Skip to content

The Mistakes Practitioners Repeat

Information Synergy-iA
Information Synergy-iA
The Mistakes Practitioners Repeat
5:15

2. The Mistakes Practitioners Repeat — And What You Should Hold Them Accountable For

The Commitments Worth Testing: How to Read an Audit Report Without Being Managed by It

Every assurance report arrives looking competent. It counts things — audits completed, controls closed, findings rated, coverage percentages. The numbers are real, and the effort behind them is real. What the numbers do not tell you is whether risk actually moved. An organization can complete 42 audits in a year and still be unable to state, in a single paragraph, what its residual risk looks like by domain, or which three things could most positively or negatively affect the strategy it just approved.

That gap between the volume of assurance activity and the quality of the assurance itself — is where this series lives.

The table that follows is the test itself. Read it as a set of commitments being offered to you — and treat every row as something you are entitled to verify, not something you are being asked to trust. If you are a buyer, a stakeholder, or a Board member, these are the commitments worth testing. Each row is a mistake we see routinely, followed by the accountability question that should be asked out loud.

Repeated mistake

Examples of how it shows up

Hold them accountable for

Reporting activity instead of risk

'We completed 42 audits', 'we closed 300 controls'

A statement of residual risk by domain, with the three things that could most negatively or positively (opportunities and threats) impact the strategy and the evidence behind each

Duplicated testing and efforts across lines and business functions

The same control tested by the process owner, risk, compliance, and audit

A single coverage map showing who tested what, when last, and what each provider relied on

Negotiated findings

Severity quietly downgraded in the close-out meeting

Rating assigned by agreed criteria before fieldwork begins, with any change logged and reasoned in the issue register

Overdue findings treated as administration

Aging items sit open for 12+ months at 'in progress'

Root-cause analysis on anything overdue beyond one cycle, escalated to the Audit Committee with a named owner

Maturity scores improving while losses rise

Heat maps get greener, incidents get worse

Trend data pairing control maturity with actual loss, near-miss, and third-party exposure data

AI governance as a policy artifact

A principles document, an approval forum, no inventory

A complete, current inventory of models and use cases, with pre-deployment testing and post-deployment monitoring evidence

Cyber assurance as questionnaire management

Vendor attestations accepted as control evidence

Independent validation of the controls the business actually depends on, including tested incident and recovery capability

IT controls tested apart from the business

Access reviews pass, fraud and outage risk unchanged

Control testing tied to the business processes and the critical vendors those processes depend on

Multi-year audit plans that never change

Plan locked in Q4 for the whole following year

A plan re-prioritized at least quarterly against the current risk profile, with the changes documented

Independence claimed but not demonstrated

Internal audit reports to the CFO or to a risk owner

A charter, an Audit Committee reporting line, and a documented independence safeguard in every engagement. Ideal reporting to the CEO (administratively) and functionally to the Audit Committee Chair, with appointment, remuneration, and objectives determined by the Audit Committee, and annual confirmation of organizational independence made to the board

 

Three Questions That Separate Assurance From Administration

The table above is long because there are many patterns, but the underlying test is short. A functioning audit activity can produce evidence of judgment under pressure. A functioning audit activity on paper can only produce activity counts. The difference shows up the moment you ask a question whose answer could embarrass the person answering it.

Three questions do most of the work. Ask them of your internal audit leader, and ask them again, with appropriate rephrasing — of your external audit partner, whose standards require the audit of internal control over financial reporting to be integrated with the audit of the financial statements rather than bolted on beside it (PCAOB AS 2201). Then ask them about the chair of your Audit Committee. The variance between the three answers is the finding itself.

  • In the last twelve months, name one Internal Audit finding whose severity rating changed after fieldwork closed. Who asked for the change, what justified it, and where is it logged?
  • Pick three oldest open items from Internal Audit observations and tell me the root cause, the named owner, and the escalation date.
  • Who can change the Internal Audit scope, budget, or the CAE performance review—and what stops them from doing it without documented approval?
To learn more about Synergy-IA or our Fractional CAE Services, email us at information@synergy-ia.com  

Share this post