Turning Audit Findings and Compliance Gaps Into Budget Language
Once a year someone from outside walks through your transfer estate, asks questions you had hoped nobody would ask, and writes down the answers. The document that results is the most valuable thing you will receive all year. Most administrators treat it as a telling-off. It is not a telling-off. It is a budget request, written for you, by a person the board already pays to be believed. It uses the exact language the board uses. All it lacks is the last paragraph.
This article shows you how to write that paragraph. It explains what an audit finding is and how it differs from an auditor's preference. It shows how a finding maps to a control and a control maps to a spend. It explains why you must use the auditor's words rather than your own. It also shows how to turn the report into a one-page memo that asks for a decision. It is part of our Business Case series. What the compliance frameworks themselves require, and what evidence an auditor will accept, live in their own series. They are linked where they matter.
What a Finding Actually Is
An audit finding is a documented gap between what a standard, regulation, policy, or contract requires and what the auditor observed. It has four parts: the requirement, the observation, the risk the gap creates, and a severity. "Supplier files are exchanged over an unencrypted service using a credential shared by multiple parties" is an observation. Attached to the policy clause it breaches and a rating of "high," that observation is a finding. The auditor's list of what they look for in a transfer estate is in what auditors ask about transfers. It is worth reading before the visit rather than after.
A finding usually arrives with a management response, which is the organization's written reply. The reply accepts the finding and commits to a fix by a date, or explains why the gap is tolerated. That response is signed by someone senior, which is the detail that matters for budget purposes. A finding with an accepted response and a date is a commitment the organization has already made in writing. You are not asking for money to do something new; you are asking for the money to do something already promised.
Severity ratings are the auditor's estimate of likelihood and impact in their own vocabulary. "High" typically means the gap could cause a serious loss or a regulatory breach and should be fixed within months. "Medium" means this cycle; "low" means when convenient. Do not inflate a medium to a high in your case. Auditors read business cases too. A rating that does not match their report costs you the one thing the report gave you: their credibility on loan.
The last piece of vocabulary is the control: any process, setting, or piece of software that closes the gap. Encryption in transit is a control. One login per partner is a control. A retained, reviewed log is a control. Findings describe the absence of a control; a budget request describes its purchase. That sentence is the whole translation, and the rest of this article is the mechanics.
Findings Map to Controls, Controls Map to Spend
The chain is short and it runs in one direction. A finding names a gap. A gap is closed by a control. A control has a cost, which has a shape: an up-front bump, a flat ongoing part, and occasional spikes. The business case walks the reader along that chain in three steps, and the diagram below shows it for Meridian Parts' highest-rated finding.
Two things about the chain are easy to get wrong. The first is skipping the middle box: going straight from "the auditor said X" to "so we need product Y." The reader cannot check that jump, and neither can the auditor at the follow-up. Name the control in plain words first, then say which options provide it. The second is letting the spend column contain only one option. A control can nearly always be provided in more than one way. You can fix the existing server's configuration or build the missing piece around the scripts. You can adopt a free or open-source tool or buy a commercial one. The finding does not care which. The reader does, and wants to see that you considered them.
Where a finding cites a regulation or framework by name, resist the urge to explain the regulation in the case. Quote the clause the auditor quoted and move on. You may need to understand what the framework actually requires of a transfer estate before you can name the control. In that case, why regulations care about file transfer is the short version. The article building a transfer control matrix is the method for lining every requirement up against every flow. The matrix is the long-form version of the table in this article; the business case needs only the rows with findings against them.
Using the Auditor's Own Words
Quote the finding exactly, with its reference number, its severity, and the date of the report. Do not paraphrase it into technical language, and do not improve it. "Finding 4.2 (high): supplier files are exchanged over an unencrypted service using a credential shared by multiple parties" is a sentence the finance director has already read. It is in a document they have already signed a response to. "The legacy FTP endpoint lacks transport encryption and per-principal authentication" is a sentence they have never seen. It makes them wonder whether it is the same problem. It is; but you have just spent their attention proving it.
The auditor's words carry three things yours cannot. They carry independence: the auditor has no stake in your budget. They carry the organization's own signature, via the management response. And they carry a deadline, because most responses commit to a date. Dates are the thing that moves a request from "consider" to "decide." A business case that opens with a quoted finding, its signed response, and its committed date has done most of its persuading in three lines.
The same applies to the evidence the auditor will want when they come back. Whatever control you propose, the case should say how its operation will be shown next year: the log, the report, the access review. Evidence auditors accept describes what that looks like. A control that cannot produce evidence closes the finding for a year and reopens it at the next visit. That is the expensive kind of closed.
Remember: the auditor wrote your problem statement for you, and someone senior signed it. Quote it, do not paraphrase it. Every word you change is a word the reader has to re-verify, and every word you keep is one they have already accepted.
The Difference Between a Finding and a Preference
Not everything in an audit report is a finding. Reports also contain observations and recommendations: the auditor's view of good practice, offered without a requirement behind it. "Management may wish to consider consolidating transfer services onto a single platform" is a preference. It may be excellent advice. It is not a gap against a standard, nobody signed a response to it, and there is no date. Treat it as advice, and say so in the case. Spending finding-grade urgency on a preference is the fastest way to teach a finance director that your urgency is negotiable.
The temptation runs the other way too. Vendor feature lists are written to look like control lists, with a checkmark next to every framework the marketing team could spell. We make transfer software, and our feature lists are no exception, so read this section with that in mind. A feature is a control only if it closes a specific gap the auditor named. Everything else on the list is a preference with a logo. When you map findings to options, map each finding to the specific capability that closes it. Ignore the rest of the sheet, however long it is. (It will be long.)
Here is a practical test for each line in the report. Does it cite a requirement? Does it carry a severity? Did someone sign a response with a date? Three yeses is a finding and goes in the table. Anything less is a preference and goes in a paragraph at the end of the memo headed "also recommended." There, it can be funded if the budget allows and ignored without consequence if it does not.
Template: The Finding-to-Control-to-Spend Table
One row per finding, in the auditor's severity order. The spend column holds a shape and the options that provide it, not a figure; the option you recommend is marked. Filled in for Meridian Parts' three transfer findings, it looks like this.
| Finding (auditor's words) | Response and date | Control that closes it | Spend shape and options | Evidence next year |
|---|---|---|---|---|
| 4.2 (high): "Supplier files are exchanged over an unencrypted service using a credential shared by multiple parties." | Accepted; remediation plan due before next review; signed by the operations director | Encrypted transfer service; one login per supplier; session logging; rotation on staff change | Bump: two weeks of one admin. Flat: within support line. Options: (a) reconfigure existing server if it supports SFTP, (b) open-source SFTP server, (c) commercial server. Recommend (c); (a) ruled out, see appendix | Per-supplier login list; sample session logs; rotation record |
| 4.5 (medium): "There is no record of transfer failures and no evidence that failures are detected within the business day." | Accepted; fix this cycle; signed by the IT manager | Job scheduler with retained run history and alerting on failure | Bump: one week of one admin. Flat: within support line. Options: (a) add logging and alerting to existing scripts, (b) scheduled-transfer tool with retry and notification. Recommend (b); (a) costed in appendix | Run history export; sample alert; monthly failure summary |
| 4.7 (low): "Transfer accounts for two former suppliers remain enabled." | Accepted; closed during the audit | Quarterly access review of transfer accounts | Bump: none. Flat: two hours a quarter. No purchase required | Signed quarterly review record |
Notice the third row. It costs nothing and asks for nothing, and it is in the table anyway. It shows the reader you have closed what you could close for free. That makes this a case they believe when it asks for money on the rows above. Notice also that the first two rows point at the same purchase from two directions. An encrypted server with logging closes 4.2, and a scheduler with alerting closes 4.5. If a single option provides both, the case should say so once, in the spend column, rather than asking for it twice. A commercial server such as Sysax Multi Server is one way to provide the first control. It offers SFTP, FTPS, and HTTPS with per-user authentication and activity logging. A carefully configured open-source SFTP daemon is another way. The table treats them as equals until the appendix argues otherwise.
Template: The Memo That Turns a Report Into a Request
The audit report is addressed to the board. The memo is addressed to whoever can approve the spend, and it is one page. It quotes the findings, states the controls, presents the options, and ends with a decision. Here is the skeleton, followed by Meridian's version.
MEMO: REMEDIATION OF TRANSFER-RELATED AUDIT FINDINGS To: [approver] From: [you] Date: [date] Subject: Findings [refs] from the [period] audit report: proposed remediation 1. Findings and commitments Finding [ref] ([severity]): "[auditor's words, verbatim]" Management response: [accepted / tolerated], due [date], signed by [name]. [repeat per finding] 2. Controls required [ref]: [control in one line] [repeat per finding] 3. Options and cost shape Option A, do nothing: findings remain open; [consequence at next review] Option B, fix what we have: [bump] + [flat]; closes [refs]; does not close [refs] Option C, replace: [bump] + [flat]; closes [refs] Ongoing costs expressed as a fraction of [existing budget line]. 4. Recommendation Option [x], because [one sentence]. 5. Also recommended by the auditor (not findings) [preference], [preference]. Not costed here. 6. Decision requested Approve option [x] and [specific first step] by [date], with a report back on [date] showing [the evidence in section 5 of the report].
MEMO: REMEDIATION OF TRANSFER-RELATED AUDIT FINDINGS, MERIDIAN PARTS
To: Operations Director From: IT (transfer services)
Subject: Findings 4.2, 4.5, 4.7 from this year's audit: proposed remediation
1. Findings and commitments
4.2 (high): "Supplier files are exchanged over an unencrypted service using a
credential shared by multiple parties." Accepted; plan due before next review;
signed by you.
4.5 (medium): "There is no record of transfer failures and no evidence that
failures are detected within the business day." Accepted; this cycle.
4.7 (low): "Transfer accounts for two former suppliers remain enabled."
Accepted; closed during the audit; quarterly review now in place.
2. Controls required
4.2: encrypted service, one login per supplier, session logging, rotation.
4.5: scheduler with retained run history and alerting on failure.
3. Options and cost shape
A, do nothing: 4.2 and 4.5 remain open; 4.2 will be reported as a repeat
finding, which the audit committee sees.
B, fix what we have: about three weeks of one administrator to add encryption
where the current server allows it and alerting to the
scripts; closes 4.5; closes 4.2 only partly (the current
server cannot issue per-supplier logins).
C, replace: about three weeks of one administrator to migrate twelve
suppliers and forty jobs; ongoing cost within the existing
support line; closes 4.2 and 4.5.
Neither B nor C changes headcount.
4. Recommendation
Option C, because B leaves the high-rated finding open at the next review.
5. Also recommended by the auditor (not findings)
Consolidating the two remaining departmental FTP servers. Not costed here.
6. Decision requested
Approve option C and a four-week pilot with two suppliers starting next
month, with a report back at the end of the pilot showing per-supplier
logins, session logs, and the failure summary the auditor asked for.
The memo is short, and it does one thing the audit report cannot: it ends with a question that has a yes. Notice that option B is presented fairly, including the part of the finding it does close. A memo that pretends the cheaper option does nothing is a memo the reader stops trusting at section 3. For the fuller three-option structure, with the risk and operational-cost legs alongside the audit leg, see the one-page business case.
What Happens When the Finding Is Ignored
Bluewater Bank's internal audit noted the same shared-credential FTP finding three years running. Each year the management response said "accepted; mitigated by compensating process," and each year the process was a spreadsheet of who knew the password. In the fourth year the external examiner read the three reports together. The examiner asked, in writing, why a high-rated finding had been open for three cycles. That converted an internal finding into an external one with a regulator's deadline. The fix that had been declined three times as "not this cycle" was approved in a week, at roughly three times the effort. That was because it now had to be done in six weeks by contractors rather than in six months by staff. The administrator who had written the original request kept a copy of it in his desk. It had been right the first time.
The lesson is that an open finding compounds. A repeat finding is read by people who never see a first finding. The spend required to close it under a deadline is always larger than the spend required to close it on a quiet Tuesday. The "do nothing" option in your memo should say this plainly, in one sentence, without drama. For example: "4.2 will be reported as a repeat finding, which the audit committee sees."
The most common funded outcome of a transfer audit finding, across every organization I have watched, is the retirement of plain FTP. Plain FTP is unencrypted, shared-credential, unlogged, and easy for an auditor to spot from the doorway. If that is where your findings point, why retire FTP gives you the technical argument in the same plain terms. The rest of that series is the plan.
Gotcha: a finding closed with a control that produces no evidence is not closed; it is deferred. Put the "evidence next year" column in the table and the "report back" in the decision. That way, the money you are asking for closes the finding at the next visit and not just at this meeting.
From the Report to the Room
The audit leg of the case is the strongest of the three, because its numbers are not yours. The severity, the deadline, and the signature all belong to other people. Combined with the risk scenario and the operational-cost worksheet, it gives the one-pager something to say to a reader who cares about risk. The one-pager also speaks to a reader who cares about hours. And it speaks to a reader who cares about not being asked the same question by the audit committee twice. Presenting all three in the room, and answering the objections that follow, is the subject of presenting the case and following through.
Frequently Asked Questions
What is the difference between a finding and a recommendation?
Should I rewrite the finding in technical terms so the fix is clearer?
The management response says the risk is "tolerated." Can I still ask for money?
What if the cheapest option only closes part of a finding?
From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.
