Follow-Up and Tracking of Management Action Plans
Follow-up and tracking of management action plans is how internal audit makes sure that agreed engagement results lead to real change. (Note: in the current CIA syllabus, this topic sits under Engagement Results and Monitoring in Part 2, Practice of Internal Auditing. It also connects to Part 3 gov… Follow-up and tracking of management action plans is how internal audit makes sure that agreed engagement results lead to real change. (Note: in the current CIA syllabus, this topic sits under Engagement Results and Monitoring in Part 2, Practice of Internal Auditing. It also connects to Part 3 governance concepts.) Under the IIA's Global Internal Audit Standards, mainly Standard 15.2, and the earlier Standard 2500, the chief audit executive must establish and maintain a process to monitor and confirm that management has implemented recommendations or action plans. Management owns the implementation. Internal audit's role is to verify progress and report on it, not to perform the corrective work. Each action plan should state the specific actions, a responsible owner, and a target completion date. Internal audit records these in a tracking system, often audit management software, and monitors their status: open, in progress, overdue, or closed. The depth of follow-up depends on risk. High-risk issues may call for testing evidence, re-performing controls, or a separate follow-up engagement. Lower-risk items may be closed on the basis of management's written confirmation and supporting documentation. Timing should reflect the significance of the issue, and the follow-up process should be defined in the internal audit charter or methodology. Internal audit regularly reports implementation status to senior management and the board. These reports highlight overdue, repeatedly extended, or inadequately addressed actions, which strengthens accountability. If management decides not to act, it is accepting risk. If the chief audit executive concludes that management has accepted a level of risk that may be unacceptable to the organization, the matter must be discussed with senior management. If it is not resolved, it must be communicated to the board (Standard 11.5; formerly Standard 2600). Effective follow-up shows the value of internal audit and feeds into future risk assessments and audit planning. It also supports the quality assurance and improvement program by showing whether recommendations were practical. For the exam, remember three points: management implements, internal audit monitors and confirms, and the board resolves unresolved risk acceptance.
Follow-Up and Tracking of Management Action Plans: A Complete CIA Exam Guide
Introduction
An internal audit engagement does not end when the final report is issued. Its value comes from what management actually does about the findings. Follow-up and tracking of management action plans is the process internal auditors use to monitor, confirm and report whether management has addressed the risks and control weaknesses identified during an engagement. This guide explains why the process matters, what it involves, how it works in practice, and how to approach exam questions on it.
1. Why Follow-Up Is Important
It closes the assurance loop. A finding that is reported but never fixed leaves the organization exposed to the same risk. Follow-up turns recommendations into risk reduction.
It is required by the Standards. The IIA's Global Internal Audit Standards (Standard 15.2, Confirming the Implementation of Recommendations or Action Plans) require internal auditors to confirm that management has implemented the recommendations or action plans by the agreed dates. Under the earlier IPPF this requirement appeared as Standard 2500, Monitoring Progress, which required the chief audit executive (CAE) to establish and maintain a system for monitoring the disposition of results.
It supports governance and accountability. The board and senior management depend on internal audit to tell them whether significant issues are being resolved. Overdue or ignored actions are an important governance signal.
It demonstrates internal audit's value. Tracking implementation rates shows the impact of audit work and provides useful performance metrics for the internal audit function.
It informs future planning. Unresolved issues raise residual risk, and that should influence the risk-based audit plan and future engagement scopes.
It surfaces risk acceptance. Follow-up shows when management has effectively chosen not to act. That may trigger the CAE's escalation duty under Standard 11.5, Communicating the Acceptance of Risks (formerly Standard 2600).
2. What Follow-Up Is
Follow-up is the process by which internal auditors evaluate the adequacy, effectiveness and timeliness of the actions management takes on reported observations and recommendations. It includes:
• Monitoring: keeping an ongoing record of all open action plans, with owners, due dates and status.
• Confirmation and validation: getting evidence that actions were completed and are working as intended.
• Reporting: telling senior management and the board about implementation status, overdue items and significant unresolved risks.
• Escalation: raising issues where management has not acted or has accepted a level of risk that may be unacceptable.
Key roles:
• Management owns the risk and is responsible for designing, carrying out and documenting corrective action. Internal audit does not implement fixes, because doing so would impair objectivity.
• Internal auditors confirm and evaluate the actions taken.
• The CAE establishes the monitoring methodology, decides the nature, timing and extent of follow-up, and reports to the board.
• The board oversees results and holds management accountable.
Action plan vs. recommendation: Under the Global Internal Audit Standards, auditors may make recommendations, or management may develop its own action plans in response to findings. An action plan should say what will be done, who is responsible, and by when. Agreement on these points is usually documented in the final engagement communication (Standard 15.1).
3. How Follow-Up Works
Step 1: Agree on action plans during the engagement. Findings are discussed with management, and management commits to specific actions, owners and target dates. Auditors judge whether the proposed actions would address the root cause and reduce risk to an acceptable level.
Step 2: Record actions in a tracking system. The CAE keeps a log or database, often in audit management software (GRC tools). Each entry typically shows the finding, its risk rating, the agreed action, the owner, the due date, the current status and any revised dates.
Step 3: Monitor progress. Internal audit periodically asks action owners for status updates. Owners may self-report progress, but self-reporting alone is generally not enough to close high-risk items.
Step 4: Determine the nature, timing and extent of follow-up. The CAE uses a risk-based approach. Relevant factors include:
• the significance and risk rating of the finding
• how complex and costly the corrective action is
• the effect of the action failing
• how long the action will take
• management's history of following through
• any changes in the environment since the engagement
Step 5: Perform follow-up procedures. Procedures range from low to high rigor:
• Inquiry or status confirmation from management (lowest assurance; suitable for low-risk items)
• Review of documentation, such as updated policies, reconciliations or system change records
• Observation and walkthroughs of the revised process
• Re-performance and testing of the new controls over a period of operation (highest assurance; expected for high-risk findings)
• A full follow-up engagement for pervasive or critical issues
Step 6: Evaluate and conclude. Auditors decide whether each action has been implemented as agreed and whether it is effective. Possible outcomes are: implemented and effective; implemented but not effective; partially implemented; not implemented; or superseded by alternative action.
Step 7: Report results. Follow-up status is reported regularly to senior management and the board, often quarterly. Typical content includes open items by risk rating, overdue actions, ageing analysis and items with revised due dates.
Step 8: Escalate and handle risk acceptance. If management has not acted, or has decided not to act, the CAE should discuss the matter with senior management. If the CAE concludes that management has accepted a level of risk that exceeds the organization's risk appetite or tolerance, and the matter cannot be resolved with senior management, the CAE must communicate it to the board.
Special considerations
• Revised due dates: Extensions should be justified, approved by an appropriate level of management, and tracked. Repeated extensions are a red flag.
• Alternative actions: Management may address a risk differently than recommended. Auditors evaluate whether the alternative reduces the risk adequately.
• Consulting engagements: The earlier IPPF (2500.C1) required internal audit to monitor the disposition of consulting results only to the extent agreed upon with the client. The scope of follow-up for consulting work is set by agreement.
• External auditor or regulator findings: Internal audit may also track these if they fall within its mandate or the CAE judges it appropriate.
• Responsibility: Follow-up is the responsibility of the internal audit activity. It may be delegated within the team, but the CAE remains accountable for the monitoring system.
• Documentation: Follow-up work, evidence obtained and conclusions must be documented, just as for any engagement.
4. Common Concepts and Terminology
• Disposition of results: the outcome of how management handles reported findings.
• Root cause: effective action plans address the underlying cause, not just the symptom.
• Ageing of open items: how long actions have stayed open past their due date.
• Implementation rate: a KPI showing the percentage of actions closed on time.
• Residual risk: the risk that remains, which unresolved actions leave elevated.
• Risk acceptance: management's decision to tolerate a risk rather than reduce it.
5. Exam Tips: Answering Questions on Follow-Up and Tracking of Management Action Plans
Tip 1: Know who is responsible for what. Management is responsible for taking corrective action. Internal audit is responsible for monitoring and confirming. The CAE is responsible for establishing the follow-up process. Reject any answer where internal audit implements the fix, designs and operates the new control, or 'signs off' on management's responsibility.
Tip 2: Follow-up is risk-based. Not every finding needs the same effort. If a question asks how to decide the extent of follow-up, choose the answer based on the significance of the risk or finding, not on convenience, auditor availability or a fixed schedule for everything.
Tip 3: Self-reporting is weak evidence. For high-risk or significant findings, the best answer usually involves obtaining evidence and testing the new controls. Management's statement that an issue is fixed is rarely enough to close a critical item.
Tip 4: Effective means more than implemented. Follow-up confirms that actions were taken and that they address the risk. If a question describes a control that was put in place but is not working, the item should not be closed.
Tip 5: Recognize the escalation sequence. When management fails to act or accepts excessive risk, the CAE first discusses the matter with senior management. If it remains unresolved, the CAE communicates it to the board. Watch for distractors that skip straight to the board, go to external regulators, or have the auditor ignore the issue.
Tip 6: Management can accept risk. Management has the right to accept a risk instead of implementing a recommendation. The CAE's role is not to force implementation. It is to make sure risk acceptance beyond appetite is communicated to the board.
Tip 7: Consulting engagements differ. For consulting work, follow-up is performed to the extent agreed with the client. Do not assume assurance-level follow-up applies automatically.
Tip 8: Know the purpose of a tracking system. Questions may ask for the primary purpose of a follow-up or tracking system. The best answer is usually to ensure that management action has been effectively implemented or that senior management has accepted the risk of not acting. It is not to evaluate staff performance or to generate audit hours.
Tip 9: Link follow-up to the audit plan. Unresolved significant issues increase risk and should be considered in future risk assessments and audit planning. Answers that connect follow-up results to planning are often correct.
Tip 10: Watch for 'best', 'first' and 'most appropriate'. In scenario questions, choose the action that is professionally sound and consistent with the Standards. For example, if an action is overdue, the first step is typically to contact the responsible manager to find out the status and reason, not to immediately escalate to the board.
Tip 11: Timing matters. Follow-up should happen around the agreed implementation dates, with enough time for new controls to operate before they are tested. Testing a control the day after it was introduced may not give sufficient evidence of operating effectiveness.
Tip 12: Documentation is required. Follow-up conclusions must be supported by sufficient, reliable, relevant and useful evidence, and must be documented in the workpapers.
6. Sample Exam-Style Reasoning
Scenario: An audit found a high-risk weakness in user access controls. Management agreed to implement quarterly access reviews within 90 days. At the due date, the manager emails that the reviews are 'in place.' What should the internal auditor do?
Reasoning: The finding is high risk, so an email confirmation is not enough. The auditor should get evidence, such as completed and approved access review reports, and test whether inappropriate access was identified and removed. Only then can the item be closed.
Scenario: Management states it will not implement a recommendation because the cost is too high. The CAE believes the remaining risk exceeds the organization's risk appetite.
Reasoning: The CAE should discuss the matter with senior management. If it cannot be resolved, the CAE must communicate the risk acceptance to the board. The auditor should not implement the control personally or simply close the finding.
7. Quick Summary
• Follow-up confirms that management actions are implemented, effective and timely.
• The CAE establishes and maintains the monitoring system. Management owns corrective action.
• Follow-up is risk-based: higher risk calls for stronger evidence and testing.
• Status is reported regularly to senior management and the board.
• Unacceptable risk acceptance is discussed with senior management and, if unresolved, communicated to the board.
• For consulting engagements, follow-up is performed to the extent agreed with the client.
• Follow-up results should feed into future risk assessments and audit planning.
Master these principles and you will be able to identify correct answers and avoid common distractors in exam questions on follow-up and tracking of management action plans.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!