8.5 Addressing Findings from External Entities: Regulators, Outside Counsel, and Consultants
Key Takeaways
- The Detailed Content Outline makes ensuring that audit results from external entities — outside counsel, government, and consultants — are addressed a discrete Domain 4 task, separate from developing and conducting internal audits.
- External findings arrive outside the internal audit workflow and are frequently orphaned: delivered to legal or to a business unit, discussed once, and never entered into any tracking system with an owner and a due date.
- Every external finding should enter a single enterprise findings register alongside internal findings, with a named owner, root cause, corrective action, due date, and verification evidence, regardless of who produced it.
- A repeat finding is materially worse than a first finding: it shows the organization was told, agreed to act, and did not, which enforcement authorities read as conscious disregard rather than oversight failure.
- Findings that management declines to remediate must be escalated as formal, documented risk acceptance at the governing-authority level, not resolved by silence at the business-unit level.
8.5 Addressing Findings from External Entities
Internal audit findings have a workflow. They are logged, assigned, tracked, and reported to the audit committee until closed. Findings that arrive from outside the organization frequently have no workflow at all — and the Detailed Content Outline lists ensuring that audit results from external entities (e.g., outside counsel, government, consultants) are addressed as its own Domain 4 task precisely because this is where organizations lose track.
The exposure is asymmetric. An unaddressed internal finding is an internal control weakness. An unaddressed regulator finding is documented proof that the organization was told and did nothing.
1. Where External Findings Come From, and Why They Get Lost
| Source | Typical form | Why it goes untracked |
|---|---|---|
| Regulatory examination or inspection | Examination report, deficiency letter, warning letter, Form 483 | Routed to legal or the regulated business unit; treated as a legal matter rather than a control finding |
| Government investigation or audit | Subpoena-driven findings, agency audit report, OIG report | Managed by counsel under privilege; remediation obligations never leave the legal file |
| Outside counsel investigation | Investigative report with control recommendations | The report's conclusions on culpability are actioned; the control recommendations at the back are not |
| External program assessment | Maturity assessment, gap analysis | Delivered to the CCO as a strategy document rather than as findings with owners |
| External financial audit | Management letter, significant deficiency, material weakness | Owned by finance and the audit committee; compliance-relevant items never reach compliance |
| Customer or third-party audit | Supplier audit report, certification body finding | Handled by the account or quality team as a commercial matter |
| Accreditation or certification body | Non-conformity report (e.g., against ISO 37301) | Treated as a certification administrative step |
| Whistleblower-triggered external review | Independent review commissioned by the board | Board receives the report; operational follow-through is assumed rather than tracked |
The common thread: external findings are delivered to a recipient rather than into a system. A finding that lives in an inbox, a board deck, or a privileged legal folder has no owner, no due date, and no closure evidence.
2. The Unified Findings Register
The correcting control is simple to describe and demands real discipline to run: one enterprise findings register, one workflow, regardless of source. Internal audit findings, monitoring exceptions, investigation-derived control gaps, and external findings all enter the same pipeline.
| Field | Why it matters |
|---|---|
| Finding ID and source | Distinguishes a regulator finding from a self-identified one — a distinction the board must see |
| Description and criteria | The standard the organization failed to meet, in the external party's own words |
| Risk rating | Drives sequencing and escalation thresholds |
| Named individual owner | A department is not an owner; accountability requires a person |
| Root cause | Prevents the "re-train the employee" response to a design failure |
| Corrective action | The specific control change, not a restatement of the finding |
| Due date and status | With explicit approval required for any extension |
| Verification evidence | What proves it closed — a test result, not an assertion |
| Independent closure validation | Who confirmed closure, and it must not be the owner |
| Repeat flag | Whether this finding, or its root cause, has appeared before |
The Closure Workflow
External Finding Lifecycle:
├── 1. Intake Any external report routes to the findings register within a fixed window
├── 2. Triage Compliance + Legal + Internal Audit classify, rate, and assign an owner
├── 3. Root Cause Owner analyses cause; compliance challenges "human error" conclusions
├── 4. CAP Corrective action with milestones, resources, and a due date
├── 5. Execution Owner implements; compliance monitors progress against milestones
├── 6. Verification Independent testing confirms the control now operates as designed
├── 7. Closure Closed only on evidence; validated by someone other than the owner
└── 8. Reporting Open external findings reported to the audit committee every cycle
Two rules make the workflow real:
- Closure requires evidence, not assertion. "Policy updated" is not closure of a finding that payment approvals were bypassed. Closure is a test showing that bypassed approvals are now blocked or detected.
- The validator is never the owner. The person accountable for fixing a control cannot be the person who certifies it fixed.
3. Repeat Findings and Formal Risk Acceptance
Repeat Findings Are a Governance Event
A first finding says a control was weak. A repeat finding says the organization was told, agreed to remediate, reported closure, and the weakness persisted. That progression maps directly onto the difference between an oversight failure and conscious disregard, which is the distinction Delaware fiduciary jurisprudence and federal prosecutors both care about.
Repeat findings should therefore be handled differently from new ones:
- Automatic escalation to the audit committee, not just to management.
- Mandatory re-examination of the original root cause — a repeat almost always means the first root-cause analysis was wrong, typically because a design defect was diagnosed as a training defect.
- Review of whether the original closure was validated at all, and by whom.
When Management Declines to Remediate
Sometimes the business will not act: the cost is high, the finding is contested, or the control conflicts with an operational reality. That outcome is legitimate only as an explicit, documented decision at the right level.
| Weak handling | Correct handling |
|---|---|
| Finding stays open indefinitely with rolling extensions | Finding is closed as accepted risk, with a decision record |
| Business unit informally decides not to act | Acceptance approved at the governing-authority or designated committee level, proportionate to the risk |
| No record of who decided or why | Named approver, rationale, compensating controls, and a re-review date |
| Compliance stops reporting it | Accepted risks remain on the board report until the re-review date |
Exam Watch — The finding that was never entered. A scenario describes a regulator's examination letter delivered to the general counsel eighteen months ago, discussed once at a management meeting, and never entered into any tracking system; the same deficiency now recurs. The best answer is not "remediate the deficiency" alone — that fixes one instance of a systemic intake failure. It is to remediate and close the intake gap, routing all externally sourced findings into the enterprise findings register with owners, due dates, and audit committee reporting. Fixing the finding without fixing the pipeline guarantees the next external finding is lost the same way.
During a routine review, a compliance director discovers that a state regulator issued an examination deficiency letter fourteen months ago identifying inadequate segregation of duties in claims payment approvals. The letter was sent to the general counsel, discussed once at a management meeting, and never entered into any tracking system. The same deficiency has now been identified again in the current examination. What is the most complete response?
An external compliance assessment identifies a gap in third-party screening. The business unit owner reports the finding remediated, citing an updated procedure document and a completed staff briefing. The compliance function is preparing to close the finding in the register. What closure standard should apply?
A finding from an external program assessment recommends a control change that the affected business unit says would cost $2.4 million and materially delay order fulfillment. Management does not intend to implement it. How should the compliance function handle the finding?