Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

The Audit Finding: Structure, Rating and Response

An audit finding is the written account of a control that failed its test, set down in five fixed parts: AF1 the condition, what was found; AF2 the criteria, what should have been; AF3 the cause, why the gap exists; AF4 the effect, what it could lead to; and AF5 the recommendation, with a named owner and a date. Drop AF3 and all that can be bought is a patch.

Four of those five parts can be written by somebody standing outside the process with a rule book and a stack of evidence. One cannot. AF3, the causeWhy the gap exists. The only part of a finding that cannot be produced by counting, sampling or reading a rule, because it is a statement about a mechanism rather than about an event., asks why a competent institution, staffed by people who wanted to do the job properly, ended up doing the wrong thing anyway. Nobody can look that up. The asymmetry between AF3 and its four neighbours is why AF3 is the part most often left blank, and why a finding without it produces an action that stops this instance of a failure and leaves the machinery that produced it exactly where it stood. Everything that follows rests on that asymmetry, so it is worth holding on to before the five parts are taken one at a time.

What is an audit finding a record of?

Start somewhere small. The shape is identical and nothing is at stake. A housing society keeps a register in which the lift technician signs after each monthly service. The rule is one signature a month. Somebody from the managing committee, who is not the technician and does not book the service, opens the register in December and counts. Four of the twelve months carry no signature.

Almost everybody gets the next step wrong on the first pass, so be careful about what has just been produced. The committee member has not found that the lift is unsafe. Nor have they found that the technician is careless. Nobody has even established that the lift was not serviced. A gap between a claim and the evidence for it is what the count produced, and that gap is the entire subject of an audit finding. The society claimed a control was operating. For four months there is nothing to show that it was. Whether the lift was in fact serviced on those four occasions is a separate question, and the register cannot answer it. The register exists for precisely that reason.

Scale that up without changing a single joint. Inside Vindhya Commercial Bank Limited, an invented bank of Rs 96,000 crore whose every figure is illustrative, there are 214 key controlsThe controls an institution has decided in advance it would notice the absence of, and therefore the only ones its testing plan can ever produce a finding about. spread across nine named processes. Each of those controls carries a claim: somebody does a specific thing, at a specific moment, and a specific outcome therefore cannot happen unnoticed. Testing takes a sample of the occasions on which the thing was supposed to happen and asks for the evidence. Where the evidence is missing, or shows the thing happening in a way that would not have achieved the objective, the tester writes it up. The write-up is the finding, and a finding is a document about a control rather than about a person, a loss or a year.

A finding is therefore not the same object as an operational loss, even when the two describe one afternoon. A loss is money that left the institution. A finding is a statement that a defence did not hold. The two can appear together, they can appear separately, and their sizes have almost nothing to do with each other. A control can fail expensively and produce no finding because nobody tested it, and a control can fail at zero cost and produce the most serious finding of the year. Both of those happened at this invented bank, and the second one is the worked instance below.

Five parts, five different questions, and one that cannot be looked up The order is not decorative. Each part is only meaningful once the one before it is settled. THE PART THE QUESTION IT ANSWERS HOW IT IS ARRIVED AT AF1 THE CONDITION what was found What actually happened, on what dates, across what population? Counted from evidence AF2 THE CRITERIA what should have been What was it supposed to do, and who said so? Read off a stated rule AF3 THE CAUSE why the gap exists Why did a competent institution end up doing the wrong thing? Worked out, never looked up AF4 THE EFFECT what it could lead to What could this lead to, and measured against what base? Sized against a named base AF5 THE RECOMMENDATION what will be done What will be done, by whom, and by when? Agreed with the process Four of the five can be written by somebody standing outside the process. The third cannot.
Each row answers a question none of the other rows answers, so a write-up that skips a row has not been shortened, it has been left without an answer to something a reader will need, and the red row is the one no amount of extra evidence can fill.

One more property of the structure is worth naming before the parts are taken apart. The order runs forward and cannot be shuffled. An effect cannot be sized before the condition is known; a cause cannot be stated for a gap that has not yet been defined against a rule; and an action certainly cannot be recommended before the thing being acted on is known. In practice, findings get written out of order all the time, usually because somebody had a fix in mind before they had the facts. A finding whose recommendation was decided first will always look tidy and will almost always be aimed at the wrong thing.

Try it out

Name the five parts of an audit finding, in order.

Financial Analyst Program Bootcamp — Fin Maverick

What does the condition have to state, and what may it never contain?

AF1, the conditionWhat was actually found, written as a fact with dates and a population attached, rather than as an impression of how well something is going., is the part that reads as though it were the easy one. The condition is what was found. The difficulty is that there are two very different ways to write what was found, and only one of them survives being read by a stranger six months later.

A condition that survives has three things in it: a fact, a date or a stretch of dates, and a population. Not one of the three is optional. Take a real shape from this invented bank's record. The collateral valuation control in process PR3 did not operate for 11 working days. Three hundred and forty loans were wrongly marked as a result. No monitoring control detected any of it. All three are present: the days can be counted, the loans can be counted, and anybody who disagrees has to disagree with the working papersThe file of evidence a tester keeps: what was sampled, what was seen, and what was concluded from it, kept so that somebody who was not there can check the reasoning later. rather than with the writer.

A condition that does not survive reads like this instead: controls in this area are weak and need strengthening. Every word of that might be true. None of it can be checked, argued with, or acted on. There is no population, so nobody can tell whether two loans or two thousand were affected. There is no date, so nobody can tell whether the problem is running now or ended in month 3. There is no fact, only a judgement dressed up as one. A condition that cannot be re-counted by somebody who was not there has already given up the one advantage an audit finding has over an opinion.

The population matters more than people expect, and the reason is unglamorous. When a finding says that 340 loans were wrongly marked, a reader immediately wants to know 340 out of how many, drawn how, over what period. If the tester looked at 340 loans and all 340 were wrong, that is a very different institution from one where 340 out of forty thousand were wrong. AF4 will later have to size the effect and cannot invent a denominator that AF1 never supplied, so the condition is the only place that ratio can honestly live. The same discipline keeps a finding from quietly growing in the retelling: the number in the condition is a counted number, and a counted number does not get rounder as it travels up a management chain.

Where do the criteria come from, and what happens without them?

AF2, the criteriaWhat should have been, together with where that expectation came from. A finding that states no source for its expectation is stating a preference., is the rule the condition is measured against. Practitioners skip the criteria most casually, and its absence does the most quiet damage. A finding with no criteria is not a weak finding. Such a finding is a different kind of document altogether.

Go back to the housing society. Four months carry no signature. Against what? If the society's own maintenance rule says a monthly service with a signature, the four blank months are a gap against a stated rule and there is nothing to argue about. If the rule says nothing at all about signatures, and the committee member simply expected them because that is how their previous building did it, then the four blank months are a gap against a preference. Both write up identically and only one of them obliges anybody to do anything. The technician who says, reasonably, that nobody ever asked for signatures has completely answered the second version and has not touched the first.

So the criteria have to name their source, and there are only a few places a legitimate source can come from. The table below sets them out as this invented bank would use them, from the narrowest to the broadest.

Where the expectation came fromWhat it looks like in a findingHow strong it is
The control objective itselfThe control exists so that no advance is carried at a stale valueStrongest. The control was built for that reason.
A written procedure the process maintainsThe procedure requires the feed to be reconciled before the book is markedStrong, and checkable by anybody.
One of the nine policies PL1 to PL9The policy requires a named owner for every data element that feeds a reportStrong, and approved above the process.
A stated external requirementNamed with the body that issues it, and read at the source rather than quotedStrong, and outside the institution's gift.
Nobody's expectation in particularThe process is inefficient and should be automatedNot criteria at all. A preference wearing the clothes of a rule.

Notice what the last row costs. If a finding rests on a preference, the correct management response is a conversation, not an action, and a management team that agrees to an action anyway has agreed to spend money to satisfy somebody's taste. Institutions that let this happen for a few years end up with a remediation queue full of work nobody can justify and a testing team nobody quite trusts. Stating the criteria is not paperwork. Stating the criteria is what makes a finding binding on somebody other than its author.

Try it out

A finding says that a process is inefficient and should be automated. Which part is missing, and why does it matter?

Why does the cause decide whether anything can actually be fixed?

One difference sets AF3 apart from its four neighbours, and it is worth stating flatly. AF1, AF2, AF4 and AF5 can all be produced by somebody who never sets foot inside the process. AF1 is counted. AF2 is read off a rule. AF4 is arithmetic on a base. AF5 is a sentence somebody else agrees to. AF3 is different in kind: it is a claim about a mechanism, and mechanisms are not visible in evidence. Evidence shows what happened; only reasoning shows what would make it happen again.

The test of a cause is therefore a future test rather than a past one. The proposed cause is written down, and a single question is put to it: if exactly these conditions arrived again next month, would the failure recur? If the answer is yes, what has been written is not the cause, however true it is. Suppose the finding at the housing society records that the technician forgot. Would the technician forget again next month, under the same arrangement, with the same reminders and the same register sitting in the same drawer? Almost certainly. So forgetting is not a cause; it is a restatement of the condition with a person's name attached to it.

One layer down, the shape changes. Perhaps the register lives in the society office, and the office is locked when the technician arrives on a Sunday morning. Perhaps the four blank months are the four months the office secretary was away, and nobody else has a key. A locked office is a cause: it can be acted on, and the failure genuinely stops. It is far less satisfying than forgetting, and far more useful. A cause is almost never about attention and almost always about an arrangement. An arrangement takes work to find, so the box so often ends up holding a description of somebody's state of mind instead.

One consequence surprises people new to the craft: a good cause frequently makes the institution look better, not worse. Nobody was careless. The arrangement made the failure available, and the arrangement was built by people acting sensibly at the time. An arrangement is a far more comfortable thing to put in front of a committee than a suggestion that somebody was not trying, and it is also the only version anybody can do anything about. A finding that names a person has produced a consequence for one individual and a repeat performance for the institution.

Try it out

A finding records that a reconciliation was not performed in four of twelve months, and the agreed action is that it will be performed monthly in future. What is missing?

Breaking Into Quants Bootcamp — Fin Maverick

Is an earlier warning the same thing as a cause?

One mistake produces the most convincing wrong answers of all. The event being confused with a cause is genuinely important and genuinely damning. An antecedentAn earlier event that carried the same information as the failure which followed it. It proves the failure was foreseeable and says nothing at all about why it occurred. is an earlier event that carried the same information as the failure that followed it. The antecedent is the near miss that nobody linked, the small version four months before the large one, the complaint that was closed rather than read.

Vindhya Commercial Bank Limited has an exact instance in its record. In month 6, the collateral valuation feed went stale for 2 working days. A data quality check caught it. Nobody raised it as an issue. The bank calls that near miss N3. In month 10, the same feed went stale for 11 working days, 340 loans were wrongly marked, and no monitoring control detected any of it. The second one is incident I10, and it is the failure behind the year's single most serious finding.

N3 establishes three things and fails to establish a fourth. The near miss proves the failure was available to be seen, four months before it arrived at full size. It proves the institution's detection worked once and its escalation did not. It proves that somebody, somewhere, made a decision to treat a caught problem as closed rather than as a signal. All three of those are facts, and all three belong in a finding. Not one of them says why the feed goes stale, why no monitoring control fired in month 10, or why a catch in month 6 went nowhere. An antecedent is evidence of foreseeability. A cause is an account of a mechanism. Putting the first in the box reserved for the second fills the form and answers nothing.

The same feed, twice, and only one of the two is a cause One invented bank, twelve numbered months, one collateral valuation feed. NEAR MISS N3, MONTH 6 INCIDENT I10, MONTH 10 1 2 3 4 5 6 7 8 9 10 11 12 stale for 2 working days caught, and never raised stale for 11 working days 340 loans wrongly marked four months later WHAT N3 SHOWS The feed had gone stale before. A check caught it that time. Nobody raised it as an issue. So the failure was foreseeable. WHAT A CAUSE WOULD SHOW Why does the feed go stale? Why did no monitoring control fire? Why did the earlier catch stop there? None of these is recorded. An antecedent sits on the timeline. A cause sits underneath it, and this record holds only the first.
The earlier event establishes that the same failure had already appeared in miniature and been let go, which is damning and is still not an explanation, because none of the four things it proves answers any of the three questions on the right.

There is a practical tell for this confusion, and it works on any finding at all. The cause box is read out loud and checked for a date. Causes are timeless: an arrangement, a gap in a rule, a step that only one person can perform. Antecedents are dated: in month 6 this happened, last quarter that was reported. If the cause box has a date in it, somebody has almost certainly filed a piece of history where an explanation was supposed to go. That is not a rule of the craft, it is just a reliable symptom, and it takes about four seconds to apply.

Try it out

The same collateral valuation feed went stale for 2 working days four months before it went stale for 11. Does that earlier event supply the cause?

Risk Management Program Bootcamp — Fin Maverick

What does the effect actually measure, and against what base?

AF4, the effectWhat the condition could lead to, sized against a named base. It describes exposure created by a control not working, not the money that happened to be lost., is where findings most often become either alarming or invisible, depending on who is writing. The rule that keeps it honest is short: the effect describes exposure, not the loss that happened to be booked.

Exposure and booked loss are wildly different numbers, and it is worth seeing how far apart they can sit. When the collateral valuation control at this invented bank failed for 11 working days, the net operational loss booked against that event was Rs 1.4 crore, and no customer lost money. If the effect were written as the loss, the finding would read as a minor administrative slip. The control actually sits on the valuation of Rs 8,640 crore of secured advances. Nothing about that Rs 8,640 crore was lost, and nothing about it was even necessarily wrong. The figure is simply the size of the book whose marks depend on a control that stopped working with nobody watching. An effect is a statement about what was exposed, and it is a much larger and much more useful number than what happened to leave.

And now the discipline that stops the larger number becoming dishonest. A share needs a denominator, so Rs 8,640 crore on its own is a figure without a meaning, and this particular figure has two very clean denominators. Against net advances of Rs 57,600 crore it is exactly 15.0 per cent. Against total assets of Rs 96,000 crore it is exactly 9.0 per cent. Both are correct, both come out to a round decimal, and they leave a reader with two quite different impressions of how much of the institution is involved. A share whose base is not named in the same sentence has invited the reader to pick whichever number the writer wanted them to feel. The base belongs beside the figure, net advances or total assets, rather than three paragraphs further down in a footnote.

One block of rupees, two bases, two honest answers Both bars are drawn on the same rupee scale, so the red block is physically identical on each. NET ADVANCES, Rs 57,600 CRORE 15.0 per cent TOTAL ASSETS, Rs 96,000 CRORE 9.0 per cent Rs 8,640 crore of secured advances, the identical block on both bars Both shares are exact. 8,640 over 57,600 is 15.0 per cent and 8,640 over 96,000 is 9.0 per cent. The block never moves. Only the bar behind it changes, and only the base says which was meant.
The red rectangle is the same rupee amount in both rows and the bar behind it is not, which is the whole reason a share quoted without its base can be doubled or halved without anybody writing down a false number.

There is a second habit inside AF4 that separates a careful finding from a dramatic one. The effect did not necessarily happen, so it is written in the conditional. The valuation of Rs 8,640 crore of secured advances could have been wrong, and the record does not say by how much. A wrong collateral mark does not become a misstatement one for one either. The mark feeds a provision, the provision feeds a reported number, and the record here does not measure the several steps in between. The honest effect names the size of the book the control sits on and stops, and every attempt to convert that into a loss without the intervening arithmetic is somebody guessing in public.

Try it out

A finding says the effect is Rs 8,640 crore. What is wrong with that sentence?

Who writes the recommendation, and who has to carry it?

AF5 is really two documents sharing a box. The recommendation is what the tester thinks should happen. The agreed actionWhat management commits to do, distinct from what the tester recommended. It carries a named person inside the process and a date, and it is the only part of a finding somebody signs up to deliver. is what management commits to do, and the two are frequently not the same sentence. The divergence is not a malfunction. A tester who has spent three weeks on one process is often the person least qualified to judge what is practical across nine of them, and a recommendation that survives contact with the business unchanged should raise a mild eyebrow rather than a cheer.

Two properties of the agreed action are not negotiable, and both are about who, rather than what. The first is that it carries a named individual and not a department. Naming a department produces an action that four people believe somebody else is doing. The second is that the named individual sits inside the process, never inside the testing team. The second property catches people out. The tester is the person who understands the finding best and is often keen to help. If the person who wrote the finding is also the person accountable for fixing it, then at the retest there is nobody left in the building who can say no. The independence that made the finding worth having evaporates at exactly the moment it was about to be tested.

The date is the third element and it is the least interesting until a finding arrives without one. An action with no date is a statement of intent, and a statement of intent cannot be overdue, cannot be escalated, and cannot appear on any report of what is late. Vindhya runs an open issue population of 92 with an ageing profile and an overdue count, and every one of those measurements depends on a date having been agreed at the moment the finding was accepted. A finding that leaves the date to be settled later has quietly removed itself from every list on which it might otherwise have appeared.

What is a rating on a finding actually for?

Every finding gets a rating, and this is the point at which readers most often assume something about it that is not true. A rating is not a measure of money. Nor is it a measure of how angry anybody is. A rating is a name for how seriously the write-up is to be treated, drawn from a scale the institution set for itself in advance so that the seriousness of a finding is decided by a stated rule rather than by whoever is loudest in the room.

Vindhya uses its own four point scale: D1 an observation, D2 a deficiency, D3 a significant deficiency and D4 a material weakness. Its year produced 42 findings, and they sit 18 at D1, 16 at D2, 7 at D3 and 1 at D4. Those four counts sum to 42. The single D4 is 2.4 per cent of the findings and 1 of the 214 key controls, being 0.5 per cent of the population. Both those shares are rounded to one decimal from exact fractions, and the counts underneath are exact.

A scale sorts findings for routing and language. A D1 changes what somebody does next week. A D4 changes what has to be said out loud, to whom, and in what document. The scale exists so that those consequences follow from a stated definition rather than from a judgement made freshly each time by whoever happens to be writing. Where a given finding belongs on that scale is a genuine and difficult judgement. The scale is named here; deciding which step a weakness sits on, and what turns one into the most serious step of all, are each covered separately.

The tag travels upward. The five parts stay where they were written WHAT THE SUMMARY LINE CARRIES The year's 42 findings: 18 at D1, 16 at D2, 7 at D3, and 1 at D4 WHAT THE RATING IS FOR A rating is a name for how seriously a finding is to be treated, on this invented bank's own four point scale. It is not a measure of money and it is not a substitute for the cause. WHAT SITS BEHIND ONE TAG AF1 condition, recorded AF2 criteria, recorded AF3 cause, not recorded AF4 effect, recorded AF5 action, recorded Deciding which step of that scale a given finding belongs on is a separate judgement, made elsewhere.
A rating is the only part of a finding compact enough to reach a summary line, so the tag arrives at a committee while the five parts that produced it stay in a file nobody at that table has opened.

What does the year's most serious finding look like written out?

The structure is easier to trust once it has been seen done. The single D4 finding this invented bank raised in its year, written into the five parts using nothing that is not in the record, does that work. Four of the boxes fill. One does not, and it stays empty rather than holding something merely plausible.

AF1, the condition: the collateral valuation control in process PR3 did not operate for 11 working days, 340 loans were wrongly marked, and no monitoring control detected it. AF2, the criteria: the valuation used to mark secured lending must be current, and a monitoring control exists so that a stale feed is noticed. AF4, the effect: the valuation of Rs 8,640 crore of secured advances was affected, being 15.0 per cent of net advances of Rs 57,600 crore and 9.0 per cent of total assets of Rs 96,000 crore. AF5, the recommendation: an agreed action, an owner inside process PR3, and a date.

And now AF3. The record holds exactly one relevant fact: the same feed went stale for 2 working days four months earlier, a data quality check caught it, and nobody raised it as an issue. The record calls that near miss N3 and, as the timeline above set out, it is an antecedent and not a cause. It establishes that the failure was foreseeable. It says nothing about why the feed went stale, why no monitoring control fired, or why a catch went nowhere. The invented record states no cause for this finding, so the box stays empty, and refusing to fill it is the single most useful discipline in the whole craft.

The year's one finding at D4, written out from the record Every line below comes from one invented bank's own record. One box has nothing to put in it. AF1 THE CONDITION The collateral valuation control in process PR3 did not operate for 11 working days. 340 loans were wrongly marked and no monitoring control detected it. AF2 THE CRITERIA The valuation used to mark secured lending must be current, and a monitoring control exists so that a stale feed is noticed. AF3 THE CAUSE Not recorded. The record holds an earlier event and no explanation. AF4 THE EFFECT The valuation of Rs 8,640 crore of secured advances was affected, being 15.0 per cent of net advances of Rs 57,600 crore and 9.0 per cent of total assets. AF5 THE RECOMMENDATION An agreed action, an owner inside process PR3, and a date. The record names that shape and no wording for it is invented here. Four boxes fill from the record. The fifth stays empty because nothing in the record answers it.
Four of the five boxes fill straight out of one invented bank's own record and the fifth cannot, which is what a finding looks like at the exact moment somebody has to decide whether to write a guess or leave a gap.

How does a finding differ from the remediation that follows it?

A finding and the work that follows it are so often bundled into one conversation that the distinction gets lost, and losing it is expensive. The finding and the remediation are two documents about two different stretches of time, written by two different people, and true in two different ways.

Audit Finding vs Issue Remediation, laid side by side

The finding is a statement about a period that has already closed. The finding rests on evidence gathered from days that have been and gone, and nothing anybody does from here can change whether it is accurate. Its author is somebody outside the process, and that author cannot be the person who agrees to fix it. The remediation is the opposite object on every axis: a commitment about a period that has not begun, resting on intention rather than evidence, written by a named person inside the process, and not yet true about anything. Nothing that happens to the second one can make the first one stop being the case.

The response is therefore a separate document rather than an edit. Management writes back, and it can say one of three things. Management can agree, in which case the agreed action, the owner and the date become the commitment. A second response is partial agreement: the condition accepted, the effect or the rating disputed. Partial agreement is normal and healthy. Or it can disagree outright, and here is the part people find counterintuitive: the finding does not go away. The disagreement is recorded beside it, both documents travel together, and the reader gets to see the argument rather than one side of it. Where disagreement deletes findings, the survivors are exactly the ones nobody minded, so the process very quickly has no findings worth reading.

Two documents, two clocks, and two people who cannot be the same person Identical rows. Every single one of them comes out the other way round. THE FINDING THE ISSUE ITS SUBJECT Evidence about a period that has already closed A commitment about a period that has not started ITS TENSE Past. It happened. Future. It will happen. WHO WRITES IT Somebody outside the process, from evidence The named person inside the process WHO MAY NOT WRITE IT The people who ran the control it is about The person who wrote the finding Disagreeing with the right hand column does not touch a single word of the left hand one.
Every row comes out the other way round, which is why the two documents cannot be merged into one and why the person who wrote the left hand column is disqualified from being the name at the bottom of the right hand one.
Try it out

Management disagrees with a finding. What happens to the finding?

What is actually being asserted at each step of the chain?

One control failing on a sample of days sets off a short chain, and each link in it is a different kind of claim. Treating a closed issue as evidence that a control works is one of the most common mistakes in the whole practice, and seeing the five links separately is what stops it.

The chain runs: a test result, then a finding, then a rating, then an issue, then a retest. The test result asserts that the control did not work on the days somebody looked. The finding asserts an account of what went wrong, in five parts. The rating asserts how seriously that account is to be treated. The issue asserts what will be done, by whom and by when. The retest asserts whether the control works now. Five statements, made at five different moments, and not one of them can be substituted for any of the others.

One control, five claims, five different moments Underneath each box is what that step actually asserts, in the words it would use. TEST RESULT a control failed on the days somebody looked THE FINDING five parts, written up by the tester THE RATING a name for how seriously it is treated THE ISSUE an owner and a date, agreed by the process THE RETEST a later test of the same control it did not work then here is what went wrong here is how serious it is here is what will be done it works now, or still does not Five statements about one control, made at five different moments, asserting five different things. Nothing later in the chain re-opens anything earlier in it, and a closed issue is not a working control.
Reading left to right, the thing being claimed changes at every arrow, so a reader who sees only the last box has been told that somebody delivered what they promised and has not been told whether the control now works.

The last link is the one people over-read. A retest asserts something about the days it sampled after the fix, and it does that honestly. A retest does not assert that the cause was found. A control can pass a retest for the same reason it passed for years before it failed: nothing happened to test it. The only way to know whether a repair reached the cause is to have written a cause down in the first place and to check the retest against that, and this is exactly where the nine blank boxes at this invented bank come home.

What does this bank's population of 42 findings look like?

Numbers make the shape concrete, so here is the year at Vindhya Commercial Bank Limited. Independent testing produced 42 findings. Sixteen of them are design gaps at stage CL3, meaning the control as designed would not have achieved its objective even if somebody performed it perfectly every time. Twenty six of them are operating failures at stage CL4, meaning the design was sound and the doing was not. Sixteen plus 26 is 42, and the finding count equals the failure count exactly because this institution writes one finding per failed control. The equality is a choice about drafting conventions, not a law, and an institution that grouped three related failures into one finding would report a smaller number about an identical year.

Now the number that matters most. Nine of those 42 findings carry no cause at all. Nine of 42 is 21.4 per cent, so better than one finding in five records what happened and never records why. Each of those nine has an agreed action written against a blank, and this invented record does not say which nine they are. The record also does not say how they split between the 16 design gaps and the 26 operating failures, and what can still be said in the face of that is set out below. A finding process that leaves the cause box empty on more than a fifth of its output has not produced 42 explanations, it has produced 33.

One year of findings, cut two different ways The same 42 findings appear in both bars. Only the question being asked of them changes. THE 42 FINDINGS, CUT BY WHAT FAILED 16 design gaps at CL3 26 operating failures at CL4 The two cuts do not line up, and this invented record never says how they overlap. THE SAME 42, CUT BY WHETHER A CAUSE WAS WRITTEN 9 with no cause 33 carrying a cause 9 of the 42 findings, being 21.4 per cent of them One failed control produced exactly one finding here, so 16 plus 26 is both the failure count and the finding count. This 42 counts findings, and is not the Rs 42.0 crore gross loss of incident I2 nor the 42 issues open beyond 90 days.
Both bars hold the same 42 findings and the two divisions in them are deliberately drawn out of alignment, because this invented bank never recorded which of its causeless findings were design gaps and which were operating failures.
Try it out

How many of this invented bank's 42 findings carry no cause, and what share of them is that?

Hypothesis Testing — free micro-course from Fin Maverick

Can a rate nobody ever measured still be pinned down?

One situation arises constantly and almost nobody handles it well. Somebody asks a reasonable question about the 42 findings: are the causeless ones mostly design gaps or mostly operating failures? The answer matters. If the blanks cluster in one kind of failure, that says something about where the thinking stopped. And the answer is that this invented bank never measured it. The record holds 9 causeless findings, 16 design gaps and 26 operating failures, and no crossing between them.

The wrong move at that point is to guess and present the guess. The right move is to notice how much survives being unmeasured. Call the unknown j, the number of the 9 causeless findings that are design gaps. j must be a whole number between 0 and 9. The causeless rate among design gaps is then j over 16, and the causeless rate among operating failures is 9 less j over 26. Both are fully determined by j, so moving j across its whole range shows everything the record permits.

Try it out

Nine of the 42 findings carry no cause. They split somehow between 16 design gaps and 26 operating failures. Before the control is moved: is there a split on which the two causeless rates come out equal?

Play with it

Move the split that nobody measured, and watch the two rates refuse to meet

One variable moves: j, how many of the 9 causeless findings sit among the 16 design gaps rather than among the 26 operating failures. Everything else is held: 42 findings, 16 design gaps at stage CL3, 26 operating failures at stage CL4, 9 findings with no cause recorded. The split j was never measured at this invented bank and appears nowhere in its record. The control is here for exactly that reason.

j of 0j of 3j of 9
Two causeless rates, and the line they would have to meet on 18.8 per cent 23.1 per cent 0 10 20 30 40 50 60 21.4 per cent AMONG THE 16 DESIGN GAPS AMONG THE 26 OPERATING FAILURES j of the 9 causeless findings 9 less j of the 9 causeless Split set to j of 3: 3 of the 9 causeless findings sit among the 16 design gaps.
HELD CONSTANT
9 of 42
AMONG THE 16 DESIGN GAPS
18.8 per cent
AMONG THE 26 OPERATING FAILURES
23.1 per cent
GAP BETWEEN THEM
4.3 points
With 3 of the 9 causeless findings sitting among the 16 design gaps, the two causeless rates are 18.8 per cent and 23.1 per cent, and they are not equal. The design gaps come out lower, and the population rate of 21.4 per cent sits between the two.
Educational illustration. Four readings in plain words, so they survive without the control. At j of 0 the rates are 0.0 per cent among the 16 design gaps and 34.6 per cent among the 26 operating failures. At j of 3 they are 18.8 and 23.1 per cent, the closest they ever come at 4.3 percentage points apart. At j of 4 they are 25.0 and 19.2 per cent, and the order has flipped. At j of 9 they are 56.3 and 0.0 per cent. The two rates would be equal only where 26 times j equals 144 less 16 times j, at j of 3.43, and findings come in whole numbers, so there is no possible split on which they meet. The population rate of 9 over 42, being 21.4 per cent, sits between the two at every whole value of j. The split j was never measured and is not in this invented bank's record. Every count belongs to Vindhya Commercial Bank Limited and to no real institution.

Watch what that does to the conversation. Nobody has to guess, nobody has to say the data is not available and stop, and nobody has to pretend to a number. Out comes a set of statements that hold on every possible reading: the two rates are never equal, they come closest at 4.3 percentage points apart, they swap places between three design gaps and four, and the population rate of 21.4 per cent is always the one sitting between them. The height at which the two lines would have crossed is exactly the population rate itself. A rate on the whole is always a weighted blend of the rates on its parts, so the crossing point is the same arithmetic seen from the other side.

Two rates that step straight past each other j runs across every whole number of findings from 0 to 9. There is no tick under the crossing. 0 10 20 30 40 50 60 0 1 2 3 4 5 6 7 8 9 the only place the rates could meet j = 3.43, and findings are whole the 16 design gaps, j of 16 the 26 operating failures, 9 less j of 26 the population rate, 21.4 per cent j, how many of the 9 causeless findings are design gaps At j of 3 the rates are 18.8 and 23.1 per cent. At j of 4 they are 25.0 and 19.2 per cent. The height they would have met at is exactly the population rate itself, and no whole j reaches it.
The rising line and the falling line pass each other between the third tick and the fourth, so the point at which they are equal sits at a split of findings that could not exist, and the dashed line shows that point landing exactly on the rate for the whole population.

Agreeing an action that answers the condition instead of the cause

The commonest thing in any findings pack does not look like a failure at all. The action looks decisive. The condition said that 340 loans were wrongly marked, so the agreed action re-marks the 340 loans. An owner is named inside process PR3. A date is set. The evidence is produced. The issue closes on time and somebody signs it off. Every single part of that is correct work, and none of it touches whatever let the feed go stale for 11 working days with no monitoring control noticing.

The test that catches it is short enough to apply in a meeting and almost nobody applies it. Read the agreed action, then ask what would happen if exactly these conditions arrived again next month. If the honest answer is that the same failure would occur and be caught the same way, the action is a patchAn action that removes this instance of a failure and leaves whatever produced it entirely untouched, so it can close on time with full evidence and change nothing. rather than a repair. Nine of this invented bank's 42 findings carry no cause at all, so nine agreed actions were written against a blank box, and the record does not say which nine they are.

And the reason it happens is not laziness. Naming it as laziness therefore never fixes it. AF1 can be counted, AF2 can be read off a rule, AF4 is arithmetic and AF5 is a negotiation. AF3 is the only part that requires somebody to sit down and think about a mechanism, and a findings process running against a reporting deadline drops the part that needs thinking before it drops anything else. Institutions that fix this do not exhort people to try harder. The fix is structural. The cause box goes in front of the recommendation box on the form, a finding that leaves it empty is not accepted, and a matter of diligence becomes a matter of sequence.

A clean closure on the left, and nothing at all changed on the right Both panels describe the same finding at the same moment, three months after it was raised. THE AGREED ACTION Re-mark the 340 loans. An owner named in process PR3. A date agreed. Evidence produced at the retest. The issue closes on time. CLOSED, WITH EVIDENCE Every part of that is correct work. WHAT PRODUCED IT Whatever let the feed go stale. Whatever let it run 11 working days with nothing noticing. Whatever let a caught warning in month 6 go nowhere. STILL EXACTLY THERE None of it was touched. Read the agreed action, then ask what happens if the same conditions arrive next month.
The left panel is a genuine piece of delivered work that closes on time with full evidence behind it, and the right panel is what the institution still contains on the morning after that closure was signed off.
Hypothesis Testing teaches you to run a test, say what it can and cannot support, and recognise a manufactured result.

What can a finding never establish?

Three things, and each one is the kind of limit that only bites when somebody forgets it.

The first is anything about a control that was never tested. Vindhya's 42 findings came out of a population of 214 key controls chosen in advance of any testing at all. Nothing outside that 214 was ever on the sheet, so nothing outside it was ever going to produce a finding, however badly it was working. A finding count is bounded by the testing plan long before it is bounded by the quality of the controls, and only one of those two bounds ever gets printed beside the number. An institution that had called 300 things key would very likely have reported a bigger number and had a better year. The thought is uncomfortable and entirely correct.

The second is whether the cause written in the box is the right cause. A finding records that somebody made a claim about a mechanism. A finding does not evidence that claim in the way it evidences the condition. Mechanisms are not the sort of thing a sample can prove. A cause is therefore worth arguing about at the moment it is written and almost impossible to argue about a year later, when the action has closed and the report has gone.

The third is how the failure it describes compares with the ones that were tested and passed. A single finding is a report on one control. It says nothing about the twenty other controls in the same process that were tested and held, and nothing about whether this one failure is a symptom of something broad or an isolated event. The comparison lives in the population, never in the individual document. Nobody should ever form a view of an institution from one finding read on its own.

Try it out

A year produces 42 findings across a chosen population of 214 key controls. What does that count say about the controls nobody tested?

Debt Capital Markets Bootcamp — Fin Maverick

How does somebody outside a risk function ever use this?

Most readers will never write an audit finding. Almost all of them will, constantly and often without noticing, read documents built on exactly this skeleton and decide how much weight to put on them. A school circulates a note about a transport incident. A housing society issues a report on a water leak. A hospital sends a letter after a complaint. A lender receives a covenant compliance certificate. An analyst reads a paragraph in a set of accounts about controls. Every one of those is a finding, or is pretending to be one, and the five parts are the fastest way to tell which.

The method is thirty seconds long. Take the document and look for the five boxes. Is there a condition, with a date and a number in it, or only an impression? Is there a criterion, with a source attached, or only somebody's expectation? Is there a cause, or is there a dated earlier event standing in for one? Is there an effect, with its base named in the same sentence? Is there an action, with a person and a date, or a department and a hope? A document that filled two of the five boxes has told its reader far less than its length suggests, so the single most useful question available to a non-specialist is which boxes this one actually filled.

The same method works at household scale, where nothing is at stake and the shape is identical. A garage reports that the brakes were checked. Checked against what specification, on what date, by whom, and what were the readings? A landlord says the wiring has been looked at. A contractor says the waterproofing is sound. In every case the same five questions apply, and in most cases what turns up is a condition with no population, no criteria at all, and an action with no name on it. None of that is a reason to distrust anybody. It is a reason to know exactly how much the document can carry, and knowing that is far more useful than a feeling.

Now the reading that matters for money. A lender reading a borrower's control environment, an investor reading a paragraph about internal controls, a board member reading a findings pack, and a depositor choosing where to put savings are all doing the same thing: converting somebody else's written conclusion into a decision. The most valuable habit any of them can develop is to look for the cause box and to notice when what is in it has a date in it. An institution whose findings routinely record what happened and not why has a remediation programme that is genuinely busy and is not getting anywhere, and the only visible symptom is a set of closed issues and a list of problems that keeps coming back with different dates on it.

One closing habit, from this invented bank's own year. The same collateral valuation feed failed twice, four months apart. The first time it was caught and closed. The second time it ran for 11 working days and produced the most serious finding of the year. Nothing about the second event was new information. When a finding is handed over, the most productive question is not how bad is this, it is has this institution seen this before and what did it do with it then.

Where the expectation comes from

India, and where the binding text is stated

The five part structure of a finding is a matter of craft and belongs to no jurisdiction. Jurisdiction enters with the surrounding duty to report on internal control at all. In India, the reporting duty on internal financial controls sits in the Companies Act, and the text, who it applies to, who is exempt and the form the report takes all come from the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note behind independent work on controls come from the Institute of Chartered Accountants of India at icai.org. The additional duties on a bank, including the standing of its internal audit function and its arrangements for internal control, come from the Reserve Bank of India at rbi.org.in. The four point scale D1 to D4 and every count above belong to Vindhya Commercial Bank Limited alone.

How a root cause is actually analysed, as a method with steps somebody follows, is covered separately under operational risk. The nature of the cause, why it is structurally different from the other four parts, and what a finding without one can and cannot buy are treated above. Issue management as a process is covered there too, as is the near miss register and how a near miss is recorded, and near miss N3 appears here only as a record. How an issue is closed properly, and what a genuine repair looks like against a patch that closes on time, is covered under issue remediation. The judgement of which step of a four point scale a given finding belongs on, and what turns an ordinary weakness into the most serious step there is, are each covered separately. How a control is sampled and tested, and how a testing plan is built, are covered separately. Committee structure, charters and escalation are covered under risk governance. The audit of the financial statements themselves sits with accounting and audit.

Sources

SourceDocumentSite
Ministry of Corporate AffairsThe Companies Act duty to report on internal financial controls: the text, its applicability, the exemptions and the form of the reportmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standard and the guidance note behind independent work on controls, including how a deficiency is documented and communicatedicai.org
Reserve Bank of IndiaWhat binds a bank in India on internal control arrangements and on the standing and reporting line of its internal audit functionrbi.org.in

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

Covered in this topic

Subtopics

Audit Finding vs Issue Remediation
← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.