CORAA

SIA 390 — Monitoring and Reporting of Prior Audit Issues

ICAI Internal Audit Standards Board · October 2022 compendium · 300 series
Reviewed 1 October 2026

SIA 390 covers what happens to observations after the report: monitoring and closing open issues from earlier audits, independently validating the corrective action the auditee says it has taken, escalating delays, and reporting status to those charged with governance on time.

This page covers SIA 390 as it stands in ICAI’s October 2022 compendium. ICAI’s February 2026 compendium, applicable from 1 April 2026, renumbers the standards, so check the current number and text in that compendium before citing it in a report.

What the internal auditor has to do

  • Monitor the closure of open issues continuously, through a formal process agreed in advance.
  • When the auditee says an action is implemented, validate that independently with additional procedures and document it.
  • Match the closure evidence to the risk of the issue.
  • Escalate delays under the agreed protocol.
  • Send a periodic action taken report to management and the Audit Committee.

Key requirements of SIA 390

Paragraph numbers refer to SIA 390 as it appears in ICAI’s Compendium of Standards on Internal Audit (as on 1 October 2022). The points below are close paraphrases, not quotations.

  • The Chief Internal Auditor continuously monitors closure through a formal, pre-agreed process. Implementing the actions remains management's responsibility.(para 3.1, 4.1)
  • After the auditee claims implementation, the internal auditor independently validates closure with additional procedures, and documents this.(para 3.2)
  • Closure evidence is tiered by risk: follow-up audit procedures for high-risk and fraud-risk issues, documentary proof for medium-risk issues, and written management confirmation for low-risk issues.(para 4.2)
  • Delays are escalated under the pre-agreed protocol. The timeline may be reset on new facts, or the action deferred with an agreed carry-forward.(para 3.3, 4.3)
  • If an action is still not implemented after escalation, the internal auditor obtains management's written acceptance of the risk or issues a note of the unaddressed risks.(para 4.2 Note)
  • A periodic Action Taken Report goes to management and the Audit Committee, with closure confirmations, the ageing of pending issues and the reasons for delay.(para 3.4, 4.3)

How SIA 390 shows up in the internal audit file

  • A tracker of every open issue with owner, due date and status.
  • For each closed issue, the closure evidence appropriate to its risk and the internal auditor's own validation.
  • Escalation records for overdue actions.
  • Written risk acceptance from management, or the note of unaddressed risks, where an action was not implemented.
  • The periodic action taken reports sent to management and the Audit Committee.

Common mistakes in practice

  • Marking an issue closed because management said so, with no validation by the internal auditor.
  • Asking for the same level of proof for every issue, whatever its risk.
  • Letting overdue actions roll forward quietly with no escalation and no revised date agreed.
  • Dropping an unimplemented action with no written risk acceptance.
  • An action taken report that lists open items without ageing or reasons for delay.

The file checklist and the mistakes above are practice points drawn from the requirements of the standard. They are not text from the standard.

Related standards

SIA 370 · Reporting ResultsSIA 250 · Communication with those Charged with GovernanceSIA 11 · Consideration of Fraud in an Internal Audit

How this relates to global frameworks

The IIA's Global Internal Audit Standards (effective 9 January 2025) are a separate set from a different body, and there is no paragraph-for-paragraph match. The closest IIA principle is Communicate Engagement Results and Monitor Action Plans.

Status and source

This standard is described here as it stands in the October 2022 compendium, which is the earlier set. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). That compendium renumbers the standards, so check the current number and text there before citing this standard in a report. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. The effective-date clause in each 2019 standard said it applied to internal audits beginning on or after a date to be notified by the Council of ICAI.

These pages summarise each standard as it stands in ICAI's Compendium of Standards on Internal Audit (as on 1 October 2022), working from an extract of that document. They are summaries and close paraphrases, not the text of the standards. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). For that current set we have only the titles, taken from the Board's 2025-26 annual report; its text is available from ICAI through a registration form on the compendium page and is not summarised here. ICAI's compendium page does not say whether the standards are mandatory or recommendatory, so we do not describe any standard as mandatory. Before you cite a number, a paragraph or a status in a report, check the February 2026 compendium. internalaudit.icai.org

Free working files for SIA 390

Take the working versions with you

Editable formats and tools from CORAA’s internal audit library that put SIA 390 into practice. Free to use.

Internal Audit Follow-up / Closure Tracker →Action Taken Report →Action taken report tracker →Closure evidence and retesting checklist →Risk acceptance and escalation register →

SIA 390 — frequently asked

What is SIA 390?

SIA 390, Monitoring and Reporting of Prior Audit Issues, is a Standard on Internal Audit issued by the Internal Audit Standards Board of ICAI. SIA 390 covers what happens to observations after the report: monitoring and closing open issues from earlier audits, independently validating the corrective action the auditee says it has taken, escalating delays, and reporting status to those charged with governance on time.

What closure evidence does SIA 390 expect before an audit issue is closed?

It depends on the risk of the issue. SIA 390 para 4.2 tiers the evidence: follow-up audit procedures for high-risk and fraud-risk issues, documentary proof for medium-risk issues, and written management confirmation for low-risk issues. Para 3.2 requires the internal auditor to validate closure independently and document it.

Is SIA 390 mandatory?

ICAI's compendium page does not say whether the Standards on Internal Audit are mandatory or recommendatory, so we do not describe SIA 390 as mandatory. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026 (source: the Board's compendium page, checked on 1 October 2026). SIA 390 as described on this page is from the earlier October 2022 compendium. The February 2026 compendium renumbers the standards, so check the current number and text there before citing it in a report.

What should the internal audit file show for SIA 390?

A tracker of every open issue with owner, due date and status. For each closed issue, the closure evidence appropriate to its risk and the internal auditor's own validation. Escalation records for overdue actions. Written risk acceptance from management, or the note of unaddressed risks, where an action was not implemented. The periodic action taken reports sent to management and the Audit Committee.

← Previous
SIA 370 — Reporting Results
Next →
SIA 520 — Internal Auditing in an Information Technology Environment