Beyond Title IX: Auditing Civil Rights Infrastructure in Higher Education

by Adrienne Meador Murray

Civil rights compliance in higher education is often organized as a collection of separate legal obligations and administrative functions. Title IX may sit in one office. Title VI responsibilities may be assigned elsewhere. Disability compliance may involve Accessibility Services, Human Resources, Information Technology, Facilities, and Academic Affairs. Complaints involving employees may move through Human Resources, while student matters may be addressed through student conduct.

That structure may make operational sense. From an internal audit perspective, however, it can obscure a larger question: Does the institution have a functioning civil rights infrastructure through which discrimination, discriminatory harassment, retaliation, and accessibility concerns may be reported?

Civil rights infrastructure is not a term of art in federal law. It is a useful way to describe the institutional system through which civil rights obligations are assigned, communicated, implemented, documented, monitored, and escalated. It includes governance, policies, reporting channels, complaint processes, data, training, third-party oversight, management reporting, and regulatory change management.

For internal audit, examining that infrastructure may reveal risks that a narrow review of any single policy or compliance office would miss.

Civil Rights Compliance Is an Enterprise Process

Civil rights compliance does not belong exclusively to a civil rights office. The underlying risks exist throughout the university. Financial aid may publish scholarship opportunities. Academic departments establish program requirements. Student Affairs manages organizations, events, and conduct processes. Human Resources oversees employment practices and complaints. Information Technology and Procurement acquire digital products and services that may carry accessibility obligations. Athletics, Campus Safety/Campus Police and individual schools or colleges operate within their own regulatory environments.

Each area may function appropriately on its own while gaps remain between them. That is where internal audit can add value. The objective is not to determine whether every institutional decision complies with every civil rights law. Internal auditors do not need to become Title IX coordinators, civil rights investigators, or legal counsel. They can, however, determine whether the institution has controls capable of recognizing civil rights risk, assigning responsibility, moving information to the right people, and documenting what happened. Seven areas deserve particular attention.

1. Governance and Accountability

Every significant civil rights obligation should have identifiable institutional ownership. Internal audit should test more than whether a person or office is named in policy. Who has authority to require corrective action? What matters must be escalated? What reaches executive leadership or the governing board? Who assumes responsibility when a matter crosses organizational boundaries?

A university may have clearly defined Title IX leadership, but less clarity about responsibility for other forms of discrimination or accessibility compliance. In decentralized institutions, several offices may reasonably share the responsibility. The control objective is not organizational uniformity; it is gap-free accountability.

2. Intake and Routing

Universities rarely have one reporting system. A concern may first reach student conduct, Human Resources, Campus Safety, a dean, an ethics hotline, Disability Services, a department chair, or a civil rights office. That creates an important control risk: The institution may receive information about a potential incident without the office responsible for evaluating its civil rights implications being informed.

Internal audit can map major intake channels and follow a sample of reports through the system. Are employees expected to recognize concerns that may require referral? Are referrals documented? Are handoffs tracked? Does responsibility clearly transfer from one office to another? When multiple offices remain involved, are their respective responsibilities understood?

A reporting channel is not an effective control simply because it exists. The control is effective only if information reaches the people responsible for acting on it.

3. Data and Reconciliation

Civil rights compliance increasingly depends on an institution’s ability to understand what is happening across multiple systems. That requires reliable data. Depending on institutional structure and legal requirements, management may need information concerning allegation type, reporting channel, respondent affiliation, organizational unit, status, outcome, timeliness, recurring locations or programs, and remedial action.

The goal is not to create the largest possible database. It is to determine whether management can answer basic risk questions using information the institution already possesses. Fragmented data can prevent an institution from recognizing patterns that no single office can see on its own.

Internal audit can test this by selecting matters from different reporting channels and following them through the institution. Do they appear in the appropriate system? Are classifications consistent? Is disposition information complete? Can management reports be reconciled to underlying records?

4. The Compliance Perimeter

Some civil rights risks originate well outside the office responsible for compliance. Scholarships, internships, academic opportunities, external partnerships, camps, vendors, digital platforms, and other decentralized activities may all implicate civil rights requirements.

Internal audit should ask whether the institution has identified this broader compliance perimeter. Who reviews eligibility requirements for new programs or opportunities? Who reviews external partnerships? Do technology procurement processes incorporate applicable accessibility requirements? Are exceptions documented? Can a department establish a new program without anyone considering whether civil rights obligations are implicated?

Third-party involvement does not necessarily move risk outside the institution’s control environment.

The audit question is whether the institution has controls at the points where decentralized activity can create enterprise-level compliance exposure.

5. Complaint Resolution and Remediation

Internal auditors should distinguish between processing a case and managing institutional risk. A complaint may be administratively closed, referred to another office, or resolved through a conduct or employment process. That does not necessarily mean every institutional issue associated with the matter has been resolved.

Internal audit should not second-guess legal conclusions or credibility determinations, but it can test the process surrounding them. Was jurisdiction assessed consistently? Was the matter routed correctly? Were required steps completed? Were conflicts addressed? Was the outcome documented? Were remedial or corrective actions assigned? Was completion verified?

The last question is especially important. A recommendation is not a completed control. A corrective action that appears in a report but is never implemented does not reduce institutional risk.

6. Documentation and Evidence

Civil rights programs may have strong policies but weak evidence that required controls are actually operated. Internal auditors know this distinction well.

  • A policy requiring training is not evidence that training occurred.
  • A procedure requiring review is not evidence that the review took place.
  • A committee assigned oversight responsibility is not evidence that concerns were escalated or corrective action occurred.
  • A management report is not reliable simply because it contains numbers.

Testing should focus on evidence: source records, reconciliations, approvals, referral documentation, exception logs, training completion records, corrective-action tracking, committee records, and evidence of follow-up.

This is where the role of internal audit should remain especially clear: Compliance owns the requirement. Management owns the controls. Internal audit tests whether those controls are appropriately designed and operating as represented. This is what ensures defensibility.

7. Regulatory Change Management

Civil rights requirements continue to evolve, as do institutional structures, technology, and operating practices. An effective compliance environment therefore needs a method for translating legal and regulatory developments into operational change.

Internal audit can examine whether that process answers several basic questions. What changed? Which policies, systems, contracts, or practices are affected? Who owns implementation? How will the institution verify that implementation occurred? How will leadership know when the work is complete?

A legal update circulated by email is not a control. The control is the process that converts the update into documented institutional action. This is particularly important when a regulatory change affects several areas of the institution at once. Without defined ownership and follow-through, implementation can become inconsistent across schools, campuses, or administrative units.

Five Questions to Start the Audit

A civil rights infrastructure review does not need to begin as a comprehensive legal compliance audit. Internal audit can start with five questions:

  1. Who owns each major civil rights compliance responsibility, and is that responsibility documented?
  2. Can the institution identify the primary channels through which discrimination, discriminatory harassment, retaliation, and accessibility concerns may be reported?
  3. Are there controls ensuring that concerns reach the appropriate compliance function regardless of where they are first reported?
  4. Can management reports concerning civil rights activity be reconciled to reliable underlying records?
  5. Does the institution have a documented process for converting changes in law, regulation, and institutional requirements into operational action?

The answers may tell an audit committee considerably more about civil rights risk than confirming that required policies are posted on a website.

The Opportunity for Internal Audit

Civil rights matters are legally complex, operationally significant, and frequently sensitive. That can make Internal Audit understandably cautious about entering this area. But internal auditors do not need to decide the law to audit the infrastructure supporting compliance.

Governance, data integrity, referral processes, documentation, third-party controls, corrective-action tracking, and regulatory change management are all auditable. One could argue that the increasing complexity of civil rights compliance makes independent assurance over those processes more important, not less.

The most useful question for internal audit may therefore be broader than whether an institution’s Title IX policy or other civil rights procedure is technically correct on paper. If a civil rights risk emerged somewhere in the institution tomorrow, would the college or university’s infrastructure reliably identify, route, evaluate, address, and document the risk and tell leadership what it needed to know? If the answer depends on which office happens to receive the information first, the institution may have policies. It may not yet have infrastructure.

Sharing OU’s Journey to Improve Anonymous Ethics and Compliance Reporting

By Carolyn Clink

Anonymous ethics and compliance reporting programs are a critical component of institutional governance in higher education, yet their effectiveness depends on far more than awareness alone. Posters, training reminders, and website links may create visibility, but utilization is ultimately shaped by trust in the system, clarity of the reporting process, and the institution’s follow-through once a concern is raised.

Over the past five years, the University of Oklahoma (OU) undertook a series of incremental but deliberate enhancements to its anonymous reporting hotline and case management practices that collectively strengthened utilization, improved the experience for reporters and case managers, and produced more reliable data for oversight and improvement. The results offer a practical example for institutions seeking to move beyond awareness toward sustained performance.

Enhancing the Hotline Intake Process

OU transitioned from a single general intake site launched in 2016 to campus‑branded “Report It!” sites in 2021 and expanded the program to all system campuses. Although branding may appear primarily visual, it also serves to reassure users that the reporting site is an official institutional channel, which can enhance credibility and encourage reporting. Ease of access can be the difference between a completed report and an abandoned attempt. OU improved usability through the addition of mobile reporting access, streamlined intake questionnaires, and automatic system responses which allowed reporters the comfort that their complaint was being addressed.

One of the most common friction points in hotline intake is asking reporters to choose from an overwhelming list of reporting categories. OU reduced its issue types from 46 to 26, aiming to make selection faster and more consistent. Better taxonomy helps reporters spend less time guessing where their issue fits and also benefits case managers with clearer issue routing. OU also refined issue categories to better align with institutional risk areas.

OU added process overviews and resource links directly to the intake sites. This created a more transparent reporting pathway by giving users additional context about how the process works and where to find related support resources. In 2025, OU also added a detailed “Your Obligations as a Reporter” statement to the websites, reinforcing expectations around good faith reporting, non-retaliation, and the consequences of false reporting. This type of clarity can reduce misuse while strengthening confidence in the integrity of the process.

With the reporting process easier to navigate, OU focused next on ensuring students, employees, and other stakeholders knew when and how to use it.

Awareness Efforts

Intake improvements were paired with sustained awareness efforts for the Report It! program rather than initiating a one‑time launch. Highlights across the timeline included:

  • 2021 enhancement launch: posters, a presidential mass email, an internal newsletter article, and integration into manager orientation.
  • 2022 refresh: adding digital signs and improving poster placement through walkthroughs and public-space targeting.
  • 2023–present: collaboration with enterprise risk stakeholders to meet specific group needs.
  • 2024–2025: expansions into student-facing channels, including wallet cards at events, move-in initiatives, arena signage, tabling, and training touchpoints.

Over time, awareness efforts were implemented through successive outreach activities tailored to different campus settings, audiences, and communication channels.

Case Handling Improvements

Enhancing awareness and the reporter experience, however, represented only half of the effort. The second half is ensuring the internal system supports consistency, speed, and reliable outcomes. OU’s enhancements for case managers included:

  • Reducing duplication in questionnaires and data capture.
  • Clarifying definitions and aligning stakeholders on issue type meaning.
  • Adding search functionality to find and manage cases more efficiently.
  • Single sign-on to reduce access friction.
  • Training for subject matter experts after software enhancements.
  • Expansion of functional add-ons, including a Clery Act CSA reporting tool in 2024.

These changes positively affected cycle times, documentation quality, and reporting consistency, which influenced reporter confidence in the overall process.

To further support consistency, OU formalized case management standards with clear timelines and required documentation. Cases were assigned within 24 hours, status updates were expected within two business days, and post-closure follow-up was required. Defined case closure protocols and required data fields, including outcome, action taken, Clery indicators, and synopsis notes, were established to improve comparability across cases and time periods. OU also established a five-business-day post-closure period during which reporters may provide clarification or supplemental information, which is particularly valuable for anonymous reports that initially lack sufficient detail for investigation.

These standards enabled more reliable monitoring, reporting, and benchmarking and reduced variability that can undermine KPI analysis.


KPIs and Benchmarking

With structured data in place, OU developed a KPI framework that examined both intake and outcomes. Key metrics included:

  • Intake volume by campus and issue type
  • Intake method
  • Anonymous reporting rate
  • Open versus closed case counts
  • Average case closure time
  • Substantiation rate
  • Outcomes and actions taken
  • Anonymous follow-up rate

These metrics supported internal monitoring, transparency with senior leadership and the Board of Regents, and continuous improvement discussions with subject matter experts. Importantly, metrics were used as management tools rather than static scorecards, enabling conversations about awareness, investigative effectiveness, policy clarity, and organizational culture.

One notable KPI goal was to reduce the number of anonymous reports. This sounds like the opposite of what a hotline program desires. A consistently high anonymous rate may suggest concern about retaliation, limited trust, or uncertainty about the reporting process. OU’s rationale was aligned with mature program thinking. Named reporters tend to be more engaged, and increased trust often reduces the perceived need for anonymity. Additionally, better collaboration with the reporter supports faster resolution and increased trust.

Once consistent metrics were in place, the program moved from basic volume tracking to broader questions about patterns, policy implications, and preventive action. OU’s reporting and analysis approach supports:

  • Trend analysis and risk identification
  • Targeted recommendations for program improvements
  • Better governance reporting for transparency
  • Reinforcement of behavioral expectations (e.g., recommendations for improved employee civility expectations; student antibullying and social media expectations)
  • Feedback loops into academic units to monitor follow-through and actions taken

This way hotline programs can contribute to institutional value: by addressing individual cases while also informing policy, systems, and culture over time.

Results of the Improvements

The cumulative impact of these enhancements was measurable. Case intake increased in each reporting period reviewed, with growth of 58 percent from 2020 to 2021, 23 percent from 2021 to 2022, 24 percent from 2022 to 2023, and 16 percent from 2024 to 2025. Viewed collectively, these trends suggest that coordinated improvements to intake design, awareness, and case management can support sustained utilization rather than temporary spikes.

OU’s intake rate increases between 2020-2024 (metrics by Carolyn Clink)

In addition to increased volume, the quality and disposition of reports provided further insight into program effectiveness. In calendar year 2024, 55 percent of hotline reports contained sufficient information and/or reporter engagement to support an investigation, representing 303 cases investigated to resolution. Thirty-five percent of reports lacked sufficient information to resolve the matter, while the remaining 10 percent were either referred outside the University or determined to be frivolous. These results highlight both the value of increased utilization and the continued importance of enhancing report quality and reporter engagement.

Over time, improved data allowed OU Internal Audit to analyze trends and make recommendations to management to refine policies such as employee civility and student conduct expectations, and to provide more targeted feedback to academic and administrative units.

OU’s ongoing efforts also include a focus on consolidated incident reporting across disparate systems, with stakeholders working to cross-reference data and report consistent KPIs across platforms so stakeholders can compare trends, strengthen management visibility, and identify emerging risks more consistently.

Key Takeaways for Higher Education Programs

For institutions reviewing anonymous reporting programs, OU’s experience highlights the following practical considerations:

  • Simplify intake – Reduce friction, clarify categories, and add clear guidance.
  • Support trust – Branding, transparency, and follow-through can influence whether individuals report.
  • Fix the internal workflow – Case manager experience shapes speed, consistency, and data quality.
  • Standardize case handling – Clear timelines, definitions, and required closure fields improve consistency and reporting quality.
  • Use KPIs that inform action – Metrics are most useful when they support operational and governance decisions.
  • Plan for cross-system visibility – Multiple reporting platforms require stronger coordination over time.

For higher education institutions, anonymous reporting systems are most effective when usability, process discipline, and performance measurement are addressed together. OU’s experience suggests that incremental operational changes can improve both utilization and consistency over time.

Metrics that Matter: How KPIs Define and Demonstrate Success

By Lisa Beymer and the ACUA Audit and Accounting Principles Subcommittee

While the term “Key Performance Indicator” (KPI) is not used in the Institute of Internal Auditor’s (IIA) revised Global Internal Audit Standards for considering the internal audit department’s effectiveness, it is clear that performance measurement is not optional. The underlying expectations call for internal audit functions to clearly define, monitor, and report on meaningful measures of performance. These measures are essential not only for demonstrating conformance to the Standards but also serve as objective evidence of Internal Audit’s effectiveness and value.

The following key Standards elevate the importance of performance measurement:

  • Standard 8.3 requires the Chief Audit Executive (CAE) to maintain a quality assurance and improvement program that evaluates efficiency and effectiveness.
  • Standard 8.4 has the expectation that external quality assessments evaluate whether the internal audit function is actively monitoring performance.
  • Standard 9.2 requires supporting initiatives that align with Internal Audit’s strategy.
  • Standard 12.2 specifically calls for developing objectives to measure performance.

Additionally, the IIA has released their IIA Performance Measurement Tool that provides guidance on conforming with Standard 12.2 on performance measurement.

KPI Examples for Internal Auditors

Are your KPIs addressing the right risks and making a meaningful impact? Effective KPIs should directly align with your department’s strategy, areas of improvement needed, and stakeholder expectations. KPIs can also be internal or external – designed for the benefit of the internal audit shop or to furnish outside leadership with performance information.

Measuring Activity and Value in Thoughtful KPI Design

Take your KPIs even farther by tying them to goals to drive positive action rather than simply reporting activity. Rather than only reporting the quantity of engagements completed during the year, set a desired completion rate as a goal. For example, “we completed 18 of 20 planned engagements,” can be tied to a goal by stating “we completed 90% of our planned audits, which exceeds our goal of 85%.”

Make sure your goals are SMART – specific, measurable, achievable, relevant, and timely. For example, a goal to “decrease time spent in reporting” can become a SMART goal by adding details, such as “decrease average days spent in reporting from 45 to 30 by the end of this calendar year.”

Monitoring KPIs can be achieved using the simplest of manual Excel spreadsheets to embedded dashboards and modules from audit workpaper management software. Progress on KPIs is often shared with senior management and the board through annual reports and board presentations.

The Double-Edged Sword of KPIs

Well-designed KPIs drive quality, accountability, and continuous improvement. On the other hand, poorly designed or managed KPIs can encourage shortcuts, misaligned priorities, or even unintended manipulation. For example, overly emphasizing a shorter audit cycle time could lead to rushed fieldwork. Encouraging a high number of audit findings could lead to auditors making mountains out of molehills, which may negatively affect your department’s credibility.

There are numerous challenges to developing a KPI system. The ability to gather and update data from multiple sources can be time consuming, and data reliability may become a factor. There is a risk of only measuring the activity versus its impact. KPI results may be misinterpreted by management, and CAEs may be tempted to skew the statistics to appear more favorable. Additionally, the audit team may be reluctant to adapt to new goals.

When creating balanced and relevant KPIs, consider the following practical implementation tips:

  • Measure what is most meaningful, not just what is easiest to track.
  • Focus on outcomes, not just activity.
  • Define KPIs clearly to avoid confusion in how they are measured.
  • Avoid KPI overload – keep the team focused on the metrics that matter most.
  • Be balanced – include multiple dimensions of performance measurement.
  • Involve the team to promote accountability and buy-in.
  • Periodically review KPIs to ensure they are not outdated or irrelevant.

Well-defined KPIs can improve the audit department’s effectiveness and efficiency while addressing the new Global Internal Audit Standards. With the new fiscal year approaching, this is a great time to evaluate and enhance your department’s KPIs.

AAP Roundtable: Strategies for Risk Assessments, Developing Findings, and Follow-up

By Susie Geiger and the AAP Subcommittee

On January 14, 2026, the Auditing and Accounting Principles (AAP) Subcommittee of the Association of College and University Auditors (ACUA) hosted a roundtable to help institutions strengthen conformance with Domain V of the updated Institute of Internal Auditor’s Global Internal Audit Standards. The session focused on three standards central to effective engagement execution: Standard 13.2 on engagement risk assessments, Standard 14.2 on analyses and developing potential findings, and Standard 15.2 on confirming the implementation of recommendations or action plans. Nearly 50 ACUA members participated by sharing challenges, comparing practices, and identifying strategies to improve consistency, efficiency, and quality across their audit functions.

This highly interactive roundtable was facilitated by AAP Committee members Hollie Andrus, Patty Davidson, Jennifer Dent, Erin Egan, John McDaniel, and Agnessa Vartanova. After sharing the requirements of each of the Standards, the participants met in breakout rooms to discuss how institutions conduct and document risk assessments, analyze information to identify findings, and perform follow-up activities. These discussions are summarized below.

Standard 13.2 – Engagement Risk Assessments

Standard 13.2 requires internal auditors to understand the activity under review, assess relevant risks, evaluate governance and compliance processes, and identify the significance of risks, including fraud risks. Institutions reported that meeting these expectations consistently remains a significant challenge. In the breakout rooms, participants were asked to discuss the question “How does your institution conduct and document your engagement risk assessments?”

Challenges in Risk Assessment

Several audit shops struggle with training auditors to identify and analyze risks in a consistent manner across diverse engagements. Limited subject‑matter expertise, particularly in IT and fraud, further complicates risk identification. Many offices also lack tools or data analytics capabilities to support more sophisticated assessments.

Organizational dynamics add another layer of difficulty. Risk tolerance varies widely across campus units, and leadership turnover can disrupt expectations. Smaller audit shops, in particular, often lack a centralized risk management function to help define institutional risk tolerance and appetite. Communication barriers also arise when auditors and clients use terminology differently, leading to misunderstandings that hinder risk identification.

Strategies for Improving Risk Identification and Evaluation

Despite these challenges, participants shared a range of practical strategies for effectively identifying and evaluating risks. Many offices have adopted standard templates to document risk assessments and utilize inventories of common risks, including ones specifically related to fraud. Others conduct team brainstorming sessions at the start of each engagement to determine potential risks.

Audit functions are also drawing on diverse information sources such as prior audit reports, peer institution audits, policies, strategic plans, regulatory guidance, and ACUA resources such as the Risk Dictionary. Some offices incorporate frameworks like the Association of Certified Fraud Examiner’s (ACFE) Occupational Fraud Framework to strengthen evaluation of fraud and other types of risks. Some shops work directly with their institution’s risk management office to get an understanding of the institution’s risk tolerance and appetite. A few institutions have hired a Certified Fraud Examiner or are encouraging existing auditors to pursue the designation with the support of the office.

To improve consistency, several participants described developing scoring systems for prioritizing risks and creating standard lists of client questions to guide kickoff meetings. Others emphasized the value of pre‑engagement research and the use of asking the client open‑ended questions such as “what can go wrong?” to uncover contextual risks. Another suggestion was to provide audit clients with a confidential method for communicating their concerns to internal audit.

Standard 14.2 – Analyses and Potential for Engagement Findings

Standard 14.2 requires auditors to analyze relevant, reliable, and sufficient information to develop potential findings and evaluate identified differences between the evaluation criteria and the existing state (condition) to determine which are reportable findings. In the breakout rooms, members shared several challenges they have faced in developing testing observations into reportable findings and worked together to brainstorm strategies for improving conformance with this standard. Participants were asked to discuss the questions “How does your institution conduct and document your engagement risk assessments?” and “How much testing is needed for assurance engagements to develop an issue?”

Challenges in Testing and Analysis

Higher education institutions often have multiple decentralized systems that do not interface, leading to inconsistent datasets that complicate testing.  Participants also identified inconsistent testing methodologies, lack of standard templates, and difficulty balancing over‑ and under‑documentation as common concerns which can lead to poor quality assurance.

Some offices reported experimenting with AI tools but expressed uncertainty about evaluating the reliability of AI‑generated results. Others noted that some clients may not fully understand internal controls, making it harder to validate observations or explain findings. Several participants also said that their offices have trouble performing root cause analysis, especially for newer auditors who may be tempted to rely on assumptions rather than structured analysis.

Strategies for Enhancing Finding Development

Participants shared several approaches to improve testing quality and consistency. Many offices use verification between data sources to validate accuracy. Others have adopted standard testing templates with required fields but built‑in flexibility to accommodate diverse audit areas.  Some shops have created specialized procedures and templates for conducting and documenting the testing of regularly reviewed processes like travel expenses and procurement card transactions.

Training plays a central role, and many offices are emphasizing documentation expectations during onboarding and ongoing professional development. Audit management software, such as TeamMate, helps some teams link risks, controls, and testing more effectively. To strengthen root cause analysis, participants recommended techniques such as the “five whys” and incorporating client input. AI tools may also support testing when procedures are carefully designed and validated.

Determining the Extent of Testing

Participants also discussed how much testing is needed to develop a finding. Resource constraints and inconsistent access to data prevent audit functions from effectively employing population-level analysis at a significant scale, leading many offices to rely on judgmental sampling. Some auditors also struggle to move beyond inquiry and neglect to corroborate client statements with evidence. Several participants said that their offices do not have procedures for assessing and prioritizing/ranking identified observations.

To address these issues, offices are developing standard definitions of “relevant, reliable, and sufficient” information aligned with Standard 14.1. Others use external frameworks (AICPA, FASB) to guide finding criteria. Risk decision matrices help some teams evaluate materiality and determine whether an observation warrants verbal communication or a formal finding. Some shops are making efforts to transition from testing small samples to population-level testing when feasible. Auditors are also being trained that inquiry is often not sufficient to confirm or dismiss a finding; they should corroborate management statements with observation, examination, or reperformance.

Standard 15.2 – Confirming the Implementation of Recommendations or Action Plans

Standard 15.2 requires internal audit functions to confirm whether management has implemented action plans and, when they have not, to follow the CAE’s established guidelines for management acceptance of risk. Participants were asked to discuss the question “How does your institution monitor and perform follow-up activities?” and discussed the following related challenges and strategies in the breakout rooms.

Challenges in Follow‑Up

Follow‑up processes are often less structured than planning or testing phases. Many offices rely heavily on e-mail and phone communication and lack standardized tools for tracking status updates. Some participants felt the follow‑up process is treated like an afterthought and receives much less attention and standardization than the planning and testing phases.

Delays in management action plan completion are common, and some clients do not provide explanations or updated timelines. Auditors also struggle to balance accountability with maintaining positive client relationships. Determining what constitutes sufficient verification, especially when deciding between retesting and reviewing client-provided evidence, remains a challenge.

Strategies for Effective Follow‑Up

Participants highlighted several practices that improve follow‑up effectiveness, including transitioning from “trust but don’t verify” cultures to more evidence-based follow-up procedures. Some offices include follow‑up activities directly in the audit plan to signal their importance to leadership and audit committees. Many have also developed standard templates for documenting action plan status updates.

Regular follow‑up cadences, such as every 90-120 days, help maintain momentum. Some offices conduct interim check‑ins rather than waiting for due dates, which has improved implementation rates. Prioritization methodologies also help identify high‑risk findings that require closer monitoring or escalation.

Clear communication is essential. Some offices have the client determine the specific action plan, with internal audit approval, to mitigate each finding rather than prescribing action plans they may not fully understand. During reporting, auditors define what “implemented” will look like for each action plan and explain how non‑responsiveness may be escalated. Some offices require written justifications for non‑implementation or use standard forms for documenting risk acceptance. Others report overdue action plans to leadership using dashboards and visualizations, and a few require clients to present their rationale for non‑implementation directly to the audit committee.

Conclusion

This roundtable generated discussion that was fruitful and varied, allowing participants to find comfort in shared struggles while also coming together to share creative ideas for solutions. Participants reported in a post-event survey that they found the roundtable valuable and would be interested in attending future roundtables focused on the Standards, as well as other topics.

The AAP Subcommittee will host another roundtable focused on conformance with Standards 13.2, 14.2, and 15.2, this time from the lens of conducting advisory work. This event is tentatively scheduled for Wednesday April 15, 2026, and invitations to register for the session will be e-mailed soon.