6.4 Following Up Findings & Recommendations
Key Takeaways
Follow-up determines whether agreed action addresses the risk behind a finding, not merely whether management reports an action as complete.
Recommendations need a responsible owner, target date, priority and a clear statement of the intended risk reduction or result.
Evidence and follow-up depth should be proportionate to risk; high-risk actions may require reperformance, inspection or data testing.
Partial, alternative, overdue and risk-accepted actions require transparent assessment and escalation under the relevant governance process.
Closure should record the evidence, evaluator, date, residual risk and basis for the conclusion.
6.4 Following Up Findings & Recommendations
An audit recommendation has little value if no one determines whether corrective action actually reduced the identified risk. Annex II therefore names following up findings and recommendations and monitoring implementation as part of audit execution.
Follow-up is not a new audit of everything. It is a focused assessment of management's response to the condition, cause, effect and risk documented in the original finding.
Design recommendations for follow-up
A followable recommendation identifies the outcome needed without unnecessarily prescribing management's exact design. Record:
- the finding and risk it addresses;
- the agreed action or management response;
- the responsible owner;
- the target date and priority;
- expected evidence or success indicator; and
- any governance body responsible for accepting residual risk.
Vague wording such as “strengthen controls” makes closure subjective. A stronger result statement might require that privileged access be approved, periodically reviewed and promptly removed, with retained evidence.
Maintain a reliable action register
The register should link each action to the final report, owner, due date, risk rating, status, evidence and follow-up conclusion. Protect it against unauthorised alteration and preserve an audit trail of revised dates or actions.
Management owns implementation and should update status. Audit owns the independent assessment of whether the response is adequate. A self-reported “complete” status is evidence to evaluate, not the closure decision.
Plan risk-based follow-up
Set timing and depth according to significance. A low-risk documentation issue may be checked through a revised procedure and a small sample. A critical access-control finding may require configuration inspection, user-list analysis, reperformance of periodic reviews and testing that terminated users were removed promptly.
Consider urgency, implementation complexity, dependency on a larger project and whether delay extends exposure. Combine follow-up work when several recommendations depend on the same system or governance change, but preserve a conclusion for each action.
Evaluate implementation
Use sufficient, relevant evidence. Common procedures include document inspection, inquiry corroborated by records, observation, reperformance, data analysis and limited transaction testing. Ask two separate questions:
- Was the agreed or alternative action implemented as represented?
- Does it address the original risk to an acceptable degree?
An action can be implemented but ineffective. For example, management may issue procurement guidance yet leave the approval workflow unchanged and show continued non-compliance. Conversely, management may choose a different control that addresses the risk more efficiently. Evaluate substance, not wording identity.
Status conclusions
Use clear categories defined by the organisation, such as open, in progress, implemented, partly implemented, superseded or risk accepted. Avoid “closed” as a convenience for old items. For partial implementation, state what is complete, what remains and the residual exposure.
If management proposes risk acceptance, confirm that the authorised level understands the nature and consequence of the exposure. The audit function does not assume management's responsibility by accepting the risk itself. Where residual risk appears outside appetite or authority, escalate through the applicable governance channel.
Overdue actions require more than reminders. Reassess risk, obtain a revised plan where justified, and report persistent delay or repeated extensions. Do not reset the original due date without preserving the history.
Report and close
Periodic reporting should highlight high-risk overdue actions, recurring themes, disputed conclusions and systemic dependencies. Avoid reporting only completion percentages: ten closed low-risk actions can obscure one critical unresolved weakness.
A closure record should identify the evidence reviewed, procedures performed, evaluator, date, conclusion and residual risk. If follow-up reveals a materially different issue, consider separate audit work rather than silently expanding the original recommendation.
Validate the completeness of the action population as well as individual statuses. Reconcile the register to issued reports, agreed management responses and governance minutes so that omitted or renumbered actions cannot disappear from monitoring. Where one recommendation contains several commitments, define whether each component must be complete before closure; avoid using an average completion percentage that conceals an unresolved critical element.
Mini-case
An audit found that terminated contractors retained application access. Management marks the action complete after issuing a policy requiring same-day removal. Follow-up compares HR termination records with access logs, identifies two late removals and finds that the systems are not integrated. The policy exists, but the control is not operating consistently. The appropriate conclusion is partial implementation, with the residual exposure and required next step reported—not closure based on the policy document alone.
What is the central objective of recommendation follow-up?
To determine whether action was implemented and adequately addressed the original risk
To count management emails
To rewrite the original report
To transfer implementation responsibility to audit
Why is management’s “complete” status insufficient by itself?
Management may never provide evidence
It is a representation that audit must evaluate with evidence proportionate to risk
Audit must reject every management statement
Only external regulators may close actions
A new control was installed, but testing shows the original risk remains material. What is the best conclusion?
Close because an action occurred
Delete the finding
Do not close; describe the ineffective or partial result and residual risk
Change the original due date retroactively
Who should formally accept residual operational risk?
The junior auditor
The external data provider
The audit tool owner
Management or governance at the level authorised by the organisation
Sections you finish are checked off in the contents.