KITE 2025 New Product Award — Local IT | SACEEC

How Do You Track Audit Recommendations? A Practical Tracker Workflow

Findings only create value when they get fixed. Learn how to build a recommendations tracker that drives remediation to closure.

Free PDF GuideDownload this guide as a PDF

An internal audit report is only the beginning. Its real value lies in whether the recommendations inside it actually get implemented. Yet in many organizations, recommendations are agreed in the closing meeting, written into the report, and then quietly forgotten until the next audit re-discovers the same weakness. A disciplined recommendations tracker is what turns audit findings into durable improvement.

Watch: How to build and run an audit recommendations tracker Watch: Build an audit recommendations tracker (short tutorial)
i

What You'll Learn

By the end of this tutorial you will know exactly what fields a recommendations tracker needs, how to set a follow-up cadence, how to manage overdue actions without nagging blindly, how to report status to the audit committee, and how to close a recommendation properly with evidence.

Why a Recommendations Tracker Matters

Every audit produces a set of findings, and each finding is paired with one or more recommendations, the agreed actions that management will take to address the root cause. Without a structured tracker, those actions disperse into individual inboxes, project plans, and good intentions. Three predictable problems follow:

  • Repeat findings: The same control weakness reappears in the next cycle because the original fix was never completed or never worked.
  • No line of sight: Leadership and the audit committee cannot answer the basic question, "Are we closing what we said we would?"
  • Audit credibility erodes: If recommendations rarely close, the function looks like it generates paperwork rather than improvement.

A tracker fixes this by making remediation visible, owned, and time-bound. It is the bridge between the report and the actual reduction of residual risk. It is also the source of truth that feeds a follow-up audit when one is warranted.

The Core Fields Your Tracker Needs

A recommendations tracker is essentially a structured register, conceptually close to a risk register used by internal audit but focused on actions rather than risks. Keep it lean. Every field should earn its place by supporting a decision or a status update. The set below covers what almost any organization needs:

Field Purpose Example
Recommendation ID Unique reference for tracking and reporting AUD-2026-014-R2
Source audit Links the action back to its report Procurement Audit Q1 2026
Finding The weakness the action addresses No segregation between requisition and approval
Rating Priority inherited from the finding High
Recommendation The agreed action, stated as an outcome Enforce dual approval in the procurement system
Owner Single accountable person, not a department Head of Procurement
Agreed due date The committed completion date 30 June 2026
Status Where the action stands now In progress
Evidence Proof of completion attached at closure System config screenshot + change ticket
Validation Who confirmed the action worked Audit, 12 July 2026

Two fields deserve special attention. The owner must be a named individual with the authority to deliver the action, never a team or a job title shared by five people. And the recommendation text should describe an outcome ("dual approval is enforced for all purchases above the threshold"), not an activity ("review the approval process"). An outcome-based recommendation is one you can actually verify as done.

i

Pro Tip

Carry the finding's rating into the tracker as a priority field. It lets you sort the whole population so that high and critical actions get follow-up attention first, instead of treating a minor documentation gap with the same urgency as a control that exposes the organization to fraud.

Want the full framework with worked examples?

Defining a Clear Status Model

Ambiguous status values are where trackers go to die. "In progress" can mean anything from "we started yesterday" to "it has been ninety percent done for six months." Define a small, unambiguous set of statuses and apply them consistently:

  • Open / Not started: Agreed but no work has begun.
  • In progress: Work is actively underway against the agreed plan.
  • Implemented (pending validation): Management says it is done; audit has not yet verified.
  • Closed: Audit has validated the action with evidence and confirmed it addresses the finding.
  • Overdue: The agreed due date has passed without closure.
  • Risk accepted: Management has formally chosen not to implement, with sign-off at the appropriate level.

The distinction between "implemented" and "closed" is the single most important discipline in the whole model. Management implements; audit closes. An action only moves to Closed when audit has seen evidence that the control exists and works, not merely a claim that it has been done.

!

Important

Do not let owners self-close their own recommendations. If the same person who owns the fix can also mark it complete with no independent check, your tracker measures optimism, not remediation. Reserve the move to "Closed" for the audit function.

Setting a Follow-Up Cadence

A tracker that is reviewed once a year is barely a tracker. The cadence of follow-up should be proportionate to the rating of the action, so that scarce attention goes where the risk is highest:

Rating Follow-up frequency Escalation trigger
Critical Every 2 to 4 weeks Any slippage past due date
High Monthly 30 days overdue
Medium Quarterly One full quarter overdue
Low Semi-annually Two cycles overdue

The follow-up itself does not have to be heavy. For most actions it is a short status confirmation from the owner: still on track, evidence attached, or a flagged blocker. The point is rhythm. When the cadence is predictable, owners expect to be asked, plan for it, and rarely reach the due date with nothing to show.

Make Follow-Up Light but Relentless

The most effective audit teams automate the reminder so the human conversation is reserved for genuine problems. The system pings owners ahead of the due date, and the auditor only steps in when something is stuck. That keeps the relationship constructive. You are a partner helping the action land, not a debt collector.

Managing Overdue Recommendations

Overdue actions are inevitable; what matters is how you handle them. A mature process distinguishes between a slipped date with a credible new plan and a recommendation that is quietly being abandoned.

1. Confirm the Reason

When an action goes overdue, the first step is to understand why. Common causes include competing priorities, a dependency on a system change, a reorganization that moved the owner, or genuine technical difficulty. The reason determines the response.

2. Re-baseline Deliberately, Not Casually

If a new date is justified, record a revised due date, but keep the original agreed date visible too. A recommendation that has been re-dated three times is telling you something the current date alone would hide. Trackers that simply overwrite the due date erase this signal.

3. Escalate by Exception

Use the escalation triggers from your cadence table. When a high-rated action passes 30 days overdue, it should appear on an escalation list that goes to the executive sponsor and, if it persists, to the audit committee. Escalation is not punishment. It surfaces the resourcing or prioritization decision that is actually blocking the fix.

Example

An Overdue Action Handled Well

Recommendation: Implement automated user-access reviews for the finance system (High rating, due 31 March).

What happened: By the monthly follow-up on 5 April it was overdue. The owner explained the access-review module depended on an ERP upgrade slipping to June.

Response: Audit recorded a revised due date of 30 June, kept the original 31 March date on the record, and flagged the dependency. Because the action was High and now more than 30 days from its original date, it was added to the audit committee's overdue list with a one-line explanation.

Outcome: The committee asked the CFO to confirm the ERP timeline. The action closed on 24 June with evidence. The slippage was managed transparently rather than hidden, and credibility was preserved on both sides.

Reporting Status to the Audit Committee

The audit committee does not want to read the whole tracker. It wants a clear answer to a small number of questions: Are we closing actions at a healthy rate? Where are the overdue items, especially the high-risk ones? Has management formally accepted any risk instead of fixing it? Your reporting should answer those directly.

A useful committee view summarizes the population rather than listing every line:

Metric This period What it tells the committee
Open recommendations 42 Total remediation workload outstanding
Closed this period 11 Throughput / pace of remediation
Overdue (high/critical) 3 The items that need committee pressure
Average age of open items 54 days Whether actions are ageing dangerously
Risk-accepted 1 Where management chose not to remediate

Pair the summary table with a short narrative on the few items that genuinely need attention. This recommendation-tracking summary is a natural companion to the broader status reporting you provide in a full internal audit report and to the risk view in a board risk report. For the live conversation in the room, see our guide on presenting audit results to the board.

i

Pro Tip

Always name the overdue high-risk items individually, with the owner and the reason. A committee can act on "the automated access review is blocked by the ERP upgrade, owned by the CFO." It cannot act on "three high items are overdue."

Closing a Recommendation With Evidence

Closure is the moment the tracker proves its worth, and it is also where weak processes cut corners. Closing on the strength of an email that says "done" is not closure; it is wishful thinking. A defensible closure has three components:

  1. The action is implemented. The control or change physically exists. A configuration is live, a policy is published, a reconciliation is being performed.
  2. Evidence is captured. Audit obtains and stores proof: a system screenshot, a sample of the new control operating, an approved policy, a change ticket, a sample of records showing the control worked.
  3. The evidence addresses the root cause. Crucially, the evidence must show the original finding is resolved, not just that some activity happened. A new policy that nobody follows does not close a finding about behavior.

The depth of evidence should scale with the rating. A low-rated documentation update might close on confirmation that the document now exists. A critical control weakness should close only after audit has tested the control operating in practice, often through a follow-up audit that re-rates the residual risk.

Example

Evidence That Actually Closes a Finding

Finding: Purchase orders above R50,000 were being approved by a single person.

Recommendation: Configure mandatory dual approval above the threshold.

Weak evidence: An email from the Head of Procurement saying "dual approval is now switched on."

Strong evidence: A screenshot of the system rule, plus a sample of five recent purchase orders above R50,000 each showing two distinct approvers, plus a test of one order attempted with a single approver being rejected by the system.

Result: The strong evidence demonstrates the control exists, operates, and prevents the original failure. The recommendation closes with confidence.

Common Mistakes to Avoid

1. Letting Owners Self-Close

If management can mark its own actions complete, the tracker becomes a record of intentions. Reserve closure for the audit function and require evidence.

2. Overwriting Due Dates Silently

Replacing a missed date with a new one and erasing the original hides chronic slippage. Keep the original agreed date alongside any revised date.

3. Tracking Activities Instead of Outcomes

"Review the access process" is never verifiably done. "Quarterly access reviews are performed and documented" is. Write recommendations as outcomes.

4. Reporting the Whole Tracker to the Committee

Dumping 40 rows onto the audit committee guarantees the three items that matter get lost. Summarize the population; name only the exceptions.

5. No Cadence

Without a scheduled follow-up rhythm, actions drift until the next audit re-finds them. Set frequency by rating and stick to it.

6. Closing Without Real Evidence

An email saying "done" is not evidence. Match the depth of proof to the risk, and verify the root cause is resolved.

Key Takeaways

Summary

  • A recommendations tracker is what turns audit findings into real, durable improvement.
  • Capture finding, recommendation, owner, due date, status, and evidence as core fields, each with a named owner.
  • Use a clear status model and reserve the move to "Closed" for audit, never the owner.
  • Set follow-up cadence by rating, and manage overdue items by re-baselining deliberately and escalating by exception.
  • Report a summarized view to the audit committee and name only the high-risk exceptions.
  • Close recommendations only on evidence that the action exists, works, and resolves the original root cause.

Frequently Asked Questions

Who should own the recommendations tracker?

The internal audit function owns and maintains the tracker because it is the only party that can independently validate and close actions. Each individual recommendation, though, has a management owner: a named person accountable for delivering that specific action. Audit facilitates and reports; management implements.

What's the difference between implemented and closed?

"Implemented" means management says the action is done. "Closed" means audit has independently verified, with evidence, that the action exists, works, and resolves the original finding. Keeping these separate prevents premature closure and is the single most important discipline in the tracker.

How often should we follow up on open recommendations?

Set cadence by rating. Critical actions warrant follow-up every two to four weeks, high actions monthly, medium quarterly, and low semi-annually. Keep the follow-up itself light, a short status confirmation, so that auditor attention is reserved for items that are genuinely stuck.

What do we do when management refuses to implement a recommendation?

Record it as a formal risk acceptance, signed off at the level appropriate to the risk's severity. A critical risk acceptance should reach the audit committee. The tracker should show the accepted risk explicitly so the decision is transparent and revisited periodically, rather than letting an unaddressed finding simply disappear.

Can we use a spreadsheet, or do we need software?

A spreadsheet works when you have a handful of audits and a short action list. As volume grows, dedicated software adds automated reminders, an audit trail of status changes, evidence storage, and instant committee reporting, removing the manual chasing that makes spreadsheet trackers drift. The discipline matters more than the tool, but the tool makes the discipline sustainable.

How does the tracker relate to a follow-up audit?

The tracker is the day-to-day record of remediation. A follow-up audit is a deeper, formal verification, usually reserved for high-risk findings, that re-tests whether the control truly works and re-rates the residual risk. The tracker tells you what to follow up on; the follow-up audit confirms the highest-stakes closures with rigorous evidence.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.