Blog

The Internal Audit Co-Sourcing Conversation: How to Make the Case to Your Audit Committee

Subscribe now to join the Risk Register community:

Most internal audit leaders already know they need help. The question is how to say that to an audit committee in a way that lands as strategic rather than as a request for more resources.

The difference between those two conversations comes down to framing. Co-sourcing is not a staffing request. It is a capability decision, and the audit committee is exactly the right audience to hear it framed that way.

Audit Committees Already Expect This Conversation

Most audit committee members have seen this pattern before: an internal audit function covering a wider risk landscape every year, with a budget that has not kept pace. The 2024 IIA Global Internal Audit Standards reinforce that internal audit is accountable for assurance across the full scope of the organization's risk universe, including technology risk, third-party risk, and AI governance. In practice, those expectations land on a function whose expertise was scoped for a narrower risk universe than the one it is now accountable for.

What that means for your pitch: you are not asking the committee to fund a gap. You are inviting them into a conversation about how the audit function scales its capability to match its mandate. That reframe does most of the work.

According to the IIA's 2023 Global Internal Audit Practitioner Survey, more than 60% of internal audit leaders reported that emerging risk areas such as cybersecurity and AI are now part of their audit scope, but fewer than half said their team has sufficient specialized expertise to cover them. The committee already suspects this. A direct conversation about co-sourcing is not a surprise. It is an answer.

The Language That Loses the Room

Audit committees hear budget and resource requests constantly. The fastest way to have your co-sourcing conversation heard as just another one of those is to frame it around capacity alone. "We don't have enough people" is true, but it is not the argument that moves the room.

Here is the language that tends to land poorly: asking for additional headcount, describing the function as stretched thin, or positioning co-sourcing as a stopgap while you try to hire. All of those framings put the committee in a mode of weighing cost versus necessity, which is a negotiation you rarely win.

Language that works: capability, coverage, credibility. The conversation committee members want to have is about whether internal audit is positioned to provide reliable assurance across the risk areas they are accountable for. When you connect co-sourcing to that question, you are speaking their language. What assurance gaps exist today? What risks are moving fast enough that waiting on a full-time hire is the wrong answer? Where does specialized expertise produce better audit outcomes than a generalist with a good attitude?

Three Arguments That Land With Audit Committees

The most effective co-sourcing conversations with audit committees tend to cluster around three arguments, and each one connects the decision to something the committee already cares about.

First: specialized expertise on demand is faster and more credible than building internally. A cybersecurity audit engagement, a SOC 2 review, a third-party risk assessment under the IIA's new Topical Requirement (effective September 15, 2026) each requires a specific knowledge base that takes years to develop. Co-sourcing lets you rent that expertise for the engagement instead of buying it permanently. Renting keeps the function flexible as risk areas shift; buying locks you into a fixed skill set and a full-time salary you carry whether the need returns or not.

Second: co-sourcing does not replace your team. It extends it. This distinction matters to audit committees because it preserves the institutional knowledge and organizational relationships that sit inside the function. Your team still runs the engagement. The co-sourced partner brings depth in a specific area. Full stop.

Third: a well-scoped co-sourcing engagement is a more efficient use of budget than a full-time hire for a need that surfaces once or twice a year. The committee will appreciate that this is a deliberate resource allocation decision, not a reaction to being overwhelmed.

Scoping the Ask Before You Walk In

Vague requests get vague responses. The strongest co-sourcing presentations to audit committees come in with a defined scope: here is the specific engagement, here is the expertise required, here is why this moment calls for it, and here is what the function gains from it.

Consider a CAE who has just taken on responsibility for auditing the organization's AI-enabled vendor platforms but has no one on the team with applied AI governance experience. Walking in with a named engagement ("AI-enabled process audit, Q3") and a defined capability gap ("alignment with NIST AI RMF and the committee's disclosure expectations") is a completely different conversation than "we need more expertise in AI."

The more specific you can be about what the engagement covers, what the deliverable looks like, and what risk it addresses, the easier it is for the committee to approve. Committees are not resistant to co-sourcing in principle. They are resistant to undefined requests. Give them something concrete to react to.

What the Committee Is Really Evaluating

Behind every audit committee conversation about co-sourcing is a deeper question: does the CAE have a clear view of what the function needs to provide reliable assurance, and is the CAE managing the function strategically? The co-sourcing ask is actually an opportunity to demonstrate both.

When you walk in with a co-sourcing recommendation that is tied to a specific risk area, scoped to a defined engagement, and connected to the audit plan they have already approved, you are showing the committee exactly what they want to see. You understand the risk landscape. You are being intentional about how the function covers it. And you are making a resource decision based on what produces the best audit outcome, not on what is easiest to staff.

Here is a question worth sitting with before the meeting: if the committee asks why you are recommending co-sourcing for this particular area rather than hiring or training internally, can you answer that in two sentences? If yes, you are ready. If you are still working out the answer, work it out first.

Positioning Co-Sourcing as a Long-Term Capability Model

The most sophisticated internal audit functions use co-sourcing not as a reaction to a gap but as a deliberate part of how they scale. They maintain a strong internal team that carries institutional knowledge and organizational relationships, and they bring in specialized expertise for engagements that require it. That model gives the function flexibility as risk areas shift without requiring headcount decisions every time the landscape changes.

According to the ACFE's 2024 Report to the Nations, the median cost of a fraud scheme that went undetected for more than two years was $189,000 versus $88,000 for those detected within a year. The cost of not having the right coverage at the right moment is measurable. The audit committee already knows this. Your job is to help them see co-sourcing as the mechanism that closes that coverage gap before it becomes a finding.

When internal audit can bring in the right expertise for cybersecurity, AI governance, third-party risk, or fraud investigations on an engagement-by-engagement basis, the function is not just covering more ground. It is building a more credible assurance picture for the board. That is the argument that gets co-sourcing approved.

The Next Conversation Is Already on the Horizon

Risk areas that did not exist five years ago are now firmly inside the audit committee's line of sight: AI governance, cyber disclosure obligations, third-party concentration risk, anti-corruption programs in a geopolitical environment that makes the old control playbook look quaint. The committees that are moving fast on these topics are not waiting for internal audit to figure it out on a delayed timeline.

The internal audit functions that will hold their credibility through this period are the ones that build the capability architecture now. Co-sourcing is part of that architecture. The committee conversation you have today is not just about a single engagement. It is about how the function positions itself for the next five years of risk expectations.

If you want to think through how co-sourcing fits the specific risk coverage gaps in your current audit plan, Cherry Hill Advisory's internal audit co-sourcing practice works alongside internal audit teams to extend capacity and bring specialized expertise for exactly these conversations. 

Reach out through our internal audit co-sourcing page to start the discussion.

Subscribe now to join the Risk Register community: