CIA-1 - Foundations of Internal Auditing - Section A.4

Interpret the differences between assurance services and advisory services, including limited versus reasonable assurance, and determine which type of service is appropriate in a given context.

Distinguish assurance services, where the auditor gives an independent assessment for the benefit of stakeholders, from advisory services, where the auditor provides advice at the request of the engagement client without assuming management responsibility. Differentiate limited assurance from reasonable assurance by the level of work performed and the confidence conveyed, and judge which service fits a given situation.

Assurance servicesAdvisory servicesReasonable assuranceLimited assurance

Practice question for this objective

Free sampleFoundations of Internal Auditingmedium

An internal audit function is explaining to a newly appointed audit committee member how assurance services differ from advisory services under the Global Internal Audit Standards. Which statement captures the essential difference between the two?

  • AAssurance services generate advice that the client is free to accept or reject, whereas advisory services deliver a formal conclusion that external stakeholders rely upon.
  • BAssurance services give an independent assessment of a subject for stakeholders, while advisory services provide advice at the client's request without the auditor assuming management responsibility. Correct
  • CBoth services produce an independent conclusion for stakeholders, differing only in whether the engagement was requested by management or placed in the audit plan.
  • DAssurance services may be performed only by external auditors, while advisory services are the sole preserve of the internal audit function inside the organisation.
Distinguish assurance as an independent stakeholder assessment from advisory as client-requested advice given without assuming management responsibility. Assurance and advisory differ in purpose and parties: assurance delivers an independent conclusion for stakeholders, while advisory delivers advice to the requesting client, and the auditor must never assume the management responsibility that would compromise objectivity.

Why A is wrong: This is tempting because it uses the right vocabulary, but it reverses the two services: advice the client may accept or reject describes advisory work, and a conclusion relied upon by stakeholders describes assurance.

Why B is correct: Correct: assurance is an independent assessment communicated to stakeholders, and advisory is client-requested advice in which the auditor supports but does not take over management's responsibilities.

Why C is wrong: The trigger for an engagement is a real distinction, but advisory work does not produce an independent conclusion for third-party stakeholders, so treating both as opinion-bearing is wrong.

Why D is wrong: This sounds orderly but is false: internal auditors routinely perform assurance engagements, and external parties can also provide advisory work, so provider identity is not the dividing line.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Foundations of Internal Auditing objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.