Follow-up: from action plan to evidence

Insights
Key takeaways

A finding is only closed with evidence that the remediation works, not with a notification that it has been dealt with. The Global Internal Audit Standards require follow-up on progress before the deadline, risk-based follow-up assessments, a tracking system with status per action, and, where progress fails to materialise, a documented management explanation. If progress continues to be absent, escalation proceeds via the head of the internal audit function to senior management and, if unresolved there, to the board — in the Dutch two-tier structure, the management board and the audit committee. Resolving the risk remains management's responsibility, not the internal audit function's.

How an audit report is structured, how a finding is written, and what the Standards require regarding recommendations and action plans, is covered in The audit report: structure, findings and opinion under GIAS. This article covers what happens after that report: follow-up.

An action plan with a deadline is not a closed finding. It only becomes one with evidence that the measure has been implemented, and until then there is an open risk that someone, somewhere, has accepted. Usually without writing it down.

The Global Internal Audit Standards are more specific on this point than on almost any other part of engagement work. Where many Standards leave room for an organisation's own methodology, the standard on follow-up is notably concrete. Standard 15.2, which prescribes how to confirm that recommendations or action plans have actually been implemented, names four actions: inquiring about progress, performing follow-up assessments on a risk basis, updating status in a tracking system, and documenting a statement from management where progress is lacking12. An audit function that treats follow-up as a checklist to be ticked off somewhere misses precisely that last point: it is about documented evidence, not an impression that things will probably turn out fine.

What GIAS requires on follow-up

Follow-up does not begin at Standard 15.2, but a step earlier, at Standard 14.4 on recommendations and action plans. When closing the engagement, the internal auditor chooses between three routes: developing recommendations independently, requesting an action plan from management, or working with management towards agreement on the actions to be taken1. Whichever route is chosen, the outcome must be the same: a measure, an owner and a target date, documented before the engagement file closes. Without those three, there is nothing to follow up on.

Standard 15.2 picks it up from there. The professional confirms, following an established methodology, that management has implemented the recommendations or its own action plan2. That is a four-step cycle:

  • inquiring about progress, before the agreed date, not after;
  • performing follow-up assessments using a risk-based approach, so not retesting every finding in the same way;
  • updating the status of actions in a tracking system;
  • letting the extent of all this move in line with the significance of the finding.

That last point is often skipped. A finding with limited risk warrants a brief progress check; a finding that touches a standard, a risk tolerance or a key control warrants a follow-up assessment with its own evidence. Applying the same depth to both is a waste of time on one side and insufficient assurance on the other.

No progress by the date: what then

Standard 15.2 explicitly provides for the scenario where the deadline passes without result. The internal auditor then obtains and documents a statement from management, and discusses the matter with the head of the internal audit function2. Those two steps, documenting the statement and escalating within the function, are fixed in the Standard: the professional follows them and does not weigh them up independently.

The head of the internal audit function (CAE) then determines whether senior management, through delay or through inaction, has accepted a risk that exceeds the organisation's risk tolerance2. If the CAE concludes that this is the case, they discuss it with senior management. If the matter remains unresolved there, it goes to the board3. In the Dutch two-tier structure, that means the executive board and, on behalf of the supervisory board, the audit committee. That step is Standard 11.5, on communicating a risk that management has accepted while it exceeds the organisation's tolerance. Resolving the risk is not, at either level, the CAE's task: the CAE communicates, management and the board decide.

That makes the escalation ladder, in practice, four steps short:

  1. Auditor: documents the statement explaining the delay, with date and rationale.
  2. CAE: assesses whether a risk exceeding tolerance has been accepted here.
  3. Senior management: discusses the matter, with the CAE.
  4. Board: if the matter is not resolved at senior management level.
Performing follow-up: ten process steps, the escalation ladder, five tips and two rules of thumb for tracking findings
The follow-up process from action plan to evidence, with escalation ladder, tips and where follow-up breaks down in practice

A tracking system is not a mailbox

Standard 15.2 explicitly refers to a tracking system in which the status of actions is maintained2. That word does work: a spreadsheet maintained differently by each auditor, or an email exchange in which "we're almost there" passes as a status update, is not a tracking system within the meaning of the Standard. A tracking system records, per action, the owner, the date, the status and the evidence, and displays this to everyone who needs it, not just to whoever can still find the email.

Audirium's Action Tracking is built for this: findings and improvement actions with owner, deadline and progress, role-based views for auditor, management and CAE, and an audit trail that records exactly who updated what and when. The escalation under Standard 15.2 remains the same; the system turns "no progress by the date" into a signal that surfaces automatically, rather than something a professional happens to notice while leafing through a file.

Tips that save time

Five habits make the difference between follow-up the organisation takes seriously and a list everyone ignores:

  • Agree the evidence upfront. The document, screenshot or log that demonstrates the measure works, rather than "sort it out". Then the owner knows from day one what counts.
  • One date per action. "Q3" is not a date, it is a deferral mechanism with three months of slack.
  • Schedule the retest immediately. Not only once the deadline has passed: that starts the follow-up assessment with delay nobody planned for.
  • Group by root cause. Four actions arising from the same underlying cause deserve one conversation with the owner, not four separate threads.
  • Report periodically, not on request. A status overview that only appears on request depends on who still remembers to ask.

Two rules of thumb sum it up. Closed means evidence plus date, not "reported as done". And follow-up is a methodology in the manual, not a habit per auditor: if the approach is not fixed, the professional's own agenda determines how strictly a finding is followed up, and that is precisely the arbitrariness Standard 15.2's "established methodology" is meant to prevent.

Where it breaks down in practice

Four patterns recur in audit functions where follow-up looks well organised on paper and does not work in practice:

  • an action list nobody updates after the engagement, so that by the time of the next review the status is as stale as the report itself;
  • every finding receiving the same retest, regardless of significance, which draws capacity away from the findings that need it;
  • an action closed on the owner's say-so, without having seen the evidence itself;
  • a delay heard and accepted verbally, without documenting the statement Standard 15.2 requires.

None of the four is an exceptional error. They are the ordinary consequences of follow-up that has not been set up as a separate process, with its own system, its own rhythm and its own escalation path. A delay is also a decision. The manager who lets the date pass accepts the risk, just without writing it down, and writing it down is exactly what Standard 15.2 asks for.

This article covers the follow-up after the report: the process, the escalation ladder and the tracking system. If you are looking for how the report itself is structured and what Standard 14.4 requires when drafting recommendations and action plans, read The audit report: structure, findings and opinion under GIAS.

References

[1] The IIA. (2024). Global Internal Audit Standards. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/

[2] IIA Nederland. (2024). Global Internal Audit Standards, Dutch version. https://www.theiia.org/globalassets/site/standards/editable-versions/global-internal-audit-standards-dutch.pdf

[3] IIA Nederland. (2025). Effectuering GIAS. https://www.iia.nl/nieuws/effectuering-gias

Back to Insights