The management response is the moment a finding stops being the auditor’s and becomes the organization’s. Everything before it, the testing, the evaluation, the writing, produces a description of a problem; the response is the first commitment to do something about it, and the quality of that commitment decides whether the finding changes anything. Most audit functions treat the response as a formality: management writes a paragraph, the auditor pastes it under the finding, and the report goes out with an action plan that promises a review, a reminder or a training session against a design gap that none of those will touch. Standard 14.4 puts the responsibility where it belongs: when management has not developed an action plan that addresses the finding, internal auditors provide recommendations that address the root cause, and the plan that appears in the report has to be one the auditor has evaluated, not merely received.
This guide is about that evaluation. It covers what a response is for and what the Standards expect of it, the five tests an action plan has to pass, a taxonomy of the eight responses auditors actually receive with what each one fixes and when it is acceptable, how to handle the four kinds of dispute, a response evaluation memo template, five responses from the engagements on this site with how each was evaluated and what happened, scripts for pushing back without a fight, the escalation ladder and its timing, and the mistakes that let weak responses into reports. It sits between the life of a finding, which covers the stages before and after, and the risk acceptance guide, which covers the response that is not an action plan at all.
In this guide
- What a response is for, and what the Standards expect
- The five tests of an action plan
- The eight responses you will actually receive
- Reading a response: the signals in the wording
- Disputes: facts, cause, rating and consequence
- The response evaluation memo
- Worked examples: five responses and what happened to them
- Pushing back without a fight: three scripts
- When to escalate, to whom, and how fast
- The interim measure: what protects the organization while the fix is built
- Responses at the report level
- A calibration exercise for the function
- Common mistakes
- Where to go next
What a response is for, and what the Standards expect
A response does four jobs. It confirms or contests the facts, which by the time of the draft should already have happened in the fact validation the life of a finding describes. It commits to an action, or to no action, which is the risk acceptance path. It names an owner and a date. And it becomes the thing the function will validate against a year later, which means its wording has to be specific enough that closure can be tested. The Standards frame it from both sides: Standard 14.4 requires recommendations and action plans that address the root cause and are practical, and Standard 15.1 requires the final communication to include management’s action plans or its acceptance of the risk; Standard 15.2 then requires the chief audit executive to confirm implementation, which is impossible if the plan was “management will review the process”.
The auditor’s role in the response is easy to get wrong in both directions. Writing management’s response for them produces a plan management does not own and will not deliver. Accepting whatever arrives produces a report with a finding and a promise that do not match. The right position is the one an editor takes with an author: the plan is management’s, its adequacy is the auditor’s to judge, and a plan that does not pass the tests below goes back with the reason, before the report is issued and not after.
The five tests of an action plan
Every action plan is run against five tests before it goes into the draft. A plan that fails one is returned with the failed test named; a plan that fails three is a signal that the finding itself has not landed, and the conversation goes back to the cause.
| Test | The question | Passes | Fails |
|---|---|---|---|
| 1. Cause | Does the action change the thing the cause element names? | “Configure the workflow to block issuer approval of credit memos” against a cause of “the system permits issuer approval” | “Remind staff of the credit policy” against the same cause |
| 2. Specificity | Could a validator test whether it was done, and whether it works, from the words alone? | “Load contract price lists for the twenty largest vendors and configure the match to test invoice price to contract” | “Strengthen contract price controls” |
| 3. Ownership | Is the owner a named person with the authority and budget to do it? | “The controller”; “the head of procurement” | “Finance”; “management”; a person two levels below the decision |
| 4. Timing | Is the date realistic for the action and proportionate to the rating? | A system change in two quarters; a policy change in one; an interim compensating control now for a High | “Ongoing”; a High with an eighteen-month date and nothing in between |
| 5. Proportion | Does the effort match the rating, in both directions? | A Low fixed with a procedure note; a High with a system control and an interim measure | A High answered with training; a Low answered with a six-month project |
Test 1 is the one that matters most and fails most often, because it depends on the cause element having been written properly in the first place. A finding whose cause says “the control did not operate” invites a response that says “we will operate the control”, and both are empty. The root cause analysis guide covers how to write a cause that an action plan can address; the test here is whether the plan addressed it.
The eight responses you will actually receive
Management responses come in a small number of shapes, and each shape has a legitimate use and an illegitimate one. The table names the eight, what each one actually fixes, when it is the right answer, and the question that separates the legitimate version from its twin.
| Response | What it fixes | When it is the right answer | The question to ask |
|---|---|---|---|
| The review (“we will review the process”) | Nothing yet; it defers the decision | Only as the first step of a plan whose later steps are dated, for a finding whose fix is genuinely undecided | “What will the review decide, by when, and what happens to the risk until then?” |
| The reminder (“staff will be reminded”) | Knowledge gaps, briefly | When the cause was that people did not know the rule, and the rule is enforceable afterward | “Did the people who did this not know, or did the system let them?” |
| The training | Skill gaps | When the cause was capability, and the training is specific, scheduled and measured | “What will they be able to do afterward that they cannot do now, and how will you know?” |
| The policy rewrite | Design gaps in the rule | When the cause was a rule that permitted the condition, and the rewrite will be enforced | “What in the system or the review will enforce the new wording?” |
| The system change | Design gaps in enforcement | When the cause was a configuration or workflow that allowed the condition; the strongest response to most control findings | “What is the interim control until the change is live?” |
| The staffing change | Capacity and segregation gaps | When the cause was that one person did two incompatible things, or nobody had time to do one | “Is the role funded, and who does the work until it is filled?” |
| The compensating control | The consequence, not the cause | When the cause cannot be removed at reasonable cost and a detective control can catch the consequence | “Who performs it, how often, against what population, and how will its operation be evidenced?” |
| The risk acceptance | Nothing; it accepts the consequence | When management with the authority decides the cost of fixing exceeds the risk, documented, and the CAE agrees or escalates | “Who has the authority to accept this, and has the board seen it?” |
The first three are the responses that fail test 1 most often, and they are not wrong in themselves; they are wrong as answers to design findings. A reminder is a fine response to a finding whose cause was that a new rule had not been communicated; it is no response to a finding whose cause was that the system permits self-approval. The taxonomy’s purpose is to make the mismatch visible in the draft rather than in the follow-up two years later.
Reading a response: the signals in the wording
Responses are written by people under time pressure who have not always read the finding closely, and the wording carries signals about whether the finding has landed. The table lists the phrases that recur and what each usually means, so that the evaluation can go to the substance quickly.
| Phrase in the response | What it usually signals | What to do |
|---|---|---|
| “Management agrees with the finding and will…” | The finding landed; evaluate the plan on the five tests | Proceed to the tests |
| “Management notes the finding” | The finding has not been accepted and management does not want to say so | Ask directly whether the facts and the cause are agreed; record the answer |
| “While no losses have occurred…” | A dispute of consequence dressed as agreement; the plan that follows will be light | Point to the effect mechanism and any realized example; evaluate the plan against the rating, not against the absence of loss |
| “This is an isolated instance” | A dispute of condition; management believes the sample, not the population | Restate the population figures with denominators; if the condition is a single item, the finding should already say so |
| “Compensating controls are in place” | Sometimes true; usually the controls were not tested because nobody named them | Ask which controls, who performs them, against what population; test them before accepting the response |
| “Resource constraints prevent…” | A risk acceptance that has not been made by anyone with the authority to make it | Route it up the ladder as a risk acceptance decision, not down as a weak plan |
| “Will be addressed as part of the wider transformation program” | An undated fix owned by a program, which is to say by nobody | Ask for the program milestone, its date, and the interim measure until then |
| “Already completed” | Often true for the condition, rarely for the cause | Ask for the evidence now; validate the fix during the engagement; report as remediated during fieldwork if the cause is fixed too |
Disputes: facts, cause, rating and consequence
A response that disputes the finding is not a failure of the process; it is the process working, provided the dispute is about something that can be resolved with evidence or with the scale. Disputes come in four kinds, and each has its own resolution. A dispute about facts is resolved with evidence, and only with evidence: if management says the condition is wrong, they show the document, the auditor examines it, and the condition changes or does not; a dispute about facts that arrives at the draft stage after fact validation was completed is a sign the validation was skipped, and the answer is to do it now. A dispute about cause is recorded on both sides, and the report may carry both: the auditor’s evaluation says why the auditor’s cause is preferred, management’s response says why they disagree, and the action plan reveals which one management actually believes, because plans address the cause their author holds. A dispute about rating is resolved against the function’s scale anchors in the severity ratings guide, never against the auditee’s sense of proportion or the auditor’s; the question is which anchor the finding meets, and if the scale cannot answer it, the scale needs work. A dispute about consequence is the hardest, because the effect element is often a plausible mechanism rather than a realized loss, and management’s argument is usually that it has not happened; the answer is that the finding is about exposure, that the mechanism is stated, and that the one example where it did happen, if there is one, is in the report.
| Dispute | Resolved by | Who decides | Recorded where |
|---|---|---|---|
| Facts | Evidence produced and examined | The auditor, on the evidence | Finding record, stage 5; the condition amended or confirmed |
| Cause | Both causes stated; the plan reveals the operative one | The auditor’s evaluation stands; management’s view is reported beside it | The report, in the finding and the response |
| Rating | The scale’s anchors | The engagement lead, calibrated; the CAE on appeal | Finding record, stage 6, with the anchor named |
| Consequence | The mechanism and any realized example | The auditor; the audit committee if management’s disagreement persists | The report; the CAE’s summary to the committee where material |
The response evaluation memo
The evaluation of a response is a judgment, and judgments in an audit file are documented. The memo below is a half-page per finding, completed by the engagement lead before the draft is finalized, and it is the document a reviewer, an external assessor or a regulator reads to see whether the function evaluated responses or merely collected them.
Response evaluation memo. 1. Finding: number, title, rating, and the cause element in one sentence. 2. Response received: date, from whom, and the response type from the taxonomy. 3. Five tests: for each of cause, specificity, ownership, timing and proportion, pass or fail with one line of reasoning. 4. Disputes: any dispute of facts, cause, rating or consequence, how it was resolved, and what changed as a result. 5. Interim risk: for a High or Medium with a fix more than a quarter away, the interim measure agreed, or a statement that none was and why. 6. Returned for revision: whether the response was returned, on what date, with which tests named, and what the revised response changed. 7. Conclusion: accepted as adequate; accepted with the residual risk noted; or not accepted, with the escalation path taken. 8. Validation standard: the evidence closure will require, agreed with management now so that it is not argued about later.
Worked examples: five responses and what happened to them
The five responses below come from engagements written up elsewhere on this site, at the three organizations used across it. Each shows the initial response, the evaluation against the five tests, what was returned and why, and the outcome a year later where one is known.
| Finding | Initial response | Evaluation | Revised response and outcome |
|---|---|---|---|
| Brightwater Foods, procurement audit: the sole-source program (High), 57 awards, six of fifteen re-performed market checks finding alternatives | “Sole-source awards are justified case by case by experienced buyers; we do not agree the program is deficient.” A dispute of cause and rating. | Facts not disputed. Cause disputed: management’s cause was buyer experience; the audit’s was the absence of a memo standard and a market-check requirement. Rating held against the anchor for a control absent by design. The six re-performed checks, twenty minutes each, put on the table. | Accepted after the checks: the justification memo template adopted, approval one level up enforced, the standing sanitation-chemicals arrangement competed. A year later the rate had fallen from 16 to 11 percent and the memo was in use on 17 of 19 awards. |
| MidState Beverage, travel and expense audit: three effective policies and no card program at the acquired distributors (High) | “We will review the policies across entities during the next year.” A review response to a design finding. | Failed tests 1, 2 and 4: the review did not change the design, could not be validated, and a High carried an undated fix. Returned with the tests named. | Revised: one policy adopted by the end of the quarter, card program extended to the acquired distributors within two quarters, owner the chief financial officer. Accepted; the fix cost less than the audit. |
| MidState Beverage, order-to-cash audit: the allowance method unchanged since 2019 (Medium) | “The allowance will be reviewed as part of the year-end close.” A review response, with the review already scheduled. | Failed test 1: the annual review was the control that had failed, so promising it again changed nothing. Failed test 2: nothing testable. Returned. | Revised: the method re-based on three years of write-off history by the year-end close, with the annual review documented as a re-performance; internal audit to observe the first re-basing. Accepted. |
| Lakeshore Bancorp, third-party risk audit: concentration of the core provider’s disaster recovery, digital banking and account opening in one public cloud region | “The concentration is a consequence of the market; the board accepts the risk.” A risk acceptance. | Not an action plan and not evaluated as one. Test of authority: the board had the authority. Test of documentation: the acceptance was minuted with the rationale. The chief audit executive’s view, that the risk was material and the acceptance should be revisited annually, was minuted beside it under Standard 11.5. | Accepted as a documented risk acceptance; reported to the audit committee as such; the annual revisit added to the board calendar. Covered in the risk acceptance guide. |
| Pennine Foods plc, financial close audit: balance sheet reconciliations (High), with three external auditor points on the same accounts open for more than a year | “Ownership of the affected reconciliations will be redistributed.” A staffing response from the controller, who had made the same commitment to the external auditor the year before. | Passed tests 1 and 2 in isolation; failed test 3 in context, because the owner had not delivered the same commitment once already. Returned with a request that the chief financial officer own the plan and that the escalation of the status report be part of it. | Revised: ownership redistributed by the next close, roll-forward disabled in the tool, status report escalated monthly to the chief financial officer, the fourteen differences cleared by the half-year, owner the chief financial officer. Accepted and reported to the audit committee with the Provision 29 consequence. |
The pattern across the five is that the returned responses were returned with a test named, not with an opinion, and that the revised responses arrived within days because the test told management what was missing. The one response that was not an action plan, Lakeshore’s, was handled as what it was rather than argued with, which is the subject of the risk acceptance guide.
Pushing back without a fight: three scripts
Returning a response is a conversation most auditors avoid, because it feels like telling a senior manager their answer is wrong. It is not; it is telling them which test the answer did not pass, which is a different conversation and a shorter one. The three scripts below cover the common cases.
The review response. “Thanks for this. The plan commits to a review, and I need to be able to validate the finding as closed a year from now, which I cannot do against a review. Can we add what the review will decide, the date it will decide it by, and what happens to the risk between now and then? If the answer to the last one is nothing, I will need to say so in the report.”
The reminder or training response. “I want to make sure the plan matches the cause we agreed. The cause is that the system lets the person who enters a change approve it. A reminder tells people not to do what the system allows; it does not stop the next person. Is there a reason the system cannot be configured to block it? If there is, let us put the compensating control in the plan instead, with who performs it and how often.”
The response with the wrong owner or an undated fix. “The plan is right; the owner and the date are what I need to check. The fix needs budget and a system change, and the named owner does not control either, so I would like the plan to name the person who does. And because this is a High, a date eighteen months out needs an interim step, even a manual one, so that the report can say what protects us in the meantime. Can we agree both today so that the draft goes out on schedule?”
When to escalate, to whom, and how fast
Most responses are resolved between the engagement lead and the process owner within a week of the draft. The ones that are not follow a ladder whose rungs everyone knows in advance, because an escalation nobody expected is an ambush and an escalation everyone expected is governance. The ladder has four rungs. The engagement lead returns the response with the failed tests named and a date, usually five working days. If the revised response still fails, the audit manager or chief audit executive discusses it with the process owner’s manager, with the finding, the response and the tests in front of both. If that fails, the chief audit executive discusses it with the executive responsible, and the outcome is one of three: an adequate plan, a documented risk acceptance, or a disagreement. A disagreement about a finding rated High, or about a risk acceptance the chief audit executive considers unacceptable, goes to the audit committee under Standard 11.5, in the report or in the CAE’s summary, with management’s position stated fairly beside the function’s. The whole ladder should take less than the draft-to-final interval the life of a finding sets at fifteen working days; a report held for two months while a response is argued is a report whose facts are aging.
The interim measure: what protects the organization while the fix is built
The best responses to control findings are system changes, and system changes take quarters. The gap between the report and the fix is where the risk continues to run, and a response for a High or a Medium is not complete until it says what happens in the gap. Interim measures are usually detective and manual: a monthly review of the population the control should have prevented, a report of exceptions to a named manager, a temporary second approval performed by hand, a sample re-performed by the process owner until the workflow is live. They have to be specific enough to validate, owned by someone who will perform them, and dated to end when the permanent fix arrives. The evaluation memo records the interim measure at item 5, the report states it beside the permanent action, and the follow-up tests both: whether the interim measure operated in the gap, and whether the permanent fix replaced it. A High finding with no interim measure is a risk acceptance for the duration of the gap, and should be described as one in the report so that the audit committee knows what it is accepting.
Responses at the report level: the overall conclusion and the summary response
Findings carry individual responses; reports carry an overall conclusion under Standard 14.5 and usually a summary response from the executive responsible. The summary response is where an audit’s rating is contested at the level that matters, and the same discipline applies: the facts were validated, the findings’ ratings are anchored to the scale, and the overall rating follows from the findings under the function’s stated rule, so that a summary response disputing the overall rating has to dispute either a finding’s rating or the rule, and both are things the function can point to. The engagement lead evaluates the summary response for one thing above all: whether it commits the executive to the action plans beneath it, or whether it stands apart from them, thanking the auditors for their work while the process owners’ plans quietly promise reviews. A summary response that says “the executive team has reviewed and endorsed the action plans below and will report progress to the audit committee quarterly” is worth more than any individual response in the report, because it names the person the committee will ask.
A calibration exercise for the function
A function can test the quality of its own response evaluation in an afternoon. Take the last twenty findings rated High or Medium, read each response against the five tests without looking at the original evaluation, and classify the response type from the taxonomy. Then look at the follow-up file: how many were validated as closed, how many closed with a residual, how many are still open past their date, and how many were reborn in a later engagement. The pattern is usually the same. Responses that were reviews, reminders or training are the ones still open or reborn; responses that were system changes with interim measures are the ones closed. If the function has been accepting the first kind, the exercise shows the cost, and the five tests become the standard from the next draft onward. The issue log template has the fields to run the exercise from, and the life of a finding has the failure patterns the exercise will find.
Common mistakes
Pasting the response under the finding without evaluating it. Writing the response for management and then validating it against themselves. Accepting a review, a reminder or a training against a design cause. Accepting an owner who cannot deliver, because the right owner is senior and the conversation is uncomfortable. Issuing a High with a distant date and no interim measure. Letting a dispute of facts reopen at the draft stage instead of settling it at fact validation. Arguing ratings on proportion rather than on the scale’s anchors. Treating a risk acceptance as a bad action plan and arguing with it, instead of testing its authority and documentation. Holding the report while the argument runs. And failing to write down the evaluation, so that a year later nobody can say whether the function accepted the plan or merely received it.
Where to go next
Evaluate every response against the five tests before it goes into the draft, name the failed test when you return it, insist on a cause-level fix for design findings and an interim measure for Highs, and write the evaluation down. The stages before and after the response are in the life of a finding; the response that is not a plan is in the risk acceptance guide; the argument about wording and rating that follows the response is in the negotiating findings guide; and the structure the response sits in is in the anatomy of an audit report.
Related guides
- The life of a finding — the twelve stages the response sits in the middle of
- Risk acceptance by management — the response that is not an action plan
- Negotiating findings without watering them down — scripts and the escalation ladder for the draft stage
- Anatomy of an audit report — where the response appears and how it is formatted
- The 5 C’s of audit findings — the cause element the response has to address
- Root cause analysis for audit findings — writing a cause an action plan can fix
- Finding severity ratings — the scale anchors rating disputes are settled against
- The finding and issue log template — where the accepted plan is tracked
- Issue validation in internal audit — the evidence standard the memo’s item 8 sets
- Treating high-risk issues differently — why a High needs an interim measure
- Internal audit report examples — responses in the model reports
- How to audit procurement — the sole-source response, in context
- How to audit travel and expense — the policy fragmentation response
- How to audit order-to-cash end to end — the allowance response
- Third-party risk management end to end — the cloud concentration acceptance
- How to audit the financial close — the reconciliation response
- Findings and reporting guides and issue validation guides — the full collections
- Writing Airtight Audit Conditions — stating what is, without editorializing.
- Writing Cause Statements That Point to the Fix — causal logic on paper.
- Writing Impact That Lands — audit consequences in dollars, risk and plain sight.
- Writing Audit Recommendations Management Can Actually Implement — owners, dates and end states.
- Finding Makeovers — five real-shaped audit findings rewritten before your eyes.
Leave a Reply