Management Action Plans and Root Cause
Note: Under the 2025 CIA syllabus, engagement results and monitoring sit mainly in Part 2 (Practice of Internal Auditing); earlier syllabi placed related topics elsewhere. The concepts below apply either way. Root cause is the underlying reason a condition differs from the criteria. A finding is c… Note: Under the 2025 CIA syllabus, engagement results and monitoring sit mainly in Part 2 (Practice of Internal Auditing); earlier syllabi placed related topics elsewhere. The concepts below apply either way. Root cause is the underlying reason a condition differs from the criteria. A finding is commonly framed using condition (what is), criteria (what should be), cause (why the gap exists) and effect (the risk or impact). The Global Internal Audit Standards (2024) expect auditors to identify root causes where possible when evaluating findings (Standard 14.3). Symptoms, such as an unapproved payment, often trace back to deeper causes, such as unclear policies, inadequate training, poor system design, insufficient resources, misaligned incentives or weak tone at the top. Techniques include the 5 Whys, fishbone (Ishikawa) diagrams, process mapping, fault tree analysis and data analytics. Fixing the root cause prevents recurrence and adds more value than correcting isolated errors. It also helps auditors spot themes that recur across engagements. Management action plans are management's documented commitments to address findings. Under Standard 14.4, internal auditors develop recommendations or discuss with management its proposed actions. An effective plan addresses the root cause, assigns a specific owner, sets realistic deadlines and defines measurable outcomes. Auditors assess whether proposed actions are adequate for the risk. Management, not internal audit, owns and implements them, which preserves auditor objectivity. Disagreements are documented in the final communication, along with management's view. Monitoring follows the engagement. Standard 15.2 requires the chief audit executive to confirm that management has implemented the recommendations or action plans, or has accepted the risk of not acting. Follow-up methods include inquiry, reviewing evidence, retesting controls or a separate follow-up audit, scaled to the significance of the risk. If management accepts a level of risk that the CAE believes exceeds the organization's risk appetite, the CAE must discuss it with senior management. If the issue remains unresolved, the CAE escalates it to the board. Exam tip: Choose answers that target root causes, keep management accountable for action and ensure systematic follow-up.
Management Action Plans and Root Cause: A Complete CIA Exam Guide
Introduction
Management Action Plans (MAPs) and Root Cause Analysis (RCA) are central to how internal audit adds value after fieldwork ends. Under the IIA Global Internal Audit Standards (2024), and particularly within the Engagement Results and Monitoring domain, auditors are expected to do more than report what went wrong. They must understand why it went wrong and make sure management commits to credible, time-bound actions that fix it. CIA exam questions on this topic test whether you can tell symptoms from causes, recognize who owns the remediation, and judge whether an action plan is adequate.
Why This Topic Is Important
1. Prevents recurrence: Fixing a symptom, such as correcting one erroneous invoice, does not stop the problem from returning. Addressing the root cause, such as the lack of an automated three-way match, does.
2. Adds value: The Standards emphasize that internal audit should improve the organization's operations. Recommendations based on root cause give stakeholders insight rather than just a list of findings.
3. Supports accountability: Action plans assign ownership and due dates, so responsibility for fixing an issue is clear.
4. Enables monitoring: The Chief Audit Executive (CAE) must establish and maintain a system to monitor whether management has acted on results. Without documented action plans, there is nothing to follow up on.
5. Supports risk acceptance decisions: When management chooses not to act, the CAE must evaluate whether the accepted risk exceeds the organization's risk appetite and escalate if needed.
What Is Root Cause Analysis?
Root cause is the underlying reason for the difference between the condition (what is) and the criteria (what should be). In the classic elements of an engagement finding, root cause is the Cause:
- Criteria: the standard, policy or expectation.
- Condition: what the auditor actually found.
- Cause: why the condition exists. This is the root cause.
- Effect (Consequence): the risk or impact of the condition.
- Recommendation / Action Plan: what should be done.
Under the 2024 Global Internal Audit Standards, Standard 14.3 (Evaluation of Findings) asks internal auditors to identify the root cause of findings to the extent possible. Root causes often fall into these categories:
- People: lack of training, insufficient staffing, unclear responsibilities.
- Process: poorly designed procedures, missing controls, manual workarounds.
- Technology: system limitations, inadequate access controls, poor interfaces.
- Governance and culture: weak tone at the top, conflicting incentives, lack of oversight.
- External factors: regulatory change, vendor failures.
Common Root Cause Analysis Techniques
1. The 5 Whys: Repeatedly ask 'why?' until you reach a cause that, if fixed, would prevent recurrence.
Example: Payments were duplicated. Why? The vendor was set up twice. Why? There was no duplicate check in the master file. Why? The system was configured without validation rules. Why? IT implementation requirements did not include data validation. That last answer is the root cause.
2. Fishbone (Ishikawa) Diagram: Groups possible causes into categories, such as people, process, technology, environment, materials and measurement, to give a structured view.
3. Fault Tree Analysis: A top-down logical diagram tracing how combinations of failures lead to an event.
4. Pareto Analysis: Applies the 80/20 rule to find the few causes behind most problems.
5. Bow-tie Analysis: Links causes, a risk event and its consequences, showing preventive and mitigating controls.
6. Data analytics and trend analysis: Spots recurring patterns across locations, periods or processes that point to systemic causes.
What Are Management Action Plans?
A Management Action Plan is management's formal response to an audit finding. It describes what management will do to address the issue. A good action plan includes:
- The specific action to be taken, linked to the root cause.
- The owner: a named individual or role accountable for completion.
- The target completion date: realistic and proportionate to risk.
- Resources needed, where relevant.
- Evidence of completion that will show the action has been implemented.
Key principle: Management owns both the risks and the action plans. Internal audit recommends and evaluates but does not implement corrective actions. Implementing them would impair objectivity and independence. Internal audit may advise on design if this is properly managed as an advisory activity, but responsibility stays with management.
How It Works: The Process Flow
1. Identify the finding during fieldwork by comparing condition to criteria.
2. Perform root cause analysis to find why the gap exists, often working jointly with process owners.
3. Assess significance by rating the finding (for example high, medium or low) based on impact and likelihood.
4. Develop recommendations that target the root cause, not just the symptom.
5. Discuss with management in exit meetings to confirm facts, the root cause and practical solutions.
6. Obtain management action plans, which are agreed and documented, often included in the final report alongside or in place of recommendations.
7. Issue the final communication, including findings, ratings, root causes and action plans.
8. Monitor and follow up. The CAE tracks implementation through a monitoring system, such as an issues log or GRC tool.
9. Validate closure. Internal audit tests evidence to confirm that actions were implemented and work effectively. Management's word alone is not enough for high-risk items.
10. Escalate. If actions are overdue or management accepts a risk beyond the risk appetite, the CAE discusses it with senior management. If unresolved, the CAE communicates it to the board.
Monitoring and Follow-up
- The CAE must establish a process to monitor and confirm that management's actions have been effectively implemented, or that senior management has accepted the risk of not acting.
- The nature, timing and extent of follow-up depend on the significance of the finding, the cost and effort of corrective action, the impact if the action fails, and the complexity and timing involved.
- For high-risk findings, follow-up typically includes independent testing. For low-risk findings, management self-certification may be acceptable.
- Follow-up status, especially overdue and high-risk items, is commonly reported to the board or audit committee on a regular basis.
Risk Acceptance
Management may decide not to implement a recommendation because of cost, priorities or strategy. That is acceptable if the residual risk is within risk appetite. If the CAE concludes management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss it with senior management. If the matter is not resolved, the CAE must communicate it to the board. Internal audit does not have the authority to force management to act. Its role is to communicate and escalate.
Characteristics of Strong Versus Weak Action Plans
Strong: Specific, measurable, assigned to an accountable owner, time-bound, addresses the root cause, proportionate to risk, and has verifiable evidence of completion.
Weak: Vague (for example, 'will improve controls'), no owner, open-ended dates, fixes only the symptom (for example, 'will correct the errors found'), or relies only on reminders and training when the real cause is a system design flaw.
Illustrative Example
Condition: 15 of 60 sampled user accounts belonged to terminated employees.
Symptom-level response: Disable the 15 accounts. This is necessary but insufficient.
Root cause: HR termination data is not automatically sent to IT, and there is no periodic user access review.
Strong action plan: IT Security Manager to implement an automated HR-to-IAM interface by 30 June, and to establish quarterly access reviews certified by department heads starting Q3. Evidence: interface test results and signed review records.
Exam Tips: Answering Questions on Management Action Plans and Root Cause
1. Separate symptoms from causes. If an answer option describes the condition, such as 'errors were found in invoices,' it is not the root cause. Look for the option that explains why, such as a missing control, inadequate training or system design.
2. Choose the option that prevents recurrence. When asked for the best recommendation or action plan, prefer the one that fixes the underlying cause over one that corrects the individual errors found.
3. Management owns remediation. Any option where internal audit implements the fix, writes the procedure as the owner, or takes responsibility for the control is usually wrong because it impairs objectivity.
4. Follow-up responsibility belongs to the CAE. Questions about who establishes the monitoring process point to the CAE. Questions about who carries out corrective action point to management.
5. Follow-up is risk-based. The extent of follow-up depends on significance. High-risk findings call for testing and validation, not just management assertion.
6. Know the escalation path. Unacceptable risk acceptance goes first to senior management, then to the board if unresolved. Internal audit cannot override management or force implementation.
7. Match the element to the definition. Criteria means 'should be.' Condition means 'is.' Cause means 'why.' Effect means 'so what.' Many questions test these labels.
8. Identify the root cause technique. Repeated 'why' questions indicate the 5 Whys. Categorized cause branches indicate a fishbone diagram. The 80/20 rule indicates Pareto analysis.
9. Look for SMART qualities. The best action plan answer is usually specific, has an owner and a deadline, and links to the cause.
10. Beware of 'training' as a default answer. Training solves people-related causes. If the scenario points to system or process design, training alone is not the best fix.
11. Collaboration is good, ownership is not. Internal audit may facilitate root cause workshops with management and give advice, and this is valued. Taking ownership of decisions is not acceptable.
12. Read for 'most' and 'best.' Several options may be partly correct. Choose the one that best addresses the root cause, keeps independence and fits the level of risk.
13. Systemic issues need a broader response. If the same finding appears across several units, the root cause is likely organization-wide, such as policy, governance or a shared system. The best answer will address it at that level.
Quick Recap
- Root cause explains why the condition differs from the criteria.
- Recommendations and action plans should target the root cause.
- Management owns action plans and the CAE monitors them.
- Follow-up is risk-based. Significant items need validation.
- Unacceptable risk acceptance is escalated to senior management, then to the board.
- Internal audit never takes on management's responsibility for remediation.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!