Skip to content

What internal audit co-sourcing is

Internal audit co-sourcing is a model in which an organisation's own internal audit function works with an external partner that supplies qualified auditors and specialist skills. The chief audit executive (CAE) keeps ownership of the audit universe, the risk-based plan, the methodology and the opinions given to the audit committee. The partner provides people and expertise that work inside that framework.

It sits between two familiar alternatives. Fully outsourced internal audit hands the function to a firm, which suits smaller organisations but distances management from the work. Purely in-house audit gives full control but is slow and costly to scale, and rarely covers every specialism a modern audit plan needs.

Co-sourcing keeps the control of the first model's opposite while borrowing the flexibility of the second. That is why it has become a common choice for mid-size and large organisations in the US, the UK, Europe, Australia and the Middle East.

Why demand for co-sourcing is rising

  • Wider scope. Audit plans now routinely include cyber security, third-party risk, data privacy, ESG reporting and the use of AI, alongside financial and operational controls.
  • Higher expectations. The IIA's Global Internal Audit Standards, in effect since January 2025, raise expectations on quality, independence and coverage. Reporting regimes such as Sarbanes-Oxley in the US, and strengthened internal control requirements in the UK, add recurring testing work.
  • Talent shortage. Experienced auditors and qualified accountants are scarce in most developed markets, so vacancies stay open and plans slip.
  • Uneven workload. Year-end testing, regulatory reviews and special investigations create peaks that a permanent team sized for the average cannot absorb.

Co-sourcing, outsourcing or hiring?

ModelWho owns the planBest forTrade-offs
In-house onlyInternal teamStable scope and a team already at full strength.Slow to scale; specialist skills are hard to keep busy all year.
Co-sourcedInternal team, with partner capacity and specialistsGrowing scope, peaks in testing, skill gaps, vacancies.Needs clear methodology, supervision and knowledge transfer.
Fully outsourcedExternal firmSmaller organisations without an audit function.Less institutional knowledge; management further from the work.

What to co-source first

Start where external capacity adds the most and the risk of handing work over is lowest:

  • Controls testing, including SOX testing support: walkthroughs, test-of-design and operating-effectiveness testing against your documented controls.
  • Recurring financial and operational audits across business units, entities and geographies.
  • Specialist reviews where you need expertise for weeks, not years: IT general controls, data analytics, regulatory reporting.
  • Follow-up of findings, so remediation is tracked and evidenced rather than left to the next annual cycle.
  • Peak support at year end or during regulatory reviews.

Keep the audit plan, risk assessment, final opinions and audit committee reporting with your own leadership. That division is what makes co-sourcing work.

Keeping quality, independence and confidentiality

The risk in any co-sourced model is inconsistency: different standards of work, documentation or judgement. Five practices manage it:

  • One methodology. Partner auditors work to your audit manual, templates and working-paper standards, in your audit management system.
  • Clear supervision. Every engagement has an in-house owner who reviews and signs off the work. The partner provides its own senior reviewers as a first line of quality.
  • Qualified people. Look for internationally recognised qualifications such as ACCA, CA, CPA or CIA, and experience in your industry and regulatory environment.
  • Independence checks. Confirm the partner does not provide services that would create conflicts, such as designing the controls it later tests.
  • Data protection. Work inside your systems with role-based access, confidentiality agreements and the data-handling controls your regulators expect.

The case for an offshore co-sourcing team

Co-sourcing does not need to mean flying in auditors. Much of the testing, analysis and documentation can be done by a qualified team in India working on your systems during your hours or across time zones. Combined with a small onshore or senior presence for interviews and site work, this gives three advantages:

  • Depth of qualified talent. India has a large pool of ACCA- and CA-qualified professionals with experience of international standards.
  • Continuity. A stable, named team builds knowledge of your business year after year, which rotating contract auditors cannot.
  • Room to grow. The same team can later support finance operations, close and reconciliations, and can become the start of a finance and audit capability centre.

How data analytics and AI change co-sourced audit

Co-sourcing is also a practical way to bring analytics into the audit plan without building a data team first. Instead of testing samples, a partner team can analyse full populations of transactions: every payment, every journal entry, every user access change. That surfaces exceptions a sample would miss and gives the audit committee stronger evidence.

Typical starting points include duplicate and unusual payments, journal entries posted outside normal patterns, segregation-of-duties conflicts and changes to vendor bank details. AI tools increasingly help classify exceptions and summarise documents, but auditors still own the judgement. Anything an AI tool produces should be reviewed, evidenced and reproducible, in the same way as any other audit work.

The same discipline applies when the organisation itself adopts AI in finance. Internal audit will be asked to give assurance over those models and automations, and a co-sourcing partner with that experience shortens the learning curve.

Pitfalls to avoid

  • Co-sourcing without a methodology. If the partner brings its own templates and standards, you end up with two audit functions and inconsistent evidence.
  • Handing over judgement. Partners can draft findings and recommendations, but ratings, opinions and audit committee messages must stay with your leadership.
  • Rotating people every cycle. Continuity is where much of the value lies. Ask for named team members and a plan for keeping them.
  • No knowledge transfer. Insist that work papers, process notes and data scripts stay with you, so the knowledge belongs to the organisation.
  • Measuring hours, not outcomes. Track plan delivery, quality of work papers and the closure of findings, not just days billed.

What this looks like in practice

For one of Japan's largest banks, we provide ACCA-qualified international audit professionals who work alongside the bank's global audit teams, inside the bank's own systems and to its standards of rigour and confidentiality. The same engagement runs accounts payable and receivable operations with the bank's finance teams. The case study describes the model.

How to start well

  • Define the scope for the first cycle: which audits, which testing, which entities.
  • Agree the methodology and quality gates before fieldwork begins, including review levels and documentation standards.
  • Onboard properly: system access, walkthroughs of key processes and an introduction to the people auditees will meet.
  • Measure it: plan completion on time, review points per working paper, issues raised and closed, and audit committee feedback.
  • Review after the first cycle and decide what to expand, such as more testing, specialist areas or finance operations.

Most organisations find that one full audit cycle is enough to judge the model. By then you will know whether the team meets your quality bar, how much supervision it needs and which parts of the plan it can take on next. Internal audit co-sourcing works best as a long-term partnership that grows with the plan, not as a one-off fix for a busy quarter.

For CFOs weighing broader options, our guide for finance leaders covers how co-sourcing fits with finance operations and a longer-term capability centre, and AI in finance and accounting looks at where automation now supports audit and close.

Frequently asked questions

What is internal audit co-sourcing?

A model in which an organisation's internal audit function works with an external partner that supplies qualified auditors and specialist skills, while the chief audit executive keeps ownership of the plan, methodology and conclusions.

What is the difference between co-sourcing and outsourcing internal audit?

In co-sourcing, your internal audit leadership owns the plan and opinions and the partner adds capacity and expertise. In outsourcing, an external firm runs the internal audit function on your behalf.

Which internal audit work is best suited to co-sourcing?

Controls testing including SOX testing support, recurring financial and operational audits, specialist reviews such as IT general controls, follow-up of findings, and peak workloads at year end or during regulatory reviews.

Can internal audit co-sourcing be done offshore?

Yes. Much testing, analysis and documentation can be performed by a qualified team working remotely on your systems, with role-based access and confidentiality controls, combined with onshore presence where interviews or site visits are needed.

How do you keep quality consistent with a co-sourced team?

Use one methodology and audit system, assign an in-house reviewer to every engagement, require recognised qualifications such as ACCA, CA, CPA or CIA, and measure review points and on-time completion.

Planning a capability centre?

Start with a capability assessment of one function. You keep the findings, with no commitment.