Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Issue & Incident Remediation

Follow-Up

Also known as: Follow up, Follow-up action
Simply put

A follow-up is a communication or action taken after an initial interaction in order to continue a conversation, gather more information, or move a matter forward. In everyday usage, 'follow-up' (with a hyphen) is a noun or adjective, while 'follow up' (two words, no hyphen) is a verb.

Formal definition

As a general term, a follow-up denotes any subsequent act performed after an initial interaction to advance, verify, or progress a matter that was previously raised. The evidence available defines the term only in its general and grammatical senses: it functions as a noun or adjective when hyphenated ('follow-up') and as a verb when written as two open words ('follow up'). Note that this entry reflects only the general-usage evidence provided and does not establish a governance, risk, or compliance-specific meaning; in a GRC context the term is often applied to actions taken after audit findings, risk assessments, or remediation activities, but any such specialized definition would require verification against authoritative GRC sources not present in this evidence.

Why it matters

In everyday professional communication, a follow-up is the mechanism by which matters that have been raised are actually advanced, verified, or brought to closure. Without a deliberate subsequent action after an initial interaction, conversations stall, requests go unanswered, and issues that were flagged may never progress. The evidence describes a follow-up simply as any communication or action taken after an initial interaction to continue a conversation, gather information, or move a relationship forward.

Because the term is general rather than technical, its significance lies in the discipline of returning to an open item rather than in any single prescribed method. The grammatical distinction also matters for clear writing: 'follow up' (two words) functions as a verb, while 'follow-up' (hyphenated) functions as a noun or adjective, and the closed spelling 'followup' is generally treated as incorrect in standard usage guidance. Precise usage supports clarity in written records, correspondence, and documentation.

It should be noted that the evidence available defines this term only in its general and grammatical senses. In a governance, risk, or compliance setting the word is often used to describe actions taken after audit findings, risk assessments, or remediation activities, but the evidence provided here does not establish that specialized meaning. Any GRC-specific definition would need to be verified against authoritative sources not present in this evidence.

Who it's relevant to

Professionals managing open items and correspondence
Anyone responsible for advancing matters after an initial conversation relies on follow-ups to continue discussions, gather further information, or move a matter forward. The concept is broadly applicable across professional communication rather than tied to a single role.
Writers and those preparing formal documentation
Because usage guidance distinguishes 'follow up' (verb) from 'follow-up' (noun or adjective) and treats 'followup' as incorrect, individuals drafting clear, consistent written records and correspondence benefit from applying the correct grammatical form.
GRC practitioners (with a caveat)
Compliance officers, risk managers, and internal auditors frequently use the word to describe actions taken after audit findings, risk assessments, or remediation activities. However, the evidence provided does not establish a governance, risk, or compliance-specific definition; any such specialized meaning should be verified against authoritative GRC sources.

Inside Follow-Up

Tracking of Remediation Actions
A record of agreed management actions arising from audit findings, risk assessments, or compliance reviews, typically including the action owner, agreed completion date, and current status, used to monitor whether commitments are being met over time.
Verification of Implementation
The process by which the follow-up party confirms that a corrective or remedial action has actually been implemented and is operating as intended, as distinct from simply relying on management's assertion that it is complete.
Assessment of Adequacy
An evaluation of whether the action taken sufficiently addresses the underlying issue or root cause, rather than treating any response as automatically closing the matter. Note that judgments of adequacy often require professional evaluation and can be context-dependent.
Escalation and Reporting
The pathways through which overdue, incomplete, or ineffective actions are communicated to appropriate levels of management, and in many governance structures to a board or audit committee, so that accountability is maintained.
Documentation and Audit Trail
The retained evidence supporting follow-up conclusions, including status updates, supporting materials, and the basis for closing or keeping open a given item, which supports transparency and later review.

Common questions

Answers to the questions practitioners most commonly ask about Follow-Up.

Is follow-up the same as re-performing the original audit or assessment?
No. Follow-up is a distinct, typically narrower activity focused on determining whether previously agreed management actions or remediation for identified issues have been implemented and are operating as intended. It generally does not re-examine the entire scope of the original engagement. A fresh audit or assessment may be warranted in some cases, but follow-up itself is usually confined to verifying the status and effectiveness of responses to prior findings.
Does closing a follow-up item mean the underlying risk has been eliminated?
Not necessarily. Closing a follow-up item typically indicates that the agreed action has been completed or that management has accepted the residual risk, not that the risk no longer exists. Controls modify risk rather than eliminate it, so residual risk often remains after remediation. Follow-up conclusions should be read as confirmation of action status and, where assessed, control effectiveness, rather than as assurance that exposure has been removed entirely.
Who is typically responsible for performing follow-up on agreed actions?
Responsibility often varies by organization and by the function that raised the original finding. In many internal audit settings, the audit function tracks and verifies remediation, while management retains ownership of implementing the agreed actions. Compliance and risk functions may run their own follow-up processes for their respective findings. Clarifying these roles and decision rights in advance is generally treated as part of sound governance, and the specific allocation should be defined in relevant charters or policies.
How can organizations prioritize follow-up when there are many open actions?
Prioritization is commonly based on factors such as the severity or rating of the original issue, the significance of the associated risk relative to objectives, regulatory sensitivity, and the agreed remediation deadline. Higher-risk or overdue items often receive earlier or more rigorous verification. The approach typically depends on the organization's risk appetite and available resources, and it is often documented so that prioritization decisions are consistent and defensible.
What evidence is typically appropriate to verify that a follow-up action is complete?
Appropriate evidence often depends on the nature of the action. Verification may range from reviewing management representations for lower-risk items to inspecting documentation, testing the operation of a revised control, or observing a process for higher-risk matters. Relying solely on a status update without corroboration is generally considered weaker assurance. The level of evidence sought is often calibrated to the significance of the original issue.
How should overdue or repeatedly deferred remediation actions be handled?
Many frameworks and internal practices call for escalation of overdue or repeatedly deferred actions to appropriate governance bodies, such as senior management, an audit committee, or a risk committee. Escalation typically brings visibility to unaddressed exposure and supports informed decisions about accepting risk, reallocating resources, or revising deadlines. The specific escalation thresholds and pathways generally should be defined in the organization's follow-up procedures rather than applied ad hoc.

Common misconceptions

Follow-up is complete once management reports that an action has been taken.
Management's assertion of completion is typically a starting point, not the conclusion. Follow-up often involves verifying that the action was implemented and, where warranted, assessing whether it adequately addresses the issue. The rigor of verification varies by the significance of the finding and by organizational convention.
Follow-up is purely a compliance or internal audit activity.
Follow-up spans more than one GRC pillar. It supports compliance by confirming that policy or regulatory gaps are closed, supports risk management by confirming that agreed treatments have modified the relevant risk, and supports governance by preserving accountability and reporting to oversight bodies. Its placement and ownership vary by organization.
Closing a follow-up item means the associated risk has been eliminated.
Confirming that an action is implemented does not eliminate risk; it typically reduces or modifies it, leaving some residual risk. Whether that residual level is acceptable is a separate judgment against risk appetite and tolerance, and remains outside the mechanical act of closing the item.

Best practices

Record each agreed action with a clearly identified owner, an agreed target date, and a defined status, so that accountability and timeliness can be monitored consistently.
Distinguish between actions that are self-reported as complete and those that have been independently verified, and calibrate the depth of verification to the significance of the underlying finding.
Where practical, assess whether an implemented action addresses the root cause and adequately modifies the associated risk, rather than closing items solely on the basis of activity being performed.
Establish escalation pathways for overdue or ineffective actions, reporting them to appropriate management levels and, where the governance structure provides for it, to a board or audit committee.
Maintain a documented audit trail of status updates and the basis for closure decisions, supporting transparency and enabling later review.
Treat the acceptability of any remaining residual risk as a separate, explicit judgment against risk appetite and tolerance, and seek professional or legal advice where matters of interpretation or jurisdiction-specific obligation arise.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.