After an internal audit, most teams build an action plan from the findings and track implementation to closure. The step they skip is testing whether the assumptions embedded in each finding still hold before the action plan commits resources.
An internal audit is an independent assurance activity that evaluates whether an organisation's controls, risk management, and governance processes operate as intended.
The standard next step after an internal audit
The audit team issues a report. Findings are rated by severity: critical, high, medium, low. Each carries a recommendation and a management response. Management assigns owners, sets deadlines, and commits to remediation. The cycle is well established and well documented.
Professional standards reinforce this sequence. The IIA's Global Internal Audit Standards require the chief audit executive to communicate results, obtain management responses, and monitor their disposition. ISO 19011 describes a comparable cycle for management system audits: plan, conduct, report, follow up. The same sequence drives the response after an ISO 9001 audit and after an ISO 14001 audit, where nonconformities replace severity ratings but the untested premises underneath are the same. Within the three lines model, internal audit sits as the third line, providing independent assurance to the board that first and second line controls are working. The standard next step after completing that assurance is to close the loop: confirm that management acted on the findings.

Most organisations add a follow-up audit to verify corrective actions were implemented. Some track metrics: percentage of findings closed on time, aging of open items, severity trends across periods. Audit committees review dashboards. The apparatus is thorough.
The entire sequence assumes that the original findings were sound, the severity ratings accurate, and the root cause behind each finding correctly identified. When those conditions hold, the standard playbook works. When any of them rest on premises nobody examined, the playbook produces activity without progress.
The follow-up audit checks whether the corrective action was implemented. It does not revisit whether the finding itself rested on conditions that changed since fieldwork. A gap identified in March and remediated in September may no longer reflect the same operating environment. The playbook treats the finding as fixed. Whether the fix addresses the actual problem depends on assumptions the playbook does not reopen.
What that step adds
The standard playbook converts observations into obligations. Without it, audit findings sit in a PDF and nothing changes.
Action tracking gives findings a shelf life. Ownership assignments prevent the diffusion of responsibility that kills most governance recommendations. A high-rated finding with a named owner and a deadline creates accountability that a narrative report cannot.
Severity ratings do useful work. They force the audit team to judge consequence and likelihood, then signal to the board where attention should concentrate first. Governance structures depend on this signal. The audit committee relies on internal audit to surface the problems that operational reporting misses, and the rating system is how that signal reaches the committee room. Without that prioritisation, every finding competes equally for management attention, and the critical gaps drown in a list of minor procedural observations.
Trending data adds another layer. When the same process generates repeat findings across cycles, the pattern points toward systemic weakness rather than isolated error. Good audit functions track this and escalate accordingly. The standard playbook, followed well, stops an organisation from ignoring its own oversight function. Whether internal audit should also perform risk assessment is a separate question, but the assurance cycle itself produces genuine value.
The value is real: structured follow-up, clear ownership, severity-based prioritisation. These are not trivial contributions. They move internal audit from observation to influence. Organisations that dismantle these processes in the name of efficiency tend to discover the cost quickly. The question is not whether the playbook adds value. The question is what it does not test.
Write down the assumption your highest-rated finding depends on and ask whether the corrective action will hold if that assumption is wrong. Start the Walk →
Where the standard playbook breaks down
The playbook breaks down at a specific point: the moment a finding is rated, that rating becomes a fact in the system. Nobody revisits the judgment that produced it.
A finding rated "high" assumes that the control gap it describes will produce the consequence the auditor projected, under conditions the auditor believed were true during fieldwork. A finding rated "low" assumes the opposite. Both ratings rest on premises. The standard playbook treats those premises as settled and moves straight to remediation.
Wirecard exposed what happens when the premises go untested at scale. EY audited Wirecard's financial statements for over a decade and issued unqualified opinions each year. The audits followed the standard cycle: fieldwork, findings, sign-off. When Wirecard's supervisory board commissioned KPMG for a special independent audit in October 2019, KPMG reported that Wirecard could not provide sufficient documentation to verify revenues worth approximately EUR1 billion over several years. The regular audit cycle had produced findings, ratings, and conclusions. What it had not done was test the foundational assumption: that the reported cash balances in trust accounts in the Philippines and Singapore actually existed.
In June 2020, EY refused to sign the 2019 accounts after trustee banks indicated that EUR1.9 billion in cash probably did not exist. Wirecard filed for insolvency within days. CEO Markus Braun was arrested. COO Jan Marsalek disappeared. The European Parliament's briefing on the collapse described regulatory failure and institutional capture. The deeper problem was simpler: nobody tested the premise on which every audit opinion rested.
This is not unique to Wirecard's scale. Any internal audit function that rates a control deficiency as "medium" embeds an assumption about the operating environment that produced that rating. If the organisation has restructured since fieldwork, if a compensating control has been introduced informally, if transaction volumes have shifted, the original rating may no longer apply. The resources committed to remediation are then pointed at the wrong target. Deficiency ratings after a SOX compliance review carry the same exposure, because each control conclusion describes conditions at the test date.
The standard playbook checks whether the corrective action was implemented. It does not ask whether the finding itself still deserves the rating it received. The distinction between a documented finding and a tested finding is where most governance failures begin. Not in the absence of oversight, but in the assumption that the oversight produced judgments that no longer need examination.
The step to take first
Before building the action plan, test the assumptions behind each finding.
The five-step method (Frame, Tentative Elements, Assumptions, Sufficient Certainty, Implement and Monitor) provides a structure for this. Applied to internal audit findings, it works as follows.
Frame: state the decision each finding requires. A finding rated "high" for access-control weakness is not merely a remediation task. It is a decision about where to allocate limited resources, which controls to strengthen first, and what to defer. Framing it as a decision forces the question: what conditions make this allocation correct? For access controls, what to do after a threat vulnerability assessment tests the routes a threat actor can actually use before funds are committed to closing the listed gaps.
Tentative Elements: identify what the finding depends on. Which controls were tested directly? Which were inferred from documentation rather than observation? What does the severity rating assume about transaction volumes, staffing patterns, or the regulatory environment?
Assumptions: name them explicitly. A "high" rating on a segregation-of-duties gap assumes the current staffing model will persist, that compensating controls are not already managing the exposure informally, and that the projected consequence is realistic given actual transaction patterns. Making those assumptions transparent forces the room to judge each one rather than accepting the rating as given.
Sufficient Certainty: judge whether the evidence supports each assumption well enough to act. Not maximum certainty. Sufficient certainty. Some assumptions will hold. Others will reveal that the finding, while technically correct, rests on conditions that changed or were never verified during fieldwork.
Implement and Monitor: build the action plan from verified assumptions and attach monitoring triggers that reopen the decision if conditions shift. This is where the standard playbook starts. The difference is that the plan now rests on tested ground.
Internal audit is valuable. The findings are real work. But findings are not decisions, and ratings are not evidence. Testing the assumptions behind each finding before the action plan commits resources is the difference between governance that works and governance that merely looks compliant. The same test applies one level up, when the audit examines the oversight structures themselves: what to do after a governance audit runs on identical logic.
You could close this tab and carry that decision into another week.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.