, ,

Co-Sourcing vs. Outsourcing Internal Audit: Board Comparison

Boards get the co-sourcing versus outsourcing question wrong in a predictable way: they treat it as a procurement decision and decide it on price. It is a governance decision. The internal audit function is the board’s own instrument for finding out whether what management tells it is true, and the question of who performs the work, who they report to, who owns the files, and who can be fired for finding the wrong thing determines whether the instrument works. A fully outsourced function that reports to the CFO, is staffed by whoever the firm has available, and holds its workpapers on the firm’s servers is cheaper than an in-house team and worth very little to the audit committee that relies on it. A co-sourced function with a strong internal head, a specialist firm on call, and a contract that puts the committee in charge can be both cheaper and better than either pure model. The difference is in the structure, not the invoice.

This guide is written for the board members and executives who make the decision and the chief audit executives who live with it. It defines the four sourcing models precisely, sets out what the Global Internal Audit Standards and the main regulators require of each, compares the models on the twelve dimensions that matter with a scored decision matrix, gives a governance table showing who does what under each model, a contract-terms checklist for any external provider, three worked decisions at companies of different sizes and regulatory positions, the warning signs that a sourcing model has failed, a transition plan for moving between models, and the mistakes boards make. It was rewritten in September 2026 to reflect the Global Internal Audit Standards and current US and UK listing and regulatory expectations. The cost side of the decision is worked in detail in the site’s guide to what an internal audit costs; the operational side of buying external hours well is in co-sourcing 101.

In this guide

The four sourcing models, defined precisely

The vocabulary is used loosely, and loose vocabulary produces loose contracts. Four models cover the field, and the defining question for each is who holds the chief audit executive role in substance: who owns the risk assessment and the plan, who signs the reports, who sits in the private session with the audit committee, and who is accountable when a control failure surfaces in an area the function covered.

ModelDefinitionWho holds the CAE roleWho performs the workTypical use
In-houseThe organization employs the chief audit executive and the audit staff; external help is occasional and engagement-specificAn employee, reporting functionally to the audit committeeEmployees, with a specialist bought for a single engagement now and thenLarge and regulated organizations; any organization above roughly 6,000 engagement hours a year
Co-sourcedThe organization employs the chief audit executive and a core team; an external provider supplies skills or capacity under the CAE’s direction, on the CAE’s plan and methodologyAn employeeEmployees plus provider staff working to the function’s standards; the CAE reviews and signs everythingThe most common model for mid-sized organizations; the first model for most new functions
OutsourcedAn external provider performs the whole function under a contract; an executive of the organization sponsors and oversees it and holds the CAE responsibilities the Standards place on the organizationFormally an employee (often the general counsel, CFO, or a designated executive); in substance often the provider’s engagement partner, which is the model’s central weaknessProvider staffOrganizations under about 1,500 engagement hours a year; first-time functions; interim arrangements
Managed service or “internal audit as a service”A variant of outsourcing in which the provider supplies a named individual to act as chief audit executive on a part-time or fractional basis, plus staff, under a multi-year agreementThe provider’s individual, contractually bound to report to the audit committeeProvider staffSmaller companies wanting a recognizable CAE without a full-time hire; PE portfolio companies

The distinction between co-sourcing and outsourcing is not the share of hours the provider delivers; a co-sourced function can buy 70 percent of its hours and remain co-sourced if the CAE owns the plan, the methodology, and the reports. It is the location of the CAE role. Under co-sourcing the organization has someone whose job is to know what the risks are, decide what gets audited, and stand behind the conclusions, and who cannot be replaced by a phone call to the firm. Under outsourcing that person has to be created by the contract and the sponsor’s attention, and the history of failed outsourcing arrangements is the history of that person not existing in substance.

What the Standards, listing rules, and regulators require

Every sourcing model is permitted by the Standards and by the main regulators, with conditions, and the conditions are where the governance work is. The Global Internal Audit Standards place the duties of Domain III on the board regardless of model: to establish the mandate and charter, to position the function independently with a qualified chief audit executive, and to oversee its resources, quality, and performance. Where the function is outsourced, the Standards expect the organization to retain responsibility for the function’s effectiveness and for the CAE role’s duties, which cannot be contracted away; a board that outsources and then treats the provider as the accountable party has outsourced its own responsibility, which the Standards do not allow. The GIAS Domain III guide sets out those duties in full.

SourceWhat it requires or prohibitsEffect on the sourcing decision
Global Internal Audit Standards, Domain III (board) and Domain IV (CAE)Board approves the charter, plan, budget, and CAE appointment; oversees resources and quality; external quality assessment at least every five years; the CAE ensures competency and manages resources including external providersAny model must leave a real CAE role and a real board relationship; outsourced functions need a designated executive holding the CAE duties
Sarbanes-Oxley Act Section 201 (US public companies)Prohibits the external auditor from providing internal audit outsourcing services to its audit clientPublic companies cannot outsource or co-source internal audit to their external audit firm; the Big Four firm that audits you is off the list
NYSE Listed Company Manual Section 303A.07Each listed company must have an internal audit function, which may be outsourced to a third party other than the independent auditorOutsourcing is expressly permitted; having no function is not
Nasdaq listing rulesNo requirement to maintain an internal audit function (a 2013 proposal was withdrawn)The decision is the board’s; most Nasdaq companies of size maintain one anyway for SOX 404 and investor expectations
US banking agencies: Interagency Policy Statement on the Internal Audit Function and Its Outsourcing (2003, still in force)Board and audit committee remain responsible; a competent internal audit manager oversees the arrangement; contract terms specified; the external auditor should not be the outsourcing vendor; examiners assess the arrangementBanks may outsource but must keep a qualified internal person in charge and meet the contract requirements; examiners test this
UK Corporate Governance Code (2024)The audit committee monitors and reviews the effectiveness of internal audit and, where there is no function, considers annually whether one is needed and explains the absence in the annual reportOutsourced and co-sourced functions are common in UK listed companies; the committee’s review obligation is the same for all models
Sector regulators (insurance, healthcare, utilities, public sector)Vary; many require an internal audit function with defined independence and some restrict outsourcing to specific providers or require regulator notificationCheck the sector rule before choosing; regulated entities usually end up co-sourced or in-house

Two rules trip boards most often. The Section 201 prohibition means that the firm a public company already trusts, and whose people already know the business, is the one firm it cannot use for internal audit; the decision then turns on whether another firm can learn the business fast enough to be useful. And the banking policy statement’s requirement for a competent internal audit manager is frequently met on paper by naming the CFO, which examiners have learned to see through, because the CFO is the most-audited executive in the institution and cannot oversee the auditors of their own function; the financial services guide covers what examiners look for.

The twelve dimensions and a scored decision matrix

The matrix below scores the three main models on twelve dimensions from 1 (weak) to 5 (strong), from the board’s point of view. The scores describe a well-run version of each model; a badly run in-house function scores worse than a well-run outsourced one on most rows, and the last section of this guide is about how to tell. Weights are the board’s to set: a regulated bank weights regulatory acceptability and independence heavily; a private company building its first function weights speed and cost; a company with a fraud history weights institutional knowledge and continuity.

DimensionWhat the board is askingIn-houseCo-sourcedOutsourcedComment
Independence and objectivityCan the function report what it finds without consequence to the people who found it?443A provider’s commercial interest in renewal is a pressure the in-house CAE does not face; mitigated by committee-controlled contracts
Institutional knowledgeDoes the function know where the risks actually are?542Provider staff rotate; knowledge leaves with them unless the contract fixes named staff
Access to specialist skillsCan it audit cyber, ERP security, models, actuarial, or new regulation?254The co-sourced model’s defining advantage: buy the skill for the engagement that needs it
Scalability and surgeCan it absorb an acquisition, an investigation, or a regulator’s request?254Providers scale; employees do not
Cost per engagement hourWhat does an hour of assurance cost?5 above 6,000 hours a year; 2 below 1,50042 (rates of $200 to $400) but 5 in absolute terms for very small programsThe break-even is about 1,500 hours a year; see the cost guide
Speed to stand upHow soon does the board get its first report?2 (six to nine months to hire)45 (weeks)Outsourcing is the fastest start and a legitimate interim model
Continuity and key-person riskWhat happens when someone leaves?3 (a small team is exposed)4 (two sources of continuity)3 (contract continuity, staff churn)Fix named staff and transition terms in the contract
Regulatory acceptabilityWill examiners and listing rules accept it?553 (accepted with conditions; the internal manager must be real)Section 201 rules out the external auditor for public companies under any model
Management influence over the functionCan management steer what gets audited or how it is reported?342 unless the committee controls the contractThe most common outsourcing failure: the provider reports to the CFO who pays the invoice
Confidentiality and data controlWhere do the workpapers and the data live?542 unless ownership and access are contractedWorkpapers must be the organization’s property and accessible on demand
Conflicts of interestIs the provider also selling the company something else?532A provider that also implements the ERP or advises on SOX cannot audit its own work
Board relationship and candorWill the committee hear bad news early, in private?553An in-house CAE has a career stake in the committee’s trust; a provider has a renewal stake in management’s
Unweighted total (of 60)43 to 465135 to 38Co-sourcing wins unweighted for most mid-sized organizations; the extremes of size change the answer

The unweighted total favors co-sourcing, and so does experience, for organizations between roughly 1,500 and 6,000 engagement hours a year, which is most companies with revenue between $150 million and $2 billion. Below that range the absolute cost of a full-time CAE cannot be justified and outsourcing, structured properly, is the right answer; above it, the in-house model’s knowledge and cost advantages take over and external help reverts to occasional specialist use. The board’s job is to weight the rows for its own situation and to notice that the outsourced model’s low scores on independence, management influence, data control, and conflicts are all fixable by contract and governance, which is what the next two sections are for.

Governance: who does what under each model

The Standards’ Domain III duties do not move when the work is contracted out, and the table shows who carries each one under each model. The column to read most carefully is the outsourced one, because every row in it that says “the sponsor executive” describes a duty that the organization has to perform with someone who has the time, the standing, and the independence to perform it. Where the sponsor is the CFO, the rows on the plan, the reports, and the private session are compromised, and the arrangement should be restructured so that the sponsor is the general counsel, the company secretary, or a designated executive outside finance and operations, with the committee chair as the substantive counterpart.

DutyIn-houseCo-sourcedOutsourced
Charter and mandateBoard approves; CAE draftsBoard approves; CAE draftsBoard approves; sponsor executive drafts with the provider; the charter names the sponsor’s CAE responsibilities and the provider’s role
Risk assessment and annual planCAE owns and presentsCAE owns and presents; provider contributes specialist inputProvider drafts; sponsor executive challenges and presents; board approves; the risk is that no one in the organization owns the assessment
Methodology and qualityCAE; QAIP; external assessment every five yearsCAE’s methodology governs provider work; provider staff work to the function’s standards, not their firm’sProvider’s methodology, which the committee should approve and have assessed; the five-year external assessment still applies to the function
Engagement supervision and report sign-offCAECAE reviews and signs all reports including provider-led onesProvider’s engagement leader signs; sponsor executive reviews; the committee should require the provider’s signatory to attend and answer
Reporting line and private sessionCAE reports functionally to the committee; private session each meetingSameProvider’s lead and the sponsor executive attend; the private session must include the provider without management present, and the contract must say the provider reports to the committee
Hiring, evaluation, and removal of the CAECommittee approves appointment and removal; sets or approves compensationSameCommittee approves the provider’s appointment, the named lead, and any change of lead; committee controls termination, not the CFO
BudgetCommittee approvesCommittee approves, including the co-source lineCommittee approves the contract value and any change orders; invoices should not be approvable by an executive the function audits
Workpapers and dataOrganization’s systemsOrganization’s systems; provider works in themContract makes workpapers the organization’s property, held or mirrored on its systems, with access on demand and return on termination
Issue follow-up and validationCAE’s issue logCAE’s issue logProvider maintains the log; sponsor executive reviews quarterly; the log is the organization’s record
Independence confirmationCAE confirms annuallyCAE confirms; provider confirms no conflicting servicesProvider confirms annually in writing: no conflicting services, no financial interest, staff independence; the sponsor confirms their own

Contract terms for any external provider

The contract is where the outsourced and co-sourced models’ governance weaknesses are fixed or left open, and it is usually negotiated by procurement against the provider’s standard engagement letter, which is written for the provider. The terms below are the ones an audit committee should insist on and read itself. They apply in full to outsourcing and in proportion to co-sourcing; a co-source arrangement for 140 hours of ERP security work still needs the independence, workpaper, and conflict terms.

TermWhat to requireWhy
Reporting lineThe provider reports functionally to the audit committee; the committee approves the plan, receives all reports, and meets the provider privatelyWithout it, the provider reports to whoever signs the invoice
Named staff and continuityThe engagement leader and key staff are named; changes require committee approval; a minimum tenure or a replacement-approval rightInstitutional knowledge is the outsourced model’s weakest point; rotation destroys it
Scope and planThe annual plan and hours are a schedule to the contract; changes are approved by the committee, not negotiated between the provider and managementPrevents scope erosion by the people being audited
Methodology and standardsWork is performed in conformance with the Global Internal Audit Standards; the methodology is disclosed and the committee may have it assessedThe five-year external assessment applies to the function whoever performs it
Workpapers and dataWorkpapers are the organization’s property, held on or mirrored to its systems, accessible on demand, returned on termination; data handling meets the organization’s security policyThe organization must be able to hand its own audit files to a regulator or a successor provider
Independence and conflictsAnnual written confirmation; disclosure of all other services to the organization and its executives; prohibition on auditing the provider’s own advisory or implementation work; for public companies, confirmation that the provider is not the external auditorSection 201 and basic objectivity
Access and cooperationThe provider has the access rights the charter grants internal audit; management’s obligations to cooperate are statedA provider without charter authority is a consultant
FeesHours and rates by grade, or a fixed fee tied to a defined plan; change-order rules; no success or contingent feesEffective rate visibility; contingent fees compromise objectivity
Performance measuresPlan completion, report cycle time, committee satisfaction, staff continuity, validation coverage; reviewed annually by the committeeMakes renewal a decision on evidence
SubcontractingNot without committee consent; subcontractors bound by the same termsOtherwise the named-staff term is hollow
Termination and transitionTermination by the committee for convenience on notice; a transition period with knowledge transfer, file handover, and continued follow-up on open issuesThe exit is when the organization discovers what it did not own
Liability and insuranceProfessional indemnity at a level proportionate to the engagement; liability caps reviewed by counselStandard, but often set at the fee value, which is too low for an assurance function

The two terms most often missing are the reporting line and the workpaper ownership, and their absence explains most of the horror stories: a provider that could not be removed without the CFO’s agreement because the CFO held the contract, and a company that changed providers and found it did not own three years of its own audit files. The co-sourcing best practices guide covers how a chief audit executive manages the relationship day to day once the contract is right.

Three worked decisions

The three organizations below sit at different points on the size and regulation axes, and each reached a different answer by weighting the same twelve dimensions. The table records the decision the way a committee minute should: the options considered, the weights that decided it, the structure adopted, and the terms that made it safe.

ElementBrightwater Foods: $180M specialty food manufacturer, 600 staff, private with lenders, first functionMidState Beverage: three-state distributor, 12 depots, six-person in-house function, fraud historyLakeshore Bancorp: $9B regional bank, public, examined annually
Options consideredOutsource entirely (about $250,000 for six engagements); co-source with one hired head (about $345,000 for 1,600 hours); three-person in-house team (about $600,000)Keep the in-house team; add co-source for ERP security and cyber; outsource the depot rotations to a regional firmIn-house with occasional specialists; co-source model validation and IT; outsource the whole function to a national firm (rejected early)
Weights that decided itInstitutional knowledge and independence weighted high because of the lender relationship and a founder-led culture; speed weighted low because the first engagement was six months away either wayInstitutional knowledge and continuity weighted highest after the Dayton diversion; specialist skills weighted high for the ERP access engagement; cost weighted lowRegulatory acceptability and independence weighted highest; Section 201 excluded the external auditor; examiner expectations of a competent in-house manager made full outsourcing unacceptable
DecisionCo-source: hire a head of internal audit; buy 600 specialist and surge hours a year from a regional firm at about $220 an hourCo-source: retain the in-house function; buy 140 hours of ERP security expertise for $28,000; keep depot rotations in-house because depot knowledge is the function’s core assetIn-house with structured co-source: twenty-two in-house auditors; a three-year co-source agreement for model validation and cybersecurity with a specialist firm that is not the external auditor
Terms that made it safeProvider reports to the head of internal audit on the function’s methodology; named staff; workpapers in the company’s systems; no other services to the company; committee approves the co-source budget lineSpecialist scoped to the ERP security question only; internal staff do the surrounding work; deliverables in the function’s workpaper format; independence confirmation on fileCommittee approves the provider and named leads; annual conflicts disclosure covering all services to the bank; provider staff work under the CAE’s methodology; examiners briefed on the arrangement
What would change the answerA pre-IPO decision would push toward the three-person team for ICFR readiness; losing the lender relationship would make outsourcing acceptable as an interimA sale to a private equity owner might bring a managed-service model for cost reasons, which the committee should resist given the fraud historyNothing short of a regulatory change; the bank’s size and examination regime fix the model

Brightwater’s decision is the one most readers face, and the arithmetic behind it is in the site’s guide to setting up a small-company function, which prices the three options in detail. The point the committee minute captures is that the $95,000 difference between outsourcing and co-sourcing bought a person whose job was to know the company, and that after a lender’s field examination and a founder’s succession, that person turned out to be the function’s most valuable asset. The co-sourcing ROI guide shows how to make that case in the board paper.

Warning signs that the model has failed

Sourcing models fail slowly, and the committee is usually the last to know, because the failure is in what it is not being told. The signs below are observable from the committee’s chair, and each maps to a fixable term or governance step; a committee that sees two or more of them should treat the arrangement as impaired and act at the next meeting rather than at renewal.

Warning signWhat it usually meansModel most exposedFix
Every report is SatisfactoryThe function has stopped finding things, or has stopped reporting them; under outsourcing, the provider has learned what management rewardsOutsourcedPrivate session with the provider’s lead; compare ratings to incident and loss data; consider an external assessment
Different provider staff at every meetingRotation; institutional knowledge is not accumulatingOutsourced and co-sourcedEnforce the named-staff term; approve changes
The plan changes without coming to the committeeManagement and the provider are negotiating scopeOutsourcedPlan and changes as a contract schedule approved by the committee
Findings are “observations” and actions are “recommendations”Softening under commercial pressureOutsourcedRating definitions in the contract; committee reviews the distribution of ratings annually
The sponsor executive is the CFO and never disagrees with the providerThe CAE role is not being performed; the provider reports to its clientOutsourcedMove the sponsor role outside finance; committee chair as the substantive counterpart
The committee cannot get the workpapersOwnership was never contractedOutsourcedAmend the contract; mirror files to the organization’s systems
The provider is also implementing the new ERP or advising on SOXA conflict that will eventually be audited aroundCo-sourced and outsourcedConflicts disclosure; exclude the conflicted area from the provider’s scope or change provider
The CAE signs provider reports without having reviewed the workCo-sourcing has become outsourcing without the governanceCo-sourcedReview evidence on every provider workpaper; reduce provider share until the CAE can supervise it
Costs rise every year with the same planChange orders and rate escalation without committee visibilityOutsourcedFees as a schedule; change orders approved by the committee; effective rate tracked
Validation of prior findings has stoppedFollow-up was never in the contracted scopeOutsourcedValidation windows and the issue log written into the plan schedule

Moving between models

Most organizations change model at least once: outsourced to co-sourced as they grow, co-sourced to in-house as the function matures, occasionally in-house to co-sourced after a cost review. The transition is where the contract terms above are tested, and the sequence below is the one that preserves the function’s knowledge and the committee’s assurance through the change. From outsourced to co-sourced, hire the head of internal audit first and have them run the existing provider for two quarters before changing anything, so that the plan, the issue log, and the files are taken over by someone who has seen them work; renegotiate the provider’s role to specialist and surge work at the next plan cycle. From co-sourced to in-house, convert the provider’s recurring engagements to internal staff one cluster at a time as hires are made, keeping the provider on specialist work throughout, and do not let the provider’s last engagement end before its knowledge has been walked through with the person inheriting it. From in-house to a heavier co-source model, which usually follows a cost review, protect the CAE role and the core team’s knowledge of the highest-risk areas, and buy the commodity work rather than the judgment; a function that co-sources its route cash audit at a company with a cash-diversion history has sold the wrong thing.

In every direction, three things move with the function: the issue log with every open action and its evidence, the risk assessment and universe with the scoring history, and the workpaper archive for at least the current and prior cycle, all in the organization’s systems before the outgoing arrangement ends. The issue log template and the audit planning guide describe the two records in the form that survives a handover, and the QAIP guide covers how the function’s quality program continues across a change of model, which the five-year external assessment will examine.

Common board-level mistakes

FailureWhat it looks likeWhy it mattersFix
Deciding on priceThe cheapest proposal wins; the governance terms are procurement’s problemThe board buys an instrument that cannot tell it bad newsScore the twelve dimensions with the committee’s weights; price is one row
Outsourcing the responsibilityThe committee treats the provider as the accountable partyThe Standards and the regulators place the duty on the board and a designated internal manager; it cannot be delegatedName the sponsor executive, outside finance, with the CAE duties in the charter
The CFO as sponsorThe provider reports to, is paid by, and is renewed by the most-audited executiveIndependence in form only; examiners and assessors see itGeneral counsel, company secretary, or a designated executive; committee chair as counterpart
Using the external auditorThe audit firm proposes internal audit outsourcing to a public companyProhibited under Section 201; unwise under any ruleExclude the external auditor from the shortlist
No named staffThe engagement letter promises “appropriately qualified professionals”Rotation destroys institutional knowledgeNamed lead and key staff; committee approval of changes
Provider’s methodology unexaminedThe committee has never seen how the provider rates findings or sizes samplesRatings and conclusions cannot be compared across years or providersMethodology disclosed and, for outsourced functions, externally assessed
Workpapers on the provider’s serversFiles are the firm’s; access is by requestThe organization does not own its own audit historyOwnership and mirroring in the contract
Conflicted providerThe co-source firm also runs the SOX readiness project or the ERP implementationSelf-review; the provider audits around its own workAnnual conflicts disclosure; exclusion of conflicted areas
Co-sourcing that has become outsourcingThe in-house CAE signs work they have not reviewed because 80 percent of hours are externalThe governance of co-sourcing without its substanceCap the provider share at what the CAE can supervise; review evidence on every provider file
No exit planThe contract has no transition, handover, or file-return termsThe organization discovers what it did not own at the worst momentTermination for convenience and a defined transition in every contract

The right sourcing model is the one that gives the board an instrument it controls: a real chief audit executive role inside the organization, a plan the committee approves, reports that reach it unsoftened, files it owns, and a provider, if there is one, that answers to the committee rather than to the people it audits. Co-sourcing achieves that most naturally for most mid-sized organizations; outsourcing can achieve it with the right contract and sponsor; in-house achieves it by default at scale. What none of the models can do is substitute for a committee willing to read the private-session agenda and ask what it is not being told. The site’s ten signs you need external help covers the trigger for adding a provider to an in-house function, and the guides by role page collects the material for audit committee members and CAEs.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading