CORAA

SIA 530 — Third Party Service Provider

ICAI Internal Audit Standards Board · October 2022 compendium · 500 series
Reviewed 1 October 2026

SIA 530 is about independent assurance over operations the entity has outsourced to third parties. The internal auditor assesses the risk of outsourcing, especially information security risk, and evaluates whether controls at the third party are adequate.

This page covers SIA 530 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

What the internal auditor has to do

  • Identify the operations the entity has outsourced to third parties.
  • Assess the risk of that outsourcing, with particular attention to information security.
  • Evaluate whether controls at the third party are adequate.

How SIA 530 shows up in the internal audit file

  • Third parties included in the audit universe. SIA 220 paras 3.4 and 4.4 count third parties among the auditable units.
  • The outsourcing risk assessment, including information security.
  • The evaluation of controls at the third party and the conclusion reached.

Common mistakes in practice

  • Leaving outsourced operations out of the audit universe because another company runs them.
  • Assessing the commercial side of the arrangement and ignoring information security.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Related standards

SIA 220 · Conducting Overall Internal Audit PlanningSIA 520 · Internal Auditing in an Information Technology EnvironmentSIA 240 · Using the Work of an Expert

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. The effective-date clause in each 2019 standard said it applied to internal audits beginning on or after a date to be notified by the Council of ICAI.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 530

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 530 into practice. Free to use.

Third-Party / Outsourcing Risk Audit Checklist →Third-party outsourcing risk guide →

SIA 530 — frequently asked

What is SIA 530?

SIA 530, Third Party Service Provider, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 530 is about independent assurance over operations the entity has outsourced to third parties. The internal auditor assesses the risk of outsourcing, especially information security risk, and evaluates whether controls at the third party are adequate.

Is SIA 530 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 530 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 530 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 530?

Third parties included in the audit universe. SIA 220 paras 3.4 and 4.4 count third parties among the auditable units. The outsourcing risk assessment, including information security. The evaluation of controls at the third party and the conclusion reached.

← Previous
SIA 520 — Internal Auditing in an Information Technology Environment
Next →
SIA 5 — Sampling