Following Up Remediation and Reporting to the Audit Committee

An audit finding means nothing if management does not fix it. Follow-up is where audit creates value: ensuring that agreed recommendations are implemented, confirming that fixes actually work, and reporting to the audit committee on remediation progress. This final lesson covers follow-up procedures, reporting, and what to do when management does not implement recommendations.
Tracking Remediation Actions
After your audit report is issued, management commits to recommendations. These commitments should be tracked in an audit tracking system or log. Each finding should have: the original issue, the recommendation, management’s agreed action, who owns the action, the target date for completion, and current status. Update the log quarterly or monthly. Some issues get fixed quickly; others are slower. The log allows you to spot which recommendations are progressing and which are stalling.
Testing That Fixes Actually Work
When management reports an action complete, do not take their word for it. Go back and test. If the recommendation was to implement fairness monitoring, audit the monitoring to confirm it actually works. If the recommendation was to establish an approval process, sample recent approvals to confirm the process is being followed. A common audit surprise is that management thinks an action is complete when it is not, or when it has been implemented in name only.
Escalation When Remediation Stalls
Some findings are not remediated. Management says it is too expensive, or too disruptive, or simply does not prioritise it. If a critical finding is not being remediated, that is important information for the audit committee. Document what was recommended, when the target date was, and what management says is the reason for the delay. After six months of delay on a critical finding, escalate to the audit committee. They have the authority to push management on priorities.
Reporting to the Audit Committee
The audit committee (or board audit subcommittee) is internal audit’s primary stakeholder. Quarterly reporting to the audit committee should include: summary of audit work completed, findings issued, remediation progress on prior findings, and any critical issues that need escalation. Good audit committee reporting is clear, concise, and focused on what the committee needs to make decisions.
The Annual AI Audit Summary
At year-end, pull together a summary of your AI audit work for the year. How many audits did you complete? How many findings did you issue? What categories of issues are most common (governance, controls, monitoring, etc.)? Are findings improving, static, or worsening? Are certain systems or teams consistently problematic? Trends in findings help the board understand whether AI governance is strengthening or slipping.
Closing Audits
Eventually findings are resolved and audits close. Before closing an AI audit, confirm that all recommendations have been implemented and tested, or that management has consciously decided not to implement specific recommendations (with documented justification). Do not close an audit with open findings. Open findings should be tracked separately and followed up regularly.
Building Your AI Audit Capability
This final reflection brings you to the end of the course, but the start of your real work. Building a strong AI audit capability takes time. Start with high-risk systems, build your skills and evidence base, and gradually expand into lower-risk areas. Connect with other auditors, especially the IIA AI auditing community, to learn from peers. Stay up to date on regulatory changes: the EU AI Act, ISO 42001, NIST framework, and sector-specific rules are evolving. Your audit procedures should evolve with them.
