11.3 Evaluating & Relying on External Auditors and Regulators

Key Takeaways

  • Under Global Internal Audit Standard 9.5 (Coordination and Reliance), internal audit may coordinate activities and rely on the work of other assurance providers, but internal audit retains ultimate responsibility for its conclusions and opinions.
  • Placing formal reliance requires rigorous, documented evaluation across five mandatory criteria: competence, objectivity, due professional care, adequacy of scope, and appropriateness of methodology.
  • Internal auditors must verify underlying work through direct workpaper reviews, testing program assessments, and sample re-performance rather than accepting third-party reports at face value.
  • Regulatory examination reports provide valuable compliance intelligence and industry benchmarks, but cannot be treated as complete operational assurance because regulators focus strictly on statutory compliance rather than business efficiency or control optimization.
  • The CAE can never deflect blame or shift fiduciary accountability to an external auditor, specialist, or regulator if an undetected control failure or fraud occurs within an area subjected to reliance.
Last updated: September 2026

11.3 Evaluating & Relying on External Auditors and Regulators

[!NOTE] GIAS Standard 9.5 Mandate: Under Global Internal Audit Standard 9.5 (Coordination and Reliance), the Chief Audit Executive (CAE) must coordinate internal audit activities and share information with other internal and external assurance providers to ensure proper coverage and minimize duplication. If the CAE plans to rely on the work of another provider, the CAE must evaluate the provider's competence, objectivity, and due professional care, as well as the scope, adequacy, and results of their work.

In modern corporate environments, organizations engage external specialists across numerous technical disciplines: external financial auditors, SOC attestation practitioners, cybersecurity penetration testers, environmental compliance engineers, and actuarial consultants. Simultaneously, government regulators conduct intensive statutory examinations. If internal audit ignores this external work, the organization squanders resources re-performing identical evaluations. Conversely, if internal audit blindly accepts external reports without rigorous verification, it abdicates its professional duties. Standard 9.5 establishes the disciplined methodology required to balance coordination with professional skepticism.


The Five Mandatory Criteria for Placing Reliance

Before internal audit can incorporate or rely upon the conclusions or testing of an external assurance provider, the CAE must conduct a structured, documented evaluation spanning five non-negotiable criteria:

  1. Competence: The CAE must verify that the external provider possesses the technical knowledge, skills, professional credentials, and experience required for the engagement. This includes validating certifications (CPA, CA, CIA, CISA, CISSP, actuarial credentials), inspecting the firm's professional and regulatory standing (such as PCAOB inspection reports), and verifying the qualifications of specific engagement team members.
  2. Objectivity and Independence: The external provider must be structurally and psychologically free from conflicts of interest. The CAE must confirm that the provider has no operational authority over the audited activity, no substantial commercial ties or contingent fee arrangements, and did not design or implement the controls being evaluated (e.g., verifying that an external cyber consultant did not configure the network architecture).
  3. Due Professional Care: The provider's work must reflect the diligence, thoroughness, and discipline expected of a seasoned audit professional. This includes adherence to recognized professional standards (AICPA, PCAOB, International Standards on Auditing [ISA], ISO 19011), adequate supervision and review of fieldwork by senior professionals, and complete workpaper documentation providing a clear audit trail.
  4. Adequacy of Scope and Alignment: The provider's engagement scope must align with internal audit's specific risk coverage needs. The CAE must verify temporal alignment (testing period corresponds to internal audit's assurance timeframe), boundary alignment (all relevant corporate entities and systems were included), and reconcile materiality differences. External financial auditors utilize financial materiality thresholds calibrated to balance-sheet misstatements, which are often significantly higher than internal audit's operational materiality thresholds for detecting localized control breakdowns.
  5. Appropriateness of Methodology and Evidence: Internal audit must evaluate the scientific validity and rigor of the provider's testing techniques. This includes assessing whether the provider performed substantive testing and direct re-performance rather than passive inquiry, evaluating sample sizes and selection methods, and ensuring findings are logically supported by underlying workpapers.

Practical Verification: Testing and Workpaper Review

Placing reliance is an active, investigatory process rather than a passive administrative sign-off. Under GIAS Standard 9.5, internal audit executes four structured verification procedures:

1. Information-Sharing Agreements

The CAE establishes formal reliance protocols with the external provider, such as access letters delineating how workpapers can be reviewed, cited, and safeguarded, while respecting statutory confidentiality constraints.

2. Workpaper Review and Detailed Inspection

Internal auditors directly inspect the provider's engagement documentation, reviewing the formal audit program, population definitions from which samples were drawn, specific evidentiary items inspected, and the handling of deviations and remediation plans.

3. Sample Re-Performance and Walkthroughs

A vital safeguarding protocol is sample re-testing. Internal auditors independently re-perform a selected sample (typically 10% to 20%) of the control tests executed by the external provider. If discrepancies, unrecorded exceptions, or sloppy documentation emerge during re-performance, the CAE must immediately reject reliance and expand internal audit field testing.

4. Documenting Reliance in Workpapers

The internal audit files must contain a dedicated Reliance Evaluation Memorandum documenting the assessment of the provider's competence and independence, scope reconciliation, verification procedures executed, and the formal justification for the degree of reliance placed.


Comparison: Reliance Framework Across Assurance Providers

Assurance ProviderPrimary Focus & StandardsObjectivity LevelScope & Materiality DifferencesRequired IA Verification Procedures
External Financial AuditorFinancial statement accuracy; SOX 404 controls (PCAOB / AICPA)High; independent CPA firm bound by statutory independence rulesHigh financial materiality; focuses on material misstatement, ignores operational wasteFormal access letter; review test scripts; re-perform 10-20% sample of key controls
Regulatory ExaminersCompliance with statutory laws, consumer protection, systemic safetyHigh; sovereign government authority, completely independentNarrow legal focus; point-in-time review; does not evaluate operational efficiencyMap findings to risk universe; validate remediation; do not infer control health from silence
Third-Party Specialists (Cyber, Forensic, Actuaries)Technical evaluation of specific complex systems (ISO, NIST)Moderate; hired by management or board; assess commercial tiesDeep technical focus; limited to contractual statement of workVerify technical credentials; evaluate independence; review raw data & testing scripts
Second-Line Monitors (Compliance, ERM, Quality)Internal policy compliance, risk monitoring, operational metricsLimited; part of management hierarchy, lacks audit independenceAligned with internal operations, but susceptible to management pressureReview monitoring programs; re-test samples; never substitute for independent assurance

Utilizing Regulatory Examination Reports and Retained Accountability

Statutory regulatory authorities (such as the Federal Reserve, OCC, CFPB, SEC, FDA, and OSHA) conduct rigorous examinations possessing compulsory legal authority and broad industry comparative data. When regulators issue findings, the CAE must update the audit universe and independently validate management's corrective remediation. However, regulatory reports cannot substitute for comprehensive internal audit coverage because regulators focus strictly on statutory compliance rather than operational efficiency, and an absence of regulatory findings does not prove controls are effective.

Most fundamentally, the CAE must uphold the principle of retained accountability:

[!IMPORTANT] Accountability Cannot Be Outsourced: Under GIAS Standard 9.5, internal audit retains full and ultimate responsibility for the conclusions, opinions, and overall assessment reached by the internal audit activity. Relying on the work of an external auditor, specialist, or regulator never relieves the CAE or internal audit from fiduciary accountability. Internal audit always owns the final assurance conclusion and can never deflect blame to third parties.

Loading diagram...
Decision Gateway for Evaluating and Relying on the Work of Others (GIAS Standard 9.5)
Test Your Knowledge

An internal audit team relies on the testing performed by an external cybersecurity firm regarding enterprise cloud access controls. Six months later, a major security breach occurs due to an unpatched vulnerability in cloud access that the external firm failed to test properly. When the Audit Committee questions the Chief Audit Executive (CAE), what is the CAE's ultimate accountability under GIAS Standard 9.5?

A
B
C
D
Test Your Knowledge

A Chief Audit Executive is preparing an internal audit engagement covering the organization's corporate pension fund liabilities and plans to rely upon the valuation report issued by an independent external actuarial firm. Before placing reliance on the actuary's valuation, which procedure must the CAE execute first under GIAS Standard 9.5?

A
B
C
D
Test Your Knowledge

A national banking regulator completes a comprehensive statutory examination of a commercial bank, issuing a formal supervisory report with zero citations, penalties, or Matters Requiring Attention (MRAs) regarding consumer lending practices. How should the bank's Chief Audit Executive interpret this clean regulatory report during annual audit planning?

A
B
C
D