04-22)
Whistle-blowing may work as an accommodation for the abuse of power by the DGs, but using the media or reporting to the government is not always viable. In situations that present a CAE with severe breaches and obstacles to the IAF, the easiest way to accommodate the situation is to resign.
I would say that such issues are best dealt with by changing jobs, if I am being blunt. It is a bit like being part of an organisation with a psychopathic boss. Now, I am exaggerating, but without leadership and knowledge, one cannot change that alone. You can do your very best, but I think it is really difficult to turn it around. (I2020-05-06)
With difficulty accommodating this situation in a way that enables the internal audit to remain viable, the internal auditor chooses to use a transcription move to resign and perform their function elsewhere rather than protect their current organisation. Consequently, by relinquishing the IAF within a dysfunctional PSA, such a move enables CAEs to protect the independence of their profession. Internal auditors find themselves vulnerable to their structural position in organisations and the competence and goodwill of DGs and boards. Management that understands and values internal auditing was presented as a precondition for independent reporting and the performance of the IAF.
Good management that has a good outlook on improvements and is open to being audited is an important precondition for delivering independent, fact-based reports. You could experience pressure if you do not have a mature management team, meaning that they only see the short-term and the negative side of displaying deficiencies. (I2020-04-22)
The internal auditor needs management with a positive outlook on identifying deficiencies; that is, management that views the organisation as constantly developing and deficiencies as vehicles for improvement. If management distrusts the IAF and does not embrace this approach, the internal auditor is situated in a difficult position. It is clear that the internal auditor role is isolated and places high demands on the individual, especially if the functional preconditions for this role are not in place.
6. Discussion and conclusions
We began this study by asking how internal auditors adapt their role to manage the situational realities they face and set out to produce an answer based on 29 semi-structured interviews with internal auditors. In line with previous research, we find that ambiguity is a burden for CAEs (Ahmad and Taylor, 2009; Arena and Jeppesen, 2016; Fazli Aghghaleh et al., 2014; Lenz and Sarens, 2012; Page and Spira, 2005; Roussy, 2015; Van Peursem, 2005), not because it directly hampers their independence (Chambers and Odar, 2015; Gustafsson Nordin, 2023; Roussy, 2015; Van Peursem, 2005), but because it engenders resistances to their role that they must accommodate. As noted above, resistance often arises from knowledge gaps stemming from the expectation that internal auditors should perform tasks belonging to the first and second lines, roles that properly fall to managers and controllers. The need to accommodate these resistances is not by accommodating managers, as previous research shows (Roussy, 2013, 2015; Roussy and Rodrigue, 2018), but by defending the boundaries of the internal auditor role from the expectations that arise because managers and other organisational members see internal auditors as competent and trusted advisors who can provide solutions to their problems. Assuming such an advisory role would compromise internal auditors' ability to conduct independent audits, accommodations are necessary to enable internal auditors to continue striving towards their goals. To be clear, it is important to reiterate that accommodation in our case does not simply mean yielding to managers’ expectations but rather taking these into account and identifying accommodations that protect the internal auditor's objectives and independence.
To uphold the integrity of the internal audit process, the CAEs we interviewed engage in three tactics: modelling, safeguarding and augmenting. Modelling (bridging) involves utilising independence as a bridgehead to align the auditor's position with the goal of performing high-quality internal audits. In the face of resistance from agents who may seek to leverage CAEs' competence – potentially integrating internal auditors into the first and second lines of the TLM—internal auditors must perform safeguarding moves (transcriptions) to secure their place in the third line and maintain their independence. Thus, internal auditors may act in tandem with the disciplinary agency of regulation and ethical guidelines by resisting managerial pressure, documenting clear justifications for audit findings to prevent undue influence and reinforcing professional standards. At the same time, augmenting moves (filling) may also come into play. Auditors may perform actions not mandated by regulation that function as a lubricant to maintain good relations and understanding between the internal audit and the organisation. This includes educating organisational members about the role of internal audit and the importance of independence, as well as clarifying the added value that CAEs' recommendations bring to the organisation, which is in line with Van Peursem's (2005) observation that informal communication is central to the independence of internal audit. Together, these modelling, safeguarding and augmenting tactics allow internal auditors to accommodate resistances while securing the conditions necessary for an independent and effective IAF. It is also worth noting that the PSAs where the CAEs that are part of this study have their occupations have not substantially implemented the TLM framework. Despite this, CAEs utilise modelling, safeguarding and augmenting tactics within their confines when their role's objectives and independence are endangered.
In summary, the internal audit role emerges through the play of resistances and three different tactical moves or accommodations by CAEs: (1) modelling or bridging moves are employed to elucidate the role to others, thereby clarifying the appropriate position of the IAF in the TLM; (2) safeguarding moves or transcriptions are used to defend the role when the discipline is under threat, while protecting the future ability to provide independent audits, either internally or elsewhere; and (3) augmenting moves (filling) that establish the value of an independent IAF, capable of providing advisory input for organisational success, derived from their audit work. Here, internal audit also emerges to fulfil a competence development function through pedagogical work that safeguards its independence and educates organisational members about the value of internal audit to organisations.
This study contributes to previous endeavours following Van Peursem (2005), Roussy (2013, 2015), Ferry et al. (2017) and Roussy and Rodrigue (2018), who focus on how internal auditors manage conflicts. Van Peursem (2005) shows that internal auditors, who best overcome the tensions of working with management, do so by maintaining their professional status with the support of both formal and informal communication networks. Through informal communication, most notably, internal auditors work to reach consensus and clarify their role. Similarly, our study shows that internal auditors rely on themselves to strengthen their role through dialogue with auditees. However, our study provides a deeper understanding of the work of internal auditors to accommodate the expectations of organisational members in different ways. We show that they model their accommodations after the TLM to conceptualise the situations in terms of the importance of the function's independence. They augment internal auditing in the eyes of auditees by clarifying the roles of different lines of defence in the process and the value added by their audit-based recommendations. In turn, threats to independence (Ahmad and Taylor, 2009; Roussy, 2013, 2015) are dealt with through safeguarding moves supported by the modelling and augmenting moves described earlier. Thus, the internal audit emerges as a pedagogical function not only through its recommendations but also through the work that internal auditors perform to distinguish between the different lines in the TLM and the importance of doing so to safeguard the IAF and its production of assurance. Hence, by drawing on Pickering's (1995) “mangle” of practice, we demonstrate that independence is not a static attribute but an emergent property, continuously constructed through the dialectic of resistance and accommodation in daily interactions between internal auditors and other organisational actors.
Moreover, we find that the interviewees sidestep the tension between auditing and consulting that previous literature refers to (Ahmad and Taylor, 2009; Chambers and Odar, 2015; Everett and Tremblay, 2014; Norman et al., 2010; Parker and Johnson, 2017; Roussy and Perron, 2018; Roussy, 2013, 2015; Stewart and Subramaniam, 2010; Van Peursem, 2005) by distinguishing between giving advice and offering recommendations. While previous research shows internal auditor bias towards management to the detriment of boards or audit committees (Roussy and Rodrigue, 2018; Roussy, 2013, 2015), thereby weakening internal auditor independence, our results show a deep awareness of independence and its importance not only for the provision of assurance but also for the future of internal audit and its ability to add value to the organisation through audit-based recommendation. This finding, unusual in the affirmation of internal auditors' abilities to maintain their independence, is in line with Ferry et al. (2017), who find that internal auditors are not necessarily colonised by governance rules and managerial influence, and Cantù et al. (2024), who find that they contribute to the quality of internal controls through their audit work. Our results illustrate internal auditors' tactics to make such contributions to the organisation without sacrificing their independence.
In addition, the literature points to a mixed role for both assurance and consulting, with an emphasis on the latter (cf. Abbott et al., 2010; D'Onza et al., 2015; Lenz and Sarens, 2012; Roussy and Brivot, 2016; Roussy, 2013, 2015). From this perspective, the role of internal auditors as advisors to management (Ahmad and Taylor, 2009; Chambers and Odar, 2015; Everett and Tremblay, 2014; Norman et al., 2010; Parker and Johnson, 2017; Roussy and Perron, 2018; Roussy, 2013, 2015; Stewart and Subramaniam, 2010; Van Peursem, 2005) could be reinterpreted to underscore not primarily consultancy work but rather independent and trustworthy internal audit work that includes recommendations, thereby adding value to the organisation. In this sense, the modelling, safeguarding and augmenting tactics that internal auditors utilise in this study can be understood as a negation of the duality and ambiguity of the role. This disambiguation is not merely a matter of deparadoxification to make sense of an impossible task (Gustafsson Nordin, 2023) rather, it produces the conditions of possibility for the emergence of internal audit as an independent practice.
It is important to note that the context of our study and certain differences between contexts may explain the variation in the findings compared with other studies. This is particularly relevant when comparing our study to research on internal audit practice in the Quebec public sector. While we find that internal auditors do not side with management but rather accommodate expectations to safeguard the independence of the IAF, Roussy (2013, 2015) and Roussy and Rodrigue (2018) find that internal auditors in the contexts they study tend to side with management. Following Roussy (2015), this could be explained by the historical development of internal audit in Quebec, where internal auditors initially reported to management and were only later, in the early 2000s, mandated to report to the audit committee. Given the results presented by Roussy (2013, 2015) and Roussy and Rodrigue (2018), the reform has not yet fully established the intended governance function. In contrast, in our case, few PSAs had audit committees and, therefore, no obvious formal communication network that strengthened the independence of the IAF. Nevertheless, our CAEs worked to defend their independence in the governance structures of their PSAs; hence, our findings may also be relevant to countries where both boards and audit committees are rare (cf. Alzeban and Gwilliam, 2014; Nerantzidis et al., 2022). With this we contribute to the literature by examining a European setting, which, as Arena and Jeppesen (2016) note, has been less studied and differs from Anglo-American or Asia-Pacific contexts where public administration tends to be more influenced by regulation. However, studies across different European contexts are needed to further understand the conditions under which internal auditors can maintain their independence and how they do so in practice.
For their insightful comments on earlier versions of this manuscript, the authors are grateful to Peter Skærbæk at the Nordic Accounting Conference (CBS, 2021), Jan Mouritsen and Yuval Millo at the EAA Annual Congress (Bergen, 2022), as well as Karin Jonnergård and Bino Catasús. The authors would also like to thank IIA Sweden and the Academy of Management Control in Government (AES) for the chance to present our results at their seminars. Special thanks go to the joint funding editor, Lee Parker, and the two anonymous reviewers for their valuable guidance and constructive feedback. The authors are indebted to the interviewees for providing us with the opportunity to study their practice. Finally, the authors gratefully acknowledge the financial support provided by the Jan Wallander and Tom Hedelius Foundation (project number P19-0073).
Note
Cantù et al. (2024, p. 9) utilise the concept “maieutic” to illustrate the role of internal auditors to exert helpfulness by giving advice to auditees.

