Internal and External Assurance Providers
In the CIA Part 3 syllabus, which covers managing the internal audit function, internal and external assurance providers matter when building a risk-based internal audit plan. The Chief Audit Executive (CAE) should identify every party that gives assurance over the organization's risks and coordina… In the CIA Part 3 syllabus, which covers managing the internal audit function, internal and external assurance providers matter when building a risk-based internal audit plan. The Chief Audit Executive (CAE) should identify every party that gives assurance over the organization's risks and coordinate with them. This avoids duplicated work, closes coverage gaps, and gives the board and senior management a complete view of assurance. The IIA's Global Internal Audit Standards address this under Coordination and Reliance (Standard 9.5). Internal assurance providers are functions inside the organization that monitor risk and control. Under the IIA Three Lines Model, they include first-line management controls and self-assessments. They also include second-line functions such as risk management, compliance, information security, quality assurance, health and safety, environmental monitoring, and legal. These groups usually report to management, so they are less independent than internal audit, which is the third line. External assurance providers are outside the organization. Examples include the external financial statement auditor, regulators and government inspectors, ISO certification bodies, actuaries, and specialist consultants. Another example is a service organization auditor who issues SOC 1 or SOC 2 reports on outsourced processes. Some external providers report mainly to outside stakeholders, while others are engaged by the board or management. When planning, the CAE often builds an assurance map. This tool links key risks to the providers that cover them and shows where coverage overlaps or is missing. It supports a combined assurance approach. Before relying on another provider's work, the CAE should evaluate their: - competence - objectivity and independence - due professional care - scope and methodology - quality of evidence and reporting The level of reliance can then be adjusted, for example by reducing internal audit's planned work in well-covered areas. The CAE should document the basis for reliance and share relevant information with these providers. Even when relying on others, the CAE remains responsible for the conclusions and opinions that internal audit gives. Effective coordination improves efficiency and optimizes audit resources. It also strengthens the board's confidence in the organization's overall governance, risk management, and control.
Internal and External Assurance Providers: A Complete CIA Part 3 Guide to Coordination and Reliance
Introduction
Within CIA Part 3 (Business Knowledge for Internal Auditing) and the wider topic of the internal audit plan, candidates must understand who else in the organisation provides assurance, and how the chief audit executive (CAE) works with them. The CIA exam tests whether you can tell the different assurance providers apart, judge when internal audit may rely on their work, and explain how coordination improves coverage while avoiding duplication. This guide covers why the topic matters, what it is, how it works in practice, and how to answer exam questions on it.
Why It Is Important
Organisations face many risks, and no single function can provide assurance over all of them. Management, compliance teams, risk management, external auditors, regulators and specialist consultants all look at risk and control in some way. Without coordination, three problems arise:
• Duplication of effort: several functions test the same controls, which wastes resources and frustrates the people being audited (audit fatigue).
• Gaps in coverage: significant risks fall between functions and nobody gives assurance over them.
• Inconsistent reporting: the board and senior management receive fragmented or contradictory messages about risk and control.
The Global Internal Audit Standards (2024) require coordination and reliance. Principle 9 (Plan Strategically) includes Standard 9.5, Coordination and Reliance. Under it, the CAE must coordinate with internal and external providers of assurance services and consider relying on their work. The earlier IPPF expressed the same requirement in Standard 2050. The aim is proper coverage and less duplication. Done well, coordination supports a combined assurance model that gives the board a holistic view of the organisation's risk and control environment.
What It Is
1. Definition of an assurance provider
An assurance provider is any function, inside or outside the organisation, that gives an objective assessment of governance, risk management or control processes. Providers differ in their independence and objectivity, competence, scope, and to whom they report.
2. Internal assurance providers
Internal providers usually belong to the first or second line roles of The IIA's Three Lines Model. Examples include:
• Operational management (first line): owns and manages risk, performs day-to-day controls, and carries out self-assessments. Objectivity is lowest because management assesses its own work.
• Risk management function (second line): sets frameworks, monitors risk appetite and challenges the first line.
• Compliance function (second line): monitors adherence to laws, regulations and policies.
• Health, safety and environment (HSE), quality assurance, information security, legal, and financial control functions (generally second line).
• Control self-assessment (CSA) programmes facilitated across the business.
Internal audit is the third line. Its independence comes from reporting functionally to the board, which lets it provide the most objective internal assurance.
3. External assurance providers
External providers sit outside the organisation. Examples include:
• External (statutory) auditors: give an opinion on the financial statements and report primarily to shareholders. Their focus is financial reporting and material misstatement.
• Regulators and supervisory bodies: for example banking or health regulators, who examine compliance with regulatory requirements.
• Certification bodies: for example ISO auditors.
• Service organisation auditors: for example those issuing SOC 1 and SOC 2 reports on outsourced service providers.
• External consultants and specialists: engaged for areas such as cybersecurity, actuarial or environmental reviews.
• Co-sourced or outsourced internal audit providers working under the CAE's direction.
• External quality assessment (EQA) reviewers of the internal audit activity itself.
4. Key distinction: assurance vs. reliance
Coordinating with another provider does not automatically mean relying on its work. Coordination means sharing plans, timing, risk assessments and results. Reliance means using another provider's work as evidence that supports internal audit's own conclusions. Reliance requires an evaluation of that provider first.
How It Works
Step 1: Identify and map assurance providers
During risk-based planning, the CAE identifies all providers and maps them against the organisation's key risks. The result is often called an assurance map. It shows which risks are covered, by whom, how often, and with what level of assurance. It highlights gaps and overlaps.
Step 2: Evaluate the provider before relying on its work
Before relying on another provider, the CAE should consider the following:
• Independence and objectivity: Are there conflicts of interest? Who does the provider report to? Is it assessing its own work?
• Competence: Does the provider have the right qualifications, certifications, experience and professional standing?
• Due professional care: Was the work properly planned, supervised, documented and reviewed?
• Scope, objectives and methodology: Do they match internal audit's needs? Was the methodology appropriate and the sampling sufficient?
• Quality of evidence and findings: Is the evidence sufficient, reliable, relevant and useful, and are the conclusions reasonable?
Step 3: Agree a consistent approach
Coordination works better with a common language and shared understanding. Providers can align on risk terminology, rating scales and reporting formats, and can share audit plans, schedules, work papers and findings. This should happen within confidentiality limits and agreed access protocols.
Step 4: Decide the degree of reliance
Reliance can be full, partial or none. Even when relying, the CAE may perform limited re-performance or review to confirm quality. The CAE should document the basis for reliance.
Step 5: Retain responsibility
A critical exam point: the CAE remains responsible for the conclusions and opinions internal audit reaches, even when it relies on others. Responsibility cannot be delegated to the other provider.
Step 6: Communicate with the board and senior management
The CAE should explain the coordination strategy, the assurance map, any reliance placed, and remaining coverage gaps. If the CAE cannot achieve proper coordination, or concludes that reliance is inappropriate, this should be raised with senior management and, if necessary, the board.
Relationship with the external auditor
This relationship is tested frequently. Coordination with the external auditor may include:
• Sharing audit plans and risk assessments to minimise duplication.
• Giving access to internal audit work papers and reports.
• Exchanging management letters and findings.
• Agreeing common techniques and terminology.
• Holding periodic meetings.
The two functions differ in important ways. External auditors focus on financial statement assurance for shareholders, while internal audit serves the board and management across all risks. The external auditor may use internal audit's work under its own standards (for example ISA 610), but it retains sole responsibility for its audit opinion. In the same way, internal audit keeps responsibility for its own conclusions.
Benefits of effective coordination
• Comprehensive risk coverage with fewer gaps.
• Lower cost and less audit fatigue.
• A more holistic, consistent view for the board.
• Better use of specialist expertise.
• Stronger governance and a clearer understanding of the Three Lines Model.
Risks and limitations
• Over-reliance on providers that lack independence, especially management self-assessments.
• Differences in scope, timing or materiality between providers.
• Confidentiality restrictions on sharing work.
• False comfort if providers' methodologies are weak.
Exam Tips: Answering Questions on Internal and External Assurance Providers
1. Remember who is responsible. If an option suggests the CAE transfers responsibility to another provider, it is wrong. The CAE always retains responsibility for internal audit's conclusions.
2. Evaluate before relying. The best answer usually involves assessing the provider's independence, objectivity, competence and due professional care before using its work. Watch for options that accept work at face value.
3. Distinguish coordination from reliance. Coordination is always expected. Reliance is optional and depends on the evaluation.
4. Rank objectivity correctly. Management self-assessments (first line) are the least objective. Second line functions are more objective but still not fully independent. External providers and internal audit are the most independent. When asked which source gives the greatest assurance, look for independence plus competence.
5. Know the purpose. Questions often ask why coordination matters. The answer is to ensure proper coverage and minimise duplication of effort.
6. Assurance mapping and combined assurance are the tools for identifying gaps and overlaps. Recognise them in scenario questions.
7. External auditor scenarios: pick answers that involve sharing plans, work papers and findings while respecting each party's distinct objectives. Internal audit does not take over the external auditor's role, and the external auditor does not direct internal audit.
8. Escalation: if coordination fails or reliance is inappropriate, the CAE communicates this to senior management and the board. Silently ignoring the issue is never correct.
9. Document the basis for reliance. Answers mentioning documentation and a consistent process are generally stronger.
10. Read carefully for keywords such as MOST appropriate, FIRST step and BEST. The first step is typically to identify providers and understand their scope, or to evaluate their objectivity and competence, before relying on them.
Sample Question
The CAE wants to use the compliance department's testing of anti-money-laundering controls in the annual audit plan. What should the CAE do FIRST?
A. Include the compliance results directly in the audit report.
B. Evaluate the compliance department's objectivity, competence and methodology.
C. Ask the external auditor to approve the reliance.
D. Eliminate AML from the audit universe.
Answer: B. Reliance requires prior evaluation of the provider. Option A skips the evaluation step. Option C is wrong because the external auditor does not approve internal audit's reliance decisions. Option D is wrong because removing a significant risk from the audit universe would create a coverage gap.
Summary
Internal and external assurance providers together form the organisation's assurance landscape. The CAE must identify these providers, coordinate with them, and evaluate them before relying on their work, all while retaining responsibility for internal audit's conclusions. Mastering this topic means understanding the Three Lines Model, objectivity levels, assurance mapping, and the criteria for reliance. These themes appear regularly in CIA Part 3 questions on audit planning and governance.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!