Assurance Versus Advisory Engagement Objectives
In CIA Part 2, engagement planning starts with clear objectives, and their nature depends on whether the engagement provides assurance or advisory (consulting) services. Under the IIA Global Internal Audit Standards, internal auditors must establish engagement objectives and scope that reflect the … In CIA Part 2, engagement planning starts with clear objectives, and their nature depends on whether the engagement provides assurance or advisory (consulting) services. Under the IIA Global Internal Audit Standards, internal auditors must establish engagement objectives and scope that reflect the engagement's purpose, the risks identified, and stakeholder needs. Assurance engagement objectives focus on giving an objective, independent evaluation of governance, risk management, and control processes. They usually involve three parties: the process owner responsible for the area, the internal auditor performing the evaluation, and the users of the results, such as senior management and the board. Objectives are set mainly by the internal audit function and are based on a preliminary risk assessment of the activity under review. They typically address whether controls are adequately designed and operating effectively, whether risks are managed within risk appetite, and whether operations comply with laws, policies, and contracts. Auditors must identify suitable evaluation criteria. If management's criteria are inadequate, the auditor should work with management to develop appropriate ones. Results lead to formal conclusions or opinions communicated to stakeholders. Advisory engagement objectives aim to add value and improve the organization's operations at the request of management. These engagements generally involve two parties: the internal auditor and the client who requests the service. The nature and scope are agreed with the client, and objectives may include facilitation, training, process design advice, or reviewing a planned system implementation. Objectives should still address governance, risk, and control to the extent agreed, and must remain consistent with the organization's values, strategies, and objectives. Auditors should not assume management responsibilities, which protects their objectivity. Key exam distinctions are who sets the objectives (internal audit versus agreement with the client), the number of parties involved, and the output (a formal assurance conclusion versus advice and recommendations). If significant risks are discovered during an advisory engagement, they should be communicated to management and may warrant future assurance work.
Assurance Versus Advisory Engagement Objectives: A Complete CIA Part 2 Guide
Overview
Every internal audit engagement starts with a clear statement of what it is meant to achieve. In CIA Part 2 (Practice of Internal Auditing), candidates must be able to tell assurance engagement objectives apart from advisory (consulting) engagement objectives. They differ in four main ways:
• Who sets them
• What they must cover
• How criteria are used
• How results are reported
This topic sits within engagement planning. It is tested through scenario questions that ask what the internal auditor should do, what is most appropriate, or what is required by the Standards.
1. Why This Topic Is Important
• Objectives drive everything else. They determine the following, so a poorly framed objective leads to wasted effort, missed risks, or reports that do not meet stakeholder needs:
- Scope
- Criteria
- Work program
- Resources
- Testing approach
- Form of the final communication
• It protects independence and objectivity. Advisory work must not drift into management decision-making. Assurance work must not be shaped by the client so that it hides risk.
• It manages stakeholder expectations. An assurance engagement leads to an independent conclusion or opinion. An advisory engagement leads to advice, facilitation, or recommendations. Mixing the two causes confusion about what the board and senior management can rely on.
• It is a core Standards requirement. The Global Internal Audit Standards (Domain IV, Principle 13, Plan Engagements Effectively) require internal auditors to establish engagement objectives and scope. Standard 13.3 sets this out, building on the risk assessment in 13.2 and supported by evaluation criteria in 13.4. Former IPPF Standard 2210 contained separate 'A' (assurance) and 'C' (consulting) implementation requirements, and those distinctions are still examined.
• It is heavily tested. Questions often present a client request and ask how the objectives should be set. They also ask what happens when an advisory engagement uncovers a significant risk.
2. What It Is: Key Definitions
Assurance services: An objective examination of evidence that gives an independent assessment and conclusions about governance, risk management, and control processes. Examples include:
• Financial, compliance, operational, and IT audits
• Performance audits
• Some due diligence reviews
Assurance typically involves three parties:
• The person or group directly involved with the activity (the process owner)
• The internal auditor making the assessment
• The user relying on the assessment, such as the board or senior management
Advisory (consulting) services: Advice and related client services whose nature and scope are agreed with the client. They are intended to add value and improve governance, risk management, and control processes, without the internal auditor assuming management responsibility. Examples include:
• Advice on designing a new process or system
• Facilitating risk or control self-assessment workshops
• Training
• Benchmarking
• Pre-implementation reviews
• Readiness assessments
Advisory work typically involves two parties: the internal auditor and the engagement client.
Engagement objectives: Broad statements that set out what the engagement is intended to accomplish. They are linked to the risks and processes under review and are refined by the scope, which covers boundaries, period, locations, and activities.
3. How It Works: Assurance Engagement Objectives
Who sets them: The internal auditor sets them, approved within the internal audit function. Management and other stakeholders are consulted and their input considered. However, the internal auditor keeps responsibility so that the assessment stays independent.
What they must reflect:
• The preliminary engagement risk assessment of the activity under review. Objectives should address the significant risks identified (former 2210.A1).
• The probability of significant errors, fraud, noncompliance, and other exposures (former 2210.A2). Internal auditors must consider these when developing objectives.
• Adequate criteria to evaluate governance, risk management, and controls (former 2210.A3; now Standard 13.4). Examples:
- Policies and procedures
- Laws and regulations
- Contracts
- Industry standards
- Frameworks such as COSO
- Key performance indicators
What to do about criteria:
• If management's criteria are adequate, the internal auditor uses them.
• If they are inadequate, the internal auditor identifies appropriate criteria, generally through discussion with management and/or the board. The auditor does not simply invent criteria alone.
Output: Conclusions or an overall opinion on whether controls are adequately designed and operating effectively, plus findings and recommendations. The board and senior management rely on these conclusions.
Example assurance objectives:
• 'Determine whether controls over vendor master file changes are designed adequately and operating effectively to prevent unauthorized or fictitious vendors.'
• 'Evaluate compliance with the organization's data privacy policy and applicable regulations.'
4. How It Works: Advisory Engagement Objectives
Who sets them: The internal auditor and the client agree on the objectives. The client's needs largely shape the nature and scope, but the agreement should be documented, for example in an engagement letter or terms of reference.
What they must reflect:
• Objectives must address governance, risk management, and control processes to the extent agreed upon with the client (former 2210.C1).
• Objectives must be consistent with the organization's values, strategies, and objectives (former 2210.C2). Internal audit should not accept an advisory engagement that works against organizational interests.
• Scope must be sufficient to achieve the agreed objectives. If the auditor develops reservations about scope during the engagement, these should be discussed with the client to decide whether to continue (former 2220.C1).
• Internal auditors must stay alert to significant risks and control issues found during advisory work and address them consistent with the agreed objectives (former 2220.C2). Significant issues may need to be communicated to senior management and the board.
Criteria: Formal evaluation criteria are not always central to advisory work. Where the agreed objectives involve evaluating something, relevant criteria should be identified. Under the Global Internal Audit Standards, criteria are identified as appropriate to the engagement, and they are essential for assurance.
Output: Advice, recommendations, facilitation results, or training. The form and content of the communication vary according to the agreement with the client.
The key limit: The internal auditor must not take on management responsibilities. Examples of what the auditor must not do:
• Make decisions
• Own the process
• Approve transactions
• Implement controls
Management stays responsible for accepting and implementing advice.
Example advisory objectives:
• 'Advise the project team on control considerations for the design of the new ERP purchasing module.'
• 'Facilitate a risk assessment workshop with the operations team to identify and prioritize key risks.'
5. Side-by-Side Comparison
Purpose
• Assurance: independent assessment and conclusion
• Advisory: adding value through advice and improvement
Who determines objectives
• Assurance: the internal auditor, after considering stakeholder input
• Advisory: agreed with the client
Parties
• Assurance: three (process owner, auditor, user)
• Advisory: two (auditor, client)
Basis for objectives
• Assurance: preliminary risk assessment, plus the likelihood of significant errors, fraud, and noncompliance
• Advisory: client needs, consistent with organizational values, strategies, and objectives
Criteria
• Assurance: adequate criteria are required; if they are inadequate, the auditor works with management or the board to develop them
• Advisory: used as relevant to the agreed objectives
Scope
• Assurance: set by the auditor and must be sufficient to achieve the objectives
• Advisory: agreed with the client; reservations are discussed with the client
Reporting
• Assurance: conclusions or opinion to management and the board
• Advisory: form agreed with the client; significant risks are escalated as appropriate
Independence and objectivity
• Required for both.
• In advisory work, the auditor must not assume management responsibility.
6. Special Situations Frequently Tested
Significant risk found during an advisory engagement
The auditor should not ignore it simply because it falls outside the agreed scope.
• Communicate it to management.
• If it is significant, communicate it to senior management and/or the board.
• A separate assurance engagement may be planned.
Client asks to limit or shape the objectives of an assurance engagement
The auditor considers the request, but objectives and scope remain the auditor's responsibility. A scope limitation that impairs the ability to achieve objectives must be communicated, and significant limitations should go to the board.
Blended engagements
Some engagements combine assurance and advisory elements. Objectives for each component should be clearly defined so stakeholders know which parts provide assurance.
Changing nature midway
If an advisory engagement turns into one requiring an assurance conclusion, objectives, scope, and communication need to be re-established. In practice, this is often done as a separate engagement.
Objectivity across engagement types
Internal auditors may provide advisory services on operations they were previously responsible for. However, they must refrain from providing assurance on activities they were responsible for within the previous 12 months. They should also be cautious about assuring areas where their prior advisory work could impair objectivity.
Declining advisory work
The chief audit executive may decline an advisory engagement in either of these cases:
• It is not consistent with organizational objectives.
• It would impair independence or objectivity, or exceeds internal audit competence.
7. Step-by-Step Approach to Setting Objectives
Assurance
• Understand the activity, its objectives, and its context.
• Perform the preliminary risk assessment.
• Consider the likelihood of significant errors, fraud, noncompliance, and other exposures.
• Identify and assess the adequacy of criteria.
• Draft objectives linked to significant risks.
• Set scope.
• Document the objectives and obtain approval.
Advisory
• Understand the client's request and needs.
• Confirm the work aligns with organizational values, strategies, and objectives.
• Assess impacts on independence, objectivity, and competence.
• Agree on objectives, scope, responsibilities, and deliverables with the client.
• Document the agreement.
• Stay alert to significant risks while performing the work.
Exam Tips: Answering Questions on Assurance Versus Advisory Engagement Objectives
1. Identify the engagement type first. Look for key words.
• Signals of assurance:
- 'Independent assessment'
- 'Opinion'
- 'Evaluate effectiveness'
- 'Compliance audit'
- 'The board wants comfort'
• Signals of advisory:
- 'Management requested advice'
- 'Facilitate'
- 'Help design'
- 'Training'
- 'Agreed with the client'
2. Ask 'Who decides?'
• Assurance: the internal auditor determines objectives, with stakeholder input.
• Advisory: objectives are agreed with the client.
A common distractor says management 'determines' assurance objectives. This is usually wrong.
3. Link assurance objectives to risk. The best answer for assurance usually mentions:
• The preliminary risk assessment
• Significant risks
• The probability of errors, fraud, or noncompliance
Answers based only on management preference, last year's program, or convenience are usually wrong.
4. Remember the criteria rule.
• If criteria are inadequate in an assurance engagement, the correct action is to work with management and/or the board to identify or develop appropriate criteria.
• Wrong answers include proceeding without criteria, or using the auditor's personal judgment alone without consultation.
5. Watch for management responsibility traps. In advisory scenarios, reject any option where the auditor:
• Makes the decision
• Implements the control
• Approves the process
• Owns the outcome
The auditor advises; management decides.
6. Out-of-scope significant risk in advisory work. The correct answer is to communicate it to the appropriate level, with significant matters going to senior management and the board. Ignoring it 'because it is outside the agreed scope' is wrong.
7. Organizational alignment. If an advisory request conflicts with organizational values, strategy, or objectives, the best answer is usually to decline the engagement or renegotiate its objectives.
8. Use the 'most appropriate' or 'first' lens. Many questions have several plausible answers. Choose the one that is required by the Standards and comes first in sequence. For example, for both engagement types, the risk assessment and understanding of the activity come before writing objectives.
9. Do not confuse objectives with scope or procedures.
• Objectives say what the engagement will achieve.
• Scope says where, when, and how much.
• The work program says how the work will be done.
If an option describes a test step, it is not an objective.
10. Know old and new terminology. The current exam aligns with the Global Internal Audit Standards. These use 'advisory services' and place planning requirements in Principle 13. You may still see 'consulting' and the former 2210.A/2210.C references in study materials, and both describe the same concepts.
Practice Questions
Q1. During an advisory engagement to help design a new procurement workflow, the internal auditor discovers that a manager can create and pay vendors without review. What should the auditor do?
Answer: Communicate the significant control issue to management and, given its significance, to senior management and/or the board. Advisory work does not excuse ignoring significant risks.
Q2. In planning an assurance engagement, the auditor finds that management has no defined criteria for evaluating the effectiveness of a process. What is the most appropriate action?
Answer: Work with management and/or the board to identify appropriate evaluation criteria before proceeding.
Q3. Which statement best describes how objectives are set for an advisory engagement?
Answer: They are agreed with the client. They address governance, risk management, and control to the extent agreed, and they are consistent with the organization's values, strategies, and objectives.
Q4. Which factor must the internal auditor consider when developing assurance engagement objectives?
Answer: The probability of significant errors, fraud, noncompliance, and other exposures, based on the preliminary risk assessment.
Summary
Assurance objectives
• Set by the internal auditor
• Driven by risk
• Sensitive to fraud and noncompliance
• Anchored in adequate criteria
• Aimed at an independent conclusion
Advisory objectives
• Agreed with the client
• Aligned with organizational values and strategy
• Focused on adding value
• Limited by the rule that internal auditors never assume management responsibility
Master these distinctions and the special situations above, and you will be well prepared for this area of CIA Part 2.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!