16.3 Aggregating Findings and Concluding on Governance, Risk, and Control

Key Takeaways

  • CIA Part 2 B8a is determining the significance of aggregated findings by professional judgment — several moderate findings with a common root cause can change the overall conclusion
  • GIAS Standard 14.5 requires an engagement conclusion that summarizes results relative to objectives and the overall significance of aggregated findings, including judgments on the activity's governance, risk management, and/or control processes
  • Apply rating scales only when the internal audit methodology requires them, consistently and supported by the file; ratings do not replace the GRC conclusion
  • Aggregation weighs shared root cause, pervasiveness, compensating controls, trend, and qualitative factors such as fraud indicators, law, safety, and reporting integrity
  • Formulating recommendations, CAE residual-risk acceptance communication, and action-plan monitoring are primarily CIA Part 3 2025 — Part 2 B8 stops at the engagement conclusion on GRC
Last updated: August 2026

16.3 Aggregating Findings and Concluding on Governance, Risk, and Control

Quick Answer: CIA Part 2 B8a–b asks you to determine the significance of aggregated findings by professional judgment and to determine elements when developing engagement conclusions — including the effectiveness of governance, risk management, and control processes of the activity under review. Several moderate findings can change the overall conclusion. If the methodology uses ratings, apply them consistently; ratings do not replace the GRC conclusion. The conclusion is a judgment on the activity's GRC, not a list of exceptions. Formulating recommendations, CAE residual-risk communication, and action-plan monitoring are primarily CIA Part 3 2025 — know the boundary; do not treat them as Part 2 core.

Chapter 15 appraised each finding (root cause, effect, significance). B8 is the next proficient step: look at the findings together, then conclude on the activity, not on a spreadsheet of exceptions. GIAS Standard 14.5, Engagement Conclusions, requires internal auditors to develop an engagement conclusion that summarizes results relative to the engagement objectives and management's objectives, and that summarizes professional judgment about the overall significance of the aggregated engagement findings. For assurance work, that conclusion includes judgments on the effectiveness of relevant governance, risk management, and/or control processes.

Aggregated significance is a professional-judgment call

B8a is not a calculator. You add, pattern-match, and judge. Chapter 15.4 already taught that an isolated, compensated, trivial exception is not automatically a significant finding. Aggregation asks the next question: do several findings, none of which was labeled high by itself, still change what you can say about the activity?

Same root cause. Three moderate findings — unmatched invoices paid, vendor-master changes without dual approval, and a shared AP service-account — may share one root cause: access and segregation of duties at the AP/IT boundary. Individually each might be moderate. Aggregated, they can support a conclusion that control over disbursements is not effective, or that risk management did not treat a known SOD risk.

Pervasiveness. One exception at one plant is not the same as the same exception at four plants and in two periods. Aggregation looks across sites, processes, and time — using the file (section 16.2), not a hunch about other sites you did not test.

Compensating controls. Five documentation findings in a process with a strong independent reconciliation that actually caught the dollars may remain moderate in aggregate. Five access findings with no compensating detective control may become a significant GRC issue.

Trend and interaction. Findings that worsen across quarters, or that combine (weak IT general control plus weak business-process control), weigh more together than separately.

Qualitative overlays. Fraud indicators, legal or safety exposure, and integrity of reporting can make a small-dollar cluster significant in aggregate even when no single item is high.

The classic fail is to treat each finding as a sealed box: none was rated high, therefore the activity's controls are effective. B8a exists because several moderate findings can change the overall conclusion.

PatternIndividual labelsAggregate judgment to consider
Twelve unmatched invoices, one site, compensating detective control caught all but twoModerateMaybe still needs improvement on that control, not automatically ineffective GRC
Unmatched invoices + SOD in vendor master + generic AP login, same root cause, no compensating controlModerate + moderate + moderateLikely ineffective control (and weak risk management of SOD) for the activity
Documentation nits only; key automated control tested effectiveLow / lowUnlikely to flip an otherwise effective conclusion
One high fraud-red-flag finding plus clean tests elsewhereHigh + satisfactory testsMay dominate the GRC conclusion for that objective even without many other findings

Rating scales — if the methodology uses them

Some internal audit functions rate findings (high / medium / low) and/or overall engagements (satisfactory / needs improvement / unsatisfactory, or a numeric scale). GIAS 14.5 does not require a universal color chart. If the methodology requires ratings, internal auditors must apply them consistently with that methodology, and the ratings must be supported by the file (section 16.2).

Ratings are a communication device, not a substitute for the conclusion. A Part 2 item that says assign overall green because no finding was red is testing whether you understand aggregation. A methodology that defines unsatisfactory as one high or three mediums is a local rule you follow when the vignette gives it. Do not memorize a fake IIA scoring table. If the methodology does not use ratings, do not invent them on the exam. Conclude in GRC language — effective, partially effective, ineffective — as supported by aggregated findings relative to objectives.

The conclusion is on GRC of the activity, not a list of exceptions

B8b's elements include the effectiveness of governance, risk management, and control processes of the activity under review. That is a judgment about the system, aligned to the engagement objectives and scope.

  • Governance of the activity: oversight, accountability, policies, and information used to direct the activity. A cluster of findings that management never saw, or that a committee never reviewed, can support a governance conclusion even if each operational exception is moderate.
  • Risk management of the activity: identification, assessment, and treatment of the risks you were scoped to look at. Repeated SOD failures after a known risk-register entry support a risk-management conclusion.
  • Control processes: design and operating effectiveness of the controls that mitigate those risks (Chapters 9–10 and 15). This is the most common Part 2 conclusion, but it is not the only one the syllabus names.

A bullet list of seven exceptions with no overall statement is not an engagement conclusion. Satisfactory except for the following items, without judging whether those items together leave GRC effective, is the same miss. Conversely, copying every exception into a paragraph labeled conclusion still is not a GRC judgment — it is a list with a heading. The conclusion must also stay inside scope. If you did not test IT operations, do not conclude that all IT general controls are effective. If the objective was disbursement control, the GRC conclusion is about that activity, not the entire enterprise.

Part 2 / Part 3 boundary (do not study these as Part 2 core)

GIAS Standard 14.4 (recommendations and action plans), Principle 15 (final engagement communication and monitoring action plans), and the CAE's duty to communicate acceptance of residual risk are primarily CIA Part 3 2025. On a Part 2 B8 item you develop the engagement conclusion on aggregated findings and GRC. You do not need a signed management action plan before you can conclude. You do not formulate the recommendation library or negotiate due dates as the tested skill. You do not accept residual risk for the board or write the CAE's residual-risk communication. You do not design the follow-up monitoring program.

Those topics may appear as wrong-answer options. Recognize them, then return to aggregation and the GRC conclusion. Chapter 18 covers communication during the engagement. Chapter 19 will map the rest of the Part 2 versus Part 3 fence. Do not drag 2019 Part 2 Domain I (managing the internal audit activity) into a B8 item either.

Worked example: AP engagement wrap-up

You have four findings: (1) twelve unmatched invoices paid, $186,400, moderate; (2) vendor-master changes by a single clerk, moderate; (3) a generic AP login used by three people, moderate; (4) missing evidence of annual AP policy acknowledgment, low. Findings 1–3 share an access/SOD root cause; no compensating detective control actually stopped the payments. The methodology uses high/medium/low findings and satisfactory / needs improvement / unsatisfactory overall. Individually nothing is high. Aggregated, professional judgment supports unsatisfactory (or at least not effective) control over disbursements, and risk management that did not treat the known SOD risk — not satisfactory because no high findings. You still do not, for Part 2, write the six recommendations and the follow-up tracker; that is Part 3.

Exam traps

  • No high finding implies overall effective (ignores aggregation).
  • Conclusion equals an exception list.
  • Ratings used as a substitute for GRC language, or invented when the methodology has none.
  • Requiring action plans or residual-risk acceptance before a Part 2 conclusion.
  • Concluding beyond scope.
Loading diagram...
From individual findings to a GRC engagement conclusion (GIAS 14.5)
Illustrative significance: highest single finding vs aggregated GRC concern (teaching 0–10 scale, not a real scoring model)
Test Your Knowledge

An AP engagement produced three moderate findings that share one root cause — unmatched invoices paid, vendor-master changes without dual approval, and a generic AP login — and no compensating detective control. No finding was rated high. Which B8a judgment is most appropriate?

A
B
C
D
Test Your Knowledge

Which statement best describes an engagement conclusion under CIA Part 2 B8b and GIAS Standard 14.5?

A
B
C
D
Test Your Knowledge

A CIA Part 2 item asks what the auditor must complete before developing the engagement conclusion on disbursement GRC. Which answer is correct for the 2025 Part 2 / Part 3 boundary?

A
B
C
D