Practical guide · Stage: Action

    Internal audit action closure: what evidence is enough?

    By , Founder of Beyond the Lines™ ·

    Internal audit action closure needs evidence that the agreed change has been implemented, assessed against clear criteria and with follow-up proportionate to the risk. Where the action is intended to improve a control, establish what the evidence shows about that control working. A completed task alone cannot support every claim about reduced risk.

    A policy has been updated. Training has been delivered. A system change has gone live. Each is a useful fact. The closure question is what those facts allow you to conclude about the original problem.

    If that question first appears when the deadline arrives, the action was probably under-specified from the start.

    Agree the evidence before the work starts

    When agreeing an action, make the intended change explicit. “Improve oversight” gives everyone room to interpret success differently. “Introduce a monthly review that identifies overdue reconciliations and records their resolution” creates something you can examine.

    Agree four things with the owner:

    1. The problem: which risk, weakness or underlying cause needs attention?
    2. The change: what will people or systems do differently?
    3. The evidence: what records, observations or tests would demonstrate implementation and, where relevant, operation?
    4. The judgement: who will assess the evidence, over what period and against which criteria?

    This is a practical approach to follow-up. The IIA’s Standard 15.2 requires confirmation of implementation through an established methodology, including risk-based follow-up, with the extent of procedures reflecting the finding’s significance.

    Worked example: supplier bank-detail changes

    Illustrative example, not a client case. An audit identifies that supplier bank-detail changes can be processed without independent verification. Management agrees to introduce a verification control.

    Closure evidence for a supplier bank-detail verification control, and what each item still leaves open
    Evidence offeredWhat it supportsWhat still needs checking
    Approved procedure and staff briefingThe process has been defined and communicatedWhether staff follow it on actual changes
    Screenshot showing a new approval stepA system configuration existsWhether the step can be bypassed and whether the approver checks the right evidence
    Records from completed changesEvidence of operation for the transactions examinedCoverage, timing, exceptions and the reliability of the records
    Review of exceptions and their resolutionEvidence that monitoring identifies and addresses problemsWhether the review covers the relevant population and is sustained

    The right conclusion depends on the action’s scope and the work performed. Examining a small selection of transactions may support a limited conclusion. It does not establish that every transaction is correct or that fraud is impossible.

    Connect action to movement

    The Beyond the Lines Assurance to Action System™ follows:

    Insight → Message → Decision → Ownership → Action → Movement → Outcome

    For closure, the useful distinction is between Action, the agreed intervention, and Movement, observable change in how work happens. Outcome is the resulting effect on risk or organisational performance.

    In the example, introducing verification is the action. Evidence that staff consistently perform it is movement. A better-supported assessment of exposure to unauthorised changes is part of understanding the outcome. A quiet month with no reported fraud is weak evidence on its own.

    Your tracker should preserve these distinctions, even if your organisation uses different status labels. If implementation is complete but operating evidence is immature, record that limitation and agree the next review. Avoid allowing a green status to imply more assurance than the work supports.

    Make the closure judgement proportionate

    Start with the significance of the issue, the control’s frequency and what could go wrong. A low-risk document correction and a critical payment control need different follow-up.

    Record what you examined, the period covered, the exceptions identified and the basis of the conclusion. Where evidence is incomplete, identify the gap and its consequence. Where management changes the action, reassess whether the revised response addresses the original issue.

    Management retains responsibility for implementing change and managing risk. Internal audit’s follow-up should make the evidence and unresolved exposure clear. Where the same weakness keeps returning, the committee discussion matters as much as the tracker, which is the subject of the guide on internal audit reporting to the Audit Committee.

    Common questions

    Is a management confirmation enough to close an audit action?

    It may contribute to the evidence. Whether it is sufficient depends on the issue and the established follow-up methodology. For a significant control weakness, ask what independently supports the confirmation.

    Must every action stay open until an outcome improves?

    No. Some outcomes take time or cannot be attributed to one intervention. Assess the agreed action against appropriate criteria and distinguish implementation from any remaining uncertainty about effectiveness or outcomes.

    What if management accepts the remaining risk?

    Record risk acceptance explicitly through the appropriate governance process. An accepted exposure should be distinguishable from verified remediation, with the rationale and authority clear.

    Apply this to your next action review

    Choose three actions approaching closure. Ask the owners what evidence would demonstrate the intended change, then compare their answers with the original wording. Any mismatch is worth resolving before the deadline.

    Explore the Assurance to Action Toolkit to put a more structured approach to decisions, ownership and action into practice.

    Sources