Developing Recommendations in Internal Audit: A Complete CIA Part 3 Guide to Engagement Results and Monitoring
Developing Recommendations: CIA Exam Guide
Introduction
Developing recommendations is one of the most visible and valuable parts of an internal audit engagement. After auditors identify findings, they must suggest practical actions that fix control weaknesses, reduce risk and improve governance and operations. In the CIA syllabus this topic sits within Engagement Results and Monitoring. It ties directly to the IIA's International Professional Practices Framework (IPPF), especially the standards on communicating results and monitoring progress.
Why Developing Recommendations Is Important
1. Adds value to the organization: The IIA defines internal auditing as an activity designed to add value and improve operations. Recommendations are the main way findings become improvements.
2. Addresses root causes: A good recommendation fixes the underlying cause of a problem, not just its symptoms. This prevents the issue from coming back.
3. Supports management decisions: Recommendations give management a clear, risk-based path to strengthen controls, governance and risk management.
4. Builds credibility: Practical, cost-effective recommendations build trust between internal audit and the business. Unrealistic ones damage it.
5. Enables monitoring: Clear, specific recommendations make it possible to track whether action plans are carried out. This links to the requirement that the chief audit executive (CAE) maintain a follow-up process.
6. Meets professional standards: The Standards require that final engagement communications include applicable conclusions, recommendations and/or action plans.
What Developing Recommendations Is
A recommendation is a proposed course of action that addresses the gap between the condition (what is) and the criteria (what should be).
Every audit finding has five classic attributes:
- Criteria: the standard, policy, regulation or expectation used for evaluation.
- Condition: the factual evidence of what the auditor found.
- Cause: the reason the difference exists. This is the root cause.
- Effect (Consequence): the risk or exposure that results from the difference.
- Recommendation: the corrective action, sometimes shown alongside management's action plan.
Recommendations should flow logically from the cause. If the cause is weak training, the fix should target training, not simply more reviews. Recommendations can also highlight opportunities for improvement, including satisfactory performance that can be strengthened or shared as good practice.
How It Works: The Process
Step 1: Confirm the finding. Make sure the evidence is sufficient, reliable, relevant and useful. Recommendations built on weak evidence lose credibility.
Step 2: Perform root cause analysis. Common tools include:
- The 5 Whys
- Fishbone (Ishikawa) diagrams
- Process mapping
Ask whether the cause is related to people, process, technology, governance or external factors.
Step 3: Assess significance and risk. Weigh the effect in terms of likelihood and impact, including financial, operational, compliance, reputational and strategic risk. This drives prioritization and ratings such as high, medium or low.
Step 4: Identify alternative solutions. Consider several options, such as:
- Preventive versus detective controls
- Manual versus automated controls
- Policy changes, training or system changes
Step 5: Evaluate cost versus benefit. The cost of a control should not exceed the expected benefit. Internal auditors aim for reasonable, not absolute, assurance.
Step 6: Draft SMART recommendations. Effective recommendations are:
- Specific
- Measurable
- Achievable
- Relevant
- Time-bound
Recommendations should say what needs to be achieved. They should generally not dictate exactly how management must do it, because management owns the controls.
Step 7: Discuss with management. The Standards encourage discussing conclusions and recommendations with appropriate management before issuing final results. This:
- Confirms facts
- Improves feasibility
- Secures buy-in
- Lets management develop action plans, with owners and target dates
Step 8: Communicate in the final report. Include recommendations, management responses and agreed action plans. Communications must be accurate, objective, clear, concise, constructive, complete and timely.
Step 9: Monitor and follow up. The CAE must establish and maintain a system to monitor how results communicated to management are handled. If management accepts a level of risk the CAE believes may be unacceptable, the CAE must:
- First discuss the matter with senior management
- Then, if it remains unresolved, communicate it to the board
Key Principles to Remember
- Management owns the risk and the remediation. Internal audit recommends; management decides and implements. Auditors who design and implement controls may impair their objectivity.
- Objectivity and independence: If an auditor later reviews a control they recommended, they should be aware of possible threats to objectivity.
- Consulting engagements: Recommendations are shaped by the scope agreed with the client. Follow-up is done as agreed with the client.
- Positive language: Constructive tone encourages acceptance. Avoid blame and focus on processes, not individuals.
- Prioritization: Rank recommendations by risk so management focuses resources on the most significant exposures.
- Disagreements: If management disagrees, report both positions and the reasons in the engagement communication.
Examples
Weak recommendation: Management should improve controls over vendor payments.
Strong recommendation: Management should implement an automated three-way match (purchase order, receiving report, invoice) in the ERP system. Exceptions above $5,000 should be reviewed by the AP supervisor before payment, with implementation by Q3. This addresses the root cause of manual matching errors identified in 12% of sampled payments.
Exam Tips: Answering Questions on Developing Recommendations
1. Link the recommendation to the root cause. When options are offered, choose the one that addresses the cause, not the symptom or condition. A trap answer often fixes the immediate error, such as correcting a single invoice, rather than the process failure.
2. Remember the five attributes. Expect questions asking which attribute a statement represents:
- What should be = criteria
- What is = condition
- Why = cause
- So what = effect
- What to do = recommendation
3. Management is responsible for implementation. Reject answers where internal audit implements the fix, takes ownership of controls or makes management decisions. These impair objectivity.
4. Cost-benefit matters. If an option is costly relative to the risk it addresses, it is usually wrong. Look for the most cost-effective control that reduces risk to an acceptable level.
5. Prefer preventive and automated controls when appropriate. These are generally more reliable. Still, consider the cost-benefit and context given in the question.
6. Discuss before finalizing. If asked what the auditor should do before issuing the final report, the best answer usually involves discussing findings and recommendations with management.
7. Know the escalation path for risk acceptance. When management accepts unacceptable risk, the CAE discusses it with senior management first. If unresolved, the CAE goes to the board. The CAE does not force remediation.
8. Follow-up is the CAE's responsibility. The CAE establishes the monitoring and follow-up process. The nature, timing and extent of follow-up depend on:
- The significance of the finding
- The effort and cost of correction
- The impact of failure
- The complexity of the action
- The time period involved
9. Watch for absolute words. Answers that say a recommendation will eliminate all risk or guarantee compliance are usually wrong. Controls give reasonable assurance.
10. Distinguish assurance from consulting. In consulting work, recommendations and follow-up depend on the agreed engagement terms.
11. Read scenario questions carefully. Find the cause in the scenario, such as lack of training, inadequate segregation of duties or outdated policy. Then match it with the targeted remedy.
12. Choose the best answer, not just a correct one. Several options may be reasonable. Pick the one that is the most comprehensive, risk-based, cost-effective and consistent with IIA Standards.
Summary
Developing recommendations turns audit findings into meaningful improvement. Effective recommendations:
- Rest on solid evidence and root cause analysis
- Are prioritized by risk
- Are cost-effective and SMART
- Are discussed with management, who owns implementation
- Are monitored through the CAE's follow-up process
For the CIA exam, focus on cause-driven solutions, management ownership, cost-benefit thinking, communication standards and the escalation and monitoring responsibilities of the CAE.