Internal audit co-sourcing means the organisation retains internal audit ownership while using an external firm or specialist for defined work such as overflow reviews, technical domains, analytics or location support.
Internal audit co-sourcing should be a controlled delivery decision, not an emergency procurement choice. Use it when the annual plan needs specialist skill, temporary capacity, geographic reach or analytics support, while the CAE or internal audit owner retains methodology, quality review and Audit Committee accountability.
Download the Excel/PDF pack for co-source decisioning, provider scorecard, conflict checks, SLA/reporting cadence, quality review and transition planning.
Use co-sourcing when the approved plan exceeds available internal hours after realistic utilisation, buffer and quarter loading.
Use specialists for ITGC, cybersecurity, treasury, tax, data analytics, AI governance, ESG or sector-specific reviews.
Check whether the provider has management responsibilities, implementation work, financial interests or relationships that impair internal audit reliance.
Decide which work should stay internal so the IA team does not lose process understanding, stakeholder access or issue history.
Require work programmes, evidence standards, review notes, exception grading and report format to fit the IA methodology.
Confirm data classification, secure transfer, retention, deletion, subcontracting, AI-tool use and client confidentiality expectations.
Risk-based planning, SOW, RCM, sampling, evidence, issue rating, reporting, ATR and QAIP fit.
Process, industry, IT, cyber, tax, treasury, data analytics, AI governance or regulatory specialist depth.
Named partner/lead, reviewer depth, staff mix, continuity, escalation route and replacement plan.
Secure evidence platform, report reliability discipline, analytics traceability, AI-use controls and retention rules.
No statutory-auditor conflict, conflicting implementation role, management responsibility, prohibited relationship or undisclosed subcontracting.
Clear deliverables, turnaround time, meeting cadence, draft report timeline, rework handling and fee model.
Signed SOW, exclusions, locations, period, systems, deliverables, stakeholder list and evidence access route.
Entrance meeting, RACI, data request list, due dates, escalation thresholds and weekly blocker review.
Status calls, workpaper review, exception validation, management discussion and draft observation log.
Manager/partner review notes, evidence completeness, rating consistency, report wording and independence sign-off.
Draft report, management response, final report, Audit Committee summary, limitation disclosure and issue owner confirmation.
Process notes, RCM updates, monitoring candidates, recurring issue themes and next-period planning handoff.
Implementation and assurance roles may conflict unless safeguards and scope boundaries are clear.
Named staff matter, but the provider scorecard should test methodology, supervision, evidence quality and data handling.
A report without reviewable evidence is weak for CAE/Audit Committee reliance.
Fourth-party work can create confidentiality, quality, availability and accountability gaps.
Very low fixed fees may push checklist reporting instead of evidence-backed internal audit procedures.
The IA function becomes dependent on one provider without retaining taxonomy, RCMs, issues and monitoring logic.
This public resource can become specification input for the separate Internal Audit product build: provider scorecards, scope split, conflict checks, SLA tracking, quality review and knowledge-transfer records.
Vendor management: Capability score, independence status, methodology fit, data controls, SLA and commercial rating.
Annual plan builder: In-house work, co-sourced work, specialist work, advisory work, reviewer owner and committee rationale.
Governance setup: Relationship, implementation role, management responsibility, subcontracting, safeguards and sign-off.
Engagement workflow: Milestones, PBC due dates, review turnarounds, blocker ageing, report dates and escalation triggers.
QAIP module: Workpaper review status, evidence gaps, rating override, report review and partner sign-off.
Product onboarding: RCM updates, taxonomy changes, monitoring candidates, issue themes and retained templates.
Internal audit co-sourcing means the organisation keeps internal audit oversight and ownership while using an external firm or specialist for selected reviews, skills, locations, analytics or overflow capacity.
Evaluate methodology, domain capability, named team, supervision, independence, conflicts, data handling, technology controls, SLA, fee model, working-paper access and knowledge-transfer plan.
Section 138 permits prescribed companies to appoint an internal auditor, who may be a chartered accountant, cost accountant or other professional decided by the Board. However, Section 144 prohibits the statutory auditor from providing internal audit services to the company directly or indirectly. Appointment facts, independence, network relationships and professional obligations should be checked for each entity and engagement.
In co-sourcing, the internal audit function retains ownership, planning, methodology and stakeholder accountability while external specialists support defined work. Full outsourcing shifts more delivery responsibility outside, but oversight cannot be abdicated.