Internal audit should not close management actions because an owner says the action is done. A defensible closure needs implementation evidence, a reviewer conclusion and, for meaningful controls, a retest showing the fix operated after it went live.
Download the Excel/PDF pack for evidence types, retest planning, closure status, red flags, accepted risk, authority notes and future product workflow fields.
Approved policy, version history, effective date, communication record and owner acknowledgement.
Change ticket, maker-checker approval, before/after configuration, access log and UAT or production evidence.
Workflow screenshot, approval matrix, sample approvals after go-live and exception log.
Reconciliation format, preparer/reviewer sign-off, exception ageing and evidence of follow-up.
User listing before/after, HR exit tie-out, privileged access approval and last-login review.
Master-data change log, approval evidence, duplicate report, bank/GST/PAN validation and monitoring rule.
Training material, attendance, affected-user coverage, post-training checks and first-period exception trend.
Review calendar, reviewed report, exception notes, owner sign-off and proof of timely escalation.
The implemented fix should address the reported root cause, not only the symptom or one transaction.
Inspect documents, system logs, workflow settings, reconciliations or approvals proving the action exists.
Choose the period after implementation, population source, completeness check and sample basis.
Test whether the corrected control operated as intended after the fix went live.
Close, partially close, keep open, re-open or escalate based on evidence and retest result.
Record conclusion, reviewer, evidence reference, next action and repeat-finding status.
Implementation evidence is sufficient and retesting shows the control operated after the fix.
Some action was implemented, but coverage, timing, owner acceptance or retest result is incomplete.
Management has not implemented the action or evidence is not sufficient to support closure.
Previously closed action failed retesting, repeat exceptions occurred or closure evidence was misleading.
Management accepts residual risk with appropriate authority; internal audit documents the basis and reports where required.
A process owner saying completed is not audit evidence unless it is supported by source proof and reviewer conclusion.
The fix may exist on paper, but internal audit has not checked whether it operated after implementation.
Testing old transactions does not prove the new control works.
The root cause remains if only one invoice, user ID, journal or vendor record was corrected.
The committee cannot see that the same control is failing again under a new observation number.
The ATR shows closed, but the file cannot defend who reviewed what and why closure was accepted.
| Artifact | Module | Likely fields |
|---|---|---|
| Closure evidence checklist | ATR workflow | Evidence type, source reference, owner, reviewer, sufficiency status, retained file link. |
| Retest planner | Fieldwork workflow | Implementation date, retest period, population source, sample basis, exceptions, conclusion. |
| Partial closure route | Remediation workflow | Open dependency, residual risk, revised date, committee flag, management owner. |
| Repeat finding detector | Analytics and reporting | Observation theme, prior issue ID, repeated owner, repeated control, escalation level. |
| Accepted-risk register | Governance workflow | Risk owner, acceptance authority, compensating controls, committee date, next review. |
Closure evidence is the retained proof that management implemented an agreed action. It can include approved policies, system logs, configuration evidence, reconciliations, approval records, access listings, training records, monitoring reports and retest results.
A management email may support status tracking, but it is usually not sufficient closure evidence by itself. Internal audit should inspect source evidence and conclude whether the action was implemented and whether retesting is needed.
Retesting is the follow-up procedure where internal audit tests transactions, controls or system settings after implementation to confirm whether the corrective action is operating effectively.
Use partial closure when management has completed part of the action but evidence, coverage, timing, dependency resolution or retest results are not strong enough to close the observation fully.