Beyond the binary: structuring your internal audit function
Internal Audit, together with other assurance providers, forms the third line of defence and has, strategically, proved its value over and over again. The existence of the function, to assess the adequacy and effectiveness of internal controls whilst also reviewing performance against strategic objectives, assures the Board and those charged with governance that management is executing its mandate and protecting shareholder value.
The independence of the function is critical to ensure it is a trusted advisor to both management and the Board. That is why Boards are often confronted with what appears to be a binary decision: whether to in-source or to outsource the function.
In practice, however, this decision is rarely as clear cut.
We have previously published an article on the criteria that the Board and or the Audit and Risk Committee should consider when making this decision. In this article, we move beyond that framework to unpack the practical realities of each model and explore what tends to work best, depending on the size and complexity of the organisation.
The In-Sourced Model
Independence Concerns
The argument against in-sourcing internal audit is often based on the possible corrosion of its independence. This is because the function head often forms part of executive management and regularly engages with operational leaders whom they are expected to audit. Independence can be further blurred by the dual reporting lines, functionally to the Audit and Risk Committee or Board, but administratively to the Chief Executive Officer. This creates a dynamic where budgets approvals and resourcing decisions may sit with the very structures subject to audit.
The Strategic Value of In-Sourcing
Notwithstanding this, there are compelling reasons why internal audit remains well suited to being in-sourced.
With the adoption of the Global Internal Audit Standards, the role of Internal Audit continues to evolve into that of a strategic, value adding partner, moving away from the perception of being a purely “corporate policing function”. This requires a function that is deeply embedded in the organisation, one that understands its strategy, monitors shifts in its risk environment, and continuously assesses alignment to strategic objectives.
An in-sourced function is therefore often more responsive and proactive, with direct access to organisational data and an ability to monitor trends in real time. It is also better positioned to respond quickly to management and Board requests for advisory support, and to address fraud or misconduct concerns raised internally.
Cost and Familiarity Risks
However, the case against in-sourcing is not limited to independence concerns. Cost remains a significant consideration, particularly for organisations with layered compensation structures. Maintaining a fully resourced internal audit function requires investment in specialised skills, technology, and continuous upskilling to keep pace with evolving audit methodologies and technological advancements. There is also an inherent familiarity risk that may, over time, impact objectivity and the depth of challenge applied during reviews.
The Outsourced Model
On the other hand, fully outsourcing the function addresses some of these concerns, particularly around independence and access to specialised expertise. External providers bring diverse skillsets and are not embedded in the day-to-day operations of the organisation, which reduces familiarity threats and strengthens perceived objectivity.
However, this distance can come at a cost. Outsourced functions may lack the depth of organisational understanding required to provide timely, insight driven assurance, and responsiveness is often influenced by contractual arrangements and budget constraints.
The Hybrid Model
The most effective framework therefore often sits outside of this binary.
How It Works in Practice
In practice, what we have seen work exceptionally well is a hybrid model. In this approach, the organisation retains a small internal team, typically two or three individuals including the Chief Audit Executive, while execution is largely supported by outsourced professionals and specialists.
The internal team focuses on managing the audit plan, coordinating and scheduling audits, performing follow up reviews to ensure implementation of recommendations, and monitoring changes in the risk environment. They also remain accessible to management and staff, responding to consulting requests and fraud reports as they arise. The outsourced component then provides the depth of expertise and capacity required to execute audits effectively.
This model allows organisations to retain institutional knowledge and responsiveness, while still benefiting from independence, scalability, and specialised skills.
Choosing the Right Model for Your Organisation
Ultimately, the right approach will differ across organisations. Smaller entities, such as NPOs with predictable activities, may not require a permanent internal audit presence and can rely on periodic reviews and advisory services. Larger organisations, however, often require continuous engagement and view internal audit as a strategic investment rather than a support cost.
There is no one size fits all model. The most effective internal audit structures are those that recognise that the decision is not binary, but rather a balance. Organisations that find this balance, between independence and insight, cost and value, assurance and agility, are often those that position internal audit not just as a function, but as a meaningful contributor to governance and strategic execution.


