Every audit ends the same way: a list of exceptions, a management response written under deadline, and a board slide that says "remediation in progress." Twelve months later a third of the findings reappear. The problem is rarely effort. It is that findings are treated as items to close rather than as evidence about how the control environment is designed. Here is the method we use to turn SOC 2 and SOX findings into a roadmap executives will fund and auditors will accept.

Separate the finding from the failure

A finding is an observation: "3 of 25 sampled terminated users retained active access beyond 24 hours." The failure is the reason it happened: HR notifications reach IT by email, the mailbox is monitored by one person, and there is no reconciliation between the HR system and the directory. Fix the finding and it returns next year. Fix the failure and it does not. For every exception, write a one-line root cause using a simple taxonomy — design (the control could not have caught it), operation (the control exists but was not performed), evidence (it was performed but cannot be proven), or scope (the population was wrong). The taxonomy tells you which kind of fix to fund.

Rate by consequence, not by count

Auditors report findings by control; boards need them by consequence. Re-rate each finding on two axes: the impact if the underlying risk materializes (financial misstatement, customer data exposure, contract breach, regulatory penalty) and the likelihood given the current state. A single unremediated privileged-access finding on the ERP that feeds financial reporting outranks a dozen documentation gaps. Present the result as a heat map with no more than three tiers. Executives fund what they can see.

Cluster into initiatives

Findings cluster. Access-review exceptions, terminated-user exceptions, and privileged-account exceptions are one initiative — identity governance — not three projects. Change-management exceptions across three systems are one initiative with a common approval workflow. Clustering typically turns 30 to 40 findings into six to eight initiatives, each with a business owner, an IT owner, a target control state, and a completion date. This is also the moment to check for framework leverage: the identity initiative that closes SOX findings usually closes SOC 2 CC6 findings and ISO 27001 A.5.15–A.5.18 gaps at the same time. Say so on the slide; it changes the funding conversation.

Define "done" as evidence, not activity

A remediation plan that says "implement quarterly access reviews" is not finished when the first review runs. It is finished when the review has run for a full period, the evidence exists in the form the auditor will test, and a sample has been pulled internally to confirm it holds up. Write the acceptance criterion for every initiative as the artifact that will exist and the test it will pass. Then schedule the internal re-test before the external auditor returns. Findings that are closed on paper but reopened in fieldwork are the most damaging outcome for a control owner's credibility.

Sequence for the audit calendar

Operating-effectiveness testing needs a period. If your SOC 2 Type 2 window opens in January and a control is redesigned in November, the auditor needs to see it operate across the window. Work backward from the audit calendar: design changes land at least a quarter before the observation period; evidence-only fixes can land later; scope corrections must be agreed with the auditor in advance. Put the sequence on one timeline the audit committee can read at a glance.

Report progress in the auditor's language

Monthly status should show, per initiative, the control state (designed / operating / evidenced), the re-test result, and the date the external auditor will next look. Avoid percentage-complete metrics; they hide the fact that the last ten percent — evidence and re-test — is where findings are actually closed. When a remediation slips, say which finding will likely repeat and what the management response will be. Boards tolerate slippage; they do not tolerate surprise.

The roadmap as a governance artifact

Done well, the roadmap stops being a remediation tracker and becomes the control-improvement plan for the year: owned by management, reviewed quarterly, reconciled to the risk register, and cited in the next management assertion. That is what the audit committee is actually asking for when it asks "are we going to have findings again next year?" The honest answer is yes, some — but not the same ones.

References

  • American Institute of Certified Public Accountants. (2017; 2022 revision). Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy.
  • Committee of Sponsoring Organizations of the Treadway Commission. (2013). Internal Control — Integrated Framework.
  • Public Company Accounting Oversight Board. (2007). Auditing Standard No. 5 (now AS 2201): An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements.
  • ISACA. (2018). COBIT 2019 Framework: Governance and Management Objectives.
Next step

Walk in prepared. Walk out with findings that hold up.

Audit readiness services
Anthony Adeoti is Principal Consultant at StrongTower InfoTech & Cybersecurity Consultancy (STICC). He holds the CISA, CISM, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 Lead Auditor credentials and is a CMMC Certified Professional (CCP) candidate, with 10+ years across GRC, IT audit, IAM and AI governance in financial services, government and defense. About Anthony →