Skip to main content
Category: Internal Audit and Assurance

Follow-Up Audit

Also known as: Audit Follow-Up, Follow-Up Review, Post-Audit Follow-Up
Simply put

A follow-up audit is a review conducted after an initial audit to check whether the corrective actions that management agreed to take have actually been carried out. It confirms not only that the promised actions were completed, but also that they are working as intended to address the original findings. It typically takes place some months after the first audit, once management has had time to implement changes.

Formal definition

A follow-up audit is an assurance activity performed by the internal audit function to verify whether management action plans issued in response to prior audit findings and recommendations have been fully implemented and are operating effectively. It generally distinguishes completion of the agreed action from its effectiveness in remediating the underlying risk or control deficiency. Timing is typically set with reference to the priority or risk rating of the original finding, and in many practices ranges from roughly three to six months after the initial audit, though this varies by organization and by the nature of the corrective action. Accountability for implementing corrective actions rests with management, while the follow-up audit itself is an independent verification performed by the assurance function; this entry is educational and not audit, legal, or compliance advice.

Why it matters

An audit delivers value only if its findings lead to durable improvements. A follow-up audit closes the loop by testing whether management actually implemented the corrective actions it agreed to, rather than allowing recommendations to lapse once the original report is filed. Without this verification step, an organization can accumulate a backlog of unaddressed findings while assuming its risks and control deficiencies have been remediated.

Critically, a follow-up audit generally distinguishes between the completion of an agreed action and its effectiveness in addressing the underlying issue. An action can be marked complete on paper yet fail to remedy the original control weakness or risk. By assessing whether corrective actions are operating as intended, the follow-up provides the board, audit committee, and senior management with more reliable assurance about the state of remediation than a self-reported status update from management alone.

The follow-up also reinforces accountability. Because responsibility for implementing corrective actions sits with management while independent verification sits with the assurance function, the follow-up audit creates a clear record of whether commitments were honored. This separation of roles helps the audit committee track outstanding items and press for resolution where progress has stalled. This entry is educational and not audit, legal, or compliance advice.

Who it's relevant to

Internal Auditors
Internal auditors plan and perform follow-up audits, setting timing with reference to the priority or risk rating of the original finding and gathering evidence to verify both completion and effectiveness of agreed corrective actions. This work distinguishes their independent verification role from management's responsibility for implementation.
Audit Committees and the Board
The audit committee and board rely on follow-up audit results to gain assurance that agreed remediation has occurred rather than remaining an open commitment. Follow-up findings help the committee track outstanding items and challenge management where progress on corrective actions has stalled.
Management and Process Owners
Management holds accountability for implementing the corrective actions covered by a follow-up audit. Process owners are expected to complete their action plans within the agreed timeframe and to be prepared to demonstrate, with evidence, that the changes are operating as intended when the follow-up is performed.
Chief Compliance and Risk Officers
Compliance and risk leaders have an interest in whether findings tied to control deficiencies or regulatory exposures have been effectively remediated. Follow-up audit results can inform their view of residual risk where corrective actions are incomplete or not yet operating effectively, though the follow-up itself is owned by the assurance function.

Inside Follow-Up Audit

Purpose and Scope
A follow-up audit is a subsequent engagement conducted by internal audit to assess whether management has implemented, and effectively operated, the corrective actions agreed in response to previously reported findings. Its scope is generally limited to the original observations and the related remediation, rather than a full re-audit of the area.
Verification of Remediation
The core activity is verifying that agreed management action plans have been completed and are functioning as intended. This typically distinguishes between whether a control has been designed to address the root cause (design) and whether it is operating over time (operating effectiveness).
Assessment of Residual Risk
Follow-up work generally evaluates whether remediation has reduced the risk exposure to a level consistent with the organization's risk appetite. Some inherent risk typically remains, and the follow-up assesses whether residual risk is now within acceptable limits.
Status Reporting and Tracking
Findings are commonly tracked in an issue log or tracking system with statuses such as open, in progress, closed, or overdue. Follow-up audits generally update these statuses and report outstanding items to the audit committee or equivalent oversight body.
Accountability and Ownership
Management owns the corrective actions and their implementation; internal audit provides independent assurance over whether those actions were completed and effective. The board or audit committee typically holds oversight responsibility for ensuring findings are addressed.
Escalation Protocols
Follow-up processes generally include a mechanism to escalate findings that remain unresolved beyond agreed deadlines or where management accepts a risk that appears inconsistent with the entity's risk tolerance.

Common questions

Answers to the questions practitioners most commonly ask about Follow-Up Audit.

Is a follow-up audit just a repeat of the original audit?
No. A follow-up audit is generally narrower in scope than the original engagement. Rather than re-performing the full audit, it typically focuses on verifying whether management has implemented the agreed-upon corrective actions for previously identified findings and whether those actions have adequately addressed the underlying issues. The original audit's broader control testing is not usually repeated unless the follow-up work indicates that related areas warrant fresh examination. Scope ultimately depends on the audit function's judgment and the nature of the original findings.
Does internal audit own responsibility for fixing the issues it follows up on?
No. Accountability for designing and implementing corrective actions, remediation, generally sits with management, which owns the risks and controls in the first and second lines. Internal audit's role in a follow-up is an assurance role: to independently assess and report on whether management's remediation has occurred and whether it appears effective. Treating internal audit as responsible for remediation would compromise its independence and blur the distinction between management's operational duties and assurance's evaluative duties.
How do you decide which findings require a follow-up audit versus routine tracking?
Prioritization typically reflects the assessed risk and significance of the finding. Higher-risk or higher-impact findings, or those touching regulatory or financial reporting matters, generally warrant a dedicated follow-up audit, while lower-risk items may be handled through less intensive monitoring such as management self-certification or status tracking in an issue-management system. Many audit functions apply a risk-based methodology and document their rationale. The specific thresholds depend on the organization's audit charter, methodology, and professional judgment.
What timing is appropriate for scheduling a follow-up audit?
Timing generally allows enough time for management to have implemented the agreed action while remaining close enough to confirm the remediation before risk exposure persists unaddressed. Follow-up is often aligned to the target completion dates management committed to for each action. Some functions schedule follow-up work as part of the annual audit plan; others trigger it on a per-finding basis. There is no single universal interval, the appropriate window depends on the severity of the finding and the complexity of the remediation.
How should a follow-up audit distinguish between control design and operating effectiveness?
This distinction is central to meaningful follow-up. Confirming that a new or revised control has been designed and put in place addresses design; testing whether that control has been operating as intended over a period addresses operating effectiveness. A follow-up that verifies only that a policy was written or a control was implemented, without testing operation, may overstate the degree of remediation. Where practical and relevant, follow-up work generally seeks evidence of operating effectiveness, though the depth achievable can depend on how much time has passed since implementation.
How should the results of a follow-up audit be reported and to whom?
Results are typically reported to the same stakeholders who received the original findings, which in many organizations includes relevant management and the audit committee or equivalent oversight body. Reporting generally states the current status of each action, for example, implemented and effective, in progress, or not yet addressed, and highlights any findings that remain open or unremediated past their agreed dates. Persistent or overdue high-risk items are often escalated to the board or its audit committee. Specific reporting lines and formats depend on the organization's governance structure and audit charter.

Common misconceptions

A follow-up audit is simply a repeat of the original audit.
A follow-up audit is typically narrower in scope, focusing specifically on whether previously agreed remediation has been implemented and is effective, rather than re-performing the full original engagement.
Internal audit is responsible for fixing the findings it verifies during follow-up.
Remediation is owned by management. Internal audit's role is to provide independent assurance over whether corrective actions were completed and are operating effectively; performing the remediation itself would generally compromise auditor independence.
Confirming that a control has been designed or put in place means the finding is fully resolved.
Design implementation and operating effectiveness are distinct. A control may be designed appropriately yet fail to operate consistently; follow-up work generally needs to consider whether the control has actually functioned over a relevant period before a finding is closed.

Best practices

Define the follow-up scope up front, tying it to the specific original findings and the agreed management action plans rather than expanding into a broader re-audit unless the facts warrant it.
Distinguish clearly between verifying control design and testing operating effectiveness, and avoid closing findings on the basis of design alone where sustained operation matters.
Maintain a centralized issue tracking log with clear statuses, owners, and target dates, and reconcile follow-up conclusions against it to ensure completeness.
Preserve auditor independence by confirming that management, not internal audit, owns and executes remediation, while internal audit provides the assurance.
Apply defined escalation protocols for overdue or unresolved findings, reporting outstanding items and any management-accepted risks to the audit committee or equivalent oversight body.
Assess residual risk against the organization's risk appetite before closing a finding, and document the judgment used, recognizing that conclusions may depend on facts, jurisdiction, and applicable frameworks.