Defensiveness and Ego: When an Audit Finding Becomes Personal
- John C. Blackshire, Jr.

- 3 hours ago
- 11 min read
“You’re Criticizing Me.”
Internal auditors believe they are auditing processes, risks, and controls.
The people being audited do not always see it that way.
An auditor says:
“We identified a weakness in the approval process.”
The process owner may hear:
“You don't know how to manage your department.”
The auditor says:
“The control was not operating effectively.”
The manager may hear:
“You failed.”
The auditor says:
“Management should strengthen monitoring.”
The executive may hear:
“You're telling me how to run my business.”
Once that happens, the audit conversation can change dramatically.
The discussion stops being about risk and internal control and becomes about identity, competence, authority, reputation, and ego.
That is the third major human behavior problem internal auditors need to understand:
Defensiveness and Ego — “You're criticizing me.”
The skilled internal auditor must learn how to separate the person, the process, and the control deficiency without weakening legitimate audit conclusions.
Internal Auditors Audit Processes—People Experience the Audit Personally
Consider a manager who has run Accounts Payable for 15 years.
She built the department.
She hired many of the employees.
She helped design the procedures.
She selected portions of the technology.
She trained the supervisors.
She believes the department performs well.
Then Internal Audit arrives.
After several weeks of fieldwork, the auditor reports:
“Controls over vendor master-file changes are inadequately designed.”
To the auditor, that is a technical conclusion.
To the manager, it may sound like:
“Something you built is inadequate.”
That difference matters.
The process may have become part of the manager's professional identity.
Criticizing the process can therefore feel like criticizing the person.
Internal auditors need to recognize that reaction without allowing it to interfere with the audit.
Defensiveness Is a Normal Human Reaction
When people perceive a threat to their competence, status, reputation, or authority, defensive behavior is predictable.
The reaction may appear as:
Arguing
Interrupting
Blaming others
Challenging the auditor's competence
Attacking the sample
Questioning the methodology
Minimizing the finding
Withholding cooperation
Escalating the disagreement
Attempting to rewrite the report
Some managers become angry.
Others become highly technical.
Still others become passive:
“Fine. Write whatever you want.”
That is defensiveness too.
The auditor's responsibility is not to diagnose the individual's personality.
It is to recognize when defensiveness is interfering with a productive discussion of the audit evidence.
The Audit Finding May Threaten More Than Pride
It is easy to dismiss defensiveness as ego.
That can be a mistake.
An audit finding may have real consequences for the process owner.
A significant finding could affect:
Performance evaluations
Bonuses
Promotion opportunities
Departmental budgets
Executive reputation
Regulatory scrutiny
Audit Committee attention
Employment
Suppose an Audit Committee receives a report stating that management failed to adequately control a significant cybersecurity risk.
The responsible executive may immediately recognize that the finding could affect how the CEO and Board view that executive's performance.
Now the audit finding is not merely technical.
There are personal consequences.
That does not mean Internal Audit should soften the finding.
It means the auditor should understand the environment in which the discussion is occurring.
Do Not Make the Audit About Winning
A dangerous moment occurs when management challenges the auditor personally.
Management says:
“You don't understand this process.”
The inexperienced auditor may immediately think:
“I'm going to prove that I do.”
Now both parties have something to defend.
Management is defending the process.
The auditor is defending the audit.
The conversation becomes:
Ego versus ego.
That is rarely productive.
The objective of Internal Audit is not:
Prove that the auditor is right.
The objective is:
Determine what happened, why it happened, what risk exists, and what should change.
That distinction is fundamental to good audit communication.
Separate the Person From the Process
A useful principle for auditors is:
Good people can operate bad processes.
A highly competent manager can inherit:
A poorly designed system
An outdated policy
Inadequate staffing
Weak segregation of duties
Manual processes
Legacy technology
Conflicting responsibilities
The control deficiency does not necessarily mean the manager is incompetent.
That gives the auditor a better way to frame the discussion.
Instead of:
“You aren't adequately reviewing vendor changes.”
consider:
“The current process does not consistently provide evidence of an independent review before vendor banking changes become effective.”
The second statement focuses on the process and control.
It is also more auditable.
Separate the Person, Process, and Control
Internal auditors should consciously distinguish among three things.
The Person
Who performs or manages the activity?
The Process
How is the business objective accomplished?
The Control
What prevents, detects, or corrects the identified risk?
Suppose a payroll manager personally reviews every payroll adjustment.
The auditor discovers that there is no evidence documenting those reviews.
Do not jump directly to:
“The payroll manager isn't reviewing adjustments.”
The manager may be reviewing every one.
The actual issue may be:
The organization cannot demonstrate that the control occurred.
That is different.
Precision reduces unnecessary conflict.
Start With Facts, Not Conclusions
Suppose Internal Audit tests 50 purchase orders and identifies eight without the required evidence of approval.
A confrontational approach would be:
“Your purchasing controls are ineffective.”
Management may immediately become defensive.
A better approach begins with the condition:
“Eight of the 50 purchase orders we tested did not contain evidence of the approval required by policy.”
Then ask:
“Can we walk through these eight transactions together?”
Now the conversation begins with evidence.
Perhaps management identifies:
Approval stored elsewhere
A system issue
An emergency exception
A misunderstanding of policy
Actual control failures
The auditor learns something either way.
Use the Five Elements of an Audit Finding
A structured finding helps remove personality from the discussion.
Condition
What did Internal Audit find?
Criteria
What should have happened?
Cause
Why did the difference occur?
Consequence
Why does it matter?
Corrective Action
What should change?
This structure forces the auditor to move beyond:
“Management did something wrong.”
Instead, the discussion becomes:
Here is what happened.
Here is what should have happened.
Here is why the difference occurred.
Here is the resulting risk.
Here is what could improve the process.
That is a professional audit discussion.
Ask Management to Challenge the Facts
When defensiveness begins, one of the most useful questions an auditor can ask is:
“Which fact do we have wrong?”
This changes the conversation.
If the auditor has something wrong, management should be able to identify it.
Perhaps:
The population is incomplete.
The auditor misunderstood the workflow.
A compensating control exists.
Documentation was stored somewhere else.
The policy cited is obsolete.
The system behaves differently than the auditor believed.
Good.
Correct the finding.
Internal Audit should never defend an incorrect finding merely because changing it feels like losing.
But if management cannot identify an incorrect fact, the discussion should return to the evidence.
Management Disagreement Can Improve the Audit
Auditors should not fear disagreement.
A strong challenge can make the audit better.
Management may force the audit team to reconsider:
Scope
Sampling
Criteria
Evidence
Root cause
Risk
Wording
Recommendations
That is healthy.
Professional skepticism should apply to the auditor's own conclusions.
The question is not:
“Did management agree?”
The question is:
“After considering all available evidence, is our conclusion still supportable?”
If yes, maintain it.
If no, change it.
That is objectivity.
Do Not Use Audit Language as a Weapon
Words matter.
Compare:
“Management failed to properly supervise employees.”
with:
“The current supervisory review did not consistently detect transactions processed without the required authorization.”
The second statement may actually be stronger because it identifies the control problem.
Auditors should be especially careful with words such as:
Failed
Neglected
Ignored
Refused
Incompetent
Reckless
Mismanaged
Sometimes those words are justified.
If management knowingly ignored repeated warnings, “ignored” may be exactly the right word.
But use such language because the evidence supports it, not because the auditor is frustrated.
An audit report is not the place to settle an argument.
S.P.I.N. Questioning Can Reduce Defensiveness
The S.P.I.N. questioning methodology can help auditors explore problems without immediately putting the process owner on the defensive.
S.P.I.N. stands for:
Situation
Problem
Implication
Need-Payoff
Situation
Understand the process.
“Walk me through how purchase requests are approved.”
Problem
Explore difficulties.
“What happens when the designated approver is unavailable?”
Implication
Connect the weakness to risk.
“If employees can process the purchase before approval, what prevents an unauthorized purchase from occurring?”
Need-Payoff
Explore improvement.
“Would delegated approval authority within the system allow the department to maintain workflow without bypassing the control?”
Notice what happened.
The auditor did not begin with:
“Your approval process is inadequate.”
Instead, the questions allowed management to participate in identifying the weakness and possible solution. Management owns the internal controls!!
That can substantially reduce defensiveness.
Walkthroughs Are Where Relationship Skills Matter
A walkthrough should not feel like an interrogation.
The auditor needs information.
The process owner has it.
That relationship matters.
Consider two questions.
Question One
“Why didn't you follow the policy?”
That immediately sounds accusatory.
Question Two
“Walk me through what happens when the normal approval process cannot be completed.”
The second question is likely to produce much more useful information.
Auditors should remember:
The objective of an interview is to obtain information, not demonstrate superiority.
Do Not Embarrass the Process Owner
Auditors sometimes unnecessarily create resistance by identifying problems in front of the wrong audience.
Imagine discovering an exception during a walkthrough attended by:
The employee
The employee's supervisor
The department manager
The CFO
The auditor says:
“So you're telling us you don't actually perform the required control?”
That may be technically accurate.
It may also be a terrible interviewing technique.
The employee now has an immediate reason to defend themselves.
A better auditor recognizes when a sensitive issue should be explored privately.
People who feel humiliated rarely become more cooperative.
Ego Exists on Both Sides of the Table
This is critical.
Internal auditors have egos too.
Auditors can become emotionally attached to findings.
They spent three weeks developing them.
They discussed them with the Audit Manager.
They drafted the report.
They may begin thinking:
“This is my finding.”
That is dangerous.
It is not your finding.
It is a professional conclusion based on evidence.
If new evidence changes the conclusion, change it.
Auditor ego can appear when we say:
“Management is just being defensive.”
Sometimes management is being defensive.
Sometimes management is right.
The auditor must be willing to distinguish between the two.
Confirmation Bias Can Make the Problem Worse
Once auditors develop a theory, they may unconsciously seek evidence supporting it.
Suppose the auditor concludes early in fieldwork:
“This department has weak management.”
Now every exception may reinforce that belief.
Positive evidence may receive less attention.
That is confirmation bias.
The process owner may be doing exactly the same thing:
“Internal Audit doesn't understand our business.”
Now every auditor question becomes proof of that belief.
Both parties can become trapped.
The solution is evidence.
Ask:
What evidence would cause me to change my conclusion?
That is a powerful professional-skepticism question.
AI Can Help Auditors Challenge Their Own Ego
Artificial intelligence can be useful here.
Using an organization's approved AI environment and appropriately protected information, the audit team can ask:
“Act as the process owner and develop the strongest arguments against this finding.”
Or:
“Identify statements in this finding that sound accusatory rather than objective.”
Or:
“Separate the factual condition from conclusions or assumptions.”
Or:
“What additional evidence would be required to support this conclusion?”
Or:
“Rewrite this finding so it focuses on the control deficiency rather than the individuals involved, without reducing the seriousness of the risk.”
That is an excellent use of AI.
Do not merely ask AI to make the report sound impressive.
Use AI to challenge the auditor's reasoning and communication.
Defensiveness Can Reveal Organizational Culture
One defensive manager does not necessarily indicate a cultural problem.
But repeated patterns deserve attention.
Suppose management routinely:
Attacks auditors
Disputes minor wording
Minimizes findings
Discourages employees from speaking freely
Demands names of employees who provided information
Delays evidence
Escalates routine disagreements
Pressures Internal Audit to reduce ratings
That may tell the Chief Audit Executive something important about the control environment.
Ask:
How does this organization respond to bad news?
Healthy organizations may disagree vigorously with auditors.
But they ultimately want accurate information.
Unhealthy organizations may treat the messenger as the problem.
Watch What Happens to Employees Who Tell Internal Audit the Truth
This is particularly important.
Suppose an employee tells Internal Audit:
“We routinely bypass this control because our manager tells us to.”
Later, management demands:
“Who told you that?”
The auditor now needs to think carefully.
How management responds to people who raise concerns can reveal a great deal about:
Tone at the top
Psychological safety
Ethics
Whistleblower culture
Management override
Control environment
Internal Audit should not casually expose sources simply to make a finding easier to defend.
When Does Defensiveness Become a Governance Issue?
Not every disagreement belongs before the Audit Committee.
But significant unresolved disagreement may require escalation when it involves:
Material financial exposure
Fraud
Cybersecurity
Regulatory compliance
Management override
Significant control deficiencies
Repeated findings
Risk acceptance beyond management's authority
Interference with Internal Audit
At that point, the issue is no longer:
“Management doesn't like our finding.”
The issue becomes:
“Is governance receiving an accurate picture of organizational risk?”
That is exactly where an independent Internal Audit function becomes important.
Do Not Confuse Diplomacy With Weakness
Auditors sometimes believe they face a choice:
Maintain the relationship
or
Tell the truth.
That is a false choice.
A skilled auditor should be able to do both.
Professional diplomacy means:
Listening
Being precise
Avoiding unnecessary accusations
Considering contrary evidence
Explaining risk clearly
Treating people respectfully
It does not mean:
Removing valid findings
Understating risk
Changing ratings to avoid conflict
Accepting unsupported explanations
Allowing management to control the audit conclusion
You can be respectful and firm simultaneously.
A Practical Method for Handling Defensive Management
When a process owner becomes defensive, try this sequence:
Do not become defensive yourself. Keep your emotional reaction out of the audit.
Return to the facts. Identify precisely what the evidence demonstrates.
Ask what the auditor may have misunderstood. Give management a legitimate opportunity to challenge the conclusion.
Separate the person from the process. Focus on how the control operates, not on someone's character.
Separate condition from consequence. Establish what happened before debating how serious it is.
Ask S.P.I.N.-style questions. Help management work through the problem and implications.
Look for compensating controls. Management may know something the audit team does not.
Identify the root cause. Do not stop at the individual who performed the transaction.
Document significant disagreement. Do not make an issue disappear simply because the conversation became uncomfortable.
Escalate significant unresolved risk appropriately. Governance needs to understand important risks even when management disagrees.
The Auditor Does Not Need an Admission of Guilt
This may be the most important point.
The objective of an audit meeting is not to get the process owner to say:
“You were right. I was wrong.”
That may never happen.
And it does not need to.
The auditor needs to determine:
What happened?
What should have happened?
Why was there a difference?
What risk resulted?
What should change?
Management may disagree with Internal Audit while still agreeing to corrective action.
That can be a successful outcome.
From Confrontation to Collaboration
The best internal auditors learn how to change the conversation.
Instead of:
“We're here to tell you what's wrong.”
move toward:
“We're here to understand what is preventing this process from achieving its objectives while keeping risk within acceptable limits.”
That does not compromise independence.
It improves the quality of the audit.
The auditor remains independent.
Management remains responsible for the process.
But both parties can focus on the same objective:
Making the organization better.
The Bottom Line
Defensiveness and ego are among the most difficult human behaviors internal auditors encounter because they exist on both sides of the table.
Management may hear:
“You're criticizing me.”
The auditor may hear:
“You're saying my audit is wrong.”
Now two people are defending themselves instead of examining the evidence.
That is when the auditor needs discipline.
Separate:
Person
from
Process
from
Control deficiency.
Return to:
Facts.
Criteria.
Evidence.
Cause.
Risk.
Corrective action.
Listen to management's challenge.
Change the finding when the evidence requires it.
Defend the conclusion when the evidence supports it.
And never turn an audit into a contest over who gets to be right.
The objective is not to prove someone wrong. The objective is to establish what happened, why it happened, the resulting risk, and what should change.
That is professional Internal Audit.
The Five Human Behavior Problems Internal Auditors Must Overcome
This is Part Three of our series:
1. Denial — “We don't have a problem.”
2. Rationalization — “There is a good reason we do it this way.”
3. Defensiveness and Ego — “You're criticizing me.”
4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”
5. Resistance to Change — “We've always done it this way.”
The first two problems can hide the facts.
The third can make the audit personal.
The fourth—Fear and Self-Preservation—creates an even more difficult problem: the employee may know exactly what is wrong but decide that telling the auditor the truth is simply too dangerous.
Comments