top of page
Search

Denial: One of the Most Difficult Human Behaviors Internal Auditors Must Overcome

Aug 12
10 min read

“We Don’t Have a Problem.”


Internal auditors are trained to evaluate risks, controls, transactions, processes, and evidence.


But some of the hardest problems auditors encounter are not accounting problems or control problems.


They are human behavior problems.


Among the most difficult is denial.


An auditor identifies a control weakness. The evidence is clear. Exceptions have been documented. The risk has been explained.


Management responds:

“We don't have a problem.”

Or perhaps:

“That can't happen.”
“That's only one exception.”
“Nobody has ever complained about this before.”
“We've been doing it this way for 15 years.”
“You're making this sound much worse than it is.”

At this point, the auditor is no longer dealing only with an internal-control deficiency.


The auditor is dealing with the human tendency to reject, minimize, or reinterpret information that threatens existing beliefs, reputation, authority, competence, or self-interest.


Understanding how to deal with denial is an important part of internal audit tradecraft.


Denial Does Not Necessarily Mean Dishonesty

Auditors should be careful about immediately interpreting denial as deception.


The manager who says, “We don't have a problem,” may genuinely believe it.


Human beings naturally construct mental models about themselves and their organizations.


A manager may believe:

  • “I run a good department.”

  • “My people are competent.”

  • “Our controls are strong.”

  • “We have never had a fraud.”

  • “I would know if something serious were wrong.”


Then Internal Audit arrives with evidence contradicting that belief.


The auditor may believe the discussion is about a control.


The manager may experience it as a challenge to something much more personal:

  • Competence.

  • Reputation.

  • Authority.

  • Professional judgment.

  • Status.


That distinction matters.


If the auditor treats every defensive response as dishonesty, the auditor can make the situation worse.


Why People Deny Audit Findings

Suppose Internal Audit identifies that employees can both create vendors and modify vendor banking information.


The auditor sees:


Control weakness → Fraud opportunity → Business risk.


The Accounts Payable manager may see:


Audit finding → My department failed → I failed.


Those are completely different perspectives.


Management denial can therefore have several sources.

Threat to Competence

The finding may suggest that a manager did not understand or adequately control the process.

Threat to Reputation

A significant audit finding may be reported to senior management or the Audit Committee.

Threat to Authority

Corrective action may reduce a manager's discretion or change responsibilities.

Threat to Budget

Fixing the problem may require:

  • Additional employees

  • New technology

  • Consulting assistance

  • Process redesign

Threat to Performance Measures

The finding may affect departmental metrics, bonuses, or performance evaluations.

Threat to the Status Quo


Sometimes people simply prefer the current process.


They understand it.


They know how to operate within it.


Changing it creates uncertainty.


The auditor therefore needs to recognize an important reality:

The audit finding that looks technical to the auditor may look deeply personal to management.

The Most Dangerous Phrase: “It Has Never Happened Before”

Internal auditors hear variations of this frequently.

“We've never had a fraud.”
“We've never lost money from this.”
“Nobody has ever complained.”
“We've never had a cybersecurity incident.”

Management may believe these statements prove the control environment is adequate.


They do not.


The absence of a known failure does not establish the effectiveness of a control.


Consider a warehouse with no restrictions on access.


Management says:

“Nothing has ever been stolen.”

That does not prove the access control is properly designed.


It may mean:

  • Nothing has been stolen.

  • Something was stolen but not detected.

  • The opportunity has not yet been exploited.

  • Other controls have compensated for the weakness.


Auditors evaluate risk and control effectiveness, not merely historical luck.


A useful question is:

What prevents this from happening tomorrow?

That moves the discussion away from history and toward control design.


“It's Only One Exception”

This is another common form of denial.


Suppose Internal Audit tests 40 transactions and identifies one significant exception.


Management responds:

“You tested 40 and only found one problem. That's a 97.5% success rate.”

Maybe.


But the auditor needs to understand the nature of the exception.


Suppose the one exception involved a $450,000 payment to a fraudulent bank account.


Calling that a 2.5% exception rate misses the point.


Audit significance is not determined solely by counting exceptions.


The auditor should consider:

  • Dollar exposure

  • Fraud potential

  • Regulatory consequences

  • Control frequency

  • Nature of the control

  • Population

  • Root cause

  • Whether the exception indicates a systemic weakness


One exception can reveal that a control is capable of being circumvented.


The correct question is not always:

“How many exceptions did we find?”

Sometimes it is:

“What does this exception tell us about the control?”

“The Auditor Doesn't Understand Our Business”

Sometimes management is correct.


Internal auditors should acknowledge that possibility.


Auditors make mistakes.


They misunderstand processes.


They apply inappropriate criteria.


They misinterpret evidence.


They occasionally develop findings that do not survive serious challenge.


Management disagreement is therefore not automatically denial.


A strong auditor welcomes factual challenges.


Ask management:

“What fact do we have wrong?”

That is a powerful question.


If management provides evidence demonstrating that the auditor misunderstood the process, change the finding.


Internal Audit should never defend a bad finding merely because the audit team wrote it.


But notice what happens when the question is framed around facts.


The discussion moves away from:

“I disagree with Internal Audit.”

toward:

“Which fact is incorrect?”

That is a much more productive conversation.


Separate Condition From Consequence

One reason findings become unnecessarily contentious is that auditors mix facts and interpretations together.


Suppose the auditor writes:

“Management has failed to maintain adequate controls over vendor-master-file changes, creating a significant fraud risk.”

Management may immediately attack the statement.


Break it apart.

Condition

Three of 25 vendor banking changes tested did not contain evidence of independent verification required by company policy.

Criteria

Company policy requires independent verification before changes to vendor banking information are processed.

Cause

The employees performing the changes stated that the verification procedure was sometimes bypassed when payment deadlines were approaching.

Consequence

An unauthorized change to vendor banking information could redirect company payments to an account controlled by a fraudster.


Now the discussion can occur one component at a time.

  • Did three exceptions exist?

  • Does the policy require verification?

  • Was the procedure bypassed?

  • Could an unauthorized banking change redirect payments?


Breaking the finding into components makes broad denial more difficult.


Evidence Is the Auditor's Anchor

When management becomes defensive, inexperienced auditors sometimes become defensive too.


That creates an argument.


The conversation becomes:

Management: “Your finding is wrong.”
Auditor: “No, it isn't.”
Management: “You don't understand the process.”
Auditor: “Yes, I do.”

Nothing useful is happening.


The auditor should return to the evidence.


Try:

“Let's walk through the transactions together.”

Or:

“Show me where our understanding differs from the actual process.”

Or:

“What evidence demonstrates that the control operated?”

That is a fundamentally different conversation.


The auditor does not need to win the argument.


The auditor needs to establish the facts.


Use S.P.I.N. Questioning to Work Through Denial

The S.P.I.N. questioning methodology can be particularly effective when an auditor encounters denial.


S.P.I.N. stands for:

  • Situation

  • Problem

  • Implication

  • Need-Payoff

Although developed for consultative selling, the structure adapts remarkably well to audit interviews and walkthroughs.


Situation Questions

Understand the process.

“Walk me through how vendor bank-account changes are processed.”
“Who can make the change?”
“Who reviews it?”
“What evidence is retained?”

Do not begin by accusing anyone of having a control problem.


Understand the situation first.


Problem Questions

Explore what can go wrong.

“What happens when independent verification cannot be completed?”
“Can the change still be processed?”
“Have there been situations where payment deadlines caused the normal procedure to be bypassed?”

Now management may begin identifying the weakness themselves.


Implication Questions

Explore why the problem matters.

“If an employee changed the bank account without independent verification, how would the organization know that the new account actually belonged to the vendor?”

That question is much stronger than saying:

“Your control is ineffective.”

Let the process owner think through the consequence.


Need-Payoff Questions

Move toward corrective action.

“Would an automated workflow preventing payment until independent verification is documented reduce that exposure?”

The conversation has now moved from:

Denial

to

Problem recognition

to

Risk understanding

to

Corrective action.


That is productive audit communication.


Do Not Trigger Unnecessary Defensiveness

Auditor language matters.


Consider these two approaches.


Approach One

“Your department has inadequate controls over purchasing cards.”

Now compare:

Approach Two

“Our testing identified five transactions where the required supervisory approval was not documented. Let's walk through those transactions and determine what happened.”

The second approach is stronger.


It begins with evidence rather than accusation.


The auditor should avoid unnecessarily loaded language such as:

  • Failure

  • Negligence

  • Incompetence

  • Reckless

  • Management ignored

  • Management refused

unless the evidence clearly supports those characterizations and they are necessary to communicate the issue.


Audit reports should not sanitize serious problems.


But they should not manufacture emotional conflict either.


Denial Can Turn Into Rationalization

When the evidence becomes difficult to dispute, denial often evolves.


Management moves from:

“That didn't happen.”

to:

“It happened, but there was a good reason.”

Now the auditor is dealing with rationalization.

Examples include:

“We don't have enough people.”
“The system doesn't allow us to do it properly.”
“Everyone knows about the workaround.”
“We had to get the payment out.”
“Senior management told us to do it.”

This is progress.


Why?


Because management has moved from disputing the condition to discussing the cause.


And cause is precisely where the auditor needs to go.


Root Cause Can Break Through Denial

Suppose management admits employees sometimes bypass a required review because the process takes too long.


A weak auditor writes:

Recommendation: Management should ensure employees comply with the review requirement.

That may accomplish nothing.


The advanced auditor asks:

Why does the review take too long?

Perhaps:

  • The reviewer has too many responsibilities.

  • The workflow is manual.

  • Supporting information is unavailable.

  • The approval threshold is inappropriate.

  • The technology is poorly configured.

  • Responsibilities are unclear.


Now Internal Audit can recommend something that might actually fix the problem.


Denial is easier to overcome when management sees that the auditor is trying to understand why the problem exists, rather than simply assigning blame.


Denial Becomes More Dangerous Higher in the Organization

Denial at the employee level creates problems.


Denial at the executive level can create organizational risk.


Senior leaders influence:

  • Culture

  • Risk appetite

  • Internal control

  • Resource allocation

  • Corrective action

  • Employee behavior


If leadership consistently responds to bad news by attacking the messenger, employees learn something quickly:

Do not bring leadership bad news.

That can create an environment where problems remain hidden until they become crises.

Internal Audit should therefore consider repeated denial itself as information about the control environment.


A management team that routinely:

  • Minimizes findings

  • Delays corrective action

  • Attacks auditors

  • Challenges evidence without contrary evidence

  • Reclassifies significant issues as minor

  • Allows repeat findings

may have a broader governance problem.


The Audit Committee Should Understand Persistent Denial

Some disagreements are normal.


Internal Audit should not escalate every argument.


But persistent management denial of well-supported significant risks may need Audit Committee attention.


The Chief Audit Executive should consider whether the disagreement involves:

  • Significant financial exposure

  • Fraud risk

  • Regulatory compliance

  • Cybersecurity

  • Management override

  • Material internal-control weaknesses

  • Significant unresolved findings

  • Acceptance of risk outside established authority


At some point, the question is no longer:

“Does management agree with Internal Audit?”

It becomes:

“Does governance understand the risk management has chosen to accept?”

That is a very different issue.


Internal Auditors Must Watch Their Own Denial

There is another side to this discussion.


Auditors are human too.


We can become attached to:

  • Our findings

  • Our theories

  • Our risk assessments

  • Our audit programs

  • Our interpretation of evidence


An auditor may experience the same psychological reaction when management produces evidence contradicting an audit finding.


That creates a dangerous situation.


Internal Audit cannot criticize management for refusing to accept evidence while simultaneously refusing to accept evidence itself.


Professional skepticism works in both directions.


The auditor should continually ask:

What evidence would cause me to change my conclusion?

If the answer is “nothing,” the auditor is no longer exercising professional skepticism.


The auditor is defending a position.


AI Can Help the Auditor Challenge Their Own Thinking

Artificial intelligence provides an interesting new tool for dealing with this problem.


Using an organization's approved AI environment and appropriately protected information, an auditor could ask:

“Act as a skeptical process owner. Identify the strongest arguments against this audit finding.”

Or:

“What alternative explanations could account for these exceptions?”

Or:

“What additional evidence would be necessary to distinguish between a control-design problem and isolated operating exceptions?”

Or:

“Identify assumptions in this finding that are not directly supported by the evidence.”

That is an excellent use of AI.


Do not merely use AI to make your audit finding sound better.


Use it to attack your own reasoning before management does.


If the finding survives that challenge, it becomes stronger.


If it does not, fix it.


A Practical Method for Auditors Facing Denial

When management says, “We don't have a problem,” the auditor should resist the temptation to argue.


Instead:

1. Return to the facts.What exactly happened?

2. Establish the criteria.What should have happened?

3. Validate the evidence.Can both parties agree on what the records demonstrate?

4. Explore the cause.Why did the condition occur?

5. Explain the risk.What could happen because the condition exists?

6. Determine whether compensating controls exist.Is something else reducing the exposure?

7. Consider management's evidence.Could the auditor be wrong?

8. Separate disagreement from denial.A legitimate difference in professional judgment is not necessarily denial.

9. Document unresolved disagreement.Do not allow an important issue to disappear merely because management objects.

10. Escalate significant unresolved risk appropriately.Governance ultimately needs visibility into significant risks management chooses to accept.


The Auditor's Job Is Not to Get Management to Admit It Was Wrong

This distinction is critical.


Internal Audit's objective should not be:

Get management to admit that Internal Audit is right.

The objective is:

Ensure that significant risks are understood and appropriately addressed or accepted by the proper level of management and governance.

Those are not the same thing.


An auditor can win an argument and damage the relationship.


An auditor can also preserve the relationship while allowing a serious risk to remain hidden.


Neither is success.


The skilled internal auditor does something harder:

  • Establish the facts.

  • Explain the risk.

  • Listen to management.

  • Challenge unsupported explanations.

  • Modify conclusions when contrary evidence warrants it.

  • Remain firm when the evidence supports the finding.

  • Escalate when necessary.


That is audit tradecraft.


The Bottom Line

Internal auditors audit systems, transactions, processes, and controls.


But they conduct those audits through people.


People have careers.


People have reputations.


People have egos.


People have budgets.


People have authority.


People have beliefs about themselves and their organizations.


When audit evidence threatens those things, denial is a predictable human response.


The successful auditor recognizes it without automatically interpreting it as dishonesty.


When management says:

“We don't have a problem.”

do not immediately fight harder.


Ask better questions.


Return to the evidence.


Separate condition, criteria, cause, and consequence.


Use S.P.I.N. questioning to move from situation to problem to implication to solution.


Challenge your own assumptions.


And remember the auditor's ultimate responsibility:

We do not need management to like the finding. We need management and governance to understand the risk.

That is one of the most important behavioral skills an internal auditor can develop.


The Five Human Behavior Problems Internal Auditors Must Overcome

This is Part One of our series:

1. Denial — “We don't have a problem.”

2. Rationalization — “There is a good reason we do it this way.”

3. Defensiveness and Ego — “You're criticizing me.”

4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”

5. Resistance to Change — “We've always done it this way.”


Understanding these behaviors should be part of every internal auditor's professional toolkit because the strongest audit methodology in the world will accomplish very little if the auditor cannot effectively work with the human beings operating the controls.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page