Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Audit Issue

← Back to Glossary
By NHI Mgmt Group Updated September 7, 2026 Domain: Governance, Ownership & Risk

An audit issue is a documented control weakness, exception, or failure that requires review and remediation. In ERP security programmes, audit issues often arise from access mismanagement, incomplete testing, or poor evidence. They matter because unresolved findings can affect assurance, compliance, and operational trust.

Expanded Definition

An audit issue is more than a failed check. It is a recorded control deficiency, exception, or evidence gap that an auditor, assurance team, or internal control owner has deemed important enough to track to resolution. In security and ERP contexts, the term usually applies to controls that can be tested, documented, and closed, rather than informal improvement suggestions.

The boundary matters. A control weakness becomes an audit issue when it is formally observed, assigned, and expected to be remediated within a defined governance process. That distinguishes it from a general operational problem, a one-off incident, or a broad risk statement. In practice, audit issues often reflect access review failures, incomplete logging, missing approvals, weak segregation of duties, or test evidence that does not support the control claim.

Industry usage is mostly consistent on the core idea, although organisations differ on whether they call these findings, observations, exceptions, or issues. What changes is usually the severity and the remediation workflow, not the underlying concept. For a broader governance lens, NIST Cybersecurity Framework 2.0 provides a useful reference point for how control gaps connect to accountability, risk treatment, and continuous improvement: NIST Cybersecurity Framework 2.0.

Examples and Use Cases

Audit issues appear wherever control performance must be evidenced, challenged, and tracked. In ERP and identity-heavy environments, they often emerge when day-to-day operations drift away from the documented control design.

  • A quarterly access review shows that privileged accounts were approved but not recertified on time, creating an issue for control operation and evidence retention.
  • Audit testing finds that a critical change request was completed without the required sign-off, so the issue is recorded as a control exception rather than treated as a simple process miss.
  • Logs exist, but retention is too short to support the audit period, which turns a technical configuration gap into an assurance issue.
  • Segregation of duties testing finds that the same user can create and approve a payment workflow, creating a repeatable control weakness.
  • A control owner can describe the process verbally but cannot produce supporting evidence, which is a common audit issue in immature governance programmes.

These examples show an important trade-off: the more controls rely on manual evidence collection, the more likely it is that the issue is about proof and consistency rather than only system design.

Security Implications

Unresolved audit issues can indicate that a control is failing in a way that matters to assurance, not just compliance. A single issue may be limited in scope, but repeated issues in the same area often point to weak ownership, poor monitoring, or a control that is not operating as designed.

The security consequence is that organisations may believe a control is effective when the evidence says otherwise. That can leave excessive access in place, weaken change governance, or hide gaps in logging and detective coverage. In regulated or audit-dependent environments, the issue can also create reporting risk if management attests to a control that is not adequately supported by proof.

A common practitioner signal is pattern repetition: when similar findings recur across cycles, the real problem is usually not the individual ticket, but the underlying control design, process discipline, or evidence model. If that pattern is ignored, the organisation can accumulate unresolved exceptions that erode trust in the entire control environment.

Domain and Governance Relevance

In security governance, an audit issue is the point where a control deficiency becomes actionable within formal oversight. It is the mechanism that turns a finding into ownership, prioritisation, remediation, and closure criteria. That is why audit issues matter in identity governance, ERP controls, access administration, and any environment where assurance depends on traceable evidence.

For non-human identities, the relevance is especially clear when service accounts, API keys, or automated workflows fall outside the normal review cycle. If those identities are not inventoried, recertified, or evidenced properly, the resulting audit issue is not just administrative. It can signal that machine access is operating without reliable oversight, which weakens confidence in who or what can act in the environment.

For practitioners, the key governance question is whether an issue is being treated as a one-off correction or as a sign that the control itself needs redesign. Audit programmes are strongest when they separate isolated exceptions from systemic weaknesses and track both to clear closure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyAudit issues evidence control gaps that should feed risk treatment decisions.
GV.OV — Governance OversightAudit issues require accountable oversight, tracking, and closure.
DE.CM — Continuous MonitoringRepeated audit issues often indicate weak monitoring or control drift.
Recommendation — Use GV.RM to prioritise unresolved audit issues by business and security risk. Assign GV.OV ownership to track findings, validate remediation, and close exceptions. Apply DE.CM to detect recurring control failures before they reappear in audits.
CIS Controls v86 — Access Control ManagementMany audit issues arise from privilege, review, and segregation failures.
8 — Audit Log ManagementEvidence gaps and log retention failures are common audit issue triggers.
Recommendation — Enforce Control 6 to correct access weaknesses that become recurring audit issues. Apply Control 8 to preserve evidence needed to substantiate control operation.
MITRE ATT&CKT1068 — Exploitation for Privilege EscalationUnresolved access findings can preserve paths attackers may exploit for privilege gain.
Recommendation — Map audit findings to T1068 where weak controls expose privilege-escalation paths.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org