Escalation When Action Plans Are Not Implemented
Escalation when action plans are not implemented is the structured process internal audit follows when management fails to carry out agreed corrective actions by their due dates. It falls under monitoring and follow-up of engagement results. (Note that in the current CIA syllabus, this topic is typ… Escalation when action plans are not implemented is the structured process internal audit follows when management fails to carry out agreed corrective actions by their due dates. It falls under monitoring and follow-up of engagement results. (Note that in the current CIA syllabus, this topic is typically covered in Part 2.) Under the Global Internal Audit Standards (Standard 15.2) and the earlier IPPF Standards 2500 and 2600, the chief audit executive (CAE) must establish and maintain a system to monitor whether management has effectively implemented action plans. Where risks remain unaddressed, the CAE must also act. The process usually moves in steps. First, internal audit tracks open issues, often in an issue-tracking database, and contacts the responsible process owner as deadlines approach or pass. If the action is overdue, the auditor asks why. Common reasons include resource limits, changed priorities, or disagreement about the risk. Management may propose a revised, reasonable timeline, which is documented. If progress still stalls, the issue is escalated to the owner's superior or to senior management. If the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the matter is not resolved, the CAE must communicate it to the board or audit committee. Internal audit's role is to escalate, not to resolve the risk-acceptance decision itself. Effective escalation relies on several features. It needs clear criteria, such as days overdue, risk rating, or repeated deadline extensions. It needs escalation paths that are defined in the internal audit charter or methodology. It requires objective documentation of follow-up efforts, management responses, and risk implications. Regular reporting of overdue items to the board, often through aging reports, is also expected. High-risk findings call for faster escalation and may trigger a follow-up audit. Escalation protects accountability, supports governance, and preserves internal audit's independence. It ensures that significant risks are not quietly ignored and that the board is informed about risk acceptance decisions.
Escalation When Action Plans Are Not Implemented: CIA Exam Guide
Overview
Internal audit adds value only when its findings lead to real change. Management agrees to action plans to fix the weaknesses auditors identify, but plans are sometimes delayed, partly completed or quietly dropped. Escalation is the structured process internal audit uses to raise unresolved issues to higher levels of authority, ending with the board if necessary. This topic sits within Engagement Results and Monitoring. It is tested through scenario questions that ask what the internal auditor or the chief audit executive (CAE) should do next.
Why It Is Important
1. It closes the assurance loop. An audit finding that is never fixed leaves the organization exposed to the same risk. Without follow-up and escalation, audit reports become paperwork rather than drivers of improvement.
2. It protects governance. The board relies on internal audit to tell it when risks are not being managed. Escalation ensures that unaddressed risks do not stay hidden at the operational level.
3. It enforces accountability. Management owns risk and owns the remediation. Escalation makes that ownership visible.
4. It keeps risk within appetite. When management fails to act, it has in effect accepted the risk, whether or not anyone says so. Escalation forces a conscious decision about whether that risk is acceptable.
5. It supports independence and credibility. A clear, pre-agreed escalation protocol lets auditors raise problems objectively, without personal conflict and without taking over management's role.
What It Is
Escalation is the process of moving an unresolved audit issue up the organization's chain of authority when agreed corrective actions are not completed by the committed date or are not effective.
Key concepts
Follow-up (monitoring): the ongoing process of confirming whether management has implemented recommendations or action plans. Under the Global Internal Audit Standards (2024), Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, requires internal auditors to confirm implementation using an established methodology. This includes:
- asking management about progress;
- performing follow-up assessments using a risk-based approach; and
- updating the status in a tracking system.
Explanation for delays: if management has not met its completion dates, internal auditors must obtain and document management's explanation and discuss the matter with the CAE.
Risk acceptance: Standard 11.5, Communicating the Acceptance of Risks, applies when the CAE concludes that management has accepted a level of risk beyond the organization's risk appetite or tolerance. The CAE must first discuss the matter with senior management. If senior management does not resolve it, the CAE must communicate the matter to the board. Under the legacy IIA Standards, the equivalents were 2500 (Monitoring Progress) and 2600 (Communicating the Acceptance of Risks).
Internal audit charter and methodology: the escalation path, timelines and reporting expectations should be defined in advance, ideally approved by the board and understood by management.
How It Works
Step 1: Agree on action plans with clear ownership. During the engagement, management commits to specific actions. Each action has a named owner and a target date, and these are recorded in the final communication.
Step 2: Track in a monitoring system. Internal audit keeps an action-tracking log or database showing each open item's status, owner, due date and risk rating. Aging reports highlight overdue items.
Step 3: Perform risk-based follow-up. The depth of follow-up matches the significance of the finding:
- Low-risk items may be closed based on management's self-reported status.
- High-risk items usually require testing or evidence review to confirm the action was implemented and works.
Step 4: Identify slippage. When a deadline passes or evidence shows the action is incomplete or ineffective, the auditor contacts the action owner.
Step 5: Obtain and document an explanation. The auditor learns why the action is late, for example resource constraints, changed priorities, a system dependency or disagreement. Management may propose a revised, realistic date. The auditor documents this and informs the CAE.
Step 6: Escalate through the management hierarchy. If the delay continues or is unjustified, the issue moves up the chain:
- action owner;
- owner's manager or business unit head;
- senior management (for example, the CEO or CFO);
- the CAE in direct discussion with senior management.
The goal at each level is resolution: completing the action, revising the plan, or formally accepting the risk.
Step 7: Determine whether risk has been accepted. If management decides not to implement, or keeps delaying indefinitely, the CAE judges whether the remaining risk exceeds the organization's risk appetite.
Step 8: Communicate to the board. If senior management does not resolve a risk the CAE considers beyond appetite, the CAE must report it to the board or audit committee. The board then decides. Many CAEs also give the audit committee regular status reports on open and overdue actions, so the board sees trends even before formal escalation.
Step 9: Close or carry forward. An item is closed when one of the following happens:
- implementation is verified;
- the board or appropriate authority accepts the risk; or
- circumstances make the action no longer relevant.
Persistent issues may also shape future risk assessments and the audit plan.
What internal audit should NOT do
- Implement the corrective action itself. This impairs objectivity and takes on management's responsibility.
- Force management to act. Internal audit has influence and reporting lines, not operational authority.
- Silently close an overdue finding..
- Skip senior management and go straight to the board for routine delays. The usual path is to discuss with senior management first, unless there are special circumstances such as senior management involvement in fraud.
- Report to external parties or regulators unless law, regulation or the charter specifically requires it.
Illustrative Scenario
An audit found weak user-access controls over the payroll system. IT management agreed to remove terminated users within 30 days. At the 90-day follow-up, terminated users are still active.
- The auditor documents IT management's explanation: staff shortages.
- The auditor informs the CAE.
- The CAE raises the issue with the CIO and CFO.
- Senior management says the fix will wait until next year's system upgrade.
- The CAE concludes that the unauthorized-access risk exceeds the organization's tolerance and reports the matter to the audit committee.
- The audit committee decides whether to require faster action or accept the risk.
Exam Tips: Answering Questions on Escalation When Action Plans Are Not Implemented
1. Follow the sequence. Most questions test the correct next step. Remember the order:
- confirm status;
- obtain and document management's explanation;
- inform the CAE;
- CAE discusses with senior management;
- if unresolved, CAE communicates to the board.
Choose the answer that represents the immediate next appropriate step, not the final one.
2. Senior management before the board. If a choice says 'report immediately to the audit committee' and another says 'discuss with senior management,' the senior management option is usually correct. The exceptions are when senior management has already been consulted or is itself the problem.
3. The CAE owns the risk-acceptance judgment. Questions about who decides whether accepted risk is unacceptable and must go to the board point to the CAE, not the staff auditor.
4. Management owns remediation. Eliminate answers where internal audit designs, performs or takes responsibility for corrective action. Internal audit may advise, but implementation belongs to management.
5. The board makes the final call. Internal audit does not resolve disagreements between itself and management. It ensures the board is informed so the board can decide.
6. Follow-up is risk-based. Choices suggesting identical, full re-audits for every item are usually wrong. Expect more rigorous verification for high-risk findings and lighter confirmation for low-risk ones.
7. Documentation matters. Answers involving documenting management's explanation, revised dates, risk acceptance decisions and tracking status are generally aligned with the Standards.
8. Watch for distractors:
- closing the finding because time has passed;
- notifying external auditors or regulators by default;
- refusing to start new engagements until items are fixed;
- reducing the finding's rating to avoid conflict;
- the auditor personally reprimanding management.
9. Recognize implicit risk acceptance. Repeated missed deadlines with no plan is effectively risk acceptance and triggers the Standard 11.5 process, even if management never formally says 'we accept the risk.'
10. Know the terminology. The current Standards are 15.2 (confirming implementation) and 11.5 (communicating the acceptance of risks). Older materials use 2500 and 2600. The concepts are the same, so answer based on principle.
11. Check the charter. If a question mentions the internal audit charter or an agreed escalation protocol, the correct answer often follows that pre-approved process.
12. Read who is acting. Is the question about the staff auditor, the audit manager or the CAE? A staff auditor's correct action is usually to document and inform the CAE, not to contact the board.
Practice Question
Management has repeatedly missed the deadline for an agreed corrective action on a high-risk finding and now says it will not implement the action. The CAE believes the residual risk exceeds the organization's risk appetite. What should the CAE do first?
A. Report the issue directly to the audit committee.
B. Discuss the matter with senior management.
C. Assign internal audit staff to implement the control.
D. Close the finding and note management's decision.
Answer: B. The CAE must first discuss the matter with senior management. If it is not resolved, the CAE then communicates it to the board.
- A is the next step only if the discussion fails.
- C impairs objectivity.
- D ignores a risk that exceeds appetite.
Summary
Escalation keeps audit findings from dying quietly. Internal audit tracks action plans, follows up based on risk, and documents explanations for delays. Unresolved issues move up through management. When management has accepted risk beyond appetite, the CAE discusses it with senior management and, if needed, informs the board. For the exam, remember: management fixes, internal audit monitors and escalates, the board decides.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!