Boards get the co-sourcing versus outsourcing question wrong in a predictable way: they treat it as a procurement decision and decide it on price. It is a governance decision. The internal audit function is the board’s own instrument for finding out whether what management tells it is true, and the question of who performs the work, who they report to, who owns the files, and who can be fired for finding the wrong thing determines whether the instrument works. A fully outsourced function that reports to the CFO, is staffed by whoever the firm has available, and holds its workpapers on the firm’s servers is cheaper than an in-house team and worth very little to the audit committee that relies on it. A co-sourced function with a strong internal head, a specialist firm on call, and a contract that puts the committee in charge can be both cheaper and better than either pure model. The difference is in the structure, not the invoice.
This guide is written for the board members and executives who make the decision and the chief audit executives who live with it. It defines the four sourcing models precisely, sets out what the Global Internal Audit Standards and the main regulators require of each, compares the models on the twelve dimensions that matter with a scored decision matrix, gives a governance table showing who does what under each model, a contract-terms checklist for any external provider, three worked decisions at companies of different sizes and regulatory positions, the warning signs that a sourcing model has failed, a transition plan for moving between models, and the mistakes boards make. It was rewritten in September 2026 to reflect the Global Internal Audit Standards and current US and UK listing and regulatory expectations. The cost side of the decision is worked in detail in the site’s guide to what an internal audit costs; the operational side of buying external hours well is in co-sourcing 101.
In this guide
- The four sourcing models, defined precisely
- What the Standards, listing rules, and regulators require
- The twelve dimensions and a scored decision matrix
- Governance: who does what under each model
- Contract terms for any external provider
- Three worked decisions
- Warning signs that the model has failed
- Moving between models
- Common board-level mistakes
The four sourcing models, defined precisely
The vocabulary is used loosely, and loose vocabulary produces loose contracts. Four models cover the field, and the defining question for each is who holds the chief audit executive role in substance: who owns the risk assessment and the plan, who signs the reports, who sits in the private session with the audit committee, and who is accountable when a control failure surfaces in an area the function covered.
| Model | Definition | Who holds the CAE role | Who performs the work | Typical use |
|---|---|---|---|---|
| In-house | The organization employs the chief audit executive and the audit staff; external help is occasional and engagement-specific | An employee, reporting functionally to the audit committee | Employees, with a specialist bought for a single engagement now and then | Large and regulated organizations; any organization above roughly 6,000 engagement hours a year |
| Co-sourced | The organization employs the chief audit executive and a core team; an external provider supplies skills or capacity under the CAE’s direction, on the CAE’s plan and methodology | An employee | Employees plus provider staff working to the function’s standards; the CAE reviews and signs everything | The most common model for mid-sized organizations; the first model for most new functions |
| Outsourced | An external provider performs the whole function under a contract; an executive of the organization sponsors and oversees it and holds the CAE responsibilities the Standards place on the organization | Formally an employee (often the general counsel, CFO, or a designated executive); in substance often the provider’s engagement partner, which is the model’s central weakness | Provider staff | Organizations under about 1,500 engagement hours a year; first-time functions; interim arrangements |
| Managed service or “internal audit as a service” | A variant of outsourcing in which the provider supplies a named individual to act as chief audit executive on a part-time or fractional basis, plus staff, under a multi-year agreement | The provider’s individual, contractually bound to report to the audit committee | Provider staff | Smaller companies wanting a recognizable CAE without a full-time hire; PE portfolio companies |
The distinction between co-sourcing and outsourcing is not the share of hours the provider delivers; a co-sourced function can buy 70 percent of its hours and remain co-sourced if the CAE owns the plan, the methodology, and the reports. It is the location of the CAE role. Under co-sourcing the organization has someone whose job is to know what the risks are, decide what gets audited, and stand behind the conclusions, and who cannot be replaced by a phone call to the firm. Under outsourcing that person has to be created by the contract and the sponsor’s attention, and the history of failed outsourcing arrangements is the history of that person not existing in substance.
What the Standards, listing rules, and regulators require
Every sourcing model is permitted by the Standards and by the main regulators, with conditions, and the conditions are where the governance work is. The Global Internal Audit Standards place the duties of Domain III on the board regardless of model: to establish the mandate and charter, to position the function independently with a qualified chief audit executive, and to oversee its resources, quality, and performance. Where the function is outsourced, the Standards expect the organization to retain responsibility for the function’s effectiveness and for the CAE role’s duties, which cannot be contracted away; a board that outsources and then treats the provider as the accountable party has outsourced its own responsibility, which the Standards do not allow. The GIAS Domain III guide sets out those duties in full.
| Source | What it requires or prohibits | Effect on the sourcing decision |
|---|---|---|
| Global Internal Audit Standards, Domain III (board) and Domain IV (CAE) | Board approves the charter, plan, budget, and CAE appointment; oversees resources and quality; external quality assessment at least every five years; the CAE ensures competency and manages resources including external providers | Any model must leave a real CAE role and a real board relationship; outsourced functions need a designated executive holding the CAE duties |
| Sarbanes-Oxley Act Section 201 (US public companies) | Prohibits the external auditor from providing internal audit outsourcing services to its audit client | Public companies cannot outsource or co-source internal audit to their external audit firm; the Big Four firm that audits you is off the list |
| NYSE Listed Company Manual Section 303A.07 | Each listed company must have an internal audit function, which may be outsourced to a third party other than the independent auditor | Outsourcing is expressly permitted; having no function is not |
| Nasdaq listing rules | No requirement to maintain an internal audit function (a 2013 proposal was withdrawn) | The decision is the board’s; most Nasdaq companies of size maintain one anyway for SOX 404 and investor expectations |
| US banking agencies: Interagency Policy Statement on the Internal Audit Function and Its Outsourcing (2003, still in force) | Board and audit committee remain responsible; a competent internal audit manager oversees the arrangement; contract terms specified; the external auditor should not be the outsourcing vendor; examiners assess the arrangement | Banks may outsource but must keep a qualified internal person in charge and meet the contract requirements; examiners test this |
| UK Corporate Governance Code (2024) | The audit committee monitors and reviews the effectiveness of internal audit and, where there is no function, considers annually whether one is needed and explains the absence in the annual report | Outsourced and co-sourced functions are common in UK listed companies; the committee’s review obligation is the same for all models |
| Sector regulators (insurance, healthcare, utilities, public sector) | Vary; many require an internal audit function with defined independence and some restrict outsourcing to specific providers or require regulator notification | Check the sector rule before choosing; regulated entities usually end up co-sourced or in-house |
Two rules trip boards most often. The Section 201 prohibition means that the firm a public company already trusts, and whose people already know the business, is the one firm it cannot use for internal audit; the decision then turns on whether another firm can learn the business fast enough to be useful. And the banking policy statement’s requirement for a competent internal audit manager is frequently met on paper by naming the CFO, which examiners have learned to see through, because the CFO is the most-audited executive in the institution and cannot oversee the auditors of their own function; the financial services guide covers what examiners look for.
The twelve dimensions and a scored decision matrix
The matrix below scores the three main models on twelve dimensions from 1 (weak) to 5 (strong), from the board’s point of view. The scores describe a well-run version of each model; a badly run in-house function scores worse than a well-run outsourced one on most rows, and the last section of this guide is about how to tell. Weights are the board’s to set: a regulated bank weights regulatory acceptability and independence heavily; a private company building its first function weights speed and cost; a company with a fraud history weights institutional knowledge and continuity.
| Dimension | What the board is asking | In-house | Co-sourced | Outsourced | Comment |
|---|---|---|---|---|---|
| Independence and objectivity | Can the function report what it finds without consequence to the people who found it? | 4 | 4 | 3 | A provider’s commercial interest in renewal is a pressure the in-house CAE does not face; mitigated by committee-controlled contracts |
| Institutional knowledge | Does the function know where the risks actually are? | 5 | 4 | 2 | Provider staff rotate; knowledge leaves with them unless the contract fixes named staff |
| Access to specialist skills | Can it audit cyber, ERP security, models, actuarial, or new regulation? | 2 | 5 | 4 | The co-sourced model’s defining advantage: buy the skill for the engagement that needs it |
| Scalability and surge | Can it absorb an acquisition, an investigation, or a regulator’s request? | 2 | 5 | 4 | Providers scale; employees do not |
| Cost per engagement hour | What does an hour of assurance cost? | 5 above 6,000 hours a year; 2 below 1,500 | 4 | 2 (rates of $200 to $400) but 5 in absolute terms for very small programs | The break-even is about 1,500 hours a year; see the cost guide |
| Speed to stand up | How soon does the board get its first report? | 2 (six to nine months to hire) | 4 | 5 (weeks) | Outsourcing is the fastest start and a legitimate interim model |
| Continuity and key-person risk | What happens when someone leaves? | 3 (a small team is exposed) | 4 (two sources of continuity) | 3 (contract continuity, staff churn) | Fix named staff and transition terms in the contract |
| Regulatory acceptability | Will examiners and listing rules accept it? | 5 | 5 | 3 (accepted with conditions; the internal manager must be real) | Section 201 rules out the external auditor for public companies under any model |
| Management influence over the function | Can management steer what gets audited or how it is reported? | 3 | 4 | 2 unless the committee controls the contract | The most common outsourcing failure: the provider reports to the CFO who pays the invoice |
| Confidentiality and data control | Where do the workpapers and the data live? | 5 | 4 | 2 unless ownership and access are contracted | Workpapers must be the organization’s property and accessible on demand |
| Conflicts of interest | Is the provider also selling the company something else? | 5 | 3 | 2 | A provider that also implements the ERP or advises on SOX cannot audit its own work |
| Board relationship and candor | Will the committee hear bad news early, in private? | 5 | 5 | 3 | An in-house CAE has a career stake in the committee’s trust; a provider has a renewal stake in management’s |
| Unweighted total (of 60) | — | 43 to 46 | 51 | 35 to 38 | Co-sourcing wins unweighted for most mid-sized organizations; the extremes of size change the answer |
The unweighted total favors co-sourcing, and so does experience, for organizations between roughly 1,500 and 6,000 engagement hours a year, which is most companies with revenue between $150 million and $2 billion. Below that range the absolute cost of a full-time CAE cannot be justified and outsourcing, structured properly, is the right answer; above it, the in-house model’s knowledge and cost advantages take over and external help reverts to occasional specialist use. The board’s job is to weight the rows for its own situation and to notice that the outsourced model’s low scores on independence, management influence, data control, and conflicts are all fixable by contract and governance, which is what the next two sections are for.
Governance: who does what under each model
The Standards’ Domain III duties do not move when the work is contracted out, and the table shows who carries each one under each model. The column to read most carefully is the outsourced one, because every row in it that says “the sponsor executive” describes a duty that the organization has to perform with someone who has the time, the standing, and the independence to perform it. Where the sponsor is the CFO, the rows on the plan, the reports, and the private session are compromised, and the arrangement should be restructured so that the sponsor is the general counsel, the company secretary, or a designated executive outside finance and operations, with the committee chair as the substantive counterpart.
| Duty | In-house | Co-sourced | Outsourced |
|---|---|---|---|
| Charter and mandate | Board approves; CAE drafts | Board approves; CAE drafts | Board approves; sponsor executive drafts with the provider; the charter names the sponsor’s CAE responsibilities and the provider’s role |
| Risk assessment and annual plan | CAE owns and presents | CAE owns and presents; provider contributes specialist input | Provider drafts; sponsor executive challenges and presents; board approves; the risk is that no one in the organization owns the assessment |
| Methodology and quality | CAE; QAIP; external assessment every five years | CAE’s methodology governs provider work; provider staff work to the function’s standards, not their firm’s | Provider’s methodology, which the committee should approve and have assessed; the five-year external assessment still applies to the function |
| Engagement supervision and report sign-off | CAE | CAE reviews and signs all reports including provider-led ones | Provider’s engagement leader signs; sponsor executive reviews; the committee should require the provider’s signatory to attend and answer |
| Reporting line and private session | CAE reports functionally to the committee; private session each meeting | Same | Provider’s lead and the sponsor executive attend; the private session must include the provider without management present, and the contract must say the provider reports to the committee |
| Hiring, evaluation, and removal of the CAE | Committee approves appointment and removal; sets or approves compensation | Same | Committee approves the provider’s appointment, the named lead, and any change of lead; committee controls termination, not the CFO |
| Budget | Committee approves | Committee approves, including the co-source line | Committee approves the contract value and any change orders; invoices should not be approvable by an executive the function audits |
| Workpapers and data | Organization’s systems | Organization’s systems; provider works in them | Contract makes workpapers the organization’s property, held or mirrored on its systems, with access on demand and return on termination |
| Issue follow-up and validation | CAE’s issue log | CAE’s issue log | Provider maintains the log; sponsor executive reviews quarterly; the log is the organization’s record |
| Independence confirmation | CAE confirms annually | CAE confirms; provider confirms no conflicting services | Provider confirms annually in writing: no conflicting services, no financial interest, staff independence; the sponsor confirms their own |
Contract terms for any external provider
The contract is where the outsourced and co-sourced models’ governance weaknesses are fixed or left open, and it is usually negotiated by procurement against the provider’s standard engagement letter, which is written for the provider. The terms below are the ones an audit committee should insist on and read itself. They apply in full to outsourcing and in proportion to co-sourcing; a co-source arrangement for 140 hours of ERP security work still needs the independence, workpaper, and conflict terms.
| Term | What to require | Why |
|---|---|---|
| Reporting line | The provider reports functionally to the audit committee; the committee approves the plan, receives all reports, and meets the provider privately | Without it, the provider reports to whoever signs the invoice |
| Named staff and continuity | The engagement leader and key staff are named; changes require committee approval; a minimum tenure or a replacement-approval right | Institutional knowledge is the outsourced model’s weakest point; rotation destroys it |
| Scope and plan | The annual plan and hours are a schedule to the contract; changes are approved by the committee, not negotiated between the provider and management | Prevents scope erosion by the people being audited |
| Methodology and standards | Work is performed in conformance with the Global Internal Audit Standards; the methodology is disclosed and the committee may have it assessed | The five-year external assessment applies to the function whoever performs it |
| Workpapers and data | Workpapers are the organization’s property, held on or mirrored to its systems, accessible on demand, returned on termination; data handling meets the organization’s security policy | The organization must be able to hand its own audit files to a regulator or a successor provider |
| Independence and conflicts | Annual written confirmation; disclosure of all other services to the organization and its executives; prohibition on auditing the provider’s own advisory or implementation work; for public companies, confirmation that the provider is not the external auditor | Section 201 and basic objectivity |
| Access and cooperation | The provider has the access rights the charter grants internal audit; management’s obligations to cooperate are stated | A provider without charter authority is a consultant |
| Fees | Hours and rates by grade, or a fixed fee tied to a defined plan; change-order rules; no success or contingent fees | Effective rate visibility; contingent fees compromise objectivity |
| Performance measures | Plan completion, report cycle time, committee satisfaction, staff continuity, validation coverage; reviewed annually by the committee | Makes renewal a decision on evidence |
| Subcontracting | Not without committee consent; subcontractors bound by the same terms | Otherwise the named-staff term is hollow |
| Termination and transition | Termination by the committee for convenience on notice; a transition period with knowledge transfer, file handover, and continued follow-up on open issues | The exit is when the organization discovers what it did not own |
| Liability and insurance | Professional indemnity at a level proportionate to the engagement; liability caps reviewed by counsel | Standard, but often set at the fee value, which is too low for an assurance function |
The two terms most often missing are the reporting line and the workpaper ownership, and their absence explains most of the horror stories: a provider that could not be removed without the CFO’s agreement because the CFO held the contract, and a company that changed providers and found it did not own three years of its own audit files. The co-sourcing best practices guide covers how a chief audit executive manages the relationship day to day once the contract is right.
Three worked decisions
The three organizations below sit at different points on the size and regulation axes, and each reached a different answer by weighting the same twelve dimensions. The table records the decision the way a committee minute should: the options considered, the weights that decided it, the structure adopted, and the terms that made it safe.
| Element | Brightwater Foods: $180M specialty food manufacturer, 600 staff, private with lenders, first function | MidState Beverage: three-state distributor, 12 depots, six-person in-house function, fraud history | Lakeshore Bancorp: $9B regional bank, public, examined annually |
|---|---|---|---|
| Options considered | Outsource entirely (about $250,000 for six engagements); co-source with one hired head (about $345,000 for 1,600 hours); three-person in-house team (about $600,000) | Keep the in-house team; add co-source for ERP security and cyber; outsource the depot rotations to a regional firm | In-house with occasional specialists; co-source model validation and IT; outsource the whole function to a national firm (rejected early) |
| Weights that decided it | Institutional knowledge and independence weighted high because of the lender relationship and a founder-led culture; speed weighted low because the first engagement was six months away either way | Institutional knowledge and continuity weighted highest after the Dayton diversion; specialist skills weighted high for the ERP access engagement; cost weighted low | Regulatory acceptability and independence weighted highest; Section 201 excluded the external auditor; examiner expectations of a competent in-house manager made full outsourcing unacceptable |
| Decision | Co-source: hire a head of internal audit; buy 600 specialist and surge hours a year from a regional firm at about $220 an hour | Co-source: retain the in-house function; buy 140 hours of ERP security expertise for $28,000; keep depot rotations in-house because depot knowledge is the function’s core asset | In-house with structured co-source: twenty-two in-house auditors; a three-year co-source agreement for model validation and cybersecurity with a specialist firm that is not the external auditor |
| Terms that made it safe | Provider reports to the head of internal audit on the function’s methodology; named staff; workpapers in the company’s systems; no other services to the company; committee approves the co-source budget line | Specialist scoped to the ERP security question only; internal staff do the surrounding work; deliverables in the function’s workpaper format; independence confirmation on file | Committee approves the provider and named leads; annual conflicts disclosure covering all services to the bank; provider staff work under the CAE’s methodology; examiners briefed on the arrangement |
| What would change the answer | A pre-IPO decision would push toward the three-person team for ICFR readiness; losing the lender relationship would make outsourcing acceptable as an interim | A sale to a private equity owner might bring a managed-service model for cost reasons, which the committee should resist given the fraud history | Nothing short of a regulatory change; the bank’s size and examination regime fix the model |
Brightwater’s decision is the one most readers face, and the arithmetic behind it is in the site’s guide to setting up a small-company function, which prices the three options in detail. The point the committee minute captures is that the $95,000 difference between outsourcing and co-sourcing bought a person whose job was to know the company, and that after a lender’s field examination and a founder’s succession, that person turned out to be the function’s most valuable asset. The co-sourcing ROI guide shows how to make that case in the board paper.
Warning signs that the model has failed
Sourcing models fail slowly, and the committee is usually the last to know, because the failure is in what it is not being told. The signs below are observable from the committee’s chair, and each maps to a fixable term or governance step; a committee that sees two or more of them should treat the arrangement as impaired and act at the next meeting rather than at renewal.
| Warning sign | What it usually means | Model most exposed | Fix |
|---|---|---|---|
| Every report is Satisfactory | The function has stopped finding things, or has stopped reporting them; under outsourcing, the provider has learned what management rewards | Outsourced | Private session with the provider’s lead; compare ratings to incident and loss data; consider an external assessment |
| Different provider staff at every meeting | Rotation; institutional knowledge is not accumulating | Outsourced and co-sourced | Enforce the named-staff term; approve changes |
| The plan changes without coming to the committee | Management and the provider are negotiating scope | Outsourced | Plan and changes as a contract schedule approved by the committee |
| Findings are “observations” and actions are “recommendations” | Softening under commercial pressure | Outsourced | Rating definitions in the contract; committee reviews the distribution of ratings annually |
| The sponsor executive is the CFO and never disagrees with the provider | The CAE role is not being performed; the provider reports to its client | Outsourced | Move the sponsor role outside finance; committee chair as the substantive counterpart |
| The committee cannot get the workpapers | Ownership was never contracted | Outsourced | Amend the contract; mirror files to the organization’s systems |
| The provider is also implementing the new ERP or advising on SOX | A conflict that will eventually be audited around | Co-sourced and outsourced | Conflicts disclosure; exclude the conflicted area from the provider’s scope or change provider |
| The CAE signs provider reports without having reviewed the work | Co-sourcing has become outsourcing without the governance | Co-sourced | Review evidence on every provider workpaper; reduce provider share until the CAE can supervise it |
| Costs rise every year with the same plan | Change orders and rate escalation without committee visibility | Outsourced | Fees as a schedule; change orders approved by the committee; effective rate tracked |
| Validation of prior findings has stopped | Follow-up was never in the contracted scope | Outsourced | Validation windows and the issue log written into the plan schedule |
Moving between models
Most organizations change model at least once: outsourced to co-sourced as they grow, co-sourced to in-house as the function matures, occasionally in-house to co-sourced after a cost review. The transition is where the contract terms above are tested, and the sequence below is the one that preserves the function’s knowledge and the committee’s assurance through the change. From outsourced to co-sourced, hire the head of internal audit first and have them run the existing provider for two quarters before changing anything, so that the plan, the issue log, and the files are taken over by someone who has seen them work; renegotiate the provider’s role to specialist and surge work at the next plan cycle. From co-sourced to in-house, convert the provider’s recurring engagements to internal staff one cluster at a time as hires are made, keeping the provider on specialist work throughout, and do not let the provider’s last engagement end before its knowledge has been walked through with the person inheriting it. From in-house to a heavier co-source model, which usually follows a cost review, protect the CAE role and the core team’s knowledge of the highest-risk areas, and buy the commodity work rather than the judgment; a function that co-sources its route cash audit at a company with a cash-diversion history has sold the wrong thing.
In every direction, three things move with the function: the issue log with every open action and its evidence, the risk assessment and universe with the scoring history, and the workpaper archive for at least the current and prior cycle, all in the organization’s systems before the outgoing arrangement ends. The issue log template and the audit planning guide describe the two records in the form that survives a handover, and the QAIP guide covers how the function’s quality program continues across a change of model, which the five-year external assessment will examine.
Common board-level mistakes
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Deciding on price | The cheapest proposal wins; the governance terms are procurement’s problem | The board buys an instrument that cannot tell it bad news | Score the twelve dimensions with the committee’s weights; price is one row |
| Outsourcing the responsibility | The committee treats the provider as the accountable party | The Standards and the regulators place the duty on the board and a designated internal manager; it cannot be delegated | Name the sponsor executive, outside finance, with the CAE duties in the charter |
| The CFO as sponsor | The provider reports to, is paid by, and is renewed by the most-audited executive | Independence in form only; examiners and assessors see it | General counsel, company secretary, or a designated executive; committee chair as counterpart |
| Using the external auditor | The audit firm proposes internal audit outsourcing to a public company | Prohibited under Section 201; unwise under any rule | Exclude the external auditor from the shortlist |
| No named staff | The engagement letter promises “appropriately qualified professionals” | Rotation destroys institutional knowledge | Named lead and key staff; committee approval of changes |
| Provider’s methodology unexamined | The committee has never seen how the provider rates findings or sizes samples | Ratings and conclusions cannot be compared across years or providers | Methodology disclosed and, for outsourced functions, externally assessed |
| Workpapers on the provider’s servers | Files are the firm’s; access is by request | The organization does not own its own audit history | Ownership and mirroring in the contract |
| Conflicted provider | The co-source firm also runs the SOX readiness project or the ERP implementation | Self-review; the provider audits around its own work | Annual conflicts disclosure; exclusion of conflicted areas |
| Co-sourcing that has become outsourcing | The in-house CAE signs work they have not reviewed because 80 percent of hours are external | The governance of co-sourcing without its substance | Cap the provider share at what the CAE can supervise; review evidence on every provider file |
| No exit plan | The contract has no transition, handover, or file-return terms | The organization discovers what it did not own at the worst moment | Termination for convenience and a defined transition in every contract |
The right sourcing model is the one that gives the board an instrument it controls: a real chief audit executive role inside the organization, a plan the committee approves, reports that reach it unsoftened, files it owns, and a provider, if there is one, that answers to the committee rather than to the people it audits. Co-sourcing achieves that most naturally for most mid-sized organizations; outsourcing can achieve it with the right contract and sponsor; in-house achieves it by default at scale. What none of the models can do is substitute for a committee willing to read the private-session agenda and ask what it is not being told. The site’s ten signs you need external help covers the trigger for adding a provider to an in-house function, and the guides by role page collects the material for audit committee members and CAEs.
Related guides
- Internal audit co-sourcing 101 — how to buy external hours well once the model is chosen
- When to co-source: 10 signs — the trigger for adding a provider
- The ROI of co-sourcing — making the case in the board paper
- Co-sourcing best practices for CAEs — managing the relationship
- How much does an internal audit cost? — the build, blend, or buy arithmetic
- Setting up a small-company internal audit function — Brightwater’s three options priced
- GIAS Domain III: governing — the board’s duties under every model
- GIAS Domain IV: managing — the CAE’s duties including external providers
- QAIP and the external quality assessment — quality across a change of model
- Internal audit in financial services — what examiners expect of the arrangement
- All Guides — the full index
Leave a Reply