Skip to main content
Promotional banner for the pentest readiness checklist
Auditor Ethics and External Consultants: What the FRC Changes MeanRegulatory Obligations Management
5 min readFor Internal Auditors

Auditor Ethics and External Consultants: What the FRC Changes Mean

When the Financial Reporting Council revised two standards in late 2024, many audit teams overlooked the changes. However, if your team works with external consultants on audits or coordinates with external auditors, these updates impact how you document independence and manage third-party relationships.

What Changed in the FRC Standards?

The FRC revised two standards to align with the International Ethics Standards Board for Accountants' Code. The key change is the introduction of explicit ethical requirements for how auditors use external consultants in audit, assurance, and non-assurance engagements.

Previously, the ethical framework assumed consultants were covered under general independence rules. Now, there's specific language requiring auditors to evaluate and document the consultant relationship, the nature of work performed, and how that work integrates into the audit opinion.

This means your external auditors can't simply bring in a specialist without documenting the ethical considerations. If they're using a cybersecurity consultant to evaluate IT general controls or a valuation expert for goodwill impairment testing, they must now explicitly document how they maintained independence and objectivity.

Does This Affect Internal Audit’s Use of Consultants?

While these FRC standards don't directly impact internal audit, they create a parallel expectation you should adopt.

If external auditors must document consultant independence and evaluate potential conflicts, your internal audit function should apply similar rigor. When you bring in a third party to assess control design or test operating effectiveness, document:

  • The consultant's relationship to the organization (e.g., past implementation work or ongoing advisory relationships)
  • The scope of work and deliverables
  • How you'll validate their work product
  • Any limitations on their independence

The Institute of Internal Auditors' Standards already require maintaining objectivity, but these FRC changes highlight specific documentation practices external auditors will now follow. Adopting similar practices strengthens your position when audit committees or regulators review your work.

How to Identify Independence Issues in Consultant Relationships

Start with the self-review threat. If the consultant helped design or implement the controls you're auditing, that's a problem. If they provided training on the control framework but didn't design specific controls, that's usually acceptable.

Consider the advocacy threat. If the consultant has a financial interest in the outcome of your audit findings, that compromises independence. A consultant paid based on finding cost savings shouldn't also evaluate whether those savings calculations are accurate.

The IESBA Code uses a threats-and-safeguards approach. Identify the threat category (self-review, self-interest, advocacy, familiarity, intimidation), then determine if you can apply safeguards that reduce the threat to an acceptable level. Acceptable safeguards include having a separate team review the consultant's work, limiting the consultant's role to purely technical analysis without judgment, or imposing a cooling-off period between advisory work and audit work.

Document this analysis. Record the threats identified, safeguards applied, and who reviewed the independence determination.

Communicating Consultant Use to External Auditors

Be proactive. If you've used consultants in areas your external auditors will review, disclose that upfront during planning.

Provide specifics: who the consultant was, what work they performed, when they performed it, and what deliverables they produced. If the consultant helped implement a new revenue recognition process and your external auditors will test revenue controls, they need to know that before they start fieldwork.

Your external auditors will document their evaluation of whether your consultant use creates issues for their audit. If you've already documented your own independence analysis, share that. It demonstrates control maturity and speeds up their planning.

Applicability to All Types of Assurance Work

Yes, the FRC changes cover audit, assurance, and non-assurance engagements.

If your organization undergoes SOC 2 examinations, ISAE 3402 reports for service organizations, or agreed-upon procedures engagements, the practitioner performing that work must now apply these consultant ethics requirements. This is broader than many teams realize.

For internal audit, this means if you're coordinating multiple assurance providers (external auditors, SOC 2 examiners, ISO 27001 certification bodies), each may now ask similar questions about consultant use. Standardize your documentation so you're not recreating the analysis for each provider.

Alignment with Other Regulatory Expectations

These FRC changes reflect a broader regulatory trend: more scrutiny of third-party relationships in assurance and compliance functions.

The PCAOB has emphasized auditor responsibility for specialist work in AS 1210. The SEC has questioned audit firms about their use of third-party service providers in audit execution. DORA requires financial entities to manage ICT third-party risk, including service providers supporting compliance functions.

The common thread: you can't outsource accountability. Whether you're an auditor using a consultant or an internal audit function using a specialist, you remain responsible for the work product and must demonstrate you maintained appropriate oversight and independence.

Documenting Consultant Relationships

Create a consultant registry for your internal audit function. Track:

  • Consultant name and firm
  • Engagement dates
  • Scope of work
  • Areas or processes they touched
  • Independence analysis and safeguards applied
  • Review and approval of their work

Update this registry before each audit planning cycle and share relevant portions with your external auditors during planning. If you're using a GRC platform, build this into your audit management module so it's linked to specific audit engagements.

For external auditors, ask them how they're documenting consultant use under the revised standards. You want to understand their process so you can provide information in the format they need.

Next Steps

Review the IESBA Code's sections on using the work of experts and other practitioners. Even though it's written for external auditors, the principles apply to internal audit practice.

If you're coordinating with UK-based external auditors or your organization has UK operations, request a copy of their updated engagement letter language around consultant use. Understanding what they're committing to helps you align your own practices.

For internal audit teams, the IIA's Practice Guide on using external service providers remains the baseline. Layer these FRC expectations on top as an example of how regulators are tightening documentation requirements around third-party relationships in assurance work.

Application Security Isn’t Optional Anymore.

You Might Also Like