Learn Engagement Results and Monitoring (CIA Part 3) with Interactive Flashcards
Master key concepts in Engagement Results and Monitoring through our interactive flashcard system. Click on each card to reveal detailed explanations and enhance your understanding.
Attributes of Quality Engagement Communications
In the CIA syllabus, the attributes of quality engagement communications come from IIA Standard 2420 (Quality of Communications) and are carried forward in Standard 11.2 (Effective Communication) of the 2024 Global Internal Audit Standards. Communications must be accurate, objective, clear, concise, constructive, complete, and timely. Exam questions often ask candidates to tell these attributes apart. 1. Accurate: Communications are free from errors and distortions and faithful to the underlying facts. Findings must rest on sufficient, reliable, and relevant evidence documented in workpapers. If a final communication is later found to contain a significant error or omission, the chief audit executive must send corrected information to everyone who received the original. 2. Objective: Communications are fair, impartial, and unbiased. They result from a balanced assessment of all relevant facts and circumstances. Auditors avoid emotional or inflammatory language and may acknowledge satisfactory performance alongside deficiencies. 3. Clear: Communications are logical and easy to understand. They avoid unnecessary technical jargon and present significant information in proper context. 4. Concise: Communications are to the point and free of unnecessary elaboration, redundancy, and wordiness. Concise does not mean incomplete. 5. Constructive: Communications help the engagement client and the organization and lead to improvements where needed. The tone should be collaborative, and recommendations should be practical, cost-effective, and aimed at root causes. 6. Complete: Communications contain everything essential for the intended audience. This includes all significant information and observations needed to support conclusions and recommendations, typically the elements of a finding: criteria, condition, cause, effect, and recommendation or corrective action. 7. Timely: Communications are well timed and delivered promptly according to the significance of the issue, so management can act. Urgent matters may call for interim communications before the final report. Together, these attributes build the credibility of internal audit and encourage management to accept and act on results. They also support the chief audit executive's monitoring and follow-up process. Communications with clear, complete, and constructive recommendations make it easier to track whether management has implemented corrective actions or accepted the associated risk.
Applying Communication Attributes to Engagement Results
Applying communication attributes means making sure every engagement result, whether an interim update, draft report, final report, or follow-up memo, meets the quality criteria in the IIA Standards (Standard 2420 in the former IPPF; Standard 11.2 in the 2024 Global Internal Audit Standards). These criteria turn raw audit work into communication that management and the board can trust and act on. Note that in many CIA syllabus versions this material is tested mainly in Part 2, though it supports the monitoring concepts discussed elsewhere. The seven attributes are: (1) Accurate: free from errors and distortions and faithful to the underlying facts. Findings must trace to sufficient, reliable workpaper evidence. If a significant error is found after issuance, the chief audit executive must send corrected information to everyone who received the original. (2) Objective: fair, impartial, and unbiased, based on a balanced assessment of all relevant facts. Auditors avoid emotional or accusatory wording and acknowledge mitigating factors. (3) Clear: easily understood and logical. Auditors avoid unnecessary jargon, define technical terms, and organize findings by criteria, condition, cause, and effect, or consequence, so readers see why an issue matters. (4) Concise: to the point, without redundancy or excessive detail. Executive summaries help senior readers grasp key risks quickly. (5) Constructive: helpful to the engagement client and the organization, leading to improvement. Recommendations should be practical, cost-effective, and tied to root causes. (6) Complete: nothing essential to the target audience is missing. All significant information and observations supporting conclusions and recommendations are included. (7) Timely: delivered promptly so stakeholders can take corrective action. Delayed reports lose value as conditions change. In practice, auditors apply these attributes through supervisory review, quality checklists, and discussing draft observations with management before finalizing. Results should also acknowledge satisfactory performance where appropriate and include management action plans with owners and due dates. These elements make later monitoring and follow-up more effective. Strong communication attributes increase credibility, encourage acceptance of recommendations, and help internal audit add value to governance, risk management, and control processes.
Effective Communication Methodologies
Effective communication methodologies are how internal auditors deliver engagement results so stakeholders understand them, accept them, and act on them. (Note: in the current CIA syllabus, engagement communication and monitoring are tested mainly in Part 2, but the principles also support Part 3 governance and management topics.) Under the IIA Standards (Standard 2420, and Principle 11 and Standard 14.x of the 2024 Global Internal Audit Standards), communications must be accurate, objective, clear, concise, constructive, complete, and timely. Accurate means free of errors and supported by evidence. Objective means fair, impartial, and balanced. Clear means logical and free of unnecessary jargon. Concise means without redundancy. Constructive means helpful and focused on improvement. Complete means nothing essential is missing. Timely means delivered while the issues still matter. Findings are usually built on the 5 Cs model. Criteria describes what should be. Condition describes what exists. Cause explains why the gap occurred. Consequence (effect) describes the risk or impact. Corrective action is the recommendation or management action plan. Auditors also rate severity so readers can prioritize. Key methodologies include: (1) audience tailoring, giving the board and senior management high-level, risk-focused summaries and giving operational managers detailed findings; (2) interim and oral communications, such as status updates and exit meetings that discuss observations early, prevent surprises, and confirm facts; (3) formal written reports with executive summaries, scope, objectives, conclusions, overall opinions, and management responses; (4) visual aids such as dashboards, heat maps, and charts that make complex data easier to grasp; and (5) acknowledging satisfactory performance to keep the tone balanced. If a final communication contains a significant error or omission, the chief audit executive must send corrected information to everyone who received the original. Communication continues after the report through monitoring. The CAE sets up a follow-up process to track whether management has carried out its action plans. If management accepts a level of risk that may be unacceptable to the organization, the CAE discusses it with senior management and escalates unresolved issues to the board. This ongoing dialogue strengthens accountability and maximizes the value of internal audit.
Key Components of the Final Engagement Report
The final engagement report is the internal auditor's formal communication of engagement results. Note that in the current CIA syllabus, communicating results and monitoring progress is tested mainly in Part 2, though it supports Part 3 concepts. Under the IIA's Global Internal Audit Standards (Standard 15.1), the final communication should include the following key components.
1. Engagement objectives and scope: These state what the engagement set out to achieve and which processes, locations, systems and time periods were covered. Any scope limitations or areas specifically excluded should be disclosed so readers understand the boundaries of the work.
2. Findings (observations): Each significant finding is typically structured around the elements often taught as the '5 Cs'. Criteria describe the expected standard, policy or benchmark. Condition is the factual evidence of what actually exists. Cause is the root reason for the gap. Consequence (effect) is the risk or impact on the organization. Corrective action is the recommendation or management's planned response. Findings are usually prioritized or rated by significance.
3. Conclusions and overall opinion: The report gives the auditor's professional judgment on the area reviewed, such as the adequacy and effectiveness of governance, risk management and controls. This may take the form of a rating (for example, satisfactory, needs improvement or unsatisfactory) supported by sufficient evidence.
4. Recommendations and management action plans: These are practical recommendations that address root causes. They are paired with management's responses, which name the responsible owners and set target completion dates. Any disagreements between auditors and management should be documented.
5. Acknowledgment of satisfactory performance: Strengths and well-functioning controls are recognized to provide balance.
6. Conformance statement: The report may state that the engagement was performed in conformance with the Standards. Any nonconformance must be disclosed along with its impact.
7. Distribution: The report goes to the parties who can ensure that results receive appropriate consideration and action.
Quality attributes: Communications must be accurate, objective, clear, concise, constructive, complete and timely.
Monitoring: The Chief Audit Executive must establish a follow-up process to confirm that management actions are implemented effectively. If management accepts a risk that the CAE considers unacceptable, the CAE must escalate the matter to senior management and, if it remains unresolved, to the board.
Engagement Conclusions and Overall Opinions
Engagement conclusions and overall opinions are how internal auditors turn individual findings into meaningful judgments for management and the board. An engagement conclusion is the auditor's professional judgment about the significance of aggregated findings for the specific area reviewed. It answers the engagement objectives, for example whether controls over procurement are effective, partially effective, or ineffective. Conclusions must rest on sufficient, reliable, relevant, and useful evidence documented in working papers. They should weigh the significance and root causes of findings, consider risk tolerance and the organization's criteria, and reflect both weaknesses and satisfactory performance. Under the IPPF (Standard 2410.A1, carried forward in the Global Internal Audit Standards), final engagement communications must include applicable conclusions along with recommendations or action plans. Communications should be accurate, objective, clear, concise, constructive, complete, and timely. Many organizations use rating scales such as satisfactory, needs improvement, or unsatisfactory to express conclusions consistently. An overall opinion is broader. It addresses governance, risk management, or control across the organization or a large segment of it, often over a defined period such as a year. Under Standard 2450 (Overall Opinions), and its equivalent in the Global Internal Audit Standards, such an opinion must consider senior management, board, and stakeholder expectations. It must be supported by sufficient, reliable, relevant, and useful information, typically drawn from multiple engagements, the work of other assurance providers, and follow-up results. The communication should state the scope and time period covered and any scope limitations. It should identify the projects relied upon and the use of other assurance providers. It should describe the risk or control framework or other criteria used, and summarize the opinion and the reasons for it, including unfavorable conclusions. The chief audit executive is responsible for issuing overall opinions. Exam candidates should distinguish engagement-level conclusions from organization-wide opinions and recognize the evidence, criteria, and disclosure requirements behind each.
Stating Conformance with the Global Internal Audit Standards
Under the IIA's Global Internal Audit Standards (effective January 2025), internal auditors may state that their work conforms with the Standards only when that claim is supported by evidence. This topic falls under Engagement Results and Monitoring because the statement usually appears in final engagement communications and reports to the board.
1. Basis for the statement: Under Standard 4.1, Conformance with the Global Internal Audit Standards, internal auditors must plan and perform services in accordance with the Standards. A statement such as 'conducted in conformance with the Global Internal Audit Standards' is appropriate only when the quality assurance and improvement program supports it. That support comes from ongoing monitoring, periodic self-assessments (Standard 12.1, Internal Quality Assessment) and an external quality assessment performed at least once every five years by a qualified, independent assessor or team (Standard 8.4, External Quality Assessment).
2. Responsibility of the chief audit executive (CAE): The CAE decides whether the function can make the statement. The CAE also communicates quality assessment results, including any significant nonconformance, to the board and senior management. Making the statement without supporting evidence misleads stakeholders and violates the principles of integrity and professionalism.
3. Disclosing nonconformance: Legal or regulatory restrictions, resource limits or other circumstances may prevent full conformance. When this happens, internal auditors should document and disclose:
- the requirements that were not met,
- the reasons for the nonconformance,
- any alternative actions taken, and
- the effect on the engagement and its results.
If the nonconformance affects a specific engagement, the disclosure belongs in that engagement's communication.
4. Related requirements: When internal audit follows other authoritative guidance alongside the Standards, such as government auditing standards, the function may cite conformance with both where appropriate. Any differences between the requirements must be recognized and documented.
Exam tip: CIA candidates should remember that the conformance statement is a claim that must be earned through the quality assurance and improvement program. Any nonconformance that affects an engagement must be disclosed openly rather than hidden.
Documenting and Reporting Scope Limitations
A scope limitation is any restriction that prevents internal auditors from performing the work needed to achieve engagement objectives. Common examples are denied or delayed access to records, personnel, or physical properties; budget or time constraints imposed by management; missing or unreliable data; and management directing auditors to exclude certain areas. Under the IIA's International Professional Practices Framework, including the Global Internal Audit Standards, scope limitations can impair objectivity or organizational independence, so they must be identified, documented, and communicated.
Documentation: Auditors should record the limitation in the engagement workpapers. This includes its nature, when and how it arose, who imposed it, which objectives or procedures it affected, and any alternative procedures attempted. Workpapers should show whether enough relevant, reliable, and useful evidence was still obtained to support conclusions. Good documentation supports supervisory review, quality assurance, and later disputes about the basis of an opinion.
Resolution and escalation: When a limitation arises, the auditor should first discuss it with the engagement supervisor and the chief audit executive (CAE). The CAE may try to resolve it with management. If it cannot be resolved, the CAE must escalate it to senior management and the board or audit committee. A scope limitation imposed by senior management is especially serious because it threatens the internal audit mandate set out in the charter.
Reporting: Final engagement communications must state the engagement scope accurately, including areas that were excluded or limited and the reasons. Auditors should explain how the limitation affects the conclusions. Depending on its significance, this may mean qualifying an opinion, issuing a limited-assurance statement, or declining to give an opinion on affected areas. Reports must not imply assurance over areas that were not adequately examined.
Monitoring: The CAE should track recurring or significant limitations and include them in periodic reporting to the board. The CAE should also consider their effect on the audit plan, overall opinions, and conformance with the Standards. If limitations lead to nonconformance, that impact must be disclosed.
Developing Recommendations
In the Certified Internal Auditor curriculum, developing recommendations is the step that turns engagement findings into practical improvement actions. (Under the current CIA syllabus this topic sits mainly in Part 2, Practice of Internal Auditing, but it builds on the same engagement concepts.) A recommendation follows from the elements of a finding. The criteria describe what should be, the condition describes what is, the cause explains why the gap exists, and the effect describes the risk or impact. The most important principle is that recommendations should address the root cause rather than only the symptoms. For example, recommending a one-time correction of misposted invoices fixes the condition. Recommending better system validation controls and staff training addresses why the errors happened, so they do not recur. Effective recommendations are specific, actionable, realistic, and cost-effective. The cost of implementing a control should not exceed the benefit of the risk it reduces. They should also be prioritized according to the significance of the risk, so management can focus first on high-impact issues. The Global Internal Audit Standards (Standard 14.4) expect internal auditors to develop recommendations or acknowledge management's action plans, and to discuss them with management before finalizing the communication. Collaboration matters because management is responsible for deciding on and implementing corrective actions. Internal auditors should not assume management responsibilities, since doing so would impair their objectivity and independence. Auditors may suggest alternatives, but management may choose a different solution if it adequately addresses the risk. If management accepts a level of risk the chief audit executive believes is unacceptable, the CAE should discuss it with senior management and, if unresolved, escalate it to the board. Final communications typically include the recommendation, management's response, the responsible owner, and target completion dates. These details support the monitoring process, in which the internal audit activity follows up to confirm that actions were implemented effectively. On exam questions, favor answers that target root causes, are practical, are agreed with management, and preserve auditor objectivity.
Management Action Plans and Root Cause
Note: Under the 2025 CIA syllabus, engagement results and monitoring sit mainly in Part 2 (Practice of Internal Auditing); earlier syllabi placed related topics elsewhere. The concepts below apply either way.
Root cause is the underlying reason a condition differs from the criteria. A finding is commonly framed using condition (what is), criteria (what should be), cause (why the gap exists) and effect (the risk or impact). The Global Internal Audit Standards (2024) expect auditors to identify root causes where possible when evaluating findings (Standard 14.3). Symptoms, such as an unapproved payment, often trace back to deeper causes, such as unclear policies, inadequate training, poor system design, insufficient resources, misaligned incentives or weak tone at the top. Techniques include the 5 Whys, fishbone (Ishikawa) diagrams, process mapping, fault tree analysis and data analytics. Fixing the root cause prevents recurrence and adds more value than correcting isolated errors. It also helps auditors spot themes that recur across engagements.
Management action plans are management's documented commitments to address findings. Under Standard 14.4, internal auditors develop recommendations or discuss with management its proposed actions. An effective plan addresses the root cause, assigns a specific owner, sets realistic deadlines and defines measurable outcomes. Auditors assess whether proposed actions are adequate for the risk. Management, not internal audit, owns and implements them, which preserves auditor objectivity. Disagreements are documented in the final communication, along with management's view.
Monitoring follows the engagement. Standard 15.2 requires the chief audit executive to confirm that management has implemented the recommendations or action plans, or has accepted the risk of not acting. Follow-up methods include inquiry, reviewing evidence, retesting controls or a separate follow-up audit, scaled to the significance of the risk. If management accepts a level of risk that the CAE believes exceeds the organization's risk appetite, the CAE must discuss it with senior management. If the issue remains unresolved, the CAE escalates it to the board.
Exam tip: Choose answers that target root causes, keep management accountable for action and ensure systematic follow-up.
Cost-Benefit Considerations for Recommendations
In the CIA syllabus, cost-benefit considerations help internal auditors make recommendations that are practical, proportionate, and likely to be implemented. A recommendation should fix the root cause of a finding without costing the organization more than the risk it reduces. IIA Standards require auditors to communicate results that are accurate, objective, clear, concise, constructive, and timely. A recommendation that is too expensive or impractical is not constructive.
Costs include direct expenses such as new technology, staff, training, or consultants. They also include indirect costs, such as slower processes, lost productivity, operational disruption, extra complexity, and the ongoing cost of monitoring. Benefits include fewer losses, lower fraud risk, better regulatory compliance, greater efficiency, more reliable information, stronger reputation, and better achievement of objectives. Some benefits are hard to measure in money, so auditors may weigh qualitative factors alongside numbers.
A key principle is that internal controls offer reasonable, not absolute, assurance. Controls cost money, so management sets them in line with its risk appetite. Auditors should judge how significant a finding is, both in likelihood and impact, and match the strength of the recommendation to that level of risk. Severe risks may justify large investments. Minor issues may call for simple compensating controls, or management may decide to accept the risk.
Auditors should discuss recommendations with management before the final report. Management usually knows the costs and practical limits best, and early discussion builds agreement on corrective action plans. Management is responsible for deciding what action to take. If management accepts a level of residual risk that the chief audit executive believes is unacceptable, the CAE must discuss it with senior management and, if it remains unresolved, escalate it to the board.
During monitoring and follow-up, auditors check whether management's actions were carried out and work as intended. This links cost-benefit analysis to lasting value and continuous improvement.
Resolving Disagreements with Management
Resolving disagreements with management is a key part of communicating engagement results and monitoring progress. Internal auditors and management may disagree about the facts, the root cause, the significance of a finding, the risk rating, or the corrective action proposed. The goal is not to win an argument but to reach accurate, objective, and useful conclusions that serve the organization.
The process usually starts with factual accuracy. Auditors should discuss preliminary observations with management throughout the engagement and at the exit or closing meeting. This gives management a chance to provide evidence the auditor may have missed. If management proves that a finding is factually wrong, the auditor should correct it. Disagreements are often prevented by clear communication, early sharing of observations, and well-documented, sufficient, reliable, relevant evidence in the workpapers.
When disagreement remains after discussion, the auditor does not drop or water down a supported finding just to satisfy management. Doing so would harm objectivity. Instead, the final engagement communication should present the auditor's conclusion and also state management's position and the reasons for the disagreement. This lets readers judge both views fairly.
A special case arises when management accepts a level of risk that the chief audit executive (CAE) believes may be unacceptable to the organization. The IIA Standards, under the former Standard 2600 and Standard 11.5 of the 2024 Global Internal Audit Standards, call for a set escalation path. First, the CAE discusses the matter with senior management. If the matter is still unresolved, the CAE must communicate it to the board. Internal audit itself does not resolve the risk. Its role is to make sure the right decision-makers are informed.
During monitoring and follow-up, the CAE tracks whether management carries out its agreed action plans. If management fails to act, this may also be treated as risk acceptance and escalated in the same way.
For the exam, remember four key points: base conclusions on evidence, document management's view, keep objectivity, and escalate unresolved significant risk acceptance to senior management and then the board.
Closing Communication and the Exit Conference
In the CIA syllabus on Engagement Results and Monitoring, the closing communication and exit conference are the final steps of fieldwork. They make sure engagement results are accurate, understood, and accepted before the final report is issued. Under the IIA Global Internal Audit Standards, internal auditors should discuss findings, recommendations, and conclusions with management before finalizing communications (Standards 14.3 to 14.6).
The exit conference, also called the closing meeting, is usually held after fieldwork and before the final report. Attendees normally include the engagement supervisor or audit manager, the auditors who did the work, and client management who own the process and can commit to corrective action. Senior management may attend for significant engagements.
Key objectives include:
1. Validating facts. Management confirms that the conditions, criteria, causes, and effects of each finding are accurate and complete. This reduces the risk of factual errors in the report.
2. Avoiding surprises. Findings should already have been shared during the engagement, so the exit conference confirms rather than reveals issues.
3. Agreeing on action plans. Management states its responses, the corrective actions it will take, who is responsible, and target completion dates.
4. Resolving disagreements. If management disagrees, both positions are documented. The auditor's independent opinion is not changed simply to reach consensus, and management's view may be included in the final report.
5. Communicating the overall conclusion and rating of significance.
A draft report is often circulated before or during the meeting. Auditors should prepare an agenda, rank findings by significance, use a constructive and objective tone, and document the discussion in the workpapers.
After the exit conference, the chief audit executive reviews and approves the final communication. The CAE then distributes it to appropriate parties, such as management and, where warranted, the board.
The agreed action plans become the basis for monitoring and follow-up (Standard 15.2). Through follow-up, internal audit confirms that management has implemented its actions or has accepted the risk of not acting. If accepted risk exceeds the organization's risk appetite, it is escalated to senior management or the board.
Distributing Final Engagement Communications
Distributing final engagement communications is the last step in reporting engagement results. It ensures that the right people receive accurate conclusions, recommendations, and action plans so they can act on them. Under the IIA's Global Internal Audit Standards (Standard 15.1, Final Engagement Communication) and the earlier Standard 2440 (Disseminating Results), the chief audit executive (CAE) is responsible for communicating results to the appropriate parties. The CAE may delegate preparation and distribution but keeps overall responsibility.
Who should receive the report? Distribution should include parties who can ensure results get due consideration and who can take corrective action or ensure it is taken. These typically include the engagement client or process owner, management accountable for the area, senior management, and, where appropriate, the board or audit committee. Recipients may be given different levels of detail. For example, the board may receive a summary of significant findings, while operational management receives the full report.
Communicating outside the organization requires extra caution. Unless law, regulation, or the internal audit charter requires otherwise, the CAE should first assess the potential risk to the organization. The CAE should also consult senior management or legal counsel as appropriate. Finally, the CAE should control dissemination by restricting how the results may be used, for example through confidentiality statements.
If a final communication contains a significant error or omission, the CAE must send corrected information to every party who received the original. This protects the reliability of internal audit's work.
When results are distributed, the report should be accurate, objective, clear, concise, constructive, complete, and timely. Distribution often triggers the monitoring process. The CAE must establish and maintain a system to track whether management has implemented agreed actions, or whether senior management has accepted the risk of not acting.
For the CIA exam, remember three points:
- The CAE owns distribution.
- External release requires a risk assessment, consultation, and restrictions on use.
- Corrections go to all original recipients.
Communicating Results to Different Stakeholders
Communicating results is how internal auditors turn engagement work into value. Note that in the current CIA syllabus this topic is usually tested in Part 2 (Practice of Internal Auditing), but the principles below apply wherever it appears. Under the IIA Global Internal Audit Standards (Domain V, formerly the 2400 series), communications must be accurate, objective, clear, concise, constructive, complete, and timely. The key skill is tailoring content, detail, and format to each audience while keeping the conclusions consistent.
Board and Audit Committee: These stakeholders need a strategic view. Communications focus on significant risk exposures, control issues, fraud risks, governance concerns, overall engagement conclusions, and trends across engagements. Formats include executive summaries, dashboards, heat maps, and periodic reports from the Chief Audit Executive (CAE). Detail is limited and the emphasis is on what matters to oversight.
Senior Management: Executives need findings ranked by significance, root causes, business impact, and management action plans with owners and due dates. They also need to know when management has accepted a level of risk that may be unacceptable. The CAE must discuss this with senior management and, if it is not resolved, escalate it to the board.
Operational Management and Process Owners: These users need the detailed findings, structured around criteria, condition, cause, and effect, plus practical recommendations. Exit meetings let them confirm facts, avoid surprises, and agree on corrective actions before the final report is issued.
External Parties: Regulators, external auditors, and other outside parties may receive results only when the CAE has assessed the potential risk, consulted senior management or legal counsel as appropriate, and controlled how the information can be distributed and used.
Other Requirements: If a final communication contains a significant error or omission, the CAE must send corrected information to everyone who received the original. The CAE is responsible for disseminating final results to the appropriate parties.
Monitoring: Communication does not end when the report is issued. Internal audit must establish a follow-up process to confirm that management has implemented its actions effectively and to report the status of open issues to stakeholders.
Reporting Findings Already Resolved by Management
In the CIA Part 3 domain of Engagement Results and Monitoring, a common question is how to handle findings that management corrects before the final engagement report is issued. Internal auditors often share observations with management while fieldwork is still underway. Management may then fix a control weakness, recover a loss, or update a procedure before the report is finalized.
The general principle is that significant findings should still be reported, even if they have already been resolved. Communications must be accurate, objective, clear, concise, constructive, complete, and timely. Leaving out a significant issue simply because it was fixed would make the report incomplete. Senior management and the board would lose information about the risk exposure that existed, its root cause, and whether similar weaknesses may exist elsewhere. Reporting the issue also gives a historical record and supports accountability.
The report should describe the condition, criteria, cause, and effect. It should then state clearly that management has already taken corrective action. This balanced presentation recognizes management's responsiveness, which supports constructive communication and good client relationships. Before describing an issue as resolved, the auditor should verify the corrective action, such as by testing the revised control or reviewing evidence. Otherwise the auditor should note that the action has not yet been validated and may require follow-up.
Professional judgment governs how each finding is treated. Minor or low-risk issues that are corrected immediately may be communicated informally, for example in a memo or closing meeting, rather than in the formal report. These informal communications should still be documented in the engagement workpapers. Significant or systemic issues, fraud indicators, and matters relevant to governance belong in the formal report regardless of their status.
For exam purposes, remember these points: report significant findings even if they are resolved, acknowledge management's corrective action, verify that the fix actually works, and use judgment for minor items. This approach keeps reporting complete while fairly reflecting management's efforts.
Correcting Errors and Omissions in Final Communications
In the Certified Internal Auditor (CIA) curriculum, correcting errors and omissions in final communications is a key quality requirement in the Engagement Results and Monitoring domain. It comes from IIA Standard 2421 (Errors and Omissions) and continues in the 2024 Global Internal Audit Standards under Standard 15.1 (Final Engagement Communication). The rule is that if a final engagement communication contains a significant error or omission, the chief audit executive (CAE) must communicate corrected information to all parties who received the original communication. The Global Standards add that this must be done promptly. An error is an unintentional misstatement, such as incorrect figures, a misattributed finding, or a wrong conclusion. An omission is significant information that was left out, such as a material finding, a scope limitation, or relevant context. Whether an issue is significant is a matter of professional judgment. The CAE considers whether the problem could change a reader's understanding of the results, affect management decisions, alter risk ratings, or influence the board's oversight. Minor typographical or formatting mistakes usually do not trigger formal reissuance. The process typically has four steps. First, the CAE evaluates the nature and impact of the problem. Second, the CAE prepares a corrected or supplementary communication that clearly identifies what changed and why. Third, it is distributed to every original recipient so that no stakeholder relies on flawed information. Fourth, the correction and its rationale are documented in the engagement workpapers. This requirement protects the credibility, accuracy, and objectivity of internal audit. It is also tied to the quality assurance and improvement program, because recurring errors may point to weaknesses in supervision or review. Strong supervisory review before issuance is the main preventive control. For the exam, remember three points: the CAE is responsible, the threshold is significance, and corrected information must reach all original recipients, not just senior management.
Assessing Residual Risk for the Engagement
Assessing residual risk is the internal auditor's judgment about how much risk remains after management's controls and other responses have been applied. Inherent risk is the exposure before any controls. Residual risk is what is left once the design and operating effectiveness of those controls are taken into account. (In the current CIA syllabus, this topic sits mainly in Part 2, Practice of Internal Auditing, under communicating results and monitoring progress.)
During the engagement, the auditor first identifies key risks and the controls meant to address them. Testing then shows whether each control is well designed and works consistently. If controls are missing, poorly designed, or not operating effectively, residual risk is higher than management may believe. The auditor rates each finding by its likelihood and impact and compares the residual risk with the organization's risk appetite and tolerance.
This assessment shapes how results are communicated. Findings are prioritized by significance, often rated high, medium, or low, so senior management and the board can focus on the most critical exposures. Recommendations aim to bring residual risk back within acceptable limits, for example by strengthening controls, transferring risk through insurance, or redesigning processes. The overall engagement conclusion, such as satisfactory or needs improvement, also reflects the combined residual risk.
Residual risk also drives monitoring. Under the IIA Standards (formerly Standard 2500, now Global Internal Audit Standard 15.2), the chief audit executive must track whether management has implemented agreed actions. Follow-up work verifies that corrective actions actually reduced residual risk rather than merely being documented.
Sometimes management chooses to accept a risk instead of fixing it. If the chief audit executive concludes that management has accepted a level of risk that may be unacceptable to the organization, it must be discussed with senior management (formerly Standard 2600, now Standard 11.5). If the matter is not resolved, it must be escalated to the board. This makes residual risk central to accountability and to effective governance.
Aggregating and Prioritizing Findings
Aggregating and prioritizing findings is the step where internal auditors turn individual observations into meaningful, risk-focused conclusions before communicating engagement results. Under the Global Internal Audit Standards (notably Standard 14.3, Evaluation of Findings, and Standard 14.5, Engagement Conclusions), auditors must evaluate each finding's significance and then consider findings collectively. Note that in the current CIA syllabus this content sits mainly in Part 2 (Practice of Internal Auditing), though it is often studied alongside reporting and monitoring topics.
Aggregation means combining related findings to reveal their true significance. Several minor control weaknesses that look immaterial on their own may, together, point to a systemic problem such as a weak control environment, inadequate training or a flawed process design. Auditors group findings by common root cause, process, risk category or business unit. This helps them avoid reporting scattered symptoms and instead address underlying causes, which supports more effective and lasting recommendations. Aggregation also works across engagements: the chief audit executive combines results from multiple audits to identify organization-wide themes and to support any overall opinion given to the board and senior management.
Prioritization means ranking findings by significance so that management and the board can focus on what matters most. Auditors assess the likelihood and potential impact of the underlying risk, both quantitative factors such as financial loss and qualitative factors such as reputational, regulatory, safety or strategic consequences. They compare these against the organization's risk appetite and tolerance. Findings are then commonly rated using a defined scale, such as high, medium and low or critical, major and minor. The methodology should be documented, applied consistently and understood by stakeholders.
Prioritized findings shape the final communication. The most significant issues are typically presented first, often in an executive summary, along with the overall engagement conclusion. Priority ratings also drive monitoring: high-priority issues usually require faster corrective action, closer follow-up and possible escalation if management accepts a level of risk that exceeds the organization's risk appetite.
Engagement Rating Scales
Engagement rating scales are standardized tools internal auditors use to summarize and communicate how significant engagement findings are and, often, the overall condition of the area reviewed. In the CIA syllabus, this topic sits under communicating engagement results and monitoring progress (currently Part 2, Practice of Internal Auditing). Rating scales support the requirement that final communications include conclusions or opinions and that findings be prioritized by significance.
There are two common levels of rating. At the finding level, individual observations are rated, often High, Medium or Low, based on the impact and likelihood of the related risk, the extent of control weakness, and possible financial, regulatory or reputational consequences. At the engagement level, an overall opinion summarizes the adequacy and effectiveness of governance, risk management and control processes. Examples include Satisfactory, Needs Improvement and Unsatisfactory, or Effective, Partially Effective and Ineffective.
Formats include descriptive labels, numeric scores (1 to 5), and color codes such as red, amber and green. Whatever the format, the criteria for each rating should be clearly defined, documented in the internal audit methodology, agreed with senior management and the board, and applied consistently across engagements.
Ratings offer several benefits. They let busy executives and the board grasp results quickly, they focus attention on the highest-priority issues, they allow comparison and trend analysis across audits and periods, and they help allocate resources. They also drive monitoring. High-rated findings usually require shorter remediation deadlines, more rigorous follow-up, testing of corrective actions, and escalation if they are not resolved. If management accepts a level of risk the chief audit executive believes is unacceptable, the CAE must discuss it with senior management and, if unresolved, communicate it to the board.
Limitations include oversimplification, subjectivity, inconsistency among auditors, and defensive reactions from auditees. To reduce these risks, auditors should support every rating with clear evidence and explanatory narrative, calibrate ratings through quality review, and discuss ratings with management before issuing the final report.
Determining Whether a Risk Is Unacceptable
Determining whether a risk is unacceptable is a key judgment the Chief Audit Executive (CAE) makes during the engagement results and monitoring phase. Under IIA Standard 2600 (Global Internal Audit Standards Standard 11.5, Communicating the Acceptance of Risks), when the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the issue is not resolved, the CAE must communicate it to the board.
The situation usually arises during follow-up. Internal audit monitors whether management has implemented agreed corrective actions. If management fails to act, delays indefinitely, or explicitly decides not to address a finding, management has effectively accepted the residual risk. The CAE must then judge whether that acceptance is appropriate.
Key criteria include:
1. Risk appetite and tolerance: Does the residual risk exceed the limits approved by the board or set out in the risk management framework?
2. Impact and likelihood: Could the risk materially harm strategic, operational, financial, or compliance objectives?
3. Legal and regulatory exposure: Does accepting the risk create possible violations, fines, or sanctions?
4. Reputational and ethical consequences: Could stakeholder trust be damaged, or does the risk conflict with the organization's code of conduct?
5. Authority: Was the risk accepted by someone with the proper level of authority to do so?
6. Cost-benefit: Is the cost of mitigation clearly disproportionate to the risk, or is management simply avoiding the effort?
7. Aggregation: Do several individually minor risks combine into a significant exposure?
The CAE should document the analysis, management's rationale, and the communications that follow. Internal audit's role is not to accept or resolve the risk itself, because doing so would impair its independence. Instead, it ensures that risk acceptance decisions are transparent and made by the appropriate level of governance.
Escalation follows a clear path. The CAE first discusses the matter with the responsible manager, then with senior management, and finally with the board if necessary. This sequence reinforces internal audit's assurance role and supports sound governance.
Communicating Risk Acceptance
Communicating risk acceptance covers what the Chief Audit Executive (CAE) must do when management decides to accept a risk instead of fixing it. Under the IIA Standards (formerly Standard 2600, now Standard 11.5 of the Global Internal Audit Standards), if the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the CAE still believes the issue has not been resolved, the CAE must communicate it to the board. This topic falls under Engagement Results and Monitoring because risk acceptance usually appears during monitoring and follow-up. For example, management may decline to implement agreed corrective actions, delay them indefinitely, or say the cost of remediation outweighs the benefit. Management may legitimately accept risk, since it owns risk and decides how to respond to it. Internal audit's role is to judge whether the accepted risk exceeds the organization's risk appetite or tolerance, conflicts with policy or regulation, or could seriously harm the organization's objectives or reputation. The process typically follows these steps: (1) identify the accepted risk through follow-up or engagement work; (2) understand management's rationale, any compensating controls, and the decision authority involved; (3) assess the residual risk against established risk appetite; (4) document the acceptance and the discussions; (5) discuss concerns with senior management; and (6) escalate unresolved matters to the board, which makes the final governance decision. Key exam points: internal audit does not resolve the risk or override management, because doing so would impair objectivity. The CAE's duty is to communicate and escalate. Communication should be timely, objective, and supported by evidence. The board, not internal audit, decides whether the accepted risk is appropriate. Documenting risk acceptance also protects the internal audit activity and supports accountability, transparency, and effective governance.
Follow-Up and Tracking of Management Action Plans
Follow-up and tracking of management action plans is how internal audit makes sure that agreed engagement results lead to real change. (Note: in the current CIA syllabus, this topic sits under Engagement Results and Monitoring in Part 2, Practice of Internal Auditing. It also connects to Part 3 governance concepts.) Under the IIA's Global Internal Audit Standards, mainly Standard 15.2, and the earlier Standard 2500, the chief audit executive must establish and maintain a process to monitor and confirm that management has implemented recommendations or action plans. Management owns the implementation. Internal audit's role is to verify progress and report on it, not to perform the corrective work. Each action plan should state the specific actions, a responsible owner, and a target completion date. Internal audit records these in a tracking system, often audit management software, and monitors their status: open, in progress, overdue, or closed. The depth of follow-up depends on risk. High-risk issues may call for testing evidence, re-performing controls, or a separate follow-up engagement. Lower-risk items may be closed on the basis of management's written confirmation and supporting documentation. Timing should reflect the significance of the issue, and the follow-up process should be defined in the internal audit charter or methodology. Internal audit regularly reports implementation status to senior management and the board. These reports highlight overdue, repeatedly extended, or inadequately addressed actions, which strengthens accountability. If management decides not to act, it is accepting risk. If the chief audit executive concludes that management has accepted a level of risk that may be unacceptable to the organization, the matter must be discussed with senior management. If it is not resolved, it must be communicated to the board (Standard 11.5; formerly Standard 2600). Effective follow-up shows the value of internal audit and feeds into future risk assessments and audit planning. It also supports the quality assurance and improvement program by showing whether recommendations were practical. For the exam, remember three points: management implements, internal audit monitors and confirms, and the board resolves unresolved risk acceptance.
Confirming Implementation of Action Plans
Confirming the implementation of action plans is the follow-up stage of an internal audit engagement. The internal audit function verifies that management has actually carried out the corrective actions it agreed to after the engagement results were communicated. (Note: in the current IIA syllabus, this topic sits under Part 2, Practice of Internal Auditing, in the Engagement Results and Monitoring domain.) Under the Global Internal Audit Standards (Standard 15.2), and formerly Standard 2500, the chief audit executive (CAE) must establish a methodology to monitor and confirm that management has implemented recommendations or action plans, or has accepted the risk of not acting.
The process typically involves several steps. First, the function keeps a tracking system that records each finding, the agreed action, the responsible owner, and the target completion date. Second, it does periodic follow-up whose timing and depth depend on the significance of the finding. High-risk issues usually get prompt, on-site verification. Lower-risk items may rely on management's representations. Third, auditors gather evidence to confirm the action works as intended. Methods include inquiry, inspecting documents, observation, re-performance, and testing whether the new controls are operating effectively. A finding should be closed only when evidence supports that the root cause has been addressed.
The CAE reports implementation status to senior management and the board. This report highlights overdue items, repeated extensions, and trends. If management has not taken action, the CAE assesses why. If management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If it remains unresolved, the CAE must communicate it to the board. Internal audit does not decide how to resolve the risk, because management owns that responsibility.
Effective follow-up holds management accountable and shows the value internal audit adds. It reduces the risk of recurring issues and feeds into future risk assessments and audit planning. Exam questions often test who is responsible (management implements, internal audit monitors). They also test the risk-based nature of follow-up and how unacceptable risk acceptance is escalated.
Escalation When Action Plans Are Not Implemented
Escalation when action plans are not implemented is the structured process internal audit follows when management fails to carry out agreed corrective actions by their due dates. It falls under monitoring and follow-up of engagement results. (Note that in the current CIA syllabus, this topic is typically covered in Part 2.) Under the Global Internal Audit Standards (Standard 15.2) and the earlier IPPF Standards 2500 and 2600, the chief audit executive (CAE) must establish and maintain a system to monitor whether management has effectively implemented action plans. Where risks remain unaddressed, the CAE must also act. The process usually moves in steps. First, internal audit tracks open issues, often in an issue-tracking database, and contacts the responsible process owner as deadlines approach or pass. If the action is overdue, the auditor asks why. Common reasons include resource limits, changed priorities, or disagreement about the risk. Management may propose a revised, reasonable timeline, which is documented. If progress still stalls, the issue is escalated to the owner's superior or to senior management. If the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the matter is not resolved, the CAE must communicate it to the board or audit committee. Internal audit's role is to escalate, not to resolve the risk-acceptance decision itself. Effective escalation relies on several features. It needs clear criteria, such as days overdue, risk rating, or repeated deadline extensions. It needs escalation paths that are defined in the internal audit charter or methodology. It requires objective documentation of follow-up efforts, management responses, and risk implications. Regular reporting of overdue items to the board, often through aging reports, is also expected. High-risk findings call for faster escalation and may trigger a follow-up audit. Escalation protects accountability, supports governance, and preserves internal audit's independence. It ensures that significant risks are not quietly ignored and that the board is informed about risk acceptance decisions.
Accurate and Objective Communications
Accurate and objective communications are core quality criteria for internal audit engagement results. In the IIA's International Professional Practices Framework, they appear in Standard 2420, Quality of Communications, and in the 2024 Global Internal Audit Standards under Standard 11.2, Effective Communication. Note that in the current CIA syllabus, communicating engagement results is mainly tested in Part 2, although the principles apply to all internal audit reporting.
Accuracy means communications are free from errors and distortions and faithfully reflect the underlying facts. Every observation, finding, conclusion and recommendation must be supported by sufficient, reliable, relevant and useful evidence documented in the working papers. Auditors achieve accuracy by verifying data, reconciling figures, confirming facts with process owners, and having supervisors review the work before it is released. Accuracy builds credibility. One factual error can lead management to dismiss an entire report.
Objectivity means communications are fair, impartial and unbiased. They result from a balanced assessment of all relevant facts and circumstances. Objective reports avoid emotional, inflammatory or accusatory language. They present conditions without exaggeration and recognize satisfactory performance alongside deficiencies. Objectivity follows from the auditor's independent mental attitude and freedom from conflicts of interest. It is supported by structured findings that state the criteria, condition, cause, effect and recommendation.
When a final communication contains a significant error or omission, the chief audit executive must send corrected information to everyone who received the original communication. This requirement appears in Standard 2421, Errors and Omissions, and is also reflected in the 2024 Standards.
Accuracy and objectivity work together with the other quality attributes: clear, concise, constructive, complete and timely. Practical techniques include:
- discussing draft findings with management before finalizing them;
- including management's responses;
- using neutral wording;
- applying quality assurance reviews.
For the exam, remember that accuracy relates to factual correctness, while objectivity relates to fairness and absence of bias. Both are essential for stakeholders to trust and act on internal audit results.
Clear and Concise Communications
Clear and concise communication is a core quality attribute of internal audit engagement results. Under the IIA's former Standard 2420 (Quality of Communications), communications must be accurate, objective, clear, concise, constructive, complete, and timely. The 2024 Global Internal Audit Standards keep these attributes under Standard 11.2 (Effective Communication). Note that in the current CIA syllabus, engagement communication and monitoring fall mainly under Part 2, though older materials linked them to Part 3. Clear communication is logical and easy to understand. It avoids unnecessary technical jargon, defines specialized terms when they must be used, and gives all significant and relevant information. Clarity improves when auditors use a logical structure, plain language, headings, and visual aids such as tables or charts. Each observation should follow a coherent format: criteria (what should be), condition (what is), cause (why it happened), effect or risk (why it matters), and the recommendation or management action plan. Concise communication is to the point. It avoids redundancy, excessive detail, wordiness, and unrelated information. Conciseness does not mean leaving out essential facts. Communications must still be complete. The goal is to help busy stakeholders, such as senior management and the board, quickly grasp key results, their significance, and the actions required. An executive summary that highlights the most significant issues supports this goal. The detailed findings can follow for operational management. For exam purposes, candidates should recognize how these qualities support the purpose of engagement results. Clear and concise reports help management understand risks and take timely corrective action. That understanding makes the monitoring and follow-up process more effective, because responsibilities and action plans are clearly defined. Reports that are cluttered, ambiguous, or overly long risk misunderstanding, delayed responses, and reduced credibility for the internal audit function. Exam questions often ask candidates to identify which attribute a report lacks. Unneeded elaboration, for example, points to a lack of conciseness, while confusing terminology points to a lack of clarity.
Constructive, Complete, and Timely Communications
Constructive, complete, and timely are three of the qualities internal audit communications must have. The others are accurate, objective, clear, and concise. These qualities appear in IIA Standard 2420 (Quality of Communications) and in Standard 11.2 (Effective Communication) of the 2024 Global Internal Audit Standards. Engagement results and monitoring are tested mainly in CIA Part 2 under the current syllabus, but the concepts are the same whichever part you are studying.
Constructive communications help the engagement client and the organization and lead to improvements where needed. A constructive report goes beyond listing deficiencies. It explains the causes of issues, offers practical recommendations or action plans, and uses a collaborative, professional tone rather than an accusatory one. It may also acknowledge satisfactory performance. This encourages management to accept findings and take ownership of corrective actions, which strengthens governance, risk management, and control processes.
Complete communications lack nothing essential to the target audience. They include all significant and relevant information and observations that support the recommendations and conclusions. This typically covers the engagement objectives, scope, results, criteria, condition, cause, effect, recommendations, management's action plans, and an overall conclusion or opinion where appropriate. Being complete does not mean including every detail. It means readers have enough information to understand the issues and make informed decisions without misleading omissions.
Timely communications are well-timed and expedient, depending on how significant the issue is. They allow management to take appropriate corrective action before risks materialize or worsen. Internal auditors should communicate serious issues promptly, even before the final report is issued, for example through interim or oral communications. Timeliness should be planned with the organization's decision-making cycle in mind. Delayed reports lose relevance and value.
Together, these qualities make communications credible, useful, and actionable. They also support the chief audit executive's monitoring process, which tracks whether management has implemented its action plans or accepted the risk of not taking action.
Objectives and Scope Sections of the Final Report
In the CIA syllabus, the final engagement report communicates what internal audit set out to do, what it covered, and what it found. Under the IIA Standards (formerly Standard 2410, now Standard 15.1 of the Global Internal Audit Standards), final communications must include the engagement objectives, scope, conclusions, and recommendations or action plans. The objectives and scope sections give readers the context needed to interpret the results correctly.
Objectives Section: This section states the purpose of the engagement, meaning what the auditors were trying to accomplish. Objectives are usually linked to the risks and controls identified during planning. Examples include evaluating the effectiveness of procurement controls, assessing compliance with data privacy regulations, or determining whether inventory is safeguarded. Clear objectives show the board and senior management why the engagement was performed and how it supports organizational goals. They also form the basis for the conclusions: each objective should be addressed by a corresponding conclusion, so readers can see whether the purpose was achieved.
Scope Section: This section defines the boundaries of the engagement. It typically describes the processes, systems, locations, business units, and time period reviewed, and may summarize the nature and extent of the work performed. Importantly, it should identify anything excluded, along with any scope limitations, such as restricted access to records, personnel, or properties. Disclosing limitations prevents readers from assuming assurance over areas that were not examined. If the scope changed during fieldwork, the report should reflect the final scope actually covered.
Why They Matter: Together, these sections establish the reliability and limits of the assurance provided. They help manage stakeholder expectations, reduce misinterpretation, and protect the internal audit activity from claims that it overlooked areas never included in the engagement. For exam purposes, remember that objectives explain the why, scope explains the what, where, and when, and both must be clear, accurate, concise, and consistent with the engagement work program.
When to Request Action Plans from Management
In the CIA syllabus, engagement results and monitoring cover how internal auditors communicate findings and make sure management responds to them. Action plans are management's documented commitments to fix identified issues. Under the Global Internal Audit Standards, internal auditors develop recommendations or collaborate on solutions, but management owns the remediation.
Timing: Auditors request action plans after findings are developed, validated, and discussed with management. Validation means the condition, criteria, root cause, and effect have been established and the significance has been rated. The usual point is the closing or exit meeting, or immediately after the draft report is shared. Requesting plans before the final communication lets management's responses be included in the final report. The board and senior management then see both the problem and the agreed solution.
Triggers: Action plans should be requested whenever a finding shows a meaningful gap between the condition and the criteria. Examples include control deficiencies, noncompliance, inefficiencies, or unmitigated risks. Significant or high-rated findings always require formal plans. Lower-rated observations may be handled informally, depending on the internal audit methodology. Auditors should not request plans before the root cause is understood, because remediation may then address symptoms rather than causes.
Content: A good action plan specifies the corrective actions, the accountable owner, and realistic target completion dates. These should be proportionate to the risk. Auditors assess whether the proposed actions adequately address the root cause. If they do not, auditors discuss alternatives with management.
Disagreement and risk acceptance: If management disagrees or declines to act, auditors document management's position. If management accepts a level of risk that exceeds the organization's risk appetite, the chief audit executive discusses it with senior management. If the matter remains unresolved, the CAE escalates it to the board.
Monitoring: After plans are agreed, internal audit tracks implementation through a follow-up process. It confirms completion and reports the status of overdue or open actions to senior management and the board.
Collaborating with Management to Agree on Actions
Note: Under the current CIA syllabus, communicating engagement results and monitoring progress is usually covered in Part 2. Collaborating with management to agree on actions is the step where internal auditors and the responsible managers turn engagement findings into practical, owned plans to fix problems. Under the IIA's Global Internal Audit Standards (Standard 14.4, Recommendations and Action Plans), auditors develop recommendations or identify opportunities for improvement. They then discuss these with management, who is responsible for creating and carrying out action plans.
The process usually starts before the final report. Auditors share preliminary findings in exit meetings or draft reports. This lets management confirm the facts, give context, and raise concerns. The goal is to agree on the condition, criteria, root cause, and effect of each finding. Root cause matters most, because an action plan that only treats symptoms is unlikely to stop the problem from recurring.
Management then proposes specific actions. Each action should have a clearly named owner and realistic completion dates. Auditors assess whether the planned actions actually address the root cause and reduce risk to an acceptable level. The auditor's role is advisory. Auditors can challenge weak plans and suggest alternatives, but they should not take ownership of implementation. Taking ownership would impair their objectivity.
If auditors and management disagree, the engagement communication should present both positions fairly. If management accepts a level of risk that the chief audit executive believes exceeds the organization's risk appetite, the CAE must discuss it with senior management (Standard 11.5, Communicating the Acceptance of Risks). If the matter remains unresolved, the CAE escalates it to the board.
The agreed actions are documented in the final engagement communication. They also form the basis for monitoring. Under Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, the internal audit function follows up to confirm the actions were implemented effectively. It then reports the status to senior management and the board.
Effective collaboration builds trust, improves buy-in, increases implementation rates, and strengthens internal audit's value as a trusted advisor while preserving independence.
Purpose of the Closing Communication
The closing communication, often called the exit meeting or closing conference, is the formal discussion between the internal auditor and engagement client management at the end of fieldwork and before the final report is issued. Note that in the current CIA syllabus, communicating engagement results and monitoring progress are tested mainly in Part 2, though the concepts also support Part 3 topics on managing the internal audit activity. The closing communication serves several purposes.
First, it confirms the accuracy of findings. Auditors present preliminary observations, conclusions, and recommendations so management can verify the facts and correct any misunderstandings. This lowers the risk of issuing a report that contains errors, which could damage the credibility of the internal audit activity.
Second, it supports a no-surprises approach. Management should already know about significant issues raised during the engagement. The closing meeting formally consolidates them so the final report contains nothing unexpected, which builds trust and cooperation.
Third, it gives management an opportunity to respond. Management can explain their perspective, provide additional evidence, and discuss or commit to corrective action plans, including responsible parties and target dates. These responses are often included in the final report and form the basis for later monitoring and follow-up.
Fourth, it helps resolve disagreements. If management disagrees with findings or recommendations, the meeting allows both sides to discuss the issue. Unresolved disagreements, along with both positions, may be documented in the final communication. Under the Standards, if management accepts a level of risk the chief audit executive believes is unacceptable, the CAE must discuss the matter with senior management and, if it remains unresolved, communicate it to the board.
Fifth, it encourages buy-in for improvement. Collaborative discussion makes management more likely to accept and implement recommendations, which advances the purpose of internal audit to add value and improve operations.
Finally, the closing communication can be used to gather feedback on the engagement process. That feedback supports the quality assurance and improvement program.
Parties Involved in the Exit Conference
The exit conference, also called the closing meeting, takes place near the end of fieldwork and before the final engagement report is issued. Its purpose is to discuss preliminary observations, confirm the accuracy of facts, resolve misunderstandings, and obtain management's responses and action plans. Choosing the right participants is essential to its success.
The first party is the internal audit engagement team. This usually includes the auditor-in-charge, who leads the discussion because they have direct knowledge of the work, and the engagement supervisor or audit manager, who provides oversight and can address disputes about conclusions. For sensitive or high-risk engagements, the Chief Audit Executive may attend to show the significance of the issues and to negotiate at a senior level. Staff auditors who performed specific tests may join to explain technical details.
The second party is the engagement client, meaning the management of the activity under review. This includes the manager directly responsible for the audited area and the process owners who will carry out corrective actions. These participants should have the authority to accept findings and commit resources, deadlines, and responsibilities for remediation. Their presence ensures that management responses in the final report are realistic and owned by the right people.
A third group may include senior management or other stakeholders, such as the executive overseeing the auditee's function. Specialists from IT, legal, compliance, or finance may also attend when findings involve their areas. Under the IIA Standards, auditors must discuss findings with appropriate management before finalizing communications.
The board or audit committee normally does not attend. However, it receives the final report and is informed of significant issues, including any unresolved disagreements or risks that management has accepted. Including the correct parties promotes fairness, accuracy, and buy-in. It also supports effective monitoring, because the people who commit to action plans become accountable during follow-up.
Communicating with External Auditors and Regulators
Communicating with external auditors and regulators is part of engagement results and monitoring. It means sharing information outside the internal audit activity in a controlled and coordinated way. Internal auditors communicate with external parties for three main reasons: coordination, reliance, and compliance. Coordinating with external auditors avoids duplicated work, gives assurance coverage across key risks, and can lower total assurance costs. External auditors may use internal audit work papers, risk assessments, or test results. Internal auditors may also rely on external auditors' findings, provided they first assess their competence, objectivity, and due professional care. Regulators may request internal audit reports, observations on control weaknesses, or evidence of remediation, especially in banking, insurance, healthcare, and public sector environments.
The chief audit executive (CAE) normally oversees these relationships. Under the IIA's standards, the CAE should coordinate activities with other assurance providers and keep a clear, open dialogue on scope, timing, methodology, and significant findings. Regular meetings, shared risk maps, and agreed protocols for exchanging information support this.
Releasing results outside the organization requires extra care. Unless law, regulation, or the internal audit charter requires otherwise, the CAE should do the following before disclosure:
- assess the potential risk to the organization;
- consult senior management and/or legal counsel as appropriate;
- control dissemination by restricting how the results may be used.
Confidentiality, legal privilege, data protection, and contractual obligations must be respected. Any limits on distribution should be stated clearly in the communication.
Monitoring also matters. Regulators often expect evidence that management has addressed reported issues, so internal audit should track corrective actions and report their status accurately. Good communication improves the organization's credibility with regulators, supports external audit efficiency, and strengthens governance. Poor communication can lead to regulatory sanctions, reputational damage, or exposure of sensitive information.
For the CIA exam, remember these points: coordinate to reduce duplication, evaluate before relying on others' work, have the CAE oversee and control external disclosure, and keep confidentiality and legal advice central to the process.
Communicating with the Risk Management Function
Communicating with the risk management function means how internal audit shares engagement results, monitoring outcomes, and risk insights with the people responsible for enterprise risk management (ERM), such as a chief risk officer or second-line risk and compliance teams. Under the IIA Three Lines Model, management owns and manages risk (first line), the risk management function supports and oversees it (second line), and internal audit gives independent assurance (third line). Good communication between the second and third lines helps the organization see its risks clearly, avoids duplicated work, and lets reliance be placed on each other's work where appropriate.
Key elements include:
1. Coordination and reliance: The chief audit executive should coordinate with other assurance providers, including risk management, to share risk assessments, audit plans, and results. This matches Global Internal Audit Standard 9.5. Internal audit may rely on risk management's work only after evaluating its objectivity, competence, and methodology.
2. Sharing engagement results: Findings about control weaknesses, emerging risks, or poor risk responses should reach risk management so risk registers, risk appetite measures, and key risk indicators can be updated. Communications must be accurate, objective, clear, concise, constructive, complete, and timely.
3. Monitoring progress: Internal audit tracks whether management's action plans are put in place. Sharing the status of open issues with risk management keeps residual risk ratings realistic.
4. Risk acceptance: If the CAE concludes that management has accepted a level of risk above the organization's risk appetite, the CAE must discuss it with senior management. If it is not resolved, the CAE escalates it to the board. Risk management is often involved in judging such tolerance decisions.
5. Independence safeguards: Internal audit may advise on ERM, but it must not take on management responsibilities, such as setting risk appetite or owning risks. Doing so would impair its objectivity.
In short, structured and ongoing communication with the risk management function strengthens governance, supports combined assurance, and improves the board's view of organizational risk.
Releasing Engagement Results Outside the Organization
Releasing engagement results outside the organization is a high-risk communication decision. Internal audit reports often contain sensitive information about control weaknesses, fraud, legal exposure, or strategic plans. External parties may include regulators, external auditors, lenders, business partners, insurers, or the public. Because disclosure can harm the organization, it must be tightly controlled. (In the current CIA syllabus, this topic is covered mainly under Part 2, Engagement Results and Monitoring.)
Under the IIA Standards, specifically former Standard 2440.A2 and the related confidentiality and communication requirements in the 2024 Global Internal Audit Standards, the chief audit executive (CAE) has three main obligations when release is not already mandated by law, statute, or regulation:
1. Assess the potential risk to the organization. The CAE considers legal liability, reputational damage, competitive harm, privacy concerns, and possible loss of legal privilege.
2. Consult with senior management and/or legal counsel. Legal counsel can advise on privilege, contractual obligations, and regulatory implications. Senior management helps assess business consequences.
3. Control dissemination by restricting the use of the results. Common methods include distribution limits, confidentiality agreements, disclaimers stating the report's purpose and scope, and statements that the report may not be relied on by others or redistributed without consent.
Even when disclosure is legally required, the CAE should still follow the organization's policies and include appropriate limitations. Standard 2410.A3, now reflected in the Global Standards, requires that external communications state any limitations on distribution and use.
The internal audit charter and policies should define who has authority to approve external release, typically the CAE together with the board or senior management. Auditors must also respect confidentiality: they may not disclose information without proper authority unless there is a legal or professional obligation to do so.
Exam tip: If a question asks what the CAE should do before an external release that is not required by law, look for the answer that covers assessing risk, consulting management or legal counsel, and restricting use. Avoid answers involving unrestricted release or unilateral decisions.
Communicating Results to Management of the Activity Under Review
Communicating results to management of the activity under review is the step where internal auditors share engagement conclusions with the people directly responsible for the audited process, so they can understand the findings and act on them. (Note: in the current CIA syllabus, engagement results and monitoring are generally covered in Part 2, but the principles are the same.) Under IIA Standards, communications should be accurate, objective, clear, concise, constructive, complete, and timely. Communication usually happens throughout the engagement rather than only at the end. Auditors discuss observations informally as they arise, which lets management confirm facts, correct misunderstandings, and begin fixing problems early. Near the end of fieldwork, the auditor holds an exit or closing meeting to review the draft observations, ratings, and recommendations. This meeting helps ensure there are no surprises and that the facts are correct. Each observation is typically structured around criteria (what should be), condition (what is), cause (why the gap exists), and effect (the risk or impact), followed by a recommendation. Management is then asked to give a formal response, including an action plan, a responsible owner, and a target completion date. These responses are often included in the final report. When management disagrees with a finding, the auditor should consider their evidence and change the report if it is factually wrong. If both sides still disagree, the report should present both positions while keeping the auditor's professional judgment intact. The final communication goes to management of the activity and to other parties who can ensure the results receive due consideration, such as senior management and the board. The chief audit executive decides who receives it. Afterward, the internal audit activity monitors whether management's actions are carried out. If management accepts a risk that the CAE believes is unacceptable to the organization, the CAE must discuss it with senior management and, if it remains unresolved, escalate it to the board.
Evaluating Control Design Adequacy for Residual Risk
Evaluating control design adequacy for residual risk means judging whether the controls management has put in place, as designed, are able to reduce inherent risk to a level within the organization's risk appetite. This sits at the boundary between performing the engagement and communicating results, and it drives how internal auditors rate observations and monitor progress. Inherent risk is the exposure before any controls. Residual risk is the exposure that remains after controls are applied. Design adequacy asks a simple question: if this control operated exactly as intended, would it prevent or detect the risk event in a timely way? This differs from operating effectiveness, which tests whether the control actually worked consistently over a period. A poorly designed control cannot be effective, so design is usually assessed first, often through walkthroughs, process narratives, flowcharts, and control matrices. Auditors consider several criteria. They check alignment, meaning the control addresses the specific risk and assertion. They consider type and timing, including preventive versus detective, manual versus automated, and whether it acts early enough. They assess precision, such as thresholds, review depth, and frequency. They review segregation of duties and authority levels, the competence of the people performing the control, and documentation and evidence trails. They also look at reliance on other controls, such as IT general controls. Auditors then compare the estimated residual risk with the risk appetite and tolerance approved by senior management and the board. If residual risk exceeds appetite, a design gap exists, and the auditor recommends redesigned, additional, or compensating controls. If controls are excessive relative to the risk, the auditor may note inefficiency. In engagement results, design deficiencies are rated by significance and communicated with root causes and recommendations. During monitoring, auditors track management action plans to confirm that remediated designs truly lower residual risk. If management accepts residual risk beyond appetite, the chief audit executive discusses it with senior management and, if unresolved, escalates it to the board, consistent with IIA Standards.
Evaluating Control Effectiveness for Residual Risk
Evaluating control effectiveness for residual risk is how internal auditors decide whether the risk that remains after controls are applied fits within management's risk appetite. This judgment shapes engagement conclusions, how findings are rated, and which issues are monitored afterward. (In the current IIA syllabus, engagement results and monitoring are covered mainly in CIA Part 2, but the concepts link to Part 3's governance and risk management content.) The process starts with inherent risk, the exposure that exists before any controls, judged by likelihood and impact. Auditors then identify the key controls meant to reduce that risk, whether preventive, detective, corrective, or directive, and assess them on two levels. Design effectiveness asks whether the control, if it works as intended, would adequately reduce the risk. Operating effectiveness asks whether the control actually works consistently over time, tested through inquiry, observation, inspection, reperformance, and sampling. Residual risk is what remains after control effectiveness is considered against inherent risk. If controls are well designed and working, residual risk may be acceptable. If gaps, design flaws, or operating failures exist, residual risk may exceed the risk appetite, and the auditor reports a finding. Auditors weigh the significance of deficiencies, compensating controls, the cost of controls versus their benefits, and how control weaknesses combine or aggregate. Findings are communicated using the criteria, condition, cause, effect, and recommendation structure, often with ratings such as low, medium, or high. Under the IIA Standards, the chief audit executive must set up a process to monitor whether management has taken action on reported issues. If management accepts a level of residual risk that the CAE believes is unacceptable, the CAE must discuss it with senior management and, if it remains unresolved, escalate it to the board. Follow-up procedures check whether corrective actions actually reduced residual risk. This makes control evaluation a continuous assurance cycle rather than a one-time test.
Inherent Versus Residual Risk
Inherent risk is the level of risk an organization faces before management takes any action to change the likelihood or impact of an adverse event, meaning the risk that exists without controls. Residual risk is the risk that remains after management's responses, such as internal controls, risk transfer, or avoidance, have been applied. The relationship is often summarized as residual risk equals inherent risk minus the effect of risk responses. For the Certified Internal Auditor exam, this distinction matters because it shapes how auditors evaluate findings, communicate results, and monitor progress. (Engagement results and monitoring are covered mainly in CIA Part 2, while risk concepts recur across all three parts.) When communicating engagement results, auditors assess whether residual risk falls within the risk appetite and tolerance set by senior management and the board. A finding is significant when control weaknesses leave residual risk above acceptable levels. For example, a cash handling process carries high inherent risk of theft. If segregation of duties and reconciliations are weak, residual risk stays high and warrants a high-priority observation. Conversely, strong controls may reduce residual risk to an acceptable level even where inherent risk is high, which supports positive assurance. Observation ratings typically consider the likelihood and impact of the residual exposure, which helps prioritize recommendations and management action plans. If management has accepted a level of residual risk that may be unacceptable to the organization, the chief audit executive must discuss the matter with senior management and escalate it to the board if it remains unresolved, as required by the IIA Global Internal Audit Standards. In monitoring, internal auditors track whether corrective actions actually reduce residual risk as intended. Follow-up confirms that controls were implemented and operate effectively. Changes in the business environment can raise inherent risk, so a residual risk that was once acceptable may become excessive and require reassessment. Key exam takeaways: inherent risk ignores controls, residual risk reflects them, management owns risk acceptance decisions, and auditors evaluate and report residual risk against the organization's risk appetite.
Parties Involved in Communicating Risk Acceptance
In CIA Part 3, under Engagement Results and Monitoring, risk acceptance occurs when management decides not to implement corrective action and accepts the related risk. The IIA Standards (formerly Standard 2600, retained in the Global Internal Audit Standards) define who must be involved when the accepted risk may exceed the organization's risk appetite. Several parties are involved. First, internal auditors and engagement supervisors identify the issue. They may find it during an engagement, through follow-up and monitoring of action plans, or through other activities. They document the finding, the risk exposure, and management's response, then escalate concerns to the Chief Audit Executive (CAE). Second, the CAE is the central party. The CAE judges whether the accepted risk is unacceptable to the organization, using the organization's risk appetite, tolerance levels, and potential impact. The CAE owns the communication process. Third, operational or process-owner management is usually the party that accepted the risk. Internal auditors first discuss findings with this level and confirm that management understands the exposure and the consequences of inaction. Fourth, senior management must be consulted. If the CAE concludes that management has accepted an unacceptable level of risk, the CAE must discuss the matter with senior management. This gives senior management a chance to reconsider, mitigate, or formally confirm the decision. Fifth, the board or audit committee serves as the final escalation point. If the CAE determines that the matter has not been resolved with senior management, the CAE must communicate it to the board. This supports governance oversight and the CAE's functional reporting relationship. Sixth, external parties such as regulators may receive information only when laws, regulations, or policy require it, following organizational protocols. Key exam points include the following. Internal audit does not resolve the risk or decide on acceptance, because management owns risk decisions. The CAE's role is to communicate and escalate, not to impose remedies. Escalation follows a defined sequence: management, then senior management, then the board. All discussions and conclusions should be documented to preserve objectivity, accountability, and a clear audit trail.
Sequence of Steps for Communicating Risk Acceptance
In CIA Part 3, under Engagement Results and Monitoring, communicating risk acceptance covers what the Chief Audit Executive (CAE) does when management accepts a level of risk that may be unacceptable to the organization. The traditional IIA Standard 2600 and the Global Internal Audit Standards both call for a structured escalation path. The typical sequence is as follows.
Step 1: Identify the accepted risk. Through engagement results, follow-up or ongoing monitoring, internal audit finds that management has not implemented corrective action, or has knowingly chosen to accept a risk exposure.
Step 2: Evaluate the risk against risk appetite. The CAE considers whether the residual risk exceeds the organization's risk appetite or tolerance. Relevant factors include likelihood, impact, regulatory implications, reputational harm and strategic effect. Not every accepted risk needs escalation, only those that may be unacceptable to the organization.
Step 3: Understand management's rationale. The CAE gathers facts and context, such as cost-benefit reasoning, resource limits or compensating controls. This confirms that the concern is well founded and not based on a misunderstanding.
Step 4: Discuss with senior management. The CAE first raises the matter directly with senior management. The goal is to explain the exposure and seek resolution, either through mitigation or through formal, informed acceptance by someone with the proper authority.
Step 5: Escalate to the board if unresolved. If the CAE still believes the risk is unacceptable after these discussions, the CAE must communicate the matter to the board or audit committee. The CAE presents the facts objectively, including management's position.
Step 6: Document and monitor. The CAE documents the communications, the decisions made and the final risk owner. The CAE then continues to monitor the risk and reports changes as needed.
Key exam points:
- Management, not internal audit, owns risk decisions.
- The CAE's role is to communicate and escalate, not to resolve the risk personally.
- Board escalation comes only after discussion with senior management fails to resolve the issue.
Follow-Up Process Design and Tracking Systems
Note: in the current CIA syllabus, engagement results and monitoring is mainly tested in Part 2, but the concepts apply wherever they appear. Follow-up confirms that management has addressed reported findings. The Global Internal Audit Standards (Standard 15.2, which replaced former Standard 2500) require the chief audit executive (CAE) to establish a process to confirm that management has implemented agreed recommendations or action plans, or has accepted the risk of not acting.
A well-designed follow-up process includes several elements. First, policy and responsibility: the internal audit charter or methodology defines who performs follow-up, how often, and how to escalate. Management owns corrective action, and internal audit verifies it. Second, risk-based prioritization: high-risk findings get earlier and more rigorous follow-up, such as retesting controls. Low-risk items may need only management confirmation or desk review. Third, clear action plans: each finding should have a specific corrective action, an accountable owner, and a target date, agreed when the report is issued. Fourth, verification methods: these range from inquiry and document review to observation and reperformance, depending on significance. Fifth, risk acceptance: if management accepts a level of risk the CAE believes is unacceptable, the CAE discusses it with senior management. If the matter remains unresolved, the CAE communicates it to the board.
Tracking systems support this process. They are often automated GRC or audit-management software, though spreadsheets may suffice in smaller functions. A tracking system should record each finding, its risk rating, owner, due date, status (open, in progress, implemented, verified, or risk accepted), and supporting evidence. Effective systems send automated reminders and flag overdue items. They also produce aging reports and dashboards for senior management and the audit committee.
Key exam points: follow-up is a required part of the engagement cycle, not optional. Its nature, timing, and extent depend on risk and on the cost of corrective action. Repeated overdue or unresolved issues may prompt a new engagement. Regular reporting on implementation status strengthens accountability and shows internal audit's value.
Evidence Required to Close a Management Action Plan
Under the IIA Global Internal Audit Standards, closing a management action plan (MAP) means confirming that management has implemented agreed actions and that those actions address the original risk. Standard 15.2, Confirming the Implementation of Recommendations or Action Plans, governs this work. Note that in the current CIA syllabus this topic is tested mainly in Part 2 (Practice of Internal Auditing), not Part 3. Management's assertion that an issue is 'fixed' is not enough. The chief audit executive must set up a follow-up process, and auditors must collect evidence that is sufficient, reliable, relevant and useful before closure.
The type of evidence depends on the risk and the nature of the action. Common forms include:
- Documentation, such as revised policies, approved procedures, updated system configurations, training records and signed reconciliations.
- Observation, meaning auditors watch the new control operating.
- Reperformance or testing, where auditors sample transactions after implementation to show the control works consistently over a reasonable period, not just once.
- Inquiry, used only as supporting evidence because it is the weakest form.
- System reports or data analytics showing exceptions have fallen or been eliminated.
Auditors should distinguish design (the fix exists) from operating effectiveness (the fix works over time). High-risk findings usually call for independent testing. Low-risk items may be closed with management's documentation and representation.
If management has not acted, or has chosen an alternative, auditors judge whether the residual risk is acceptable. If management accepts a risk that may be unacceptable to the organization, the CAE discusses it with senior management. If it remains unresolved, the CAE escalates it to the board (Standard 11.5 and related guidance).
Finally, the auditor should:
1. Record the evidence in workpapers.
2. Update the issue-tracking system.
3. Report the closure status to senior management and the board.
This cycle provides accountability and supports continuous improvement. It also gives the board assurance that risks have been mitigated.
Parties Involved in Escalation
In the CIA Part 3 domain on Engagement Results and Monitoring, escalation is the structured process of raising unresolved issues to higher levels of authority. Typical triggers include management failing to implement agreed corrective actions, missing deadlines, disputing significant findings, or accepting a level of risk that may be unacceptable to the organization. This concept aligns with IIA Standard 2600 (Communicating the Acceptance of Risks) and its counterpart in the 2024 Global Internal Audit Standards. Several parties are involved. First, the internal auditor or engagement team identifies the issue through follow-up and monitoring activities, documents the evidence, and discusses it with the responsible process owner. Second, the engagement supervisor or audit manager reviews the situation, confirms the facts, and attempts resolution with operational management before involving higher levels. Third, operational or line management, as the risk and action plan owners, are accountable for implementing remediation and must explain delays or justify accepting risk. Fourth, the Chief Audit Executive (CAE) plays the pivotal role. When the CAE concludes that management has accepted a level of risk that may be unacceptable, the CAE must discuss the matter with senior management. Fifth, senior management, such as the CEO, CFO, or relevant executives, has the authority to direct corrective action, reallocate resources, or formally accept the risk. Sixth, the board or audit committee is the final internal escalation point. If the matter remains unresolved after discussions with senior management, the CAE must communicate it to the board, which exercises oversight and decides on the appropriate response. In some situations, other parties may also be consulted, including legal counsel, compliance or risk management functions, and, where laws or regulations require it, external auditors or regulators. Effective escalation depends on clear protocols in the internal audit charter, accurate documentation, timely communication, and the independence of the CAE, including direct and unrestricted access to the board.
Sequence of Escalation Steps
In the CIA Part 3 context of Engagement Results and Monitoring, the sequence of escalation steps is the structured path internal auditors follow when observations, recommendations, or agreed action plans are not addressed, or when management accepts a level of risk that may be unacceptable to the organization. The aim is to resolve issues at the lowest appropriate level first, then escalate only as needed. This approach respects the chain of command while protecting the organization. Step 1 is resolution at the engagement level. The auditor discusses findings with the process owner or operational management during the exit meeting and while drafting the report. The goal is to agree on root causes, corrective actions, owners, and deadlines. Step 2 is monitoring and follow-up. The chief audit executive (CAE) maintains a system to track whether management has implemented actions. Delays, partial implementation, or unsatisfactory responses trigger the next step. Step 3 is escalation to senior management. If the operational manager does not act, or accepts a risk beyond the organization's risk appetite, the auditor or audit manager raises the issue with that manager's superiors or other senior management. Step 4 is direct involvement of the CAE. When the CAE concludes that management has accepted an unacceptable level of risk, the CAE must discuss the matter with senior management. This requirement appeared in Standard 2600 of the 2017 IPPF and is carried forward in the Global Internal Audit Standards. Step 5 is escalation to the board. If the matter remains unresolved, the CAE communicates it to the board, typically the audit committee. Internal audit does not resolve the risk itself. The board, as the ultimate governance body, decides whether the risk is acceptable. Throughout the process, auditors should document each communication and remain objective. They do not take ownership of management decisions or impose solutions. For the exam, remember three points: escalation is gradual, the CAE must discuss unacceptable risk with senior management before going to the board, and the board makes the final determination.