All articles Workflow

How Request Chasing Consumes Audit Season

Snir Kodesh
How Request Chasing Consumes Audit Season

It starts around week two. The initial PBC list has gone out. Some responses have come in. The audit senior pulls up the tracking spreadsheet, identifies eighteen items still marked Pending, and begins composing follow-up emails. Finance, IT Security, HR. Some items have been pending since day one. Some items are new requests that replaced a first batch where the documentation was for the wrong period. The follow-up emails take an hour and a half. Not because they are hard to write, but because each one requires confirming what was requested, what was received, what is still missing, and what the deadline is. This information lives across an inbox, a spreadsheet, and a shared drive, and none of them agree on the current state.

This is request chasing: the work of managing the gap between what was asked for and what has arrived. It is not analysis. It is coordination, and it expands to fill whatever time is available. Understanding how it expands and why it is so hard to compress under a manual workflow is useful before evaluating whether any particular tool or process change can actually help.

The Anatomy of a Follow-Up Loop

A single PBC item can generate three or four follow-up touchpoints before it resolves. The first follow-up is a reminder at the original deadline: "Just following up on item 14, the Q3 user access review for the ERP system." The control owner replies two days later: "Which system? We have three ERP instances." A clarification is exchanged. The correct owner is identified. A new deadline is set. At that deadline, a partial submission arrives: the access review is there but it covers only the production instance, not the staging environment. The auditor reviews what arrived, determines that staging access is in scope, and sends a second follow-up. Fourteen days after the original request, the item closes.

That sequence is not unusual. It is representative of a category of items where the original request was underspecified, where the control owner was not the right person, or where the scope of the request was ambiguous in ways that only became visible when the evidence arrived. In a forty-control engagement, fifteen to twenty items in this category is common. Each one generates multiple touchpoints. The total communication overhead is substantial, and all of it comes out of the time budget that was supposed to be available for fieldwork.

Why Follow-Up Work Concentrates on Senior Auditors

Request chasing is almost universally done by audit seniors rather than by staff-level auditors. The reason is that productive follow-up requires understanding what the control tests, what the evidence should demonstrate, and whether a partial submission is acceptable or requires a complete resubmission. Staff auditors often do not have enough context about the control framework or the engagement scope to make those calls without escalating. So the senior ends up handling the communication directly, which means the person with the most analytical value is spending the most time on coordination rather than analysis.

This is a structural problem rather than a staffing problem. In an engagement where the follow-up logic requires judgment, delegating follow-up work requires transferring the context along with the task, and transferring context takes time that is often not available. The path of least resistance is for the senior to do it themselves. The cumulative effect is an engagement where the senior's calendar is segmented into thirty-minute blocks of follow-up communication between stretches of actual fieldwork, and the total time available for fieldwork is a fraction of what the engagement plan assumed.

How the PBC List Amplifies the Problem

A PBC list that was designed as a request tracker tends to make request chasing worse rather than better. The list exists to provide an organized record of what was requested and what has arrived. But the list itself requires maintenance: updating status when responses arrive, noting partial submissions, tracking version changes when a control owner submits a revised document. This maintenance is either done by the senior in parallel with other work or it does not happen reliably, which means the list drifts from the actual state of the engagement.

A drifted PBC list creates its own problem: when the audit manager asks for a status update, the senior cannot pull the list and read it. They have to reconstruct the status from their inbox and their memory. The reconstruction takes time and is prone to omission. Items that have been partially addressed but not fully closed are the most likely to be misrepresented in a status conversation, because their status is ambiguous in a way that requires careful cross-referencing to describe accurately.

This drift dynamic is worth naming explicitly because it explains why the follow-up problem compounds over time rather than getting smaller as items close. As the engagement progresses, the number of items in ambiguous states increases: partially submitted, submitted but under review, resubmitted after rejection, closed but with a noted exception. Each ambiguous state requires active management. A list that started as a simple tracker becomes a complex status document that requires significant overhead to maintain accurately.

The Control Owner Experience Matters Too

Request chasing is not only a problem for the audit team. It is also a frustration for control owners who receive multiple follow-up emails without a clear picture of what is still outstanding. A finance manager who has submitted three documents across two email threads and received a fourth follow-up email asking for "the outstanding items on the PBC list" is not going to respond faster because the email is more urgently worded. They are going to respond with their own version of the status, which may or may not match the audit team's version, which restarts the clarification loop.

Control owners who have been through multiple audit cycles develop a certain amount of follow-up fatigue. They learn that the first request is sometimes vague and that the real requirements emerge through clarification. Some adapt by submitting whatever is easiest to produce first and waiting to see what follow-up comes back before investing in a more complete response. This adaptation is rational from their perspective and disastrous from an audit timeline perspective: it extends every item's lifecycle by default.

What a Structural Approach Changes

The premise of a structured evidence collection approach is that follow-up volume is a function of request quality and status transparency. When each request specifies exactly what is needed, the source system, the date range, the population, and the format, the first-submission rate improves. Control owners are not guessing at scope. When status is maintained automatically at the point of evidence receipt rather than manually by a senior updating a spreadsheet, the drift problem disappears. The status at any given moment reflects the actual state of the engagement, not the state as of the last manual update.

This does not eliminate follow-up entirely. Evidence that does not satisfy the control objective still requires a follow-up conversation. A control owner who provides a Q3 access review when Q4 is in scope still requires a correction request. What changes is the distribution of the senior's time. Mechanical follow-up, such as reminders for items with no response after a specified period, becomes a system function. Judgment-based follow-up, such as determining whether a partial submission is sufficient or requires a resubmission, remains with the senior. The senior's attention concentrates on the items that require it rather than being distributed across all pending items regardless of their complexity.

The aggregate effect on an engagement's timeline is not theoretical. When the time spent on coordination decreases, more of the engagement plan is available for the fieldwork the plan was built around. The cycle does not necessarily get shorter, but the quality of what gets produced in the same cycle improves because the senior's time is allocated differently. That reallocation is the actual return on investing in a structured evidence collection system, not a headcount reduction or a process shortcut.