CORAA
Resources · Internal Audit Follow-up

Internal audit closure evidence and retesting evidence.

Internal audit should not close management actions because an owner says the action is done. A defensible closure needs implementation evidence, a reviewer conclusion and, for meaningful controls, a retest showing the fix operated after it went live.

Open ATR trackerOpen remediation plan
Downloads

Closure evidence workbook checklist

Download the Excel/PDF pack for evidence types, retest planning, closure status, red flags, accepted risk, authority notes and future product workflow fields.

Evidence types

What counts as closure evidence retain

Policy or SOP change

Approved policy, version history, effective date, communication record and owner acknowledgement.

System configuration change

Change ticket, maker-checker approval, before/after configuration, access log and UAT or production evidence.

Maker-checker control implemented

Workflow screenshot, approval matrix, sample approvals after go-live and exception log.

Reconciliation introduced

Reconciliation format, preparer/reviewer sign-off, exception ageing and evidence of follow-up.

Access removed or restricted

User listing before/after, HR exit tie-out, privileged access approval and last-login review.

Vendor or customer master cleaned

Master-data change log, approval evidence, duplicate report, bank/GST/PAN validation and monitoring rule.

Training completed

Training material, attendance, affected-user coverage, post-training checks and first-period exception trend.

Management review performed

Review calendar, reviewed report, exception notes, owner sign-off and proof of timely escalation.

Retesting

Follow-up procedure test

Confirm the action matches the observation

The implemented fix should address the reported root cause, not only the symptom or one transaction.

Verify implementation evidence

Inspect documents, system logs, workflow settings, reconciliations or approvals proving the action exists.

Define the retest population

Choose the period after implementation, population source, completeness check and sample basis.

Perform retesting

Test whether the corrected control operated as intended after the fix went live.

Conclude on effectiveness

Close, partially close, keep open, re-open or escalate based on evidence and retest result.

Update ATR and committee dashboard

Record conclusion, reviewer, evidence reference, next action and repeat-finding status.

Status logic

Use clear closure status close

Closed

Implementation evidence is sufficient and retesting shows the control operated after the fix.

Partially closed

Some action was implemented, but coverage, timing, owner acceptance or retest result is incomplete.

Open

Management has not implemented the action or evidence is not sufficient to support closure.

Re-opened

Previously closed action failed retesting, repeat exceptions occurred or closure evidence was misleading.

Risk accepted

Management accepts residual risk with appropriate authority; internal audit documents the basis and reports where required.

Red flags

Weak closure patterns reject

Closed on email confirmation

A process owner saying completed is not audit evidence unless it is supported by source proof and reviewer conclusion.

No retest period

The fix may exist on paper, but internal audit has not checked whether it operated after implementation.

Sample chosen before go-live

Testing old transactions does not prove the new control works.

Action fixes one case only

The root cause remains if only one invoice, user ID, journal or vendor record was corrected.

No repeat-finding flag

The committee cannot see that the same control is failing again under a new observation number.

Closure evidence not retained

The ATR shows closed, but the file cannot defend who reviewed what and why closure was accepted.

Authority anchors

Tie closure to standards and reporting defensible

ICAI Standards on Internal Audit

Use SIA 320 evidence, SIA 330 documentation, SIA 350 review, SIA 370 reporting results and SIA 390 monitoring/reporting prior audit issues when closing ATR items.

IIA Global Internal Audit Standards

Useful benchmark for monitoring action plans, communicating accepted risk, engagement documentation and quality review before closure.

Audit Committee reporting

Overdue actions, weak closure evidence, repeated slippage and risk acceptance should feed committee reporting where the issue is significant.

Product reuse

Reusable product fields workflow

ArtifactModuleLikely fields
Closure evidence checklistATR workflowEvidence type, source reference, owner, reviewer, sufficiency status, retained file link.
Retest plannerFieldwork workflowImplementation date, retest period, population source, sample basis, exceptions, conclusion.
Partial closure routeRemediation workflowOpen dependency, residual risk, revised date, committee flag, management owner.
Repeat finding detectorAnalytics and reportingObservation theme, prior issue ID, repeated owner, repeated control, escalation level.
Accepted-risk registerGovernance workflowRisk owner, acceptance authority, compensating controls, committee date, next review.
Related resources

Use this with ATR and reporting next

Internal Audit ATR Tracker

Track observations, management responses, owners, due dates and follow-up status.

Root Cause & Remediation Plan

Design action plans that can actually be retested and closed.

Audit Committee Reporting Pack

Escalate overdue actions, weak evidence, repeated slippage and accepted risk.

Internal Audit Dashboard KPIs

Roll closure status, overdue actions and repeat findings into dashboard metrics.

Observation Report Generator

Start with observations that include owner, action, due date and evidence standard.

Quality Review Checklist

Review closure evidence and retest conclusions before marking items closed.

FAQ

Common questions answers

What is closure evidence in internal audit?

Closure evidence is the retained proof that management implemented an agreed action. It can include approved policies, system logs, configuration evidence, reconciliations, approval records, access listings, training records, monitoring reports and retest results.

Can internal audit close an ATR item based on management email?

A management email may support status tracking, but it is usually not sufficient closure evidence by itself. Internal audit should inspect source evidence and conclude whether the action was implemented and whether retesting is needed.

What is retesting in internal audit follow-up?

Retesting is the follow-up procedure where internal audit tests transactions, controls or system settings after implementation to confirm whether the corrective action is operating effectively.

When should an internal audit finding be partially closed?

Use partial closure when management has completed part of the action but evidence, coverage, timing, dependency resolution or retest results are not strong enough to close the observation fully.