Skip to main content

IIA Standards · COSO 2013 · SOX 404

Internal audit and SOX delivery support

You win the internal audit and SOX engagements, then watch the margin disappear into US staffing. We execute the fieldwork under your supervision so the work is worth running and your seniors stay on the parts that need them.

Your firm holds the engagement, the client relationship, and the committee reporting. Before any of it starts, your firm confirms it is permitted to provide internal audit services to that client at all.

The arrangement

How an internal audit engagement is split

Agreed before scoping. On internal audit the independence question comes first, ahead of capacity, ahead of price.

You

Stays with your firm

  • Client acceptance, the engagement letter, and the independence conclusion
  • Confirming your firm may provide internal audit services to that client at all
  • The risk assessment conclusions and the annual plan presented to the audit committee
  • Direction, supervision, and review of every procedure and workpaper
  • Finding severity ratings as issued, and the report that goes to the committee
  • All committee and management presentations, and the client relationship

Us

What we do

  • Risk assessment support: data gathering, interview notes, and draft risk ranking
  • Process walkthroughs and control design documentation
  • SOX 404 control testing, sampling, and evidence evaluation
  • IT general controls testing across access, change management, and recovery
  • Draft findings with condition, root cause, risk rating, and recommendation
  • Remediation tracking, retesting, and the quarterly committee pack in your template

Models

Three ways we plug into your engagement

The right model depends on what your team already covers. Most relationships start in one and move to another as the engagement settles.

01

Full delivery support

Your firm holds the internal audit engagement and we execute substantially all of the fieldwork under your direction. Your manager or partner runs the client relationship, presents to the committee, and reviews every workpaper before it leaves your firm.

Best when you are winning recurring internal audit work whose economics do not survive US-only staffing.

02

Co-sourcing with your team

Your people run the engagement and we supplement them on the areas they are not staffed for: IT general controls, data analytics, high-volume SOX testing, or a regulated process nobody on the team has covered before.

Best when the engagement is staffed but two or three workstreams are consuming disproportionate senior time.

03

Project and surge support

A defined piece of work with a deliverable and an end date: a SOX cycle running behind, a remediation program needing independent retesting, or a deep-dive the committee asked for after an incident.

Best when the need is a deadline rather than an ongoing capacity gap.

Coverage

What we execute, and what you receive

Whatever the approved plan calls for. Every output is a document your partner can review, finalize, and put in front of a committee under your firm's name. Nothing is a verbal update.

The work we execute

  • Enterprise risk assessment and fraud risk assessment support
  • Audit universe definition and draft risk-based annual plans
  • Process walkthroughs and control design assessment
  • Operational audits and compliance audits
  • SOX 404 scoping support, control documentation, and operating effectiveness testing
  • IT general controls: logical access, change management, backup and recovery, job scheduling
  • Third-party and vendor risk reviews, including evaluation of vendors’ SOC reports
  • Policy and procedure drafting where no documented process exists
  • Remediation validation and retesting of prior findings
  • Quarterly and annual audit committee pack preparation

What reaches your partner

  • Risk assessment working file with the methodology and ranking exposed
  • Draft annual internal audit plan in your template, ready for committee presentation
  • Engagement-level workpapers prepared for external auditor inspection
  • Draft findings: condition, root cause, rating, recommendation, and proposed management response
  • Quarterly audit committee pack covering plan progress and open findings
  • Remediation tracker with retesting evidence as items are closed

Standards

What we document against

Deliverables have to survive presentation to an audit committee and inspection by an external auditor. That constrains how the work is documented, not just how it is performed.

IIA Global Internal Audit Standards
Effective January 9, 2025. Five domains and 15 principles, weighted toward the board relationship and the quality assurance program.
IIA Topical Requirements
Mandatory once a subject appears in a plan. Cybersecurity in force since February 5, 2026; Third-Party Risk, Culture, and Business Resilience follow.
COSO 2013
Five components and 17 principles. What we test against for internal control over financial reporting, including SOX 404.

Process

How an engagement runs

Timings assume a mid-sized client and reasonable access to process owners. Committee scheduling, not our availability, is usually the constraint.

  1. 01

    Independence and scoping with your partner

    1 week

    Before anything else, your firm confirms it may provide internal audit services to this client. We then size the plan and agree which engagements and workstreams we carry.

  2. 02

    Risk assessment support

    3–5 weeks

    We prepare the interview schedule, capture and synthesize the interviews your team runs, review prior findings and incident history, and draft the risk-ranked audit universe for your team to conclude on.

  3. 03

    Annual plan drafted for your committee presentation

    1–2 weeks

    A draft plan with proposed engagements, timing, and hours in your template. Your partner presents it. Changes the committee makes come back through your partner, not through us.

  4. 04

    Engagement scoping and fieldwork

    2–5 weeks per engagement

    Scope memo, walkthroughs, control design assessment, and operating effectiveness testing, documented so that an external auditor evaluating whether to use the work can answer their questions from the file.

  5. 05

    Draft findings and internal review

    1–2 weeks

    Every finding carries condition, root cause, a rating against your scale, and a recommendation. The file passes our internal review against your prior review notes before it reaches your manager.

  6. 06

    Your review, committee reporting, and follow-up

    Quarterly

    Your firm finalizes ratings, agrees management action plans, and reports to the committee. We maintain the remediation tracker and perform retesting when items come due.

Independence

Why we raise this before we quote

Independence on internal audit engagements is more restrictive than on SOC work and more restrictive than most capacity conversations assume. The restriction operates on your firm, in relation to your client, and it is not something our involvement changes in either direction.

What our involvement does change is the supervision requirement. Work performed by people outside your firm still has to be directed, supervised, and reviewed by your firm, and the file has to show that it was. We build the documentation trail that makes your supervision evidenceable rather than asserted.

We would rather have this conversation at the scoping call than have your findings set aside later on independence grounds by an external auditor, a regulator, or opposing counsel.

Questions

Internal audit support FAQ

What partners and quality control leaders ask before adding offshore delivery to a risk advisory practice.

Can our firm provide internal audit services to a client we also audit?

Generally no, and this is the first thing to settle. The independence rules restrict a firm from providing internal audit outsourcing services to an entity whose financial statements it audits, because doing so places the firm in a management role over the very controls the audit must evaluate.

For SEC registrants the restriction is stricter: SEC and PCAOB independence rules prohibit internal audit outsourcing for audit clients, subject to narrow exceptions, and require audit committee pre-approval of permitted non-audit services. The conclusion is your firm’s to reach and document. We will not begin work until you tell us it has been reached, and we would rather lose the engagement than be the reason it becomes a finding.

Do you deal with our client directly?

Not by default. Your firm holds the relationship, runs the interviews, presents to the audit committee, and delivers the findings. We prepare the material that makes those conversations possible.

Some firms do authorize our seniors to join walkthrough calls or evidence requests directly, under their own protocol and with the client informed. That is a decision you make and document, not one we assume. Where it is not authorized, we draft and you send.

How is this different from the external audit work you do?

The external audit exists to support an opinion on financial statements for people outside the company. Its scope is whatever supports that opinion.

Internal audit gives the board and management independent assurance over whatever they need it over: a process, a system, a control environment, a fraud risk, a compliance obligation. Scope comes from the risk assessment and is approved by the audit committee. It produces findings and recommendations rather than an opinion. Our role is the same in both cases: we execute under your supervision and your firm concludes.

Will our external auditor accept work your team performed?

That is the external auditor’s judgment, and it turns on the objectivity of the internal audit function, the competence of the people performing the work, and whether the work was performed with due professional care and adequately documented.

What we control is the documentation. Workpapers are built to stand on their own: the population, the sampling rationale, what was examined, and what was concluded. In practice the useful step is an early conversation each year between your partner and the external audit team about which areas they would like covered and in what depth.

How do you price it, and what does it save?

We price from the approved plan: the engagements, their complexity, and the hours each needs. You get a fixed fee per engagement or a committed monthly capacity, and it changes only when the plan changes.

What it saves depends entirely on your current staffing mix and your realization on this work. We will model it against your actual plan during scoping rather than quoting a percentage. Any provider quoting a headline saving before seeing your plan is quoting a marketing number.

What credentials do the people on our engagements hold?

The credentials that matter for this work are the CIA, the CISA for IT general controls, the CPA or CA for financial process and SOX work, and the CFE for fraud engagements.

What our team actually holds is listed on our about page and driven from configuration, and we name the specific individuals who would staff your engagements in the proposal. If a credential is not shown there, we do not hold it.

How quickly can you start?

A scoped project or a single workstream can usually begin within two to four weeks of a signed services agreement, subject to your independence confirmation and our onboarding to your methodology.

Standing up support for a full function takes longer, because the risk assessment comes first and the committee has to approve the plan. Expect six to ten weeks from agreement to first fieldwork, most of which is interview and committee scheduling on the client side rather than our availability.

Send us the approved plan and we'll tell you what we can carry.

Engagements, workstreams, timing, and your review standards. You get a written capacity plan, a fee against the plan, and the onboarding checklist your quality control team will want.

See how the work is split