September 23, 2026
What an Audit Finding May Reveal About Your Finance and Operations Functions
Few phrases drain the energy from an insurance finance team faster than “the auditors found something.”
The first instinct is usually to contain it. Find the missing support, update the procedure, assign an owner, and get the response back to the auditor. The issue feels specific, and everyone would prefer to keep it that way.
Sometimes it is specific. A quarterly review may have been completed, but the sign-off was never saved. A reconciliation may have been late because the preparer was out on leave and no backup had been assigned. Those matters can often be corrected within the existing process.
Other findings point to a larger issue. A missed review may be the visible result of responsibilities that shifted months earlier, source data that now arrives later, or a reporting calendar that leaves too little time for a meaningful review. In those cases, adding another approval step may satisfy the immediate response while leaving the surrounding condition unchanged.
The finding marks where the concern became visible. Insurance leaders then need to understand how the work operates today, how far the issue reaches, and what kind of response the situation calls for.
Determine what changed around the control
Many control issues arise because the business has changed, but the control has not changed with it.
An insurer may introduce a new product, acquire another entity, or begin receiving data from an MGA or TPA in a different format. The finance team adjusts so reporting can continue, often by adding a spreadsheet, moving a review, or manually intervening to resolve exceptions. The written procedure may remain untouched while the monthly work takes a different path.
That gap can stay hidden until an audit tests the control or a key person departs.
An incomplete reconciliation may appear to be a documentation issue. A closer review may reveal that older items continue into the next period because finance lacks a defined escalation path. The missing support remains relevant, though the response may also need to address how exceptions are resolved.
A statutory accounting finding can reach further. Changes in claims information used for Schedule P may add new review steps across finance and actuarial, even though the original control still reflects an earlier process. The reviewer may be performing the required sign-off while relying on inputs that no longer follow the timing or format contemplated when the control was designed.
Leaders should understand the work from beginning to end before deciding on a response. That review should follow the information from its source through preparation, review, approval, and retention. It should also account for what happens when an exception remains unresolved near a reporting deadline.
Comparing the written procedure with employee descriptions and underlying records often reveals where the process drifted.
The review should distinguish among several conditions. The control may no longer address the risk, or employees may be performing an appropriate step inconsistently. In other cases, the work occurred without enough evidence or oversight, or decision rights remain undefined when an issue crosses departments. Each condition calls for a different response.
That distinction helps management avoid treating every finding as a request for another signature.
When the finding and the facts don’t match
Not every finding calls for a corrective response. Some call for a closer look at whether the finding itself was framed correctly.
The CFO or controller, often with input from internal audit and the audit committee, must make that determination. The insurer and the auditor may agree on the underlying facts while reaching different conclusions about the significance of the issue, the area affected, or the response required.
Consider a finding involving premium data received from an MGA. The auditor may conclude that the review was not detailed enough because several exceptions remained unresolved at period-end. Management may believe its monthly review addressed the relevant risk through follow-up with the MGA. The resolution to the exceptions could take months to correct, but the MGA has a documented and detailed follow-up process in place to mitigate material risks.
Resolving that disagreement requires a close look at the purpose of the control and the evidence retained. Management should be able to explain what the review was designed to accomplish, how it operated during the period, and how unresolved items were handled. The auditor’s concern also needs to be understood at the same level of detail.
An independent assessment may confirm the auditor’s conclusion. It may also find that the affected area is narrower than described, that existing safeguards deserve greater consideration, or that the proposed response exceeds the risk presented by the facts.
The same approach can apply to findings from internal audit or a regulatory examination. The insurer needs a supported position before agreeing to a course of action, especially when the proposed remediation would affect several teams or require a significant system change.
Follow the issue into the work that depends on it
A finding may extend into related activities when they depend on the same source data, reviewer, system, or approval structure. Leaders can examine those connections without reviewing every control across the company. The cited control is the starting point; from there, the CFO, controller, or internal audit leader should trace the information upstream to its source and downstream to the reports or decisions that rely on it.
A statutory reporting issue may also affect management reporting, capital analysis, reserve development updates, or audit schedules. A reinsurance accounting issue can reach further: recoverables, settlements, cash forecasting, Schedule F reporting, and counterparty reporting often draw on the same treaty data and the same employee’s interpretation of it. A vendor oversight finding may point to gaps in data completeness, regulatory obligations, service-level monitoring, or access and security reviews wherever that vendor’s data feeds finance. In each case, the principle is the same: trace the dependency, not the org chart.
A few questions can help define the scope:
- Where else is the same data used?
- Which activities rely on the same preparer or reviewer?
- Does the same manual step appear in another reporting cycle?
- Have similar exceptions appeared in prior audits or internal reviews?
A repeated finding can suggest that an earlier response corrected the cited item while leaving the surrounding cause in place.
Organize the response from assessment through follow-up
A durable response addresses both the cited item and the work around it. Four steps can help insurance leaders move from the initial observation to a revised control that operates under normal reporting conditions.
- Assess the issue
Define what occurred and where the concern sits in the day-to-day work. The review should distinguish among a control that no longer fits the process, a step that was performed inconsistently, and work that occurred without enough supporting evidence. The immediate correction may differ from the longer-term response. - Assign ownership
One person should coordinate the response, even when several teams are involved. The process owner, control owner, and remediation lead may be different people, so leadership should make decision rights and escalation responsibilities explicit from the start. - Document the response
The written record should explain what happened, why it happened, and how the work will operate going forward. It should also identify the responsible parties, timing, and evidence that will demonstrate the revised control has been performed. - Monitor completion
The insurer should test the revised control under normal reporting conditions and continue follow-up beyond the original remediation date. When the long-term solution depends on a system change, new hire, or revised data feed, interim procedures need their own support and review schedule.
Closing the finding is only one test
An accepted response and supporting documentation may close the finding administratively. A sustained response holds up across more than one reporting cycle. Employees understand their responsibilities, review evidence is retained consistently, and exceptions move through the escalation path management established. System access should also reflect any changes in ownership so the revised process does not depend on the prior arrangement.
Leadership can test the response with a simple question: would the control continue to operate if a key employee left, reporting volume increased, or a major deadline moved forward?
How Johnson Lambert helps move the response forward
Johnson Lambert’s Financial & Operations Advisory team helps insurance organizations assess the area surrounding an external or internal audit finding and organize the work that follows.
The team can help the insurer understand how the activity operates today and decide how far the review should extend. From there, we can help organize ownership, document the revised approach, and follow open matters through implementation.
When management and the auditor view an issue differently, Johnson Lambert can provide an independent analysis of the area under review and recommendations for a path forward. That assessment can help determine whether the concern is supported by the facts, whether the scope should be adjusted, and what response fits the level of risk involved.
An engagement may focus on one finding or a connected group of control and governance concerns.
An audit finding is one of several events that can change what insurance finance and operations teams are expected to manage. Download Maintaining Momentum Through 6 Critical Business Moments: A Guide for Insurance Organizations to explore other situations that can affect reporting, staffing, systems, governance, and strategic priorities.
Is a control or governance issue already demanding attention? Contact Johnson Lambert to talk through the finding, organize the response, or get an independent perspective on an area under review.
Frequently Asked Questions About Audit Finding Root Causes and Remediation
What does an audit finding actually indicate about my organization? An audit finding identifies where a control did not operate as intended, but it does not explain why. The cause may be limited to the specific item cited, such as a missing sign-off, or it may reflect a broader change in staffing, systems, process ownership, or documentation that has not yet been addressed. Reviewing what changed around the control, rather than treating the finding as an isolated task, is the starting point for understanding what it actually indicates.
How can insurance finance leaders determine what caused an audit finding? Reconstruct the work as it exists today, following the information from its source through preparation, review, approval, and retention. Compare the written procedure, what employees believe they follow, and what the underlying records actually show. Differences among those three versions often reveal where responsibilities shifted, source data changed, or a control no longer matches the current workflow.
Can management disagree with an audit finding? Management and the auditor may agree on the underlying facts while reaching different conclusions about the significance of the issue, the area affected, or the response required. Resolving that disagreement requires a close look at what the control was designed to accomplish, how it operated during the period, and how the auditor’s concern compares at the same level of detail. An independent assessment can confirm the auditor’s conclusion, identify a narrower affected area, or find that the proposed response exceeds the risk the facts support.
What should an insurer do if it disagrees with how an audit finding was framed? Management should first document the facts underlying the finding, the purpose of the control, how the control operated during the period, and how any exceptions were handled. From there, leadership can compare that record with the auditor’s rationale to identify where the disagreement lies, such as the significance of the issue, the area affected, or the scope of the proposed response. If the difference remains unresolved, an independent assessment can help evaluate the facts and support a well-grounded position before management commits to remediation.
How do you know if an audit finding affects other finance processes? A finding may extend into related activities when they rely on the same source data, reviewer, system, or approval structure. Tracing the cited control upstream to its source and downstream to the reports or decisions that depend on it can show whether the issue is isolated or shared. A statutory reporting issue, for example, may also touch management reporting or capital analysis, while a reinsurance accounting issue can extend to recoverables, settlements, or counterparty reporting.
What are the steps to responding to an audit finding? A structured response follows four steps: assess the issue and where it sits in the day-to-day work, assign one person to coordinate the response even when several teams are involved, document what happened and how the revised process will operate, and monitor whether the change holds under normal reporting conditions. The immediate correction may differ from the longer-term response, and both should be tracked separately.
Does closing an audit finding mean the underlying issue is resolved? Administrative closure confirms that management submitted an accepted response and supporting documentation. It does not confirm that the revised process operates under normal conditions after the original deadline has passed. A sustained response holds up across more than one reporting cycle, even if a key employee leaves, reporting volume increases, or a deadline moves forward.
When should an insurer bring in outside support for an audit finding? Outside support is often useful when the scope or cause of a finding is unclear, when management and the auditor view the issue differently, or when the proposed remediation would affect several teams or require significant change management. An independent review can help determine whether the concern is supported by the facts, whether the scope should be adjusted, and what response fits the actual level of risk.