An internal audit report is only the beginning. Its real value lies in whether the recommendations inside it actually get implemented. Yet in many organizations, recommendations are agreed in the closing meeting, written into the report, and then quietly forgotten until the next audit re-discovers the same weakness. A disciplined recommendations tracker is what turns audit findings into durable improvement.
What You'll Learn
By the end of this tutorial you will know exactly what fields a recommendations tracker needs, how to set a follow-up cadence, how to manage overdue actions without nagging blindly, how to report status to the audit committee, and how to close a recommendation properly with evidence.
Why a Recommendations Tracker Matters
Every audit produces a set of findings, and each finding is paired with one or more recommendations, the agreed actions that management will take to address the root cause. Without a structured tracker, those actions disperse into individual inboxes, project plans, and good intentions. Three predictable problems follow:
- Repeat findings: The same control weakness reappears in the next cycle because the original fix was never completed or never worked.
- No line of sight: Leadership and the audit committee cannot answer the basic question, "Are we closing what we said we would?"
- Audit credibility erodes: If recommendations rarely close, the function looks like it generates paperwork rather than improvement.
A tracker fixes this by making remediation visible, owned, and time-bound. It is the bridge between the report and the actual reduction of residual risk. It is also the source of truth that feeds a follow-up audit when one is warranted.
The Core Fields Your Tracker Needs
A recommendations tracker is essentially a structured register, conceptually close to a risk register used by internal audit but focused on actions rather than risks. Keep it lean. Every field should earn its place by supporting a decision or a status update. The set below covers what almost any organization needs:
| Field | Purpose | Example |
|---|---|---|
| Recommendation ID | Unique reference for tracking and reporting | AUD-2026-014-R2 |
| Source audit | Links the action back to its report | Procurement Audit Q1 2026 |
| Finding | The weakness the action addresses | No segregation between requisition and approval |
| Rating | Priority inherited from the finding | High |
| Recommendation | The agreed action, stated as an outcome | Enforce dual approval in the procurement system |
| Owner | Single accountable person, not a department | Head of Procurement |
| Agreed due date | The committed completion date | 30 June 2026 |
| Status | Where the action stands now | In progress |
| Evidence | Proof of completion attached at closure | System config screenshot + change ticket |
| Validation | Who confirmed the action worked | Audit, 12 July 2026 |
Two fields deserve special attention. The owner must be a named individual with the authority to deliver the action, never a team or a job title shared by five people. And the recommendation text should describe an outcome ("dual approval is enforced for all purchases above the threshold"), not an activity ("review the approval process"). An outcome-based recommendation is one you can actually verify as done.
Pro Tip
Carry the finding's rating into the tracker as a priority field. It lets you sort the whole population so that high and critical actions get follow-up attention first, instead of treating a minor documentation gap with the same urgency as a control that exposes the organization to fraud.
Want the full framework with worked examples?
Defining a Clear Status Model
Ambiguous status values are where trackers go to die. "In progress" can mean anything from "we started yesterday" to "it has been ninety percent done for six months." Define a small, unambiguous set of statuses and apply them consistently:
- Open / Not started: Agreed but no work has begun.
- In progress: Work is actively underway against the agreed plan.
- Implemented (pending validation): Management says it is done; audit has not yet verified.
- Closed: Audit has validated the action with evidence and confirmed it addresses the finding.
- Overdue: The agreed due date has passed without closure.
- Risk accepted: Management has formally chosen not to implement, with sign-off at the appropriate level.
The distinction between "implemented" and "closed" is the single most important discipline in the whole model. Management implements; audit closes. An action only moves to Closed when audit has seen evidence that the control exists and works, not merely a claim that it has been done.
Important
Do not let owners self-close their own recommendations. If the same person who owns the fix can also mark it complete with no independent check, your tracker measures optimism, not remediation. Reserve the move to "Closed" for the audit function.
Setting a Follow-Up Cadence
A tracker that is reviewed once a year is barely a tracker. The cadence of follow-up should be proportionate to the rating of the action, so that scarce attention goes where the risk is highest:
| Rating | Follow-up frequency | Escalation trigger |
|---|---|---|
| Critical | Every 2 to 4 weeks | Any slippage past due date |
| High | Monthly | 30 days overdue |
| Medium | Quarterly | One full quarter overdue |
| Low | Semi-annually | Two cycles overdue |
The follow-up itself does not have to be heavy. For most actions it is a short status confirmation from the owner: still on track, evidence attached, or a flagged blocker. The point is rhythm. When the cadence is predictable, owners expect to be asked, plan for it, and rarely reach the due date with nothing to show.
Make Follow-Up Light but Relentless
The most effective audit teams automate the reminder so the human conversation is reserved for genuine problems. The system pings owners ahead of the due date, and the auditor only steps in when something is stuck. That keeps the relationship constructive. You are a partner helping the action land, not a debt collector.
Managing Overdue Recommendations
Overdue actions are inevitable; what matters is how you handle them. A mature process distinguishes between a slipped date with a credible new plan and a recommendation that is quietly being abandoned.
1. Confirm the Reason
When an action goes overdue, the first step is to understand why. Common causes include competing priorities, a dependency on a system change, a reorganization that moved the owner, or genuine technical difficulty. The reason determines the response.
2. Re-baseline Deliberately, Not Casually
If a new date is justified, record a revised due date, but keep the original agreed date visible too. A recommendation that has been re-dated three times is telling you something the current date alone would hide. Trackers that simply overwrite the due date erase this signal.
3. Escalate by Exception
Use the escalation triggers from your cadence table. When a high-rated action passes 30 days overdue, it should appear on an escalation list that goes to the executive sponsor and, if it persists, to the audit committee. Escalation is not punishment. It surfaces the resourcing or prioritization decision that is actually blocking the fix.
An Overdue Action Handled Well
Recommendation: Implement automated user-access reviews for the finance system (High rating, due 31 March).
What happened: By the monthly follow-up on 5 April it was overdue. The owner explained the access-review module depended on an ERP upgrade slipping to June.
Response: Audit recorded a revised due date of 30 June, kept the original 31 March date on the record, and flagged the dependency. Because the action was High and now more than 30 days from its original date, it was added to the audit committee's overdue list with a one-line explanation.
Outcome: The committee asked the CFO to confirm the ERP timeline. The action closed on 24 June with evidence. The slippage was managed transparently rather than hidden, and credibility was preserved on both sides.
Reporting Status to the Audit Committee
The audit committee does not want to read the whole tracker. It wants a clear answer to a small number of questions: Are we closing actions at a healthy rate? Where are the overdue items, especially the high-risk ones? Has management formally accepted any risk instead of fixing it? Your reporting should answer those directly.
A useful committee view summarizes the population rather than listing every line:
| Metric | This period | What it tells the committee |
|---|---|---|
| Open recommendations | 42 | Total remediation workload outstanding |
| Closed this period | 11 | Throughput / pace of remediation |
| Overdue (high/critical) | 3 | The items that need committee pressure |
| Average age of open items | 54 days | Whether actions are ageing dangerously |
| Risk-accepted | 1 | Where management chose not to remediate |
Pair the summary table with a short narrative on the few items that genuinely need attention. This recommendation-tracking summary is a natural companion to the broader status reporting you provide in a full internal audit report and to the risk view in a board risk report. For the live conversation in the room, see our guide on presenting audit results to the board.
Pro Tip
Always name the overdue high-risk items individually, with the owner and the reason. A committee can act on "the automated access review is blocked by the ERP upgrade, owned by the CFO." It cannot act on "three high items are overdue."
Closing a Recommendation With Evidence
Closure is the moment the tracker proves its worth, and it is also where weak processes cut corners. Closing on the strength of an email that says "done" is not closure; it is wishful thinking. A defensible closure has three components:
- The action is implemented. The control or change physically exists. A configuration is live, a policy is published, a reconciliation is being performed.
- Evidence is captured. Audit obtains and stores proof: a system screenshot, a sample of the new control operating, an approved policy, a change ticket, a sample of records showing the control worked.
- The evidence addresses the root cause. Crucially, the evidence must show the original finding is resolved, not just that some activity happened. A new policy that nobody follows does not close a finding about behavior.
The depth of evidence should scale with the rating. A low-rated documentation update might close on confirmation that the document now exists. A critical control weakness should close only after audit has tested the control operating in practice, often through a follow-up audit that re-rates the residual risk.
Evidence That Actually Closes a Finding
Finding: Purchase orders above R50,000 were being approved by a single person.
Recommendation: Configure mandatory dual approval above the threshold.
Weak evidence: An email from the Head of Procurement saying "dual approval is now switched on."
Strong evidence: A screenshot of the system rule, plus a sample of five recent purchase orders above R50,000 each showing two distinct approvers, plus a test of one order attempted with a single approver being rejected by the system.
Result: The strong evidence demonstrates the control exists, operates, and prevents the original failure. The recommendation closes with confidence.
Common Mistakes to Avoid
1. Letting Owners Self-Close
If management can mark its own actions complete, the tracker becomes a record of intentions. Reserve closure for the audit function and require evidence.
2. Overwriting Due Dates Silently
Replacing a missed date with a new one and erasing the original hides chronic slippage. Keep the original agreed date alongside any revised date.
3. Tracking Activities Instead of Outcomes
"Review the access process" is never verifiably done. "Quarterly access reviews are performed and documented" is. Write recommendations as outcomes.
4. Reporting the Whole Tracker to the Committee
Dumping 40 rows onto the audit committee guarantees the three items that matter get lost. Summarize the population; name only the exceptions.
5. No Cadence
Without a scheduled follow-up rhythm, actions drift until the next audit re-finds them. Set frequency by rating and stick to it.
6. Closing Without Real Evidence
An email saying "done" is not evidence. Match the depth of proof to the risk, and verify the root cause is resolved.
Summary
- A recommendations tracker is what turns audit findings into real, durable improvement.
- Capture finding, recommendation, owner, due date, status, and evidence as core fields, each with a named owner.
- Use a clear status model and reserve the move to "Closed" for audit, never the owner.
- Set follow-up cadence by rating, and manage overdue items by re-baselining deliberately and escalating by exception.
- Report a summarized view to the audit committee and name only the high-risk exceptions.
- Close recommendations only on evidence that the action exists, works, and resolves the original root cause.
Frequently Asked Questions
Who should own the recommendations tracker?
The internal audit function owns and maintains the tracker because it is the only party that can independently validate and close actions. Each individual recommendation, though, has a management owner: a named person accountable for delivering that specific action. Audit facilitates and reports; management implements.
What's the difference between implemented and closed?
"Implemented" means management says the action is done. "Closed" means audit has independently verified, with evidence, that the action exists, works, and resolves the original finding. Keeping these separate prevents premature closure and is the single most important discipline in the tracker.
How often should we follow up on open recommendations?
Set cadence by rating. Critical actions warrant follow-up every two to four weeks, high actions monthly, medium quarterly, and low semi-annually. Keep the follow-up itself light, a short status confirmation, so that auditor attention is reserved for items that are genuinely stuck.
What do we do when management refuses to implement a recommendation?
Record it as a formal risk acceptance, signed off at the level appropriate to the risk's severity. A critical risk acceptance should reach the audit committee. The tracker should show the accepted risk explicitly so the decision is transparent and revisited periodically, rather than letting an unaddressed finding simply disappear.
Can we use a spreadsheet, or do we need software?
A spreadsheet works when you have a handful of audits and a short action list. As volume grows, dedicated software adds automated reminders, an audit trail of status changes, evidence storage, and instant committee reporting, removing the manual chasing that makes spreadsheet trackers drift. The discipline matters more than the tool, but the tool makes the discipline sustainable.
How does the tracker relate to a follow-up audit?
The tracker is the day-to-day record of remediation. A follow-up audit is a deeper, formal verification, usually reserved for high-risk findings, that re-tests whether the control truly works and re-rates the residual risk. The tracker tells you what to follow up on; the follow-up audit confirms the highest-stakes closures with rigorous evidence.
Save this guide for later
Download the PDF version to read offline or share with your team.

