Communicating with External Auditors and Regulators
Communicating with external auditors and regulators is part of engagement results and monitoring. It means sharing information outside the internal audit activity in a controlled and coordinated way. Internal auditors communicate with external parties for three main reasons: coordination, reliance,… Communicating with external auditors and regulators is part of engagement results and monitoring. It means sharing information outside the internal audit activity in a controlled and coordinated way. Internal auditors communicate with external parties for three main reasons: coordination, reliance, and compliance. Coordinating with external auditors avoids duplicated work, gives assurance coverage across key risks, and can lower total assurance costs. External auditors may use internal audit work papers, risk assessments, or test results. Internal auditors may also rely on external auditors' findings, provided they first assess their competence, objectivity, and due professional care. Regulators may request internal audit reports, observations on control weaknesses, or evidence of remediation, especially in banking, insurance, healthcare, and public sector environments. The chief audit executive (CAE) normally oversees these relationships. Under the IIA's standards, the CAE should coordinate activities with other assurance providers and keep a clear, open dialogue on scope, timing, methodology, and significant findings. Regular meetings, shared risk maps, and agreed protocols for exchanging information support this. Releasing results outside the organization requires extra care. Unless law, regulation, or the internal audit charter requires otherwise, the CAE should do the following before disclosure: - assess the potential risk to the organization; - consult senior management and/or legal counsel as appropriate; - control dissemination by restricting how the results may be used. Confidentiality, legal privilege, data protection, and contractual obligations must be respected. Any limits on distribution should be stated clearly in the communication. Monitoring also matters. Regulators often expect evidence that management has addressed reported issues, so internal audit should track corrective actions and report their status accurately. Good communication improves the organization's credibility with regulators, supports external audit efficiency, and strengthens governance. Poor communication can lead to regulatory sanctions, reputational damage, or exposure of sensitive information. For the CIA exam, remember these points: coordinate to reduce duplication, evaluate before relying on others' work, have the CAE oversee and control external disclosure, and keep confidentiality and legal advice central to the process.
Communicating with External Auditors and Regulators: A Complete CIA Exam Guide
Communicating with External Auditors and Regulators
Internal audit does not work alone. External auditors, banking examiners, securities regulators, tax authorities, and industry supervisors all have legitimate interests in the organization's governance, risk management, and control. The CIA exam expects you to know when internal audit shares information with these outside parties, how it does so, who authorizes it, and what safeguards apply.
1. Why This Topic Is Important
Efficiency and coverage: Coordination reduces duplicated work, lowers total assurance cost, and limits disruption to the business. It also helps close coverage gaps across the organization's assurance providers. This idea is often described as combined assurance.
Legal and regulatory compliance: Regulators may have statutory rights to see internal audit reports and working papers. This is common in banking, insurance, healthcare, and public companies. Mishandling a mandated request can expose the organization to penalties.
Protection of the organization: Information released outside the organization can create legal liability, reputational damage, or loss of confidentiality. Internal audit must balance transparency with protecting the organization.
Credibility of internal audit: External auditors may rely on internal audit's work only if it is objective and competent. Good communication builds that credibility. Regulators also assess the quality of internal audit as part of their supervision.
Standards requirement: The IIA Standards require the chief audit executive (CAE) to do three things:
- Coordinate with other providers of assurance and consulting services.
- Apply specific safeguards before releasing results outside the organization.
- Maintain confidentiality.
2. What It Is: Key Concepts and Standards
External auditors are independent public accounting firms. They give an opinion on the financial statements and, where required (for example, under SOX Section 404), on internal control over financial reporting. They owe their primary duty to shareholders and the public, not to management.
Regulators are government or quasi-government bodies with supervisory authority. Examples include central banks, banking examiners, securities commissions, the PCAOB, insurance commissioners, environmental and health agencies, and tax authorities.
Relevant IIA guidance:
Coordination and reliance
- 2017 IPPF Standard 2050.
- 2024 Global Internal Audit Standards, Standard 9.5 (Coordination and Reliance).
- The CAE should share information, coordinate activities, and consider relying on the work of other assurance providers.
- When internal audit relies on others' work, the CAE should evaluate their competence, objectivity, and due professional care. The CAE still keeps responsibility for the conclusions reached.
Disseminating results outside the organization
- 2017 Standard 2440.A2; reflected in 2024 Standard 15.1 and in the confidentiality requirements of Principle 5.
- Unless legal, statutory, or regulatory requirements say otherwise, the CAE must do three things before releasing results externally:
(1) assess the potential risk to the organization;
(2) consult with senior management and/or legal counsel as appropriate;
(3) control dissemination by restricting the use of the results.
Confidentiality and protection of information
- 2017 Code of Ethics (Confidentiality); 2024 Principle 5 and Standard 5.2.
- Internal auditors must not disclose information without appropriate authority, unless there is a legal or professional obligation to do so.
Board oversight
- The internal audit charter, approved by the board, should define relationships with external auditors and regulators and internal audit's access and reporting.
- The board or audit committee typically oversees both internal and external audit. It should be informed of significant regulatory communications.
Professional standards on the external auditor side
- ISA 610 and PCAOB AS 2605 govern how external auditors evaluate and use internal audit work.
- External auditors assess internal audit's objectivity (organizational status), competence, and systematic, disciplined approach, including quality control.
- They may use internal audit's work, or use internal auditors for direct assistance under the external auditor's supervision. Some jurisdictions restrict direct assistance.
- The external auditor alone remains responsible for the audit opinion. Responsibility is never shared.
3. How It Works in Practice
A. Coordinating with external auditors
Periodic meetings: The CAE and the external audit partner meet to discuss:
- risk assessments;
- audit plans, scope, and timing;
- significant findings;
- fraud risks;
- changes in the business.
Sharing audit plans and reports: Internal audit reports and the annual plan are commonly shared with external auditors. This helps them understand the control environment.
Access to working papers: The CAE may grant external auditors access to internal audit working papers. This is usually governed by policy and approved by senior management or the board. It also helps the external auditor judge the quality of work it intends to use.
Common methodology and terminology: Agreeing on definitions such as materiality, deficiency ratings, and sampling techniques makes reliance easier.
Avoiding conflicts: Internal auditors should not assume management responsibilities on behalf of the external auditor. They should also stay aware of the external auditor's own independence rules.
Reporting to the board: The CAE reports on the effectiveness of coordination. The board may evaluate the coordination and the external auditor's performance.
B. Communicating with regulators
Mandated requests (law, regulation, or court order):
- The organization must comply.
- The CAE should still notify senior management and legal counsel and inform the board as appropriate.
- Disclosure should be limited to what is required.
Voluntary or discretionary requests:
- Apply the three safeguards: assess risk, consult senior management and/or legal counsel, and restrict use.
Restricting use:
- Mark reports as confidential.
- Include distribution and use limitations.
- Use confidentiality agreements.
- Release summaries instead of full working papers where appropriate.
Legal privilege:
- Legal counsel may advise structuring certain engagements, such as fraud investigations, under attorney-client privilege.
- Uncontrolled disclosure to third parties could waive that privilege.
Regulatory examinations:
- Regulators often review internal audit's charter, risk assessment, plan, reports, issue tracking, and quality assurance results.
- Prepared, consistent, and accurate communication builds regulatory confidence and may reduce regulators' own testing.
Reporting violations:
- Internal auditors may discover illegal acts. The usual first step is to escalate internally: to senior management, legal counsel, and the board.
- External reporting obligations depend on law. Examples include whistleblower statutes and specific regulatory mandates.
- Internal auditors should consult legal counsel rather than act unilaterally, unless the law requires direct reporting.
C. Policies and documentation
Charter and policies: These should cover access to, retention of, and release of engagement records. Procedures should specify who approves internal and external access to engagement records.
Documentation: Record what was provided, to whom, when, under what authority, and with what restrictions.
Follow-up: Track regulatory findings and management's action plans. Internal audit is often asked to validate their remediation.
4. Exam Tips: Answering Questions on Communicating with External Auditors and Regulators
Tip 1: Memorize the three-step safeguard for external release.
- Assess risk, consult senior management and/or legal counsel, and restrict use.
- If an answer choice describes releasing internal audit results to an outside party without these steps (and with no legal mandate), it is usually wrong.
- If the question says the release is legally required, compliance is mandatory. Consultation and notification are still good practice.
Tip 2: Know who is responsible for what.
- The CAE is responsible for coordination.
- The board or audit committee oversees.
- Senior management and legal counsel are consulted before external release.
- The external auditor is solely responsible for its opinion.
- Watch for distractors claiming the external auditor and internal audit share responsibility for the financial statement opinion.
Tip 3: Reliance requires evaluation.
- Whether external auditors rely on internal audit, or internal audit relies on others, the evaluation covers objectivity, competence, and due professional care (or quality of work).
- The best answer typically includes evaluating these factors, not automatic reliance.
Tip 4: Coordination is the goal, not merger.
- Look for choices about sharing plans, scheduling, common terminology, and periodic meetings to avoid duplication.
- Be wary of choices where internal audit gives up its independence, performs management functions, or simply lets the external auditor dictate its whole plan.
Tip 5: Confidentiality is not secrecy.
- Internal auditors may disclose information when legally or professionally required, or when properly authorized.
- Questions often test whether the auditor can refuse a lawful regulatory request. Generally, the auditor cannot. The correct response is to comply through proper channels with legal counsel involved.
Tip 6: Escalate internally first.
- For discovered fraud or illegal acts, the usual best answer is to inform appropriate levels of management and the board and consult legal counsel.
- Contacting regulators or the media directly is usually wrong, unless the scenario cites a legal requirement.
Tip 7: Read for keywords.
- "Most appropriate first step" often points to consulting legal counsel or senior management, or assessing risk.
- "Prior to releasing" points to the three safeguards.
- "To maximize efficiency" points to coordination and reliance.
- "Legally mandated" means compliance is required.
Tip 8: Working papers belong to the organization.
- Access by external parties, including external auditors and regulators, should follow policy and receive appropriate approval.
- An answer saying internal auditors can freely hand over working papers on request is usually incorrect.
Tip 9: Remember board communication.
- Significant interactions with regulators and the results of coordination with external auditors should be reported to the board.
- An option that keeps the board uninformed is a red flag.
5. Practice Example
Question: A regulator informally asks the CAE for a copy of a recent internal audit report on compliance controls. No legal mandate has been cited. What should the CAE do first?
A. Provide the report immediately to demonstrate cooperation.
B. Refuse, because internal audit reports are always confidential.
C. Assess the potential risk to the organization and consult with senior management and/or legal counsel.
D. Send the report to the external auditor to forward to the regulator.
Answer: C.
- With no mandate, the Standards require assessing risk, consulting, and controlling dissemination before external release.
- A ignores the safeguards.
- B is too absolute.
- D bypasses proper controls.
Summary
Communicating with external auditors and regulators rests on four ideas:
- Coordination for efficiency and coverage.
- Evaluated reliance on others' work.
- Controlled dissemination: assess risk, consult, and restrict use.
- Respect for legal mandates combined with confidentiality.
On the exam, choose answers that protect the organization, follow proper authority and board oversight, preserve internal audit's independence, and comply with the law.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!