Skip to content

Audit & Assurance

Internal Audit Co-Sourcing

Your Chief Audit Executive keeps the plan, the relationship and the opinion. We supply the IT audit capability the annual plan needs and the function does not have in-house.

The problem this solves

Most internal audit functions in this region are staffed from a financial audit background. The annual plan contains technology coverage because the audit committee expects it, but the function has nobody who can test a privileged access recertification or read a change management log with any authority.

The usual outcomes are both bad. Either the technology audits are performed superficially and the committee gets false assurance, or they slip year after year and the coverage gap widens until a regulator notices.

Co-sourcing fixes the capability gap without a permanent hire. You do not need a full-time IT auditor; you need one for part of the year, with the depth to be credible when challenged.

How the arrangement works

This is not outsourcing. Your CAE owns the audit plan, reports to the audit committee, and signs the opinion. We are resourcing, not a replacement — and we say so in every report, because a committee should always know who is accountable.

  • You retain the plan, the committee relationship, the opinion, and the quality framework.
  • We provide the IT audit specialists, the control library, the testing methodology and the working paper standard.
  • Together we agree the universe, the risk scoring and which engagements land in which quarter.

One plan, delivered quarterly

ONE PLAN · FOUR ENGAGEMENTS · ONE OPINION Audit universe Every auditableentity Risk scoring Weighted, evidenced Annual plan Approved by thecommittee Q1 ITGC review Type A Q2 Cyberassessment Type C Q3 Regulatoryreview Type F Q4 BC/DR audit Type E
Your CAE keeps the plan, the committee relationship and the opinion. We supply the technology audit capability.

Building the audit universe

The universe is every auditable entity in the technology estate — platforms, processes, third parties, projects. Each is scored on inherent risk and known control maturity, weighted by factors that actually apply to you: regulatory exposure, financial significance, change velocity, prior findings, and time since last audit.

The scoring is documented. When the committee asks why the data centre was audited this year and the CRM was not, there is an evidenced answer rather than a judgement call nobody can reconstruct.

Multi-year rotation

High-risk entities are audited annually. Medium-risk on a two-year cycle, low-risk on three. The plan shows coverage across the rotation, so the committee can see what will not be looked at this year and agree to that consciously rather than discovering it later.

Standards

Work is performed in accordance with the IIA Global Internal Audit Standards so it integrates with your function's own quality framework, and with ISACA ITAF for the technology testing itself. Your external quality assessment should find no difference in standard between our working papers and yours.

How the engagement runs

  1. 1

    Universe build

    Identify every auditable entity in the technology estate, with an owner and a risk profile for each.

  2. 2

    Risk scoring

    Score inherent risk and control maturity against documented, weighted criteria — not intuition.

  3. 3

    Plan design

    Build the annual and multi-year plan, showing coverage and the deliberate gaps.

  4. 4

    Committee approval

    Present the plan for audit committee approval, with the rationale for what is in and out.

  5. 5

    Quarterly delivery

    Each quarter runs as a full engagement — programme, fieldwork, findings, report — with its own quality review.

  6. 6

    Annual roll-up

    Consolidated view of coverage delivered, findings raised, and remediation status across the year.

1 Plan 2 Walkthrough 3 Design 4 Operating 5 Validate 6 Report Every exception is validated with the control owner before it becomes a finding
Each quarterly engagement runs the full pipeline, with its own independent quality review.

What you receive

Audit universe register with risk scoring and rationale per entity
Risk-based annual and multi-year IA plan for committee approval
A full engagement file per quarterly audit — programme, working papers, findings
Quarterly reporting in your own committee format
Consolidated annual coverage and remediation status report
Follow-up validation of prior-period findings before they are reported closed

Frequently asked questions

Your Chief Audit Executive. We provide the specialists, the methodology and the working paper file; the opinion and the committee relationship remain yours. Every report states clearly who performed the work and who is accountable for the conclusion.

For a mid-sized institution running four technology audits a year, typically 40 to 70 person-days spread across quarters. We scope it against your plan rather than selling a fixed retainer, because the right number depends entirely on how much technology coverage your committee expects.

No. We are an IT audit practice and we will not pretend otherwise. If your plan needs operational or financial audit resourcing, that is a different firm.

Then co-sourcing usually works better, not worse. Your person keeps continuity and client knowledge; we bring depth on the specific frameworks and platforms as each engagement demands. It is also how internal people build capability quickly.

Related services

Related regulatory frameworks

Start with the workbook

Our ISO 27001:2022 gap assessment workbook is free and scores itself. Use it first — you will scope the engagement better for having done so.

Request a proposal
Top