Resistance to Change: Why Audit Findings Fail When Management Refuses to Change the Process
- John C. Blackshire, Jr.

- 3 hours ago
- 10 min read
“We’ve Always Done It This Way.”
Sometimes Internal Audit does everything correctly.
The risk is identified.
The evidence is solid.
Management agrees with the finding.
The root cause is understood.
The recommendation is reasonable.
And still, nothing changes.
Why?
Because recognizing a problem and changing behavior are two different things.
This is the fifth major human-behavior challenge internal auditors must overcome:
Resistance to Change — “We’ve always done it this way.”
Unlike denial, management may no longer dispute the facts.
Unlike rationalization, management may no longer defend the current process.
Unlike defensiveness, the conversation may no longer be personal.
Unlike fear, employees may be perfectly willing to discuss the problem.
But the organization still does not move.
That is where internal auditors need to understand change management, not just audit methodology.
And this is where Dr. John Kotter’s Eight-Step Process for Leading Change becomes particularly useful.
Agreeing With the Finding Is Not the Same as Implementing the Fix
Internal Audit may hear:
“Yes, we agree.”
Then six months later:
“The corrective action is still in progress.”
Then another six months:
“The project has been delayed.”
Then:
“The system implementation was postponed.”
Then:
“Management is reassessing priorities.”
Eventually, the finding becomes a repeat finding.
The problem was never disagreement.
The problem was implementation.
That distinction matters.
Internal Audit often treats issuance of the report as the end of the hard work.
In reality, for significant findings, the difficult part may only be beginning.
Why People Resist Change Even When They Agree It Is Necessary
People resist change for many reasons.
Some are obvious.
Others are subtle.
Uncertainty
Employees may understand the current process, even if it is inefficient.
A new process creates questions:
Will I know how to do the work?
Will the new system work?
Will I make mistakes?
Will my job change?
Will I still have a job?
The old process is familiar.
The new process is uncertain.
Additional Work
Many corrective actions require effort before they create benefit.
For example:
New training
New procedures
System testing
Data cleanup
Documentation
Additional approvals
Employees may see the short-term burden more clearly than the long-term benefit.
Loss of Authority
A new control may redistribute responsibilities.
Suppose one manager currently:
Creates vendors
Approves vendor changes
Releases payments
Internal Audit recommends segregation of duties.
The manager may agree that the control environment is weak.
But the corrective action reduces that manager’s authority.
That can create resistance.
Loss of Status
Process redesign can change who controls important information or decisions.
Change may threaten informal power.
Fear of Failure
People may prefer a flawed system they understand to a new system where they might fail publicly.
Change Fatigue
Organizations launch initiative after initiative.
Employees may think:
“This will disappear too.”
So they wait.
That is often rational behavior based on experience.
“We’ve Always Done It This Way” Is Really About Comfort
This phrase sounds intellectually weak.
But psychologically, it can be powerful.
Routine reduces uncertainty.
Employees know:
What to do
Who to ask
Which shortcuts work
Which exceptions management tolerates
How long the process takes
Changing the process destroys that familiarity.
That is why the auditor should not assume that demonstrating the superiority of a new control will automatically create adoption.
People do not always resist because they disagree with the logic.
They may resist because the existing process is comfortable.
The Audit Finding Creates the Case for Change
Internal Audit already possesses one of the most important tools in change management: evidence.
A strong audit finding can establish:
What is happening
Why it matters
What risk exists
What could happen if nothing changes
That can help create what Kotter calls a sense of urgency.
This is Step One of his Eight-Step Process.
The organization must understand:
Why must we change now?
A weak audit finding says:
“The procedure should be updated.”
A stronger finding says:
“The current process allows one employee to create a vendor, modify banking information, and release payment without independent approval, creating a fraud risk that could result in funds being redirected without timely detection.”
Now there is a reason to act.
Urgency is not panic.
It is clarity about the consequences of delay.
Kotter Step One: Create a Sense of Urgency
Internal Audit can help management understand the need for change by clearly communicating:
The current condition
The risk
The potential consequence
The likelihood
The cost of inaction
Prior repeat findings
Regulatory exposure
Fraud exposure
The auditor should answer:
Why should management care now?
Without urgency, corrective action gets pushed behind:
Operations
Revenue goals
Staffing issues
System implementations
Other projects
Everything else appears more immediate.
Kotter Step Two: Build a Guiding Coalition
Major corrective actions rarely succeed because one process owner agrees with Internal Audit.
The organization may need a coalition.
Suppose Internal Audit identifies weak user-access controls.
Fixing the problem may require:
IT
Cybersecurity
Human Resources
Compliance
Business-unit management
Internal Audit
Executive leadership
If one manager owns the corrective action but does not control these functions, implementation may stall.
A guiding coalition creates shared ownership.
Internal Audit should ask:
Who has to support this change for it to succeed?
That is often a better question than simply:
“Who is the action owner?”
Kotter Step Three: Form a Strategic Vision and Initiatives
A corrective action should describe where the organization is going.
Weak action plan:
“Management will improve access controls.”
That is vague.
Stronger vision:
“All privileged access will be assigned based on job responsibility, independently approved, reviewed quarterly, and automatically removed when employment terminates.”
Now employees can understand the target state.
The clearer the destination, the easier it is to manage change.
Kotter Step Four: Communicate the Vision
A corrective action sitting in the audit report does not implement itself.
Employees need to understand:
What is changing
Why it is changing
When it is changing
How it affects them
Who owns the change
If employees hear only:
“Internal Audit requires this,”
the change is already in trouble.
Internal Audit does not own the control.
Management does.
The message should be:
“We are changing this process because it reduces risk and improves the organization.”
Not:
“We have to do this because the auditors said so.”
The Worst Implementation Strategy: “Internal Audit Made Us Do It”
Auditors should pay attention to this phrase.
“Internal Audit requires us to do this.”
Usually, Internal Audit does not require the control.
Internal Audit identifies the risk and evaluates management’s response.
When management blames Internal Audit for the change, employees may perceive the new control as bureaucracy imposed by outsiders.
That increases resistance.
The better ownership model is:
Management understands the risk and has decided this corrective action is necessary.
That matters.
Kotter Step Five: Remove Barriers
Corrective action often fails because something prevents employees from performing the new process.
Common barriers include:
Inadequate staffing
Poor system design
Lack of training
Conflicting policies
Unclear authority
Weak leadership
Misaligned incentives
Suppose Internal Audit recommends:
“All vendor-bank changes require independent callback verification.”
Management agrees.
But employees still cannot consistently perform the control because:
Vendors do not maintain current contact information.
The system does not prevent payment before verification.
Employees are evaluated on payment speed.
One person handles all vendor changes.
The control may fail again.
A sustainable corrective action requires removing the barriers.
Ask: What Would Prevent This Corrective Action From Working?
This should become a standard Internal Audit question.
Before accepting a corrective action, ask:
What could prevent management from implementing this successfully?
Potential answers:
Budget
Staffing
Technology
Training
Procurement
Executive approval
Competing projects
Regulatory constraints
This is a pre-mortem.
It helps identify failure before implementation begins.
Kotter Step Six: Generate Short-Term Wins
Large corrective actions may take years.
Employees need evidence that change is working.
Suppose a company is redesigning procurement controls.
Instead of waiting for a two-year ERP implementation, management could first:
Implement independent review of high-risk vendor changes
Add exception reporting
Establish monthly monitoring
These are short-term wins.
They reduce risk and demonstrate progress.
Internal Audit can help by recognizing legitimate improvements rather than waiting for the entire project to finish.
Do Not Close the Finding Because a Project Started
This is important.
Management says:
“We purchased the software.”
That does not prove the control is effective.
Or:
“The new policy was issued.”
Still not enough.
Or:
“Employees completed training.”
Better, but still not operating-effectiveness evidence.
The finding should be closed when the corrective action has been:
Implemented
and
validated as effective.
Activity is not effectiveness.
Kotter Step Seven: Sustain Acceleration
One early success does not mean the change is complete.
Organizations frequently improve for several months and then drift backward.
People return to old habits.
Workarounds reappear.
The new control becomes burdensome.
Management attention moves elsewhere.
Internal Audit follow-up can help prevent this.
Ask:
Is the control still operating?
Are exceptions increasing?
Are employees bypassing it?
Did management monitoring continue?
Change has to survive after the initial implementation.
Kotter Step Eight: Institute Change
The final step is when the new process becomes:
“The way we do things here.”
The change may be embedded in:
Policies
Procedures
Job descriptions
Training
System workflows
Performance metrics
Management reviews
At that point, the new control no longer depends on the audit finding.
It becomes part of the organization.
That is the real objective.
Internal Audit Should Not Own the Change
This distinction is essential.
Internal Audit can:
Identify risk
Evaluate root cause
Advise management
Monitor corrective action
Validate effectiveness
But management must own implementation.
If Internal Audit:
Designs the process
Selects the system
Approves the control
Manages implementation
the auditor may compromise independence and later be auditing their own work.
Internal Audit should influence change without becoming management.
Resistance Can Reveal the Real Root Cause
Suppose management agrees with the finding but resists the solution.
Ask why.
The answer may reveal:
The recommendation is impractical.
The cost is excessive.
The root cause was wrong.
The process owner lacks authority.
Executive leadership does not support the change.
The proposed control creates other risks.
Resistance is information.
Listen to it.
A recommendation should not be defended simply because Internal Audit wrote it.
Internal Auditors Should Be Willing to Change the Recommendation
Auditors own the risk conclusion.
Management usually owns the solution.
Suppose Internal Audit recommends an additional approval.
Management proposes automation instead.
If automation effectively addresses the risk, that may be a better solution.
The objective is not:
“Implement Internal Audit’s recommendation exactly as written.”
The objective is:
Reduce the risk to an acceptable level.
That distinction supports better governance and preserves management ownership.
Repeated Findings Are Usually a Change-Management Warning
A repeat finding should trigger more than irritation.
Ask:
Why did the prior corrective action fail?
Possibilities include:
Management never accepted the risk.
The action owner lacked authority.
The implementation deadline was unrealistic.
Resources were never allocated.
Employees were not trained.
The control was poorly designed.
Leadership changed.
The audit recommendation did not address root cause.
Repeating the same recommendation is unlikely to produce a different result.
Metrics Can Help Sustain Change
Corrective action becomes more durable when management measures it.
Examples:
Percentage of vendor changes independently verified
Overdue reconciliations
User-access exceptions
Policy override frequency
Open audit findings
Repeat findings
Measurement creates visibility.
What gets measured is harder to ignore.
AI Can Help Internal Auditors Improve Corrective-Action Planning
Using an approved AI environment, auditors can use AI to help evaluate change risk.
For example:
“Identify ten reasons this corrective action could fail.”
Or:
“Apply Kotter’s Eight-Step Change Model to this corrective action.”
Or:
“What organizational barriers could prevent implementation?”
Or:
“Develop measurable milestones for implementation.”
This can help Internal Audit challenge whether management’s action plan is realistic.
AI should not own the recommendation.
It can help stress-test it.
The Corrective Action Should Pass the “Monday Morning Test”
Ask:
What exactly does someone do differently Monday morning?
If nobody can answer, the action may still be too vague.
“Improve monitoring” fails this test.
“Implement a monthly review of all privileged-access changes, with documented sign-off by the IT Security Manager” passes it much better.
Good corrective actions change behavior.
The Audit Committee Should Care About Resistance to Change
Significant overdue findings are governance information.
The Audit Committee should understand:
Which high-risk findings remain open
How long they have been open
Why implementation is delayed
Whether management accepted the risk
Whether resources are sufficient
Whether findings repeat
An overdue low-risk action may not matter much.
An overdue high-risk action involving fraud, cybersecurity, or regulatory exposure may matter greatly.
A Practical Method for Auditors Facing Resistance to Change
When management agrees with the finding but implementation stalls:
Reconfirm the risk. Has anything changed?
Revisit root cause. Did the original analysis identify the real problem?
Understand the resistance. What specifically is blocking action?
Determine ownership. Does the action owner have authority?
Identify stakeholders. Who else must support the change?
Define the future state. What will success look like?
Remove implementation barriers.
Set measurable milestones.
Validate effectiveness before closure.
Escalate significant unresolved risk appropriately.
That is much stronger than repeatedly changing the due date.
The Auditor’s Job Is Not Finished When Management Says “We Agree”
This may be the key lesson.
A successful audit does not end with:
“Management agrees with the finding.”
That is only one milestone.
The real sequence is:
Finding
↓
Agreement
↓
Corrective Action
↓
Implementation
↓
Operating Effectiveness
↓
Sustainable Change
Internal Audit should care about the entire chain.
The Bottom Line
Resistance to change is not necessarily irrational.
Change creates:
Uncertainty.
Work.
Risk.
Loss of authority.
Loss of comfort.
Fear of failure.
The skilled internal auditor recognizes those forces.
That does not mean Internal Audit accepts endless delays.
It means the auditor approaches corrective action as a change-management problem, not merely a reporting problem.
Dr. John Kotter’s framework provides a useful structure:
Create urgency.
Build a coalition.
Develop a vision.
Communicate the vision.
Remove barriers.
Generate short-term wins.
Sustain momentum.
Make the change part of the organization.
Internal Audit does not need to own those steps.
Management does.
But auditors who understand them can become much more effective at evaluating why corrective actions succeed—or fail.
Finding the problem is only half the audit. Sustainable corrective action is where the organization actually gets better.
That is the difference between issuing an audit report and creating lasting value.
The Five Human Behavior Problems Internal Auditors Must Overcome
This is Part Five of our series:
1. Denial — “We don’t have a problem.”
2. Rationalization — “There is a good reason we do it this way.”
3. Defensiveness and Ego — “You’re criticizing me.”
4. Fear and Self-Preservation — “What happens to me if I tell you the truth?”
5. Resistance to Change — “We’ve always done it this way.”
Together, these five behaviors explain why technically correct audits can still fail to produce meaningful improvement.
Internal auditing is not only about controls.
It is also about understanding the people who design, operate, override, defend, and ultimately change those controls.
Comments