CIA Part 2 Findings and Recommendations
A defensible audit finding compares an evidence-supported condition with applicable criteria, explains cause and risk when supported, and proposes a practical response without taking over management’s responsibility.
- Communicate significant issues accurately, validate facts, document disagreement, and escalate risk acceptance through the proper governance route.
On this page13 sections
- A finding begins with evidence and criteria
- Cause and effect require care
- From finding to recommendation
- Validate facts and handle disagreement
- Communication throughout the engagement
- Worked example: late access removal
- Risk acceptance and escalation
- Common reporting mistakes
- A concise finding structure
- Exam application checklist
- Finding severity and prioritization
- Follow-up and closure
- Management response that differs from audit
A finding begins with evidence and criteria
A finding describes a condition that differs from a relevant expected state. The condition is what the auditor observed; criteria explain what should occur. Criteria may come from law, regulation, contract, policy, approved procedure, control design, or a clear organizational objective. Both must apply to the process and period in scope.
Example: a policy requires independent approval before a supplier’s bank details change. The condition is that sampled updates lack evidence of timely independent approval. The auditor should verify whether evidence exists in another system and whether a documented exception applies before finalizing the finding.
A concern without applicable criteria may still reveal a risk, but the report should not label it noncompliance without a valid requirement. Clarify the benchmark or describe the condition and risk without overstating a breach.
Cause and effect require care
Cause explains why the condition occurred. Possible causes include unclear procedures, access conflicts, system design, staffing, training, oversight, or intentional circumvention. The cause should be supported by evidence. “Human error” or “lack of awareness” can be a guess unless the auditor investigates.
Effect describes actual or potential consequence. A control failure may increase risk of loss, error, regulatory breach, delay, or inaccurate reporting. Distinguish actual loss from exposure. If no loss was identified, do not claim that money was lost; explain the risk the weakness creates.
A useful finding is balanced. It recognizes existing controls and mitigating facts while explaining the remaining exposure. If a detective control caught an unauthorized change before payment, that matters to impact, but it does not make the preventive control operate as designed.
From finding to recommendation
A recommendation or agreed action should address the cause or reduce the risk. It should be specific enough to guide action, feasible in the process, and proportionate to severity. “Improve controls” is too vague. “Require an independent callback to a verified contact for bank-detail changes and retain the verification record” is more actionable, if it fits the organization’s risk and process.
Management owns decisions and implementation. Internal audit can discuss options and agree on an action owner and target date, but should not select the vendor, configure the system, approve the control, or certify its own implementation as independent assurance.
A recommendation is not the only acceptable response. Management may choose an alternative action that addresses the same risk. Audit evaluates whether the response is adequate and tracks implementation according to policy. If management accepts the risk, the chief audit executive considers whether that acceptance is within authority and tolerance.
Validate facts and handle disagreement
Before final communication, discuss factual accuracy with relevant stakeholders. A manager may provide evidence that an exception was approved in a separate system or that a transaction was reversed. The auditor should test that information and revise factual errors.
Disagreement about risk rating or recommendation is different from factual correction. Management may believe the exposure is acceptable; the auditor should document the rationale and retain an evidence-supported assessment. The report can state management’s response without changing a supported conclusion merely to avoid disagreement.
If evidence remains conflicting, disclose the limitation or unresolved matter. Do not write a definitive claim that the workpapers cannot support. Engage supervision helps ensure the conclusion is fair, complete, and consistent with the evidence.
Communication throughout the engagement
Communication starts during planning: purpose, objectives, scope, criteria, schedule, information requests, and responsibilities. Ongoing communication can surface access problems, new risks, urgent concerns, or misunderstandings before they affect the final result.
Significant matters may need prompt escalation before routine fieldwork concludes, particularly where there is immediate harm, suspected fraud, evidence destruction, or a material risk. Follow established protocols, preserve confidentiality, and involve authorized leaders.
Final communication should be accurate, objective, clear, concise, constructive, complete, and timely. It should explain the engagement’s purpose, scope, conclusion, important findings, and relevant management actions or responses. Avoid technical language that hides what happened or dramatic language that exceeds the evidence.
Worked example: late access removal
The criterion is that terminated employee access must be removed within one business day. The auditor tests a validated population of terminations and system accounts, then finds that 4 of 40 sampled users retained access beyond the requirement. System logs establish the removal dates, and HR records establish termination dates.
The auditor confirms the population and whether the four accounts were active, whether emergency or leave status applied, and whether compensating monitoring occurred. If one account belonged to an employee transferred to a different role, the original termination record needs context. The conclusion should report the verified exceptions and residual risk, not assume all late removals created misuse.
Evidence suggests the cause is a manual handoff with no assigned backup. The recommendation could require automated HR-to-identity notifications and monitoring of overdue removals. Management chooses the control design and owner. Audit later validates that the response was implemented and operating for a suitable period.
Risk acceptance and escalation
Management may accept residual risk after considering cost, benefit, and operational priorities. Internal audit does not make that decision. When acceptance concerns a significant exposure, determine whether the decision maker has authority and whether the risk is within approved tolerance.
If the chief audit executive concludes senior management has accepted risk beyond the organization’s tolerance, the concern is communicated to the board or other governing body according to the Standards and reporting arrangements. The engagement auditor should elevate the matter to the chief audit executive rather than independently negotiate risk acceptance with the process owner.
Escalation is not a substitute for a clear report. Document the risk, evidence, management’s rationale, who accepted it, and what governance communication occurred. A risk acceptance may remain unresolved even after the report is issued.
Common reporting mistakes
Do not confuse condition with cause: “approvals were missing” is a condition; “staff ignored the policy” is a cause claim that requires support. Do not confuse potential effect with actual loss. Do not turn a recommendation into an instruction that assumes audit controls management.
Do not remove a finding because management disagrees with severity, and do not insist on an action that fails to address the actual cause. Do not conceal scope limitations or omit contradictory evidence. Each choice can undermine the credibility of the audit.
The exam often asks for the best communication step. Identify whether the issue is a factual error, a disagreement, an urgent risk, or acceptance beyond authority. Each has a different response and escalation route.
A concise finding structure
A practical structure is: objective and scope context; condition; criterion; supported cause; actual or potential effect; recommendation or agreed action; owner and due date; management response; and follow-up method. Not every report uses identical headings, but the logic should be present.
Use concise wording and cite evidence in the workpapers. State scope and sample limits. If an issue is important but not proven, distinguish a risk indicator from a confirmed exception and explain what further work is needed.
Exam application checklist
When choosing an answer, ask: What is the criterion? What does the evidence establish? Is cause known or inferred? Is the effect actual or potential? Who owns the corrective action? Does the matter require prompt communication or governance escalation?
The 2025 Part 2 domain of Engagement Supervision and Communication is 10%, but findings depend on the other domains: objectives and criteria from planning, evidence and analysis from performance, then review and communication. Study the full chain rather than memorizing report labels.
Finding severity and prioritization
Severity should reflect the nature and magnitude of exposure, likelihood, duration, affected population, compensating controls, recurrence, and governance significance. A single high-impact issue can warrant attention even if it appears in a small sample. A frequent low-impact exception can also reveal a systemic weakness.
Do not let the number of exceptions alone decide severity. A small sample can identify a critical issue; a larger sample can reveal a minor documentation gap. Explain the reasoning and align the rating with the organization’s approved methodology.
Follow-up and closure
A management action plan should identify accountable owner, steps, and a realistic target date. Internal audit tracks agreed actions and obtains evidence of completion. Closure should be based on evidence that the response addresses the risk, not on a verbal assurance or a changed policy alone.
For a new automated access control, follow-up might inspect configuration, test sample terminations, and confirm that alerts reach an assigned reviewer. If the control is newly implemented, determine whether enough operating time has passed to assess effectiveness. If not, distinguish implementation from validated operation.
Management response that differs from audit
A process owner may reject a recommendation but propose another response. Evaluate whether the alternative reduces the same risk and whether it has an accountable owner and monitoring. Internal audit should not insist on its preferred design if management’s alternative is adequate.
If management accepts the exposure without corrective action, document the rationale and assess whether the decision is within authority and tolerance. The engagement auditor raises significant unresolved acceptance to the chief audit executive; the appropriate governance recipient handles escalation under the established framework.
A well-supported issue can be constructive without diluting its significance. State the risk plainly, recognize existing safeguards, and give management enough information to choose a response that is practical and accountable.
The final report remains independent.
For example, if four of 40 tested terminations retained access after the policy deadline, the report should identify that tested result and describe the risk. If the sample was not designed to project, avoid describing the whole workforce as affected. Further analysis can determine whether the four cases share a manager, system, or process cause.