A bank's internal audit function and the information security team both plan to assess the customer onboarding application during the same quarter. Internal audit will follow an IIA-aligned controls audit; security plans a red-team style penetration test. The CISO wants the two assessments to provide complementary assurance without compromising either. What is the BEST way to coordinate the two engagements?
- AHave internal audit observe the penetration test in real time so that the testers' actions can be evidenced in the audit working papers and double-counted as control testing.
- BDefer the penetration test until internal audit issues its report so that the testers can focus their efforts solely on the residual control weaknesses that internal audit identifies.
- CSequence the engagements with distinct objectives, agree non-overlapping scopes and rules of engagement, and have each team share results through a single risk owner who reconciles findings against the control framework. Correct
- DMerge the two engagements under the security team so that one combined report covers both control effectiveness and exploitability, and disband the separate audit workstream for this application.
Why A is wrong: Internal audit must preserve independence and cannot rely on offensive testers as its sole evidence source. Treating red-team activity as audit testing conflates assurance lines, undermines the auditor's ability to opine on control design, and risks regulators concluding that the third line outsourced its judgement to the second line.
Why B is wrong: Sequencing the penetration test purely off audit findings narrows the offensive scope to known weaknesses and removes the value of independent attacker perspective. It also delays remediation of exploitable issues that may not appear in a controls-based audit, such as chained logic flaws or business process abuse.
Why C is correct: Internal audit and offensive testing answer different questions: are the controls designed and operating as intended, and can a motivated attacker bypass them. Coordinating scope and timing, while keeping evidence streams separate, lets the risk owner triangulate design, operating effectiveness, and residual exploitability without compromising the independence of either function.
Why D is wrong: Folding internal audit work under the security team destroys the three lines model and removes the independent assurance the board relies on. Even if the technical findings overlap, audit must report through a separate chain to remain credible to the audit committee and external regulators.