Audit & Assurance
Internal Audit Co-Sourcing
Your Chief Audit Executive keeps the plan, the relationship and the opinion. We supply the IT audit capability the annual plan needs and the function does not have in-house.
The problem this solves
Most internal audit functions in this region are staffed from a financial audit background. The annual plan contains technology coverage because the audit committee expects it, but the function has nobody who can test a privileged access recertification or read a change management log with any authority.
The usual outcomes are both bad. Either the technology audits are performed superficially and the committee gets false assurance, or they slip year after year and the coverage gap widens until a regulator notices.
Co-sourcing fixes the capability gap without a permanent hire. You do not need a full-time IT auditor; you need one for part of the year, with the depth to be credible when challenged.
How the arrangement works
This is not outsourcing. Your CAE owns the audit plan, reports to the audit committee, and signs the opinion. We are resourcing, not a replacement — and we say so in every report, because a committee should always know who is accountable.
- You retain the plan, the committee relationship, the opinion, and the quality framework.
- We provide the IT audit specialists, the control library, the testing methodology and the working paper standard.
- Together we agree the universe, the risk scoring and which engagements land in which quarter.
One plan, delivered quarterly
Building the audit universe
The universe is every auditable entity in the technology estate — platforms, processes, third parties, projects. Each is scored on inherent risk and known control maturity, weighted by factors that actually apply to you: regulatory exposure, financial significance, change velocity, prior findings, and time since last audit.
The scoring is documented. When the committee asks why the data centre was audited this year and the CRM was not, there is an evidenced answer rather than a judgement call nobody can reconstruct.
Multi-year rotation
High-risk entities are audited annually. Medium-risk on a two-year cycle, low-risk on three. The plan shows coverage across the rotation, so the committee can see what will not be looked at this year and agree to that consciously rather than discovering it later.
Standards
Work is performed in accordance with the IIA Global Internal Audit Standards so it integrates with your function's own quality framework, and with ISACA ITAF for the technology testing itself. Your external quality assessment should find no difference in standard between our working papers and yours.
How the engagement runs
-
1
Universe build
Identify every auditable entity in the technology estate, with an owner and a risk profile for each.
-
2
Risk scoring
Score inherent risk and control maturity against documented, weighted criteria — not intuition.
-
3
Plan design
Build the annual and multi-year plan, showing coverage and the deliberate gaps.
-
4
Committee approval
Present the plan for audit committee approval, with the rationale for what is in and out.
-
5
Quarterly delivery
Each quarter runs as a full engagement — programme, fieldwork, findings, report — with its own quality review.
-
6
Annual roll-up
Consolidated view of coverage delivered, findings raised, and remediation status across the year.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Start with the workbook
Our ISO 27001:2022 gap assessment workbook is free and scores itself. Use it first — you will scope the engagement better for having done so.
Request a proposal