Why Good Audit, Risk and Controls Work Still Fails to Land
Good morning {{name}},
Recent subscriber replies have described different versions of the same frustration.
The analysis was sound. The issue mattered. The evidence was credible. Management appeared to agree. Yet, several months later, very little had changed.
Sometimes the report had been issued after the relevant business decision. Sometimes the person accepting the action did not control the budget, system or policy required to implement it. In other cases, the response looked sensible on paper but could not survive the pressure of normal operations.
These are not unusual exceptions. They point to a wider problem for audit, risk and controls teams.
We spend a great deal of time testing whether work is accurate, supported and professionally delivered. We spend less time testing whether it has a credible route into the decisions, operating rhythms and management interventions that could make it useful.
That route is what I call the landing gap.
I’m Tim Buckley. Through Beyond the Lines™, I explore how audit, risk and controls professionals can make sound work more useful to the people responsible for acting on it. This edition looks beyond the technical quality of the work and examines the conditions that determine whether it creates movement.
A technically sound report can still be operationally unfinished
Technical quality is essential. Poor evidence, weak analysis and unsupported conclusions will quickly damage credibility.
But technical quality is not the finish line.
A report can be accurate without being relevant to the question leadership is considering. It can be issued according to the audit timetable but after the business has committed its budget. It can contain extensive evidence while leaving the central judgement difficult to find. It can secure agreement from a manager who lacks the authority to implement the response.
The organisation may therefore receive good work without being put in a position to use it.
That is why impact should not be treated as something that begins after the report is issued. The route to impact needs to be considered when the work is selected, scoped, timed, communicated and followed through.
There are seven places where that route commonly breaks.
1. Relevance: the technical question is answered, but the business question is missed
A piece of assurance work can be methodologically excellent and still feel peripheral to leadership.
This happens when the work explains that a control is inconsistent, a policy has not been followed or an approval is missing, but does not connect the weakness to the business question currently occupying management.
That question might concern the resilience of a major programme, customer impact, regulatory exposure, cost, the pace of integration or the viability of a planned operating model.
The test is not whether the issue matters in theory. It’s whether the reader can understand why it matters now.
Before finalising the message, ask: What choice, commitment or exposure should this work help leadership understand?
If that connection is missing, the work may be acknowledged as correct while remaining distant from the decision agenda.
2. Timing: the work arrives after the decision window has closed
Annual plans create structure, but organisations do not make their most important choices according to the audit calendar.
Budgets are approved. Suppliers are selected. Systems are designed. Operating models are agreed. Programmes move from planning into delivery.
An audit can be completed on schedule and still arrive after these choices have been made.
At that point, even a strong conclusion may have limited influence. The organisation may face contractual commitments, sunk costs or implementation deadlines that make the original recommendation considerably harder to adopt.
The answer is not to abandon planning. It is to supplement the annual plan with a view of the organisation’s decision windows.
Before scheduling significant work, ask when leadership still has room to change the choice. That date may matter more than the planned reporting date.
3. Judgement: the message disappears inside the evidence
Assurance teams are trained to build an evidence base capable of withstanding challenge. That discipline matters.
The problem begins when the evidence base becomes the communication structure.
Lengthy testing schedules, control descriptions, interview summaries, exceptions and caveats may all be necessary to support the conclusion. They do not all need equal prominence in the leadership message.
Senior readers usually need five things to be immediately visible:
The main judgement.
The proof that makes it credible.
The uncertainty that remains.
Why the issue matters now.
The response that needs to be challenged, decided or changed.
Evidence establishes credibility. Judgement turns that evidence into a useful position.
If the reader has to reconstruct the central point from ten pages of detail, the message is not yet finished.
One of the easiest ways to create false comfort is to confuse acceptance with authority.
A manager may understand the issue, agree with the conclusion and genuinely support the proposed response. They may still be unable to change the relevant policy, secure funding, modify the system, direct another function or accept the exposure.
The action then appears owned, but the critical decision remains elsewhere.
This is why the named action owner should not automatically be treated as the decision owner. One person may coordinate the activity while another controls the intervention that makes the activity possible.
A useful authority test asks:
Who can approve the change?
Who controls the necessary resources or dependencies?
Who can accept the remaining exposure if the change doesn’t happen?
If those questions point to someone other than the person accepting the action, the real route to implementation is still incomplete.
5. Operating reality: the response works on paper but fails under pressure
Some responses are designed for the process as documented rather than the process as lived.
They assume people have time that they do not have. They add manual checks to an already overloaded workflow. They depend on data that is not reliably available. They create approval steps that are routinely bypassed when customer or delivery pressure rises.
The issue is not always resistance. The response may simply be incompatible with the environment in which it must operate.
A practical operating-reality test is to ask what will happen when volumes rise, deadlines shorten, experienced people are absent or commercial pressure increases.
If the control only works when conditions are calm and everyone has spare capacity, it is not yet a dependable response.
Audit, risk and controls teams should therefore challenge not only whether the action sounds reasonable, but whether it can survive predictable pressure.
6. Governance: the issue becomes more visible without becoming more resolved
Visibility and movement are not the same.
An issue may pass through a working group, steering committee, risk committee and audit committee. Each forum receives an update. Each pack becomes slightly longer. The status may move from discussed to reviewed, noted and reported.
Yet the core position remains unchanged because no forum is clear about the decision it is expected to make.
Useful governance should create flow. It should identify the choice, the person with authority, the trade-off being made and the point at which escalation is required.
Where those elements are missing, governance can become a holding pattern. The issue travels through the organisation without reaching a decision.
A simple test for any governance forum is: What became clearer, more owned or more actionable because this item was discussed here?
If the answer is simply “the committee was informed”, the issue may have gained visibility without gaining a route forward.
7. Verification: activity is completed without proving that anything improved
The final gap appears after implementation.
Policies are updated. Training is completed. New fields are added to the system. Evidence is uploaded. The tracker is marked complete.
These activities may all be necessary. None of them automatically proves that the underlying position has improved.
Verification should test what changed after the work was done. Did the control operate? Did behaviour change? Did the number or severity of exceptions fall? Is the response sustainable during normal business pressure? Is the issue now less likely to recur?
Completion describes activity. Verification tests the outcome.
Without that distinction, the organisation can achieve 100 per cent completion while remaining uncertain about whether anything meaningful has changed.
A worked example: supplier due diligence
Consider an audit of supplier due diligence.
The work finds that due diligence is inconsistent across business units. Screening evidence is incomplete, risk classifications are applied differently and higher-risk suppliers are not always subject to enhanced review.
The analysis is accurate and well evidenced. Management accepts the finding.
But the report arrives after the organisation has selected a new procurement platform and approved the implementation budget. The proposed response assumes new workflow functionality, but that functionality was excluded from the contracted design.
The procurement operations manager accepts the action, although the system design is controlled by the transformation programme and additional funding requires executive approval.
An interim manual review is introduced. It looks credible in the procedure but adds work to a team already struggling with transaction volumes. Predictably, the review is applied inconsistently during busy periods.
The issue is reported to several governance forums. Each receives an update, but none is explicitly asked to decide whether to fund the system change, redesign the interim control or accept the exposure.
Eventually, the action is closed because the procedure has been updated and training has been delivered. No one tests whether higher-risk suppliers are now being treated differently.
Every individual step appears reasonable. The work still fails to land.
A more useful audit approach would identify the timing constraint before the report, separate the process coordinator from the decision owner, test whether the manual response can survive operational pressure and ask leadership to choose between funding the system change, redesigning the control or formally accepting the interim exposure.
The technical finding has not changed. The route from finding to intervention has.
The landing review
Before issuing significant work, take ten minutes to review its route into the organisation.
Ask whether the work is connected to a live business question. Identify whether any important budget, supplier, system or operating-model decision will be made before the report arrives. Test whether the central judgement is visible without requiring the reader to reconstruct it from the evidence.
Then examine authority. Is the person accepting the response able to approve, fund or direct it? If not, who can? Test the proposed response against the conditions in which it will actually operate, including pressure, volume, competing priorities and cross-functional dependencies.
Finally, clarify the governance route and the evidence of improvement. Which forum is expected to challenge or decide? What will prove that the resulting position is better?
This review does not weaken audit independence or transfer management’s responsibility to assurance. It makes the route to action more explicit.
The three landing questions
If seven tests feel too many for the next conversation, begin with three:
What should change?
This forces the work beyond description and towards the practical difference being sought.
Who can make it happen?
This separates nominal ownership from the authority required to intervene.
What will prove it?
This moves the conversation beyond activity and towards observable improvement.
These questions are deliberately simple. Their value is that they expose where apparently complete work is still operationally unfinished.
Leadership Signals replay: AI and analytics for audit leaders
This week, I was joined by Trent Russell, Founder of Greenskies Analytics and Host of The Audit Podcast, for a practical Leadership Signals conversation on AI and analytics for audit leaders and what these capabilities should actually change in how a function is run.
Watch the full Leadership Signals replay on YouTube, and please subscribe to the BtL YouTube channel:
The discussion moved beyond individual tools, demonstrations and lists of potential use cases. At a high level, one of the strongest themes was that AI and analytics create more value when they are embedded into the way audit work is planned, scoped, delivered and reviewed, rather than treated as separate innovation projects operating at the edge of the methodology.
We also discussed why audit leaders should not think of AI and analytics as competing alternatives. Analytics remains valuable for interrogating structured data, identifying patterns, testing populations and exposing unusual activity. AI can support different parts of the work, including research, drafting and interaction with information. The important leadership question is how these capabilities work together within a controlled process.
Another clear takeaway was that adopting technology does not remove the need for human judgement. Audit teams still need to understand the evidence, challenge the output, recognise uncertainty and remain accountable for the conclusion. Faster production is not automatically better assurance, particularly if the function cannot explain how an output was produced, reviewed and used.
The conversation also reinforced the importance of starting with the problem and the audit process, not simply with the newest tool. Audit leaders need to consider data availability, team capability, quality controls, stakeholder expectations and where technology can genuinely improve coverage, timing or insight. A collection of disconnected use cases may create activity without changing how the function operates.
That connects closely to the theme of this edition. AI and analytics can help produce work more quickly, but speed alone will not close the landing gap. The work still needs to reach the right question, at the right time, with visible judgement, appropriate authority and a credible route into action.
Thank you to Trent for being my guest, and I look forward to welcoming him back again soon.
Closing reflection
Audit, risk and controls teams cannot guarantee that management will act. Nor should they take ownership of management’s response.
They can, however, make the conditions for useful action considerably clearer.
They can connect technical issues to live business questions. They can align work with decision windows. They can make judgement more visible, identify where authority really sits and test whether responses fit operating reality. They can distinguish governance visibility from governance movement and completion from demonstrated improvement.
Being right matters. Evidence matters. Professional discipline matters.
But the work is not truly finished when the conclusion is technically defensible. It is finished when the people who need to use it can see what matters, what needs to happen next and what will demonstrate a better position.
Reply and tell me: Where does good work most often disappear in your organisation: relevance, timing, judgement, authority, operating reality, governance or verification?
Have a great week ahead everyone, and thank you for being part of BtL.
Best,
Founder Beyond the Lines™ | Integral Assurance
Share with a colleague
If this edition would help someone in your audit, risk, controls or governance network, please forward it to them.
Beyond the Lines™ exists to help assurance and risk professionals turn credible work into clearer challenge, stronger intervention and visible improvement.
The 5 stages of finance grief
Denial that manual reconciliation is acceptable
Anger over the lack of spend visibility
Bargaining with colleagues to submit expense receipts
Depression for the late nights closing the books
Accepting Ramp to skip the first 4





