Instiq
Chapter 1 · Audit fundamentals & framework·v1.0.0·Updated 7/11/2026·~14 min

What's changed: Initial version

1.4Assurance-type and advisory-type audits

Key points

Covers the differences in objective, deliverable, and independence requirements between an assurance-type audit that expresses a degree of assurance, and an advisory-type (consulting) audit whose primary purpose is recommendations for improvement, and the skill of discerning "does the requester want assurance or advice" to judge the audit type and mode of engagement.

A systems audit is broadly divided into two types by its objective: an assurance-type audit (assurance engagement) in which the auditor expresses assurance (an opinion) that the audited target meets a certain standard, and an advisory-type audit (consulting engagement) in which problems are analyzed and improvements recommended to support the audited organization's improvement. This section develops not the rote memorization of both definitions, but the ability to discern whether the requester (management, etc.) truly wants "assurance that can be shown to a third party" or "practical advice for improvement," and to judge accordingly how to design the audit type, deliverable, and manner of maintaining independence.

1.4.1Assurance-type audit

  • An assurance-type audit is one in which the auditor, from an independent position, verifies and expresses "assurance" (an opinion) that the audited target (an information system, its management, internal control, etc.) meets certain standards or requirements. The deliverable is an audit report containing the auditor's opinion, whose value lies in being something a third party (management, shareholders, business partners, etc.) can rely on and use.
  • Because assurance is expressed, the auditor's independence and objectivity are required especially strictly. The opinion must be backed by sufficient and appropriate audit evidence, not the auditor's impression. A context that assures effectiveness to an external third party, as in a J-SOX internal-control audit, is a typical assurance type.

1.4.2Advisory-type (consulting) audit

  • An advisory-type audit primarily aims to support improvement of the audited organization's information systems and management, analyzing problems and giving concrete recommendations (advice) for improvement. The deliverable is recommendations and improvement plans that contribute to improvement; expressing "assurance that a standard is met" to a third party is not the primary aim.
  • Even in the advisory type, independence and objectivity are required, but there is a risk that if the auditor engages too deeply in improvement support, they later end up evaluating their own advice when auditing that improvement result in an assurance type, impairing independence. Thus one must clarify "is this advisory or assurance this time," and manage the impact on independence when the same person handles both in succession.
Exam point

Most-tested: an assurance type expresses a degree of assurance (an opinion) to a third party and demands especially strict independence; an advisory type primarily aims at recommendations, with deliverables of recommendations/improvement plans; and if the same person handles advisory then assurance in succession, they evaluate their own advice and risk impairing independence. Practice being able to work backward from the requester's objective (assurance or advice) to the audit type and mode of engagement.

Suppose you are a systems auditor, and management requests, "for the newly introduced cloud platform, so that we can confidently show business partners and the parent company, please confirm that security management is appropriately established and operating." What matters here is that the objective behind the request's wording is "assurance that can be shown to a third party." Since they want to demonstrate effectiveness to external third parties—business partners and the parent company—this is a situation to design as an assurance-type audit, not an advisory type whose primary aim is recommendations. In an assurance type, because the auditor's opinion is relied upon and used by a third party, you must maintain independence and objectivity especially strictly and back the opinion with sufficient and appropriate audit evidence. If you had been deeply involved as an advisor in the design of this cloud platform's introduction, standing now in a position to assure its effectiveness would mean evaluating your own advice and lacking independence, so you should reconsider the assignment. On the other hand, if the request were "identify where the weaknesses are in operating the cloud platform, and think through the direction of improvement together," that is support for internal improvement rather than assurance to a third party—an advisory-type audit—and the deliverable would be recommendations rather than an assurance opinion. "First discern whether the requester wants assurance or advice, and design the audit type, deliverable, and strictness of independence accordingly"—this judgment is the key to not mistaking the entrance to the audit.

CategoryPrimary objectiveDeliverableStrictness of independence
Assurance-typeExpressing a degree of assurance (opinion) to a third partyAn audit report containing the auditor's opinionEspecially strict (a third party relies on it)
Advisory-type (consulting)Supporting and recommending the audited organization's improvementRecommendations, improvement plansRequired, but manage independence impact from deeper engagement
Warning

Trap: "Assurance-type and advisory-type audits share the same objective, with no difference in deliverable or strictness of independence" is wrong—the assurance type demands especially strict independence and evidential backing to express assurance to a third party, with a deliverable of an opinion-bearing report, while the advisory type primarily aims at recommendations, with a deliverable of recommendations/improvement plans; the objective, deliverable, and independence requirements differ. Also wrong: "an auditor who was deeply involved in improvement in the advisory type has no independence problem later auditing that improvement result in an assurance type"—that would mean evaluating one's own advice and impairing independence, so separation of assignments or impact management is needed.

Contrast of two audit approaches.
Giving assurance and giving advice

1.4.3Section summary

  • An assurance-type audit expresses a degree of assurance (an opinion) to a third party, demanding especially strict independence and evidential backing
  • An advisory-type (consulting) audit primarily aims at supporting and recommending the audited organization's improvement, with deliverables of recommendations and improvement plans
  • First discern the requester's objective (assurance or advice) to judge the type, deliverable, and independence design, and when handling advisory then assurance in succession, manage the independence impact of evaluating one's own advice

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Management requests, "for the newly introduced cloud platform, so we can confidently show it to business partners and the parent company, please confirm that security management is appropriately established and operating." Which audit type should be designed for this request?

Q2. Which statement about the difference between an assurance-type (assurance) audit and an advisory-type (consulting) audit is most appropriate?

Q3. A systems auditor was deeply involved in designing internal-control improvements in an advisory-type audit for an audited organization. The next fiscal year, the same auditor is designated to evaluate the effectiveness of that internal control in an assurance-type audit. Which statement about this situation is most appropriate?

Check your understandingPractice questions for Chapter 1: Audit fundamentals & framework