An audit identifies weaknesses; management agrees to fix them. But a promise to fix is not a fix, and a fix that exists on paper is not always a control that works in practice. The follow-up audit is the discipline that closes this gap. It is the formal verification that remediation actually happened and actually reduced the risk, turning agreed recommendations into demonstrable improvement rather than good intentions.
What You'll Learn
This guide explains what a follow-up audit is and why it matters, when to run one, how to scope it, how to validate remediation evidence, how to re-rate residual risk, and how to report items that remain unresolved, illustrated with a worked outcome table.
What is a Follow-Up Audit?
A follow-up audit is a targeted review whose sole purpose is to verify whether the recommendations from a previous audit have been implemented and are effective. It is not a fresh audit of the area; it is a focused re-examination of specific agreed actions. The original audit asked, "Are the controls adequate?" The follow-up audit asks a narrower, sharper question: "Did the fixes we agreed actually happen, and do they work?"
This distinction matters. A follow-up audit deliberately constrains its scope to the open recommendations, the underlying findings they address, and the controls those findings concern. It draws its worklist directly from the recommendations tracker, which is why a well-maintained tracker is the foundation of every effective follow-up.
Verification Versus Confirmation
The core of a follow-up audit is independent verification, not management confirmation. It is easy, and worthless, to email the owner and ask "is this done?" The follow-up audit instead obtains and tests evidence that the control exists and operates. Management confirms; audit verifies. That difference is the entire reason the follow-up audit exists.
Why Follow-Up Audits Matter
Organizations that skip follow-up audits tend to discover the same weaknesses cycle after cycle. The follow-up audit delivers value in several specific ways:
- It closes the loop on risk. A finding represents elevated residual risk. Only verified remediation actually brings that residual risk back down; an unverified "closed" recommendation may have changed nothing.
- It deters paper fixes. When owners know their remediation will be independently tested, they are far more likely to implement real, durable controls rather than cosmetic ones.
- It gives the board genuine assurance. Reporting that recommendations are "implemented" means little; reporting that they are "verified effective" is the assurance the audit committee actually wants.
- It catches partial and failed fixes early. Some remediations are well-intentioned but ineffective. The follow-up surfaces these before they cause harm.
Pro Tip
Treat the follow-up audit as the only legitimate route to closing a high or critical recommendation. Lower-rated actions can often close on documented evidence alone, but the items that could genuinely hurt the organization deserve independent re-testing before anyone calls them done.
When to Run a Follow-Up Audit
You do not need a full follow-up audit for every recommendation; that would be disproportionate. The decision turns mainly on the rating of the original findings and the credibility of the remediation. Use a risk-based trigger:
| Original finding rating | Follow-up approach | Typical timing |
|---|---|---|
| Critical | Dedicated follow-up audit with control testing | Shortly after the agreed due date |
| High | Follow-up audit or focused re-test of the control | Within 1 to 3 months of due date |
| Medium | Evidence review; sample re-test if doubt remains | At next scheduled audit of the area |
| Low | Documented evidence confirmation only | Periodic tracker review |
Timing matters as much as triggering. Run the follow-up far enough after the due date that the new control has been operating long enough to test, since you cannot sample a quarterly reconciliation that has only run once, but soon enough that an unresolved high risk is not left exposed for long.
Want the full framework with worked examples?
Scoping the Follow-Up Audit
A disciplined follow-up audit defines its scope tightly around three things:
- The specific recommendations being verified. List them explicitly, with their IDs from the tracker, so the review has clear boundaries.
- The control or outcome each recommendation was meant to deliver. The follow-up tests whether that outcome now exists, not whether activity occurred.
- The evidence and testing needed to verify each one. Decide in advance what would constitute proof: a configuration, a sample of the control operating, a re-performance.
Resist scope creep. If the follow-up uncovers a new, unrelated weakness, note it for the audit plan rather than expanding the follow-up into a full re-audit. Keeping the scope tight is what makes follow-up audits efficient and repeatable. The way you scope it parallels the broader planning you would do in any audit. See how to prepare an audit risk register for how risk drives scope decisions, and what an internal audit actually looks like for the full lifecycle context.
Validating Remediation Evidence
The heart of a follow-up audit is testing whether each remediation genuinely addresses its root cause. Evidence falls along a spectrum of strength, and the rule is simple: the higher the original risk, the stronger the evidence required.
| Evidence type | What it proves | Strength |
|---|---|---|
| Owner attestation | That management believes it is done | Weak |
| Document or policy | That a rule now exists on paper | Moderate |
| System configuration | That the control is technically enabled | Moderate to strong |
| Sample of the control operating | That the control actually runs in practice | Strong |
| Re-performance / live test | That the control prevents the original failure | Strongest |
A common trap is accepting that a control exists as proof that it works. A newly published policy is a document, not a behavior change. A configured system rule still needs a sample showing it operated as intended. For a critical finding, the gold standard is re-performance: attempt the action the control is meant to block, and confirm the control blocks it.
Important
Verify against the original root cause, not the remediation activity. If the finding was that single-person approvals enabled fraud, evidence of "a new approval policy" does not close it. Evidence that two distinct approvers are now enforced on real transactions does.
Re-Rating Residual Risk
Once you have verified a remediation, the follow-up audit re-assesses the residual risk of the original finding. This is what makes the follow-up meaningful: it does not just record "done," it states how much the risk has actually fallen. Three outcomes are possible:
- Risk reduced to acceptable: The control works, residual risk is now within appetite, and the recommendation can be formally closed.
- Risk partially reduced: The remediation helped but did not fully address the cause; residual risk remains above appetite, so the action stays open with a revised plan.
- Risk unchanged: The remediation failed or was never genuinely implemented; the finding stands and may need escalation.
Re-rating uses the same likelihood and impact scoring as the original assessment, so the before-and-after comparison is meaningful. Showing a finding move from, say, a residual rating of High down to Low is far more persuasive to a board than a binary "closed" flag.
Follow-Up Audit Outcome Table
A follow-up audit of three recommendations from a procurement audit produced the following outcomes:
| Recommendation | Evidence tested | Residual risk before | Residual risk after | Outcome |
|---|---|---|---|---|
| Enforce dual approval above threshold | System rule + sample of 5 POs + rejected single-approver test | High | Low | Closed |
| Deactivate dormant vendor records | Sample showed 12 of 40 dormant vendors still active | High | Medium | Remains open |
| Quarterly vendor master review | Owner attestation only; review never performed | Medium | Medium | Remains open, escalated |
Only one of the three closed. The dual-approval control was verified end to end and the risk dropped two levels. The vendor deactivation was partially done, so the residual risk fell but stayed open. The quarterly review had no evidence beyond a claim, so it was escalated. This is exactly the nuance a follow-up audit exists to surface.
Reporting Unresolved Items
A follow-up audit is only as valuable as the action it triggers on the items that did not close. Reporting should make the unresolved items impossible to ignore:
- State clearly what remains open and why. Distinguish between remediations that partially worked and those that were never genuinely attempted, because they warrant different responses.
- Re-state the residual risk. Quantify what the organization is still exposed to, using the re-rated score.
- Escalate repeat failures. A recommendation that is open at a second follow-up is a governance signal in itself and belongs in front of the audit committee.
- Feed results back into the tracker. Update statuses, revised dates, and the verification record so the next cycle starts from an accurate baseline.
These results flow naturally into the broader status reporting you give the board. The unresolved high-risk items from a follow-up audit are among the most important entries in a board risk report and a key part of how you present audit results to the board.
Common Mistakes to Avoid
1. Accepting Attestation as Verification
An owner saying "it's done" is not evidence. The whole point of a follow-up audit is independent testing, so obtain and examine proof.
2. Confirming Existence, Not Effectiveness
A policy that exists is not a control that works. Test whether the remediation actually operates and prevents the original failure.
3. Testing Too Early
You cannot verify a control that has not run yet. Time the follow-up so the new control has operated long enough to sample.
4. Letting Scope Creep
Expanding a follow-up into a full re-audit when you spot something new defeats its efficiency. Note new issues for the plan and keep scope tight.
5. Reporting a Binary "Closed"
A flat closed/open flag hides nuance. Re-rate the residual risk so the board sees how much exposure actually changed.
6. Not Escalating Repeat Failures
A recommendation still open at a second follow-up is a governance issue. Failing to escalate it lets serious risk persist quietly.
Summary
- A follow-up audit verifies whether previous recommendations were implemented and actually work. It is verification, not confirmation.
- Trigger follow-ups on a risk basis; critical and high findings warrant dedicated re-testing, lower ratings need lighter checks.
- Scope tightly around specific recommendations and resist scope creep into a full re-audit.
- Match evidence strength to risk; for critical controls, re-perform the test to prove the original failure is prevented.
- Re-rate residual risk so the report shows how much exposure actually fell, not just a binary "closed."
- Report unresolved items clearly, escalate repeat failures, and feed results back into the recommendations tracker.
Frequently Asked Questions
How is a follow-up audit different from the original audit?
The original audit assesses whether controls in an area are adequate; the follow-up audit narrowly verifies whether the specific recommendations from that audit were implemented and are effective. The follow-up is tightly scoped to the open actions and their underlying findings, drawing its worklist from the recommendations tracker rather than re-examining the whole area.
Do I need a follow-up audit for every recommendation?
No, that would be disproportionate. Use a risk-based approach: critical and high findings warrant dedicated follow-up audits with control testing, medium findings usually need an evidence review with a sample re-test if doubt remains, and low findings can often close on documented evidence confirmed during a routine tracker review.
When is the right time to run a follow-up audit?
Time it so the new control has been operating long enough to test meaningfully, since you cannot sample a control that has run only once, but soon enough after the due date that an unresolved high risk is not left exposed. For a quarterly control, that often means a few months after implementation so there are several instances to sample.
What evidence is strong enough to close a high-risk finding?
For a high or critical finding, attestation or a policy document is not enough. You want a sample showing the control actually operating, ideally combined with re-performance: attempting the action the control is meant to block and confirming it is prevented. The evidence must demonstrate that the original root cause is resolved, not merely that some activity took place.
What happens if remediation has not worked?
The finding stays open and you re-state the residual risk. Distinguish between a partial fix that needs a revised plan and a remediation that was never genuinely attempted. A recommendation still open at a second follow-up is itself a governance signal and should be escalated to the audit committee with a clear account of the continuing exposure.
Why re-rate residual risk instead of just marking items closed?
A binary closed/open flag hides whether the risk actually fell. Re-rating with the same likelihood and impact scoring used in the original assessment shows the board a meaningful before-and-after, for example a finding moving from High to Low. That comparison is far more persuasive and honest than simply asserting an action is done.
Save this guide for later
Download the PDF version to read offline or share with your team.

