Internal audit software in Indonesia does not operate in a regulatory vacuum. Banks must comply with OJK rules, BUMN with Minister of SOEs regulations, government agencies with the government's internal control system, and almost all organizations refer to global internal audit professional standards.
This article maps the main regulations and standards relevant to the internal audit function in Indonesia, and how each is typically translated into audit software feature requirements.
Notes: This article summarizes the substance of the regulations for educational purposes, not as legal advice or official compliance guidance. Always refer to the official regulation text and consult your organization's legal or compliance department for specific implementation.

POJK No. 1/POJK.03/2019: Internal Audit Function at Commercial Banks
This Financial Services Authority (OJK) regulation governs the implementation of the internal audit function at commercial banks, including the organizational structure of the Internal Audit Work Unit (SKAI), the independence of the audit function from operational units, and the obligation to prepare an internal audit charter.
Implications for audit software: the system needs to support a reporting-independent organizational structure, an audit trail that cannot be unilaterally altered, and documentation of the charter and independence of the audit function that can be shown to OJK examiners.
Minister of SOEs Regulation No. PER-2/MBU/03/2023: SPI and Internal Control at BUMN
Among other things, this regulation requires BUMN boards of directors to establish an Internal Supervisory Unit (SPI) with broad authority, including access to information, coordination with external auditors, and monitoring follow-up on improvement recommendations.
Implications for audit software: the system needs to support monitoring of findings follow-up through to completion, the ability to show SPI's access coverage across all units, and ideally support for consolidating data across subsidiaries for BUMN with a holding structure. This is discussed further in audit software for holding companies and subsidiaries.
Government Regulation No. 60 of 2008: Government Internal Control System (SPIP)
This Government Regulation serves as the umbrella for the internal control system within central and regional government, with five main elements: control environment, risk assessment, control activities, information and communication, and monitoring. The Government Internal Supervisory Apparatus (APIP) carries out the internal audit function in government agencies based on this framework.
Implications for audit software: the system used by APIP should ideally be able to map findings to the five SPIP elements, support risk assessment as the basis for annual audit planning, and produce reports formatted to meet reporting needs for agency leadership and BPKP.
Global Internal Audit Standards (GIAS) 2024
The Institute of Internal Auditors (IIA) Global issued the Global Internal Audit Standards effective January 2025, replacing the previous International Professional Practices Framework (IPPF). This standard serves as the global reference for the internal audit profession, including for QIA- and CIA-certified practitioners in Indonesia.
Implications for audit software: the system should ideally support documentation of auditor independence and objectivity, quality assurance over audit work, and reporting on internal audit function performance to the board or audit committee in line with GIAS principles.
ISO 19011:2018: Management System Audit Guidelines
ISO 19011 provides general guidance for planning and conducting management system audits, including quality (ISO 9001), environmental (ISO 14001), and occupational health and safety (ISO 45001) audits. This standard is often used as a reference for combined audits covering several management systems at once.
Implications for audit software: the system should ideally support multi-standard audit programs, checklists that can be mapped to specific ISO clauses, and the ability to record non-conformities along with their corrective actions.
Summary Table: Mapping Regulations to Features
| Regulation/Standard | Applies to | Key Feature Requirements |
|---|---|---|
| POJK 1/POJK.03/2019 | Commercial banks | Reporting independence, audit trail, audit charter documentation |
| Permen BUMN PER-2/MBU/03/2023 | BUMN and subsidiaries | Findings follow-up, SPI access coverage, holding-level data consolidation |
| PP 60/2008 (SPIP) | Central and regional government agencies | Mapping findings to the 5 SPIP elements, risk assessment, APIP report format |
| Global Internal Audit Standards 2024 | All internal audit functions (professional reference) | Independence documentation, quality assurance, reporting to the audit committee |
| ISO 19011:2018 | Organizations with ISO management systems | Multi-standard audit programs, clause-based checklists, non-conformity recording |
FAQ About Internal Audit Regulations in Indonesia
Must all companies in Indonesia have an internal audit function?
Not all are explicitly required to, but tightly regulated sectors such as banking (POJK) and BUMN (Minister of SOEs regulation) have explicit obligations to establish an internal audit function or SPI.
What is the difference between SPI, SKAI, and APIP?
SKAI (Internal Audit Work Unit) is the term used in the banking sector under POJK, SPI (Internal Supervisory Unit) is used within BUMN, while APIP (Government Internal Supervisory Apparatus) is the term for the internal audit function in government agencies. All three carry out the internal audit function under different regulatory frameworks.
Does audit software automatically make an organization compliant with regulations?
Not automatically. Audit software is a tool that helps run and document the audit process in line with the regulatory framework, but compliance still depends on how the organization designs and runs that process.
Does GIAS 2024 replace Indonesia's internal audit standards?
GIAS is a global professional standard from IIA, not an Indonesian government regulation. It serves as a best-practice reference that is typically adopted alongside, not in place of, the sectoral regulations in force in Indonesia.
See also:
- Internal Audit and Fraud Statistics in Indonesia
- RFP Audit Management Software Checklist: 40 Criteria + Template
Methodology and Sources
This regulatory summary is compiled from official regulation texts and publications from relevant institutions (OJK, Ministry of SOEs, IIA Global, ISO) as of September 2026. Regulations may be revised at any time; always verify with official sources before making compliance decisions.
Conclusion
Understanding the relevant regulations helps audit teams choose and configure audit software that genuinely supports compliance, not just digitally records data.
If you would like to discuss how Audithink supports your organization's specific regulatory needs, schedule a demo with our team.



