3.3 Types of Advisory Services
Key Takeaways
- Advisory services include risk/control training, system design input, due diligence support, data privacy advice, benchmarking, control assessments for improvement, and process mapping.
- Nature and scope of advisory work are agreed with the engagement client; deliverables are advice and facilitation, not reliance-grade opinions.
- Internal auditors must not assume management responsibilities when advising on systems, controls, or due diligence.
- Independence safeguards—different teams, cooling-off, disclosure—are required before later assuring the same subject matter.
- On the IAP exam, distinguish advisory ‘control assessments’ (improvement-focused advice) from assurance conclusions intended for board reliance.
Advisory Services in the Global Internal Audit Standards
Syllabus A6 covers types of advisory services and the independence implications that travel with them. Advisory work is a core way internal audit adds value: it brings risk and control expertise into projects early, builds organizational capability, and helps management improve processes before failures occur. The IAP exam tests whether you can recognize advisory types and spot when advice crosses into management responsibility or future objectivity impairment.
Recall the contrast from A4:
| Assurance | Advisory | |
|---|---|---|
| Goal | Independent conclusion | Improvement advice / facilitation |
| Scope setter | Internal audit (plan/mandate) | Client-agreed with internal audit |
| Typical output | Opinion/rating/conclusion | Recommendations, designs, training, maps |
Risk and Control Training
Risk and control training builds management and staff capability. Internal audit may deliver workshops on fraud red flags, control self-assessment techniques, risk appetite concepts, or how to document control evidence.
Characteristics:
- Learning objectives agreed with the client.
- Materials should be educational, not a disguised audit opinion on the trainees’ business unit.
- Attendance and feedback may be reported, but training is not assurance that trainees’ controls are effective.
Independence note: Training on a policy you did not own is usually low risk. If internal audit wrote the policy and trains on it and later assures compliance, disclose and segregate roles.
IAP scenario: Before peak season, a retailer asks internal audit to train store managers on cash-handling controls and skimming red flags. Delivering the curriculum and facilitating case discussions is advisory training—not a conclusion that store cash controls are effective.
System Design and Development Support
Internal audit often advises during system design and development (new ERP modules, claims systems, customer portals). Valuable input includes control requirements, segregation-of-duties design, audit logging needs, and go-live readiness considerations.
Healthy advisory posture:
- Recommend control objectives and design options.
- Review prototypes and highlight residual risks.
- Refuse to approve go-live, sign as system owner, or configure production access as if internal audit were IT operations.
Unhealthy posture (management responsibility):
- Choosing the final control design as the decision-maker.
- Implementing configurations in production.
- Accepting residual risk on behalf of management.
IAP scenario: During a new expense-system implementation, auditors advise that dual approval should be enforced systematically for amounts over a threshold and that managers should not approve their own expenses. Management decides the final threshold and owns configuration. That is appropriate advisory design support.
Due Diligence Advisory
Due diligence support helps management evaluate acquisitions, investments, new markets, or major vendors. Internal audit may review control environments of targets, assess fraud/compliance red flags, or evaluate integration risk—as advice to management, not as a fairness opinion for investors.
Clarify in the engagement agreement:
- Purpose (inform management decision).
- Limitations (restricted access to target data).
- That the work is advisory unless separately scoped as assurance for a defined user group.
IAP scenario: Management considering acquisition of a payment processor asks internal audit to review the target’s incident-response maturity and highlight integration risks. Findings are recommendations for the deal team—not an assurance opinion that the target’s controls are effective for board reliance post-close (that would be a later assurance engagement).
Data Privacy Advisory
Data privacy advisory helps management design or improve privacy controls: data inventories, retention schedules, consent mechanisms, vendor privacy clauses, and incident playbooks. This differs from privacy assurance, which concludes on whether privacy controls meet criteria.
Advisory examples:
- Facilitating a privacy impact assessment workshop.
- Advising on control gaps before a new marketing data platform launches.
- Helping draft a data classification scheme for management adoption.
Independence caveat: If internal audit designs the privacy control framework, a different team (or cooling-off plus disclosure) should perform subsequent privacy assurance.
Benchmarking
Benchmarking compares the organization’s practices, metrics, or control maturity to peers, industry standards, or leading practices. Internal audit may gather benchmark data, facilitate interpretation, and recommend improvement opportunities.
Benchmarking is advisory when the deliverable is “here is how you compare and what you might improve,” not “we conclude your controls are effective.” Criteria for any later assurance engagement must still be organization-approved standards—not informal peer anecdotes alone.
IAP scenario: A manufacturing CAE shares anonymized peer data on inventory cycle-count frequency and facilitates a workshop for operations leaders. The output is advisory insight; concluding that inventory controls are effective would require a separate assurance engagement with testing.
Internal Control Assessments (Advisory Mode)
This phrase confuses candidates because “control assessment” also describes assurance work. In advisory mode, an internal control assessment is performed to help management improve, often via control self-assessment (CSA) facilitation, gap analysis against a framework, or readiness reviews before an external exam or go-live.
Distinguishing cues in exam stems:
| Cue | Lean toward |
|---|---|
| “Conclude / opinion / rate effectiveness for the audit committee” | Assurance |
| “Facilitate management’s self-assessment / help prepare / recommend improvements without an opinion” | Advisory |
| “Board relies on our rating” | Assurance |
| “Client sets scope to get advice before launch” | Advisory |
IAP scenario: Before an external PCI assessment, management asks internal audit to walk through cardholder-data controls, help identify gaps, and suggest remediation priorities—without issuing an effectiveness opinion. That is an advisory internal control assessment (readiness support).
Process Mapping
Process mapping documents how work actually flows—inputs, activities, handoffs, systems, and controls. Internal audit may facilitate mapping workshops to clarify ownership, uncover bottlenecks, and highlight control gaps for management action.
Process maps are powerful planning tools for later assurance, but the mapping engagement itself is typically advisory unless the CAE scopes it as part of an assurance engagement with a conclusion.
Best practices:
- Validate maps with process owners.
- Separate “as-is” from “should-be” designs.
- Avoid becoming the ongoing process owner or SOP writer of record if that creates management responsibility.
IAP scenario: A university asks internal audit to facilitate mapping of student refund processes after complaints about delays. Auditors run workshops, produce swimlane diagrams, and recommend control points. Management owns process changes—advisory process mapping.
Independence Caveats Across All Advisory Types
Apply these rules consistently:
- Do not take management responsibility. Approving transactions, selecting risk responses as the owner, implementing controls in production, or directing staff are management duties.
- Document the advisory nature in the engagement agreement and communications.
- Anticipate future assurance. If assurance on the same area is likely, plan staffing safeguards now.
- Disclose impairments to the CAE and, when required, the board when safeguards cannot eliminate the threat to objectivity.
- Stay within competence. Bring specialists for complex IT, actuarial, or legal questions; advisory does not lower the competence bar.
Quick Reference: Advisory Types and Red Flags
| Advisory type | Healthy example | Independence red flag |
|---|---|---|
| Risk/control training | Workshop on fraud indicators | Training used as substitute for required assurance |
| System design/development | Recommend SOD rules | Auditor configures production roles |
| Due diligence | Risk insights for deal team | Marketing the report as an investor assurance opinion |
| Data privacy | Advise on retention design | Auditor becomes privacy officer decision-maker |
| Benchmarking | Peer comparison workshop | Treating peer averages as assurance criteria without testing |
| Internal control assessment | Readiness gap analysis | Calling it “effective” for board reliance without evidence standards |
| Process mapping | Facilitate as-is maps | Auditor owns and runs the process afterward |
Choosing Advisory vs Assurance in Mixed Requests
Management often asks for “a review.” Translate the request:
- If they need help improving before go-live → advisory (design, mapping, training, readiness assessment).
- If the board needs an independent conclusion after go-live → assurance (risk/control, IT, compliance, reporting).
- If they want both → sequence them, segregate teams, and document the distinction in two engagement agreements.
Mastering A6 is less about memorizing a laundry list and more about recognizing purpose, scope-setter, deliverable, and independence impact in each scenario.
Management asks internal audit to facilitate workshops that document the as-is procure-to-pay flow, highlight control gaps, and recommend a future-state design. Management will decide which changes to implement. This engagement is best described as:
An internal auditor advising on ERP design personally configures production segregation-of-duties rules and approves go-live as the control owner. What is the primary problem?
Before a new customer-data platform launches, management asks internal audit to help identify privacy control gaps and recommend remediation—without issuing an effectiveness opinion. Six months later, the audit committee wants a reliance-grade conclusion on those same privacy controls. What should the CAE do?