Historical Context & Motivation
The modern audit engagement is far too complex for a single generalist to handle alone. Financial statements routinely contain assertions about fair values of derivatives, actuarial liabilities, environmental remediation costs, and information-technology controls—areas where the external auditor's own expertise may be insufficient. Recognizing this reality, the auditing profession has long permitted, and in many cases encouraged, auditors to draw upon the work of auditor's specialists, management's specialists, and the entity's own internal audit function. The challenge lies not in whether to use such work, but in how to evaluate it, maintain professional skepticism, and preserve the external auditor's ultimate responsibility for the audit opinion.
The central question these standards address is straightforward yet nuanced: How does the external auditor use and evaluate the work of others without improperly delegating professional responsibility? The answer requires a disciplined framework of competence assessment, objectivity evaluation, testing of underlying data, and careful consideration of scope—topics we will explore throughout this lesson.
Core Principles & Definitions
Before examining the detailed procedures, it is essential to establish the foundational definitions and principles that govern how the external auditor interacts with specialists and internal audit. The standards draw sharp distinctions between parties based on who engaged them and what role they play relative to the financial statements and the audit.
Auditor's Specialist
Management's Specialist
Internal Audit Function
Sole Responsibility Principle
Competence & Objectivity Evaluation
Visual Framework — The Auditor's Decision Tree
The following diagram illustrates the external auditor's decision process when determining whether and how to use the work of others. The flowchart highlights the key evaluation gates—competence, objectivity, adequacy of work, and the nature of the area being audited—that the auditor must pass through before placing reliance on another party's work.
As depicted in the diagram, the auditor's first decision is whether the area of expertise calls for a specialist (such as a valuation expert or actuary) or whether internal audit has already performed relevant work. For specialists, the auditor must further distinguish between one engaged by the auditor (governed by AU-C 620) and one engaged by management (evaluated under AU-C 500). For internal audit, the critical consideration is whether the area involves significant judgments—if it does, the external auditor must re-perform the work rather than simply rely on internal audit's conclusions.
Detailed Evaluation Mechanisms
Evaluating an Auditor's Specialist (AU-C 620 / AS 1210)
When an external auditor engages a specialist—for example, a valuation analyst to appraise a portfolio of complex financial instruments—the auditor must perform a structured evaluation before placing any reliance on the specialist's findings. The evaluation proceeds along three dimensions: competence, objectivity, and adequacy of work performed. Competence is assessed through credentials (e.g., ASA designation for appraisers, FSA for actuaries), relevant experience, professional reputation, and standing in peer organizations. Objectivity analysis examines whether the specialist has financial interests in the client, family or business relationships with client management, or other conflicts that might bias their conclusions. Even if the specialist is engaged by the audit firm itself, objectivity threats can arise if the specialist simultaneously provides advisory services to the audit client.
The auditor must reach an understanding with the specialist regarding the nature, scope, and objectives of the work; the respective roles and responsibilities; the methods and assumptions to be used; and the form of the specialist's report. This understanding is typically documented in an engagement letter or memorandum. The auditor then evaluates the specialist's findings by assessing the relevance and reasonableness of the assumptions, the completeness of the source data, and the internal consistency of the specialist's report. Importantly, the auditor need not possess the same technical expertise as the specialist, but must have sufficient understanding to evaluate whether the work provides appropriate audit evidence.
Evaluating Management's Specialist (AU-C 500)
When management uses a specialist to prepare financial statement amounts—consider a pension actuary computing the projected benefit obligation—the auditor treats the specialist's output as part of management's assertions. The evaluation framework under AU-C 500 mirrors the specialist evaluation above but adds an important layer: the auditor must test the underlying data that management provided to the specialist and evaluate the reasonableness of significant assumptions. For instance, if the actuary used employee census data, the auditor should vouch a sample of that data back to HR records. If the actuary assumed a 7% discount rate, the auditor should evaluate whether that rate is consistent with current market conditions and industry norms.
Evaluating the Internal Audit Function (AU-C 610 / AS 2605)
The external auditor may use the internal audit function in two distinct ways: (1) using internal audit's work as audit evidence and (2) using internal auditors to provide direct assistance under the external auditor's supervision. In either case, the external auditor must evaluate the internal audit function's organizational status (reporting line to the audit committee rather than to operating management), competence (professional certifications such as CIA, adequate staffing, continuing education), and whether their work is performed with due professional care (adequate planning, supervision, documentation, and review). A critical constraint is that the external auditor cannot use internal audit work—or direct assistance—in areas requiring significant auditor judgment, such as assessing accounting estimates or evaluating the adequacy of disclosures. For PCAOB engagements (issuers), the standard is even more restrictive: internal auditors cannot serve as direct assistants.
Classification of Work-of-Others Relationships
Understanding the distinctions among the various parties whose work the external auditor may consider is critical for exam success. The following table provides a side-by-side classification, and the diagram below maps these relationships visually to show how information flows between the parties and the external auditor.
| Attribute | Auditor's Specialist | Management's Specialist | Internal Audit |
|---|---|---|---|
| Engaged by | The external auditor | Management / TCWG | The entity (employee or outsourced) |
| Governing Standard (Nonissuers) | AU-C 620 | AU-C 500 | AU-C 610 |
| Governing Standard (Issuers) | AS 1210 | AS 1210 (as evidence) | AS 2605 / AS 2201 |
| Examples | IT security tester, forensic accountant | Actuary, appraiser, environmental engineer | Internal audit staff testing controls, reviewing compliance |
| Auditor's Key Evaluation Focus | Competence, objectivity, agreement on scope | Competence, objectivity, data accuracy, assumption reasonableness | Organizational status, competence, due care, scope of work |
| Reference in Audit Report? | No (unmodified); may reference in modified opinion | No | No |
| Direct Assistance Permitted? | N/A (not applicable) | N/A | Yes for nonissuers (AU-C 610); No for issuers (PCAOB) |
Worked Example — Evaluating Use of a Specialist and Internal Audit
Consider the following scenario: you are the senior auditor on the engagement for Apex Manufacturing, Inc. Apex has a defined-benefit pension plan. Management engaged an actuary (Smith & Associates) to compute the projected benefit obligation (PBO). Additionally, Apex's internal audit department performed testing of the payroll controls that feed employee census data to the actuary. You need to determine how to evaluate and use both sources of work.
Strengths, Limitations, and Common Pitfalls
Using the work of others provides significant benefits in terms of audit efficiency and evidence quality, but also introduces risks that the external auditor must manage carefully. The following table summarizes the key strengths and limitations, followed by common exam pitfalls that CPA candidates should be aware of.
| Strengths | Limitations |
|---|---|
| Access to specialized expertise that the auditor does not possess (actuarial science, IT security, environmental engineering, gemology) | The auditor may lack sufficient understanding of the specialist's field to fully evaluate assumptions and methods |
| Increased audit efficiency by leveraging internal audit's existing controls testing rather than duplicating it entirely | Internal audit may lack objectivity if they report to operating management rather than the audit committee |
| Improved evidence quality when specialists bring deeper domain knowledge to complex valuations or technical assessments | Management's specialist may have objectivity threats due to economic dependence on the client or contingent fee arrangements |
| Can reduce overall engagement cost and time while maintaining audit quality | Over-reliance on others without adequate re-performance or testing may constitute a deficiency in the audit |
| Internal audit's entity-specific knowledge can help the external auditor understand risks more quickly | The external auditor cannot delegate significant judgments to internal audit; areas such as revenue recognition estimates remain the external auditor's direct responsibility |
Connection to Advanced Audit Topics
The principles governing the use of specialists and internal audit connect directly to broader audit theory and advanced engagement scenarios. Understanding these connections is important both for the CPA exam and for practice. The evaluation of specialists plays a critical role in auditing accounting estimates (AU-C 540), which are among the most judgment-intensive areas of any audit. When fair value measurements involve Level 3 inputs under ASC 820, the auditor almost invariably needs specialist assistance to evaluate management's models and assumptions.
| Core Concept (This Lesson) | Advanced Application |
|---|---|
| Evaluating management's specialist under AU-C 500 | Auditing complex fair value estimates (AU-C 540 / AS 2501) where Level 3 inputs require valuation expertise—the auditor may engage their own specialist to develop an independent estimate or challenge management's model |
| Evaluating internal audit under AU-C 610 | Integrated audits of internal control over financial reporting (AS 2201) where internal audit's controls testing feeds directly into the external auditor's ICFR evaluation and affects the nature, timing, and extent of substantive procedures |
| Sole responsibility principle | Group audits (AU-C 600) where the group engagement partner must evaluate component auditors—similar evaluation of competence and objectivity, but with distinct reporting requirements and possible reference in the report |
| Competence and objectivity evaluation | Service organization reports (SOC 1 / AU-C 402) where the auditor evaluates the service auditor's competence and independence when relying on a Type 2 report for controls at a service organization |
As you advance through the AUD section, you will encounter these concepts repeatedly. The ability to recognize when a scenario involves a specialist versus internal audit, to recall the correct governing standard, and to apply the appropriate evaluation framework will be tested in both multiple-choice and task-based simulation formats. Pay particular attention to the interplay between specialist reliance and the audit risk model—using a well-qualified specialist effectively reduces detection risk for the assertions the specialist's work addresses, whereas an inadequate evaluation of a specialist may increase audit risk by introducing unreliable evidence into the auditor's conclusion.
Practice Problems
Lesson Summary
External auditors frequently need to leverage the expertise and work of others to gather sufficient appropriate audit evidence. Three categories of parties are relevant: the auditor's specialist (engaged by the auditor, governed by AU-C 620), the management's specialist (engaged by the client, evaluated under AU-C 500), and the internal audit function (addressed in AU-C 610 for nonissuers and AS 2605/AS 2201 for issuers). For every category, the auditor must evaluate competence and objectivity, assess the adequacy of work performed, and test underlying data and assumptions where applicable.
The overarching principle is that the external auditor retains sole responsibility for the audit opinion and must not reference specialists or internal audit in an unmodified opinion. For internal audit, the external auditor cannot delegate areas involving significant auditor judgment, and under PCAOB standards, internal auditors may not provide direct assistance on issuer engagements. Mastering these distinctions is essential for success on the AUD section of the CPA exam and for effective audit practice.