top of page
Search

Resistance to Change: Why Audit Findings Fail When Management Refuses to Change the Process

“We’ve Always Done It This Way.”

Sometimes Internal Audit does everything correctly.


The risk is identified.


The evidence is solid.


Management agrees with the finding.


The root cause is understood.


The recommendation is reasonable.


And still, nothing changes.


Why?


Because recognizing a problem and changing behavior are two different things.


This is the fifth major human-behavior challenge internal auditors must overcome:

Resistance to Change — “We’ve always done it this way.”

Unlike denial, management may no longer dispute the facts.


Unlike rationalization, management may no longer defend the current process.


Unlike defensiveness, the conversation may no longer be personal.


Unlike fear, employees may be perfectly willing to discuss the problem.


But the organization still does not move.


That is where internal auditors need to understand change management, not just audit methodology.


And this is where Dr. John Kotter’s Eight-Step Process for Leading Change becomes particularly useful.


Agreeing With the Finding Is Not the Same as Implementing the Fix

Internal Audit may hear:

“Yes, we agree.”

Then six months later:

“The corrective action is still in progress.”

Then another six months:

“The project has been delayed.”

Then:

“The system implementation was postponed.”

Then:

“Management is reassessing priorities.”

Eventually, the finding becomes a repeat finding.


The problem was never disagreement.


The problem was implementation.


That distinction matters.


Internal Audit often treats issuance of the report as the end of the hard work.


In reality, for significant findings, the difficult part may only be beginning.


Why People Resist Change Even When They Agree It Is Necessary

People resist change for many reasons.


Some are obvious.


Others are subtle.


Uncertainty

Employees may understand the current process, even if it is inefficient.


A new process creates questions:

  • Will I know how to do the work?

  • Will the new system work?

  • Will I make mistakes?

  • Will my job change?

  • Will I still have a job?


The old process is familiar.


The new process is uncertain.


Additional Work

Many corrective actions require effort before they create benefit.


For example:

  • New training

  • New procedures

  • System testing

  • Data cleanup

  • Documentation

  • Additional approvals


Employees may see the short-term burden more clearly than the long-term benefit.


Loss of Authority

A new control may redistribute responsibilities.


Suppose one manager currently:

  • Creates vendors

  • Approves vendor changes

  • Releases payments


Internal Audit recommends segregation of duties.


The manager may agree that the control environment is weak.


But the corrective action reduces that manager’s authority.


That can create resistance.


Loss of Status

Process redesign can change who controls important information or decisions.


Change may threaten informal power.


Fear of Failure

People may prefer a flawed system they understand to a new system where they might fail publicly.


Change Fatigue

Organizations launch initiative after initiative.


Employees may think:

“This will disappear too.”

So they wait.


That is often rational behavior based on experience.


“We’ve Always Done It This Way” Is Really About Comfort

This phrase sounds intellectually weak.


But psychologically, it can be powerful.


Routine reduces uncertainty.


Employees know:

  • What to do

  • Who to ask

  • Which shortcuts work

  • Which exceptions management tolerates

  • How long the process takes


Changing the process destroys that familiarity.


That is why the auditor should not assume that demonstrating the superiority of a new control will automatically create adoption.


People do not always resist because they disagree with the logic.


They may resist because the existing process is comfortable.


The Audit Finding Creates the Case for Change

Internal Audit already possesses one of the most important tools in change management: evidence.


A strong audit finding can establish:

  • What is happening

  • Why it matters

  • What risk exists

  • What could happen if nothing changes


That can help create what Kotter calls a sense of urgency.


This is Step One of his Eight-Step Process.


The organization must understand:

Why must we change now?

A weak audit finding says:

“The procedure should be updated.”

A stronger finding says:

“The current process allows one employee to create a vendor, modify banking information, and release payment without independent approval, creating a fraud risk that could result in funds being redirected without timely detection.”

Now there is a reason to act.


Urgency is not panic.


It is clarity about the consequences of delay.


Kotter Step One: Create a Sense of Urgency

Internal Audit can help management understand the need for change by clearly communicating:

  • The current condition

  • The risk

  • The potential consequence

  • The likelihood

  • The cost of inaction

  • Prior repeat findings

  • Regulatory exposure

  • Fraud exposure


The auditor should answer:

Why should management care now?

Without urgency, corrective action gets pushed behind:

  • Operations

  • Revenue goals

  • Staffing issues

  • System implementations

  • Other projects


Everything else appears more immediate.


Kotter Step Two: Build a Guiding Coalition

Major corrective actions rarely succeed because one process owner agrees with Internal Audit.


The organization may need a coalition.


Suppose Internal Audit identifies weak user-access controls.


Fixing the problem may require:

  • IT

  • Cybersecurity

  • Human Resources

  • Compliance

  • Business-unit management

  • Internal Audit

  • Executive leadership


If one manager owns the corrective action but does not control these functions, implementation may stall.


A guiding coalition creates shared ownership.


Internal Audit should ask:

Who has to support this change for it to succeed?

That is often a better question than simply:

“Who is the action owner?”

Kotter Step Three: Form a Strategic Vision and Initiatives

A corrective action should describe where the organization is going.


Weak action plan:

“Management will improve access controls.”

That is vague.


Stronger vision:

“All privileged access will be assigned based on job responsibility, independently approved, reviewed quarterly, and automatically removed when employment terminates.”

Now employees can understand the target state.


The clearer the destination, the easier it is to manage change.


Kotter Step Four: Communicate the Vision

A corrective action sitting in the audit report does not implement itself.


Employees need to understand:

  • What is changing

  • Why it is changing

  • When it is changing

  • How it affects them

  • Who owns the change


If employees hear only:

“Internal Audit requires this,”

the change is already in trouble.


Internal Audit does not own the control.


Management does.


The message should be:

“We are changing this process because it reduces risk and improves the organization.”

Not:

“We have to do this because the auditors said so.”

The Worst Implementation Strategy: “Internal Audit Made Us Do It”

Auditors should pay attention to this phrase.

“Internal Audit requires us to do this.”

Usually, Internal Audit does not require the control.


Internal Audit identifies the risk and evaluates management’s response.


When management blames Internal Audit for the change, employees may perceive the new control as bureaucracy imposed by outsiders.


That increases resistance.


The better ownership model is:

Management understands the risk and has decided this corrective action is necessary.

That matters.


Kotter Step Five: Remove Barriers

Corrective action often fails because something prevents employees from performing the new process.


Common barriers include:

  • Inadequate staffing

  • Poor system design

  • Lack of training

  • Conflicting policies

  • Unclear authority

  • Weak leadership

  • Misaligned incentives


Suppose Internal Audit recommends:

“All vendor-bank changes require independent callback verification.”

Management agrees.


But employees still cannot consistently perform the control because:

  • Vendors do not maintain current contact information.

  • The system does not prevent payment before verification.

  • Employees are evaluated on payment speed.

  • One person handles all vendor changes.


The control may fail again.


A sustainable corrective action requires removing the barriers.


Ask: What Would Prevent This Corrective Action From Working?

This should become a standard Internal Audit question.


Before accepting a corrective action, ask:

What could prevent management from implementing this successfully?

Potential answers:

  • Budget

  • Staffing

  • Technology

  • Training

  • Procurement

  • Executive approval

  • Competing projects

  • Regulatory constraints


This is a pre-mortem.


It helps identify failure before implementation begins.


Kotter Step Six: Generate Short-Term Wins

Large corrective actions may take years.


Employees need evidence that change is working.


Suppose a company is redesigning procurement controls.


Instead of waiting for a two-year ERP implementation, management could first:

  • Implement independent review of high-risk vendor changes

  • Add exception reporting

  • Establish monthly monitoring


These are short-term wins.


They reduce risk and demonstrate progress.


Internal Audit can help by recognizing legitimate improvements rather than waiting for the entire project to finish.


Do Not Close the Finding Because a Project Started

This is important.


Management says:

“We purchased the software.”

That does not prove the control is effective.

Or:

“The new policy was issued.”

Still not enough.

Or:

“Employees completed training.”

Better, but still not operating-effectiveness evidence.


The finding should be closed when the corrective action has been:


Implemented

and

validated as effective.


Activity is not effectiveness.


Kotter Step Seven: Sustain Acceleration

One early success does not mean the change is complete.


Organizations frequently improve for several months and then drift backward.


People return to old habits.


Workarounds reappear.


The new control becomes burdensome.


Management attention moves elsewhere.


Internal Audit follow-up can help prevent this.


Ask:

  • Is the control still operating?

  • Are exceptions increasing?

  • Are employees bypassing it?

  • Did management monitoring continue?


Change has to survive after the initial implementation.


Kotter Step Eight: Institute Change

The final step is when the new process becomes:

“The way we do things here.”

The change may be embedded in:

  • Policies

  • Procedures

  • Job descriptions

  • Training

  • System workflows

  • Performance metrics

  • Management reviews


At that point, the new control no longer depends on the audit finding.


It becomes part of the organization.


That is the real objective.


Internal Audit Should Not Own the Change

This distinction is essential.


Internal Audit can:

  • Identify risk

  • Evaluate root cause

  • Advise management

  • Monitor corrective action

  • Validate effectiveness


But management must own implementation.


If Internal Audit:

  • Designs the process

  • Selects the system

  • Approves the control

  • Manages implementation

the auditor may compromise independence and later be auditing their own work.


Internal Audit should influence change without becoming management.


Resistance Can Reveal the Real Root Cause

Suppose management agrees with the finding but resists the solution.


Ask why.


The answer may reveal:

  • The recommendation is impractical.

  • The cost is excessive.

  • The root cause was wrong.

  • The process owner lacks authority.

  • Executive leadership does not support the change.

  • The proposed control creates other risks.


Resistance is information.


Listen to it.


A recommendation should not be defended simply because Internal Audit wrote it.


Internal Auditors Should Be Willing to Change the Recommendation

Auditors own the risk conclusion.


Management usually owns the solution.


Suppose Internal Audit recommends an additional approval.


Management proposes automation instead.


If automation effectively addresses the risk, that may be a better solution.


The objective is not:

“Implement Internal Audit’s recommendation exactly as written.”

The objective is:

Reduce the risk to an acceptable level.

That distinction supports better governance and preserves management ownership.


Repeated Findings Are Usually a Change-Management Warning

A repeat finding should trigger more than irritation.


Ask:

Why did the prior corrective action fail?

Possibilities include:

  • Management never accepted the risk.

  • The action owner lacked authority.

  • The implementation deadline was unrealistic.

  • Resources were never allocated.

  • Employees were not trained.

  • The control was poorly designed.

  • Leadership changed.

  • The audit recommendation did not address root cause.


Repeating the same recommendation is unlikely to produce a different result.


Metrics Can Help Sustain Change

Corrective action becomes more durable when management measures it.


Examples:

  • Percentage of vendor changes independently verified

  • Overdue reconciliations

  • User-access exceptions

  • Policy override frequency

  • Open audit findings

  • Repeat findings


Measurement creates visibility.


What gets measured is harder to ignore.


AI Can Help Internal Auditors Improve Corrective-Action Planning

Using an approved AI environment, auditors can use AI to help evaluate change risk.


For example:

“Identify ten reasons this corrective action could fail.”

Or:

“Apply Kotter’s Eight-Step Change Model to this corrective action.”

Or:

“What organizational barriers could prevent implementation?”

Or:

“Develop measurable milestones for implementation.”

This can help Internal Audit challenge whether management’s action plan is realistic.


AI should not own the recommendation.


It can help stress-test it.


The Corrective Action Should Pass the “Monday Morning Test”

Ask:

What exactly does someone do differently Monday morning?

If nobody can answer, the action may still be too vague.


“Improve monitoring” fails this test.


“Implement a monthly review of all privileged-access changes, with documented sign-off by the IT Security Manager” passes it much better.


Good corrective actions change behavior.


The Audit Committee Should Care About Resistance to Change

Significant overdue findings are governance information.


The Audit Committee should understand:

  • Which high-risk findings remain open

  • How long they have been open

  • Why implementation is delayed

  • Whether management accepted the risk

  • Whether resources are sufficient

  • Whether findings repeat


An overdue low-risk action may not matter much.


An overdue high-risk action involving fraud, cybersecurity, or regulatory exposure may matter greatly.


A Practical Method for Auditors Facing Resistance to Change

When management agrees with the finding but implementation stalls:

  1. Reconfirm the risk. Has anything changed?

  2. Revisit root cause. Did the original analysis identify the real problem?

  3. Understand the resistance. What specifically is blocking action?

  4. Determine ownership. Does the action owner have authority?

  5. Identify stakeholders. Who else must support the change?

  6. Define the future state. What will success look like?

  7. Remove implementation barriers.

  8. Set measurable milestones.

  9. Validate effectiveness before closure.

  10. Escalate significant unresolved risk appropriately.


That is much stronger than repeatedly changing the due date.


The Auditor’s Job Is Not Finished When Management Says “We Agree”

This may be the key lesson.


A successful audit does not end with:

“Management agrees with the finding.”

That is only one milestone.


The real sequence is:

Finding

Agreement

Corrective Action

Implementation

Operating Effectiveness

Sustainable Change


Internal Audit should care about the entire chain.


The Bottom Line

Resistance to change is not necessarily irrational.


Change creates:

  • Uncertainty.

  • Work.

  • Risk.

  • Loss of authority.

  • Loss of comfort.

  • Fear of failure.


The skilled internal auditor recognizes those forces.


That does not mean Internal Audit accepts endless delays.


It means the auditor approaches corrective action as a change-management problem, not merely a reporting problem.


Dr. John Kotter’s framework provides a useful structure:

  • Create urgency.

  • Build a coalition.

  • Develop a vision.

  • Communicate the vision.

  • Remove barriers.

  • Generate short-term wins.

  • Sustain momentum.

  • Make the change part of the organization.


Internal Audit does not need to own those steps.


Management does.


But auditors who understand them can become much more effective at evaluating why corrective actions succeed—or fail.

Finding the problem is only half the audit. Sustainable corrective action is where the organization actually gets better.

That is the difference between issuing an audit report and creating lasting value.


The Five Human Behavior Problems Internal Auditors Must Overcome

This is Part Five of our series:

1. Denial — “We don’t have a problem.”

2. Rationalization — “There is a good reason we do it this way.”

3. Defensiveness and Ego — “You’re criticizing me.”

4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”

5. Resistance to Change — “We’ve always done it this way.”


Together, these five behaviors explain why technically correct audits can still fail to produce meaningful improvement.


Internal auditing is not only about controls.


It is also about understanding the people who design, operate, override, defend, and ultimately change those controls.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page