Skip to main content
Category: Internal Audit

Follow-Up

Simply put

A follow-up is an action taken after an earlier activity to check on progress or continue working toward a result. In a governance, risk, and compliance setting, it commonly refers to revisiting previously identified issues to see whether agreed actions have been carried out. The evidence available does not describe follow-up specifically within a GRC or audit process.

Formal definition

In general usage, a follow-up denotes any communication or action taken after an initial interaction to continue a conversation, gather further information, or advance a matter toward resolution. As a matter of terminology, 'follow up' functions as a verb while 'follow-up' functions as a noun or adjective. Note that the supplied evidence addresses the term only in its general and grammatical sense and does not define follow-up as it is used in assurance, audit, or compliance monitoring; practitioners should not treat this entry as a description of formal audit follow-up procedures, which typically involve verifying management's remediation of prior findings and would require sector- or framework-specific sources to define precisely.

Why it matters

In a governance, risk, and compliance context, the concept of following up on previously identified matters is closely associated with the integrity of assurance and remediation processes. However, the evidence available for this entry addresses "follow-up" only in its general and grammatical sense; it does not describe follow-up as a formal step within audit, risk, or compliance monitoring. Readers should therefore treat this entry as a definition of the ordinary term rather than as an authoritative account of audit follow-up procedures.

Because the term is used across many settings, precision in usage carries practical weight. The distinction between "follow up" as a verb and "follow-up" as a noun or adjective can affect clarity in reports, correspondence, and tracking records where the difference between an action and the record of that action matters. Where GRC practitioners intend to describe the formal verification of management's remediation of prior findings, they should rely on sector- or framework-specific sources rather than this general definition, which does not cover such procedures.

Who it's relevant to

Assurance and audit professionals
Internal auditors and other assurance providers frequently need to revisit previously identified issues to check whether agreed actions have been carried out. This entry does not define formal audit follow-up procedures; practitioners should consult framework- or sector-specific sources that address the verification of management remediation.
Compliance and risk practitioners
Those responsible for monitoring adherence to policies and obligations may use follow-up in the general sense of continuing to work toward a result after an initial action. For any formal compliance monitoring process, they should rely on authoritative sources appropriate to their jurisdiction and industry rather than this general definition.
Report writers and communicators
Anyone drafting reports, correspondence, or tracking records benefits from the grammatical distinction the evidence draws: "follow up" as a verb versus "follow-up" as a noun or adjective, with "followup" treated as incorrect in the cited guidance. Consistent usage supports clarity in documentation.

Inside Follow-Up

Tracking of Open Items
A record of previously identified findings, recommendations, or agreed management actions that remain outstanding, typically maintained in a log or tracking register to monitor progress toward closure.
Verification of Remediation
The process of confirming that management has implemented agreed corrective actions and that those actions address the underlying issue, rather than accepting assertions of completion at face value.
Assessment of Effectiveness
An evaluation of whether implemented actions have effectively mitigated the identified risk or control weakness, which may differ from simply confirming an action was taken.
Status Reporting
Communication to relevant stakeholders, such as management, audit committees, or governing bodies, summarizing the status of outstanding items, timeliness of remediation, and any items overdue or accepted as residual risk.
Escalation of Overdue Actions
A defined mechanism for raising unremediated or delayed items to appropriate authority levels when target dates are missed or remediation is inadequate.

Common questions

Answers to the questions practitioners most commonly ask about Follow-Up.

Is follow-up just re-performing the original audit or review?
No. Follow-up is a distinct activity focused on determining whether management has taken adequate and timely action to address previously reported findings or recommendations. It is typically narrower in scope than the original engagement, concentrating on the status of agreed actions rather than re-examining the entire process or control environment. A full re-audit may sometimes be warranted, but follow-up and re-performance are not the same thing.
Does completing follow-up mean the underlying risk has been eliminated?
Not necessarily. Follow-up confirms whether the agreed management actions have been implemented, but implementing a corrective action reduces or treats risk rather than guaranteeing its elimination. Residual risk commonly remains after remediation, and follow-up does not itself certify that the risk has been fully resolved. Assessing whether remaining residual risk is within tolerance is a separate management and assurance consideration.
Who is typically responsible for performing follow-up?
Responsibility varies by function and by how the term is used. In an internal audit context, the internal audit function commonly establishes and maintains a process to monitor the disposition of results, consistent with the objectivity and independence expected of a third line assurance activity. Management, as the first line, remains responsible for implementing the corrective actions themselves. The distinction between verifying action (assurance) and taking action (management) should be kept clear.
How is the timing of follow-up usually determined?
Timing is commonly risk-based and often linked to the agreed remediation dates and the significance of the finding. Higher-risk or higher-severity findings may warrant earlier or more frequent follow-up, while lower-priority items may be monitored on a longer cycle or during the next planned engagement. Specific timeframes vary by organization, policy, and applicable framework, and are typically set out in follow-up procedures rather than fixed universally.
How can follow-up outcomes be tracked and documented?
Follow-up outcomes are commonly recorded in an issue or action tracking mechanism that captures the finding, the agreed action, the owner, the due date, and the current status. Documentation typically supports reporting on whether actions are open, in progress, completed, or overdue, and provides an evidence trail for the disposition of results. This entry does not address specific tooling; the appropriate method depends on organizational needs and existing systems.
What should happen when management has not implemented an agreed action?
When agreed actions are not implemented, the matter is commonly escalated in line with established reporting protocols, which may include informing senior management and, where appropriate, the governing body or audit committee. In some frameworks, where management has accepted a level of risk that may be unacceptable, the assurance function may bring this to the attention of the appropriate governance level. The assurance function generally does not take the action on management's behalf, preserving its independence.

Common misconceptions

Follow-up is complete once management confirms an action has been taken.
Confirmation of completion is not the same as verification. Follow-up commonly involves independent corroboration that the action was implemented and, where relevant, an assessment of whether it effectively addresses the underlying risk.
Follow-up is solely an internal audit or third line responsibility.
Responsibility for remediating issues typically rests with management (the first line), while assurance functions may track and verify closure. Ownership of the corrective action and the follow-up role should be distinguished to preserve the independence and objectivity of assurance functions.
All findings must reach full closure through follow-up.
In some cases management may formally accept residual risk rather than remediate, subject to appropriate governance approval. Follow-up may then involve documenting and reporting that acceptance rather than driving the item to closure.

Best practices

Maintain a centralized tracking register of open findings and agreed actions, including owners, target dates, and current status, to support consistent monitoring.
Verify remediation through appropriate corroboration rather than relying solely on management's assertion that an action is complete.
Distinguish between confirming that an action was implemented and assessing whether it effectively mitigated the underlying risk, and document both where relevant.
Preserve the independence of assurance functions by keeping remediation ownership with management while assurance verifies and reports on closure.
Establish clear escalation paths and reporting to management and, where applicable, the audit committee or governing body for overdue or inadequately remediated items.
Document instances where management formally accepts residual risk in lieu of remediation, ensuring appropriate governance approval is recorded.
Application Security Isn’t Optional Anymore.