Back to Blog

Internal Audit Co-Sourcing vs Outsourcing: How to Structure and Price It

AccountingHiring

Last updated: October 8, 2026

By Tom Kenaley, President and Senior Partner, KORE1

Co-sourcing internal audit means your chief audit executive keeps the plan, the methodology, and the sign-off, and buys outside hours for specific gaps. Outsourcing hands the whole function to a firm. The decision is about who stays accountable, not about headcount.

The quote came back at $410,000 a year.

A specialty lender outside Cincinnati, Ohio had a three-person internal audit department and an audit committee that had just added cybersecurity to the annual plan. None of the three had ever scoped an IT general controls review. The chair wanted the work done by the next cycle, and the chief audit executive did what most people do first. She asked a national firm what it would cost to take the whole thing off her hands.

$410,000. Methodology theirs. Workpapers theirs. Findings delivered to her committee by someone who did not report to her.

What she actually needed was closer to 600 hours of ITGC and access-review work from two people who knew Entra ID and Oracle EBS, running inside her methodology, on her engagement template. That is a different purchase. It is also roughly a quarter of the money, and she kept the department.

You should know what I sell before you weigh a word of this. KORE1 staffs contract auditors into client functions through our accounting and finance staffing practice, so the model I am about to describe in friendly terms is the one that pays us. The regulatory citations below are not ours though. Check them.

Contract IT auditor and in-house internal auditor reviewing control testing results together on dual monitors in an open office

Two Models, and the Only Question That Separates Them

Co-sourced internal audit is an arrangement where an external provider supplies auditors who work inside your internal audit function, under your chief audit executive, using your methodology and reporting through your chain. The provider fills a capacity or skill gap. Ownership never moves.

Full outsourcing moves it. A firm takes the mandate, runs the plan, and reports findings. For a company with no function at all, that is sometimes the only honest option, and I am not going to pretend otherwise.

Everything else is detail. Here is the detail.

DimensionCo-sourcingFull outsourcing
Who owns the audit planYour CAEThe provider, within a mandate you approve
Methodology and templatesYours, and auditors are trained into itTheirs, usually proprietary
Cost shapeVariable, by the hour or by the auditAnnual retainer, priced on the full plan
What you keep at the endWorkpapers, risk knowledge, trained staffA report, and a renewal conversation
Best fitA function exists and has a specific gapNo function, or audit is not a capability you intend to build
Quiet riskYour methodology has to actually exist in writingInstitutional memory leaves when the contract does

Read the last row twice. Most co-sourcing arrangements that go badly go badly there, because a contractor cannot work inside a methodology that lives in one person’s head.

The Rule That Rules Out Your Most Obvious Vendor

Your external audit firm already knows your controls. They are on site anyway. The partner is responsive and the engagement team has read your trial balance more carefully than most of your own staff have. So the first call a lot of CAEs want to make is to them.

They cannot take it.

Under the SEC’s auditor independence rule at 17 CFR 210.2-01(c)(4)(v), an accountant is not independent if the firm performs “any internal audit service that has been outsourced by the audit client that relates to the audit client’s internal accounting controls, financial systems, or financial statements,” unless it is reasonable to conclude the results will not be subject to audit procedures during the financial statement audit. In practice that carve-out is narrow enough that most firms will not go near it. The reason is plain once you say it out loud. Nobody should audit their own work.

The listing standards say the same thing from the other direction. NYSE Listed Company Manual Section 303A.07(c) requires every listed company to have an internal audit function and allows that function to be outsourced to a third-party service provider “other than an issuer’s independent auditor.”

Which leaves a smaller field than people expect: the other national and regional accounting firms, specialist internal audit consultancies, and staffing firms that place contract auditors. Three categories, three different pricing logics, and only one of them bills you for a methodology you already own.

Why More Audit Committees Are Asking This in 2026

Two things happened in the same year.

The first is budget. The Internal Audit Foundation’s 2026 North America Pulse of Internal Audit, published March 10, 2026 and drawn from 373 responses collected between October 23 and December 2, 2025, found the share of functions reporting budget cuts rose from 11% to 19% year over year while the share reporting increases fell from 34% to 23%. Staff cuts moved the same way, 11% to 18%. And 86% of CAEs now oversee at least one area outside internal audit, with cybersecurity and IT alone absorbing roughly 20% of audit effort across most sectors. Smaller team, wider mandate, more technical scope. That is the co-sourcing demand curve in one sentence.

The second is stranger, and it is still unresolved as I write this. On July 31, 2026 the NYSE filed SR-NYSE-2026-37, asking the SEC to extend the transition period for a newly listed company to stand up an internal audit function from one year to five. The Exchange’s stated reason is that building the function in year one competes with everything else a new public company is doing.

The Institute of Internal Auditors asked the Commission to disapprove it. Their September 8, 2026 comment letter is worth twenty minutes of any CAE’s time, and the sharpest paragraph in it is about evidence. The filing, the IIA writes, “contains no data of any kind: it identifies no population of affected issuers, quantifies no burden associated with the current one-year period, offers no analysis of the investor-protection consequences of a five-year assurance gap.” The letter also points out that IPO proceeds tripled year over year to a record $178 billion in the first half of 2026, under the current one-year rule, which is an awkward fact for an argument about burden.

The SEC pushed its own deadline to November 16, 2026.

Here is why a sourcing article cares. If the extension is approved, a newly public company gets five years of discretion about when to build. Discretion is not absence. The audit committee still wants coverage, the pre-IPO risk assessment still exists, and the practical answer in year two is almost never a fully staffed department. It is two or three people and purchased hours.

Chief audit executive in an orange blouse marking up a tabbed printed annual internal audit plan at her desk

Four Ways a Co-Source Engagement Gets Structured

These are not philosophies. They are contract shapes, and the one you pick determines what you can and cannot do in month seven.

StructureHow it billsUse it whenWhere it breaks
Hours bankPre-purchased block drawn down as usedScope is real but timing is not yet knownUnused hours expire, or grades get substituted
Named contract auditorHourly, one person, your directionYou need capacity for a quarter or longerYou now manage a person, which is a real job
Fixed fee per auditOne price for one defined reviewA discrete, well-scoped audit such as SOC 2 readinessScope creep becomes a change order, every time
SME on callRetainer or small hour block for review onlyYour team executes but needs technical reviewUnder-used, then quietly dropped at renewal

Most functions end up running two of these at once. An hours bank for the unpredictable work, a named auditor for the predictable work, and nobody plans it that way on day one. It just happens by the third quarter.

Pricing: Start With What an Internal Hour Actually Costs You

Everyone compares a contractor’s hourly rate to an employee’s hourly wage. The wage math says about $40 an hour. The real number is closer to $64, and the difference is where most build-versus-buy decisions go wrong.

The Bureau of Labor Statistics puts the median annual wage for accountants and auditors at $83,680 as of May 2025, with employment projected to grow 5 percent from 2025 to 2035 and about 115,300 openings a year on average. One caveat before anyone builds a budget on that figure. BLS reports accountants and auditors as a single occupational group, so an experienced IT auditor or a SOX senior sits well above the median, and in the markets where we place most often the real number for a competent internal audit senior runs materially higher than $83,680. Use the median as a floor, not a forecast.

Then load it.

InputFigureNote
Base salary$83,680BLS median, accountants and auditors, May 2025
Benefits, payroll tax, insuranceadd 25% to 35%Varies most with health plan design
Fully loaded costroughly $105,000 to $113,000Before software, training or CPE
Productive hours per yearabout 1,7002,080 less PTO, holidays, CPE, admin
Effective internal cost per audit hourabout $62 to $66This is your real comparison number

Now compare. A contract internal auditor billed hourly will land above $62, obviously, and the gap narrows the moment you account for the three things an employee costs you that a 600-hour engagement does not: the recruiting cycle, the ramp, and the risk that the work ends and the person does not.

I am going to be careful here, because precision I do not have would be worse than none. There is no credible public benchmark survey of co-source billing rates. The numbers that circulate get quoted from vendor marketing pages and from each other, and the spread between a Big Four blended rate and a regional specialist for the same scope is wide enough that a single published range would mislead you more than it helped. What I can tell you is the structure of the quote you should insist on, and that is a more useful thing to own anyway.

Ask for three rates, not one. Partner or director review, manager, and staff or senior. Then ask what percentage of the engagement’s hours sits at each grade, in writing. A blended rate without a grade mix is a number you cannot audit, which is a funny thing to accept from an auditor.

Finance manager using a calculator beside a laptop spreadsheet to work out the fully loaded cost of an internal audit hour

Hours Banks Fail on Five Clauses

Hours banks are the most common co-source structure and the easiest to get wrong. The failures are boring, repetitive, and all in the paperwork.

  1. Expiry. Unused hours that vanish at the twelve-month mark convert your flexible purchase into a use-it-or-lose-it retainer. Negotiate a rollover window. Six months is normal and almost nobody asks.
  2. Grade substitution. You priced 70% of hours at senior grade. Month five arrives and a first-year is doing the walkthroughs at the senior rate. Require named resources, or at minimum a grade mix with a true-up at the end.
  3. Who owns the workpapers. This one gets skipped, and it is the whole point of co-sourcing. The deliverable should be workpapers in your system, in your template, that survive the relationship. If the provider’s answer involves their platform and an export on request, you are buying outsourcing with extra steps.
  4. Minimum draw. Some agreements bill a floor per month regardless of use. Fine if your plan is steady. Expensive if your plan is seasonal, and internal audit plans are seasonal.
  5. The external quality assessment. Under the IIA’s Global Internal Audit Standards, which took effect January 9, 2025, your function needs an external assessment at least every five years by a qualified, independent assessor. A firm that performed a meaningful share of your audit work is not that assessor. Keep the two purchases separate, and keep them separate in the contract, not just in your head.

Independence Survives Co-Sourcing. Objectivity Needs Help.

The structural answer is clean. Your CAE remains accountable for the opinions the function issues, including conclusions supported by work an external provider performed. The IIA’s standards are explicit that relying on a service provider does not transfer that accountability, and the audit committee should be told, in the charter or the engagement letter, exactly which parts of the plan are co-sourced.

The practical answer takes more care.

Self-review is the threat that actually shows up. A contract auditor who spent nine months last year helping remediate a segregation-of-duties problem in Workday should not be the person testing that control this year. We have had to say no to a client who asked for exactly that, because the person was excellent and available and it would have been easy. It was still the wrong assignment. Rotate the scope or rotate the person.

Two smaller things, stated once and then I will move on. Contract auditors need to sign your independence and conflicts attestation, not only their employer’s. And if a co-sourced specialist is the only person in the room who understands the technology being audited, your CAE cannot meaningfully challenge the conclusion, which is a competence gap dressed as a staffing solution.

Where We Fit

We have been at this since 2005, in eight verticals, and internal audit sits inside our accounting and finance desk next to SOX and technical accounting. Twelve months after a placement starts, 92 percent of ours are still in the seat. More than thirty U.S. metros. The recruiters on this desk have been doing it fifteen years or longer, which matters less than you would think for most roles and a great deal for this one.

For a co-source bench, the people we are usually asked for are IT general controls and application auditors, SOX 404 seniors for the testing crunch, and data analytics capability for continuous monitoring work. That is auditor staffing rather than managed internal audit, and the distinction matters. We do not bring a methodology, a report template, or an opinion. You already have those. We bring the hours and the specific skill, usually on a contract staffing basis, and when a role turns out to be permanent we convert it instead of pretending it was temporary.

Adjacent work we do that often gets confused with this: CPA staffing for technical accounting, and the year-end capacity problem covered in our guide to bringing in contract accountants for year-end close. If your question is really about buying a capability rather than a function, the general version of this argument is in staff augmentation versus outsourcing.

What CAEs Ask Us Before They Sign

Can our external audit firm just do this for us?

No, not if you are an SEC registrant and the work touches internal accounting controls, financial systems or the financial statements. 17 CFR 210.2-01(c)(4)(v) treats that as an independence violation. The narrow exception requires a reasonable conclusion that the results will not be subject to audit procedures, and most firms decline rather than defend it.

We have two auditors and a 40-audit plan. Co-source or outsource?

Co-source, and then cut the plan. Forty audits across two people is not a sourcing problem, it is a risk-assessment problem, and buying hours to execute a plan nobody could have executed just makes the overrun more expensive. Right-size the plan first. Then buy the gap.

Is an hours bank actually cheaper than hiring?

Sometimes, and the honest answer depends on utilization. Our arithmetic above puts an internal audit hour at roughly $62 to $66 fully loaded for a mid-level employee. If you can keep that person busy all year on work you need, hiring usually wins on cost. If you need 600 hours of Entra ID and Oracle EBS expertise once, a bank wins on everything.

What happens to the knowledge when the engagement ends?

In a properly structured co-source, it stays, because the workpapers were always in your system and your template. That is the clause people skip. In full outsourcing the knowledge leaves with the provider, and you find out how much of it mattered during the first audit after the transition.

Do we have to tell the audit committee which audits are co-sourced?

Yes, and in writing. The committee is approving coverage and relying on conclusions, so it needs to know which conclusions rest on purchased work and whether any provider is close enough to a prior remediation to raise a self-review question. Put it in the plan document, not in the verbal update.

Our IPO is next year and the NYSE rule might change. Should we wait?

Plan for one year, not five. The SEC has until November 16, 2026 to approve, disapprove, or institute proceedings on SR-NYSE-2026-37, and the IIA has formally urged disapproval. Building a small function with purchased hours works under either outcome. Betting on the extension does not.

How fast can you put a contract internal auditor in seat?

Two to four weeks is typical for IT audit and SOX seniors, faster if you have a written methodology for them to work inside. Our average time-to-hire across IT roles is 17 days. Internal audit searches with a niche platform requirement, Guidewire or a specific ERP module, run longer than that and I would rather say so now than in week six.

If you are weighing the two models against a plan you have already committed to, talk to a recruiter on our accounting and finance desk. Bring the plan and the gap. We will tell you if the honest answer is that you should hire instead.