Balancing Assurance and Advisory Engagements (CIA Part 3: Internal Audit Operations)
Balancing Assurance and Advisory Engagements: A Complete Guide for CIA Part 3
1. Why It Is Important
Internal audit adds value through two complementary services: assurance (objective examination of evidence to give an independent assessment) and advisory services, which earlier IIA guidance called consulting (advice and other client-requested help).
The Chief Audit Executive (CAE) must decide how much of each to provide. Getting the balance wrong carries real risks:
- Too much advisory work can erode independence and objectivity. It can also leave key risks without assurance and turn internal audit into a free management consultancy.
- Too little advisory work means missing chances to improve governance, risk management and control early, especially on new systems, projects and emerging risks. Stakeholders may come to see internal audit as only a compliance policing function.
The board relies on internal audit for a reliable opinion on governance, risk management and control. If resources are diverted to advisory work, gaps in that assurance coverage can appear.
Balancing the two is therefore central to strategy, resource management and stakeholder expectations. It is also a frequently tested area in CIA Part 3, under managing the internal audit activity and its operations.
2. What It Is
Assurance engagements
- Three parties are involved:
- the process owner (the party responsible for the process);
- the internal auditor (who performs the assessment);
- the user (the board or senior management, who relies on the results).
- Internal audit determines the nature and scope.
- Examples include financial, compliance, operational, IT and performance audits.
Advisory engagements
- Usually two parties are involved: the internal auditor and the engagement client.
- Nature and scope are agreed with the client.
- The aim is to add value without the auditor assuming management responsibility.
- Examples include advice, facilitation, training, process design input, and control self-assessment workshops.
Balancing means deliberately planning the mix of these services. The goals are to:
- deliver adequate assurance coverage over significant risks;
- provide advisory value where it best serves the organization;
- safeguard independence and objectivity.
3. How It Works
a) Mandate and charter
- The internal audit charter, approved by the board, defines the nature of both services.
- The board approves the mandate and the risk-based plan, which reflects the intended mix.
- Significant advisory engagements not in the plan may require board or senior management awareness or approval. This is especially true when they affect resources.
b) Risk-based planning
- The CAE builds the plan from a risk assessment and stakeholder input, including the board, senior management and external auditors.
- Assurance should cover the highest risks and areas the board needs comfort on.
- Advisory requests are evaluated for their potential to:
- improve risk management, control and governance;
- add value;
- fit available resources and skills.
- The CAE should consider accepting advisory engagements based on their potential to improve the management of risks, add value and improve operations. Accepted engagements should be included in the plan.
c) Resource allocation
- Total resources must be appropriate, sufficient and effectively deployed.
- If advisory demand threatens core assurance coverage, the CAE must:
- reprioritize;
- obtain additional resources, for example through co-sourcing or outsourcing;
- or communicate the impact of resource limitations to senior management and the board.
- Many functions keep a flexible reserve of hours for unplanned advisory requests.
d) Independence and objectivity safeguards
- Internal auditors must not assume management responsibilities, such as making decisions, implementing controls, or owning processes.
- An auditor who provided advisory services on an activity should not perform assurance on it if objectivity is impaired.
- A cooling-off period of typically at least one year is expected when auditors assess operations for which they were previously responsible.
- Assurance may be provided on areas where the auditor previously did advisory work, provided the advisory work did not impair objectivity. Where it does, impairments must be disclosed to the appropriate parties before accepting the engagement.
e) Integrating the two
- Advisory work can feed assurance planning by revealing emerging risks.
- Assurance findings can reveal where advice or training is needed.
- If significant issues arise during an advisory engagement, they should be communicated to senior management and the board as appropriate.
- Advisory engagements on major projects, such as a system implementation, provide early-stage input. Later assurance must remain objective and may need different staff.
f) Monitoring and reporting
- The CAE reports periodically to the board on:
- performance against the plan, including the mix of assurance and advisory;
- significant risk exposures;
- resource sufficiency;
- any impairments.
- Quality assurance and improvement program (QAIP) reviews assess whether the balance supports the mandate.
4. Key Distinctions to Remember
- Scope set by: internal audit (assurance) versus agreed with the client (advisory).
- Parties: three (assurance) versus two (advisory).
- Output: an opinion or conclusion (assurance) versus advice or recommendations (advisory).
- Communication: standard report to management and the board (assurance) versus format agreed with the client (advisory).
5. Exam Tips: Answering Questions on Balancing Assurance and Advisory Engagements
Tip 1: Assurance on key risks comes first. When advisory requests compete with assurance over significant risks, the best answer protects board-required assurance coverage. That may mean declining the request, deferring it, or seeking extra resources.
Tip 2: Never assume management responsibility. Reject options where auditors design and implement controls, approve transactions, make decisions, or own processes. Advising is acceptable; deciding or doing is not.
Tip 3: Watch for objectivity impairments. If an auditor advised on or designed a process, prefer answers that:
- assign a different auditor to later assurance work;
- apply a cooling-off period;
- disclose the impairment.
Tip 4: Think board and CAE communication. For resource shortfalls or significant changes to the plan, the correct response usually involves the CAE communicating with senior management and the board. The CAE does not quietly absorb the shortfall.
Tip 5: Recognize the engagement type. Identify which service the scenario describes, then apply the matching rules on scope, parties and reporting:
- client-requested, scope agreed with the client, two parties: advisory;
- independent opinion for the board, three parties: assurance.
Tip 6: Value-add criteria. Accept advisory engagements that improve governance, risk management and control, and that fit available skills. If skills are lacking, the CAE should:
- decline the engagement;
- or obtain competent assistance.
Tip 7: Keyword scanning.
- Words such as always, never, or implement in options often signal wrong answers.
- Words such as risk-based, approved plan, disclose, and communicate to the board often signal correct ones.
Tip 8: Significant issues found in advisory work. If a serious control weakness or fraud indicator emerges during an advisory engagement, it should be communicated to senior management and the board. It may also warrant a separate assurance engagement.
Tip 9: Choose the most comprehensive answer. CIA questions often have several plausible options. Pick the one that balances stakeholder needs, independence and resource constraints together.
6. Sample Question
Scenario: Management asks internal audit to help design controls for a new ERP system, taking 40% of planned hours. Several high-risk assurance audits would be dropped. What should the CAE do?
Best answer: Evaluate the request against the risk-based plan and discuss the resource impact with senior management and the board. Then either secure additional resources or adjust the scope, so that critical assurance coverage is maintained. Advisory involvement in the ERP project should stay limited to advice and must not include implementation.
Summary: Balancing assurance and advisory engagements means using a risk-based, board-approved plan. That plan should secure assurance over key risks, add value through well-chosen advisory work, protect independence and objectivity, and clearly communicate resource constraints and impairments.