
ASSURANCE TO ACTION FOR INTERNAL AUDIT, RISK & CONTROLS LEADERS
ISSUE 052 • 29 SEPTEMBER 2026
━ ━ ━
What would convince you the fix worked?
Hi {{name|there}},
Agreement on a finding is a start. The harder work is deciding who will act, resolving the obstacles and showing that the response has made a difference.
In Issue 50, we looked at where an assurance handoff can fail. In Issue 51, we agreed the evidence before the work starts. This time, we turn to the decision at the other end: what would convince you the fix worked?
This week, I’m sharing what I heard from risk and controls practitioners at Impero, followed by Evan Tsai’s guest article on why findings stall. Then we put it to work with a short closure review and the full Evidence Before Closure field guide.
FROM THE ROOM
People are ready to challenge the controls they have

Speaking at Impero’s Compliance.Curated event in Copenhagen.
Speaking about control theatre at Impero’s Compliance.Curated event in Copenhagen gave me the chance to compare perspectives with people doing this work every day. Three things stayed with me.
Control rationalisation is high on the agenda. People are ready to challenge the status quo. Risk and controls maturity is a journey: once the basics are in place, it is time to get brave and ask whether each control still deserves its place. For me, that means being clear about what it protects, what would change without it and whether there is a better way to manage the risk.
AI is moving faster than agreement on what comes next. The conversations covered tooling, control performance, testing and the role of the second line. There is plenty still to work through, while companies seem to be advancing quickly with agents. My practical question is who can approve, challenge or stop an agent’s actions, and how we will know its controls are working as intended.
Peer learning leaves you with things to do. Hearing different experiences and perspectives gave me a list of ideas I want to put into action. Watch this space.
Those conversations brought me back to a practical question: when we agree something needs to change, who has the responsibility and authority to make it happen? Evan’s two examples show why the answer matters.
GUEST PERSPECTIVE
Why Governance Structure Determines Whether Audit Findings Land
I want to start with something most internal auditors have experienced but rarely talk about directly.
You do the work. The finding is solid. Management sits across the table, looks at the evidence, and agrees — yes, this is a real issue, yes, it needs to be fixed. The report goes out. The finding gets logged.
And then six months later, nothing has changed.
Not because anyone was dishonest. Not because the audit was flawed. But because somewhere between "we agree this is a problem" and "someone actually fixes it," the whole thing just... stalled.
I've seen this enough times now to know it's rarely about the quality of the audit work. It's almost always about what's underneath the finding — the governance structure that's supposed to carry it from identification to resolution. Decision rights. Ownership. Escalation routes. When those things aren't clear, even the most valid finding can drift indefinitely.
Let me show you what I mean with two examples. Same issue type. Completely different outcomes.
The first one didn't go well.
A mid-sized technology and manufacturing company had SAP as its core ERP, with a GRC tool extracting access profiles to flag Segregation of Duties conflicts. The SOD issue was first identified in 2023. Nobody disputed it — the access conflicts were real and everyone agreed something needed to be done.
But the finding was written in a way that left ownership open. The issue touched Finance, Accounting, and IT, and the write-up didn't pin accountability to any one of them. Each function read the finding and saw a problem that belonged to someone else.
So it sat. For six months, the finding lived in a tracker while conversations went in circles. Finance thought IT should lead since it was a system access issue. IT felt the business needed to define what an acceptable conflict even looked like. Accounting wasn't sure it was their call at all.
Eventually the organisation found a way out — compensating controls applied across all affected access. The finding got closed. The underlying SOD conflicts stayed.
The audit did everything right. The governance structure had no mechanism to force the ownership question to an answer, no escalation path to surface the stalemate to someone who could break it. So the path of least resistance won.
The second one went differently.
A larger services organisation had a comparable problem: elevated access and SOD conflicts in Oracle Fusion. I mention the size only to make a point — bigger doesn't automatically mean better governed. Plenty of large organisations have the same ownership vacuum as the first example. What made the difference here had nothing to do with headcount or budget.
This organisation had a compliance function that had positioned itself as a formal bridge between Internal Audit and the business. Not a passive go-between — an active one. When the SOD issue came up, that function didn't wait to be asked. They pulled the access data, analyzed where the real conflicts sat, and led a redesign of access roles where it actually made sense to do so.
Audit didn't have to chase anyone for a remediation plan. The structure had already answered the ownership question before it became a problem.
The result was real remediation. Not a workaround. Not a blanket compensating control. A deliberate, well-reasoned fix.
So what's the actual difference between these two situations?
It's tempting to look at the second example and say the organisation succeeded because it was bigger, or better resourced, or had more mature processes. I'd push back on that. A small organisation with a well-positioned compliance function gets the same result. A large one without it hits the same wall as the first example.
The difference was structural. In the first case, the governance architecture beneath the finding had no way to carry the weight of resolution — no clear decision rights, no named owner, no escalation path that anyone was obligated to use. In the second, a functioning compliance layer had effectively pre-answered all of those questions.
Same issue type. Same audit objective. The structure underneath determined everything.
So what does that structure actually look like in practice?
When a finding stalls, the instinct is usually to look at the audit — was the finding worded clearly enough, was the evidence strong enough, was management engaged early enough? Those are reasonable questions. But they're often the wrong ones.
Before the report goes out, the more useful diagnostic is structural. Ask:
Who owns this finding — specifically? Not a function. A name. If the answer is "Finance and IT jointly," that's not ownership, that's ambiguity with a slash in the middle.
If ownership is contested, what's the escalation path — and who triggers it? In the first example, there was no clear answer. The stalemate had nowhere to go.
Is there a second line function positioned to bridge audit and the business? Not just to relay messages, but to take an active role in driving remediation when it crosses functional lines.
In the first example, none of those had a clear answer going in. In the second, the compliance function had quietly answered all of them before the issue even surfaced.
And this is the part that matters most.
Internal Audit can surface the truth. It can document the issue, make the case, and get management to agree. But whether that truth turns into action — whether the finding actually lands — depends on a governance structure that most audit functions spend very little time examining.
Transformation measured by movement has to start one level deeper than the audit itself. At the structure that decides whether movement is even possible.
That's where the real work sits.
Evan Tsai is the Founder of Phoenix Ascent Advisory LLC, a governance, risk and compliance consulting firm that helps senior audit and compliance leaders build governance structures that hold up under pressure. Both client examples have been anonymised. Connect with Evan on LinkedIn.
PUT IT TO WORK
Before you approve the closure
Evan’s examples take us from agreeing a finding to getting a response in place. The next question is what that response allows us to conclude about the risk.
A compensating control can be a sound response when its coverage and effectiveness are evidenced. A redesigned role needs evidence too. The type of fix alone cannot settle the closure decision.
Choose one action due for closure and review it with the person who owns the underlying risk.
1 · STATE THE CLAIM
What do you want to be able to say is different? Be specific about the control, behaviour or exposure. “The new process is live” is a narrower claim than “the original problem has been resolved”.
2 · MATCH THE EVIDENCE
What supports that claim? Distinguish evidence that the change was implemented from evidence that it operates in practice and has the intended effect. Consider the period covered, exceptions and ways the control could be bypassed.
3 · MAKE THE NEXT DECISION
Is there enough evidence for closure under your agreed criteria, is further validation needed, or does the response need changing? Record the remaining uncertainty, the evidence still needed, the owner and the next review date.
Match the depth of the review to the risk. Where implementation is complete but effectiveness remains unproven, keep that distinction visible. Management remains responsible for the risk and any decision to accept it.
Useful closure record: What we can conclude. What we cannot yet conclude. Who owns the next check, and when.
BTL TOOLBOX
Evidence Before Closure
FG02 · The complete nine-page Action Closure Field Guide
Use the guide alongside the exercise to make a more defensible closure, validation or escalation decision. It brings together the five questions before closure, evidence guidance, worked examples and a closure review record.
Bring one action and its evidence pack to your next review. Use the guide to identify the claim the evidence supports, then record the decision and any follow-up.
The appetite for practical AI discussion and peer learning is also why Trent’s upcoming conference feels relevant to this edition.
IN THE ROOM
AUDIT ANALYTICS & AI FALL CONFERENCE 2026
21–22 October | Virtual | 9am–4pm Central Time
Trent Russell and Greenskies Analytics are bringing together two days focused on analytics and AI in internal audit. The programme features 12 applied sessions, with speakers from organisations including ConocoPhillips and TIAA.
Sessions run from 9am to 4pm Central Time on both days, with live Q&A throughout, on-demand options, and up to 12 NASBA CPE credits available.
I’m recommending it because the agenda is built around people showing how the work is being done. If you are building analytics or AI capability in an audit or assurance team, it is worth a look. This is a paid event; current options are on the registration page.
YOUR VIEW
What is hardest to judge before you close an action?
Whether it has been implemented, whether it operates consistently, or whether it has made the intended difference? Reply and tell me where your team gets stuck.
Tim Buckley
Founder, Beyond the Lines™ | Integral Assurance
Assurance Impact | Assurance to Action


