Audit Follow-Up: Tracking Remediation Progress
Learn how to effectively follow up on audit findings and track remediation progress. A critical post-audit responsibility covered on the CISA exam.
Why Follow-Up Matters
The value of an audit is realized only when findings are addressed and controls are improved. Audit follow-up is the process of tracking management's progress in implementing corrective actions agreed upon during the audit. Without effective follow-up, audit findings may go unresolved, and the organization remains exposed to the identified risks. This is a frequently tested topic on the CISA exam.
The Follow-Up Process
A structured follow-up process ensures that remediation activities are tracked to completion:
1. Establish a Tracking Mechanism
Create and maintain a database or tracking system that records all open audit findings. For each finding, track:
- Finding description and risk rating
- Agreed-upon corrective action
- Responsible party (the individual accountable for remediation)
- Target completion date
- Current status (open, in progress, completed, overdue)
- Evidence of remediation
2. Schedule Follow-Up Activities
Determine the appropriate follow-up timeline based on finding severity:
- Critical and high-risk findings: Follow up within 30 to 90 days, depending on the nature of the issue.
- Medium-risk findings: Follow up within 90 to 180 days.
- Low-risk findings: Follow up within the next audit cycle or within one year.
3. Verify Remediation
When management reports that a corrective action is complete, the auditor should verify implementation through:
- Re-testing: Perform the original audit test again to confirm the control now operates effectively.
- Evidence review: Examine documentation, system configurations, or other artifacts that demonstrate the corrective action was implemented.
- Interviews: Discuss changes with relevant personnel to understand what was done and whether the underlying cause was addressed.
4. Report on Follow-Up Status
Regularly report to management and the audit committee on the status of open findings. Reports should highlight:
- Total number of open findings by risk rating
- Aging analysis (how long findings have been open)
- Overdue items and reasons for delays
- Trends in remediation completion rates
Escalation Procedures
When management fails to implement corrective actions within the agreed timeframe, the auditor should follow a defined escalation path:
- First, discuss the delay with the responsible party and understand the reasons.
- If delays continue, escalate to the responsible party's management.
- Persistent delays should be reported to senior management or the audit committee.
- If management formally accepts the risk of not remediating a finding, this acceptance should be documented and reported to the appropriate level of authority.
Risk Acceptance
In some cases, management may decide that the cost of remediation outweighs the benefit or that the risk is acceptable. When management chooses to accept a risk rather than remediate a finding, the auditor should:
- Ensure the decision is made by someone with appropriate authority.
- Document the risk acceptance formally.
- Communicate the accepted risk to the audit committee or board.
- Monitor the risk to determine if conditions change and the acceptance should be reconsidered.
CISA Exam Tips
For the CISA exam, remember that follow-up is a responsibility of the audit function, not optional. The auditor's role is to verify that management's corrective actions actually address the identified risk. Simply confirming that management says an action was taken is not sufficient; the auditor must independently verify the remediation. Also note that management, not the auditor, is responsible for implementing corrective actions and for accepting any residual risk.