When to Request Action Plans from Management
In the CIA syllabus, engagement results and monitoring cover how internal auditors communicate findings and make sure management responds to them. Action plans are management's documented commitments to fix identified issues. Under the Global Internal Audit Standards, internal auditors develop reco… In the CIA syllabus, engagement results and monitoring cover how internal auditors communicate findings and make sure management responds to them. Action plans are management's documented commitments to fix identified issues. Under the Global Internal Audit Standards, internal auditors develop recommendations or collaborate on solutions, but management owns the remediation. Timing: Auditors request action plans after findings are developed, validated, and discussed with management. Validation means the condition, criteria, root cause, and effect have been established and the significance has been rated. The usual point is the closing or exit meeting, or immediately after the draft report is shared. Requesting plans before the final communication lets management's responses be included in the final report. The board and senior management then see both the problem and the agreed solution. Triggers: Action plans should be requested whenever a finding shows a meaningful gap between the condition and the criteria. Examples include control deficiencies, noncompliance, inefficiencies, or unmitigated risks. Significant or high-rated findings always require formal plans. Lower-rated observations may be handled informally, depending on the internal audit methodology. Auditors should not request plans before the root cause is understood, because remediation may then address symptoms rather than causes. Content: A good action plan specifies the corrective actions, the accountable owner, and realistic target completion dates. These should be proportionate to the risk. Auditors assess whether the proposed actions adequately address the root cause. If they do not, auditors discuss alternatives with management. Disagreement and risk acceptance: If management disagrees or declines to act, auditors document management's position. If management accepts a level of risk that exceeds the organization's risk appetite, the chief audit executive discusses it with senior management. If the matter remains unresolved, the CAE escalates it to the board. Monitoring: After plans are agreed, internal audit tracks implementation through a follow-up process. It confirms completion and reports the status of overdue or open actions to senior management and the board.
When to Request Action Plans from Management: A Complete CIA Exam Guide
Introduction
Asking management for action plans is one of the most practical steps in an internal audit engagement. It is the step that turns audit findings into real improvements. CIA candidates need to know three things: when to ask for action plans, who owns them, and how they connect to reporting and monitoring. This guide explains what the concept is, why it matters, how it works in practice, and how to answer exam questions on it.
1. What Is a Management Action Plan?
A management action plan is management's formal commitment to deal with an audit finding. It sets out how management will fix a control weakness, lower a risk, or take advantage of an improvement opportunity.
A good action plan answers four questions:
• What will be done? This is the specific corrective action.
• Who is responsible? This should be a named owner, not a vague department.
• When will it be completed? This is a realistic target date.
• How will completion be shown? This is the evidence auditors can later check.
Under the IIA's Global Internal Audit Standards, internal auditors develop recommendations, request management action plans, or both, based on the findings. These must be discussed with management. Under the earlier Standards, management responses and action plans were linked to engagement communications (the 2400 series) and to monitoring progress (Standard 2500).
2. Why Is It Important?
• It confirms accountability. Management, not internal audit, owns risks and controls. Asking management for the plan reinforces that responsibility.
• It protects auditor objectivity. If auditors designed and carried out the fixes, they would later be auditing their own work. Having management own the solution avoids this.
• It makes the plan workable. Management knows its own resources, systems, and constraints. Plans it builds are usually more practical and more likely to be carried out.
• It allows follow-up. Without agreed actions, owners, and dates, internal audit has nothing concrete to monitor.
• It improves the report. Final reports that include management's responses and plans give the board and senior management a full picture: the problem, its effect, and the fix.
• It brings disagreement into the open. If management will not act, the issue becomes a risk-acceptance question that the CAE may need to escalate.
3. When Should Action Plans Be Requested?
Timing is the main issue tested on the exam. The general rule is: request action plans after findings are developed and validated with management, and before the final engagement communication is issued.
Stage-by-stage view:
• Planning and fieldwork: It is too early to ask for formal action plans. Findings are still being gathered and checked. However, auditors should talk with management about observations as they come up, so there are no surprises later.
• Validating findings: Auditors confirm the facts with process owners. Both sides should agree on the condition, criteria, cause, and effect before solutions are discussed. If the facts are disputed, the action plan will not be meaningful.
• Exit or closing meeting: This is the usual point to discuss findings, recommendations, and expected management responses. Management is asked to prepare or confirm action plans.
• Draft report stage: The draft report goes to management, who return written responses with action plans, owners, and dates. These are added to the final report.
• Final report: Ideally it already contains management's action plans. If management has not responded in time, the CAE may issue the report noting that responses are pending, depending on internal audit policy.
• After the report (monitoring): Internal audit tracks the plans and confirms they were carried out. This is required by the Standards: the CAE must set up and maintain a monitoring process.
Other timing situations:
• Urgent or high-risk findings: Examples are fraud indicators, significant control failures, or safety and legal exposures. These should be reported promptly, and immediate action may be requested before the engagement ends. Interim communication is appropriate here.
• Low-risk or minor observations: These may be shared informally, for example in a management letter or verbal discussion. Formal action plans may not be needed, depending on the audit function's methodology.
• Consulting engagements: The nature and timing of action plans depend on what was agreed with the client. Monitoring follows the agreed terms.
• Management already fixing the issue: Auditors should still record the corrective action already under way in the report, and may confirm it during follow-up.
4. How the Process Works
Step 1: Develop and validate findings. Document the condition, criteria, cause, and effect, along with an assessment of significance or risk rating.
Step 2: Develop recommendations where appropriate. Recommendations should address the root cause, not just the symptoms. Under the Global Standards, auditors may give recommendations, ask management to create action plans, or do both.
Step 3: Discuss with management. Hold discussions or an exit meeting with the right level of management, meaning those with the authority to commit resources.
Step 4: Request formal responses. Ask management to provide action plans with owners, actions, and target dates. Agree on a deadline for the response.
Step 5: Evaluate the adequacy of the plan. Internal auditors assess whether the plan actually addresses the root cause and reduces risk to an acceptable level. Auditors do not simply accept any response.
Step 6: Include the plans in the final communication. Report findings, recommendations, and management's action plans together.
Step 7: Monitor and follow up. Track plans to completion. Confirm implementation through evidence, inquiry, or retesting, depending on risk.
Step 8: Escalate if needed. If management accepts a level of risk that the CAE believes is unacceptable, the CAE first discusses it with senior management. If the matter is not resolved, the CAE communicates it to the board. This is covered by the Global Standards on communicating the acceptance of risks and by Standard 2600 in the earlier framework.
5. Roles and Responsibilities
• Management: Owns the action plan, provides resources, carries out the corrective actions, and reports on progress.
• Internal auditors: Request the plans, evaluate whether they are adequate, include them in reports, and monitor implementation. Auditors may advise but must not take on management responsibilities.
• CAE: Sets up the monitoring process, decides follow-up timing based on risk, and escalates unresolved risk acceptance.
• Board or audit committee: Receives reports on the status of action plans, especially overdue high-risk items.
6. Common Pitfalls
• Asking for action plans before findings are validated, which leads to disputes and weak plans.
• Internal audit writing the action plan for management, which threatens objectivity and ownership.
• Accepting vague plans such as 'Management will review the process' with no owner or date.
• Holding the final report indefinitely while waiting for responses. Policy should set response deadlines.
• Failing to escalate when management refuses to act on significant risks.
Exam Tips: Answering Questions on When to Request Action Plans from Management
Tip 1: Remember the ownership principle. Any answer where internal audit designs, owns, or carries out corrective actions is almost always wrong. Management owns the action plan. Internal audit requests it, evaluates it, and monitors it.
Tip 2: Know the best timing. Choose answers that place the request after findings are discussed and agreed with management, usually at or around the exit meeting or draft report stage, and before the final report is issued. Watch for distractors such as 'during engagement planning' or 'only after the board reviews the report'.
Tip 3: Urgent issues change the timing. For significant risks, fraud, or illegal acts, the best answer often involves prompt communication and immediate action rather than waiting for the final report.
Tip 4: Look for the four elements. When asked which action plan is most appropriate, pick the one with a specific action, an accountable owner, a target date, and a link to the root cause.
Tip 5: Auditors evaluate, not just accept. If a question asks what the auditor should do with management's response, the correct answer usually involves assessing whether it adequately addresses the risk.
Tip 6: Disagreement leads to escalation. If management will not act and accepts an unacceptable level of risk, the correct sequence is: CAE discusses it with senior management, then communicates it to the board if unresolved. The auditor does not drop the issue, and does not force management to act.
Tip 7: Disagreement can still be reported. If management disagrees with a finding, the report can include both the auditor's position and management's view. Auditors should not change a valid finding just to gain management's agreement.
Tip 8: Monitoring is mandatory. Questions on post-report steps point to the CAE's monitoring process. Follow-up timing and intensity are risk-based: high-risk items get closer and earlier follow-up.
Tip 9: Assurance and consulting differ. For consulting engagements, action plans and monitoring follow the terms agreed with the client. Do not apply assurance requirements automatically.
Tip 10: Read qualifiers carefully. Words such as 'most appropriate', 'first', and 'best' matter. When two options seem correct, choose the one that keeps internal audit objective, keeps management accountable, and makes sure risks are dealt with on time.
Sample Question
An internal auditor has completed fieldwork and validated a significant control deficiency with the process owner. What should the auditor do next?
A. Design and implement a new control to fix the deficiency.
B. Discuss the finding with management and request an action plan with an owner and target date before issuing the final report.
C. Issue the final report immediately without management input.
D. Wait until the next annual audit to see whether management fixes the issue.
Answer: B. Option A impairs objectivity because the auditor would be taking on management's role. Option C skips the required discussion with management and leaves out their response. Option D ignores the need for timely action and monitoring.
Key Takeaway
Request action plans once findings are validated and discussed, ideally at the closing stage and before the final report. Act sooner for urgent, high-risk issues. Management owns the plan. Internal audit evaluates it, reports it, monitors it, and escalates unacceptable risk acceptance through the CAE to senior management and then the board.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!