Comptables et conseillers intégrés à l'IA, à l'ESG et reliés au monde entier. Vérification, fiscalité, consultation, financement des entreprises et 16 piliers de services spécialisés.Comptables et conseillers intégrés à l'IA, à l'ESG et reliés au monde entier. Vérification, fiscalité, consultation, financement des entreprises et 16 piliers de services spécialisés.Comptables et conseillers intégrés à l'IA, à l'ESG et reliés au monde entier. Vérification, fiscalité, consultation, financement des entreprises et 16 piliers de services spécialisés.Comptables et conseillers intégrés à l'IA, à l'ESG et reliés au monde entier. Vérification, fiscalité, consultation, financement des entreprises et 16 piliers de services spécialisés.
All insights

Internal Audit vs External Audit: Key Differences

Understand internal audit vs external audit, UK statutory audit duties, differences in scope and independence, and when CFOs benefit from both.

23 September 2026

Internal Audit vs External Audit: Key Differences

For a CFO, the word audit can describe two different questions: are the financial statements fairly presented, and are the organisation's risks and controls being managed effectively? The answer helps direct assurance to decisions, accountability and oversight. This is particularly relevant in UK financial services regulatory compliance.

Internal audit vs external audit is a distinction in purpose and audience: internal audit provides objective assurance and advice on governance. Risk management and controls, while an external statutory auditor independently examines financial statements and reports an opinion for shareholders. The two can complement one another, but one does not replace the other.

Contact Aureliant Global

The practical starting point is to understand what internal audit examines, how its remit is set, and how its findings help the board and management act on risk.

What Is Internal Audit and What Does It Do?

Internal audit is an objective assurance and advisory function that helps an organisation assess and improve its governance, risk management, controls and operations. The Institute of Internal Auditors defines internal audit as an independent, objective activity designed to add value and improve operations by evaluating and improving how the organisation manages risk, controls and governance. Its work can therefore extend beyond checking financial processes.

In practice, internal auditors examine whether important risks are identified and managed. Whether controls are designed and working as intended, and whether processes support reliable information, sound decisions and organisational objectives. They may recommend improvements when testing identifies a control gap or an inefficient process. Management remains responsible for running the business and implementing decisions; internal audit provides a structured challenge and evidence-based view, rather than taking over those responsibilities. The board and senior management use its findings to understand where assurance is strong and where further action may be needed.

Objectivity depends on how the function is positioned. Internal audit may be delivered by employees, co-sourced specialists or an external provider. But the people conducting an engagement should be able to assess the area without undue influence from those responsible for it. Clear access to senior leadership and appropriate board or audit committee oversight can help protect that objectivity. This is a governance safeguard, not the same as the statutory independence required of an external auditor expressing an opinion on financial statements.

The scope and timing of internal audit work should reflect the organisation's risks and priorities, rather than being limited to a single annual review of accounts. Findings can inform practical remediation, risk ownership and oversight. A tailored internal audit checklist can help structure that work, while the audit plan should determine which areas merit attention and why.

What Is External Audit and Who Requires It?

An external statutory audit is an independent examination of a company's financial statements, performed under applicable auditing standards and legal requirements. The auditor gathers evidence and expresses an opinion on whether the statements give a true and fair view. Rather than assessing every business decision or control across the organisation. The FRC's ISA (UK) 200 sets out the independent auditor's overall objectives and responsibilities.

In the UK, whether a company needs a statutory audit depends on its legal form, size, activities and circumstances. A private limited company may qualify for the small-company audit exemption if it meets at least two of three size tests for the relevant financial year. For financial years beginning on or after 6 April 2025, those tests are annual turnover of no more than GBP 15 million. Assets of no more than GBP 7.5 million, and an average of no more than 50 employees. Meeting the size tests alone does not settle eligibility: the rules include additional conditions.

There are important exceptions and qualifications. Some entities, including public companies and certain businesses in regulated financial sectors, may be required to have an audit. Some subsidiaries may qualify for an exemption, but group status can affect the analysis. Members may also require an audit: GOV.UK says shareholders holding at least 10% of shares by number or value can request one. Subject to the stated process and timing. Directors remain responsible for preparing accounts and maintaining accounting records whether or not an audit is required. Check the current GOV.UK audit exemption guidance against the company's exact facts, and obtain professional advice where needed; this overview is not legal advice.

An audit opinion relates to the financial statements within the audit's scope. It is not a guarantee that the auditor will uncover every instance of fraud, error or control weakness, nor a substitute for ongoing management oversight. Organisations seeking clarity on their statutory obligations and assurance needs can explore Aureliant's statutory and internal audit support.

Why the Internal Audit vs External Audit Distinction Matters to CFOs

For a CFO, the distinction is practical: internal audit helps the organisation understand and improve risk management. Governance and controls, while external audit provides an independent view of the financial statements. They answer different questions, so planning, resourcing and reporting should reflect their separate purposes.

How internal and external audit differ

Dimension

Internal audit

External audit

Primary objective

Provide objective assurance on risk management, governance and internal control, and identify areas for improvement.

Report whether the financial statements provide a true and fair view.

Scope

Can examine organisational risks and controls beyond financial reporting, with focus shaped by the organisation's needs.

Centres on the financial statements and the audit requirements that apply to the entity.

Commissioning and independence

Commissioned as an organisational function. It needs objectivity and appropriate governance safeguards, including independence from the activity under review.

Undertaken by an external auditor who must maintain independence from the audited organisation.

Audience and reporting

Findings inform senior management and the board or audit committee, supporting oversight and action.

The auditor's report serves shareholders and other users of the financial statements.

Timing and output

Work is planned around risk priorities and changes in the organisation; output typically includes findings and recommendations for management or governance follow-up.

Work is linked to the financial reporting period and culminates in an opinion on the financial statements.

These differences affect the CFO's operating calendar. Internal audit can focus attention on a changing risk area, test whether controls work in practice and give management time to address weaknesses. External audit has a defined financial-statement purpose; its opinion is not a review of every operational risk or a substitute for ongoing control oversight. The ICAEW comparison of audit roles describes the respective internal assurance and external reporting responsibilities.

Good coordination can reduce avoidable duplication: share relevant risk information and align schedules where appropriate, while preserving each function's distinct remit and the external auditor's independence. For organisations in regulated sectors, the distinction also helps clarify which assurance addresses financial reporting and which examines broader governance and controls. See Aureliant's UK financial services regulatory compliance advisory for related considerations.

What is the key difference between internal audit and external audit? Internal audit gives the organisation objective assurance on risk, governance and controls; external audit independently reports on the financial statements. Neither is inherently better, because each serves a different purpose.

Can One Firm Provide Both Internal and External Audit?

Internal audit does not have to be delivered by a permanent in-house department. An organisation may resource it internally, co-source selected expertise, or outsource the function. The appropriate model depends on its scale, risk profile, skills and governance arrangements. Whatever the model, internal audit needs sufficient objectivity and access to the board or audit committee to report findings credibly.

Using one firm for internal audit and statutory external audit is a different question. It cannot be answered with a blanket yes or no: the firm must assess the specific engagements against applicable law, professional ethical requirements and independence rules. The assessment should identify threats, including whether work performed in one role could affect judgements in the other. And determine whether safeguards can reduce those threats to an acceptable level. If they cannot, the arrangements may need to change, or the firm may have to decline or cease an engagement.

This analysis is specific to the entity and the work involved. Relevant considerations can include the nature and significance of the internal audit services, who makes management decisions. How the work is overseen, and whether the statutory auditor would be evaluating its own work. Governance controls and clear role boundaries matter, but their presence does not automatically make a combination permissible. The conclusion must follow the rules that apply to the engagement, not a general claim that separation within a firm is always sufficient.

Where the firm is appointed as statutory external auditor, it remains responsible for forming and expressing its own opinion on the financial statements. Internal audit work does not transfer that responsibility or turn the external audit opinion into management's assurance over every operational risk. Any reliance on internal audit work is a matter for the external auditor's assessment and does not remove its accountability.

Aureliant's audit and assurance service page describes its internal and statutory audit offerings. It should not be read as a general assurance that the firm can undertake both roles for every organisation. A prospective engagement requires an independence and ethics assessment based on its facts and applicable requirements.

How Risk-Based Internal Audit Adds Value Beyond Compliance

A risk-based internal audit plan directs attention to the areas most likely to affect the organisation's objectives, rather than treating every process as equally significant. The board or audit committee can use this plan to focus assurance on material changes, complex controls, emerging threats and areas where previous weaknesses remain unresolved.

The work can assess whether governance arrangements, risk management and controls are designed appropriately and operating effectively. That review may extend beyond financial reporting to operational performance, regulatory and policy compliance, technology, and the reliability of management information. Its breadth helps leaders understand not only whether a control exists, but whether it addresses the risk it was intended to manage. For a practical starting point, see this internal audit checklist guide.

Findings create value when they lead to clear decisions and accountable action. A useful report explains the risk, the evidence behind the observation, and the practical implications, then identifies an agreed owner and response date. Management remains responsible for operating controls and delivering improvements; internal audit provides objective assurance and advice, not management's substitute. Board or audit committee oversight of the plan, reporting and follow-up supports that distinction.

Follow-through should test whether agreed actions address the underlying cause, not merely whether a recommendation has been marked complete. Where a control gap reflects unclear ownership, poor process design or insufficient monitoring, the response should resolve that weakness and establish how it will be checked. Repeated or overdue findings can then inform the next risk assessment and audit plan.

This work complements, but does not replace, a statutory external audit opinion on financial statements. Nor can an internal audit plan guarantee that every instance of fraud or control failure will be detected. Its contribution is a more structured view of priority risks, control performance and the actions needed to strengthen oversight and operations.

When Should a Company Invest in Both?

Using internal and external audit together is most valuable when the organisation needs both independent financial statement assurance and ongoing insight into wider risks, governance and controls. For a CFO, the decision should reflect the company's risk profile and assurance needs, not a general preference for more audit activity.

Practical decision checklist, not a legal test:

  • Complexity is increasing. Multiple entities, systems, locations or business models can make it harder to maintain consistent controls and understand risk across the organisation.
  • Significant change is under way. An acquisition, rapid expansion, major systems implementation or restructuring may create control risks that warrant focused internal review alongside the external audit of financial statements.
  • Operations are regulated or stakeholder-sensitive. Where regulation, investor expectations or contractual commitments create heightened assurance needs, consider whether internal audit can test relevant processes between external audit cycles. For UK financial services context, see our UK financial services compliance advisory.
  • Control gaps need follow-through. If prior findings, incidents or management concerns point to weaknesses, internal audit can assess root causes and track remediation. The external auditor's separate financial-statement work does not replace that broader review.
  • The board needs a clearer view of risk. An audit committee may benefit from objective reporting on whether governance, risk management and internal controls are working as intended. ICAEW describes this as a core assurance role of internal audit.

Where both functions operate, agree an annual audit calendar, clarify scope and coordinate evidence requests. This can help limit duplicated requests to finance and operational teams. Coordination does not transfer responsibility: the external auditor remains responsible for its own audit and opinion. Any consideration of internal audit work by the external auditor depends on assessing the function's objectivity and the quality of the work. It should never be assumed in advance.

The right model depends on the assurance gap. Internal audit may be built in-house, co-sourced or outsourced, while the external audit remains a distinct engagement. The objective is complementary coverage, not two teams repeating the same tests.

Frequently Asked Questions

What is the main difference between internal and external audit?

Internal audit gives the board and management objective insight into governance, risk management and controls, and can review operational areas beyond financial reporting. External statutory audit is a separate engagement that examines the financial statements and reports an opinion for shareholders. The two functions therefore answer different questions and serve different audiences.

Which UK companies must have a statutory audit?

The answer depends on the company's legal status, size, group position and other circumstances. A private company may qualify for exemption if it meets at least two relevant size tests, but exceptions apply, and members can require an audit. For financial years starting on or after 6 April 2025, the small-company tests include turnover of no more than GBP 15 million. Assets of no more than GBP 7.5 million and an average of 50 or fewer employees. Check the current GOV.UK audit exemption guidance against the company's circumstances.

Does internal audit replace a statutory external audit?

No. Internal audit can assess risks and controls and recommend improvements, but it does not provide the statutory opinion on financial statements. If a company is required to have an external audit, an internal audit programme does not remove that requirement.

Can one firm perform both internal and external audit?

It depends on the engagement, applicable legal and ethical requirements, and whether independence threats can be addressed. The roles must remain distinct, and an external auditor remains responsible for its own opinion. Do not assume that one firm can undertake both roles for every organisation; assess the specific circumstances before appointment.

Does an external audit identify every fraud or control weakness?

No. A statutory financial statement audit is not a review of every transaction, process or control. And its opinion is not a guarantee that all fraud or weaknesses will be detected. Internal audit can examine broader risk areas, but neither function should be presented as guaranteeing detection.

Book a Consultation About Your Audit Approach

Clear decisions on audit scope, independence and assurance can help your organisation focus effort where it is most useful. Aureliant's partner-led team can discuss your context and the considerations that may shape a proportionate approach. A focused conversation may also help you frame questions for your board or audit committee while keeping internal and external audit responsibilities distinct.

Request a consultation

You can also call +44 20 7967 1177 to speak with the team.