Three separate teams tested the same vendor-onboarding control last quarter: external audit, compliance, and internal audit. The business unit answered the same 40 questions three times, and one high-risk cloud migration went untested by anyone. That is an assurance coordination failure, and it is a planning defect.
The internal audit plan must reflect what other providers already cover. Without coordination you get two failure modes: duplication, which burns hours and irritates the business, and gaps, where every provider assumes someone else has the area. The chief audit executive (CAE) coordinates with other providers and considers relying on their work so the plan gives the board a picture of total assurance coverage, not just internal audit's slice.
KEY: Coordination changes the plan's shape. Where another provider's work is adequate, internal audit narrows scope or reduces testing. Where nothing is covered, internal audit adds the area. The board sees combined coverage, with gaps named.
Sort providers by whether they sit inside or outside the organization. The Three Lines Model gives you the map: management owns and controls risk in the first and second lines...
Common mistakes
- Equating "another provider tested it" with reliance. Existence of work is not the criterion. The criteria for deciding whether another provider's work can be relied on are competence, objectivity, and work quality (scope, evidence, methodology, supervision, currency), each evaluated and documented.
- Assuming external audit's scope matches yours. External audit scopes to financial statement materiality. In Example 2, that excluded 4 of 7 applications with real operational risk.
- Relying on a second-line function that owns the control. Compliance monitoring a program compliance itself designed and runs fails objectivity. The organizational position, not the job title, decides.
Bottom line
- Internal providers: risk management, compliance, quality assurance, environmental health and safety, information security, privacy, and management self-assessment programs.
- External providers: external auditors, regulators and examiners, certification and attestation bodies including service-organization control reports, and specialist consultants.
- Second-line assurance is management's assurance; only internal audit provides independent assurance under the Three Lines Model.
- Coordination methods: assurance map, shared risk assessments and plans, periodic coordination meetings, aligned timing, shared working papers and reports, common taxonomy and ratings, combined coverage reporting to the board.
Exam shortcut
Run the reliance stem through three gates in order: competence, objectivity, work quality. Most stems fail at gate two or three, and the failure is planted in one clause. Watch for "reports to the process owner" (objectivity), "materiality" or "financial statement scope" (scope adequacy), and any date more than a few months before your engagement (currency).
The full lesson (about 2,031 words, 14 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 3
Browse all free CIA Part 3 lessons or jump into free CIA Part 3 practice questions.