Repeat Audit Findings Rate

Goal of the analysis:

The Repeat Audit Findings Rate (RAFR) measures the percentage of audit findings in a period that represent recurrences of previously identified issues. It is a leading indicator of control sustainability, remediation effectiveness, and risk culture. Executives use this metric to assess whether fixes are durable, whether root causes are addressed—not just symptoms—and where governance or accountability gaps persist. A low and declining RAFR, especially for high/critical issues, signals strong first-line ownership and effective second/third-line follow-up; a high or rising RAFR indicates systemic weaknesses, ineffective remediation, or insufficient change management. This analysis informs the audit plan, resource allocation, and escalation decisions to risk committees and the board.

Data required:

  • Audit inventory and scope:
    • List of audits completed by period (quarter/year), auditable entities/processes, risk domain, and scope statements.
    • Audit universe hierarchy (business unit, function, geography, product).
  • Findings and issue data:
    • Issue ID, audit ID, issue title/description, severity/ratings, risk category, control/process IDs, root cause classification, date raised.
    • Flags or links indicating “repeat,” “reopened,” or “related-to” prior issues (if available).
  • Remediation and closure data:
    • Action plans, owners, target dates, actual closure dates, evidence of remediation, QA/validation notes.
    • Post-closure sustainability testing results or follow-up audit outcomes (if conducted).
  • Taxonomy and mapping metadata:
    • Standardized control library and process taxonomy; mapping between issues and controls/processes.
    • Root cause taxonomy (people, process, technology, governance, external).
  • Organizational & reference data:
    • Current and historical org structures, control ownership, product/segment hierarchies.
    • Auditor, auditee, and first-line function names for accountability views.
  • Timeline and cycle context:
    • Audit calendar, audit frequency by entity, cycle times between audits.
    • Periods of major change (system go-lives, M&A, reorganizations) that may affect recurrence.
  • External/regulatory items (where applicable):
    • Regulatory examination findings and any cross-reference to internal audit issues.
    • Policy/standard revisions and effective dates.
  • Historical and benchmark data:
    • At least 8–12 quarters of findings and closures.
    • Internal targets and thresholds approved by the audit committee.

Detailed step-by-step instruction on how to conduct the analysis:

  1. Define scope and period. Select the reporting period (e.g., last 4 quarters) and scope (enterprise-wide or specific business units). Agree the RAFR definition: a “repeat” is a finding that recurs in the same or substantially similar control or process after prior closure or after a previous finding on the same topic.
  2. Extract data from systems. Pull data from your GRC/audit tool (e.g., AuditBoard, TeamMate+, Archer, ServiceNow GRC, MetricStream). Export audit inventories, findings, issue management, and closure details. Include text fields needed for matching.
  3. Standardize taxonomies. Normalize severity levels, risk categories, process/control identifiers, and root causes. Map historical control IDs to current IDs where system changes have occurred.
  4. Establish repeat-matching logic. Use a hierarchy:
    • Primary: Direct link if the system captures “repeat of issue ID.”
    • Secondary: Match on Control_ID + Process_ID + Risk_Category + Entity.
    • Tertiary: Text similarity on titles/descriptions combined with same process/control family and root cause. Flag a confidence score (e.g., high/medium/low) and review samples.
  5. Apply look-back window. Define a look-back (typically 12–24 months after closure). If recurrence occurs before prior issue was closed, classify as “reopened” rather than “repeat” and track separately.
  6. Deduplicate and classify. If multiple audits cite the same repeat in the same period, count once per entity/control. Classify repeats as by severity (critical/high/medium/low) and by confidence level (confirmed vs probable).
  7. Calculate core metrics.
    • RAFR = number of repeat findings in period / total findings in period.
    • Severity-weighted RAFR: assign weights (e.g., Critical=4, High=3, Medium=2, Low=1); compute sum(weighted repeats) / sum(weighted findings).
    • High/Critical RAFR = repeat high/critical findings / total high/critical findings.
    • Time-to-repeat: median months from prior closure to recurrence.
    • Sustainability rate: percent of closed issues that do not repeat within 12 months.
  8. Segment and compare. Produce RAFR by business unit, process, geography, product, control owner, risk domain (e.g., ITGC, access management, vendor risk), and audit team. Separate internal vs regulatory-driven areas if relevant.
  9. Trend analysis. Show quarterly RAFR trends for 8–12 quarters, with bands for high/critical. Overlay major events (system changes, reorganizations) to contextualize inflections.
  10. Root cause and control family analysis. Use Pareto charts to identify the top 5–10 root causes driving repeats and the control families most affected (e.g., change management, access provisioning, reconciliations).
  11. Quality assurance checks. Manually review a sample of “probable repeats” to validate matching logic; refine rules as needed. Ensure that re-opened issues are not double-counted as repeats.
  12. Synthesize insights and priorities. Identify hot spots (units with >2x enterprise RAFR), systemic themes, and areas where severity-weighted RAFR is high. Formulate actions and escalate per governance thresholds.

Format of the output of analysis:

  • Executive summary slide with KPI tiles: RAFR, High/Critical RAFR, Time-to-repeat, Sustainability rate, and quarter-over-quarter trend.
  • Heatmap of RAFR by business unit and risk domain, with severity layers.
  • Pareto charts of repeat findings by root cause and control family.
  • Time-series line charts for overall and severity-weighted RAFR over 8–12 quarters.
  • Cohort chart showing sustainability of fixes by closure quarter (percent repeating within 12 months).
  • Drill-down dashboards (e.g., in Power BI/Tableau) enabling filters by entity, process, geography, and severity.
  • Appendix with methodology, matching logic, and data quality checks.

How to interpret results:

  • Low overall RAFR with low High/Critical RAFR indicates durable remediation and strong ownership; verify that audit depth is adequate to avoid false comfort.
  • High RAFR, especially in High/Critical severity, signals systemic control weaknesses, ineffective root cause remediation, or inadequate closure validation. Immediate governance attention is warranted.
  • Large differences across units suggest inconsistent control maturity or uneven management attention. Persistent hot spots may require centralized standards or targeted interventions.
  • Upward trends following reorganizations or system changes may reflect transition risk; expected temporarily but should normalize within subsequent audit cycles.
  • If overall RAFR is low but sustainability rate is also low, re-open dynamics could be masking repeats; tighten closure criteria and conduct post-closure validation.
  • Benchmark gaps (internal or external) should inform risk appetite discussions and audit plan focus; prioritize areas with high severity-weighted RAFR and short time-to-repeat.

Steps a company can take to improve on this measure:

  • Process and policy changes:
    • Strengthen issue closure criteria to require evidence of sustained operating effectiveness (e.g., two cycles of control performance) for critical/high issues.
    • Mandate root cause analysis using standard methods (5 Whys, fishbone) and independent QA review for repeats.
    • Escalate repeat high/critical issues to risk committee with remediation milestones and executive ownership.
    • Introduce “sustainability checks” 3–6 months post-closure for high-risk areas.
  • Data, systems, and tooling:
    • Enhance GRC linking between issues and control/process libraries; enforce unique control IDs across the enterprise.
    • Implement text analytics to proactively flag potential repeats during fieldwork.
    • Create a KRI dashboard including RAFR, reopen rate, and time-to-repeat, with automated alerts when thresholds are breached.
  • Capability building and governance:
    • Train first line on durable remediation and control design principles; train auditors on root cause and sustainability testing.
    • Tie management performance objectives to timely and sustainable remediation, not just closure speed.
    • Establish a community of practice to share effective fixes for recurring control themes.
  • Targeting and audit plan adjustments:
    • Increase frequency/depth for domains with high severity-weighted RAFR (e.g., privileged access, third-party risk).
    • Use thematic audits on top repeat root causes (e.g., change management) across multiple entities.
    • If RAFR is high but time-to-repeat is long, focus on change management and turnover impacts; if RAFR is high and time-to-repeat is short, scrutinize closure validation and remediation quality.

Benchmark comparisons:

General benchmarks:

  • Overall RAFR: Many mature internal audit functions target low double-digit or better (e.g., roughly 10–15%) with a steady downward trend.
  • High/Critical RAFR: Common targets are very low single digits; any sustained elevation warrants executive attention.
  • Sustainability rate: Aim for the vast majority of closed issues not repeating within 12 months; monitor cohorts by closure quarter.

Segment- or industry-specific benchmarks:

  • Highly regulated sectors (financial services, healthcare) often observe higher RAFR due to stringent standards and change cadence; technology and fast-growth firms may see elevated RAFR during scale-up.
  • Control domains prone to recurrence include access management, vendor/third-party oversight, and change management; set tighter thresholds for these domains.
  • If robust external benchmarks are unavailable, construct internal benchmarks: compare across business units, track top quartile internal performers, and use rolling four-quarter medians to set targets and trigger thresholds.

How to get started

1

arrow-down-blue

Tell us about your project

2

arrow-down-blue

Interview candidates

(We’ll provide bios within 48 hours on average)

3

Select your consultant and start work

Find a Consultant

or email us at: [email protected]