A finance director asks internal audit to sit in on the design of a new payables system. Say yes and you gain influence early. Say yes the wrong way and you disqualify yourself from ever auditing it.
Advisory services are internal audit engagements where the nature and scope are agreed with the client and the aim is to improve governance, risk management, or control processes. They differ from assurance engagements in one structural way. In assurance, internal audit forms an independent conclusion and there are three parties: the process owner, the auditor, and the user of the conclusion (usually the board). In advisory, there are typically two parties: the auditor and the client requesting the advice. No independent opinion is issued to a third party.
The Global Internal Audit Standards treat advisory work as part of internal audit's mandate, not a departure from it. The internal audit charter should state that advisory services are within scope, and the chief audit executive considers advisory requests when building the risk-based plan.
Common mistakes
- Assuming objectivity relaxes in advisory work. It does not. The parties and scope-setting change; the objectivity requirement is identical.
- Treating a signature as harmless. Signing a control readiness form, approving a privacy impact assessment, or authorizing a system for production is management approval regardless of how minor it looks.
- Setting the benchmark target. Presenting a 14-day versus 5-day gap is advisory. Declaring that 5 days is the goal is a management decision.
Bottom line
- Advisory scope: nature and scope agreed with the client, two parties, no independent opinion to a third party; assurance is three parties with an independent conclusion.
- Charter and plan: advisory services must be authorized in the internal audit charter, and significant advisory work is reflected in the risk-based plan reported to the board.
- Named advisory services: risk and control training, system design and development input, due diligence, data privacy advice, benchmarking, internal control assessment support, and process mapping.
- Objectivity: unchanged in advisory engagements; only the reporting model and scope-setting differ.
Exam shortcut
Scan the stem for a verb attached to internal audit. Analyze, review, facilitate, train, map, benchmark, and recommend are safe. Decide, approve, sign, implement, configure, own, and serve as are barred. The verb, not the topic, decides the answer. When two answer choices both sound reasonable, pick the one that keeps management holding the pen.
The full lesson (about 2,569 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 6
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.