Skip to main content
Category: Internal Audit

Reliance on Assurance

Also known as: Reliance by Internal Audit on Other Assurance Providers, Assurance Reliance, Coordination and Reliance
Simply put

Reliance on assurance is when an internal audit function uses the work already performed by other parties that also provide assurance, rather than repeating that work itself. This can help avoid duplicated effort and use audit resources more efficiently. It applies to assurance from both internal sources and external sources.

Formal definition

Reliance on assurance refers to an approach in which the chief audit executive (CAE) and internal audit leadership place reliance on assurance work carried out by other internal or external assurance providers, as addressed in IIA practice guidance on coordination and reliance. It is a coordination mechanism intended to improve efficiency and reduce duplication across assurance activities, typically requiring the CAE to evaluate the competence, objectivity, and quality of the other provider's work before relying on it. This entry addresses the concept of relying on other providers' assurance; it does not prescribe specific evaluation criteria, documentation requirements, or the extent to which reliance is permitted, which depend on applicable guidance, jurisdiction, and organizational context. Independence and objectivity distinctions between internal audit as an assurance function and the parties whose work is relied upon should be maintained.

Why it matters

Organizations frequently face assurance from multiple sources, including internal audit, second line risk and compliance functions, external auditors, regulators, and specialist reviewers. Without coordination, these activities can overlap, subjecting the same processes to repeated review while other areas receive little coverage. Reliance on assurance addresses this by allowing internal audit to draw on work already performed by others, which can help direct limited audit resources toward areas of greater need and reduce duplicated effort across the assurance landscape.

The practice matters most where audit capacity is constrained relative to the range of risks an organization must cover. By placing reliance on credible work from other providers, the chief audit executive can extend the effective reach of internal audit without simply re-performing procedures. This depends, however, on the reliability of the work being relied upon; the IIA practice guidance on coordination and reliance frames the CAE's evaluation of the competence, objectivity, and quality of another provider's work as central to whether reliance is appropriate.

Reliance also carries a governance dimension because it touches the independence and objectivity that distinguish internal audit as an assurance function from the parties whose work it uses. Reliance is not a transfer of responsibility, and the distinctions between internal audit and the sources it relies upon should be maintained. Whether, and how far, reliance is permitted depends on applicable guidance, jurisdiction, and organizational context rather than on any single universal rule.

Who it's relevant to

Chief Audit Executives and Internal Audit Leadership
The CAE and internal audit leadership are the primary audience for reliance decisions. They determine when reliance on other providers is appropriate, evaluate the competence, objectivity, and quality of that work, and coordinate coverage so audit resources are used efficiently while independence and objectivity are maintained.
Internal Auditors
Practitioners planning and performing engagements need to understand how reliance affects scoping, so that coverage is coordinated with other assurance activities and effort is not needlessly duplicated, while recognizing that reliance does not remove internal audit's own responsibilities.
Second Line Risk and Compliance Functions
Risk management and compliance functions are among the internal providers whose assurance work may be relied upon. Understanding how internal audit evaluates and coordinates with their work supports effective assurance mapping across the organization, while preserving the distinction between these management-aligned functions and internal audit's assurance role.
External Assurance Providers
External auditors, regulators, and specialist reviewers may produce work that internal audit considers relying upon. Awareness of how their competence, objectivity, and quality are assessed helps clarify the basis on which their assurance may be used by an internal audit function.
Audit Committees and Governance Bodies
Those charged with oversight benefit from understanding reliance as a coordination mechanism, since it affects how assurance is distributed across the organization and how efficiently audit resources are deployed, without transferring internal audit's accountability for the reliance it places.

Inside Reliance on Assurance

Assurance Source
The function or party providing the assurance on which reliance is placed, which may include second line monitoring functions, internal audit, external auditors, or independent third parties. The nature and independence of the source shape the degree of reliance that is appropriate.
Objectivity and Independence Assessment
An evaluation of whether the assurance provider is sufficiently free from conflicts of interest and organizational bias to render a reliable conclusion. Reliance on assurance from a function that lacks independence typically warrants greater caution.
Competence and Proficiency
Consideration of whether the assurance provider possesses the skills, knowledge, and resources to perform the work, since the credibility of the assurance depends in part on the capability of those performing it.
Scope and Coverage
The extent to which the assurance work addresses the risks, controls, or processes relevant to the relying party's needs. Reliance is generally limited to what the assurance activity actually examined, not areas outside its stated scope.
Quality and Sufficiency of Evidence
The basis on which the assurance conclusion rests, including the methodology, testing approach, and evidence gathered. Reliance may be tempered where the underlying work is inconclusive or based on limited evidence.
Coordination Across Lines
The alignment of assurance activities across the first, second, and third lines to avoid duplication or gaps. Reliance on assurance often involves one function drawing on the work of another, consistent with a coordinated assurance approach.

Common questions

Answers to the questions practitioners most commonly ask about Reliance on Assurance.

Does reliance on assurance mean one function can simply defer to another's work without doing anything itself?
No. Reliance is not a wholesale transfer of responsibility. A function that relies on another's assurance typically remains accountable for its own conclusions and is generally expected to evaluate the relevance, sufficiency, and reliability of the work relied upon before placing weight on it. Reliance reduces duplication where appropriate; it does not eliminate the relying party's own judgment or accountability.
Can management activities be treated as a source of assurance in the same way as independent audit work?
These should be distinguished. Management's own monitoring and self-assessment can inform a view of control performance, but it is generally regarded as a management activity rather than independent assurance. Assurance functions that value objectivity and independence, such as internal audit under the three lines model of the IIA, commonly weight the reliability of a source according to its independence from the activity being assessed. Reliance on management-generated information typically warrants greater corroboration than reliance on independent work.
How can a function assess whether another party's assurance work is reliable enough to rely on?
In many frameworks, this assessment considers factors such as the competence and objectivity of the provider, the scope and timing of the work relative to the reliance being placed, the methodology applied, and the sufficiency of the underlying evidence. The relying party may also re-perform or test a sample of the work to validate its quality. The depth of this evaluation commonly scales with the significance of the risk or decision the reliance supports.
What should be documented when placing reliance on another party's assurance?
Documentation practices vary, but relying parties commonly record the source relied upon, the scope and period covered, the basis for concluding the work is reliable, and any limitations or gaps that reliance does not address. Where reliance is partial, it is useful to note what additional procedures were performed to cover the residual scope. This supports transparency and helps demonstrate that reliance was a considered decision rather than an assumption.
How does reliance on assurance relate to the three lines model?
Under the three lines model of the IIA, first line management owns and manages risks and controls, second line functions provide oversight and expertise, and third line internal audit provides independent assurance. Reliance can flow between these lines, for example internal audit considering the work of a second line function, but the appropriateness of such reliance typically depends on the objectivity and competence of the source. The model does not prescribe a single mandatory approach to reliance, and arrangements often differ by organization.
When might reliance on assurance be inappropriate or need to be limited?
Reliance may be inappropriate where the source lacks sufficient independence or competence for the matter at hand, where the scope or timing of the underlying work does not align with the current reliance need, or where the risk is significant enough that corroborating evidence is warranted. Reliance is also generally limited to the specific scope the underlying work covered; extending a conclusion beyond that scope is a common misuse. This entry does not address specific tooling, legal advice, or the evidentiary standards of any particular jurisdiction or regulator.

Common misconceptions

Placing reliance on an assurance function transfers accountability for the underlying risks and controls to that function.
Management typically retains ownership and accountability for risks and controls. Reliance on assurance informs a relying party's judgment but does not shift the responsibility for managing the risk or operating the control to the assurance provider.
Assurance provides a guarantee that controls are effective or that objectives will be achieved.
Assurance offers a level of confidence based on the work performed and the evidence examined; it is subject to inherent limitations such as sampling, judgment, and scope boundaries. It does not guarantee outcomes, and reliance should reflect these limitations.
All assurance sources warrant the same degree of reliance.
The appropriate degree of reliance commonly varies with the source's independence, competence, scope, and the sufficiency of its evidence. Assurance from a function lacking objectivity or with limited scope generally supports a lower degree of reliance than assurance from an independent, competent source with relevant coverage.

Best practices

Before relying on an assurance source, assess its objectivity, independence, and competence, and document the rationale supporting the intended degree of reliance.
Confirm that the scope and timing of the assurance work align with the risks, controls, or processes for which reliance is sought, and limit reliance to what was actually examined.
Evaluate the sufficiency and quality of the evidence and methodology underlying the assurance conclusion rather than accepting the conclusion at face value.
Coordinate assurance activities across the first, second, and third lines to reduce duplication and identify coverage gaps, in a manner consistent with a coordinated assurance approach.
Preserve the distinction between assurance and management activities, recognizing that reliance on assurance does not transfer ownership or accountability for risks and controls.
Periodically revisit reliance decisions as circumstances, scope, or the independence and capability of assurance sources change.
Application Security Isn’t Optional Anymore.