Summary
- ICANN’s December 2025 committee minutes say a proposed external-assessment interval changed from “five-year” to “periodic”; the Board-adopted July 2026 charter uses the new wording.
- That edit is not evidence that the deadline vanished. ICANN had adopted the Global Internal Audit Standards, and Standard 8.4 still requires an external quality assessment at least once every five years.
- The strongest public candidate for the start of ICANN’s clock is 25 August 2025, when the Risk Committee approved the Internal Audit Function Charter. That would imply a conditional outer date of 25 August 2030, not a published ICANN deadline.
- A small standards-and-assurance register could make the controlling version, adoption act, due date, assessment mode, independence check, result and corrective action visible without releasing confidential audit work.
The number that left the page
Institutional deadlines rarely disappear with a trumpet blast. More often, a number is replaced by a word that sounds sensible enough to escape notice.
The public record shows precisely that transition in ICANN’s internal-audit oversight. Minutes from the Board Risk Committee’s meeting on 8 December 2025 describe a proposed revision to the committee charter. They list four changes. Sections would be reordered. Internal-audit language would be aligned with professional standards. Responsibilities would be made consistent with actual process. And the timing requirement for assessment of internal-audit activities would change from “five-year” to “simply periodic.”
The Board later adopted the revision. The current charter approved on 20 July 2026 says the committee must ensure that external assessments of internal-audit activities are conducted periodically, in accordance with professional standards.
Read in isolation, the sequence looks like dilution. Five years is calculable. Periodic is elastic. A date can be missed; an adjective can be explained.
But isolation is exactly the wrong way to read an incorporated rule. The charter does not say assessment will occur whenever the committee feels like it. It points outward to professional standards. The question therefore becomes: which standard, which version, adopted when, and what does it require?
The answer changes the story. The number left the charter, but it remained in the rule to which the charter points.
Two charters, two different jobs
The first necessary distinction is between the Board Risk Committee charter and the Internal Audit Function Charter.
The committee charter defines what a Board committee may oversee, approve, receive and recommend. The function charter defines the mandate, independence, reporting line and operating basis of the internal-audit function itself. The names are similar enough to invite confusion, but they do different constitutional work.
The Board’s 13 March 2025 resolution made internal audit a new area of Risk Committee oversight. ICANN said growth in size and complexity justified an internal-audit function and that the Risk Committee, rather than the financial Audit Committee, was best placed to oversee work that could extend beyond financial statements and controls.
The March 2025 committee charter reflects that first arrangement. The committee would recommend the selection of internal auditors to the Board. For outsourced work, it would review provider performance, qualifications and independence and recommend retention or dismissal decisions. It would review the function’s independence and authority, proposed scope, plans and budgets, receive findings and progress reports, and promote continuous improvement.
That adopted charter did not contain a five-year external-assessment clause. This matters. The December minute describes a change inside a later proposed revision; it does not prove that ICANN repealed a five-year clause that had already appeared in the March charter. The honest chronology is narrower: a draft introduced or carried a five-year timing rule, the committee changed that draft to periodic language, and the Board adopted periodic language in July 2026.
The missing redline prevents a more dramatic claim. It does not prevent analysis of the system that emerged.
The standard behind “professional standards”
ICANN’s own minutes identify the external rule.
At the Risk Committee meeting on 30 June 2025, staff presented the proposed Internal Audit Function Charter. The minutes say it covered purpose, mission, authority, responsibility, independence, reporting relationships, scope and conformance to the Global Audit Standards. They also say the Internal Audit Manual and Methodology used the Global Internal Audit Standards and other leading frameworks.
On 25 August 2025, after revisions and management feedback, the committee approved that Function Charter. It also approved the organization’s recommendation for lead and standby service providers and approved the methodology’s overview and structure.
The relevant professional text is the Institute of Internal Auditors’ Global Internal Audit Standards, issued in 2024 and effective from 9 January 2025. Standard 8.4 is not vague. The chief audit executive must develop a plan for an external quality assessment and discuss it with the Board. The assessment must occur at least once every five years. It must be performed by a qualified, independent assessor or assessment team, although a self-assessment with independent validation can satisfy the requirement.
The standard also turns the Board into more than a recipient of a final badge. Its essential conditions include discussing the plan, helping determine scope and frequency, approving the plan, receiving the complete result directly, approving action plans for deficiencies and monitoring their completion.
So “periodic” has two layers. At the ICANN-charter layer, it avoids fixing a number. At the incorporated-standard layer, the outside interval remains five years. Either layer alone is incomplete. Together they create a real obligation—and a public legibility problem.
When does the clock begin?
A five-year interval is useful only if its first day is knowable.
The IIA’s quality-assurance guidance says the cycle begins when the internal-audit function formally adopts the Standards. It points to committee minutes, charter updates and conformance language as evidence of that adoption.
ICANN’s public chronology gives a strong candidate. On 30 June 2025, the Function Charter was still a proposal and the committee requested revisions. On 25 August, the committee approved it. The earlier minutes had already said that the charter contained conformance to the Global Audit Standards. If approval of that document was formal adoption for Standard 8.4, the five-year outer date would be 25 August 2030—unless a completed external assessment later reset the cycle.
That calculation is a conditional inference, not an ICANN announcement. The public package examined for this Article does not include the complete approved Function Charter. It does not include a standards-adoption register. It does not publish an external-quality-assessment plan or a resolution naming a due date. A different formal adoption act, an earlier applicable assessment or a later reset could alter the answer.
This is precisely why the clock should not live only in an analyst’s reconstruction. When an institution incorporates a dynamic standard, it also assumes a recordkeeping duty. Someone must preserve the version, the adoption event and every later event that changes the calculation.
A timing edit inside a larger transfer of responsibility
The July 2026 charter did more than replace five years with periodic.
It changed how the Risk Committee participates in internal audit. The 2025 text had the committee recommend internal-auditor selection to the Board and recommend decisions on an outsourced provider’s retention or dismissal. The 2026 text says the committee reviews and approves selection or retention of outsourced internal-audit service providers based on recommendations from the Head of Internal Audit. It also says the committee reviews and approves proposed scope, plans and associated budgets under professional standards and a risk-based approach.
The reporting surface became richer. The committee is to receive completed-audit findings and explanations for significant deviations from the audit plan. It is also to receive reporting on significant risk exposures, control issues, governance concerns and the state of management corrective actions.
The December minutes say the committee discussed wording to clarify that the Board retains ultimate approval authority for items recommended to it. The adopted charter makes that boundary explicit for overall risk appetite: the committee makes recommendations to the Board for approval. But the internal-audit clauses use direct committee approval verbs.
That does not prove that the Board abandoned residual corporate authority. It does show why a reader needs to know which acts belong to the committee, which belong to the Head of Internal Audit, which remain with management and which require the full Board. A standards register should not become a substitute constitution. It should name the act, actor and authority behind each state change.
The strongest defence of the new wording
There is a good reason not to engrave every professional interval into a committee charter.
External standards change. A charter that repeats a number can become stale when the professional rule evolves. “Periodically, in accordance with professional standards” can preserve flexibility, allow more frequent assessment when risk rises, and import a richer set of safeguards than a date alone. Standard 8.4 contains qualifications, independence tests, Board engagement, direct result receipt and remediation duties. Reducing it to “once every five years” would omit most of its governance value.
The new wording can therefore be stronger than a naked calendar rule. It can bind ICANN to the standard as a living package rather than to one copied sentence.
But a living reference has a price: version discipline. If the external body revises its text, ICANN must know whether adoption is automatic or requires a new internal act. If the standard preserves a five-year floor, ICANN must preserve the date from which that floor is calculated. If a self-assessment with independent validation is chosen instead of a full external assessment, the decision and rationale must remain attributable. Flexibility without lineage becomes discretion by obscurity.
The strongest defence therefore supports the Article’s proposal. It does not defeat it.
What the public record can and cannot prove
The Board’s 20 July 2026 resolution says the revisions align the charter with current governance requirements and actual committee practices. The Board Governance Committee’s June minutes show that it reviewed the proposal and recommended approval. ICANN’s current committee page now correctly identifies the July charter as current and the March 2025 version as superseded.
The operating function is also moving. At the Risk Committee meeting on 29 May 2026, staff said the refreshed risk register would feed the internal-audit universe, risk-based audit plan and multiyear planning. Final discussions about outsourced-provider arrangements were still under way.
These facts support a picture of an institution building an audit function. They do not establish a missed deadline, a defective provider or a neglected assessment. The first plausible five-year outer date remains years away. The absence of a public plan in the checked material does not prove that no internal plan exists.
The public defect is narrower. A reader cannot move from “periodic” to an authoritative due date without stitching together several pages and making at least one inference. The institution can remove that inference at negligible cost.
A receipt for an incorporated obligation
The answer is not to publish audit workpapers. It is not to disclose exploitable control weaknesses, privileged advice, employee data or every disputed finding. It is not to invent another review body.
ICANN needs a small standards-and-assurance register.
For each incorporated obligation, the register should name the standard-setting body, exact standard and clause, version, issue date and effective date. It should link the internal adoption instrument, the adopting body and the date that starts the interval. It should state the computed outer due date and any shorter internal target.
For the assessment itself, the record should identify whether ICANN chose a full external assessment or a self-assessment with independent validation. It should record approved scope and frequency, the authority that selected the assessor, the qualification requirement, the independence and conflict review, and the date on which the committee or Board approved the plan.
After completion, the public record needs only a bounded disposition: completion date, assessment mode, the body that received the result, a conformance rating or carefully scoped conclusion where publishable, and the existence, owner, deadline and closure state of corrective actions. Sensitive substance can remain protected.
Finally, the register must keep history. A new standards edition, a revised Function Charter, a completed assessment or a change in assessment mode can reset the clock. The old calculation should not be overwritten as if it never governed.
This is not administrative decoration. It is the difference between an obligation that can be audited and an assurance phrase that can only be trusted.
The clock is a chain of authority
The date is the visible end of a longer chain.
The standards body defines the minimum. ICANN formally adopts it. The Head of Internal Audit develops a plan. The committee and Board perform the acts assigned to them. A qualified independent assessor challenges the function. Management answers deficiencies. The committee monitors closure. A later assessment or standards version changes the next due date.
Break any link and the calendar becomes misleading. A date without an adopted standard is arbitrary. A standard without an adoption date is incalculable. An assessment without independence is self-description. A result without corrective-action custody is a ceremonial report. A new assessment that erases the previous cycle destroys institutional memory.
This is the reality layer beneath “periodic.” The word can remain. The chain must become visible.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
