Relying on the Work of Other Assurance Providers
Relying on the work of other assurance providers is a key consideration when the chief audit executive (CAE) builds the risk-based internal audit plan. Under the Global Internal Audit Standards (Standard 9.5, Coordination and Reliance), the CAE should coordinate with internal and external providers… Relying on the work of other assurance providers is a key consideration when the chief audit executive (CAE) builds the risk-based internal audit plan. Under the Global Internal Audit Standards (Standard 9.5, Coordination and Reliance), the CAE should coordinate with internal and external providers of assurance and advisory services and consider relying on their work. This improves coverage, reduces duplication and audit fatigue, and supports a combined assurance view for the board. Other providers fit the Three Lines Model. Second-line functions include risk management, compliance, information security, health and safety, and quality assurance. External providers include external auditors, regulators, certification bodies, and outsourced specialists. The process usually starts with an assurance map. This links the organization's key risks to the providers that cover them, showing gaps and overlaps. The plan can then focus internal audit resources where assurance is weak or absent. Before relying on another provider's work, the CAE must evaluate several factors: 1) Independence and objectivity, including reporting lines, conflicts of interest, and whether the provider assesses areas it manages. 2) Competence, including qualifications, experience, and professional certifications. 3) Due professional care, including whether the work was properly planned, supervised, documented, and reviewed. 4) Scope, objectives, and methodology, and whether they match internal audit's needs. 5) Whether findings and conclusions are reasonable and supported by sufficient evidence. The CAE should document the basis for reliance. The degree of reliance can vary: full reliance, partial reliance with additional testing, or no reliance. Reliance does not transfer accountability. Internal audit remains responsible for its own conclusions and opinions. The CAE should also establish a consistent process for coordination, such as shared risk terminology, timing of work, and reporting. The CAE should communicate the reliance approach to senior management and the board. For the CIA exam, remember these points: coordination is expected, reliance requires evaluation, and responsibility for internal audit conclusions always stays with internal audit.
Relying on the Work of Other Assurance Providers: A Complete CIA Part 3 Guide
Introduction
Internal audit is rarely the only function in an organization that gives assurance. External auditors, risk management, compliance, quality assurance, information security, health and safety teams, regulators and outside specialists all review controls and risks. Relying on the work of other assurance providers means the internal audit activity uses the results of these providers' work, after evaluating it, instead of repeating that work itself. This topic sits within internal audit planning because decisions about reliance directly shape audit coverage, scope, resources and the risk-based plan.
1. Why It Is Important
Efficiency and cost. Without coordination, several functions may test the same controls. This wastes resources and causes audit fatigue for management. Reliance reduces duplication.
Broader coverage. Internal audit has limited resources. Relying on others frees capacity for high-risk areas that nobody else covers, so the overall assurance coverage improves.
Better information for the board. When assurance activities are coordinated, the board and senior management get a clearer, consolidated view of risk and control. This is often called combined assurance.
Professional requirement. The IIA Standards expect it. The legacy Standard 2050 (Coordination and Reliance) required the chief audit executive (CAE) to share information, coordinate activities and consider relying on the work of other internal and external assurance and consulting providers. The 2024 Global Internal Audit Standards keep this principle in Standard 9.5 (Coordination and Reliance), within the domain on managing the internal audit function.
Gaps and overlaps become visible. Mapping who provides assurance over which risks shows where risks are over-audited and where they are not covered at all.
2. What It Is
Definition. Reliance is the internal audit activity's use of another provider's work as a basis for its own conclusions, either partly or fully. The internal audit activity does not reperform the work, or reperforms only a limited part of it.
Types of other assurance providers
Internal providers (inside the organization):
- First line: operational management self-assessments and control self-assessment (CSA). These are usually the least independent.
- Second line: risk management, compliance, information security, quality, health, safety and environmental functions, internal control or SOX teams. They have some objectivity but still report to management.
External providers (outside the organization):
- External auditors performing the financial statement audit
- Regulators and examiners
- Consultants and specialists, such as actuaries, IT security testers and engineers
- Service organization auditors issuing SOC 1 and SOC 2 reports for outsourced processes
- Certification bodies, such as ISO auditors
Key related concepts
- Coordination: sharing plans, schedules, findings and methods to reduce duplication. It does not necessarily mean reliance.
- Reliance: actually using the other party's work as evidence.
- Assurance map: a matrix of key risks against the providers that give assurance over each one. It shows coverage, gaps and overlaps.
- Combined assurance: an integrated model that aligns all lines of assurance to give the board a holistic view.
- Three Lines Model: the framework that explains the roles of management (first line), risk and compliance functions (second line) and internal audit (third line).
Critical principle. Relying on others does not transfer responsibility. The CAE remains fully accountable for the conclusions and opinions issued by internal audit, even when those conclusions rest partly on another provider's work.
3. How It Works
Step 1: Identify providers and map assurance.
During risk assessment for the audit plan, the CAE identifies all assurance providers and the risks or areas they cover. An assurance map is commonly used for this.
Step 2: Establish a consistent basis for reliance.
The CAE should develop a documented, consistent process for evaluating providers. The board should understand it, and it is often described in the internal audit charter or methodology.
Step 3: Evaluate the provider. The IIA guidance highlights these criteria:
- Independence: Does the provider's position and reporting line allow it to work free of interference? External auditors and regulators are usually more independent than second-line functions.
- Objectivity: Does the provider have conflicts of interest? Are they assessing their own work? Do they have a personal stake in the results?
- Competence: Do they have the relevant qualifications, certifications, experience and knowledge of the subject?
- Due professional care / elements of the work: Was the work properly planned, supervised, documented and reviewed? Did it follow a recognized methodology?
- Scope, objectives and timing: Does the work cover the same risks, period and locations that internal audit needs? Is it recent enough?
- Quality of evidence and conclusions: Is the evidence sufficient, reliable and relevant? Are the conclusions reasonable and supported?
Step 4: Review the work.
The CAE or auditors review work papers, reports and methodology, and may reperform a sample of tests to confirm quality. The less independent or competent the provider, the more testing internal audit should do.
Step 5: Decide the extent of reliance.
- Full reliance: the work is accepted with minimal additional testing. This is rare and needs strong evaluation results.
- Partial reliance: some work is used, and internal audit adds its own procedures.
- No reliance: internal audit performs the work itself, though it may still coordinate with the provider.
Step 6: Adjust the audit plan and engagement scope.
Reduce or remove planned coverage where reliance is justified, and redirect resources to gaps.
Step 7: Document and communicate.
Document the basis for reliance and the evaluation performed. Communicate the coordination and reliance approach to senior management and the board. If the CAE cannot achieve appropriate coordination, the issue may need to be raised with the board.
Step 8: Monitor on an ongoing basis.
Reassess providers periodically. Changes in personnel, methodology, reporting lines or scope can change whether reliance is still appropriate.
Special case: the external auditor.
The relationship goes both ways. External auditors may rely on internal audit's work under their own standards, such as ISA 610 or AS 2605. Internal audit may in turn rely on external audit work for financial reporting controls. Coordination usually covers timing, access to work papers, sampling methods, terminology and sharing findings. Note that the external auditor's objective, an opinion on the financial statements, differs from internal audit's objectives. Scope therefore rarely aligns fully.
Special case: SOC reports.
For outsourced processes, internal audit can rely on a service auditor's SOC report. The auditor must still check the following:
- whether it is a Type I (design at a point in time) or Type II (design and operating effectiveness over a period) report
- whether the period and scope are relevant
- whether there are exceptions
- whether the complementary user entity controls that the organization must operate are in place
4. Benefits and Risks
Benefits: less duplication, lower cost, broader coverage, less disruption for management, a consolidated view of risk, and stronger relationships across the lines.
Risks:
- over-reliance on low-quality or non-independent work
- scope mismatches that leave risks untested
- outdated work
- differing risk ratings or terminology
- a false sense of assurance at board level
5. Exam Tips: Answering Questions on Relying on the Work of Other Assurance Providers
Tip 1: The CAE never transfers accountability. If an option says that responsibility shifts to the other provider, or that internal audit is no longer accountable, it is wrong. The CAE remains responsible for internal audit's conclusions.
Tip 2: Know the evaluation criteria. Questions often ask what the CAE should assess first or most importantly. Look for independence, objectivity, competence and due professional care. Cost, convenience or the provider's reputation alone are distractor answers.
Tip 3: Rank independence along the lines. External auditors and regulators are generally more independent than second-line functions, which are more independent than first-line self-assessments. If asked which work is least reliable without further testing, choose management self-assessment or first-line work.
Tip 4: Reliance requires evaluation, not blind acceptance. The correct answer usually involves reviewing the provider's work, methodology or work papers before relying on it. Be wary of answers that accept another report at face value.
Tip 5: Coordination is not the same as reliance. Sharing schedules and plans is coordination. Using their results as evidence is reliance. Read the question carefully to see which one is being tested.
Tip 6: Watch for scope and timing traps. Even competent, independent work cannot be relied on if it covers a different period, different locations or different objectives. If a scenario mentions a mismatch, the answer typically involves additional internal audit procedures.
Tip 7: Recognize the assurance map. If a question asks for the best tool to identify gaps and overlaps in assurance coverage, the answer is an assurance map or combined assurance approach.
Tip 8: Apply the sliding scale. Weaker independence or competence means more reperformance and testing by internal audit. Stronger providers justify more reliance and less retesting.
Tip 9: Document and communicate. Answers involving documenting the basis for reliance and informing the board are often correct. The board should understand how internal audit coordinates with and relies on others.
Tip 10: SOC report details matter. A Type II report gives evidence of operating effectiveness, while a Type I report covers design only. Remember the complementary user entity controls. A SOC report with qualified opinions or exceptions calls for follow-up.
Tip 11: Eliminate extreme options. Answers stating that internal audit must always reperform all work, or must never rely on others, are usually wrong. The Standards encourage reasonable, evaluated reliance.
Tip 12: Link to the audit plan. In planning questions, reliance is a factor that can reduce coverage of areas already well assured. This lets the CAE allocate limited resources to higher-risk, uncovered areas.
Worked Example
Question: The compliance department tested anti-bribery controls last quarter. Before relying on this work for the upcoming audit, what should the CAE do first?
A. Accept the compliance report because compliance is a second-line function.
B. Evaluate the objectivity and competence of the compliance team and the quality of their work.
C. Ask the external auditor to approve the reliance.
D. Reperform all compliance tests.
Answer: B.
- A is blind acceptance.
- C is not required.
- D removes the benefit of reliance and is not required by default.
Summary
Relying on the work of other assurance providers helps internal audit work efficiently and broadens assurance coverage. The approach follows a clear sequence:
- identify the providers
- evaluate their independence, objectivity, competence and due professional care
- review their work and decide the extent of reliance
- document and communicate the decision
- keep monitoring
Throughout, the CAE remains accountable for the conclusions. In the exam, favor answers that show evaluated, documented and proportionate reliance, and avoid answers that show blind acceptance or transfer of responsibility.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!