IT Audit Follow-up: Assessing Recommendation Resolution – Part II
Posted by: Robert Davis
If management’s proposed actions to implement or otherwise address reported recommendations have been discussed with, or provided to, an IT auditor; designed remedial actions should be recorded as a management response in a final IT audit report. Whether an IT auditor is engaged in external or internal reporting; after formal audit results communication, follow-up is commonly the next IT audit process phase. Procedurally, after distributing the final audit report — with findings, recommendations and client responses — the IT auditor should request and evaluate relevant information to conclude whether appropriate actions have been taken by management in a timely manner for all documented findings included in the final audit report. However, IT audit follow-up activities can be an extension of an engagement or a separate engagement, and may only include agreed-upon procedures.
“View Part I of the IT Audit Follow-up: Assessing Recommendation Resolution series here“




