Skip to main content
Category: Internal Audit

Advisory Engagement

Also known as: Consulting Engagement, Advisory Services
Simply put

An advisory engagement is a service in which an internal audit or similar function provides advice, insight, or recommendations to help an organization improve its operations, rather than delivering an independent assurance opinion. The nature and scope of the work are typically agreed with the party requesting it. Some engagements may combine advisory work with assurance components.

Formal definition

In internal audit practice, an advisory (or consulting) engagement is an advice-oriented service whose nature and scope are generally agreed with the engagement client, undertaken to add value and improve an organization's governance, risk management, and control processes without the internal auditor assuming management responsibility. Advisory engagements are commonly distinguished from assurance engagements, in which the practitioner provides an independent, objective assessment; some engagements blend both assurance and advisory components. Examples cited in the evidence include systems development projects, due diligence, and large change initiatives, which may be identified when the internal audit plan is being developed. This entry does not cover specific methodologies, engagement-planning procedures, or the independence and objectivity safeguards applicable in particular frameworks or jurisdictions.

Why it matters

Advisory engagements matter because they allow an internal audit function to contribute value beyond its traditional assurance role, offering advice, insight, and recommendations that help improve an organization's governance, risk management, and control processes. Where assurance work delivers an independent, objective assessment, advisory work responds to a request for guidance, often on activities such as systems development projects, due diligence, or large change initiatives. This flexibility lets the function bring its perspective to bear early, when the organization is designing new processes rather than reviewing them after the fact.

The distinction between advisory and assurance work is significant for preserving the integrity of the internal audit function's role. In an advisory engagement, the internal auditor provides advice without assuming management responsibility for decisions or outcomes; management retains ownership of the choices it makes. Because the nature and scope of advisory work are generally agreed with the party requesting the service, the terms of engagement can differ substantially from the more standardized expectations that attach to an assurance opinion. Keeping this boundary clear helps protect the objectivity that assurance activities depend on.

Some engagements deliberately blend advisory and assurance components, which raises practical considerations about how the two are combined and communicated. Recognizing which engagements are primarily advisory, and identifying them, where possible, as the internal audit plan is developed, supports transparent expectation-setting with stakeholders. This entry does not address the specific independence and objectivity safeguards that particular frameworks or jurisdictions apply to such arrangements.

Who it's relevant to

Internal Auditors
Internal auditors performing advisory engagements provide advice, insight, and recommendations while taking care not to assume management responsibility. Understanding how advisory work differs from assurance work helps them agree an appropriate scope with the engagement client and maintain the objectivity their assurance activities rely on.
Chief Audit Executives and Audit Leadership
Those responsible for developing the internal audit plan may identify advisory engagements, such as systems development projects, due diligence, or large change initiatives, during planning. They also decide when and how to blend advisory and assurance components within an engagement.
Management and Engagement Clients
Managers who request advisory services agree the nature and scope of the work with the internal audit function. Because advisory engagements deliver advice rather than an independent assurance opinion, and because management retains responsibility for its decisions, understanding this distinction helps set appropriate expectations for what the engagement will and will not provide.

Inside Advisory Engagement

Consulting or Advisory Nature
An advisory engagement is a service undertaken at the request of, or in agreement with, the engagement client, typically intended to add value and improve governance, risk management, and control processes without the practitioner assuming management responsibility.
Agreed Scope and Objectives
The nature and scope of the work are commonly agreed with the requesting party in advance, distinguishing advisory work from assurance engagements where the internal audit function generally determines scope independently.
Recipient of the Output
The results are typically directed to the engagement client or requesting party rather than expressed as an independent opinion to a governing body, though reporting expectations may vary by mandate and internal audit charter.
Preservation of Objectivity
Even when providing advice, internal audit practitioners are commonly expected to maintain objectivity and avoid assuming management responsibilities, so as not to impair their independence for future assurance work on the same area.
Relationship to the Three Lines Model
In the IIA's three lines model, advisory engagements are one way the third line can support governance and risk processes; care is typically taken to keep advisory activity distinct from the management (first and second line) responsibilities being advised upon.

Common questions

Answers to the questions practitioners most commonly ask about Advisory Engagement.

Is an advisory engagement the same as an assurance engagement?
No. The two differ in purpose and in the independence and objectivity considerations that apply. An assurance engagement is designed to provide an independent, objective assessment, typically expressed as an opinion or conclusion on governance, risk management, or control, for the benefit of parties other than the process owner. An advisory (or consulting) engagement is intended to add value and improve processes, usually at the request of the client, without the auditor expressing the kind of independent opinion characteristic of assurance work. The nature and scope of an advisory engagement are commonly agreed with the engagement client, whereas assurance scope is generally determined by the assurance function.
Does performing an advisory engagement mean internal audit takes ownership of the resulting decisions or controls?
No. Advisory work is a service to management, and management retains ownership of the decisions, risks, and controls involved. The advisory role is typically to provide input, insight, or facilitation; it does not transfer accountability for the underlying process to the person providing the advice. Maintaining this distinction is important to preserving the objectivity of an assurance function, particularly where it may later be asked to provide assurance over an area on which it previously advised.
How should the scope and objectives of an advisory engagement be established?
In many frameworks the scope, objectives, and nature of an advisory engagement are agreed with the engagement client before work begins, often documented in some form of understanding or engagement terms. Because advisory work is generally requested rather than mandated, clarifying deliverables, boundaries, and the respective responsibilities of the adviser and the client at the outset helps manage expectations. The specific form this documentation takes varies by organization and function.
How can a function manage the risk to its objectivity when advisory work precedes later assurance work?
A common practice is to consider whether providing advice on a process could impair the ability to assure that same process objectively in future. Functions may address this by disclosing the prior advisory involvement, assigning different personnel to any subsequent assurance engagement, or otherwise safeguarding independence. The appropriate safeguard depends on the function's mandate and applicable professional expectations, and management's retention of decision ownership remains central.
Should the results of an advisory engagement be reported, and to whom?
Reporting for advisory engagements is typically directed to the engagement client, consistent with the agreed nature of the work, rather than following the broader reporting lines used for assurance conclusions. Some functions also periodically summarize advisory activity for governance bodies to provide visibility into how audit resources are deployed. Specific reporting protocols vary by organization and by any applicable professional guidance.
What should be considered when deciding whether to accept an advisory engagement?
Considerations commonly include whether the work aligns with the function's mandate and competencies, its potential to add value or improve processes, resource availability relative to planned assurance work, and any implications for independence and objectivity. Where an engagement would consume significant resources, functions may weigh the trade-off against assurance coverage. These are judgment factors rather than fixed rules, and their weighting depends on the organization's context.

Common misconceptions

An advisory engagement produces the same kind of independent assurance opinion as an assurance engagement.
Advisory (consulting) engagements are generally distinct from assurance engagements. Assurance work typically involves an objective assessment to provide an independent opinion to a governing body, whereas advisory work is performed at the client's request to add value, and its scope is commonly agreed with that client. Conflating the two can blur the independence distinctions that assurance functions rely upon.
Providing advice means the practitioner takes on a management or decision-making role for the area advised.
In many frameworks, practitioners providing advisory services are expected to avoid assuming management responsibilities. Making or owning management decisions can impair objectivity and independence, potentially precluding the function from performing later assurance work over the same area.
Because it is advisory, objectivity requirements do not apply.
Objectivity is typically still expected during advisory engagements. The reduced formality of an advisory engagement relative to assurance does not remove the practitioner's obligation to remain objective and to consider potential impairments to future independence.

Best practices

Agree the nature, scope, and objectives of the advisory engagement with the requesting party in advance, and document these terms to set clear expectations.
Maintain objectivity throughout the engagement and avoid assuming management responsibilities or making decisions that belong to the first or second line.
Assess and document any potential impairment to independence that advising on an area may create for future assurance work over that same area.
Clarify who will receive the output and in what form, distinguishing advisory results directed to the engagement client from independent assurance opinions provided to a governing body.
Position advisory work appropriately within the organization's governance structure and the three lines model, keeping it distinct from the management activities being advised upon.
Refer to the internal audit charter and applicable professional standards to confirm the function's authority and reporting expectations for advisory engagements, as these can vary by mandate and jurisdiction.
Promotional banner for the Penetration Report Template Kit