15.2 Managing & Disclosing Nonconformance

Key Takeaways

  • Nonconformance under GIAS is divided into isolated procedural nonconformance (localized clerical lapses that do not affect findings or objectivity) and significant nonconformance (deficiencies impairing governance, independence, scope, or report validity).
  • Under GIAS Standard 12.3, the CAE must formally report significant nonconformance and its specific operational impact directly to senior management and the Audit Committee.
  • When significant nonconformance directly affects an individual engagement (such as a scope limitation), the CAE must formally disclose the nonconformance, reasons, and impact on the face of the final published report.
  • Remediation requires a formal Corrective Action Plan (CAP) structured around SMART criteria (Specific, Measurable, Achievable, Relevant, Time-bound) with designated milestone owners.
  • Restoring conformance status requires validated execution of the CAP, documented re-testing through ongoing QAIP monitoring, and formal closure reporting accepted by the Audit Committee.
Last updated: September 2026

15.2 Managing & Disclosing Nonconformance

[!NOTE] Professional Standards Foundation: Under the Global Internal Audit Standards (GIAS), specifically Standard 12.1 (Internal Quality Assessment), Standard 8.3 (Quality), and Standard 11.3 (Communicating Results), the Chief Audit Executive (CAE) is required to manage and transparently disclose any nonconformance with the Standards or the Code of Ethics. When nonconformance impacts the overall scope or operation of the internal audit function, or when it affects the validity of a specific engagement, the CAE must formally communicate the deficiency, the reasons for nonconformance, and its detailed impact to senior management and the board (Audit Committee).

Even well-managed internal audit departments may encounter situations where operational, organizational, or resource pressures cause deviations from the Global Internal Audit Standards or the Code of Ethics. Budgets may be curtailed, executive management may attempt to restrict access to sensitive records, or key competencies may be lost through sudden attrition. In other cases, internal monitoring may reveal that audit teams skipped mandatory testing steps or failed to obtain supervisory sign-offs prior to report issuance. The hallmark of a mature, professionally compliant internal audit activity is not the complete absence of errors, but the rigorous, disciplined process through which nonconformance is identified, evaluated, disclosed, and remediated.


Differentiating Isolated Procedural Nonconformance from Significant Nonconformance

Professional judgment is required to evaluate the severity of any standard deviation. GIAS distinguishes between two fundamental tiers of nonconformance:

1. Isolated Procedural Nonconformance

  • Characteristics: Minor, localized operational infractions that do not compromise the credibility, objectivity, scope, or factual validity of the audit work. Examples include an auditor clearing a supervisory review note a few days after report release, missing a secondary sign-off on an administrative kickoff checklist, or formatting an audit finding slightly outside departmental style templates.
  • Operational Impact: Negligible. The audit conclusions remain fully supported by reliable evidence, auditor objectivity remains intact, and stakeholder reliance is unaffected.
  • Remediation & Governance Handling: Handled internally through supervisory coaching, workpaper correction, and tracking in the QAIP defect log. It does not trigger formal disclosure to the Audit Committee, nor does it restrict the function from using the "Conforms with Standards" statement.

2. Significant Nonconformance

  • Characteristics: Deficiencies that directly impair the function's independence, objectivity, scope of work, technical competence, or the evidentiary validity of audit results.
  • Core Examples: Scope limitations imposed by management (e.g., denying access to sensitive accounts or systems); auditors auditing activities they managed within the past 12 months without recusal; widespread issuance of audit reports without workpaper evidence or supervisory review; lapsing past the five-year EQA deadline; or operating without an approved Internal Audit Charter.
  • Operational Impact: Severe. The integrity of audit opinions is undermined, exposing the board to undetected operational, financial, and compliance risks.
  • Remediation & Governance Handling: Triggers mandatory formal disclosure to senior management and the Audit Committee, immediate suspension of the "Conforms with Standards" statement, and the execution of an aggressive Corrective Action Plan.

Mandatory Governance and Engagement Disclosure Obligations

Transparency is non-negotiable under the Global Internal Audit Standards. When significant nonconformance occurs, GIAS Standard 12.3 and Standard 11.3 impose strict, affirmative disclosure requirements:

1. Departmental-Level Disclosures to the Board and Senior Management

When nonconformance affects the overall operation, positioning, or scope of internal audit:

  • Immediate Escalation: The CAE must formally report the matter in writing to executive leadership (CEO, CFO) and directly to the Audit Committee chair.
  • Required Content of Disclosure:
    • The exact standard(s) or ethical principle(s) violated.
    • The underlying root cause of the nonconformance (e.g., budget cuts, management refusal of access, staffing vacancies).
    • The specific operational and governance impact (e.g., inability to provide assurance over enterprise cybersecurity controls).
    • The interim risk exposure accepted by the organization as a consequence.
    • The comprehensive Corrective Action Plan and estimated remediation timeline.

2. Engagement-Level Disclosures in Published Reports

If significant nonconformance affects an individual audit engagement (such as a management-imposed scope limitation that prevented testing high-risk financial transactions):

  • Mandatory Report Disclosure: The CAE must disclose the nonconformance directly within the final engagement communication distributed to executive management and the Audit Committee.
  • Content Requirements: The report must specify:
    1. The specific standards with which full conformance was not achieved.
    2. The reason(s) for the nonconformance.
    3. The precise impact on the engagement scope, limitations on the assurance provided, and risks that could not be evaluated.
  • Prohibition on Omission: The CAE cannot conceal the impairment within confidential workpapers or verbal briefings; it must appear on the face of the issued deliverable.

Developing and Executing a Formal Corrective Action Plan (CAP)

Remediating significant nonconformance requires moving beyond superficial fixes to address systemic vulnerabilities through a structured Corrective Action Plan (CAP):

  1. Rigorous Root Cause Analysis: Utilizing diagnostic tools such as the "Five Whys" or Ishikawa (fishbone) diagrams to determine why the breakdown occurred (e.g., analyzing whether skipped supervisory reviews resulted from unrealistic audit deadlines, lack of reviewer training, or software workflow gaps).
  2. SMART Remediation Actions: Each corrective action must be Specific, Measurable, Achievable, Relevant, and Time-bound.
  3. Assigned Single-Point Accountability: Designating a named audit leader who owns the execution of each remediation milestone.
  4. Preventative Control Engineering: Implementing automated system locks in audit software (e.g., preventing report generation without supervisor sign-offs) to prevent recurrence.

Remediation Progress Tracking and Restoring Conformance Status

Remediation is a disciplined governance lifecycle that culminates in formally restoring professional standing:

  • Audit Committee Progress Dashboards: The CAE must provide periodic (typically quarterly) updates to the Audit Committee detailing milestone completion, target date variances, and testing results.
  • Validation Re-Testing: The internal QAIP team (or an independent peer reviewer) must perform validation testing on newly completed files to verify that corrective actions are functioning effectively in live operations.
  • Formal Closure and Conformance Reinstatement: Once re-testing demonstrates sustained compliance and the Audit Committee formally accepts remediation results, the CAE can reinstate the "Conforms with Standards" statement. If nonconformance involved an expired EQA, full conformance is reinstated only upon completion of a new external assessment.

Comparative Analysis: Isolated vs. Significant Nonconformance

DimensionIsolated Procedural NonconformanceSignificant Nonconformance
Operational NatureMinor, clerical, or formatting discrepancyFundamental breach of standards, ethics, or independence
Evidentiary IntegrityAudit findings and opinions remain 100% validFindings may be incomplete, biased, or unsubstantiated
Audit Scope & ObjectivityUnaffected; work completed thoroughlyDirectly impaired, restricted, or compromised
Board Disclosure Required?No; managed internally within audit functionYes; mandatory formal disclosure to Audit Committee
Engagement Report Disclosure?No; workpaper correction sufficientYes; mandatory disclosure in final published report
Impact on 'Conforms' StatementNone; function continues using statementImmediate suspension of statement until remediated
Remediation VehicleSupervisory coaching and workpaper updateFormal SMART Corrective Action Plan with board tracking
Loading diagram...
Nonconformance Triage, Escalation, and Corrective Action Plan Lifecycle
Test Your Knowledge

During an internal audit of corporate foreign subsidiaries, executive management prohibits the audit team from examining cash disbursements and local agent consulting agreements in high-risk jurisdictions, citing regional political sensitivities. Management directs the lead auditor to omit any mention of these activities from the audit report. What are the CAE's mandatory obligations under the Global Internal Audit Standards?

A
B
C
D
Test Your Knowledge

An annual periodic internal quality assessment reveals that in four completed audits, the engagement in-charge auditor cleared supervisory review notes three days after the final report had been issued to business unit management. Further investigation confirms that the workpapers contained complete evidence, findings were fully substantiated, and all observations had been reviewed verbally before issuance. How should the CAE classify and handle this finding?

A
B
C
D
Test Your Knowledge

An External Quality Assessment concludes with an overall rating of 'Partially Conforms' due to pervasive failures to conduct root cause analyses and systematic gaps in supervisory sign-offs. What sequence of actions must the CAE take to remediate the nonconformance and legally restore the department's ability to use the 'Conforms with Standards' statement?

A
B
C
D