Internal audit co-sourcing is usually sold as a resourcing decision. The rules treat it as an independence question first.
The New York Stock Exchange tells listed companies they may hand the internal audit function to an outside provider, and in the same sentence names the one provider they may not use. The SEC rule and the AICPA Code police that same relationship for public and private companies, and they do it differently.
The internal audit standards add a condition of their own: whoever does the testing, the function stays yours.
What Internal Audit Co-Sourcing Is, and How It Differs From Outsourcing
Co-sourcing keeps your internal audit function in place and buys outside help for parts of it. Outsourcing hands the function over.
The standards give the outside party a name. In the Global Internal Audit Standards, an external service provider is a resource from outside the organization that provides relevant knowledge, skills, experience or tools to support internal audit services. The same document says the standards apply whether an organization employs internal auditors directly, contracts them through an external service provider, or both.
The practical line is not the share of hours. It is who holds the chief audit executive role. That person is responsible for conformance with the standards whether directly employed by the organization or contracted through an external service provider, and the board keeps the responsibility to support and oversee the function either way.
So ask the question your contract will not answer. If a provider supplies testers and your own chief audit executive still sets the plan, that is co-sourcing. If the provider's partner is the one answering the audit committee, you have moved the role, and the duties travel with the role.
Your Own Auditor Is the One Provider the Rules Restrict
Independence restrictions fall hardest on one provider, the firm that already audits your financial statements. The limits read differently depending on which rulebook you sit under.
The SEC Rule for Public Companies
17 CFR 210.2-01 lists the non-audit services that cost an accountant its independence. Internal audit outsourcing services sits at paragraph (c)(4)(v): any internal audit service that has been outsourced by the audit client that relates to the audit client's internal accounting controls, financial systems, or financial statements, unless it is reasonable to conclude that the results of these services will not be subject to audit procedures during an audit of the audit client's financial statements.
Read the exception rather than the headline. The test is not how much of the function moved, and not what the arrangement is called on the invoice. It is whether the work touches those three subjects and whether the results will be audited. Splitting an engagement between your team and your auditor's team does not change either answer.
The Audit Committee Has to Pre-Approve It
Permitted work still carries a governance step. Under 17 CFR 210.2-01(c)(7), an accountant is not independent of an issuer unless the engagement is approved by the audit committee before the accountant is engaged, or is entered into under pre-approval policies and procedures that are detailed as to the particular service and keep the audit committee informed of each service. Those policies may not delegate the audit committee's responsibilities to management.
The waiver is narrower than it sounds. For services other than audit, review or attest work, the same section waives pre-approval only where the aggregate amount of all such services is no more than five percent of total revenues paid by the audit client to its accountant in that fiscal year, the services were not recognized as non-audit services at the time of the engagement, and they are promptly brought to the audit committee and approved before the audit is completed. All three have to hold. It is a correction mechanism, not a spending allowance.
The NYSE Listing Standard Says It Out Loud
The exchange puts it plainly. In its order approving a transition period for new listings, the SEC set out what Section 303A.07(c) of the exchange's Listed Company Manual requires: any listed company subject to Section 303A.07 must have an internal audit function to provide management and the audit committee with ongoing assessments of the listed company's risk management processes and system of internal control. A listed company may choose to outsource this function to a third party service provider other than its independent auditor.
That same order approved a one-year transition period for companies listing through an initial public offering, a carve-out or a spin-off, so the function has to exist but not on day one. Sending the function outside is treated as ordinary. Your auditor is not a candidate to receive it.
What a CPA Firm May and May Not Do for an Attest Client
Private companies answer to the AICPA Code instead, and it is far more specific about the acts than the SEC rule is. If your co-source partner also performs your audit, review or other attest work, the Code is what shapes the engagement letter.
The Line Interpretation 1.295.150 Draws
The Internal Audit interpretation in the AICPA Code of Professional Conduct lets a firm assist an attest client with internal audit activities while barring it from effectively managing the function. What makes it useful for co-sourcing is the list underneath, which describes the specific acts that cross over.
The interpretation gives 7 examples of activities that would impair independence at 1.295.150 .06(a) through .06(g), on top of the management responsibilities listed elsewhere in the Code. The wording is "for example", so treat the list as illustrative rather than complete, and treat each item as a scope clause you will need to write.
- Ongoing evaluations or control activities, at .06(a). Reviewing loan originations as part of the client's approval process, or customer credit information as part of sales authorization, puts the firm inside the transaction. Work that is routine and built into operations belongs to your own staff, whatever the capacity argument for moving it.
- Separate evaluations that become routine operations, at .06(b). Testing the effectiveness of a significant control in a way that leaves the firm, in effect, performing routine operations built into the business has the same result. Watch the calendar as well as the scope.
- Serving as the primary basis for management's assertions, at .06(c). If management leans on the firm's work as its main support for saying controls are designed or operating effectively, management has stopped forming its own view. Keep a separate management evaluation on file.
- Deciding which recommendations get implemented, at .06(d). Recommending is allowed and choosing is not. The decision log stays on your side of the table, with a named owner.
- Reporting to the board on management's behalf, at .06(e). The firm may present its own findings. It may not stand in for management or for the person responsible for the internal audit function when the audit committee asks for an answer.
- Owning the internal audit work plan, at .06(f). Approving or being responsible for the overall plan, including audit risk and scope, project priorities and how often procedures are performed, is the function rather than support for it. Plan approval is a board and management act.
- Looking like part of the organization, at .06(g). Being listed as an employee in company directories, being described as supervising or in charge of the internal audit function, or using the client's letterhead all count. Fix the titles on the org chart before the first fieldwork day.
What the Same Interpretation Lets Your Auditor Do
The permitted side is written down too, and it is narrower than the word assist suggests. Under the interpretation, a firm may assess whether performance is in compliance with management's policies and procedures, identify opportunities for improvement, and recommend improvement or further action for management consideration and decision making. That permission carries a condition, and it applies only where the firm has satisfied itself that management is genuinely directing the function.
A firm may also assist the individual responsible for the internal audit function in performing preliminary audit risk assessments, preparing audit plans, and recommending audit priorities. Notice the verbs. Assist, identify, recommend. The moment one of them becomes approve, determine or decide, you are back among the acts that impair independence.
One governance step travels with the permission. The firm should also be satisfied that those charged with governance are informed about its own and management's respective roles and responsibilities in connection with the engagement. Put that split in the audit committee minutes before fieldwork, not in a closing memo after it.
Ongoing Evaluations Versus Separate Evaluations
The Code draws one further distinction, and it decides the workable shape of a co-sourced engagement.
Ongoing evaluations are routine operations built into the client's business processes and performed on a real-time basis, including managerial activities and everyday supervision of employees. A firm that performs them is accepting responsibility for maintaining the client's internal control, and the Code says no safeguard reduces that threat to an acceptable level.
Separate evaluations are conducted periodically, generally are not ingrained in the business, and include observations, inquiries, reviews and other examinations to see whether controls are designed, implemented and conducted. Because they sit outside the process, the Code says they generally do not create a significant management participation threat.
So the defensible shape of a co-sourced engagement with your own accountants is periodic testing rather than embedded monitoring. The Code names the judgment factors as the significance of the controls being tested, the scope or extent of the controls tested in relation to the overall financial statements, and the frequency of the services. A schedule that drifts toward continuous coverage can put you there without anybody renegotiating anything.
Work That Was Never an Internal Audit Service
Some work looks like co-sourcing and is not. Services that are extensions of the firm's audit scope, such as confirming accounts receivable and analyzing fluctuations in account balances, are not internal audit services under the interpretation at all. Label those correctly in the engagement letter, because misfiling them raises an independence question where none existed.
If You Might Want This Provider as Your Auditor Later
Co-sourcing today can constrain who you may appoint tomorrow, and this particular trap is an SEC one. The rule bites during the audit and professional engagement period, defined in 17 CFR 210.2-01 at paragraph (f)(5) as both the period covered by the financial statements being audited or reviewed and the period of the engagement. The professional engagement period begins when the accountant signs an initial engagement letter or begins audit, review or attest procedures, whichever is earlier.
Read that backwards before signing anything. The audit period reaches across the financial statements themselves, so work a firm performs during a year it later audits can fall inside the window regardless of the date on the audit engagement letter. If a firm is on your shortlist to audit your SEC filings, keep it off your shortlist for internal audit work performed during the periods it would audit.
Scoping a Co-Sourced Engagement
Say which of two gaps you are filling, because the standards treat them as different problems.
Competency Gaps, Special Projects and Whole Engagements
Standard 3.1 Competency tells the chief audit executive to consider contracting with an independent, external service provider when the internal audit function collectively does not possess the competencies to perform requested services. Standard 10.2 Human Resources Management in the Global Internal Audit Standards is the other route. Where resources are insufficient to cover the planned engagements, contracting a provider sits alongside training existing staff, requesting an expert from inside the organization to serve as a guest auditor, hiring, relying on other assurance providers, and developing a rotational auditing program. That same standard asks for human resources that are appropriate, sufficient and effectively deployed, where appropriate is the mix of knowledge, skills and abilities and sufficient is the quantity.
External service providers may supply specialized skills, complete special projects, or perform engagements. Name which gap you are buying against before you read a rate card. A competency gap wants one named specialist on a defined engagement. An hours gap wants throughput, and the standards give you cheaper things to try first. A provider that answers a competency gap with a bench of generalists is answering a different question.
The standards also give you the vocabulary for what you are buying. Assurance engagements are compliance, financial, operational or performance, and technology work. Advisory engagements are things like advising on the design and implementation of new policies, processes, systems and products, forensic services, training, and facilitating discussions about risks and controls. Write the brief in those terms and a provider cannot answer a technology assurance gap with a governance workshop.
The Methodology That Exists Before the Provider Arrives
Managing external service providers, when used, is listed at Standard 9.3 Methodologies among the documented methodologies an internal audit function is most likely to need, alongside its approach to risk assessment, planning and engagement performance. Standard 10.2 lists external service provider contracts and the résumés of the internal auditors the provider assigns among the evidence that the function conforms.
The methodology is yours to write before anyone arrives. The contract and the résumés are the file you keep afterwards. Without the first you have no documented basis for judging the provider's work, and without the second nothing in the file shows that anyone checked.
Two Internal Audit Phrases Worth Getting Right
What Are the 5 C's of Internal Audit?
The 5 C's are shorthand for the parts of a finding: criteria, condition, cause, effect and corrective action. The Global Internal Audit Standards never use the phrase. They do define the parts.
A finding is the determination that a gap exists between the evaluation criteria and the condition of the activity under review. Root cause is the core issue or underlying reason for that difference. Internal auditors must collaborate with management to identify root causes when possible, determine the potential effects and evaluate significance, and the standards carry a separate requirement to confirm the implementation of recommendations or action plans.
What Are the Three Types of Internal Audits?
The standards do not sort internal audits into three types. They divide internal audit services into assurance and advisory work.
Assurance services are objective assessments performed to provide assurance. Advisory services, as the standards define them, provide advice without providing assurance or taking on management responsibilities, and their nature and scope are agreed with the relevant stakeholders.
The label matters in a co-sourcing scope. Three of the AICPA impairment examples, .06(a), .06(b) and .06(c), turn on evaluating and monitoring controls, which is assurance work, so an engagement described loosely as advisory can still land inside them.
Write the Scope Clause Before You Take the Meeting
Four documents settle most of the question before any provider presentation begins. The SEC rule and the exchange listing standard tell you whether your own auditor is a candidate at all. The AICPA interpretation names the acts a CPA firm may perform and the ones that would put it on the wrong side of the line. The internal audit standards tell you what stays yours whoever does the testing: the chief audit executive role, the documented methodology, and the board's oversight of both.
So draft the scope first. Name which gap you are filling, the periodic testing you want, who decides which recommendations get implemented, and who reports to the audit committee. A provider worth hiring will read that and tell you where its own model conflicts with it.
Accountably is offshore accounting and tax staffing for US CPA, EA and accounting firms. We place trained offshore accountants and tax preparers inside the firm, working on the firm's software and SOPs, with the signature and the final judgment staying with the firm. Since 2022 that has meant 20+ US firms and 30+ placements.
Our scope is accounting and tax work rather than internal audit fieldwork. If your compliance queue is what keeps senior people in review instead of in front of clients, that is the part we take.
The way in is small on purpose. A Free 40-Hour Proof Pilot puts a fixed block of your own representative work through the offshore team and your review chain, so your reviewer grades real output before a client file is committed. If a placement is not the right fit inside the first 30 days, the 30-Day Fit Guarantee replaces them free.
Don't trust us. Test us.
