An internal audit department co-sources its cybersecurity audit to a reputable firm. When a material control weakness is missed by the co-sourced team, who is ultimately accountable according to the IIA Standards: the co-sourced firm, the audit committee, or the Chief Audit Executive (CAE)?
The answer is the CAE. Always. This isn't a trick question; it's the core principle the CIA exam will test you on relentlessly. If you hesitated, you've found the single most common reason candidates drop points on this topic. They mistake delegating a task for delegating accountability.
Managing external providers on the CIA exam tests your understanding that the Chief Audit Executive (CAE) retains ultimate responsibility for the internal audit function's performance and reporting. This accountability cannot be transferred to a co-sourced or outsourced provider, regardless of their expertise or reputation.
Key facts
- Exam Section: Part 3: Business Knowledge for Internal Auditing
- Blueprint Domain: Primarily Domain I (Business Acumen) and Domain II (Information Technology and Data Analytics).
- Official Standard: The 2024 IIA Global Internal Audit Standards, especially Principle 7 (Competence and Due Professional Care) and Standard 2.1 (The Chief Audit Executive's Responsibilities).
- Pass Rate: The IIA reports that global pass rates for CIA exam parts hover around 43%, which highlights the need for deep topic mastery.
- Question Format: Primarily multiple-choice questions (MCQs) testing judgment and application.
- Testing Focus: The CAE's non-delegable responsibility for planning, supervising, and approving the audit plan and communications.
Your One-Week Plan to Master External Providers
This topic isn't about memorizing definitions. It's about applying professional judgment under pressure. Let's structure your path to mastering this critical area in one focused week.
Studying for CIA CIA3? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
Day 1: What's the Difference Between Co-sourcing and Outsourcing?
Your first step is to build a precise understanding of the two primary models for using external providers. The exam will test your ability to distinguish between them and identify the appropriate governance for each.
Co-sourcing is a partnership where your internal audit department supplements its team with external specialists for specific engagements. Think of hiring a cybersecurity firm to assist with a complex IT audit or a forensic accountant for a fraud investigation. Your team still leads and manages the overall audit function. Outsourcing is a full delegation where your organization contracts with a third-party firm to perform some or all of its internal audit activities. This is common in smaller organizations that may not have the resources to maintain a full-time internal audit department.| Feature | Co-sourcing | Outsourcing |
|---|---|---|
| Control | IA department retains direct control over the audit plan and execution. | CAE provides oversight, but the external firm manages day-to-day execution. |
| Objective | Fill specific skill gaps (e.g., IT, fraud, data analytics). | Fulfill the entire internal audit mandate or a significant portion. |
| Relationship | Collaborative partnership on specific projects. | Formal, ongoing service provider relationship. |
| Cost Structure | Typically project-based or time-and-materials. | Often a fixed-fee retainer or annual contract. |
| Exam Focus | CAE's judgment in identifying skill gaps and supervising specialists. | CAE's robust oversight, due diligence, and performance monitoring. |
The key point is that in both scenarios, the responsibility for maintaining an effective internal audit function rests with the organization and its CAE.
Day 2: What Is the CAE's Ultimate Responsibility for External Providers?
The single most important rule is that accountability cannot be outsourced. You can delegate tasks, but you can never delegate ultimate responsibility.
This principle is anchored in the 2024 IIA Global Internal Audit Standards. Specifically, Standard 2.1 (The Chief Audit Executive's Responsibilities) makes the CAE accountable for the performance of the internal audit function. This is reinforced by Standard 2.2 (The Internal Audit Function's Competence and Due Professional Care), which states the CAE must ensure the function collectively possesses the necessary competence—if not, the CAE must obtain it from external providers.
Even when using external providers, the CAE must have sufficient knowledge to oversee their work effectively. You can’t hire a data scientist to audit an algorithm if you don't understand the basics of what they're testing.
> ⚠️ Exam trap: A question will describe a scenario where a highly reputable external firm makes an error. The tempting wrong answer will assign blame to the external firm or suggest their reputation absolves the CAE. The correct answer will always reaffirm the CAE's ultimate responsibility for supervising the work and owning the final conclusions. The CAE is responsible for the quality of the entire audit function, including work performed by others.
This concept is foundational and connects to topics across the CIA exam, including the essentials of internal auditing covered in Part 1.
Day 3: How Should a CAE Select and Manage an External Provider?
The CAE must follow a structured process for engaging a provider, covering both due diligence and formal management of the relationship.
The due diligence process, or strategic sourcing, requires the CAE to:
- Assess Competence: Verify the provider's certifications, industry experience, and technical knowledge.
- Evaluate Independence and Objectivity: Ensure the provider has no conflicts of interest. Using the organization's external audit firm for internal audit services is a major red flag for independence impairment.
- Check Reputation: Obtain references and inquire about their professional standing.
After selection, the relationship must be formalized in a written agreement, such as a Service Level Agreement (SLA). An exam-worthy SLA must clearly define:
- The scope of the work.
- The responsibilities of both parties.
- The performance metrics for evaluation (e.g., timelines, report quality).
- A non-negotiable requirement for the provider to adhere to the IIA's Code of Ethics and the Global Internal Audit Standards.
- Provisions for CAE access to and custody of working papers.
A weak or ambiguous SLA is a major governance failure and a likely wrong answer on the exam.
Day 4: Can We Walk Through a CIA Exam Question on Provider Selection?
Let's apply these concepts to a realistic exam question to see how they are tested.
> 💡 Worked example: > The CAE of Meridian Manufacturing is considering co-sourcing the audit of its new automated inventory management system. Two firms have submitted proposals: > > * Firm A: A large, international accounting firm that is also Meridian's external auditor. They offer a 20% fee discount due to the existing relationship. They have a large IT audit practice. > * Firm B: A smaller, specialized IT audit firm with deep expertise in Meridian's specific inventory software. They have provided excellent references from other manufacturers. Their fee is higher. > > Which factor is most critical for the CAE to consider when making the selection? > > A. The fee discount offered by Firm A. > B. Firm A's size and general reputation. > C. Firm B's specialized expertise in the relevant software. > D. The potential impairment to independence from using Firm A.
Test Your CIA Exam Readiness
Evaluate your mastery of the new Global Internal Audit Standards and benchmark your baseline readiness.
Step-by-step reasoning:
- Identify the Core Issue: The question is about selecting a provider for a specialized audit. The conflict is between cost/convenience (Firm A) and expertise/independence (Firm B).
- Analyze the Options through the IIA Standards:
- A (Fee discount): Cost is a factor, but the Standards prioritize competence and objectivity. A fee discount is never the most critical factor. This is a classic distractor.
- B (Size/Reputation): "General" reputation is less important than specific, relevant expertise. This is weaker than other options.
- C (Specialized Expertise): Standard 2.2 requires the function to have the necessary competence. Firm B directly addresses the specific skill gap. This is a very strong contender.
- D (Independence Impairment): This is the most critical governance risk. Using the same firm for both external and internal audit services creates a significant threat to independence. The external auditor would essentially be auditing controls they helped assess from an internal audit perspective. This self-review threat is a major violation of professional standards.
- Determine the Most Critical Factor: While Firm B's expertise (C) is important, the potential for a severe independence impairment (D) is a fundamental governance failure. The integrity of the audit function is paramount.
Day 5: What Do Practice Questions on This Topic Look Like?
Theory is one thing; execution is another. It's time to test your judgment with exam-style questions. VoraPrep's question bank has over 4,800 questions, with our adaptive engine targeting the areas where you need the most work. Try VoraPrep's free CIA practice questions to see how you stack up.
Sample Question 1 The CAE of a regional bank determines the internal audit function lacks the expertise to audit the bank's derivatives trading platform. When co-sourcing this audit, which of the following is the CAE's primary responsibility?> Explanation: The correct answer is A. This directly reflects the CAE's non-delegable responsibility under the IIA Standards. The CAE must own the final report, which requires active oversight. B is incorrect because cost is secondary to competence. C is incorrect as it creates a significant independence impairment. D is too weak; "general understanding" is insufficient for a complex audit.
Sample Question 2 An internal audit function has outsourced its IT audit activities. The provider's final report identifies several high-risk deficiencies. Before the report is issued to the audit committee, the CAE must:> Explanation: The correct answer is A. The CAE is ultimately responsible for all communications to senior management and the board. This requires the CAE to personally review and approve the report. B is an abdication of responsibility. C compromises the audit's independence. D is possible, but only after the CAE has already reviewed and approved the report; it is not the CAE's primary duty.
Day 6: How Does This Topic Connect to Other Part 3 Domains?
Managing external providers doesn't exist in a vacuum. On the exam, questions will link this topic to other domains in Part 3.
- Organizational Governance: The decision to outsource is a strategic one. Per Standard 2.1.2, the CAE must inform the board about significant external provider arrangements.
- Risk Management: Co-sourcing is often a risk mitigation strategy to address competency gaps within the internal audit function. This relates to broader concepts of risk appetite and tolerance.
- Communication: The CAE is responsible for communicating all audit results, including those from third parties, to the board and senior management. This directly links to the principles of aligning IA strategy with stakeholder expectations.
Think of every question as a mini-case study testing your holistic business acumen, not just your knowledge of one isolated rule.
Day 7: What's the Final Review Strategy Before Exam Day?
You've built the foundation and tested your application. In the final days before your exam, focus your review of this topic on two things:
- Re-read the IIA Standards: Spend 15 minutes reviewing the 2024 Global Internal Audit Standards, focusing on Principle 7 and Domain II (especially Standards 2.1 and 2.2). These are the source of truth.
- Focus on Judgment Questions: When doing practice questions, seek out the ones that ask for the "best," "primary," or "most important" action. These test your ability to weigh competing priorities, which is the essence of this topic.
On exam day, when you see a question about co-sourcing or outsourcing, take a deep breath and ask yourself: "Where does the ultimate responsibility lie?"
The answer will always be with the CAE.