Using Prior Audit Reports and Other Assurance Work in Planning
In CIA Part 2, using prior audit reports and other assurance work is a key step in the preliminary survey phase of engagement planning. It helps internal auditors understand the area under review, focus on significant risks, and avoid unnecessary duplication of effort. Prior internal audit reports… In CIA Part 2, using prior audit reports and other assurance work is a key step in the preliminary survey phase of engagement planning. It helps internal auditors understand the area under review, focus on significant risks, and avoid unnecessary duplication of effort. Prior internal audit reports and workpapers show past engagement objectives, scope, findings, root causes, ratings, and management action plans. Reviewing them helps auditors identify recurring control weaknesses, high-risk processes, and areas where conditions may have changed. Auditors should also check the status of earlier recommendations. Open, overdue, or repeat findings may indicate a weak control environment or management's acceptance of risk, and they often justify expanded testing. Prior workpapers can also reveal useful data sources, key contacts, and testing approaches, but auditors must confirm that this information is still current. Other assurance work may come from external auditors, regulators, compliance, risk management, quality assurance, information security, or other second-line functions. Under the Global Internal Audit Standards, particularly the requirements on coordination and reliance, the chief audit executive should coordinate with these providers to achieve appropriate coverage and reduce duplication. Before relying on their work, internal auditors must evaluate the provider's competence, objectivity, and due professional care. They should also consider the scope, objectives, methodology, timing, and evidence behind the work. Even when reliance is appropriate, internal audit remains responsible for its own conclusions and must document the basis for its reliance. In practice, these sources help auditors refine the engagement objectives, scope, risk assessment, resource allocation, and work program. For example, if external auditors recently tested financial reporting controls, internal audit might rely on that testing and focus on operational or compliance risks instead. Auditors should remember that prior results do not guarantee current effectiveness. Changes in systems, personnel, regulations, or processes may make older conclusions outdated, so professional skepticism remains essential.
Using Prior Audit Reports and Other Assurance Work in Engagement Planning (CIA Part 2)
Overview
When internal auditors plan an engagement, they rarely start from a blank page. Prior internal audit reports, external audit findings, regulatory examinations, second-line reviews (risk management, compliance, quality), and third-party assurance reports (such as SOC 1 and SOC 2 reports) all contain information about the area under review. CIA Part 2 tests whether you know how to use this information properly during engagement planning. Using it well is efficient. Relying on it blindly is a professional failure.
Why It Is Important
1. Efficiency and avoiding duplication. The Global Internal Audit Standards (2024) expect the chief audit executive to coordinate with other internal and external assurance providers. The goals are to reduce duplicated effort and to limit audit fatigue for management. Knowing what has already been tested helps the auditor focus resources where they add the most value.
2. Risk-based focus. Prior reports show areas that have had control weaknesses before. Repeat findings, high-rated issues, and unresolved actions point to elevated risk. That risk should shape the engagement objectives and scope.
3. Follow-up responsibilities. Internal audit must monitor whether management has implemented agreed corrective actions. It must also confirm whether management has accepted the risk of not acting. Prior reports are the starting point for this work.
4. Understanding context. Prior work shows how the process, systems, key personnel, and control environment have changed. It also shows how management has responded to past recommendations.
5. Professional due care. The Standards require auditors to gather sufficient information to understand the activity under review. Ignoring available assurance work could mean missing known risks.
What It Is
During engagement planning, the auditor performs a preliminary survey or background review. Typical sources include:
- Prior internal audit engagement reports and working papers: findings, ratings, recommendations, action plans, and the scope and limitations of the earlier work.
- Follow-up records: the status of open and closed issues.
- External auditor reports and management letters: internal control deficiencies identified during the financial statement audit.
- Regulatory examination reports: compliance findings and required remediation.
- Second-line function reports: risk management, compliance, information security, health and safety, and quality assurance reviews.
- Third-party assurance reports: SOC 1 and SOC 2 Type I or Type II reports for outsourced service providers, ISO certifications, and consultant reviews.
- Management self-assessments: control self-assessment (CSA) results and risk registers.
The key concept is reliance. The auditor may rely on the work of other assurance providers. To decide how much, the auditor must first evaluate that work. Even when relying on others, internal audit keeps full responsibility for its own conclusions and opinions.
How It Works: The Planning Process
Step 1: Gather prior work. Collect relevant reports and working papers early in planning. This is usually part of the preliminary survey and the initial understanding of the area.
Step 2: Analyze prior findings. Ask the following questions:
- What was found?
- How severe was it?
- Was it a repeat finding?
- What actions did management agree to, and by when?
- Has the process, system, or management team changed since then?
Step 3: Determine the status of corrective actions.
- Check whether issues were closed, verified, or are still open.
- Overdue or high-risk open issues often go into the engagement scope.
- Where management has accepted a risk the CAE believes is beyond the organization's risk appetite, the CAE escalates the matter to senior management and, if needed, the board.
Step 4: Evaluate other assurance providers before relying on them. Consider these factors:
- Independence and objectivity: Is the provider free from conflicts? Do they report to the function they assessed? An external regulator or independent CPA is generally more objective than a first-line self-assessment.
- Competence: Do they hold relevant qualifications, experience, and technical expertise?
- Scope and objectives: Did their work cover the same risks, controls, locations, and period?
- Methodology and due care: Were their sampling, testing, and documentation adequate?
- Timeliness: Is the work recent enough to be relevant? Older work carries more risk.
- Evidence quality: Can internal audit review their working papers? Are the conclusions supported?
Step 5: Decide the degree of reliance. The options form a spectrum:
- Full reliance: rare. It requires high confidence and close alignment of scope and timing.
- Partial reliance: rely on some areas or on the risk assessment, and perform limited re-performance or additional testing.
- No reliance: use the work only as background information.
Step 6: Document and integrate. Record the following in the engagement work program and planning memo:
- which work was relied on;
- the basis for that reliance;
- how the reliance affected objectives, scope, and testing.
Step 7: Communicate. Where appropriate, disclose reliance on other providers in the engagement communication. Remember that responsibility is never transferred.
Special Case: SOC Reports
When processes are outsourced, internal auditors often use SOC reports. Key points:
- Type I covers the design of controls at a point in time.
- Type II covers design and operating effectiveness over a period. It is generally more useful for reliance.
- Check the opinion (unqualified or modified), noted exceptions, the period covered, and any carve-outs of subservice organizations.
- Check the complementary user entity controls. The user organization must have these controls in place for the provider's controls to be effective, and internal audit may need to test them internally.
- If the report period leaves a gap, consider a bridge letter.
Common Pitfalls
- Assuming a closed issue is truly fixed without checking.
- Copying the prior scope without reassessing current risk.
- Relying on second-line or management reports without evaluating their objectivity.
- Using outdated reports after significant changes.
- Treating another provider's conclusion as internal audit's own opinion without sufficient basis.
Exam Tips: Answering Questions on Using Prior Audit Reports and Other Assurance Work in Planning
1. Evaluate before relying. If a question asks what the auditor should do first before relying on another provider's work, look for the answer about assessing the provider's competence, objectivity, and the scope or quality of the work. Reject answers that accept the conclusions outright.
2. Responsibility is never transferred. Any option saying internal audit is no longer responsible because others performed the work is wrong. The CAE retains responsibility for conclusions.
3. Rank objectivity correctly. Independent external parties (regulators, external auditors) usually rank highest. Second-line functions come next. First-line management self-assessments are generally least objective. Choose the most objective source when a question asks which work is most reliable.
4. Prior findings drive scope. When a question describes repeat findings or overdue action plans, the best answer usually includes them in the current engagement scope or raises the assessed risk.
5. Do not just repeat the prior audit. Answers suggesting the auditor simply reuse last year's program are traps. Planning must reflect current risks, changes, and objectives.
6. Check timeliness and change. If the scenario mentions a new system, reorganization, or management turnover since the last review, reliance on prior work should decrease.
7. Know the SOC report distinctions. Type II is preferred for operating effectiveness. Complementary user entity controls must be tested at the user organization. Carve-outs mean the subservice provider is not covered by the report.
8. Understand the purpose of coordination. Coordination exists to ensure proper coverage and minimize duplication. It does not let internal audit skip work it lacks a basis for skipping.
9. Identify the correct response to accepted risk. If management accepted a risk the CAE believes exceeds the organization's risk appetite, the correct answer is to discuss it with senior management. If the matter is unresolved, it goes to the board. Do not ignore it or let the auditor fix it personally.
10. Spot qualifier words. Words like best, most appropriate, and first matter. Several options may be partially correct, so pick the one most consistent with risk-based planning and professional skepticism.
11. Document reliance. Questions on working papers often expect the planning documentation to record the extent of reliance and its basis.
Example Question
An internal auditor is planning an audit of payroll. Payroll is outsourced, and a SOC 1 Type II report is available. What should the auditor do?
Best answer: Review the report's opinion, period, exceptions, and carve-outs, and identify and test the complementary user entity controls within the organization.
Wrong answers: "Rely entirely on the report" and "Re-perform all of the service organization's controls."
Summary
Prior audit reports and other assurance work are valuable planning inputs. They sharpen the risk assessment, support follow-up, and reduce duplication. Their value depends on critical evaluation of independence, competence, scope, quality, and timeliness. On the exam, favor answers that show professional skepticism, risk-based scoping, coordination, documentation, and retained responsibility.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!