2. The Mistakes Practitioners Repeat — And What You Should Hold Them Accountable For
The Commitments Worth Testing: How to Read an Audit Report Without Being Managed by It
Every assurance report arrives looking competent. It counts things — audits completed, controls closed, findings rated, coverage percentages. The numbers are real, and the effort behind them is real. What the numbers do not tell you is whether risk actually moved. An organization can complete 42 audits in a year and still be unable to state, in a single paragraph, what its residual risk looks like by domain, or which three things could most positively or negatively affect the strategy it just approved.
That gap between the volume of assurance activity and the quality of the assurance itself — is where this series lives.
The table that follows is the test itself. Read it as a set of commitments being offered to you — and treat every row as something you are entitled to verify, not something you are being asked to trust. If you are a buyer, a stakeholder, or a Board member, these are the commitments worth testing. Each row is a mistake we see routinely, followed by the accountability question that should be asked out loud.
|
Repeated mistake |
Examples of how it shows up |
Hold them accountable for |
|
Reporting activity instead of risk |
'We completed 42 audits', 'we closed 300 controls' |
A statement of residual risk by domain, with the three things that could most negatively or positively (opportunities and threats) impact the strategy and the evidence behind each |
|
Duplicated testing and efforts across lines and business functions |
The same control tested by the process owner, risk, compliance, and audit |
A single coverage map showing who tested what, when last, and what each provider relied on |
|
Negotiated findings |
Severity quietly downgraded in the close-out meeting |
Rating assigned by agreed criteria before fieldwork begins, with any change logged and reasoned in the issue register |
|
Overdue findings treated as administration |
Aging items sit open for 12+ months at 'in progress' |
Root-cause analysis on anything overdue beyond one cycle, escalated to the Audit Committee with a named owner |
|
Maturity scores improving while losses rise |
Heat maps get greener, incidents get worse |
Trend data pairing control maturity with actual loss, near-miss, and third-party exposure data |
|
AI governance as a policy artifact |
A principles document, an approval forum, no inventory |
A complete, current inventory of models and use cases, with pre-deployment testing and post-deployment monitoring evidence |
|
Cyber assurance as questionnaire management |
Vendor attestations accepted as control evidence |
Independent validation of the controls the business actually depends on, including tested incident and recovery capability |
|
IT controls tested apart from the business |
Access reviews pass, fraud and outage risk unchanged |
Control testing tied to the business processes and the critical vendors those processes depend on |
|
Multi-year audit plans that never change |
Plan locked in Q4 for the whole following year |
A plan re-prioritized at least quarterly against the current risk profile, with the changes documented |
|
Independence claimed but not demonstrated |
Internal audit reports to the CFO or to a risk owner |
A charter, an Audit Committee reporting line, and a documented independence safeguard in every engagement. Ideal reporting to the CEO (administratively) and functionally to the Audit Committee Chair, with appointment, remuneration, and objectives determined by the Audit Committee, and annual confirmation of organizational independence made to the board |