A
AcadiFi
CC
CIA_Candidate2026-05-20
ciapart-2fraudescalationgovernance

What should internal audit do when management knows about a control failure and does nothing?

35 upvotes
AcadiFi TeamVerified Expert
AcadiFi Certified Professional

Internal audit should document the issue, preserve the supporting evidence, and escalate according to the severity of the risk. If the breakdown affects financial-reporting reliability, involves repeated tolerance, or implicates senior management, the CAE may need to raise it to the audit committee or equivalent governance body.

The key is not to substitute internal audit for management. Internal audit can recommend corrective actions and verify remediation later, but management remains responsible for fixing the control environment.

🔍

Master part-2 with our CIA Course

45 lessons · 90+ hours· Expert instruction