---
id: KB-IC-014
url: https://app.codecontract.io/help/reports-and-quality/when-the-audit-finds-something
idioma: en
categoria: informes-y-calidad
subcategoria: calidad
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-IC-007, KB-IC-009]
citadoPor: [KB-TZ-016, KB-IC-019]
---

# When the audit finds something

_A finding is not a failure. What is: the same finding two years running._

**Responde a:** responding to an audit finding · corrective action plan · audit non-conformity what do i do · closing a finding

The usual reaction to a finding is to fix the specific case and reply that it is corrected. It works for closing the paperwork and guarantees the same thing appears next year, because what was fixed was the symptom.

## The three levels of response

| Level | What is done | What happens next year |
| --- | --- | --- |
| Fix the case | The missing document is sorted | It reappears, with a different document |
| Fix the cause | What made it go missing is changed | It does not return, if that was the cause |
| Check it does not return | Look again after three months | It genuinely closes |

> [!IMPORTANT]
> The third level separates a system that works from one that reacts. A finding closed without later verification is not closed: it is waiting to be rediscovered.

## How to respond well

1. **Accept the finding if it is correct** — Arguing when they are right costs credibility for when they are not.
2. **Look for why it happened, not who did it** — It is nearly always a process asking for something operations could not give.
3. **Set an action with an owner and a date** — An action without a name and a date is an intention.
4. **And verify afterwards, with evidence** — Three months later, looking at data rather than impressions.

> [!WARNING]
> Beware the disproportionate corrective action. Adding three new controls for a minor finding creates a process nobody follows, and next year's finding will be that your invented controls are not followed.

## What to have from last year

**En corto**

- The previous findings and what was done about each.
- Evidence that they were verified.
- And if any repeated, said openly.

An auditor who sees a repeated finding acknowledged and explained judges very differently from one who discovers it themselves by comparing reports.

> [!NOTE]
> The commonest findings on third-party documentation are always the same three: something expired undetected, something approved unchecked, and something that cannot be evidenced even though it was done. All three share a root.

**What if the finding is unfair?**

Answer with evidence, not arguments. With the data, it falls by itself.

**How long is there to respond?**

Whatever the scheme sets; the sensible pattern is immediate action and deferred verification.

**Should minor findings be recorded?**

Yes: they are the ones that repeat and that foreshadow serious ones.

## Ejemplos

**A company closes a finding by uploading the missing document.**

- Looks into why it was missing and finds nobody owned the alert
- Verifies three months later

→ The finding does not repeat the following year, which was the real goal.

**The audit leaves fourteen findings and six months later nine are still open.**

- Records each finding with an owner, an action and a date
- Checks the open ones monthly, not the week before the next audit
- Closes with evidence of what was done, not with a «done»

→ The next audit finds nine fewer findings, and those remaining have dates.

**Every finding is closed the day before the follow-up audit.**

- Spreads the closing dates across the period
- Reviews progress halfway through

→ Closure reflects a real change rather than a three-day sprint.

**A finding is assigned to a department and nobody specific picks it up.**

- Assigns it to a named person
- Checks they have the permissions to close it

→ There is somebody to ask, and somebody who can act.

**The finding is closed and the same problem reappears a year later.**

- Notes the cause as well as the correction
- Checks whether that finding had come up before

→ You tackle what produces it rather than what is visible.

**The auditor asks for evidence of closure and is shown an email.**

- Attaches the evidence of what was done to the finding

→ Closure is demonstrated rather than asserted.

**Minor findings nobody prioritises end up blocking certification.**

- Marks which ones condition the certification

→ Effort goes to what actually blocks.

**A finding you disagree with is accepted anyway.**

- Records the disagreement with its reasoning

→ The position is documented for the next audit.
