11.3 Evaluating & Relying on External Auditors and Regulators
Key Takeaways
- Under Global Internal Audit Standard 9.5 (Coordination and Reliance), internal audit may coordinate activities and rely on the work of other assurance providers, but internal audit retains ultimate responsibility for its conclusions and opinions.
- Placing formal reliance requires rigorous, documented evaluation across five mandatory criteria: competence, objectivity, due professional care, adequacy of scope, and appropriateness of methodology.
- Internal auditors must verify underlying work through direct workpaper reviews, testing program assessments, and sample re-performance rather than accepting third-party reports at face value.
- Regulatory examination reports provide valuable compliance intelligence and industry benchmarks, but cannot be treated as complete operational assurance because regulators focus strictly on statutory compliance rather than business efficiency or control optimization.
- The CAE can never deflect blame or shift fiduciary accountability to an external auditor, specialist, or regulator if an undetected control failure or fraud occurs within an area subjected to reliance.
11.3 Evaluating & Relying on External Auditors and Regulators
[!NOTE] GIAS Standard 9.5 Mandate: Under Global Internal Audit Standard 9.5 (Coordination and Reliance), the Chief Audit Executive (CAE) must coordinate internal audit activities and share information with other internal and external assurance providers to ensure proper coverage and minimize duplication. If the CAE plans to rely on the work of another provider, the CAE must evaluate the provider's competence, objectivity, and due professional care, as well as the scope, adequacy, and results of their work.
In modern corporate environments, organizations engage external specialists across numerous technical disciplines: external financial auditors, SOC attestation practitioners, cybersecurity penetration testers, environmental compliance engineers, and actuarial consultants. Simultaneously, government regulators conduct intensive statutory examinations. If internal audit ignores this external work, the organization squanders resources re-performing identical evaluations. Conversely, if internal audit blindly accepts external reports without rigorous verification, it abdicates its professional duties. Standard 9.5 establishes the disciplined methodology required to balance coordination with professional skepticism.
The Five Mandatory Criteria for Placing Reliance
Before internal audit can incorporate or rely upon the conclusions or testing of an external assurance provider, the CAE must conduct a structured, documented evaluation spanning five non-negotiable criteria:
- Competence: The CAE must verify that the external provider possesses the technical knowledge, skills, professional credentials, and experience required for the engagement. This includes validating certifications (CPA, CA, CIA, CISA, CISSP, actuarial credentials), inspecting the firm's professional and regulatory standing (such as PCAOB inspection reports), and verifying the qualifications of specific engagement team members.
- Objectivity and Independence: The external provider must be structurally and psychologically free from conflicts of interest. The CAE must confirm that the provider has no operational authority over the audited activity, no substantial commercial ties or contingent fee arrangements, and did not design or implement the controls being evaluated (e.g., verifying that an external cyber consultant did not configure the network architecture).
- Due Professional Care: The provider's work must reflect the diligence, thoroughness, and discipline expected of a seasoned audit professional. This includes adherence to recognized professional standards (AICPA, PCAOB, International Standards on Auditing [ISA], ISO 19011), adequate supervision and review of fieldwork by senior professionals, and complete workpaper documentation providing a clear audit trail.
- Adequacy of Scope and Alignment: The provider's engagement scope must align with internal audit's specific risk coverage needs. The CAE must verify temporal alignment (testing period corresponds to internal audit's assurance timeframe), boundary alignment (all relevant corporate entities and systems were included), and reconcile materiality differences. External financial auditors utilize financial materiality thresholds calibrated to balance-sheet misstatements, which are often significantly higher than internal audit's operational materiality thresholds for detecting localized control breakdowns.
- Appropriateness of Methodology and Evidence: Internal audit must evaluate the scientific validity and rigor of the provider's testing techniques. This includes assessing whether the provider performed substantive testing and direct re-performance rather than passive inquiry, evaluating sample sizes and selection methods, and ensuring findings are logically supported by underlying workpapers.
Practical Verification: Testing and Workpaper Review
Placing reliance is an active, investigatory process rather than a passive administrative sign-off. Under GIAS Standard 9.5, internal audit executes four structured verification procedures:
1. Information-Sharing Agreements
The CAE establishes formal reliance protocols with the external provider, such as access letters delineating how workpapers can be reviewed, cited, and safeguarded, while respecting statutory confidentiality constraints.
2. Workpaper Review and Detailed Inspection
Internal auditors directly inspect the provider's engagement documentation, reviewing the formal audit program, population definitions from which samples were drawn, specific evidentiary items inspected, and the handling of deviations and remediation plans.
3. Sample Re-Performance and Walkthroughs
A vital safeguarding protocol is sample re-testing. Internal auditors independently re-perform a selected sample (typically 10% to 20%) of the control tests executed by the external provider. If discrepancies, unrecorded exceptions, or sloppy documentation emerge during re-performance, the CAE must immediately reject reliance and expand internal audit field testing.
4. Documenting Reliance in Workpapers
The internal audit files must contain a dedicated Reliance Evaluation Memorandum documenting the assessment of the provider's competence and independence, scope reconciliation, verification procedures executed, and the formal justification for the degree of reliance placed.
Comparison: Reliance Framework Across Assurance Providers
| Assurance Provider | Primary Focus & Standards | Objectivity Level | Scope & Materiality Differences | Required IA Verification Procedures |
|---|---|---|---|---|
| External Financial Auditor | Financial statement accuracy; SOX 404 controls (PCAOB / AICPA) | High; independent CPA firm bound by statutory independence rules | High financial materiality; focuses on material misstatement, ignores operational waste | Formal access letter; review test scripts; re-perform 10-20% sample of key controls |
| Regulatory Examiners | Compliance with statutory laws, consumer protection, systemic safety | High; sovereign government authority, completely independent | Narrow legal focus; point-in-time review; does not evaluate operational efficiency | Map findings to risk universe; validate remediation; do not infer control health from silence |
| Third-Party Specialists (Cyber, Forensic, Actuaries) | Technical evaluation of specific complex systems (ISO, NIST) | Moderate; hired by management or board; assess commercial ties | Deep technical focus; limited to contractual statement of work | Verify technical credentials; evaluate independence; review raw data & testing scripts |
| Second-Line Monitors (Compliance, ERM, Quality) | Internal policy compliance, risk monitoring, operational metrics | Limited; part of management hierarchy, lacks audit independence | Aligned with internal operations, but susceptible to management pressure | Review monitoring programs; re-test samples; never substitute for independent assurance |
Utilizing Regulatory Examination Reports and Retained Accountability
Statutory regulatory authorities (such as the Federal Reserve, OCC, CFPB, SEC, FDA, and OSHA) conduct rigorous examinations possessing compulsory legal authority and broad industry comparative data. When regulators issue findings, the CAE must update the audit universe and independently validate management's corrective remediation. However, regulatory reports cannot substitute for comprehensive internal audit coverage because regulators focus strictly on statutory compliance rather than operational efficiency, and an absence of regulatory findings does not prove controls are effective.
Most fundamentally, the CAE must uphold the principle of retained accountability:
[!IMPORTANT] Accountability Cannot Be Outsourced: Under GIAS Standard 9.5, internal audit retains full and ultimate responsibility for the conclusions, opinions, and overall assessment reached by the internal audit activity. Relying on the work of an external auditor, specialist, or regulator never relieves the CAE or internal audit from fiduciary accountability. Internal audit always owns the final assurance conclusion and can never deflect blame to third parties.
An internal audit team relies on the testing performed by an external cybersecurity firm regarding enterprise cloud access controls. Six months later, a major security breach occurs due to an unpatched vulnerability in cloud access that the external firm failed to test properly. When the Audit Committee questions the Chief Audit Executive (CAE), what is the CAE's ultimate accountability under GIAS Standard 9.5?
A Chief Audit Executive is preparing an internal audit engagement covering the organization's corporate pension fund liabilities and plans to rely upon the valuation report issued by an independent external actuarial firm. Before placing reliance on the actuary's valuation, which procedure must the CAE execute first under GIAS Standard 9.5?
A national banking regulator completes a comprehensive statutory examination of a commercial bank, issuing a formal supervisory report with zero citations, penalties, or Matters Requiring Attention (MRAs) regarding consumer lending practices. How should the bank's Chief Audit Executive interpret this clean regulatory report during annual audit planning?