8.5 Addressing Findings from External Entities: Regulators, Outside Counsel, and Consultants

Key Takeaways

  • The Detailed Content Outline makes ensuring that audit results from external entities — outside counsel, government, and consultants — are addressed a discrete Domain 4 task, separate from developing and conducting internal audits.
  • External findings arrive outside the internal audit workflow and are frequently orphaned: delivered to legal or to a business unit, discussed once, and never entered into any tracking system with an owner and a due date.
  • Every external finding should enter a single enterprise findings register alongside internal findings, with a named owner, root cause, corrective action, due date, and verification evidence, regardless of who produced it.
  • A repeat finding is materially worse than a first finding: it shows the organization was told, agreed to act, and did not, which enforcement authorities read as conscious disregard rather than oversight failure.
  • Findings that management declines to remediate must be escalated as formal, documented risk acceptance at the governing-authority level, not resolved by silence at the business-unit level.
Last updated: August 2026

8.5 Addressing Findings from External Entities

Internal audit findings have a workflow. They are logged, assigned, tracked, and reported to the audit committee until closed. Findings that arrive from outside the organization frequently have no workflow at all — and the Detailed Content Outline lists ensuring that audit results from external entities (e.g., outside counsel, government, consultants) are addressed as its own Domain 4 task precisely because this is where organizations lose track.

The exposure is asymmetric. An unaddressed internal finding is an internal control weakness. An unaddressed regulator finding is documented proof that the organization was told and did nothing.


1. Where External Findings Come From, and Why They Get Lost

SourceTypical formWhy it goes untracked
Regulatory examination or inspectionExamination report, deficiency letter, warning letter, Form 483Routed to legal or the regulated business unit; treated as a legal matter rather than a control finding
Government investigation or auditSubpoena-driven findings, agency audit report, OIG reportManaged by counsel under privilege; remediation obligations never leave the legal file
Outside counsel investigationInvestigative report with control recommendationsThe report's conclusions on culpability are actioned; the control recommendations at the back are not
External program assessmentMaturity assessment, gap analysisDelivered to the CCO as a strategy document rather than as findings with owners
External financial auditManagement letter, significant deficiency, material weaknessOwned by finance and the audit committee; compliance-relevant items never reach compliance
Customer or third-party auditSupplier audit report, certification body findingHandled by the account or quality team as a commercial matter
Accreditation or certification bodyNon-conformity report (e.g., against ISO 37301)Treated as a certification administrative step
Whistleblower-triggered external reviewIndependent review commissioned by the boardBoard receives the report; operational follow-through is assumed rather than tracked

The common thread: external findings are delivered to a recipient rather than into a system. A finding that lives in an inbox, a board deck, or a privileged legal folder has no owner, no due date, and no closure evidence.


2. The Unified Findings Register

The correcting control is simple to describe and demands real discipline to run: one enterprise findings register, one workflow, regardless of source. Internal audit findings, monitoring exceptions, investigation-derived control gaps, and external findings all enter the same pipeline.

FieldWhy it matters
Finding ID and sourceDistinguishes a regulator finding from a self-identified one — a distinction the board must see
Description and criteriaThe standard the organization failed to meet, in the external party's own words
Risk ratingDrives sequencing and escalation thresholds
Named individual ownerA department is not an owner; accountability requires a person
Root causePrevents the "re-train the employee" response to a design failure
Corrective actionThe specific control change, not a restatement of the finding
Due date and statusWith explicit approval required for any extension
Verification evidenceWhat proves it closed — a test result, not an assertion
Independent closure validationWho confirmed closure, and it must not be the owner
Repeat flagWhether this finding, or its root cause, has appeared before

The Closure Workflow

External Finding Lifecycle:
├── 1. Intake        Any external report routes to the findings register within a fixed window
├── 2. Triage        Compliance + Legal + Internal Audit classify, rate, and assign an owner
├── 3. Root Cause    Owner analyses cause; compliance challenges "human error" conclusions
├── 4. CAP           Corrective action with milestones, resources, and a due date
├── 5. Execution     Owner implements; compliance monitors progress against milestones
├── 6. Verification  Independent testing confirms the control now operates as designed
├── 7. Closure       Closed only on evidence; validated by someone other than the owner
└── 8. Reporting     Open external findings reported to the audit committee every cycle

Two rules make the workflow real:

  • Closure requires evidence, not assertion. "Policy updated" is not closure of a finding that payment approvals were bypassed. Closure is a test showing that bypassed approvals are now blocked or detected.
  • The validator is never the owner. The person accountable for fixing a control cannot be the person who certifies it fixed.

3. Repeat Findings and Formal Risk Acceptance

Repeat Findings Are a Governance Event

A first finding says a control was weak. A repeat finding says the organization was told, agreed to remediate, reported closure, and the weakness persisted. That progression maps directly onto the difference between an oversight failure and conscious disregard, which is the distinction Delaware fiduciary jurisprudence and federal prosecutors both care about.

Repeat findings should therefore be handled differently from new ones:

  • Automatic escalation to the audit committee, not just to management.
  • Mandatory re-examination of the original root cause — a repeat almost always means the first root-cause analysis was wrong, typically because a design defect was diagnosed as a training defect.
  • Review of whether the original closure was validated at all, and by whom.

When Management Declines to Remediate

Sometimes the business will not act: the cost is high, the finding is contested, or the control conflicts with an operational reality. That outcome is legitimate only as an explicit, documented decision at the right level.

Weak handlingCorrect handling
Finding stays open indefinitely with rolling extensionsFinding is closed as accepted risk, with a decision record
Business unit informally decides not to actAcceptance approved at the governing-authority or designated committee level, proportionate to the risk
No record of who decided or whyNamed approver, rationale, compensating controls, and a re-review date
Compliance stops reporting itAccepted risks remain on the board report until the re-review date

Exam Watch — The finding that was never entered. A scenario describes a regulator's examination letter delivered to the general counsel eighteen months ago, discussed once at a management meeting, and never entered into any tracking system; the same deficiency now recurs. The best answer is not "remediate the deficiency" alone — that fixes one instance of a systemic intake failure. It is to remediate and close the intake gap, routing all externally sourced findings into the enterprise findings register with owners, due dates, and audit committee reporting. Fixing the finding without fixing the pipeline guarantees the next external finding is lost the same way.

Loading diagram...
Unified Findings Register: External and Internal Sources, One Closure Workflow
Test Your Knowledge

During a routine review, a compliance director discovers that a state regulator issued an examination deficiency letter fourteen months ago identifying inadequate segregation of duties in claims payment approvals. The letter was sent to the general counsel, discussed once at a management meeting, and never entered into any tracking system. The same deficiency has now been identified again in the current examination. What is the most complete response?

A
B
C
D
Test Your Knowledge

An external compliance assessment identifies a gap in third-party screening. The business unit owner reports the finding remediated, citing an updated procedure document and a completed staff briefing. The compliance function is preparing to close the finding in the register. What closure standard should apply?

A
B
C
D
Test Your Knowledge

A finding from an external program assessment recommends a control change that the affected business unit says would cost $2.4 million and materially delay order fulfillment. Management does not intend to implement it. How should the compliance function handle the finding?

A
B
C
D