top of page
Search

Conflict Resolution for Auditors: Turning Difficult Audit Conversations into Productive Change

Conflict Is an Inherent Part of Auditing

Internal auditors are expected to identify weaknesses, challenge assumptions, evaluate management decisions, and recommend corrective action.


Those responsibilities naturally create tension.


A process owner may disagree with an audit finding. A manager may believe the auditor does not understand operational realities. An executive may resist a recommendation because of cost, timing, staffing, or reputational concerns. An auditor may become frustrated when requested information is delayed, incomplete, or contradictory.


Conflict does not necessarily mean that the audit relationship has failed.


In many cases, conflict is evidence that the audit has reached an issue that matters.


The professional challenge is learning how to manage that conflict without compromising independence, objectivity, or the factual integrity of the audit report.

Corporate Compliance Seminars’ Conflict Resolution for Auditors program is designed to help internal auditors build cooperative relationships, reduce unnecessary resistance, communicate the value of auditing, and resolve disagreements constructively. The four-CPE webinar examines conflict throughout the audit process—from risk assessment and audit planning through fieldwork, reporting, and remediation follow-up.


The objective is not to eliminate every disagreement.


It is to create an environment in which disagreement can be examined professionally, evidence can be evaluated objectively, and the organization can move toward effective corrective action.


Why Conflict Develops During an Audit

Auditors and audit clients frequently approach the same issue from different perspectives.


The auditor may focus on:

  • Risk exposure

  • Control design

  • Operating effectiveness

  • Compliance requirements

  • Supporting evidence

  • Fraud opportunities

  • Governance responsibilities


Management may focus on:

  • Operational demands

  • Budget limitations

  • Staffing shortages

  • Customer expectations

  • Production deadlines

  • System limitations

  • Competing priorities


Neither perspective is automatically unreasonable.


Conflict often arises when one party believes the other has ignored an important part of the situation.


For example, an auditor may recommend separating incompatible duties. Management may agree with the control principle but explain that the department has only two employees.


The auditor sees a segregation-of-duties risk.


Management sees a staffing reality.


A productive resolution requires both parties to move beyond defending their initial positions and examine the underlying interests:

  • What risk must be reduced?

  • What resources are available?

  • What compensating controls are practical?

  • What residual risk will remain?

  • Who has authority to accept that risk?


Conflict resolution allows the audit process to address these questions without turning the disagreement into a personal contest.


Audit Conflict Is Often About More Than the Finding

The stated disagreement may concern the wording of a report, the severity of a risk rating, or the feasibility of a recommendation.


The actual source of the conflict may be something deeper.


Common underlying causes include:

Fear of Blame

Managers may believe the finding will damage their reputation, performance evaluation, or career.

Loss of Control

The client may feel the auditor is imposing changes without understanding the process.

Unclear Expectations

The auditor and client may have different understandings of the audit scope, criteria, or deliverables.

Past Audit Experiences

Prior interactions with Internal Audit may have created distrust or resentment.

Competing Objectives

Management may prioritize speed, customer service, or cost reduction while the auditor emphasizes control discipline.

Communication Style

A technically accurate message may still create resistance when delivered in an accusatory, dismissive, or overly legalistic manner.

Organizational Politics

The disputed issue may involve conflicts between departments, senior executives, or competing strategic priorities.


Effective conflict resolution requires the auditor to determine whether the visible dispute is the real dispute.


Independence Does Not Require Hostility

Some auditors mistakenly believe that maintaining independence requires emotional distance, inflexibility, or an adversarial posture.


It does not.


An auditor can be:

  • Independent without being combative

  • Objective without being indifferent

  • Skeptical without being cynical

  • Firm without being disrespectful

  • Collaborative without surrendering professional judgment


Independence concerns the auditor’s ability to evaluate evidence and reach conclusions without inappropriate influence.


It does not require the auditor to create unnecessary conflict.


In fact, an auditor who communicates poorly may make it more difficult to obtain complete information, understand root causes, and secure meaningful corrective action.


Professional relationships support audit quality when they encourage honest dialogue and do not impair objectivity.


Audits Are Fact-Finding Engagements, Not Personal Investigations

One of the principles emphasized in the CCS course is that audits should be approached as fact-finding events rather than personal investigations. Auditors must remain independent and unbiased, and audit reports must be factual.


That distinction affects how the auditor frames questions.


Compare these approaches:

“Why did you fail to follow the procedure?”

and:

“Help me understand how this transaction was processed and which steps differed from the documented procedure.”

The first question assigns blame before the facts have been fully established.


The second invites explanation while still examining the control deviation using the S.P.I.N. Selling methodology.


Similarly, compare:

“Management ignored the warning signs.”

with:

“The available reports identified the exception, but the current review process did not result in timely follow-up.”

The second statement focuses on the condition, process, and evidence rather than attacking an individual.


Fact-based language does not weaken the finding.


It strengthens credibility.


The Auditor Must Understand Their Own Reaction to Conflict

Conflict resolution begins with self-awareness.


Before approaching the other party, the auditor should ask:

  • What is my initial emotional reaction?

  • Am I frustrated, defensive, embarrassed, or angry?

  • Am I trying to prove that I am right?

  • Am I assigning blame?

  • Am I reacting to this issue—or to a prior dispute?

  • Have I fully considered the client’s perspective?

  • Is my communication style making resolution more difficult?

  • How important is this disagreement in relation to the overall audit objective?


The CCS program encourages auditors to examine what they might have done differently, whether prior issues are fueling the disagreement, and whether their own behavior is blocking resolution.


This does not mean accepting responsibility for another person’s inappropriate behavior.


It means recognizing that the auditor controls only one side of the interaction: their own preparation, language, tone, conduct, and response.


Separate Positions from Interests

A position is what a person says they want.


An interest is why they want it.


Consider this disagreement:

  • Management’s position: “We will not accept a high-risk rating.”

  • Auditor’s position: “The finding must remain high risk.”


A positional argument may continue indefinitely.


The underlying interests may be more useful:

Management may be concerned that:

  • The rating will be reported to the board.

  • The issue will affect executive compensation.

  • The wording suggests negligence.

  • The required remediation is too expensive.

  • The rating criteria were not explained.


The auditor may be concerned that:

  • The exposure is material.

  • The issue affects regulatory compliance.

  • Similar failures have occurred previously.

  • Management has underestimated the likelihood.

  • A lower rating would mislead the Audit Committee.


Once the interests are understood, the parties can examine:

  • The evidence supporting likelihood and impact

  • The organization’s approved risk-rating methodology

  • Whether wording can be made more precise

  • Whether the recommendation can be phased

  • Whether interim controls can reduce exposure

  • What information the Audit Committee needs


The final risk rating should follow the facts and methodology—not a negotiated compromise—but understanding the interests can reduce unnecessary conflict around that conclusion.


Listen to Understand, Not Merely to Respond

Auditors are trained to ask questions.


They are not always trained to listen.


During conflict, people often listen only long enough to prepare a rebuttal.


Active listening requires the auditor to:

  • Allow the client to complete the explanation.

  • Avoid interrupting.

  • Ask clarifying questions.

  • Restate the client’s position accurately.

  • Distinguish facts from assumptions.

  • Identify areas of agreement.

  • Confirm disputed points.

  • Request evidence where needed.


A useful response is:

“Let me confirm that I understand your concern. You agree that the control was not performed, but you disagree with our conclusion because the transaction was reviewed through a separate process. Is that correct?”

This demonstrates that the auditor has heard the client without agreeing prematurely.


It also narrows the disagreement to a testable question: Did the separate review function as an effective compensating control?


Focus on the Issue, Not the Person

Personal language escalates conflict.


Process language supports analysis.


Instead of:

  • “You failed to monitor the account.”

  • “Your team ignored the policy.”

  • “Management does not take this seriously.”

  • “The department was careless.”


Use clear state the "Facts" language such as:

  • “The account was not reviewed during the period tested.”

  • “The documented procedure was not consistently performed.”

  • “The current monitoring process did not identify the exception.”

  • “Responsibility for follow-up was not clearly assigned.”


The issue remains serious.


The difference is that the wording describes an observable condition rather than making a judgment about someone’s character or motivation.


Use Evidence as the Common Reference Point

Conflict becomes harder to resolve when each side argues from memory, opinion, or perception.


The auditor should return the conversation to evidence.


Relevant evidence may include:

  • Policies and procedures

  • Transaction records

  • System logs

  • Approval histories

  • Reconciliations

  • Meeting minutes

  • Emails

  • Interviews

  • Regulatory criteria

  • Risk assessments

  • Prior audit reports

  • Data-analysis results


A disciplined discussion might follow this sequence:

  1. Confirm the agreed-upon criteria.

  2. Describe the condition identified.

  3. Present the supporting evidence.

  4. Invite management to provide additional evidence.

  5. Evaluate whether the new information changes the conclusion.

  6. Document the final determination.


An auditor should be willing to revise a finding when management provides credible evidence.


That willingness does not weaken Internal Audit.


It demonstrates objectivity.


Conflict During Audit Planning

Conflict does not begin only when findings are reported.


It may begin during annual planning.


Management may question:

  • Why a particular area was selected

  • Why the audit is scheduled now

  • Whether the scope is too broad

  • Whether Internal Audit understands current risks

  • Whether the engagement duplicates another review

  • Whether the department has resources to support the audit


The CCS course includes Internal Audit’s involvement in management’s risk assessment and the joint development of an agile audit plan.


Collaboration during planning can reduce later conflict.


Internal Audit can:

  • Explain the risk-based planning methodology.

  • Ask management about emerging risks.

  • Identify recent organizational changes.

  • Consider regulatory and strategic priorities.

  • Clarify the purpose and expected value of the engagement.

  • Explain what is inside and outside the scope.

  • Coordinate with other assurance functions.

  • Discuss timing and resource constraints.


Management should have meaningful input into the risk discussion.


Internal Audit must retain authority over the independent audit plan.


Collaboration informs the plan; it does not surrender control over it.


Conflict During Audit Fieldwork

Fieldwork frequently creates tension because auditors request records, interview employees, test transactions, and question established practices.


Common sources of conflict include:

  • Delayed documentation

  • Repeated requests

  • Unclear request lists

  • Disagreement over sample selection

  • Employee concern about being blamed

  • Operational disruption

  • Auditor misunderstanding of the process

  • Scope expansion

  • Incomplete or inconsistent answers


Auditors can reduce avoidable conflict by:

  • Providing organized request lists

  • Explaining why information is needed

  • Coordinating reasonable deadlines

  • Avoiding duplicative requests

  • Identifying a primary client contact

  • Communicating scope changes promptly

  • Discussing potential issues as they emerge

  • Respecting operational demands

  • Maintaining an issues log


The CCS program specifically addresses encouraging auditee cooperation during fieldwork and helping Internal Audit “do more with less.”


Cooperation is more likely when clients understand the purpose of the request and believe the process is being managed competently.


Conflict Over Audit Findings

Findings become contentious when management disputes one or more of the following:

  • The factual condition

  • The applicable criterion

  • The root cause

  • The risk or effect

  • The severity rating

  • The recommendation

  • The responsible owner

  • The implementation date


The auditor should separate these components rather than treating the finding as one indivisible argument.


Management may agree that the condition exists but disagree with the cause.


It may accept the risk but reject the recommendation.


It may accept the recommendation but need a different completion date.


A structured resolution meeting should address each element independently.


Condition

What happened, and what evidence supports it?

Criteria

What policy, standard, regulation, contract, or control expectation applies?

Cause

Why did the condition occur?

Consequence

What actual or potential impact results?

Management Action Plan

What will management do, who is responsible, and when will it be completed?


This structure keeps the discussion focused and prevents disagreement over one element from obscuring agreement on the others.


Recommendations Should Address Risk, Not Dictate Operations

Conflict frequently arises when audit recommendations are overly prescriptive. This is the central reason the Auditor should not make recommendations but work with the client to come up with an effective Management Action Plan.

For example:

“Management must purchase and implement a new automated reconciliation system.”

The auditor may have identified a valid control problem, but management is ordinarily responsible for choosing the operational solution.


A more appropriate appproach may be:

“Asking Management to consider how they could implement a sustainable process that ensures all accounts are reconciled, independently reviewed, and resolved within established timeframes.”

Management can then determine whether the solution involves:

  • Automation

  • Additional staffing

  • Process redesign

  • Reassignment of duties

  • Exception reporting

  • Outsourcing

  • Compensating controls


Internal Audit should define the control objective and risk to be addressed.


Management should own the corrective action unless a specific solution is required by law, regulation, or policy.


This distinction reduces conflict while preserving accountability.


Promoting Transparency in Audit Reporting

The CCS course includes a section devoted to transparency in audit reporting. It emphasizes factual, unbiased reports and constructive responses to criticism.


Transparent reporting means:

  • Findings are supported by evidence.

  • Criteria are clearly identified.

  • Management’s perspective is fairly represented.

  • Risk is explained without exaggeration.

  • Positive practices may be acknowledged where relevant.

  • Unresolved disagreements are disclosed appropriately.

  • Recommendations are practical and linked to root cause.

  • The report does not conceal important matters to avoid discomfort.


Transparency also means avoiding surprises.


Significant concerns should ordinarily be discussed with management before the final report is issued.


A client should not first learn of a major finding while sitting before the Audit Committee.


Early communication allows time to:

  • Correct factual errors

  • Obtain missing evidence

  • Clarify misunderstandings

  • Evaluate compensating controls

  • Discuss root cause

  • Develop corrective action


The conclusion may remain unchanged, but the quality of the discussion usually improves.


What to Do When Agreement Cannot Be Reached

Conflict resolution does not guarantee consensus.


There will be situations in which the auditor and management continue to disagree.


When that occurs, the auditor should:

  1. Confirm that all relevant evidence has been considered.

  2. Restate the disputed issue precisely.

  3. Apply the approved criteria and risk methodology.

  4. Document management’s position.

  5. Document Internal Audit’s conclusion.

  6. Escalate the matter through the established governance process.

  7. Ensure the Audit Committee receives the information necessary for oversight.


The objective is not to force artificial agreement.


It is to ensure that the disagreement is handled transparently, professionally, and at the appropriate level of authority.


Management may accept a risk.


Internal Audit should not accept the risk on management’s behalf.


Conflict During Remediation Follow-Up

Corrective-action follow-up can create its own disputes.


Management may report a finding as closed while Internal Audit concludes that:

  • The action was only partially implemented.

  • The revised control has not operated long enough.

  • Supporting evidence is insufficient.

  • The action does not address the root cause.

  • The risk remains above tolerance.

  • The issue has been transferred rather than resolved.


The CCS program includes coordination of control-remediation follow-up as a distinct part of conflict resolution.


Clear closure criteria should be established when the action plan is approved.


Those criteria may include:

  • Required documentation

  • Responsible owner

  • Target date

  • Expected control design

  • Period of operation

  • Validation testing

  • Residual-risk acceptance


When expectations are defined early, closure decisions are less likely to become personal disputes.


How to Create a Win-Win Audit Resolution

A win-win outcome does not mean everyone gets everything they initially wanted.


It means the resolution protects the organization’s interests while respecting the legitimate concerns of the parties.


A constructive outcome may include:

  • The risk is accurately communicated.

  • Management’s operational constraints are recognized.

  • The finding is factually correct.

  • The recommendation allows implementation flexibility.

  • Interim controls reduce exposure.

  • Responsibilities are clearly assigned.

  • The Audit Committee receives transparent information.

  • The relationship remains professional.

  • Corrective action is more likely to succeed.


The CCS course asks auditors to consider how a conflict can be resolved in a manner that creates a win-win result.


The “win” for Internal Audit is not proving management wrong.


The win is helping the organization understand and manage risk more effectively.


Building a Coalition for Change

Many audit recommendations require support beyond the process owner.


A sustainable change may require participation from:

  • Executive management

  • Finance

  • Information technology

  • Human resources

  • Legal

  • Compliance

  • Risk management

  • Operations

  • The Audit Committee


The CCS course stresses the importance of having a powerful coalition for change within management.


An auditor should identify:

  • Who understands the risk?

  • Who has authority to act?

  • Who controls the necessary resources?

  • Who may resist the change?

  • Who will benefit from the improvement?

  • Who must sustain the control after implementation?


Internal Audit should not become the owner of remediation.


It can help create awareness, facilitate communication, and ensure governance bodies understand the issue.


Selling the Value of Internal Auditing

The phrase “selling the value of Internal Audit” does not mean compromising conclusions to please the client.


It means clearly explaining how audit work supports organizational objectives.


Internal Audit creates value when it helps the organization:

  • Protect assets

  • Improve reliable reporting

  • Strengthen compliance

  • Reduce fraud exposure

  • Improve process efficiency

  • Clarify accountability

  • Anticipate emerging risks

  • Improve governance

  • Sustain corrective action


The CCS program was developed in part to help auditors communicate the value of audit services, increase awareness of the Internal Audit program, and build stronger relationships with audit clients.


Clients are more likely to cooperate when they understand that the audit is intended to improve the organization—not merely document deficiencies.


Practical Language for Difficult Audit Conversations

When the Client Disagrees with a Fact

“Let us review the evidence together and identify exactly where our understanding differs.”

When the Client Becomes Defensive

“My objective is to understand the process accurately. I am not assigning personal blame.”

When Management Minimizes the Risk

“What evidence supports the conclusion that the exposure is unlikely or immaterial?”

When the Recommendation Is Considered Impractical

“What alternative action would achieve the same control objective?”

When Documentation Is Missing

“What evidence would ordinarily demonstrate that this control was performed?”

When the Discussion Becomes Personal

“Let us return to the process, the applicable criteria, and the evidence.”

When the Parties Remain Deadlocked

“We may not reach agreement today. Let us document the points of agreement, the unresolved issue, and the additional information needed.”

These statements keep the discussion professional without avoiding difficult subjects.


Conflict Resolution Skills Every Auditor Should Develop

Effective auditors need more than technical knowledge.


They also need the ability to:

  • Listen actively

  • Ask neutral questions

  • Manage emotional reactions

  • Explain risk clearly

  • Distinguish facts from assumptions

  • Provide and receive criticism

  • Negotiate implementation details

  • Facilitate difficult meetings

  • Recognize organizational politics

  • Escalate disputes appropriately

  • Preserve relationships without compromising independence


These are not optional “people skills.”


They affect the auditor’s ability to obtain evidence, understand root causes, communicate findings, and achieve corrective action.


Who Should Attend Conflict Resolution for Auditors?

The course is designed for professionals who must manage difficult discussions and promote cooperation, including:

  • Internal auditors

  • Chief Audit Executives

  • Audit managers

  • Audit supervisors

  • Risk management professionals

  • Compliance officers

  • Internal control professionals

  • Audit team leaders

  • Professionals responsible for remediation follow-up


The program is suitable for participants at a basic level and requires no prerequisites or advance preparation. It is delivered as a Group Internet-Based seminar and provides four CPE credits in Auditing and Personal Development.


What Participants Will Learn

The program addresses methods to improve Internal Audit relationships by helping participants:

  • Communicate the value of Internal Auditing

  • Increase awareness of the audit function

  • Assist management’s risk-identification process

  • Participate appropriately in agile audit planning

  • Encourage cooperation during fieldwork

  • Promote transparency in audit reporting

  • Coordinate follow-up of control remediation

  • Approach conflict constructively

  • Examine personal reactions that may impede resolution

  • Develop win-win approaches without sacrificing objectivity


The course is based on practical audit experience and uses real-world concepts to help participants apply conflict-resolution techniques throughout the engagement lifecycle.


Conflict Can Strengthen an Audit

Poorly managed conflict can delay an engagement, damage relationships, and prevent meaningful corrective action.


Properly managed conflict can produce:

  • Better evidence

  • More precise findings

  • Stronger recommendations

  • Greater management ownership

  • More transparent reporting

  • More sustainable remediation

  • Increased respect for Internal Audit


Auditors should not avoid conflict simply to preserve harmony.


Nor should they create conflict to demonstrate toughness or independence.


The professional objective is to address difficult issues directly, fairly, and constructively.


A successful audit does more than identify what is wrong.


It creates the conditions in which people can understand the risk, accept responsibility, and improve the organization.


That requires technical competence.


It also requires conflict-resolution skill.


Corporate Compliance Seminars’ Conflict Resolution for Auditors webinar provides practical guidance for auditors who must navigate resistance, difficult personalities, disputed findings, challenging report discussions, and remediation disagreements.

Participants earn four NASBA-approved CPE credits while learning how to maintain objectivity, communicate audit value, promote cooperation, develop factual reports, and turn disagreement into productive organizational change.


Conflict is inevitable in auditing.


Destructive conflict is not.


Frequently Asked Questions

Why is conflict resolution important for auditors?

Auditors routinely challenge established practices, identify weaknesses, and recommend change. Conflict-resolution skills help them discuss those matters constructively while maintaining independence, objectivity, and professional relationships.


Does collaboration impair auditor independence?

No. Collaboration can improve understanding and corrective action as long as the auditor retains responsibility for independent evaluation, conclusions, and reporting.


What are common sources of conflict during an audit?

Common sources include disputed facts, risk ratings, impractical recommendations, delayed documentation, unclear expectations, scope changes, prior negative experiences, and fear of blame.


How should an auditor respond when management disagrees with a finding?

The auditor should separate the finding into condition, criteria, cause, consequence, and recommendation; review the evidence; consider management’s additional information; document unresolved disagreements; and escalate significant matters through the appropriate governance process.


Should auditors change a finding to preserve the client relationship?

Auditors should correct findings when new evidence warrants a change. They should not remove or minimize a supported finding merely to avoid conflict.


How can auditors make recommendations less confrontational?

Recommendations should focus on the control objective and risk rather than prescribing unnecessary operational details. Management can then develop a practical action plan that achieves the required result.


How many CPE credits does the course provide?

The live Group Internet-Based course provides four CPE credits in Auditing and Personal Development.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page