The case for integrated assurance is easy to agree with and hard to buy. The three perspectives on our landing page — the leadership team that owns the risk, the board and its Audit Committee that must rely on what is reported, and the external audit partner who depends on the quality of what sits underneath the opinion — all point to the same end state: one risk taxonomy, one assurance plan, one issue register, one report. The question that decides whether it happens is not "does this make sense?" It is "how would you actually deliver it, and what changes in my first ninety days?"
This blog post answers that. Section #1 sets out the five ways we engage, with the Synergy-IA Fractional Chief Audit Executive that anchors most engagements, interim coverage when a seat is suddenly empty, combined-assurance design and uplift for organizations that already have the pieces, targeted reviews for specific exposures, and external quality assessment for functions that have never been measured against the Global Internal Audit Standards. It also explains how we price: to the risk retained, not to hours, and, where the model is designed to reduce overtime, how the fee steps down on a trajectory agreed in writing at the outset.
Section #2 walks the first ninety days: what is diagnosed by day thirty, what is designed and approved by day sixty, and what is executed and evidenced by day ninety. Buyers deserve to know exactly what will be in the Audit Committee's hands at the end of onboarding, so we name the deliverables rather than describing activities.
Section #3 states the independence position plainly, because a single senior practitioner standing between management and the Audit Committee only works if the boundaries are explicit: what we will not own, how advisory work is separated and disclosed, why second-line scope is declined where it would impair third-line assurance, and how direct assistance to the external auditor, where contemplated at all, is delivered under the external auditor's direction and documented as such, subject to the rules that apply in your jurisdiction.
Read it from whichever seat is yours. This is the section you can hold us to.
|
Model |
What it is |
Best suited to |
|
Fractional CAE (flagship) |
A senior CAE accountable for the assurance model, reporting to the Audit Committee, on a retained monthly basis |
Organizations needing a CAE but not a full-time one; PE-backed businesses; smaller public companies |
|
Interim CAE |
Full-time-equivalent coverage during a vacancy, a remediation program, or an exit process |
Transitional periods with a hard deadline |
|
Combined-assurance design and uplift |
A defined engagement to design the shared taxonomy, the single assurance plan, the single issue register, and the consolidated reporting pack |
Organizations with multiple functions already in place that need them integrated |
|
Targeted assurance reviews |
Discrete independent reviews — AI governance, cyber resilience, ICFR sustainability, third-party risk |
Specific known exposures |
|
Quality assessment and function uplift |
External quality assessment and remediation of an internal audit function against the Global Internal Audit Standards |
Functions that have never been assessed |
Pricing for each model is scoped to the risk retained rather than to hours. Where the model is designed to reduce over time, most commonly the fractional CAE — the fee profile steps down as the function stabilizes, and that trajectory is agreed in writing at the outset.
|
Phase |
Focus |
Deliverables |
|
Days 1–30: Diagnose |
Independent baseline of the current assurance landscape; inventory of risks, controls, providers, and open issues |
Assurance landscape map; duplication and gap analysis; AI, cyber, and ICFR exposure summary; issue register consolidated with owners and dates |
|
Days 31–60: Design |
Agree the shared taxonomy, rating scale, and heat map; allocate coverage across providers; define consolidated reporting |
Charter; one risk taxonomy and rating scale; one assurance plan; one issue register; reporting template approved by the Audit Committee |
|
Days 61–90: Execute and evidence |
Begin fieldwork on the highest-priority exposures; stand up reporting; establish the QA program |
First consolidated assurance report; first risk-based audit plan per quarter; independence safeguards documented; performance metrics baseline |
By this point, the model should be legible: one taxonomy, one plan, one register, one report — delivered by a senior practitioner whose independence is engineered, not asserted. What separates a durable assurance capability from a well-formatted retainer is rarely the deck. It is the quality of the questions asked before the engagement letter is signed. Ask these three.
Ask the three questions. The answers, or the absence of them, will tell you more than any proposal. The full perspectives from all three seats are on the landing page.
To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com