7.1 Sourcing Strategy: In-House vs Co-Sourcing vs Full Outsourcing

Key Takeaways

  • Global Internal Audit Standards (GIAS) Standard 10.2 mandates that the Chief Audit Executive (CAE) may engage external service providers to support or supplement internal audit activities, but the CAE retains non-delegable accountability for the function's conformance with the Standards, deliverable quality, and fulfillment of the audit charter.
  • Sourcing models exist on a continuum: pure in-house (high institutional knowledge, fixed overhead), co-sourcing via staff augmentation ('lending hands' under direct internal supervision), co-sourcing via managed services ('buying outcomes' managed through SLAs), and full outsourcing (entire function contracted to a third party).
  • The economic and operational decision to co-source centers on specialized technical skill scarcity (such as cloud security, AI model validation, actuarial reserving, and digital forensics), peak-load capacity flexibility, and geographic distribution across global operations.
  • When an internal audit function is completely outsourced to an external service provider, the organization's governing body must still designate a senior organizational executive to oversee the contract, monitor performance, and maintain governance accountability.
Last updated: September 2026

7.1 Sourcing Strategy: In-House vs Co-Sourcing vs Full Outsourcing

[!NOTE] GIAS Standard 10.2 Mandate: Under the Global Internal Audit Standards (Domain IV: Managing the Internal Audit Function, Standard 10.2 Operational Planning and Methodologies), the Chief Audit Executive (CAE) must establish operational plans and methodologies to achieve the internal audit plan and manage the internal audit activity effectively. Standard 10.2 explicitly governs the utilization of external service providers, establishing that while the CAE may leverage external specialists or professional service firms to execute internal audit work, the CAE remains fundamentally accountable for ensuring the internal audit function conforms with the Standards and fulfills the mandate set forth in the internal audit charter.

In the modern enterprise risk landscape, internal audit leaders face unprecedented operational complexity. Organizations are rapidly adopting cloud-native infrastructures, deploying artificial intelligence and machine learning algorithms, navigating intricate international data privacy regulations, and executing complex cross-border transactions. Simultaneously, corporate boards and audit committees demand lean, cost-effective internal audit functions capable of flexing capacity quickly in response to emerging organizational risks and economic shifts.

To satisfy these demanding expectations, Chief Audit Executives (CAEs) must approach talent and delivery models strategically rather than relying solely on traditional full-time hiring. Sourcing strategy is no longer a temporary staffing reaction; it is a fundamental governance discipline. The CAE must strategically select and integrate four core sourcing models: pure in-house staffing, co-sourcing via staff augmentation, co-sourcing via managed services, and full outsourcing. Determining the appropriate sourcing mix requires balancing organizational risk profiles, specialized skill availability, long-term cost structures, and the immutable professional standards established by The Institute of Internal Auditors (IIA).


The Non-Delegable Accountability of the CAE

A fundamental doctrine emphasized throughout the Certified Internal Auditor (CIA) examination syllabus is that operational execution can be outsourced, but governance accountability cannot be delegated.

Under GIAS Standard 10.2 and Domain III (Governing the Internal Audit Function), the CAE may delegate the fieldwork, technical testing, and draft documentation of an internal audit engagement to external service providers. However, the CAE retains sole, ultimate accountability for the performance, integrity, and credibility of the internal audit activity. This non-delegable responsibility encompasses several vital governance dimensions:

  • Conformance with Professional Standards: The CAE must verify that all audit work performed by third parties complies strictly with the IIA Code of Ethics and Global Internal Audit Standards. An external firm's failure to adhere to the Standards is legally and professionally attributed to the CAE.
  • Charter Mandate Fulfillment: The CAE must ensure that external engagements align directly with the board-approved internal audit charter and satisfy the commitments detailed in the annual risk-based audit plan.
  • Quality of All Deliverables: The CAE is responsible for the thoroughness, accuracy, and evidential backing of all findings, conclusions, and recommendations. External specialists report their observations to the CAE; only the CAE (or authorized in-house internal audit leadership) has the authority to issue formal audit communications to senior management and the board.
  • Quality Assurance and Improvement Program (QAIP): The CAE must incorporate all external service providers into the department's ongoing monitoring and periodic quality assessments (GIAS Domain V), ensuring consistent methodology adherence across in-house and contracted teams.

Full Outsourcing Governance Requirements

Even in organizations where the entire internal audit function is outsourced to an external professional services firm, governance standards require that the organization's governing body (audit committee) and executive leadership designate an internal, senior corporate executive—such as the Chief Risk Officer (CRO), Chief Financial Officer (CFO), or General Counsel—to act as the internal sponsor. This internal liaison manages the external contract, monitors provider independence, assesses deliverable quality, and provides a continuous governance bridge to the audit committee.


Sourcing Decision Drivers & Strategic Criteria

When evaluating whether to build internal capabilities or engage external service providers, the CAE evaluates four primary operational drivers:

1. Technical Specialization & Niche Skill Scarcity

Modern assurance frequently requires highly technical, specialized capabilities that are difficult to recruit, costly to retain, and needed only sporadically. Examples include:

  • Cybersecurity & Penetration Testing: Red-teaming, zero-day vulnerability exploitation, and operational technology (OT/SCADA) security.
  • Artificial Intelligence & Algorithmic Validation: Evaluating model drift, training data provenance, algorithmic bias, and autonomous decision pipelines.
  • Actuarial and Quantitative Modeling: Complex insurance reserving, financial instrument valuation, and derivative stress testing.
  • Forensic Technology & Investigations: eDiscovery extraction, chain-of-custody digital evidence collection, and covert data reconstruction.

If an organization requires a quantitative financial engineer for only 120 hours annually to validate asset-backed valuation models, hiring a permanent full-time specialist at market salary creates excessive fixed overhead and inevitable skill stagnation. Co-sourcing provides instant access to world-class subject matter experts (SMEs) whose technical capabilities are continuously sharpened across multiple industry engagements.

2. Geographic Dispersion & Global Footprint

Multinational enterprises often operate production plants, distribution warehouses, or commercial offices in dozens of international jurisdictions. Dispatching home-office audit teams to remote overseas locations generates prohibitive travel expenditures, visa delays, language barriers, and cultural misunderstandings. Engaging an external service provider with an established in-country network provides immediate access to local auditors who are fluent in the native language, familiar with regional business customs, and expert in local statutory and tax regulations.

3. Peak-Load Capacity & Workforce Elasticity

Internal audit workload is naturally cyclical. Activities such as year-end internal controls testing for Sarbanes-Oxley (SOX) compliance, major enterprise resource planning (ERP) go-live validation gates, and post-merger integration reviews generate severe temporary resource deficits. Sizing the permanent in-house staff to meet peak operational demand results in expensive idle capacity during low-intensity quarters. External service providers provide workforce elasticity, enabling the CAE to rapidly scale team size during peak windows and contract immediately upon project completion.

4. Cost Structure Dynamics: Fixed Overhead vs. Variable OpEx

Permanent headcount carries substantial, inflexible fixed costs: base salaries, annual incentive bonuses, health benefits, retirement plans, payroll taxes, recruiting fees, severance liabilities, and annual Continuing Professional Education (CPE). In contrast, co-sourcing and outsourcing convert fixed personnel overhead into variable, engagement-specific operating expenditures (OpEx) that can be adjusted or suspended based on quarterly budget constraints.


Comparative Analysis of the Four Sourcing Models

The CAE must evaluate each sourcing vehicle across strategic, financial, and operational criteria:

Evaluation DimensionPure In-House StaffingCo-Sourcing: Staff AugmentationCo-Sourcing: Managed ServicesFull Outsourcing
Operating Model100% internal, permanent employees dedicated to the organization.External individual contractors integrated directly into in-house teams.External professional firm delivers an entire specialized audit sub-program.Entire internal audit activity contracted to a third-party accounting or consulting firm.
Supervisory DirectionDirect, daily operational supervision by internal audit management.Direct, daily supervision by internal audit management; "lending hands."External provider manages daily execution against contracted SLAs; "buying outcomes."External engagement partner directs execution; internal corporate liaison oversees contract.
Methodology & ToolsOrganization's proprietary audit manual and electronic workpaper system.Organization's audit manual, workpaper templates, and eWMS software.Blended; external firm uses specialized tools approved by the CAE.External service provider's proprietary audit methodology and software platforms.
Institutional KnowledgeDeep, cumulative understanding of organizational culture, politics, and systems.Moderate; contractors gain project-level context but depart upon completion.Moderate-to-High; external firm maintains dedicated core team across multi-year contract.Low-to-Moderate; vulnerable to provider staff turnover and commercial conflicts.
Cost ProfileHigh fixed overhead (salaries, benefits, training); zero vendor profit margin.Variable; premium hourly billing rates without long-term overhead obligations.Predictable fixed-fee or retainer tied to milestone deliverable approvals.Recurring contract fee; converts entire internal audit department cost into OpEx.
Optimal ApplicationCore operational, financial, and compliance audits; sustained risk monitoring.Unexpected staff leaves, temporary peak-load surges, SOX control execution.Specialized disciplines (cybersecurity, IT audit, actuarial, ESG, fraud investigations).Small-to-midsize entities lacking critical mass for a standalone in-house department.

Co-Sourcing Breakdown: Staff Augmentation vs. Managed Services

A vital distinction tested on the CIA Part 3 exam is the operational difference between the two primary co-sourcing variations:

  • Staff Augmentation ("Lending Hands"): The CAE contracts individual auditors from a professional services firm on an hourly rate basis. These external auditors report directly to the in-house audit manager, follow the internal audit department's audit programs, log hours in internal tracking systems, and store working papers in the client's electronic workpaper management system (eWMS). The external firm assumes zero deliverable risk; management retains direct operational control.
  • Managed Services ("Buying Outcomes"): The CAE engages an external firm to execute an entire specialized audit domain (e.g., global IT audit or derivatives review). The external firm provides the audit methodology, specialized technology, subject matter experts, and day-to-day engagement management. The relationship is governed through a formal Statement of Work (SOW) with defined Service Level Agreements (SLAs), delivery milestones, and quality criteria. The CAE evaluates deliverables at milestone gates rather than managing daily tasks.

The Strategic Sourcing Decision Protocol

To establish an optimal sourcing balance, the CAE applies a structured decision protocol for every element in the audit universe:

  1. Core Competency Assessment: Is the audit area central to the organization's unique competitive strategy, operational culture, or core financial transactions? If yes, maintain in-house staffing to build and preserve institutional memory.
  2. Frequency and Duration Quantification: Is the specialized skill required continuously throughout the year, or only for a condensed engagement window? If annual demand is under 250 hours, co-sourcing is mathematically and operationally superior to hiring.
  3. Market Recruitment Feasibility: Can the organization compete with top consulting firms on compensation and career progression to attract elite talent (e.g., cloud security architects)? If recruitment is unfeasible, managed co-sourcing provides immediate elite talent without disrupting internal corporate salary structures.
  4. Independence and Confidentiality Constraints: Does the audit topic involve extreme executive sensitivity (e.g., C-suite fraud or board governance)? The CAE must determine whether an external firm provides superior perceived objectivity or poses unacceptable confidentiality risks.
Loading diagram...
Internal Audit Sourcing Strategy Decision Matrix
Test Your Knowledge

The Chief Audit Executive (CAE) of a multinational bank co-sources the annual cloud cybersecurity and infrastructure audit to a specialized external consulting firm. The consulting firm performs the fieldwork, compiles the working papers, and issues a final draft report identifying no critical vulnerabilities. Three months later, a catastrophic cloud data breach occurs in a repository that the external consultants failed to test due to an improperly restricted sampling approach. In accordance with GIAS Standard 10.2, how is accountability assigned for this audit failure?

A
B
C
D
Test Your Knowledge

An internal audit department needs to conduct an annual validation of complex algorithmic trading and artificial intelligence pricing models. The audit requires an expert quantitative financial analyst with deep machine learning competencies. Financial projections show that this technical expertise will be utilized for approximately 90 hours per year during annual testing. Which sourcing model represents the most sound operational and financial strategy for the CAE?

A
B
C
D
Test Your Knowledge

A CAE is assessing two potential co-sourcing proposals to assist with the audit of a multi-year ERP migration. In Vendor Arrangement Alpha, the external firm provides three senior IT auditors who report directly to the in-house internal audit manager, follow the internal audit department's audit manual, and document work directly in the organization's electronic workpapers. In Vendor Arrangement Beta, an external professional services firm assumes full responsibility for delivering a pre-implementation control readiness assessment, managing its own daily testing schedules and delivering a final finding package against contracted Service Level Agreements (SLAs). How should the CAE classify Vendor Arrangements Alpha and Beta?

A
B
C
D