top of page
Search

Defensiveness and Ego: When an Audit Finding Becomes Personal

“You’re Criticizing Me.”


Internal auditors believe they are auditing processes, risks, and controls.

The people being audited do not always see it that way.


An auditor says:

“We identified a weakness in the approval process.”

The process owner may hear:

“You don't know how to manage your department.”

The auditor says:

“The control was not operating effectively.”

The manager may hear:

“You failed.”

The auditor says:

“Management should strengthen monitoring.”

The executive may hear:

“You're telling me how to run my business.”

Once that happens, the audit conversation can change dramatically.


The discussion stops being about risk and internal control and becomes about identity, competence, authority, reputation, and ego.


That is the third major human behavior problem internal auditors need to understand:

Defensiveness and Ego — “You're criticizing me.”

The skilled internal auditor must learn how to separate the person, the process, and the control deficiency without weakening legitimate audit conclusions.


Internal Auditors Audit Processes—People Experience the Audit Personally

Consider a manager who has run Accounts Payable for 15 years.

  • She built the department.

  • She hired many of the employees.

  • She helped design the procedures.

  • She selected portions of the technology.

  • She trained the supervisors.

  • She believes the department performs well.


Then Internal Audit arrives.


After several weeks of fieldwork, the auditor reports:

“Controls over vendor master-file changes are inadequately designed.”

To the auditor, that is a technical conclusion.


To the manager, it may sound like:

“Something you built is inadequate.”

That difference matters.


The process may have become part of the manager's professional identity.


Criticizing the process can therefore feel like criticizing the person.


Internal auditors need to recognize that reaction without allowing it to interfere with the audit.


Defensiveness Is a Normal Human Reaction

When people perceive a threat to their competence, status, reputation, or authority, defensive behavior is predictable.


The reaction may appear as:

  • Arguing

  • Interrupting

  • Blaming others

  • Challenging the auditor's competence

  • Attacking the sample

  • Questioning the methodology

  • Minimizing the finding

  • Withholding cooperation

  • Escalating the disagreement

  • Attempting to rewrite the report


Some managers become angry.


Others become highly technical.


Still others become passive:

“Fine. Write whatever you want.”

That is defensiveness too.


The auditor's responsibility is not to diagnose the individual's personality.


It is to recognize when defensiveness is interfering with a productive discussion of the audit evidence.


The Audit Finding May Threaten More Than Pride

It is easy to dismiss defensiveness as ego.


That can be a mistake.


An audit finding may have real consequences for the process owner.


A significant finding could affect:

  • Performance evaluations

  • Bonuses

  • Promotion opportunities

  • Departmental budgets

  • Executive reputation

  • Regulatory scrutiny

  • Audit Committee attention

  • Employment


Suppose an Audit Committee receives a report stating that management failed to adequately control a significant cybersecurity risk.


The responsible executive may immediately recognize that the finding could affect how the CEO and Board view that executive's performance.


Now the audit finding is not merely technical.


There are personal consequences.


That does not mean Internal Audit should soften the finding.


It means the auditor should understand the environment in which the discussion is occurring.


Do Not Make the Audit About Winning

A dangerous moment occurs when management challenges the auditor personally.


Management says:

“You don't understand this process.”

The inexperienced auditor may immediately think:

“I'm going to prove that I do.”

Now both parties have something to defend.


Management is defending the process.


The auditor is defending the audit.


The conversation becomes:


Ego versus ego.


That is rarely productive.


The objective of Internal Audit is not:

Prove that the auditor is right.

The objective is:

Determine what happened, why it happened, what risk exists, and what should change.

That distinction is fundamental to good audit communication.


Separate the Person From the Process

A useful principle for auditors is:

Good people can operate bad processes.

A highly competent manager can inherit:

  • A poorly designed system

  • An outdated policy

  • Inadequate staffing

  • Weak segregation of duties

  • Manual processes

  • Legacy technology

  • Conflicting responsibilities


The control deficiency does not necessarily mean the manager is incompetent.


That gives the auditor a better way to frame the discussion.


Instead of:

“You aren't adequately reviewing vendor changes.”

consider:

“The current process does not consistently provide evidence of an independent review before vendor banking changes become effective.”

The second statement focuses on the process and control.


It is also more auditable.


Separate the Person, Process, and Control

Internal auditors should consciously distinguish among three things.


The Person

Who performs or manages the activity?

The Process

How is the business objective accomplished?

The Control

What prevents, detects, or corrects the identified risk?


Suppose a payroll manager personally reviews every payroll adjustment.


The auditor discovers that there is no evidence documenting those reviews.


Do not jump directly to:

“The payroll manager isn't reviewing adjustments.”

The manager may be reviewing every one.


The actual issue may be:

The organization cannot demonstrate that the control occurred.

That is different.


Precision reduces unnecessary conflict.


Start With Facts, Not Conclusions

Suppose Internal Audit tests 50 purchase orders and identifies eight without the required evidence of approval.


A confrontational approach would be:

“Your purchasing controls are ineffective.”

Management may immediately become defensive.


A better approach begins with the condition:

“Eight of the 50 purchase orders we tested did not contain evidence of the approval required by policy.”

Then ask:

“Can we walk through these eight transactions together?”

Now the conversation begins with evidence.


Perhaps management identifies:

  • Approval stored elsewhere

  • A system issue

  • An emergency exception

  • A misunderstanding of policy

  • Actual control failures


The auditor learns something either way.


Use the Five Elements of an Audit Finding

A structured finding helps remove personality from the discussion.

Condition

What did Internal Audit find?

Criteria

What should have happened?

Cause

Why did the difference occur?

Consequence

Why does it matter?

Corrective Action

What should change?


This structure forces the auditor to move beyond:

“Management did something wrong.”

Instead, the discussion becomes:

Here is what happened.
Here is what should have happened.
Here is why the difference occurred.
Here is the resulting risk.
Here is what could improve the process.

That is a professional audit discussion.


Ask Management to Challenge the Facts


When defensiveness begins, one of the most useful questions an auditor can ask is:

“Which fact do we have wrong?”

This changes the conversation.


If the auditor has something wrong, management should be able to identify it.


Perhaps:

  • The population is incomplete.

  • The auditor misunderstood the workflow.

  • A compensating control exists.

  • Documentation was stored somewhere else.

  • The policy cited is obsolete.

  • The system behaves differently than the auditor believed.


Good.


Correct the finding.


Internal Audit should never defend an incorrect finding merely because changing it feels like losing.


But if management cannot identify an incorrect fact, the discussion should return to the evidence.


Management Disagreement Can Improve the Audit

Auditors should not fear disagreement.


A strong challenge can make the audit better.


Management may force the audit team to reconsider:

  • Scope

  • Sampling

  • Criteria

  • Evidence

  • Root cause

  • Risk

  • Wording

  • Recommendations


That is healthy.


Professional skepticism should apply to the auditor's own conclusions.


The question is not:

“Did management agree?”

The question is:

“After considering all available evidence, is our conclusion still supportable?”

If yes, maintain it.


If no, change it.


That is objectivity.


Do Not Use Audit Language as a Weapon

Words matter.


Compare:

“Management failed to properly supervise employees.”

with:

“The current supervisory review did not consistently detect transactions processed without the required authorization.”

The second statement may actually be stronger because it identifies the control problem.


Auditors should be especially careful with words such as:

  • Failed

  • Neglected

  • Ignored

  • Refused

  • Incompetent

  • Reckless

  • Mismanaged


Sometimes those words are justified.


If management knowingly ignored repeated warnings, “ignored” may be exactly the right word.


But use such language because the evidence supports it, not because the auditor is frustrated.


An audit report is not the place to settle an argument.


S.P.I.N. Questioning Can Reduce Defensiveness

The S.P.I.N. questioning methodology can help auditors explore problems without immediately putting the process owner on the defensive.


S.P.I.N. stands for:

  • Situation

  • Problem

  • Implication

  • Need-Payoff


Situation

Understand the process.

“Walk me through how purchase requests are approved.”

Problem

Explore difficulties.

“What happens when the designated approver is unavailable?”

Implication

Connect the weakness to risk.

“If employees can process the purchase before approval, what prevents an unauthorized purchase from occurring?”

Need-Payoff

Explore improvement.

“Would delegated approval authority within the system allow the department to maintain workflow without bypassing the control?”

Notice what happened.


The auditor did not begin with:

“Your approval process is inadequate.”

Instead, the questions allowed management to participate in identifying the weakness and possible solution. Management owns the internal controls!!


That can substantially reduce defensiveness.


Walkthroughs Are Where Relationship Skills Matter

A walkthrough should not feel like an interrogation.


The auditor needs information.


The process owner has it.


That relationship matters.


Consider two questions.


Question One

“Why didn't you follow the policy?”

That immediately sounds accusatory.


Question Two

“Walk me through what happens when the normal approval process cannot be completed.”

The second question is likely to produce much more useful information.


Auditors should remember:

The objective of an interview is to obtain information, not demonstrate superiority.

Do Not Embarrass the Process Owner

Auditors sometimes unnecessarily create resistance by identifying problems in front of the wrong audience.


Imagine discovering an exception during a walkthrough attended by:

  • The employee

  • The employee's supervisor

  • The department manager

  • The CFO


The auditor says:

“So you're telling us you don't actually perform the required control?”

That may be technically accurate.


It may also be a terrible interviewing technique.


The employee now has an immediate reason to defend themselves.


A better auditor recognizes when a sensitive issue should be explored privately.


People who feel humiliated rarely become more cooperative.


Ego Exists on Both Sides of the Table

This is critical.


Internal auditors have egos too.


Auditors can become emotionally attached to findings.


They spent three weeks developing them.


They discussed them with the Audit Manager.


They drafted the report.


They may begin thinking:

“This is my finding.”

That is dangerous.


It is not your finding.


It is a professional conclusion based on evidence.


If new evidence changes the conclusion, change it.


Auditor ego can appear when we say:

“Management is just being defensive.”

Sometimes management is being defensive.


Sometimes management is right.


The auditor must be willing to distinguish between the two.


Confirmation Bias Can Make the Problem Worse

Once auditors develop a theory, they may unconsciously seek evidence supporting it.


Suppose the auditor concludes early in fieldwork:

“This department has weak management.”

Now every exception may reinforce that belief.


Positive evidence may receive less attention.


That is confirmation bias.


The process owner may be doing exactly the same thing:

“Internal Audit doesn't understand our business.”

Now every auditor question becomes proof of that belief.


Both parties can become trapped.


The solution is evidence.


Ask:

What evidence would cause me to change my conclusion?

That is a powerful professional-skepticism question.


AI Can Help Auditors Challenge Their Own Ego

Artificial intelligence can be useful here.


Using an organization's approved AI environment and appropriately protected information, the audit team can ask:

“Act as the process owner and develop the strongest arguments against this finding.”

Or:

“Identify statements in this finding that sound accusatory rather than objective.”

Or:

“Separate the factual condition from conclusions or assumptions.”

Or:

“What additional evidence would be required to support this conclusion?”

Or:

“Rewrite this finding so it focuses on the control deficiency rather than the individuals involved, without reducing the seriousness of the risk.”

That is an excellent use of AI.


Do not merely ask AI to make the report sound impressive.


Use AI to challenge the auditor's reasoning and communication.


Defensiveness Can Reveal Organizational Culture

One defensive manager does not necessarily indicate a cultural problem.


But repeated patterns deserve attention.


Suppose management routinely:

  • Attacks auditors

  • Disputes minor wording

  • Minimizes findings

  • Discourages employees from speaking freely

  • Demands names of employees who provided information

  • Delays evidence

  • Escalates routine disagreements

  • Pressures Internal Audit to reduce ratings


That may tell the Chief Audit Executive something important about the control environment.


Ask:

How does this organization respond to bad news?

Healthy organizations may disagree vigorously with auditors.


But they ultimately want accurate information.


Unhealthy organizations may treat the messenger as the problem.


Watch What Happens to Employees Who Tell Internal Audit the Truth

This is particularly important.


Suppose an employee tells Internal Audit:

“We routinely bypass this control because our manager tells us to.”

Later, management demands:

“Who told you that?”

The auditor now needs to think carefully.


How management responds to people who raise concerns can reveal a great deal about:

  • Tone at the top

  • Psychological safety

  • Ethics

  • Whistleblower culture

  • Management override

  • Control environment


Internal Audit should not casually expose sources simply to make a finding easier to defend.


When Does Defensiveness Become a Governance Issue?

Not every disagreement belongs before the Audit Committee.


But significant unresolved disagreement may require escalation when it involves:

  • Material financial exposure

  • Fraud

  • Cybersecurity

  • Regulatory compliance

  • Management override

  • Significant control deficiencies

  • Repeated findings

  • Risk acceptance beyond management's authority

  • Interference with Internal Audit


At that point, the issue is no longer:

“Management doesn't like our finding.”

The issue becomes:

“Is governance receiving an accurate picture of organizational risk?”

That is exactly where an independent Internal Audit function becomes important.


Do Not Confuse Diplomacy With Weakness

Auditors sometimes believe they face a choice:

Maintain the relationship

or

Tell the truth.


That is a false choice.


A skilled auditor should be able to do both.


Professional diplomacy means:

  • Listening

  • Being precise

  • Avoiding unnecessary accusations

  • Considering contrary evidence

  • Explaining risk clearly

  • Treating people respectfully


It does not mean:

  • Removing valid findings

  • Understating risk

  • Changing ratings to avoid conflict

  • Accepting unsupported explanations

  • Allowing management to control the audit conclusion


You can be respectful and firm simultaneously.


A Practical Method for Handling Defensive Management

When a process owner becomes defensive, try this sequence:

  1. Do not become defensive yourself. Keep your emotional reaction out of the audit.

  2. Return to the facts. Identify precisely what the evidence demonstrates.

  3. Ask what the auditor may have misunderstood. Give management a legitimate opportunity to challenge the conclusion.

  4. Separate the person from the process. Focus on how the control operates, not on someone's character.

  5. Separate condition from consequence. Establish what happened before debating how serious it is.

  6. Ask S.P.I.N.-style questions. Help management work through the problem and implications.

  7. Look for compensating controls. Management may know something the audit team does not.

  8. Identify the root cause. Do not stop at the individual who performed the transaction.

  9. Document significant disagreement. Do not make an issue disappear simply because the conversation became uncomfortable.

  10. Escalate significant unresolved risk appropriately. Governance needs to understand important risks even when management disagrees.


The Auditor Does Not Need an Admission of Guilt

This may be the most important point.


The objective of an audit meeting is not to get the process owner to say:

“You were right. I was wrong.”

That may never happen.


And it does not need to.


The auditor needs to determine:

  • What happened?

  • What should have happened?

  • Why was there a difference?

  • What risk resulted?

  • What should change?


Management may disagree with Internal Audit while still agreeing to corrective action.


That can be a successful outcome.


From Confrontation to Collaboration

The best internal auditors learn how to change the conversation.


Instead of:

“We're here to tell you what's wrong.”

move toward:

“We're here to understand what is preventing this process from achieving its objectives while keeping risk within acceptable limits.”

That does not compromise independence.


It improves the quality of the audit.


The auditor remains independent.


Management remains responsible for the process.


But both parties can focus on the same objective:

Making the organization better.

The Bottom Line

Defensiveness and ego are among the most difficult human behaviors internal auditors encounter because they exist on both sides of the table.


Management may hear:

“You're criticizing me.”

The auditor may hear:

“You're saying my audit is wrong.”

Now two people are defending themselves instead of examining the evidence.


That is when the auditor needs discipline.


Separate:

Person

from

Process

from

Control deficiency.


Return to:

Facts.

Criteria.

Evidence.

Cause.

Risk.

Corrective action.


Listen to management's challenge.


Change the finding when the evidence requires it.


Defend the conclusion when the evidence supports it.


And never turn an audit into a contest over who gets to be right.

The objective is not to prove someone wrong. The objective is to establish what happened, why it happened, the resulting risk, and what should change.

That is professional Internal Audit.


The Five Human Behavior Problems Internal Auditors Must Overcome

This is Part Three of our series:

1. Denial — “We don't have a problem.”

2. Rationalization — “There is a good reason we do it this way.”

3. Defensiveness and Ego — “You're criticizing me.”

4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”

5. Resistance to Change — “We've always done it this way.”


The first two problems can hide the facts.


The third can make the audit personal.


The fourth—Fear and Self-Preservation—creates an even more difficult problem: the employee may know exactly what is wrong but decide that telling the auditor the truth is simply too dangerous.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page