A recurring debate within the internal audit community centers around this question:
Can we truly rely on the work of other assurance providers to reduce duplication of efforts – and if so, how do we do it responsibly?
With the release of the new Global IIA Practice Guide on Coordination and Reliance: Working with Other Assurance Providers, we now have structured guidance on this topic, and a clear direction forward.
Why This Matters
Relying on other assurance providers isn’t just a resource-saving tactic. It’s a governance decision that impacts audit quality, stakeholder trust, and the integrity of assurance reporting.
The guidance encourages internal audit teams to create an assurance map in alignment with coordination standards and, more importantly, to document a clear methodology for evaluating the basis and level of reliance.
This means moving from intuition and informal collaboration to documented, defendable criteria.
The Four Steps to Evaluate Reliance
The guide outlines a simple but powerful process:
- Identify: Determine which assurance providers cover relevant risk areas.
- Evaluate: Assess their methodology, independence, and output.
- Adjust: Modify your audit scope based on the quality and gaps of their work.
- Monitor: Reassess over time to ensure continued reliability.
This structured approach ensures that reliance decisions aren’t based on assumptions but on evidence and clarity.
Levels of Reliance Defined
One of the most helpful contributions of the guide is its definition of reliance levels:
- High Reliance: Minimal additional testing by internal audit; full trust in provider’s work.
- Moderate Reliance: Partial trust; limited additional testing still required.
- Low Reliance: Provider’s work used as input, but substantial independent testing conducted.
This framework brings consistency to what has often been a subjective judgment.
Criteria for Assessing Reliability
To determine how much you can rely on another provider, the guide suggests evaluating five key factors:
- Purpose of the work
- Independence and objectivity
- Competency of the provider
- Elements of practice (methodologies, scope, quality controls)
- Communication of results
Each of these areas helps auditors make informed, evidence-backed decisions on when and how much to rely on another’s work.
From Practice to Reality
Reflecting on past experience, high reliance has typically only been feasible with external auditors, largely due to their robust methodology and independence.
In contrast, many second-line assurance providers have lacked the structure or autonomy necessary for full reliance. Their insights could inform audit planning but not replace independent evaluation.
This new guidance gives internal audit teams the framework to make those distinctions with greater transparency and accountability.
Rethinking Reliance in Your Organization
As the internal audit function continues to mature, reliance should evolve from being a point of debate to a point of design.
Ask yourself:
- Do we have a consistent methodology for evaluating other assurance providers?
- Are our decisions on reliance documented, repeatable, and aligned with best practices?
- Could reliance help us focus more energy on strategic, high-risk areas — without compromising quality?
In a time where assurance demands are increasing but resources remain tight, making the right call on reliance isn’t just tactical, it’s essential to audit leadership.