CORAA
Resources · IA Co-Sourcing

Co-sourcing evaluation scorecard.

Internal audit co-sourcing means the organisation retains internal audit ownership while using an external firm or specialist for defined work such as overflow reviews, technical domains, analytics or location support.

Internal audit co-sourcing should be a controlled delivery decision, not an emergency procurement choice. Use it when the annual plan needs specialist skill, temporary capacity, geographic reach or analytics support, while the CAE or internal audit owner retains methodology, quality review and Audit Committee accountability.

Check capacity gapReview workpaper quality
Downloads

Co-sourcing evaluation workbook workbook

Download the Excel/PDF pack for co-source decisioning, provider scorecard, conflict checks, SLA/reporting cadence, quality review and transition planning.

Decision matrix

When co-sourcing makes sense co-source

Capacity gap

Use co-sourcing when the approved plan exceeds available internal hours after realistic utilisation, buffer and quarter loading.

Specialist skill gap

Use specialists for ITGC, cybersecurity, treasury, tax, data analytics, AI governance, ESG or sector-specific reviews.

Independence and objectivity

Check whether the provider has management responsibilities, implementation work, financial interests or relationships that impair internal audit reliance.

Knowledge retention

Decide which work should stay internal so the IA team does not lose process understanding, stakeholder access or issue history.

Quality and methodology

Require work programmes, evidence standards, review notes, exception grading and report format to fit the IA methodology.

Data access and confidentiality

Confirm data classification, secure transfer, retention, deletion, subcontracting, AI-tool use and client confidentiality expectations.

Scorecard

How to score the provider evaluate

Internal audit methodology

Risk-based planning, SOW, RCM, sampling, evidence, issue rating, reporting, ATR and QAIP fit.

Domain capability

Process, industry, IT, cyber, tax, treasury, data analytics, AI governance or regulatory specialist depth.

Team and supervision

Named partner/lead, reviewer depth, staff mix, continuity, escalation route and replacement plan.

Technology and data handling

Secure evidence platform, report reliability discipline, analytics traceability, AI-use controls and retention rules.

Independence and conflicts

No statutory-auditor conflict, conflicting implementation role, management responsibility, prohibited relationship or undisclosed subcontracting.

Commercial and SLA fit

Clear deliverables, turnaround time, meeting cadence, draft report timeline, rework handling and fee model.

SLA model

What to lock before fieldwork govern

Scope confirmation

Signed SOW, exclusions, locations, period, systems, deliverables, stakeholder list and evidence access route.

Kickoff and PBC

Entrance meeting, RACI, data request list, due dates, escalation thresholds and weekly blocker review.

Fieldwork cadence

Status calls, workpaper review, exception validation, management discussion and draft observation log.

Quality review

Manager/partner review notes, evidence completeness, rating consistency, report wording and independence sign-off.

Reporting

Draft report, management response, final report, Audit Committee summary, limitation disclosure and issue owner confirmation.

Knowledge transfer

Process notes, RCM updates, monitoring candidates, recurring issue themes and next-period planning handoff.

Red flags

Where co-sourcing fails avoid

Same provider built the control

Implementation and assurance roles may conflict unless safeguards and scope boundaries are clear.

Only resumes are evaluated

Named staff matter, but the provider scorecard should test methodology, supervision, evidence quality and data handling.

No access to working papers

A report without reviewable evidence is weak for CAE/Audit Committee reliance.

Subcontracting is undisclosed

Fourth-party work can create confidentiality, quality, availability and accountability gaps.

Fee model rewards shallow work

Very low fixed fees may push checklist reporting instead of evidence-backed internal audit procedures.

No exit or transition plan

The IA function becomes dependent on one provider without retaining taxonomy, RCMs, issues and monitoring logic.

Authority anchors

Sources to verify before appointment cite

IIA Global Internal Audit Standards

Use the Standards for board/CAE oversight, managing the internal audit function, due professional care, quality and external service provider coordination.

IIA Coordination and Reliance Guidance

Use IIA guidance when internal audit coordinates with other providers or relies on work performed outside the core IA team.

ICAI SIA 210, 220, 240, 350, 360, 370 and 530

For Indian internal audit files, connect co-sourced delivery to function management, planning, expert work, review, supervision, communication, reporting and third-party service-provider considerations.

Companies Act Sections 138 and 144, and Rule 13

For covered Indian companies, align co-sourced work with the approved internal audit scope and verify that the statutory auditor or prohibited related/network arrangement is not providing internal audit services.

Product reuse

Website resource now, provider workflow later later

This public resource can become specification input for the separate Internal Audit product build: provider scorecards, scope split, conflict checks, SLA tracking, quality review and knowledge-transfer records.

Provider scorecard

Vendor management: Capability score, independence status, methodology fit, data controls, SLA and commercial rating.

Scope split

Annual plan builder: In-house work, co-sourced work, specialist work, advisory work, reviewer owner and committee rationale.

Conflict checklist

Governance setup: Relationship, implementation role, management responsibility, subcontracting, safeguards and sign-off.

SLA tracker

Engagement workflow: Milestones, PBC due dates, review turnarounds, blocker ageing, report dates and escalation triggers.

Quality review log

QAIP module: Workpaper review status, evidence gaps, rating override, report review and partner sign-off.

Knowledge transfer pack

Product onboarding: RCM updates, taxonomy changes, monitoring candidates, issue themes and retained templates.

Related resources

Use this with planning and quality review next

Internal Audit Resource Capacity Planner

Quantify the hours and specialist gaps before deciding what to co-source.

Internal Audit Annual Plan Generator

Mark in-house, co-sourced and specialist reviews in the approved annual plan.

Internal Audit Charter & Mandate

Confirm authority, reporting line, evidence access and escalation before external delivery begins.

Internal Audit Quality Review Checklist

Review co-sourced workpapers before observations and reports are issued.

Third-Party Outsourcing Risk Guide

Use this when the audit scope is the company's vendors, not the IA provider itself.

CA Firms Internal Audit Services

See how CA firms can package SOW, PBC, RCM, reporting and monitoring retainers.

FAQs

Co-sourcing questions answered

What is internal audit co-sourcing?

Internal audit co-sourcing means the organisation keeps internal audit oversight and ownership while using an external firm or specialist for selected reviews, skills, locations, analytics or overflow capacity.

What should be evaluated before appointing an internal audit partner?

Evaluate methodology, domain capability, named team, supervision, independence, conflicts, data handling, technology controls, SLA, fee model, working-paper access and knowledge-transfer plan.

Can a CA firm provide internal audit services under Section 138?

Section 138 permits prescribed companies to appoint an internal auditor, who may be a chartered accountant, cost accountant or other professional decided by the Board. However, Section 144 prohibits the statutory auditor from providing internal audit services to the company directly or indirectly. Appointment facts, independence, network relationships and professional obligations should be checked for each entity and engagement.

How is co-sourcing different from outsourcing the whole internal audit function?

In co-sourcing, the internal audit function retains ownership, planning, methodology and stakeholder accountability while external specialists support defined work. Full outsourcing shifts more delivery responsibility outside, but oversight cannot be abdicated.