08 Audit Follow-Up and Remediation Tracking
Issuing the audit report does not remove the risk.
A finding remains relevant until management either:
Remediates the Riskor:
Formally Acceptsthe Residual RiskThe purpose of audit follow-up is to determine whether:
Agreed ActionsWere Completedand whether those actions:
Actually Addressedthe FindingA practical remediation lifecycle looks like:
Final Audit Report ↓Finding ↓Management Action Plan ↓Action Owner ↓Target Date ↓Progress Monitoring ↓Remediation Evidence ↓Audit Validation ↓Retesting ↓Residual Risk ↓Close / Keep Open / Reopen ↓Management ReportingLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of audit follow-up.
-
Understand finding lifecycle management.
-
build a remediation tracking process.
-
track management action plans.
-
identify accountable remediation owners.
-
manage remediation due dates.
-
monitor open findings.
-
calculate finding aging.
-
identify overdue remediation.
-
manage remediation extensions.
-
evaluate extension requests.
-
review remediation evidence.
-
distinguish implementation from effectiveness.
-
validate partial remediation.
-
perform audit retesting.
-
evaluate residual risk after remediation.
-
close audit findings.
-
keep findings open when remediation is insufficient.
-
reopen previously closed findings when appropriate.
-
manage risk-accepted findings.
-
identify repeat findings.
-
escalate overdue high-risk actions.
-
develop remediation KPIs and KRIs.
-
build an executive remediation dashboard.
-
maintain audit-trail evidence for closure decisions.
1. What Is Audit Follow-Up?
Section titled “1. What Is Audit Follow-Up?”Audit follow-up is the process used to determine whether management has:
ImplementedAgreed Actionsand reduced the identified risk to an acceptable level.
It connects:
Audit Reportingto:
Risk Reduction2. Why Follow-Up Matters
Section titled “2. Why Follow-Up Matters”Without follow-up:
Audit Finding ↓Report Issued ↓Management Agrees ↓Nothing ChangesA mature process requires:
Finding ↓Owner ↓Action ↓Due Date ↓Evidence ↓Validation ↓Closure3. Audit Follow-Up Objective
Section titled “3. Audit Follow-Up Objective”The auditor should answer:
Was the ActionImplemented?
Was It Implementedas Agreed?
Does It Addressthe Root Cause?
Is the ControlOperating?
Has the RiskBeen Reduced?4. Finding Lifecycle
Section titled “4. Finding Lifecycle”A typical finding lifecycle may use:
Draft
Validated
Open
In Progress
Pending Evidence
Pending Validation
Closed
Risk AcceptedSome organizations may also use:
Overdue
Extended
Reopened5. Create Finding Follow-Up Register
Section titled “5. Create Finding Follow-Up Register”Create:
01 Finding Follow-Up RegisterUse:
| Finding ID | Finding | Severity | Owner | Target Date | Status | Days Open |
|---|
6. Include Action Plans
Section titled “6. Include Action Plans”Extend the register with:
Management Action
Action Owner
Original Due Date
Current Due Date
Progress
Evidence Received
Validation Result
Closure Date7. Original Due Date
Section titled “7. Original Due Date”Always retain:
Original Target Dateeven if the date is later extended.
This preserves:
Remediation History8. Current Due Date
Section titled “8. Current Due Date”Also track:
Current ApprovedDue Dateso users can distinguish:
Original Commitmentfrom:
Approved Extension9. Finding Severity
Section titled “9. Finding Severity”Follow-up priority should consider:
Critical
High
Medium
Low10. Risk-Based Follow-Up
Section titled “10. Risk-Based Follow-Up”Not every finding requires the same level of monitoring.
Example:
Critical
Section titled “Critical”Immediate Monitoring
Frequent Management Updates
Executive Escalation
Interim ControlsMonthly Monitoring
Senior Owner Oversight
Formal ValidationMedium
Section titled “Medium”Periodic MonitoringStandard Follow-Up11. Action Owner
Section titled “11. Action Owner”Each remediation should have:
Accountable OwnerAvoid:
IT TeamPrefer:
Director of Identityand Access Management12. Why Ownership Matters
Section titled “12. Why Ownership Matters”Without clear ownership:
EveryoneIs Responsibleoften becomes:
No OneIs Accountable13. Management Action Plan
Section titled “13. Management Action Plan”A good action plan should explain:
What WillBe Changed?
Who WillDo It?
When?
How WillCompletion Be Demonstrated?14. Weak Action Plan
Section titled “14. Weak Action Plan”IAM WillImprove the Process15. Stronger Action Plan
Section titled “15. Stronger Action Plan”IAM will implementdaily reconciliationbetween HR terminationsand active accounts,with automated escalationfor unmatched records.16. Remediation Milestones
Section titled “16. Remediation Milestones”Large remediation may require intermediate milestones.
Example:
Design
Development
Testing
Pilot
Production
Validation17. Milestone Tracker
Section titled “17. Milestone Tracker”Create:
02 Remediation Milestone TrackerUse:
| Finding | Milestone | Owner | Target | Status |
|---|
18. Progress Status
Section titled “18. Progress Status”Use standardized values:
Not Started
In Progress
At Risk
Completed
Pending Validation19. Avoid “90% Complete” Without Evidence
Section titled “19. Avoid “90% Complete” Without Evidence”Statements such as:
90% Completemay be misleading unless linked to defined milestones.
Prefer:
Configuration Complete
Testing Pending
Production DeploymentScheduled20. Monitor Finding Aging
Section titled “20. Monitor Finding Aging”Finding aging measures:
How Longthe FindingHas Remained Open21. Finding Age
Section titled “21. Finding Age”Conceptually:
Current Date-Finding Open Date=Days Open22. Aging Buckets
Section titled “22. Aging Buckets”Create:
0–30 Days
31–60 Days
61–90 Days
91–180 Days
180+ Days23. Finding Aging Dashboard
Section titled “23. Finding Aging Dashboard”Create:
03 Finding Aging DashboardExample:
| Aging | Findings |
|---|---|
| 0–30 days | 8 |
| 31–60 days | 6 |
| 61–90 days | 4 |
| 91–180 days | 3 |
| 180+ days | 2 |
24. Why Aging Matters
Section titled “24. Why Aging Matters”Compare:
10 High Findingswith:
10 High Findings,8 of WhichAre Over 180 Days OldThe second represents a more serious governance concern.
25. Overdue Finding
Section titled “25. Overdue Finding”A finding becomes overdue when:
Current Date>Approved Due Dateand required remediation is incomplete.
26. Overdue Status
Section titled “26. Overdue Status”Track:
Days Overdueseparately from:
Days Open27. Example
Section titled “27. Example”Finding opened:
1 JanuaryDue:
31 MarchCurrent date:
30 AprilResult:
Days Open:119
Days Overdue:3028. Overdue Findings Require Escalation
Section titled “28. Overdue Findings Require Escalation”Example:
Finding Due ↓Owner Reminder ↓Senior Owner ↓Audit Leadership ↓Executive Management ↓Audit Committeedepending on severity and governance.
29. Escalation Matrix
Section titled “29. Escalation Matrix”Create:
04 Finding Escalation MatrixExample:
| Condition | Escalation |
|---|---|
| Medium finding 30 days overdue | Process Owner |
| High finding overdue | Executive Owner |
| Critical finding overdue | Immediate Executive / Audit Committee |
| Repeat overdue finding | Audit Leadership |
| Expired risk acceptance | Risk Committee |
30. Remediation Extensions
Section titled “30. Remediation Extensions”Sometimes remediation cannot be completed by the original date.
Examples:
Technology Dependency
Budget Approval
Vendor Dependency
Major Migration
Resource Constraint31. Extension Is Not Automatic
Section titled “31. Extension Is Not Automatic”Avoid:
Due Date Approaching ↓Change the DateInstead:
Extension Request ↓Risk Review ↓Justification ↓Interim Controls ↓Approval32. Create Extension Request Record
Section titled “32. Create Extension Request Record”Create:
05 Extension Request RecordInclude:
Finding
Original Due Date
Requested Date
Reason
Work Completed
Remaining Work
Interim Controls
Residual Risk
Approver33. Evaluate Extension Request
Section titled “33. Evaluate Extension Request”Ask:
Why IsExtension Needed?
Could ManagementHave Avoided Delay?
What RiskRemains?
Are Interim ControlsOperating?
Is New DateRealistic?
Who Approvedthe Extension?34. Repeated Extensions
Section titled “34. Repeated Extensions”Multiple extensions may indicate:
Weak Ownership
Insufficient Resources
Poor Planning
Management Risk Acceptanceand may warrant escalation.
35. Retain Extension History
Section titled “35. Retain Extension History”Do not overwrite:
Original Due DateMaintain:
Extension 1
Extension 2
Extension 3for transparency.
36. Remediation Evidence
Section titled “36. Remediation Evidence”Management should submit evidence demonstrating:
Action Completed37. Create Remediation Evidence Tracker
Section titled “37. Create Remediation Evidence Tracker”Create:
06 Remediation Evidence TrackerUse:
| Finding | Evidence ID | Evidence | Received | Validated | Result |
|---|
38. Common Remediation Evidence
Section titled “38. Common Remediation Evidence”Examples:
Updated Policy
Updated Procedure
System Configuration
Implementation Ticket
Training Record
System Report
Logs
Screenshots
Test Results39. Evidence Must Match the Finding
Section titled “39. Evidence Must Match the Finding”Finding:
Admin MFANot EnforcedWeak closure evidence:
Updated MFA PolicyBetter evidence:
MFA Configuration
Admin Population
Exception Analysis40. Policy Change vs Control Change
Section titled “40. Policy Change vs Control Change”A policy update may address:
Documentationbut not necessarily:
Actual Control Operation41. Implementation vs Effectiveness
Section titled “41. Implementation vs Effectiveness”One of the most important follow-up concepts:
Implemented≠Effective42. Example
Section titled “42. Example”Management implements:
New QuarterlyAccess Review ToolAudit should still determine:
Were ReviewsActually Completed?
Were PopulationsComplete?
Were ExceptionsRemoved?43. Closure Validation
Section titled “43. Closure Validation”Create:
07 Closure Validation WorksheetSuggested sections:
Finding
Original Condition
Root Cause
Management Action
Evidence
Validation Procedure
Retest
Residual Risk
Closure Decision44. Closure Validation Questions
Section titled “44. Closure Validation Questions”Ask:
Was the ActionImplemented?
Does It Addressthe Root Cause?
Does the New ControlAddress the Risk?
Has It OperatedLong Enough?
Is EvidenceSufficient?
Does RiskRemain?45. Retesting
Section titled “45. Retesting”Retesting independently evaluates whether remediation:
Operates Effectively46. Create Retesting Workpaper
Section titled “46. Create Retesting Workpaper”Create:
08 Retesting WorkpaperInclude:
Finding
Remediation
Control
Population
Testing Period
Procedure
Evidence
Results
Conclusion47. Retesting Scope
Section titled “47. Retesting Scope”Retesting should focus on:
Affected Control
Root Cause
Population
Risknot necessarily repeat the entire original audit.
48. Example — Termination Finding
Section titled “48. Example — Termination Finding”Original finding:
29 of 420Terminated AccountsExceeded SLAManagement implements:
Daily HR/IAMReconciliationFollow-up testing might:
Review 90 Daysof Terminations
Analyze AllTermination Events
Verify ExceptionsAre Escalated49. Appropriate Operating Period
Section titled “49. Appropriate Operating Period”A new control may need time to operate before effectiveness can be validated.
Example:
Quarterly ControlImplemented Yesterdaymay not yet provide evidence of:
QuarterlyOperating Effectiveness50. Interim Closure
Section titled “50. Interim Closure”Some methodologies may permit:
Implementation CompletePending Operating Validationbut this should not be confused with full closure unless methodology permits it.
51. Partial Remediation
Section titled “51. Partial Remediation”Management may complete:
Somebut not:
Allrequired actions.
Example:
MFA Enabledfor AWS
Not Enabledfor Azure52. Partial Remediation Decision
Section titled “52. Partial Remediation Decision”Possible outcomes:
Keep Finding Open
Reduce Scope
Update Residual Risk
Create Separate Actionaccording to audit methodology.
53. Do Not Close Based on Percentage Complete
Section titled “53. Do Not Close Based on Percentage Complete”Avoid:
90% Remediated=ClosedThe unresolved:
10%may contain the highest-risk exposure.
54. Residual Risk Assessment
Section titled “54. Residual Risk Assessment”After remediation determine:
What RiskStill Remains?55. Residual Risk Flow
Section titled “55. Residual Risk Flow”Original Risk ↓Remediation ↓Control Effectiveness ↓Remaining Gaps ↓Residual Risk56. Example
Section titled “56. Example”Original:
High Riskafter remediation:
MFA Enforcedfor 98%of Admin AccountsRemaining:
2%Service AccountsWithout MFAResidual risk requires separate analysis.
57. Finding Closure
Section titled “57. Finding Closure”A finding may be closed when:
Actions Completed
Root Cause Addressed
Evidence Sufficient
Retesting Successful
Residual Risk Acceptable58. Closure Decision
Section titled “58. Closure Decision”Use:
CLOSEonly when the evidence supports it.
59. Keep Open
Section titled “59. Keep Open”Use:
KEEP OPENwhen:
Action Incomplete
Evidence Insufficient
Retesting Failed
Risk Remains Material60. Closure Note
Section titled “60. Closure Note”Create:
Finding Closure NoteExample:
Internal Audit reviewedthe implemented HR/IAMreconciliation processand analyzed all employeeterminations occurringbetween May and July.
All 218 terminationevents were processedwithin the approved SLA,and no unmatched activeaccounts were identified.
The finding is thereforeclosed.61. Closure Evidence Should Be Traceable
Section titled “61. Closure Evidence Should Be Traceable”Maintain:
Finding ↓Management Action ↓Evidence ↓Retest ↓Closure Decision62. Closure Approval
Section titled “62. Closure Approval”Depending on severity, closure may require:
Auditor
Audit Manager
Head of Internal Auditapproval.
63. Reopen Finding
Section titled “63. Reopen Finding”A previously closed finding may need to be reopened when:
Remediation Reversed
Control Stops Operating
Evidence Was Incorrect
Same Condition RecursSoon After Closure64. Reopened vs Repeat Finding
Section titled “64. Reopened vs Repeat Finding”These concepts may differ.
Reopened
Section titled “Reopened”The original finding was closed but:
Closure Is No LongerConsidered ValidRepeat
Section titled “Repeat”A later audit identifies:
Same or SimilarControl Weaknessagain.
Use methodology-specific definitions.
65. Create Reopened Finding Record
Section titled “65. Create Reopened Finding Record”Create:
09 Reopened Finding RecordInclude:
Original Finding
Closure Date
Reason Reopened
New Evidence
Current Risk
New Action66. Repeat Findings
Section titled “66. Repeat Findings”Repeat findings can indicate:
Ineffective Remediation
Wrong Root Cause
Weak Governance
Unsustainable Control67. Repeat Finding Analysis
Section titled “67. Repeat Finding Analysis”Ask:
Was Previous ActionActually Completed?
Was Closure TestingSufficient?
Did the EnvironmentChange?
Was Root CauseCorrectly Identified?68. Risk Acceptance
Section titled “68. Risk Acceptance”Sometimes management decides not to remediate.
Use:
Risk Acceptanceinstead of falsely treating:
Findingas Remediated69. Risk Acceptance Tracker
Section titled “69. Risk Acceptance Tracker”Create:
10 Risk Acceptance TrackerUse:
| Finding | Severity | Risk Owner | Approval | Expiry | Status |
|---|
70. Risk Acceptance Requirements
Section titled “70. Risk Acceptance Requirements”Verify:
Correct Authority
Documented Rationale
Residual Risk
Compensating Controls
Review Date / Expiry71. Audit Finding vs Risk Acceptance
Section titled “71. Audit Finding vs Risk Acceptance”A risk-accepted finding may remain:
Closed forRemediation Trackingor:
Tracked Separatelydepending on methodology.
Do not erase the historical finding.
72. Expired Risk Acceptance
Section titled “72. Expired Risk Acceptance”At expiry:
Risk Acceptance ↓Reassess ↓Remediate / Renew / Escalate73. Do Not Automatically Renew
Section titled “73. Do Not Automatically Renew”Require:
Current Risk Review
Business Justification
Updated Approval74. Management Certification
Section titled “74. Management Certification”Some organizations ask management to periodically certify:
Action Status
Risk Exposure
CompletionThis supports governance but does not replace audit validation.
75. Evidence Submission Workflow
Section titled “75. Evidence Submission Workflow”ManagementSubmits Evidence ↓Audit Logs Receipt ↓Evidence Review ↓Sufficient? │ ┌──┴──┐ No Yes ↓ ↓Request RetestMore76. Evidence Rejection
Section titled “76. Evidence Rejection”Evidence may be rejected when:
Wrong Period
Wrong System
Incomplete
Not Relevant
Unsupported Screenshot
Policy Only
No Operating Evidence77. Communicate Evidence Gaps Clearly
Section titled “77. Communicate Evidence Gaps Clearly”Example:
The submitted proceduredemonstrates that thenew process was documented,but it does not demonstratethat the control hasoperated.
Please provide completedreview evidence for theperiod following implementation.78. Remediation Quality
Section titled “78. Remediation Quality”Strong remediation should:
Address Root Cause
Reduce Risk
Be Sustainable
Have Ownership
Produce Evidence
Be Monitorable79. Weak Remediation
Section titled “79. Weak Remediation”Finding:
Access ReviewsFrequently MissedWeak action:
Remind Managersto Complete Reviews80. Stronger Remediation
Section titled “80. Stronger Remediation”Automated Review Workflow
Reminders
Escalation
Completion Monitoring
Exception Tracking81. Sustainable Remediation
Section titled “81. Sustainable Remediation”Ask:
Will This ControlStill WorkNext Year?not just:
Did ManagementFix Today's Issue?82. Compensating Controls During Remediation
Section titled “82. Compensating Controls During Remediation”If permanent remediation will take time:
Permanent Fix ↓Months Awayconsider interim:
Compensating Controls83. Example
Section titled “83. Example”Permanent remediation:
AutomatedTermination Integrationtakes six months.
Interim:
Daily ManualHR/IAM Reconciliation84. Validate Interim Controls
Section titled “84. Validate Interim Controls”Audit should determine whether interim controls:
Address the Risk
Operate Consistently
Have Evidence85. High-Risk Open Findings
Section titled “85. High-Risk Open Findings”Maintain specific oversight for:
Critical
High
Repeat
Overduefindings.
86. High-Risk Finding Register
Section titled “86. High-Risk Finding Register”Create:
11 High-Risk Finding RegisterUse:
| Finding | Severity | Owner | Due | Days Overdue | Escalation |
|---|
87. Executive Reporting
Section titled “87. Executive Reporting”Executives should understand:
How ManyHigh-Risk FindingsRemain Open?
Which Are Overdue?
Which Are Repeated?
Who Owns Them?
Why Are TheyStill Open?
What DecisionIs Required?88. Executive Remediation Dashboard
Section titled “88. Executive Remediation Dashboard”Create:
12 Executive Remediation DashboardRecommended metrics:
Open Findings
Critical Findings
High Findings
Overdue Findings
Repeat Findings
Average Age
Oldest Finding
Extensions
Risk Acceptances
Closures89. Dashboard Example
Section titled “89. Dashboard Example”| Metric | Result |
|---|---|
| Open findings | 28 |
| Critical | 1 |
| High | 6 |
| Overdue | 8 |
| 180+ days old | 4 |
| Repeat findings | 3 |
| Risk accepted | 2 |
| Closed this quarter | 12 |
90. KPI — Finding Closure Within SLA
Section titled “90. KPI — Finding Closure Within SLA”Findings ClosedWithin Due Date──────────────── × 100Findings Due91. KPI — On-Time High-Risk Remediation
Section titled “91. KPI — On-Time High-Risk Remediation”High FindingsClosed on Time────────────── × 100High Findings Due92. KPI — Closure Validation Timeliness
Section titled “92. KPI — Closure Validation Timeliness”Closure ReviewsCompleted Within SLA──────────────────── × 100Closure Reviews Due93. KPI — Remediation Evidence Quality
Section titled “93. KPI — Remediation Evidence Quality”Possible metric:
Evidence SubmissionsAccepted First Time─────────────────── × 100Evidence SubmissionsUse carefully; it measures process quality rather than risk directly.
94. KRI — Overdue High Findings
Section titled “94. KRI — Overdue High Findings”High FindingsPast ApprovedRemediation Date95. KRI — Critical Findings Open
Section titled “95. KRI — Critical Findings Open”Target may be:
0depending on risk appetite.
96. KRI — Repeat Findings
Section titled “96. KRI — Repeat Findings”Repeat FindingsIdentified DuringCurrent Period97. KRI — Aging Findings
Section titled “97. KRI — Aging Findings”Track:
High FindingsOpen >180 Days98. KRI — Excessive Extensions
Section titled “98. KRI — Excessive Extensions”Track:
Findings With2+ Extensions99. KRI — Expired Risk Acceptances
Section titled “99. KRI — Expired Risk Acceptances”Target:
0100. Trend Reporting
Section titled “100. Trend Reporting”Compare:
Previous Quarterwith:
Current QuarterExample:
| Metric | Previous | Current | Trend |
|---|---|---|---|
| Open High Findings | 4 | 7 | ↑ |
| Overdue Findings | 3 | 8 | ↑ |
| 180+ Day Findings | 1 | 4 | ↑ |
| Repeat Findings | 1 | 3 | ↑ |
This indicates:
DeterioratingRemediation Performance101. Root Cause of Remediation Delays
Section titled “101. Root Cause of Remediation Delays”If findings repeatedly become overdue, ask:
Why?Possible program-level causes:
Weak Accountability
No Executive Oversight
Resource Constraints
Poor Action Planning
Technology Dependency
Unrealistic Due Dates
Low Risk Ownership102. Systemic Remediation Issue
Section titled “102. Systemic Remediation Issue”If many findings remain overdue across teams:
Individual Finding Delay ↓Common Pattern ↓Governance WeaknessThis may itself become an audit or risk theme.
103. Audit Committee Reporting
Section titled “103. Audit Committee Reporting”Audit Committee reporting may include:
Critical Open Findings
Overdue High Findings
Repeat Findings
Management Extensions
Risk Acceptances
Major Closure Activity
Escalations104. Long-Running Findings
Section titled “104. Long-Running Findings”A finding open for:
2 Yearsshould trigger questions such as:
Is ManagementActually Remediating?
Has RiskBeen Accepted?
Is Due DateStill Meaningful?
Should IssueBe Escalated?105. Finding Closure Does Not Erase History
Section titled “105. Finding Closure Does Not Erase History”Retain:
Original Finding
Evidence
Actions
Extensions
Closure Workfor future:
Audit
Regulatory Review
Trend Analysis
Repeat Finding Analysis106. Historical Finding Repository
Section titled “106. Historical Finding Repository”Maintain:
Open
Closed
Risk Accepted
Reopenedfindings in an authoritative repository.
107. Audit Trail
Section titled “107. Audit Trail”A reviewer should be able to trace:
Original Finding ↓Management Response ↓Actions ↓Progress Updates ↓Extensions ↓Evidence ↓Retesting ↓Closure Decision108. Quality Assurance
Section titled “108. Quality Assurance”Audit management should review significant closure decisions.
Questions:
Was EvidenceSufficient?
Was RetestingAppropriate?
Was Operating PeriodSufficient?
Was Root CauseAddressed?
Is ClosureDefensible?109. Example — MFA Finding
Section titled “109. Example — MFA Finding”Original condition:
7 of 250Privileged AccountsWithout MFAManagement action:
Enforce MFAThrough ConditionalAccessEvidence:
Policy Configuration
Admin Population
MFA Status ExportRetest:
250 Accounts
250 ProtectedConclusion:
Close110. Example — Quarterly Review Finding
Section titled “110. Example — Quarterly Review Finding”Original:
2 of 4 ReviewsNot CompletedManagement action:
Automated QuarterlyReview WorkflowEvidence received immediately after implementation.
Question:
Can AuditValidate OperatingEffectiveness Yet?Possibly not.
The control may need to operate through an appropriate review cycle first.
111. Example — Cloud Logging
Section titled “111. Example — Cloud Logging”Original:
4 of 100Cloud AccountsWithout LoggingRemediation:
Enable Loggingon the 4 AccountsBut root cause was:
New AccountsNot AutomaticallyEnrolledAudit should ask:
Will FutureAccounts StillBe Missed?If yes:
Root CauseNot Addressedfinding should remain open.
112. Example — Vendor Assessments
Section titled “112. Example — Vendor Assessments”Original:
6 of 50Tier 1 VendorsWithout CurrentAssessmentManagement completes the six assessments.
But:
No ReconciliationControl ImplementedPotential conclusion:
Immediate ConditionCorrected
Underlying Root CauseNot Remediated113. Example — Vulnerability Finding
Section titled “113. Example — Vulnerability Finding”Original:
8 CriticalVulnerabilitiesPast SLAWithout ExceptionManagement patches all eight.
Audit should also validate:
Why They BecameOverdue
Whether PatchGovernance Improved
Whether SimilarCritical VulnerabilitiesRemain Overdue114. Example — Risk Acceptance
Section titled “114. Example — Risk Acceptance”Finding:
Legacy ApplicationDoes Not Support MFAManagement plans replacement in:
12 MonthsRisk acceptance requires:
Appropriate Owner
Compensating Controls
Expiry
Migration Plan
Periodic Review115. Practical Follow-Up Workflow
Section titled “115. Practical Follow-Up Workflow”Finding Due Soon ↓Request Status ↓Management Update ↓Completed? │ ┌────┴────┐No Yes↓ ↓At Risk? Request Evidence│ ↓├─ No → Monitor│└─ Yes → Escalate ↓ Evidence Sufficient? │ ┌────┴────┐ No Yes ↓ ↓ Request More Retest ↓ Effective? │ ┌────┴────┐ No Yes ↓ ↓ Keep Open Close116. Finding Follow-Up Checklist
Section titled “116. Finding Follow-Up Checklist”Finding Setup
Section titled “Finding Setup”-
final finding recorded.
-
severity recorded.
-
owner assigned.
-
action plan recorded.
-
original due date recorded.
-
required closure evidence defined.
Monitoring
Section titled “Monitoring”-
status updates obtained.
-
milestones tracked.
-
days open calculated.
-
days overdue calculated.
-
high-risk findings prioritized.
-
repeat findings flagged.
Extensions
Section titled “Extensions”-
extension formally requested.
-
justification reviewed.
-
remaining risk evaluated.
-
interim controls reviewed.
-
new date assessed.
-
approval documented.
-
original date retained.
Evidence
Section titled “Evidence”-
evidence submitted.
-
evidence logged.
-
scope validated.
-
period validated.
-
implementation validated.
-
operating evidence obtained where necessary.
Retesting
Section titled “Retesting”-
retesting procedure defined.
-
population identified.
-
period appropriate.
-
evidence sufficient.
-
control effectiveness evaluated.
-
residual risk assessed.
Closure
Section titled “Closure”-
root cause addressed.
-
agreed actions completed.
-
retesting passed.
-
unresolved scope understood.
-
residual risk acceptable.
-
closure note completed.
-
approval obtained.
Risk Acceptance
Section titled “Risk Acceptance”-
accepting authority valid.
-
risk documented.
-
compensating controls documented.
-
expiry established.
-
future review scheduled.
Reporting
Section titled “Reporting”-
open findings reported.
-
overdue findings reported.
-
aging reported.
-
repeat findings reported.
-
extensions reported.
-
risk acceptances reported.
-
significant closures reported.
Audit Follow-Up Deliverables
Section titled “Audit Follow-Up Deliverables”At completion, you should be able to create:
01 Finding Follow-Up Register
02 Remediation Milestone Tracker
03 Finding Aging Dashboard
04 Finding Escalation Matrix
05 Extension Request Record
06 Remediation Evidence Tracker
07 Closure Validation Worksheet
08 Retesting Workpaper
09 Reopened Finding Record
10 Risk Acceptance Tracker
11 High-Risk Finding Register
12 Executive Remediation DashboardPractical Activity — Termination Finding
Section titled “Practical Activity — Termination Finding”Original finding:
29 of 420Termination AccountsExceeded SLASeverity:
HighAction:
Implement DailyHR/IAM ReconciliationManagement says:
CompletedEvidence:
Updated Procedure
Screenshot ofNew DashboardDetermine:
Is EvidenceSufficient?
What OperatingEvidence Is Needed?
What RetestShould Be Performed?
Can the FindingBe Closed?Practical Activity — Cloud Logging
Section titled “Practical Activity — Cloud Logging”Original:
4 Cloud AccountsWithout Audit LoggingManagement enables logging on all four.
However:
No AutomatedEnrollment forNew AccountsDetermine:
Condition Corrected?
Root Cause Corrected?
Risk Reduced?
Close or Keep Open?Practical Activity — Overdue High Finding
Section titled “Practical Activity — Overdue High Finding”Finding:
High SeverityOriginal due date:
30 JuneManagement requests:
31 Decemberbecause of platform migration.
Determine:
Is Six-MonthExtension Reasonable?
What Interim ControlsExist?
What Residual RiskRemains?
Who Should Approve?Practical Activity — Partial Remediation
Section titled “Practical Activity — Partial Remediation”Finding covered:
AWS
Azure
GCPManagement remediates:
AWS
Azurebut not:
GCPDetermine:
Can the FindingBe Closed?
Should SeverityChange?
Should ScopeBe Split?Practical Activity — Repeat Finding
Section titled “Practical Activity — Repeat Finding”2025:
Quarterly AccessReviews MissingClosed after management submitted:
Completed ReviewEvidence2026 audit finds:
Quarterly ReviewsAgain MissingDetermine:
Was PreviousRoot Cause Fixed?
Was ClosureValidation Sufficient?
Is This aRepeat Finding?
What GovernanceIssue May Exist?Practical Activity — Risk Acceptance
Section titled “Practical Activity — Risk Acceptance”Management cannot remediate a:
High-Risk LegacyAuthentication Weaknessfor:
9 MonthsDetermine:
What CompensatingControls Are Needed?
Who CanAccept Risk?
What ExpiryShould Apply?
How Will AuditMonitor It?Common Audit Follow-Up Mistakes
Section titled “Common Audit Follow-Up Mistakes”Mistake 1 — Report Issued, Finding Forgotten
Section titled “Mistake 1 — Report Issued, Finding Forgotten”Audit value is lost without remediation tracking.
Mistake 2 — Due Date Continuously Changed
Section titled “Mistake 2 — Due Date Continuously Changed”Overdue performance becomes invisible.
Mistake 3 — Management Says “Complete” and Finding Is Closed
Section titled “Mistake 3 — Management Says “Complete” and Finding Is Closed”Completion requires evidence and validation.
Mistake 4 — Policy Accepted as Proof of Operation
Section titled “Mistake 4 — Policy Accepted as Proof of Operation”A documented process may never actually operate.
Mistake 5 — Only Original Exceptions Corrected
Section titled “Mistake 5 — Only Original Exceptions Corrected”Root cause remains.
Mistake 6 — Partial Remediation Treated as Complete
Section titled “Mistake 6 — Partial Remediation Treated as Complete”Unresolved high-risk exposure may remain.
Mistake 7 — New Control Tested Too Early
Section titled “Mistake 7 — New Control Tested Too Early”There may be insufficient operating history.
Mistake 8 — Extensions Approved Without Risk Review
Section titled “Mistake 8 — Extensions Approved Without Risk Review”The organization may unknowingly continue carrying unacceptable risk.
Mistake 9 — Interim Controls Not Tested
Section titled “Mistake 9 — Interim Controls Not Tested”Temporary controls may not actually reduce risk.
Mistake 10 — Risk Acceptance Used to Avoid Remediation Governance
Section titled “Mistake 10 — Risk Acceptance Used to Avoid Remediation Governance”Acceptance requires appropriate authority and documentation.
Mistake 11 — Finding Closed Without Residual-Risk Assessment
Section titled “Mistake 11 — Finding Closed Without Residual-Risk Assessment”Remaining exposure may be ignored.
Mistake 12 — Repeat Findings Not Identified
Section titled “Mistake 12 — Repeat Findings Not Identified”Management and governance bodies lose visibility into ineffective remediation.
Mistake 13 — Reopened Findings Hidden
Section titled “Mistake 13 — Reopened Findings Hidden”Closure quality issues may not be visible.
Mistake 14 — No Escalation of Overdue High Findings
Section titled “Mistake 14 — No Escalation of Overdue High Findings”Risk remains unresolved without senior visibility.
Mistake 15 — Closure Documentation Is Weak
Section titled “Mistake 15 — Closure Documentation Is Weak”Future auditors cannot determine why the finding was closed.
Weak Remediation Tracking
Section titled “Weak Remediation Tracking”Finding ↓Management SaysFixed ↓CloseStrong Remediation Tracking
Section titled “Strong Remediation Tracking”Finding ↓Root Cause ↓Action Plan ↓Accountable Owner ↓Due Date ↓Progress Monitoring ↓Evidence ↓Validation ↓Retesting ↓Residual Risk ↓Closure Decision ↓Management ReportingGRC Analyst and Audit Follow-Up
Section titled “GRC Analyst and Audit Follow-Up”GRC professionals may support remediation by:
-
maintaining issue registers.
-
tracking corrective actions.
-
coordinating evidence collection.
-
monitoring due dates.
-
identifying overdue actions.
-
coordinating risk acceptance.
-
preparing remediation dashboards.
-
tracking control changes.
-
maintaining risk registers.
-
coordinating with control owners.
-
supporting audit evidence requests.
Internal Audit should still maintain:
Independent Validationwhen closing Internal Audit findings.
Audit Follow-Up Mindset
Section titled “Audit Follow-Up Mindset”For every open finding ask:
What Wasthe Original Risk?
What Wasthe Root Cause?
What Did ManagementAgree to Do?
Who Ownsthe Action?
What Wasthe OriginalDue Date?
Has the DateChanged?
Why?
What RiskStill Exists?
Are Interim ControlsOperating?
What EvidenceShows Completion?
Does the EvidenceMatch the Finding?
Was the ControlActually Implemented?
Has It OperatedLong Enough?
Should WeRetest?
What PopulationShould We Test?
Did RemediationAddress theRoot Cause?
Is the ControlSustainable?
What ResidualRisk Remains?
Should the FindingBe Closed?
Should ItRemain Open?
Should ItBe Escalated?
Is Thisa Repeat Issue?
Can We Defendthe Closure Decisionto Management,Auditors,and Regulators?That is the practical mindset behind professional audit follow-up and remediation tracking.
Key Takeaways
Section titled “Key Takeaways”-
Audit findings remain relevant until risk is remediated or formally accepted.
-
Audit follow-up connects reporting to actual risk reduction.
-
Every finding should have an accountable owner, action plan, and target date.
-
Original due dates should be retained even when extensions are approved.
-
Finding aging and overdue status provide important governance information.
-
Remediation extensions should require justification and risk review.
-
Repeated extensions can indicate weak accountability or ineffective remediation governance.
-
Management’s statement that remediation is complete is not sufficient for closure.
-
Remediation evidence should directly address the original finding.
-
Implementation and operating effectiveness are different concepts.
-
New controls may need an appropriate operating period before effectiveness can be validated.
-
Partial remediation should not automatically result in closure.
-
Audit retesting should focus on the affected control, root cause, and risk.
-
Findings should close only when corrective actions are complete and residual risk is acceptable.
-
Root causes must be addressed, not only individual exceptions.
-
Previously closed findings may need to be reopened if remediation is later found ineffective.
-
Repeat findings often indicate ineffective corrective action or weak governance.
-
Risk acceptance should follow formal authorization and should not erase finding history.
-
Expired risk acceptances should trigger reassessment.
-
High-risk and overdue findings require proportionate escalation.
-
Executive reporting should highlight aging, overdue, repeat, and high-risk findings.
-
Closure decisions should be supported by traceable evidence and review.
-
Strong remediation tracking demonstrates whether Internal Audit is producing lasting risk reduction.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is audit follow-up?
-
Why is remediation tracking important?
-
What information should a Finding Follow-Up Register contain?
-
Why should the original remediation due date be retained?
-
What is finding aging?
-
What is the difference between days open and days overdue?
-
Why should high-risk overdue findings be escalated?
-
What is a remediation extension?
-
What should be evaluated before approving an extension?
-
Why are repeated extensions a governance concern?
-
What is remediation evidence?
-
Why does an updated policy not necessarily prove remediation?
-
What is the difference between implementation and effectiveness?
-
What is closure validation?
-
What is audit retesting?
-
Why might a newly implemented quarterly control not be ready for effectiveness testing?
-
What is partial remediation?
-
Why should a finding not close based on percentage completion?
-
What is residual risk after remediation?
-
What criteria should generally be met before closing a finding?
-
When should a finding remain open?
-
What is a reopened finding?
-
What is the difference between a reopened and repeat finding?
-
Why are repeat findings significant?
-
How should risk-accepted findings be managed?
-
Why should risk acceptance have an expiry or review date?
-
What are useful remediation KPIs?
-
What are useful remediation KRIs?
-
What should executives see in a remediation dashboard?
-
What evidence makes a finding-closure decision defensible?
What’s Next?
Section titled “What’s Next?”➡️ Next: 09 — Compliance Assessments
In the next lesson, you will move from Internal Audit into structured compliance-assessment activities used to determine whether an organization meets applicable regulatory, contractual, framework, and internal requirements.
You will work through:
Compliance Requirement ↓Applicability ↓Control Mapping ↓Evidence Requirement ↓Assessment Procedure ↓Evidence Review ↓Compliant / Partial / Non-Compliant ↓Gap ↓Remediation ↓Attestation / ReportingYou will learn how to perform requirement interpretation, applicability analysis, control mapping, evidence collection, assessment testing, compliance scoring, gap analysis, remediation tracking, readiness assessments, certification preparation, and compliance reporting.
You will also build practical artifacts including a Compliance Requirements Register, Applicability Matrix, Compliance Control Matrix, Evidence Request List, Compliance Assessment Workbook, Gap Register, Remediation Tracker, Compliance Dashboard, and Final Compliance Assessment Report.