Confirming Implementation of Action Plans: A Complete CIA Exam Guide
Overview
Confirming implementation of action plans, often called follow-up or monitoring progress, is the stage after the engagement report is issued. Internal audit checks whether management has actually carried out the corrective actions it agreed to. Without this step, audit findings risk becoming paperwork rather than real improvement. On the CIA exam, this topic sits within Engagement Results and Monitoring and is tested through scenario-based questions about responsibility, timing, methodology and escalation.
Why It Is Important
1. It closes the loop on value creation. Internal audit adds value only when its recommendations reduce risk or improve processes. Follow-up shows whether that happened.
2. It provides assurance to the board. The board and senior management need to know whether significant risks are being addressed on time.
3. It promotes accountability. Management owns the agreed actions. Regular follow-up keeps those commitments visible.
4. It informs risk-based planning. Unresolved issues may raise the risk rating of an area and shape the next audit plan.
5. It is required by the Standards. Under the Global Internal Audit Standards (Standard 15.2, Confirming the Implementation of Recommendations or Action Plans), internal auditors must confirm implementation. Under the legacy IPPF, Standards 2500 and 2500.A1 required the CAE to establish and maintain a follow-up process.
What It Is
Confirming implementation is the process by which internal auditors determine whether management has taken effective, timely action on engagement findings, recommendations or agreed action plans. If management has not acted, the process determines whether senior management has knowingly accepted the risk of inaction.
Key elements:
- Methodology established by the CAE: The CAE sets a documented approach for monitoring and confirming implementation.
- Management responsibility: Management is responsible for implementing actions. Internal audit is responsible for monitoring and confirming them.
- Risk-based approach: How much follow-up is done depends on the significance of the finding.
- Tracking and reporting: Open issues are recorded, updated and reported to senior management and the board.
How It Works
Step 1: Agree on action plans during the engagement.
Final communications include management's responses with specific actions, responsible owners and target dates. Clear action plans make later follow-up measurable.
Step 2: Record the issues in a tracking system.
Findings, owners, due dates and risk ratings are logged in an issues-tracking database or audit management software.
Step 3: Monitor progress.
Internal auditors ask management about progress at set intervals or when due dates arrive. Management may self-report status and provide supporting evidence.
Step 4: Perform follow-up procedures based on risk.
The nature, timing and extent of follow-up depend on several factors:
- the significance of the finding and its risk rating
- the effort and cost needed to correct the condition
- the impact if corrective action fails
- the complexity of the corrective action
- the time period involved
Typical procedures, roughly from least to most rigorous:
- Inquiry of management, usually adequate only for low-risk items
- Review of documentation such as updated policies or reconciliations
- Observation of the new control in operation
- Re-performance or testing to confirm the control is designed and operating effectively
- A full follow-up engagement for high-risk or pervasive issues
Step 5: Evaluate and conclude.
Possible outcomes include:
- Implemented and effective. The issue is closed.
- Partially implemented or in progress. The due date is monitored or revised, with justification.
- Not implemented. The issue is escalated.
- Alternative action taken. The auditor assesses whether the alternative adequately addresses the risk.
- Superseded. Changes such as a new system or a discontinued process make the action unnecessary.
- Risk accepted by management. The acceptance is documented and may need escalation.
Step 6: Escalate and report.
Status of significant open issues is reported periodically to senior management and the board. If the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must:
- first discuss the matter with senior management
- then, if it remains unresolved, communicate it to the board
Internal audit does not itself resolve the risk.
Consulting engagements: Internal audit monitors the outcome of consulting engagements to the extent agreed with the client.
Common Misconceptions
- Internal audit implements the fix. False. Doing so would impair objectivity. Management implements.
- Every finding requires testing. False. Follow-up is risk-based, and inquiry may be enough for minor issues.
- Follow-up is optional if management agreed. False. Agreement is not the same as implementation, and confirmation is required.
- The CAE should go straight to the board. Usually false. The CAE discusses with senior management first, then escalates to the board if needed.
- The external auditor confirms implementation. False. This is the internal audit activity's responsibility under its own methodology.
Exam Tips: Answering Questions on Confirming Implementation of Action Plans
1. Identify who is responsible. If a question asks who implements corrective action, the answer is management. If it asks who establishes the follow-up process, the answer is the CAE. If it asks who monitors or confirms implementation, the answer is the internal auditors.
2. Think risk-based. When asked how much follow-up is appropriate, choose the answer that links effort to significance. High-risk findings call for prompt, rigorous testing, possibly a follow-up engagement. Low-risk findings may need only inquiry or documentation review.
3. Know the escalation sequence. Management fails to act or accepts risk, then the CAE discusses with senior management, then the CAE reports to the board if the risk exceeds risk appetite. Avoid answers where the auditor forces management to act, reports to regulators first, or skips senior management.
4. Prefer evidence over assertion. If a scenario shows an auditor relying only on management's statement for a significant issue, the best answer usually involves obtaining corroborating evidence through testing or observation.
5. Watch for objectivity traps. Options where the auditor designs and installs the control, or takes ownership of the action plan, are usually wrong.
6. Recognize valid reasons to close or skip follow-up. Examples include risk acceptance by appropriate senior management, a superseded process, or a newly scheduled full audit of the area. These are acceptable if documented and, where needed, communicated.
7. Understand the timing. Follow-up normally occurs after target dates pass. For critical issues, it may start sooner. A question asking when to follow up on a serious control weakness usually points to a prompt or earlier review.
8. Link to reporting. Expect the board and senior management to receive periodic status reports on outstanding significant issues. This also feeds into the CAE's overall assessments and future audit planning.
9. Read for keywords. Terms such as most appropriate, first, best and primary responsibility matter. A first step is often inquiry or reviewing the tracking status. The best evidence for a high-risk item is testing.
10. Remember consulting nuance. For consulting engagements, monitoring is performed to the extent agreed upon with the client, not automatically.
Quick Example
Scenario: An audit found that critical system access was not removed for terminated employees. Management agreed to fix it within 60 days. At day 60, management emails that the issue is resolved. What should the internal auditor do?
Best answer: Because the risk is high, obtain evidence, for example by testing a sample of recent terminations against access lists. Accepting the email alone is not sufficient. If the testing shows the issue persists, update the tracking system and escalate according to the methodology.
Summary
Confirming implementation of action plans ensures that audit findings lead to real risk reduction. Management implements, internal audit monitors and confirms, and the CAE sets the methodology and escalates unacceptable risk acceptance, first to senior management and then to the board. On the exam, choose answers that are risk-based, evidence-driven, objectivity-preserving and that follow the correct escalation sequence.