A chief audit executive inherits a function where 92% of hours go to assurance, the co-sourcing contract with an accounting firm has never been performance-reviewed, and the quality program consists of one internal assessment done four years ago. Every one of those is a testable defect in how internal audit operations are planned, organized, directed, and monitored.
Planning sets the plan and the resources. Organizing assigns the work to people, including managing external providers. Directing supervises the work while it happens. Monitoring internal audit operations measures whether the function performed and conforms. The chief audit executive (CAE) owns all four and cannot delegate accountability for any of them, even where the labor is bought from outside.
An external service provider is any firm or individual outside the organization who performs internal audit work: a full outsource, a co-source arrangement for a shared engagement, or a specialist engaged for one skill (actuarial, forensic, penetration testing, valuation). The Global Internal Audit Standards let you buy capability. They do not let you buy away responsibility.
Common mistakes
- Treating outsourcing as transferring responsibility. A fully outsourced function still needs a CAE-equivalent inside the organization who owns the plan, reviews the work, and reports conformance.
- Confusing the external assessment with the external financial audit. The external quality assessment evaluates the internal audit function against the Standards. It is not performed by the financial statement auditor as part of the audit, and 5 years is the maximum interval, not a target.
- Letting advisory work drift without a mandate. Accepting 3,100 hours of requests against a 2,400-hour ceiling starves assurance coverage. Report the gap; do not silently absorb it.
Bottom line
- External providers: the CAE keeps responsibility for the plan, results, and conformance; evaluate competence, independence, Standards conformance, workpaper ownership, and confidentiality before engaging.
- Supervision of providers matches supervision of employees: approve the program, review workpapers, sign findings, and issue under internal audit's process.
- QAIP has two components: internal assessments (ongoing monitoring plus periodic self-assessment) and external assessments at least every five years by an assessor independent of the organization.
- Nonconformance affecting the function's overall scope or operation must be disclosed to senior management and the board with impact and corrective plan.
Exam shortcut
When a stem mentions any outside firm doing internal audit work, the answer almost always contains the phrase "remains responsible" or "reviews and approves." Eliminate options that let the provider report independently or that treat the contract as a transfer of accountability. When a stem gives a date for the last external assessment, subtract immediately.
The full lesson (about 2,529 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.