Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CIA Audit Findings and Follow-Up

Updated 8 min read
Key takeaway

A finding compares evidence-supported conditions with applicable criteria and describes cause and effect when supported.

  • Management owns corrective actions.
  • Internal audit tracks the response, verifies implementation and risk reduction with evidence, and escalates significant unresolved risk acceptance through appropriate governance.
On this page14 sections
  1. Finding and action are separate decisions
  2. Agree a response and accountability
  3. Verify implementation with evidence
  4. Overdue actions and escalation
  5. Worked example: incomplete access remediation
  6. Risk acceptance
  7. Monitoring methods and performance
  8. Common follow-up mistakes
  9. Exam application
  10. Risk-based follow-up frequency
  11. What adequate evidence looks like
  12. When management rejects the recommendation
  13. Follow-up example: vendor controls
  14. Additional function-level application

Finding and action are separate decisions

An engagement finding explains a supported condition and its difference from criteria. It may describe cause, effect, and risk when the evidence supports those statements. The finding is an audit conclusion; the corrective action belongs to management.

A recommendation suggests a way to address the risk, but management may choose a different response. The internal audit function evaluates whether the alternative is adequate, assigns an owner and target date with management, and tracks implementation.

This boundary matters in Part 3 because the function monitors outcomes without operating controls. Audit should not approve transactions, configure the remediation, or make management’s risk decision and then provide assurance over its own work.

Agree a response and accountability

An action plan should identify what will change, who is accountable, when it is due, and how success will be demonstrated. A vague commitment such as “improve training” may not address a control weakness unless the issue truly arises from training and the effect can be tested.

Management owns the design and implementation. The internal audit team can discuss the risk and options, but should not dictate an operational solution in a way that assumes responsibility. If management chooses an alternative, document the rationale and evaluate whether the risk is reduced.

The owner and due date make monitoring possible. High-risk actions may need interim milestones; low-risk items may use a simpler follow-up. The function should align monitoring depth with risk, not treat every action identically.

Verify implementation with evidence

A status field marked “complete” is not enough. Internal audit obtains evidence that the action was implemented and evaluates whether it addresses the finding. Evidence might include revised system access, transaction tests, reconciliations, training records, review logs, configuration, or observation, depending on the issue.

Suppose a finding concerns terminated employees retaining access. A policy revision can show that expectations changed, but the function may need to inspect system configuration, compare termination records with access logs, and test new cases after enough operation.

Distinguish implementation from effectiveness. A new control can be installed but poorly operated. If too little time has passed to test consistent performance, report that implementation is complete but operating effectiveness remains unvalidated, and schedule appropriate follow-up.

Overdue actions and escalation

Track due dates, risk ratings, owners, status, evidence, and reasons for delay. Escalate overdue high-risk actions to responsible management and the chief audit executive according to methodology. Significant issues may need board communication, especially when management accepts risk beyond authority or organizational tolerance.

A due date extension should have a rationale and an appropriate approver. Repeated extensions can signal that risk remains unresolved. The audit function should reassess exposure and report material delays rather than letting an open item disappear from dashboards.

Management can accept residual risk; internal audit does not accept it on management’s behalf. If the chief audit executive concludes that management accepted risk beyond tolerance, the matter is communicated to the board or appropriate governing body through established channels.

Worked example: incomplete access remediation

The finding states that terminated employee accounts remained active beyond policy deadlines. Management responds by issuing a new policy and marking the action complete. The chief audit executive or designee reviews the evidence and sees no system configuration change or transaction testing.

The policy is a design improvement, but it does not establish that HR notifications now reach system administrators or that access is removed on time. Follow-up should inspect workflow configuration, test a sample of terminations from an appropriate period, and determine whether exceptions were reviewed.

If testing shows the process works in two months but no longer period has elapsed, the function can describe the evidence and schedule a later effectiveness test. Closure should not overstate certainty.

Risk acceptance

Sometimes management decides not to implement a recommendation. The chief audit executive evaluates the risk and whether acceptance is within the responsible manager’s authority and approved tolerance. An accepted risk is not the same as a resolved finding.

Document who made the decision, the rationale, residual exposure, and any compensating controls. If risk exceeds tolerance or authority, escalate it. The engagement auditor should not negotiate away a material risk or make an unauthorized board communication on their own.

The purpose is not to force every recommendation. Management can choose a reasonable alternative or accept risk within its authority. The function provides independent information so appropriate leaders can make and oversee that choice.

Monitoring methods and performance

A function may use a centralized action tracker, periodic status certifications, follow-up engagements, data reports, or management attestations. The method should support evidence, risk ranking, aging, responsible owners, and escalation. A dashboard without validation may report status but not effectiveness.

Performance measures can include overdue high-risk actions, time to remediation, recurrence, verification failures, and management response quality. Interpret metrics with context; a low overdue count can result from closing items prematurely.

The chief audit executive should periodically assess whether the follow-up method is timely and effective. If actions recur after closure, review whether root causes were addressed or the verification method was too weak.

Common follow-up mistakes

Do not close an issue solely because management says it is done. Do not require audit to implement the fix. Do not treat a revised policy as proof that a control operates. Do not let every delay pass without risk assessment. Do not accept material risk beyond authority without escalation.

A good closure note identifies the corrective action, evidence reviewed, tests performed, results, limitations, and conclusion about risk reduction. If more operating history is required, say so and schedule the remaining validation.

Exam application

Identify whether the scenario asks for agreement on an action, evidence of implementation, operating effectiveness, overdue escalation, or risk acceptance. Choose the step that addresses that question and preserves management accountability.

Part 3 allocates 45% to Engagement Results and Monitoring. Practice explaining how findings lead to action, how action is verified, and how unresolved risk reaches the right governance level.

Risk-based follow-up frequency

The function can prioritize follow-up by finding severity, exposure, management owner, promised date, recurrence, and evidence needed. High-risk action plans may require closer monitoring, while low-risk improvements may be reviewed at a planned interval. A consistent method should still allow urgent escalation.

A dashboard can show overdue age and status, but leaders should review whether repeated extensions leave risk unaddressed. A change in business conditions may make the original action inadequate and require a revised response.

What adequate evidence looks like

Evidence should match the corrective action. For a new approval step, inspect completed approvals and verify that the approver had authority. For a system access change, review configuration and logs. For training, attendance is not proof that staff apply the procedure; sample work or observe practice.

If action is to add monitoring, evaluate thresholds, alert ownership, and resolution records. A control can exist but fail if exceptions are not investigated. The auditor should state whether evidence demonstrates design, implementation, or consistent operation.

When management rejects the recommendation

Management may disagree with a recommendation while accepting the finding. The function evaluates whether the alternative action addresses the same risk. If it does, document it and monitor it; audit should not insist on its preferred design solely for uniformity.

If management disputes the underlying facts, test new evidence and correct genuine errors. If it disagrees with severity, document the rationale and maintain an evidence-based assessment. If it accepts significant risk, determine authority and tolerance and escalate as appropriate.

Follow-up example: vendor controls

A finding concerns bank-detail changes accepted through email without independent verification. Management creates a callback control and assigns the accounts-payable manager. Audit reviews the procedure, verifies that callback contacts come from a trusted source, and tests changes after rollout.

One new record shows the callback was made to a phone number included in the same request email. The action exists but does not sufficiently address social engineering. Audit reports the evidence, discusses the residual risk, and asks management to strengthen the independent source. Closure waits for evidence of the improved process.

Follow-up can also inform future planning. Repeated findings in the same process may indicate that prior remediation did not address root cause or that the risk has changed. The chief audit executive can use recurrence data in the risk assessment and decide whether a new engagement, targeted testing, or governance communication is warranted. The action tracker is a source of risk information, not merely an administrative list.

Additional function-level application

Where evidence is unavailable, record the limitation and assess whether the finding remains open. If management’s action depends on a future system release, set an interim risk response and milestone. A final closure should wait for evidence that the intended control exists and works as expected.

For a high-risk open issue, the function may report status periodically until evidence supports closure or governance accepts the residual risk.

If management repeatedly extends the same action, reassess whether the original due date, owner, resources, or solution is realistic. Communicate meaningful delays and residual exposure rather than allowing the item to age without explanation.

The chief audit executive may provide periodic updates to governance about significant open matters. Reports should include current risk, management’s plan, age and reason for delay, interim safeguards, and any decision needed. This lets oversight bodies focus on material exposure rather than a list of unranked overdue items.

That context matters.