Evidence Required to Close a Management Action Plan
Under the IIA Global Internal Audit Standards, closing a management action plan (MAP) means confirming that management has implemented agreed actions and that those actions address the original risk. Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, governs this work.… Under the IIA Global Internal Audit Standards, closing a management action plan (MAP) means confirming that management has implemented agreed actions and that those actions address the original risk. Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, governs this work. Note that in the current CIA syllabus this topic is tested mainly in Part 2 (Practice of Internal Auditing), not Part 3. Management's assertion that an issue is 'fixed' is not enough. The chief audit executive must set up a follow-up process, and auditors must collect evidence that is sufficient, reliable, relevant and useful before closure. The type of evidence depends on the risk and the nature of the action. Common forms include: - Documentation, such as revised policies, approved procedures, updated system configurations, training records and signed reconciliations. - Observation, meaning auditors watch the new control operating. - Reperformance or testing, where auditors sample transactions after implementation to show the control works consistently over a reasonable period, not just once. - Inquiry, used only as supporting evidence because it is the weakest form. - System reports or data analytics showing exceptions have fallen or been eliminated. Auditors should distinguish design (the fix exists) from operating effectiveness (the fix works over time). High-risk findings usually call for independent testing. Low-risk items may be closed with management's documentation and representation. If management has not acted, or has chosen an alternative, auditors judge whether the residual risk is acceptable. If management accepts a risk that may be unacceptable to the organization, the CAE discusses it with senior management. If it remains unresolved, the CAE escalates it to the board (Standard 11.5 and related guidance). Finally, the auditor should: 1. Record the evidence in workpapers. 2. Update the issue-tracking system. 3. Report the closure status to senior management and the board. This cycle provides accountability and supports continuous improvement. It also gives the board assurance that risks have been mitigated.
Evidence Required to Close a Management Action Plan: A Complete CIA Guide
Introduction
Internal audit engagements end with observations and recommendations, but they only add value when the agreed actions are actually carried out. A Management Action Plan (MAP) is management's formal commitment to fix a finding. It names the corrective steps, an owner and a target date.
Closing a MAP is not an administrative formality. Internal audit must obtain sufficient, reliable, relevant and useful evidence that the action was implemented and that it addresses the root cause. This topic appears in CIA exam questions on engagement results and monitoring progress. It is linked to the IIA standards that require the chief audit executive (CAE) to monitor whether management actions are put into practice.
Why It Is Important
1. Assurance integrity: If audit closes actions on management's word alone, the board and senior management get false assurance that risks are mitigated.
2. Standards compliance: The IIA Standards require the CAE to establish and maintain a follow-up process. This process monitors and confirms that management actions have been effectively implemented, or that senior management has accepted the risk of not acting.
3. Accountability: Evidence-based closure holds action owners accountable and discourages superficial fixes.
4. Risk reduction: Only verified remediation actually reduces residual risk. Unverified closure can let the same issue recur, often as a repeat finding.
5. Reporting accuracy: Reports to the audit committee on open, overdue and closed issues depend on reliable closure decisions.
6. Credibility of the audit function: Stakeholders trust audit when closed issues stay closed.
What It Is
Evidence required to close a MAP is the documented proof that internal audit collects and evaluates before marking an action as resolved. The evidence must show three things:
- The agreed action (or an acceptable alternative) was implemented.
- The action is operating effectively over a reasonable period, not just designed.
- The action addresses the underlying condition and root cause of the original finding.
Key attributes of the evidence, consistent with IIA guidance:
- Sufficient: factual, adequate and convincing, so that a prudent, informed person would reach the same conclusion.
- Reliable: the best attainable information. Reliability is higher when evidence is obtained directly by the auditor, comes from independent third parties, or is generated by systems with good controls.
- Relevant: it supports the specific action and the closure conclusion.
- Useful: it helps the organization meet its goals.
Hierarchy of Evidence Reliability (Most to Least Reliable)
1. Evidence obtained directly by the auditor, such as reperformance, observation or system inspection.
2. Documents from independent external sources, such as bank confirmations or vendor certifications.
3. Internally generated documents from an environment with strong controls, such as system logs, approved policies and signed reconciliations.
4. Internally generated documents from weak control environments.
5. Oral representations or management self-certification. This is the least reliable and is usually insufficient on its own for high-risk items.
How It Works: The Closure Process
Step 1: Agree a clear, measurable action plan. During the engagement, actions should be SMART: specific, measurable, achievable, relevant and time-bound. Ideally, the expected closure evidence is agreed upfront, for example: 'Provide three months of signed reconciliations.'
Step 2: Track the action. Actions are recorded in an issue-tracking system with owners, due dates and risk ratings.
Step 3: Management reports completion. The action owner notifies audit and submits supporting evidence.
Step 4: Internal audit evaluates the evidence. The depth of validation depends on the risk rating of the original finding:
- High or critical risk: independent auditor testing is required. This can include sample testing of operating effectiveness, reperformance, walkthroughs or a dedicated follow-up engagement.
- Medium risk: review of documentary evidence, possibly with limited testing.
- Low risk: management self-attestation may be accepted, often with spot checks. Some functions defer verification to the next scheduled audit.
Step 5: Consider design and operating effectiveness. A new policy document proves design only. Closure usually needs evidence that the control has operated for a reasonable period. For a monthly control, this means several cycles. For a quarterly control, at least one or two cycles.
Step 6: Make the closure decision. Possible outcomes:
- Closed: verified. The evidence is satisfactory.
- Closed: alternative action. Management implemented a different action that adequately mitigates the risk, and audit agrees.
- Closed: risk accepted. Senior management formally accepts the risk of not acting. If the CAE believes the accepted risk is unacceptable to the organization, the CAE must discuss it with senior management. If the matter is unresolved, the CAE escalates it to the board.
- Remains open or extended. The evidence is insufficient, or the deadline is revised with appropriate approval.
Step 7: Document and report. Audit retains the evidence and the closure rationale in the workpapers. Status is reported to senior management and the board or audit committee.
Examples of Acceptable Closure Evidence
- Finding: user access not reviewed. Evidence: completed and signed access review reports for subsequent periods, plus proof that inappropriate access was removed (system extracts showing removal).
- Finding: no segregation of duties in payments. Evidence: an updated system role matrix, and auditor inspection of system configuration showing the conflicting roles are blocked.
- Finding: missing policy. Evidence: an approved and communicated policy, plus evidence of training or compliance testing.
- Finding: reconciliations not performed. Evidence: a sample of timely, reviewed reconciliations with resolved reconciling items.
Examples of Insufficient Evidence
- An email from management stating 'this has been fixed.'
- A draft policy that has not been approved or implemented.
- A single instance of a control operating, when the control is meant to be recurring.
- A screenshot with no date, source or context.
- Evidence that addresses the symptom but not the root cause.
Roles and Responsibilities
- Management: owns the implementation of actions and provides evidence. Management, not internal audit, is responsible for remediation.
- Internal audit: independently evaluates the evidence and determines closure. Audit must not implement the fix itself, because that would impair objectivity.
- CAE: establishes the follow-up process and its policy, including evidence standards by risk level. The CAE also escalates unresolved or risk-accepted issues.
- Board or audit committee: oversees the status of open and overdue actions.
Exam Tips: Answering Questions on Evidence Required to Close a Management Action Plan
1. Favor verification over assertion. When the options include 'management confirms in writing' versus 'auditor tests the control,' the best answer for significant findings is almost always independent auditor verification.
2. Match the evidence to the risk rating. Questions often test proportionality. High-risk issues need testing of operating effectiveness. Low-risk issues may be closed on self-certification or reviewed at the next audit. Look for words like significant, critical or material.
3. Distinguish design from operating effectiveness. A newly written procedure or newly configured control is not enough if the question asks whether the issue is resolved. The best answer usually requires evidence that the control has operated over time.
4. Remember the root cause. Correct answers emphasize evidence that the underlying cause was fixed, not just the specific exceptions found.
5. Know who does what. Management implements. Internal audit evaluates and monitors. Any option where internal audit performs the remediation is a trap, because it impairs objectivity.
6. Know the risk acceptance route. If management chooses not to act, the issue may be closed as risk accepted. However, the CAE must discuss it with senior management if the risk exceeds the organization's risk appetite, and escalate to the board if it remains unresolved. The CAE does not resolve the risk personally.
7. Apply the evidence reliability hierarchy. Auditor-obtained and external evidence beats internal documents, and internal documents beat oral statements. Choose the most reliable option when asked for the best evidence.
8. Watch for alternative actions. If management implemented a different action than agreed, the correct response is to evaluate whether it adequately mitigates the risk. Do not automatically reject it.
9. Note the importance of documentation. Closure decisions and supporting evidence must be documented in the engagement records. Answers about retaining evidence and reporting status to the board are typically correct.
10. Read qualifiers carefully. Words like most appropriate, first, best and sufficient change the answer. 'First' may point to reviewing the evidence management submitted. 'Best' may point to independent testing.
Sample Exam Question
An internal audit found that bank reconciliations were not reviewed, a high-risk finding. Management reports that a review process is now in place and submits the new procedure document. What should the internal auditor do before closing the action?
A. Close the action based on the procedure document.
B. Obtain written confirmation from the CFO.
C. Test a sample of reconciliations prepared after implementation for evidence of timely review.
D. Perform the reconciliation reviews on management's behalf.
Answer: C. A shows design only. B is a management assertion. D impairs objectivity. Only C provides evidence of operating effectiveness.
Key Takeaways
- Closure requires sufficient, reliable, relevant and useful evidence that the action is implemented and effective.
- The depth of verification is proportional to the risk of the original finding.
- Management owns remediation. Internal audit independently validates it.
- Risk acceptance must be formally documented and escalated when appropriate.
- Document everything and report status to senior management and the board.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!