For internal auditors out there, do you perform post-audit reviews as part of your QAIP? If so, do you require action plans from your team members to resolve any gaps or improvement opportunities? 

962 viewscircle icon4 Comments
Sort by:
Finance Manager2 years ago

Short answer is yes. Post-audit reviews are performed by an independent team on a sample of audits. Actions to resolve any gaps are agreed and tracked to resolution. The approach to action plans about improvement opportunities is probably less mature.

1 Reply
no titlea year ago

Thanks Stephen!

Audit Practices Senior in Banking2 years ago

Yes we do perform post-audit reviews to the IIA standards as well as our internal policies and procedures. We have two categories of gap identification; findings and comments. Findings are more severe and would require the team to go back into the file and address large gaps in scope, documentation, etc. These findings always have an action plan that is tracked in our GRC tool. For comments, these are mostly items that we want to point out for future reference but do not require action plans or for the team to make changes to the archived audit file. 

1 Reply
no title2 years ago

Thanks Emily! Currently, we don't require the team to fix the large gaps. We just summarize the gaps in our lessons learned database. But I believe for large gaps they should fix it.

Content you might like

Coverage—AI claims full scan, but misses deep flaws35%

Speed—AI is fast but error-prone69%

Creativity—AI scripts can’t improvise12%

Integration—vendor tools don’t plug into DevSecOps23%

View Results

Lack of mature vendor solutions52%

Trust in AI accuracy69%

Budget constraints21%

Skills to operate the tools28%

View Results