Corrective action follow-up process flowchart (audit findings)
Corrective action follow-up flowchart template: owner and due date, progress updates, extensions, overdue escalation, evidence verification, an effectiveness check after a review period, then closure or reopening.
What the corrective action follow-up process flowchart (audit findings) process is
Corrective action follow-up is the half of the audit cycle that runs after everyone has left the room. The finding is written, the root cause is agreed and the action has an owner and a date; from that point the process is about whether the commitment is kept, and whether keeping it changed anything. The chart below follows one agreed action end to end: the owner and due date assigned at close-out, the follow-up method set by the significance of the finding, the action logged in the register, progress updates posted against the date, the paths taken when the date slips or the action is never done, the evidence submitted and tested against what was agreed, an effectiveness check run after a defined review period, and closure with the status reported into management review.
This chart is neither the audit nor the investigation. How a finding is sampled, raised and reported belongs to the internal audit process; how a root cause is established and a corrective and preventive action plan is written belongs to the CAPA process, which closes against its own CAPA record, not an audit finding. This one starts where an action already exists and stops when the finding is closed or formally accepted as a risk. It also stops short of a full escalation ladder: one management step gets the overdue path somewhere to go; tiers, timescales and committee reporting for a serious finding belong to the audit finding escalation process. The boundary matters: a follow-up register rots when reopened items turn back into unscheduled investigations. If the action was carried out properly and the problem recurs, the root cause was probably wrong, and that belongs back in investigation rather than round this chart again. Treat the chart as a starting point to adapt to your own audit procedure and to your management system's and regulator's requirements, under competent review.
Seven decisions sit on the chart; four of them carry it. 'Major or minor finding?' sets how hard the follow-up will work: a significant finding earns an on-site verification visit before anything else happens, a minor one goes straight to the register. The IIA's 2024 Global Internal Audit Standards, effective 9 January 2025, point the same way, requiring follow-up assessments to be performed using a risk-based approach and the status of management's action plans to be updated in a tracking system. 'Action complete by the due date?' is the tracking gate, and it has three exits rather than two because in practice a date is met, moved or missed. 'Action implemented as agreed?' sits in the auditor's lane rather than the owner's, because the person who did the work is not the person who confirms it was done. And 'Action effective in practice?' sits at the far right on purpose: a separate check, run later, against a measure agreed in advance.
What this flowchart covers
In this template
- Five swimlanes (Auditor / follow-up owner, Action owner, Process owner, Quality and Management) across six phases: action plan agreed, tracking and updates, overdue and escalation, evidence and verification, effectiveness check, and closure and reporting
- A risk-based start: the "Major or minor finding?" decision books an on-site verification visit for a major finding and sends a minor one straight to the register, so follow-up effort is set by the significance of the finding rather than by habit
- Tracking with three honest exits, because "Action complete by the due date?" branches to Complete, Extension and Overdue, and the extension path runs through the follow-up owner's "Extension justified?" decision and one recorded date revision before rejoining the updates
- An escalation path that can end without the action ever being done: chasing an overdue item, an "Overdue past the escalation threshold?" decision, escalation to the accountable director, and a management "Re-plan or accept the risk?" choice with a documented accepted risk as its own terminal
- Verification as a step of its own in the auditor's lane: the owner submits evidence, the auditor tests it against the agreed action, and "Action implemented as agreed?" either moves the action into the effectiveness window or loops the gaps back to "Work through the agreed action steps"
- Effectiveness treated as a later check: "Set the effectiveness measure and review date" before the window opens, monitoring by the Process owner, then a records sample, and "Action effective in practice?" either reopening it for a fresh action where the cause still holds, or sending it to closure and management review
When to use this template
- You have a follow-up register full of actions marked complete, and no record of anyone testing whether they were done, let alone whether they worked
- Audit actions routinely slip past their due dates and you cannot say at what point a late action becomes somebody else's problem
- You are setting up follow-up for a new audit programme and want the tracking, verification and effectiveness steps agreed before you configure a tool
- An external auditor or certification body has asked how you verify corrective actions and how you decide that a finding may be closed
- Quality and internal audit both chase the same actions, so you need one chart that says who verifies, who approves an extension and who escalates
How it works
Rename the lanes to your roles
Replace Auditor / follow-up owner, Action owner, Process owner, Quality and Management with the roles you genuinely have. In a small organisation the follow-up owner and Quality are usually the same person, so merge those lanes rather than drawing a handoff that never happens. Keep the action owner and the process owner apart only where they really differ.
Set the follow-up method by significance
Write your own rule onto the first decision: which findings earn an on-site verification visit and a short due date, and which can be verified from documents at the next scheduled audit. Say who grades the finding and when, because a grade assigned after the action is already late is not a grade, it is a justification.
Agree the due-date and extension rule
Decide how due dates are set at close-out, how many revisions an action may have, who may approve one and what a request must contain. One recorded revision with a named approver and a written reason is a defensible default. Unlimited silent extensions are how a register fills with actions that are permanently almost finished.
Write your escalation thresholds onto the chart
Replace the placeholder wording on the escalation decision with your own trigger: days past the due date, a second missed date, or the risk rating of the finding. Name the role the action escalates to, and say what that person can actually decide, whether that is a new plan, more resources, or a formal acceptance of the risk.
Define the evidence verification will accept
List what the auditor will test for your common action types: a revised procedure with an issue date, training records, an approved change ticket, a sample of records produced since the change. Agreeing this at close-out rather than at follow-up is what stops the verification meeting turning into a negotiation about what counts.
Choose the effectiveness measure and the window
For each action, write down what would show the problem has stopped and how long the process must run before you look: a recurrence count, an error rate, a sample of transactions, a repeat audit of the same requirement. Set both before the window opens. The chart names no period on purpose, because the right one comes from how often the activity runs.
Walk it against a closed finding
Take two or three findings you have already closed, ideally one that closed cleanly and one that came back, and trace them through the chart. Any step people describe that is not drawn, and any box that is drawn but skipped in practice, is the finding worth acting on before you publish the process.
Frequently asked questions
What are the steps in a corrective action follow-up process?
An agreed corrective action arrives from audit close-out with an owner and a due date. The follow-up owner grades it: a major finding books an on-site verification visit, a minor one goes straight to the follow-up register, and either way it is logged there. The owner works through the agreed steps and posts progress updates. At the due date it is complete, extended once with a recorded reason, or overdue and chased; a chase past the escalation threshold goes to the accountable director, who re-plans it or accepts the risk. A completed action moves to evidence: the owner submits it, the auditor tests it against what was agreed, and gaps go back. Once implementation is confirmed, an effectiveness measure and review date are set, the process runs, records are sampled, and the action is closed with evidence or reopened. Open and closed actions are reported at management review.
What is the difference between verification and an effectiveness check?
Verification asks whether the agreed action was actually carried out. It is a narrow, documentary question answered close to the completion date: is the procedure revised and issued, were the named people trained, was the change approved, does the new control exist. An effectiveness check asks whether the problem stopped, and it cannot be answered the same day, because the process has to run and produce evidence. That is why the two sit in separate phases on this chart with a review period between them. The distinction matters because an action can be fully implemented and wholly ineffective: the procedure was updated, the training was delivered, and the same nonconformity is raised again at the next audit. ISO 9001:2015 makes the second of these explicit, requiring the organisation to review the effectiveness of any corrective action taken rather than only to record that it was taken.
Who should verify a corrective action, and what records does closure need?
Verification should be done by someone independent of the work, normally the auditor who raised the finding or whoever runs the follow-up programme, and not the action owner. That is why the 'Action implemented as agreed?' decision sits in the auditor's lane on this chart. For closure, keep enough that a stranger could reconstruct the decision a year later: the finding and its agreed action, the owner and the original due date, any revision and the reason for it, the evidence that was tested and by whom, the effectiveness measure, the review period and its result, and who authorised closure. ISO 9001:2015 requires documented information on the nature of the nonconformity, the actions taken and the results of any corrective action to be retained, and follow-up is where the last of those three is actually produced.
How long should you wait before checking effectiveness?
Long enough for the changed process to run often enough to say something. A daily transaction process may give you a fair sample within a month; a quarterly close, a seasonal activity or an annual supplier review will not, and checking those after four weeks tells you only that nothing has happened yet. Take the period from how often the activity runs and how much data you need, not from a standard interval that suits the register. Write the measure down at the same time, whether that is a recurrence count, an error rate, a sample size or a repeat audit of the same requirement, because a measure chosen after the review period tends to be the one the data happens to support. ISO 19011:2018 notes that verifying the completion and effectiveness of corrective actions may be carried out as part of a subsequent audit, which is often the practical answer where the window is long.
Can an audit finding be closed if the action is never done?
Yes, but only as an explicit decision, not by attrition. If management chooses not to implement an agreed action, the honest outcome is a documented acceptance of the risk, recording who accepted it, on what basis and when it will be revisited, not a register entry that stays open for two years and is quietly tidied away. This chart draws it as a terminal of its own so the two are never confused. Internal audit standards agree: the IIA's 2024 Global Internal Audit Standards make the chief audit executive responsible for determining whether senior management has, through delay or inaction, accepted a risk that exceeds the organisation's risk tolerance, and require an unacceptable level of risk to be discussed with senior management and escalated to the board if it is not resolved there. Resolving the risk is not internal audit's job; making sure the right people have decided about it is.