Every internal auditor knows the feeling. You open last year's audit report, scan the findings, and recognize three of them immediately, because you wrote them the year before that too. Aud...
Every internal auditor knows the feeling. You open last year’s audit report, scan the findings, and recognize three of them immediately, because you wrote them the year before that too. Audit management is a tiring task.
Access reviews not performed on schedule. Vendor due diligence incomplete. Change management approvals missing for a handful of releases. Different fiscal year, same paragraph.
Repeat findings are the most honest diagnostic tool an audit function has. They don’t tell you that a control failed, you already knew that. They tell you that your organization’s mechanism for fixing failed controls isn’t working. And that is a fundamentally different, and far more serious, problem.
This piece is about why repeat findings happen, what they actually cost, and what separates organizations that close findings permanently from those that keep rewriting the same observation every cycle.
When a finding appears for the second or third time, the instinct in most organizations is to treat it as a control problem. The access review didn’t happen again, so we remind the control owner, reset the calendar invite, and mark it remediated.
Next year, it appears again.
The reason is that the finding was never really about the access review. It was about whatever caused the access review to slip in the first place, an owner who inherited the control without context, a process that depends on one person remembering, a remediation that was closed on the strength of a single completed instance rather than evidence the process had changed.
Audit functions that consistently close findings treat the repeat as a signal to investigate the remediation process, not the control. The question shifts from “why didn’t this control operate?” to “why did our fix fail to hold?” Those are different investigations with different answers.
This is the most common failure by a wide margin. An audit identifies that quarterly access reviews weren’t completed for two quarters. The remediation: complete the missing reviews. The finding closes.
But nothing about the system changed. There’s still no automated trigger, no escalation when a review goes overdue, no backup owner. The next time the control owner is on leave during quarter-end, the review slips again, and the finding reopens.
Closing an instance is not remediation. It’s cleanup. Genuine remediation changes the conditions that allowed the failure, which usually means altering a process, adding a system control, reassigning ownership, or building in monitoring that surfaces the problem before an auditor does.
Remediation plans routinely assign action items to a title, “Head of IT Operations”, rather than a named individual who has explicitly accepted the work, understood the deadline, and has the bandwidth to deliver it.
When ownership is nominal, remediation becomes everyone’s responsibility in theory and no one’s in practice. The action item sits in a tracker, gets a status update of “in progress” every month, and quietly rolls forward until the next audit cycle forces the conversation again.
The organizations that close findings well do something deceptively simple: they confirm ownership verbally and in writing with a named person, agree on a realistic date rather than an optimistic one, and treat a missed remediation deadline as an escalation event rather than an administrative delay.
There’s a strange asymmetry in many audit functions. Identifying a finding requires rigorous testing, sampling, and documentation. Closing that finding sometimes requires only an email from the control owner saying it’s been addressed.
That asymmetry is where repeat findings are born. If closure validation is lighter than original testing, the audit function is systematically accepting weaker evidence for the more consequential claim.
Mature audit functions apply the same testing rigor to closure that they applied to identification, and critically, they validate closure after enough time has passed for the fix to be tested in real operating conditions, not the week after the remediation was implemented. A control that operated correctly once, under supervision, has proven very little.
In many organizations, audit engages with a process area intensively for four weeks, issues a report, and then doesn’t look at that area again for twelve months. Remediation happens, or doesn’t, in a blind spot.
By the time the next audit begins, the organization has changed. People have moved, systems have been replaced, processes have quietly been redesigned. The remediation may have been implemented and then unwound by a subsequent change nobody flagged to audit.
Continuous monitoring doesn’t require a continuous audit. It requires a lightweight mechanism, automated control indicators, periodic check-ins, system-generated alerts on key controls, that gives audit visibility into whether remediations are holding, without waiting for the next full engagement.
The practical failure underneath the other four. Findings, remediation plans, owners, due dates, and evidence often live in a spreadsheet that’s updated in the week before an audit committee meeting and ignored otherwise.
A spreadsheet can’t trigger a reminder when a deadline approaches. It can’t escalate automatically when a date slips twice, can’t show a pattern, that the same control area has produced findings in four consecutive cycles, or that one business unit accounts for 60% of overdue remediations. It can’t link a finding to the risk it maps to, the regulation it touches, or the previous finding it’s a repeat of.
Those connections are exactly where the insight lives. Without them, audit management becomes a documentation exercise rather than a risk management function.
The cost isn’t primarily the remediation effort, though that’s real, the same work performed three times is a direct waste of scarce audit and control-owner capacity.
The larger costs are less visible:
Regulatory credibility. Regulators and external auditors pay close attention to repeat findings, because a recurring issue suggests either that management doesn’t take audit seriously or that the audit function lacks the authority to drive change. Either interpretation invites deeper scrutiny. A first-time finding is a control gap; the same finding three years running is a governance concern.
Audit committee confidence. When the same items appear on the overdue remediation list quarter after quarter, the committee’s attention shifts from the risks in the business to the performance of the audit function itself. That’s a difficult position to argue out of.
Internal authority. Perhaps the most corrosive cost. When the organization learns that findings can be acknowledged, partially addressed, and allowed to recur without meaningful consequence, audit’s recommendations start being treated as suggestions. Once that norm sets in, it’s extremely hard to reverse.
Before a remediation plan is approved, require a documented root cause. Not “the review wasn’t performed,” which restates the finding, but the actual reason, no automated trigger, ownership transferred without handover, competing priority during quarter close.
If the remediation plan doesn’t visibly address the stated root cause, it isn’t a remediation plan. This single discipline eliminates a large share of repeat findings, because it makes instance-fixing obvious at the point of approval rather than twelve months later.
A finding should be linked to the risk it relates to, the control that failed, the regulatory requirement it touches, the business unit that owns it, and any prior related findings. These relationships turn a list into an analytical tool.
With connected data, the audit function can answer questions that matter to the committee: Which control areas generate findings repeatedly? Which business units struggle most with timely remediation? Is our finding volume in a given domain rising or falling year over year? None of these are answerable from a flat spreadsheet.
Build a standard interval, typically one to two full operating cycles after implementation, before validating closure. Test the control as it actually operates, using the same standards applied during the original engagement. If a quarterly control was remediated, closure validation should cover at least one unsupervised quarter.
Automated escalation matters more than escalation policy. When a remediation date slips, the owner and their manager should know immediately, without an auditor having to chase, and it slips a second time, it should surface at the next level. When it reaches the audit committee, it should arrive with history attached, original date, revised dates, reasons given.
Visibility does most of the work here. Most remediation delays aren’t defiance; they’re deprioritization. Making the delay visible to people who can reprioritize usually resolves it.
Identify the handful of indicators that would tell you a remediated control has drifted, an overdue access review, a change deployed without approval, a vendor assessment past its review date, and monitor them continuously between engagements. The goal isn’t to audit constantly. It’s to stop discovering twelve-month-old failures at the twelve-month mark.
Audit management functions are frequently measured on coverage: engagements completed, areas reviewed, findings issued. Those metrics describe activity, not effect.
The metric that describes effect is closure, specifically, what proportion of findings close on the first attempt and stay closed. A function that issues fifty findings and permanently resolves forty-five has done more for the organization’s risk posture than one that issues a hundred and watches a third of them return.
Repeat findings are worth paying attention to precisely because they’re uncomfortable. They tell you exactly where your process for converting an observation into a durable change is breaking down. The organizations that treat that discomfort as information, rather than an administrative nuisance to be managed at report time, are the ones whose audit reports get shorter every year for the right reasons.