KITE 2025 New Product Award — Local IT | SACEEC

What is a Follow-Up Audit? Verifying Remediation Actually Worked

Agreeing a fix is not the same as fixing the problem. A follow-up audit verifies remediation actually happened, and actually works.

Free PDF GuideDownload this guide as a PDF

An audit identifies weaknesses; management agrees to fix them. But a promise to fix is not a fix, and a fix that exists on paper is not always a control that works in practice. The follow-up audit is the discipline that closes this gap. It is the formal verification that remediation actually happened and actually reduced the risk, turning agreed recommendations into demonstrable improvement rather than good intentions.

Watch: What is a follow-up audit and how to run one Watch: Understanding follow-up audits (short explainer)
i

What You'll Learn

This guide explains what a follow-up audit is and why it matters, when to run one, how to scope it, how to validate remediation evidence, how to re-rate residual risk, and how to report items that remain unresolved, illustrated with a worked outcome table.

What is a Follow-Up Audit?

A follow-up audit is a targeted review whose sole purpose is to verify whether the recommendations from a previous audit have been implemented and are effective. It is not a fresh audit of the area; it is a focused re-examination of specific agreed actions. The original audit asked, "Are the controls adequate?" The follow-up audit asks a narrower, sharper question: "Did the fixes we agreed actually happen, and do they work?"

This distinction matters. A follow-up audit deliberately constrains its scope to the open recommendations, the underlying findings they address, and the controls those findings concern. It draws its worklist directly from the recommendations tracker, which is why a well-maintained tracker is the foundation of every effective follow-up.

Verification Versus Confirmation

The core of a follow-up audit is independent verification, not management confirmation. It is easy, and worthless, to email the owner and ask "is this done?" The follow-up audit instead obtains and tests evidence that the control exists and operates. Management confirms; audit verifies. That difference is the entire reason the follow-up audit exists.

Why Follow-Up Audits Matter

Organizations that skip follow-up audits tend to discover the same weaknesses cycle after cycle. The follow-up audit delivers value in several specific ways:

  • It closes the loop on risk. A finding represents elevated residual risk. Only verified remediation actually brings that residual risk back down; an unverified "closed" recommendation may have changed nothing.
  • It deters paper fixes. When owners know their remediation will be independently tested, they are far more likely to implement real, durable controls rather than cosmetic ones.
  • It gives the board genuine assurance. Reporting that recommendations are "implemented" means little; reporting that they are "verified effective" is the assurance the audit committee actually wants.
  • It catches partial and failed fixes early. Some remediations are well-intentioned but ineffective. The follow-up surfaces these before they cause harm.
i

Pro Tip

Treat the follow-up audit as the only legitimate route to closing a high or critical recommendation. Lower-rated actions can often close on documented evidence alone, but the items that could genuinely hurt the organization deserve independent re-testing before anyone calls them done.

When to Run a Follow-Up Audit

You do not need a full follow-up audit for every recommendation; that would be disproportionate. The decision turns mainly on the rating of the original findings and the credibility of the remediation. Use a risk-based trigger:

Original finding rating Follow-up approach Typical timing
Critical Dedicated follow-up audit with control testing Shortly after the agreed due date
High Follow-up audit or focused re-test of the control Within 1 to 3 months of due date
Medium Evidence review; sample re-test if doubt remains At next scheduled audit of the area
Low Documented evidence confirmation only Periodic tracker review

Timing matters as much as triggering. Run the follow-up far enough after the due date that the new control has been operating long enough to test, since you cannot sample a quarterly reconciliation that has only run once, but soon enough that an unresolved high risk is not left exposed for long.

Want the full framework with worked examples?

Scoping the Follow-Up Audit

A disciplined follow-up audit defines its scope tightly around three things:

  1. The specific recommendations being verified. List them explicitly, with their IDs from the tracker, so the review has clear boundaries.
  2. The control or outcome each recommendation was meant to deliver. The follow-up tests whether that outcome now exists, not whether activity occurred.
  3. The evidence and testing needed to verify each one. Decide in advance what would constitute proof: a configuration, a sample of the control operating, a re-performance.

Resist scope creep. If the follow-up uncovers a new, unrelated weakness, note it for the audit plan rather than expanding the follow-up into a full re-audit. Keeping the scope tight is what makes follow-up audits efficient and repeatable. The way you scope it parallels the broader planning you would do in any audit. See how to prepare an audit risk register for how risk drives scope decisions, and what an internal audit actually looks like for the full lifecycle context.

Validating Remediation Evidence

The heart of a follow-up audit is testing whether each remediation genuinely addresses its root cause. Evidence falls along a spectrum of strength, and the rule is simple: the higher the original risk, the stronger the evidence required.

Evidence type What it proves Strength
Owner attestation That management believes it is done Weak
Document or policy That a rule now exists on paper Moderate
System configuration That the control is technically enabled Moderate to strong
Sample of the control operating That the control actually runs in practice Strong
Re-performance / live test That the control prevents the original failure Strongest

A common trap is accepting that a control exists as proof that it works. A newly published policy is a document, not a behavior change. A configured system rule still needs a sample showing it operated as intended. For a critical finding, the gold standard is re-performance: attempt the action the control is meant to block, and confirm the control blocks it.

!

Important

Verify against the original root cause, not the remediation activity. If the finding was that single-person approvals enabled fraud, evidence of "a new approval policy" does not close it. Evidence that two distinct approvers are now enforced on real transactions does.

Re-Rating Residual Risk

Once you have verified a remediation, the follow-up audit re-assesses the residual risk of the original finding. This is what makes the follow-up meaningful: it does not just record "done," it states how much the risk has actually fallen. Three outcomes are possible:

  • Risk reduced to acceptable: The control works, residual risk is now within appetite, and the recommendation can be formally closed.
  • Risk partially reduced: The remediation helped but did not fully address the cause; residual risk remains above appetite, so the action stays open with a revised plan.
  • Risk unchanged: The remediation failed or was never genuinely implemented; the finding stands and may need escalation.

Re-rating uses the same likelihood and impact scoring as the original assessment, so the before-and-after comparison is meaningful. Showing a finding move from, say, a residual rating of High down to Low is far more persuasive to a board than a binary "closed" flag.

Example

Follow-Up Audit Outcome Table

A follow-up audit of three recommendations from a procurement audit produced the following outcomes:

Recommendation Evidence tested Residual risk before Residual risk after Outcome
Enforce dual approval above threshold System rule + sample of 5 POs + rejected single-approver test High Low Closed
Deactivate dormant vendor records Sample showed 12 of 40 dormant vendors still active High Medium Remains open
Quarterly vendor master review Owner attestation only; review never performed Medium Medium Remains open, escalated

Only one of the three closed. The dual-approval control was verified end to end and the risk dropped two levels. The vendor deactivation was partially done, so the residual risk fell but stayed open. The quarterly review had no evidence beyond a claim, so it was escalated. This is exactly the nuance a follow-up audit exists to surface.

Reporting Unresolved Items

A follow-up audit is only as valuable as the action it triggers on the items that did not close. Reporting should make the unresolved items impossible to ignore:

  • State clearly what remains open and why. Distinguish between remediations that partially worked and those that were never genuinely attempted, because they warrant different responses.
  • Re-state the residual risk. Quantify what the organization is still exposed to, using the re-rated score.
  • Escalate repeat failures. A recommendation that is open at a second follow-up is a governance signal in itself and belongs in front of the audit committee.
  • Feed results back into the tracker. Update statuses, revised dates, and the verification record so the next cycle starts from an accurate baseline.

These results flow naturally into the broader status reporting you give the board. The unresolved high-risk items from a follow-up audit are among the most important entries in a board risk report and a key part of how you present audit results to the board.

Common Mistakes to Avoid

1. Accepting Attestation as Verification

An owner saying "it's done" is not evidence. The whole point of a follow-up audit is independent testing, so obtain and examine proof.

2. Confirming Existence, Not Effectiveness

A policy that exists is not a control that works. Test whether the remediation actually operates and prevents the original failure.

3. Testing Too Early

You cannot verify a control that has not run yet. Time the follow-up so the new control has operated long enough to sample.

4. Letting Scope Creep

Expanding a follow-up into a full re-audit when you spot something new defeats its efficiency. Note new issues for the plan and keep scope tight.

5. Reporting a Binary "Closed"

A flat closed/open flag hides nuance. Re-rate the residual risk so the board sees how much exposure actually changed.

6. Not Escalating Repeat Failures

A recommendation still open at a second follow-up is a governance issue. Failing to escalate it lets serious risk persist quietly.

Key Takeaways

Summary

  • A follow-up audit verifies whether previous recommendations were implemented and actually work. It is verification, not confirmation.
  • Trigger follow-ups on a risk basis; critical and high findings warrant dedicated re-testing, lower ratings need lighter checks.
  • Scope tightly around specific recommendations and resist scope creep into a full re-audit.
  • Match evidence strength to risk; for critical controls, re-perform the test to prove the original failure is prevented.
  • Re-rate residual risk so the report shows how much exposure actually fell, not just a binary "closed."
  • Report unresolved items clearly, escalate repeat failures, and feed results back into the recommendations tracker.

Frequently Asked Questions

How is a follow-up audit different from the original audit?

The original audit assesses whether controls in an area are adequate; the follow-up audit narrowly verifies whether the specific recommendations from that audit were implemented and are effective. The follow-up is tightly scoped to the open actions and their underlying findings, drawing its worklist from the recommendations tracker rather than re-examining the whole area.

Do I need a follow-up audit for every recommendation?

No, that would be disproportionate. Use a risk-based approach: critical and high findings warrant dedicated follow-up audits with control testing, medium findings usually need an evidence review with a sample re-test if doubt remains, and low findings can often close on documented evidence confirmed during a routine tracker review.

When is the right time to run a follow-up audit?

Time it so the new control has been operating long enough to test meaningfully, since you cannot sample a control that has run only once, but soon enough after the due date that an unresolved high risk is not left exposed. For a quarterly control, that often means a few months after implementation so there are several instances to sample.

What evidence is strong enough to close a high-risk finding?

For a high or critical finding, attestation or a policy document is not enough. You want a sample showing the control actually operating, ideally combined with re-performance: attempting the action the control is meant to block and confirming it is prevented. The evidence must demonstrate that the original root cause is resolved, not merely that some activity took place.

What happens if remediation has not worked?

The finding stays open and you re-state the residual risk. Distinguish between a partial fix that needs a revised plan and a remediation that was never genuinely attempted. A recommendation still open at a second follow-up is itself a governance signal and should be escalated to the audit committee with a clear account of the continuing exposure.

Why re-rate residual risk instead of just marking items closed?

A binary closed/open flag hides whether the risk actually fell. Re-rating with the same likelihood and impact scoring used in the original assessment shows the board a meaningful before-and-after, for example a finding moving from High to Low. That comparison is far more persuasive and honest than simply asserting an action is done.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.