32.2 Cause ("Why It Happened")

Key Takeaways

  • When law or regulation prohibits public disclosure, GAGAS requires the public report to state that information was omitted and identify the legal basis. Any separate restricted communication is provided only when appropriate and only to recipients authorized to receive it.
  • GAGAS findings commonly develop criteria, condition, cause, and effect or potential effect, with recommendations when warranted; which elements are necessary and how fully they are developed depend on the audit objectives and circumstances.
  • Auditee management is responsible for procuring audit services competently, providing unrestricted access, signing the Management Representation Letter, and establishing formal Corrective Action Plans (CAPs) monitored by an independent Audit Committee.
Last updated: September 2026

3. Cause ("Why It Happened")

Cause isolates the root operational reason why the condition deviated from the criteria. Identifying the true root cause is essential; if the cause is misidentified, management's corrective actions will treat symptoms rather than solving the problem. Common causes include inadequate staffing, obsolete software, absence of supervisory review, vague policy instructions, or lack of employee training.

4. Effect or Potential Effect ("What Difference It Makes")

Effect quantifies the tangible harm or exposure resulting from the condition. Effect explains why legislative leaders, executive management, and taxpayers should care about the finding. It encompasses:

  • Financial waste, improper payments, or questioned costs;
  • Public health, environmental, or physical safety hazards;
  • Delays in service delivery to vulnerable populations;
  • Compromise of sensitive data or reputational damage.

5. Recommendation ("What Needs to Be Done")

Recommendations must be logical, practical, cost-effective, and directed to the specific management official possessing authority to implement corrective change. Recommendations should address the root cause to prevent recurrence of the deficiency.


Handling Sensitive, Confidential, and Classified Information

Government audit reports are public documents, reflecting democratic accountability. However, audits frequently evaluate programs involving sensitive data: classified national security documents, Personally Identifiable Information (PII), Protected Health Information (HIPAA), confidential federal tax data (Internal Revenue Code § 6103), or ongoing criminal investigations.

GAGAS Protocols for Sensitive Information

When law or regulation prohibits public disclosure of particular information, the public report should state that information was omitted and identify the legal or regulatory basis. Auditors should consider whether a separate limited-use or restricted communication is appropriate, but GAGAS does not make an unredacted companion report automatic in every case. Any nonpublic communication must go only to recipients authorized to receive the information and must comply with the controlling protection requirements.


Auditee Governance Responsibilities Throughout the Audit Lifecycle

An effective audit requires active engagement from the audited entity. Auditee management holds critical statutory and professional responsibilities across the audit lifecycle:

1. Procurement of Audit Services

When procuring independent audit services (e.g., from CPA firms), public entities must utilize competitive procurement procedures aligned with OMB Uniform Guidance and state/local laws. Evaluation criteria must prioritize technical competence, staff qualifications, public sector experience, and peer review history over lowest price alone.

2. Supporting Fieldwork and Unrestricted Access

Auditee management is legally required to provide auditors with full, timely, and unrestricted access to all personnel, records, facilities, general ledgers, database systems, and contractor files necessary to satisfy the audit objectives.

3. The Management Representation Letter

At the conclusion of fieldwork, management must provide the auditor with a written Management Representation Letter. Signed by the agency head and Chief Financial Officer, this document confirms that:

  • Management acknowledges its responsibility for internal control and statutory compliance;
  • Management has provided complete, truthful records and disclosed all known noncompliance, fraud, and litigation;
  • Management confirms that all uncorrected misstatements are immaterial.

4. Audit Follow-Up and Corrective Action Plans (CAPs)

Auditee management is responsible for tracking prior audit recommendations. When findings are issued, management must formulate a formal Corrective Action Plan (CAP) detailing root-cause remediation, time-bound phased milestones, assigned executive owners, and dedicated resources.

5. Role of the Independent Audit Committee

A high-performing public entity establishes an independent Audit Committee appointed by the governing board. The audit committee serves as an objective liaison between external auditors and executive leadership, oversees auditor procurement, reviews audit findings, and rigorously monitors management's timely implementation of CAPs.


Practical Public Finance Scenario: State Child Welfare Casework Performance Audit & 5-Element Finding

Scenario: The State Auditor General conducts a GAGAS performance audit of the Department of Child Safety (DCS). Fieldwork uncovers that in 65 out of 100 sampled high-risk child abuse reports, caseworkers failed to conduct mandatory in-person child welfare checks within 24 hours. In 18 cases, face-to-face visits did not occur for more than 30 days. The audit reveals that DCS caseworkers carry an average of 48 active cases (national standard is 15), the agency's mobile tracking application crashes repeatedly, and supervisors do not review intake logs until monthly billing runs.

Drafting the Applicable Elements of the Audit Finding

+-----------------------------------------------------------------------------------+
|              STATE AUDITOR GENERAL: PERFORMANCE AUDIT FINDING DRAFT               |
+-----------------------------------------------------------------------------------+
|  1. CRITERIA:                                                                     |
|  State Welfare Code § 42-101 and DCS Policy Manual Section 4 mandate that all     |
|  high-risk reports of child abuse require an in-person, face-to-face safety check |
|  conducted within 24 hours of report receipt.                                     |
|                                                                                   |
|  2. CONDITION:                                                                    |
|  In 65 of 100 sampled high-risk cases (65%), caseworkers failed to conduct safety |
|  checks within 24 hours. In 18 cases, visits were delayed beyond 30 days.         |
|                                                                                   |
|  3. CAUSE:                                                                        |
|  DCS staffing shortages caused caseloads to reach 48 cases per worker (320% above |
|  industry standards); mobile caseload software suffered frequent field outages;   |
|  and supervisory review controls operated only monthly rather than daily.        |
|                                                                                   |
|  4. EFFECT / POTENTIAL EFFECT:                                                    |
|  Vulnerable children remained in unmonitored, potentially dangerous domestic      |
|  environments, resulting in substantiated physical injury in 4 documented cases.  |
|                                                                                   |
|  5. RECOMMENDATIONS:                                                              |
|  1. DCS executive management should reallocate emergency funding to hire 40       |
|     additional caseworkers to align caseloads with national standards.            |
|  2. The Chief Information Officer should remediate mobile app sync defects.       |
|  3. Management should implement mandatory daily automated supervisory exception   |
|     alerts for any intake report unvisited after 18 hours.                        |
+-----------------------------------------------------------------------------------+

Handling PII Redactions

Because child welfare records contain confidential juvenile records, psychiatric evaluations, and sensitive names protected under state juvenile privacy statutes, the State Auditor General must redact all identifying PII from the publicly released audit report, publish a formal notice citing State Welfare Code § 42-109 as the legal basis for redaction, and deliver an unredacted restricted report to the legislative oversight committee and the Governor.

Loading diagram...
The Five Elements of an Audit Finding & Auditee Remediation Lifecycle
Test Your Knowledge

A federal performance audit of a military medical logistics center uncovers significant security lapses in the storage of classified vaccine patents, alongside unauthorized disclosures of military service members' Personally Identifiable Information (PII) and medical histories protected under HIPAA. Under GAGAS reporting standards, how must the audit organization package and release these findings?

A
B
C
D
Test Your Knowledge

At the conclusion of a GAGAS audit, auditors obtain written representations from appropriate auditee management. What is the primary purpose of those representations?

A
B
C
D