6.4 Following Up Findings & Recommendations

Key Takeaways

  • Follow-up determines whether agreed action addresses the risk behind a finding, not merely whether management reports an action as complete.

  • Recommendations need a responsible owner, target date, priority and a clear statement of the intended risk reduction or result.

  • Evidence and follow-up depth should be proportionate to risk; high-risk actions may require reperformance, inspection or data testing.

  • Partial, alternative, overdue and risk-accepted actions require transparent assessment and escalation under the relevant governance process.

  • Closure should record the evidence, evaluator, date, residual risk and basis for the conclusion.

Last updated: October 2026

6.4 Following Up Findings & Recommendations

An audit recommendation has little value if no one determines whether corrective action actually reduced the identified risk. Annex II therefore names following up findings and recommendations and monitoring implementation as part of audit execution.

Follow-up is not a new audit of everything. It is a focused assessment of management's response to the condition, cause, effect and risk documented in the original finding.

Design recommendations for follow-up

A followable recommendation identifies the outcome needed without unnecessarily prescribing management's exact design. Record:

  • the finding and risk it addresses;
  • the agreed action or management response;
  • the responsible owner;
  • the target date and priority;
  • expected evidence or success indicator; and
  • any governance body responsible for accepting residual risk.

Vague wording such as “strengthen controls” makes closure subjective. A stronger result statement might require that privileged access be approved, periodically reviewed and promptly removed, with retained evidence.

Maintain a reliable action register

The register should link each action to the final report, owner, due date, risk rating, status, evidence and follow-up conclusion. Protect it against unauthorised alteration and preserve an audit trail of revised dates or actions.

Management owns implementation and should update status. Audit owns the independent assessment of whether the response is adequate. A self-reported “complete” status is evidence to evaluate, not the closure decision.

Plan risk-based follow-up

Set timing and depth according to significance. A low-risk documentation issue may be checked through a revised procedure and a small sample. A critical access-control finding may require configuration inspection, user-list analysis, reperformance of periodic reviews and testing that terminated users were removed promptly.

Consider urgency, implementation complexity, dependency on a larger project and whether delay extends exposure. Combine follow-up work when several recommendations depend on the same system or governance change, but preserve a conclusion for each action.

Evaluate implementation

Use sufficient, relevant evidence. Common procedures include document inspection, inquiry corroborated by records, observation, reperformance, data analysis and limited transaction testing. Ask two separate questions:

  1. Was the agreed or alternative action implemented as represented?
  2. Does it address the original risk to an acceptable degree?

An action can be implemented but ineffective. For example, management may issue procurement guidance yet leave the approval workflow unchanged and show continued non-compliance. Conversely, management may choose a different control that addresses the risk more efficiently. Evaluate substance, not wording identity.

Status conclusions

Use clear categories defined by the organisation, such as open, in progress, implemented, partly implemented, superseded or risk accepted. Avoid “closed” as a convenience for old items. For partial implementation, state what is complete, what remains and the residual exposure.

If management proposes risk acceptance, confirm that the authorised level understands the nature and consequence of the exposure. The audit function does not assume management's responsibility by accepting the risk itself. Where residual risk appears outside appetite or authority, escalate through the applicable governance channel.

Overdue actions require more than reminders. Reassess risk, obtain a revised plan where justified, and report persistent delay or repeated extensions. Do not reset the original due date without preserving the history.

Report and close

Periodic reporting should highlight high-risk overdue actions, recurring themes, disputed conclusions and systemic dependencies. Avoid reporting only completion percentages: ten closed low-risk actions can obscure one critical unresolved weakness.

A closure record should identify the evidence reviewed, procedures performed, evaluator, date, conclusion and residual risk. If follow-up reveals a materially different issue, consider separate audit work rather than silently expanding the original recommendation.

Validate the completeness of the action population as well as individual statuses. Reconcile the register to issued reports, agreed management responses and governance minutes so that omitted or renumbered actions cannot disappear from monitoring. Where one recommendation contains several commitments, define whether each component must be complete before closure; avoid using an average completion percentage that conceals an unresolved critical element.

Mini-case

An audit found that terminated contractors retained application access. Management marks the action complete after issuing a policy requiring same-day removal. Follow-up compares HR termination records with access logs, identifies two late removals and finds that the systems are not integrated. The policy exists, but the control is not operating consistently. The appropriate conclusion is partial implementation, with the residual exposure and required next step reported—not closure based on the policy document alone.

Loading diagram...
Recommendation Follow-Up Logic
Test Your Knowledge

What is the central objective of recommendation follow-up?

A

To determine whether action was implemented and adequately addressed the original risk

B

To count management emails

C

To rewrite the original report

D

To transfer implementation responsibility to audit

Test Your Knowledge

Why is management’s “complete” status insufficient by itself?

A

Management may never provide evidence

B

It is a representation that audit must evaluate with evidence proportionate to risk

C

Audit must reject every management statement

D

Only external regulators may close actions

Test Your Knowledge

A new control was installed, but testing shows the original risk remains material. What is the best conclusion?

A

Close because an action occurred

B

Delete the finding

C

Do not close; describe the ineffective or partial result and residual risk

D

Change the original due date retroactively

Test Your Knowledge

Who should formally accept residual operational risk?

A

The junior auditor

B

The external data provider

C

The audit tool owner

D

Management or governance at the level authorised by the organisation

Sections you finish are checked off in the contents.