07 Audit Reporting
Audit reporting is the stage where all of the work performed during an audit becomes:
Visible ↓Understandable ↓ActionableDuring the engagement, auditors may have completed:
Risk Assessment
Control Walkthroughs
Interviews
Evidence Collection
Control Testing
Exception Analysis
Root Cause Analysis
Finding DevelopmentBut stakeholders ultimately need to understand:
What DidWe Audit?
What DidWe Find?
How SignificantIs It?
What Isthe Risk?
What Needsto Change?
Who WillFix It?
When WillIt Be Fixed?The audit report communicates those answers.
A practical reporting lifecycle looks like:
Audit Objective ↓Scope ↓Audit Procedures ↓Testing Results ↓Validated Findings ↓Overall Conclusion ↓Executive Summary ↓Detailed Findings ↓Management Responses ↓Quality Review ↓Final Report ↓Distribution ↓Follow-UpLearning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of audit reporting.
-
Identify the audiences for internal audit reports.
-
structure a professional audit report.
-
write clear audit objectives.
-
document audit scope.
-
communicate scope limitations.
-
describe audit methodology.
-
summarize audit results.
-
develop executive summaries.
-
determine overall audit conclusions.
-
understand audit opinions and ratings.
-
summarize findings by severity.
-
present detailed findings.
-
incorporate management responses.
-
document management action plans.
-
assign remediation ownership.
-
establish target remediation dates.
-
communicate repeat findings.
-
report risk-accepted findings.
-
communicate positive observations appropriately.
-
avoid excessive technical detail.
-
write for executives and control owners.
-
perform report quality reviews.
-
manage draft and final reports.
-
control report distribution.
-
handle confidential audit information.
-
communicate urgent issues before final reporting.
-
build audit reporting artifacts.
-
prepare audit reports for follow-up activities.
1. What Is an Audit Report?
Section titled “1. What Is an Audit Report?”An audit report is the formal communication of:
Audit Purpose
Scope
Work Performed
Results
Findings
Risk
Conclusion
Management ActionsIt represents the final output of the audit engagement.
2. Purpose of Audit Reporting
Section titled “2. Purpose of Audit Reporting”The report should help stakeholders:
Understand Risk
Understand Control Weaknesses
Prioritize Remediation
Assign Accountability
Make DecisionsAudit reporting is therefore not simply:
DocumentingEverything theAuditor DidIt is:
CommunicatingWhat Matters3. Audit Report Audience
Section titled “3. Audit Report Audience”Reports may be read by:
Process Owners
Control Owners
Business Management
Senior Executives
CISO
CIO
Risk Management
Compliance
Legal
Audit Committee
Board Members
External Auditors
RegulatorsThe exact audience depends on the engagement.
4. Different Audiences Need Different Information
Section titled “4. Different Audiences Need Different Information”A technical control owner may need:
Exact Condition
Affected Systems
Evidence
Root Cause
Required RemediationAn executive may primarily need:
Risk
Business Impact
Severity
Accountability
Remediation Status5. Write for the Reader
Section titled “5. Write for the Reader”A strong report should allow a senior stakeholder to quickly answer:
Why WasThis Audit Performed?
What Isthe Overall Result?
What Arethe Major Risks?
What RequiresMy Attention?6. Core Audit Report Structure
Section titled “6. Core Audit Report Structure”A professional internal audit report may include:
Title Page
Report Metadata
Executive Summary
Background
Audit Objective
Scope
Methodology
Overall Conclusion
Finding Summary
Detailed Findings
Management Responses
Action Plans
AppendicesExact structure should follow the organization’s audit methodology.
7. Create the Audit Report Template
Section titled “7. Create the Audit Report Template”Create:
01 Audit Report TemplateSuggested structure:
Audit Title
Report Number
Audit Period
Report Date
Audit Team
Distribution
Executive Summary
Background
Objectives
Scope
Methodology
Overall Conclusion
Summary of Findings
Detailed Findings
Management Responses
Action Plans
Appendices8. Report Metadata
Section titled “8. Report Metadata”Important metadata may include:
Audit ID
Audit Name
Business Area
Audit Lead
Report Status
Issue Date
Audit Period
ClassificationExample:
| Field | Value |
|---|---|
| Audit ID | IA-2026-014 |
| Audit | Identity & Access Management |
| Period | Jan–Jun 2026 |
| Report Status | Final |
| Classification | Confidential |
9. Report Status
Section titled “9. Report Status”Clearly identify whether the report is:
Draft
Final Draft
FinalThis helps prevent draft findings from being treated as finalized conclusions.
10. Executive Summary
Section titled “10. Executive Summary”The executive summary is one of the most important sections.
It should communicate:
Why We Audited
What We Audited
Overall Conclusion
Most Important Findings
Management Direction11. Executive Summary Is Not a Finding Dump
Section titled “11. Executive Summary Is Not a Finding Dump”Avoid simply copying:
Finding 1
Finding 2
Finding 3
Finding 4into the executive summary.
Instead communicate:
Overall Risk Story12. Executive Summary Example
Section titled “12. Executive Summary Example”Internal Audit assessedthe design and operatingeffectiveness of identityand access managementcontrols covering userprovisioning, privilegedaccess, periodic accessreviews, and employeetermination.
Controls were generallydesigned appropriately;however, weaknesses wereidentified in terminationprocessing and privilegedaccess monitoring.
Three findings wereidentified:
1 High2 Medium
Management has agreedactions to address theidentified weaknesses.13. Create Executive Summary
Section titled “13. Create Executive Summary”Create:
02 Executive SummaryRecommended sections:
Audit Purpose
Scope
Overall Conclusion
Key Findings
Management Response14. Keep Executive Summary Concise
Section titled “14. Keep Executive Summary Concise”Executives should not need to read:
20 Pagesbefore understanding:
Audit ResultThe executive summary should usually provide the key message quickly.
15. Background Section
Section titled “15. Background Section”Background provides enough context to understand:
Business Process
Technology
Operating Model
Risk Environment
Relevant Changes16. Background Example
Section titled “16. Background Example”The organization managesapproximately 12,000workforce identities acrosscorporate, cloud, andbusiness applications.
Identity lifecycle activitiesare coordinated betweenHuman Resources, Identityand Access Management,application owners, andbusiness managers.17. Avoid Excessive Background
Section titled “17. Avoid Excessive Background”The report is not:
A Training ManualOnly include information necessary to understand:
Risk
Scope
Findings18. Audit Objective
Section titled “18. Audit Objective”The objective explains:
Why was the audit performed?
Example:
To assess whether identityand access managementcontrols are appropriatelydesigned and operatingeffectively to prevent,detect, and remediateunauthorized access.19. Strong Objectives
Section titled “19. Strong Objectives”Objectives should be:
Clear
Specific
Risk-Focused
Aligned to Scope20. Weak Objective
Section titled “20. Weak Objective”Review IAM21. Better Objective
Section titled “21. Better Objective”Assess whether controlsover user provisioning,privileged access,periodic access reviews,and account terminationadequately manage the riskof unauthorized access.22. Audit Scope
Section titled “22. Audit Scope”Scope defines:
What WasIncluded?and sometimes:
What WasExcluded?23. Scope Dimensions
Section titled “23. Scope Dimensions”Scope may define:
Business Units
Processes
Systems
Locations
Entities
Control Areas
Time Period24. Scope Example
Section titled “24. Scope Example”The audit covered identityand access managementcontrols operating between1 January and 30 June 2026for corporate ActiveDirectory, selected cloudplatforms, and five criticalbusiness applications.25. Out-of-Scope Areas
Section titled “25. Out-of-Scope Areas”Where useful, identify:
Excluded Systems
Excluded Entities
Excluded Processes
Excluded Periods26. Why Scope Matters
Section titled “26. Why Scope Matters”Without clear scope, readers may incorrectly assume:
Everything Was Audited27. Scope Limitation
Section titled “27. Scope Limitation”A scope limitation occurs when auditors cannot perform planned work because of issues such as:
Evidence Unavailable
Population Unreliable
System Access Restricted
Records Missing
Time Constraints
Legal Restrictions28. Scope Limitation Example
Section titled “28. Scope Limitation Example”Internal Audit was unableto validate the completenessof historical administratoractivity logs for Marchbecause the source logswere no longer available.29. Scope Limitations May Affect Conclusion
Section titled “29. Scope Limitations May Affect Conclusion”A significant limitation may require:
Modified Conclusion
Qualification
Escalation
Additional Audit Workdepending on audit methodology.
30. Methodology
Section titled “30. Methodology”The methodology explains how audit assurance was obtained.
Typical procedures include:
Interviews
Walkthroughs
Documentation Review
Configuration Review
Sampling
Data Analytics
Inspection
Observation
Reperformance31. Methodology Example
Section titled “31. Methodology Example”Internal Audit reviewedapplicable policies andprocedures, interviewedcontrol owners, performedprocess walkthroughs,validated controlpopulations, inspectedsupporting evidence,performed sample-basedtesting, and analyzedselected full populations.32. Avoid Excessive Testing Detail
Section titled “32. Avoid Excessive Testing Detail”The final report normally does not need:
Every Sample
Every Screenshot
Every Command
Every QueryThose belong in:
Audit Working Papers33. Overall Audit Conclusion
Section titled “33. Overall Audit Conclusion”The overall conclusion answers:
How EffectiveIs the ControlEnvironment?34. Possible Overall Ratings
Section titled “34. Possible Overall Ratings”Organizations may use:
Effective
Generally Effective
Needs Improvement
Ineffectiveor:
Satisfactory
Needs Improvement
Unsatisfactoryor another approved scale.
35. Use Approved Methodology
Section titled “35. Use Approved Methodology”Do not invent:
Audit Ratingfor each engagement.
Use the organization’s defined methodology.
36. Audit Opinion
Section titled “36. Audit Opinion”The audit opinion may consider:
Control Design
Operating Effectiveness
Number of Findings
Finding Severity
Key Control Failures
Repeat Issues
Residual Risk37. Create Audit Opinion Worksheet
Section titled “37. Create Audit Opinion Worksheet”Create:
03 Audit Opinion WorksheetExample:
| Factor | Assessment |
|---|---|
| Control design | Generally effective |
| Operating effectiveness | Needs improvement |
| High findings | 1 |
| Medium findings | 2 |
| Repeat findings | 0 |
| Key control failures | 1 |
| Overall conclusion | Needs Improvement |
38. Rating Should Not Be Pure Arithmetic
Section titled “38. Rating Should Not Be Pure Arithmetic”Avoid:
1 High+2 Medium=Needs Improvementwithout considering:
Context
Risk
Control Environment
Scope
Compensating Controls39. Overall Conclusion Example
Section titled “39. Overall Conclusion Example”The control environmentis generally designedappropriately; however,improvements are requiredto ensure timely removalof terminated-user accessand consistent monitoringof privileged accounts.
Based on the significanceof the identified issues,Internal Audit assessedthe control environment asNeeds Improvement.40. Positive Assurance
Section titled “40. Positive Assurance”Where supported, acknowledge controls that are working.
Example:
Internal Audit observedeffective automated MFAenforcement across thetested administrativeenvironment.41. Avoid Excessive Praise
Section titled “41. Avoid Excessive Praise”Audit reporting should remain:
ObjectivePositive observations should be evidence-based and relevant.
42. Finding Summary
Section titled “42. Finding Summary”Executives benefit from a concise summary.
Create:
04 Finding Summary TableExample:
| ID | Finding | Severity | Owner | Target |
|---|---|---|---|---|
| F-01 | Delayed termination access removal | High | IAM Director | 30 Sep |
| F-02 | Incomplete access reviews | Medium | IAM Manager | 31 Oct |
| F-03 | Monitoring gaps | Medium | Security Director | 30 Nov |
43. Finding Counts
Section titled “43. Finding Counts”Example:
Total Findings:5
Critical:0
High:1
Medium:3
Low:144. Finding Counts Need Context
Section titled “44. Finding Counts Need Context”Five low findings may be less significant than:
One CriticalKey-Control FailureDo not rely only on counts.
45. Detailed Findings
Section titled “45. Detailed Findings”Each detailed finding should typically include:
Title
Severity
Criteria
Condition
Cause
Risk
Recommendation
Management Response
Action Plan
Owner
Target Date46. Finding Presentation
Section titled “46. Finding Presentation”A useful format:
Finding F-01
Title
Severity
What We Found
Why It Matters
Root Cause
Recommendation
Management Action
Owner
Target Date47. Use Consistent Finding Structure
Section titled “47. Use Consistent Finding Structure”Consistency helps readers compare:
Risk
Severity
Actions
Ownershipacross findings.
48. Finding Title
Section titled “48. Finding Title”Use a title that communicates the weakness.
Weak:
AccessBetter:
Terminated User AccessIs Not ConsistentlyRemoved Within theRequired Timeframe49. Finding Severity
Section titled “49. Finding Severity”Clearly display:
Critical
High
Medium
Lowaccording to approved methodology.
50. Condition
Section titled “50. Condition”Report:
What Was Foundwith sufficient quantification.
Example:
29 of 420 terminateduser accounts remainedactive beyond the24-hour disablementrequirement.51. Criteria
Section titled “51. Criteria”Explain:
What Was RequiredExample:
The corporate accessmanagement standardrequires access forterminated employeesto be disabled within24 hours.52. Root Cause
Section titled “52. Root Cause”Explain:
Why It HappenedExample:
Automated reconciliationbetween HR terminationrecords and IAM accountdisablement events hadnot been implemented.53. Risk
Section titled “53. Risk”Explain:
Why It MattersExample:
Delayed accountdisablement increasesthe risk that formeremployees retainunauthorized access tocorporate systems andinformation.54. Recommendation
Section titled “54. Recommendation”Explain:
Required ControlOutcomeExample:
Management should establishmonitoring and reconciliationto identify accounts thatremain active beyond theapproved termination SLAand escalate exceptionsfor timely remediation.55. Management Response
Section titled “55. Management Response”Include management’s:
Agreement
Context
Action Plan
Owner
Target Datewhere required.
56. Management Action Plan
Section titled “56. Management Action Plan”Create:
05 Management Action Plan RegisterExample:
| Finding | Action | Owner | Target | Status |
|---|---|---|---|---|
| F-01 | Implement HR/IAM reconciliation | IAM Director | 30 Sep | Open |
57. Management Actions Should Be Specific
Section titled “57. Management Actions Should Be Specific”Weak:
We Will Fixthe IssueBetter:
IAM will implement a dailyreconciliation between HRtermination records andactive identities andescalate unmatched recordsto IAM operations.58. Multiple Actions
Section titled “58. Multiple Actions”One finding may require:
Action 1
Action 2
Action 3Each may have:
Different Owner
Different Target Date59. Finding Ownership
Section titled “59. Finding Ownership”The owner should have authority to:
Implement
Coordinate
Escalate
Completethe remediation.
60. Avoid Generic Ownership
Section titled “60. Avoid Generic Ownership”Avoid:
IT TeamPrefer:
Director ofIdentity andAccess Management61. Target Remediation Dates
Section titled “61. Target Remediation Dates”Dates should reflect:
Severity
Risk Exposure
Complexity
Dependencies
Resources62. Critical Findings
Section titled “62. Critical Findings”Critical findings may require:
Immediate Action
Executive Notification
Interim Controls
Frequent Monitoringbefore permanent remediation is complete.
63. Do Not Wait for Final Report for Urgent Issues
Section titled “63. Do Not Wait for Final Report for Urgent Issues”If testing identifies:
Active Compromise
Severe Control Failure
Immediate Regulatory Risk
Critical Safety Issue
Material Fraud Indicatorfollow escalation procedures immediately.
Audit reporting should never delay urgent risk communication.
64. Interim Communication
Section titled “64. Interim Communication”Internal Audit may issue:
Immediate Notification
Interim Memo
Flash Report
Management Alertdepending on methodology.
65. Repeat Findings
Section titled “65. Repeat Findings”Clearly identify significant:
Repeat Findingswhere appropriate.
66. Repeat Finding Reporting
Section titled “66. Repeat Finding Reporting”Include:
Previous Finding
Original Due Date
Prior Closure Status
Current Condition
Reason for Recurrence67. Why Repeat Findings Matter
Section titled “67. Why Repeat Findings Matter”They may indicate:
Weak Governance
Ineffective Remediation
Incorrect Root Cause
Insufficient Accountability68. Risk-Accepted Findings
Section titled “68. Risk-Accepted Findings”Management may decide to:
Accept Riskrather than remediate.
The report should clearly document:
Finding
Risk
Severity
Acceptance Authority
Rationale
Review Date69. Risk Acceptance Does Not Erase Finding
Section titled “69. Risk Acceptance Does Not Erase Finding”The finding may remain part of the audit record even when:
Risk Accepted70. Management Disagreement
Section titled “70. Management Disagreement”Management may disagree with:
Finding
Risk
Severity
Recommendation
Conclusion71. Reporting Disagreement
Section titled “71. Reporting Disagreement”Depending on methodology, the final report may document:
Management Position
Internal Audit Positionwhere material disagreement remains unresolved.
72. Maintain Independence
Section titled “72. Maintain Independence”Do not change:
Audit Conclusionsimply to achieve:
Management AgreementBut always consider valid:
Additional Evidence
Context
Corrections73. Draft Report
Section titled “73. Draft Report”Before final issuance:
Prepare Draft ↓Internal Review ↓Management Validation ↓Resolve Factual Issues ↓Obtain Responses ↓Final QA ↓Issue Final74. Draft Report Purpose
Section titled “74. Draft Report Purpose”The draft allows stakeholders to:
Validate Facts
Review Actions
Correct Errors
Provide Responses75. Draft Does Not Mean Findings Are Negotiable
Section titled “75. Draft Does Not Mean Findings Are Negotiable”Audit conclusions remain based on:
Evidence
Risk
Methodology76. Report Review Meeting
Section titled “76. Report Review Meeting”An exit or closing meeting may cover:
Audit Objectives
Overall Conclusion
Findings
Severity
Management Actions
Target Dates
Next Steps77. Exit Meeting Objective
Section titled “77. Exit Meeting Objective”Ensure:
No Surprisesin the final report where practical.
Material issues should generally have been discussed before final issuance.
78. Audit Report Quality Review
Section titled “78. Audit Report Quality Review”Before issuance verify:
Accuracy
Completeness
Objectivity
Clarity
Conciseness
Traceability
Consistency79. Create Final Report Quality Checklist
Section titled “79. Create Final Report Quality Checklist”Create:
06 Final Report Quality Checklist80. Accuracy
Section titled “80. Accuracy”Ask:
Are Counts Correct?
Are Dates Correct?
Are Systems Correct?
Are Finding FactsSupported?81. Completeness
Section titled “81. Completeness”Ask:
Are All MaterialFindings Included?
Are Responses Included?
Are Owners Included?
Are Target Dates Included?82. Objectivity
Section titled “82. Objectivity”Ask:
Is the ReportEvidence-Based?
Is the ToneNeutral?
Are Positive andNegative ResultsPresented Fairly?83. Clarity
Section titled “83. Clarity”Ask:
Could a SeniorExecutive Understandthe Main Risks?84. Conciseness
Section titled “84. Conciseness”Remove:
Unnecessary Detail
Repeated Statements
Long Technical Explanations
Irrelevant Background85. Traceability
Section titled “85. Traceability”Every material statement should be supportable through:
Working Papers
Evidence
Testing
Finding Documentation86. Report Cross-Reference
Section titled “86. Report Cross-Reference”Example:
Report F-01 ↓Finding F-01 ↓Exception EX-04 ↓Test T-08 ↓Evidence AE-2787. Consistency
Section titled “87. Consistency”Check consistency of:
Severity
Terminology
Dates
Finding IDs
Owner Names
Target Dates
Ratings88. Writing Style
Section titled “88. Writing Style”Audit reports should be:
Clear
Professional
Direct
Neutral
Risk-Focused89. Avoid Emotional Language
Section titled “89. Avoid Emotional Language”Weak:
Management CompletelyFailed to Protectthe EnvironmentBetter:
Required privilegedaccess reviews werenot completed fortwo of four quarters.90. Avoid Audit Jargon Where Possible
Section titled “90. Avoid Audit Jargon Where Possible”Executives may not need:
IPE Validation
TOD
TOE
PBC
RCMwithout explanation.
Write for the intended audience.
91. Avoid Cybersecurity Fear Language
Section titled “91. Avoid Cybersecurity Fear Language”Weak:
Hackers Could EasilyDestroy the CompanyBetter:
The identified weaknessincreases the likelihoodof unauthorized accessto privileged systems.92. Use Quantification
Section titled “92. Use Quantification”Instead of:
Many AccountsWere Incorrectwrite:
29 of 420Terminated AccountsExceeded the RequiredDisablement Timeframe93. Use Visual Summaries Carefully
Section titled “93. Use Visual Summaries Carefully”Reports may include:
Finding Summary
Severity Distribution
Control Ratings
Remediation StatusVisuals should:
Clarifynot:
Decorate94. Audit Dashboard
Section titled “94. Audit Dashboard”Create:
07 Audit Report DashboardExample:
| Metric | Result |
|---|---|
| Controls tested | 25 |
| Effective | 18 |
| Partially effective | 4 |
| Ineffective | 3 |
| Critical findings | 0 |
| High findings | 1 |
| Medium findings | 2 |
| Low findings | 2 |
95. Report Classification
Section titled “95. Report Classification”Audit reports may contain:
Security Weaknesses
Personal Information
System Details
Legal Matters
Vendor Information
Confidential FindingsApply appropriate:
InformationClassification96. Distribution List
Section titled “96. Distribution List”Create:
08 Report Distribution ListExample:
| Recipient | Role | Report Access |
|---|---|---|
| CIO | Executive | Full |
| CISO | Executive | Full |
| IAM Director | Process Owner | Full |
| Audit Committee | Governance | Full |
97. Need-to-Know Principle
Section titled “97. Need-to-Know Principle”Do not automatically distribute:
Full Audit Reportto everyone involved in the audit.
Distribution should reflect:
Role
Authority
Need to Know
Confidentiality98. Secure Distribution
Section titled “98. Secure Distribution”Use approved mechanisms for:
Email
Document Repository
Audit Platform
Board Portalaccording to information-handling requirements.
99. Final Report Approval
Section titled “99. Final Report Approval”Before issuance, the report may require approval from:
Audit Manager
Head of Internal Audit
Chief Audit Executivedepending on governance.
100. Final Report Issuance
Section titled “100. Final Report Issuance”Record:
Report ID
Version
Issue Date
Recipients
Approval
Classification101. Report Version Control
Section titled “101. Report Version Control”Example:
v0.1 Draft
v0.2 Management Review
v0.3 Final Draft
v1.0 Final102. Avoid Multiple “Final” Reports
Section titled “102. Avoid Multiple “Final” Reports”Maintain:
Single AuthoritativeFinal Version103. Report Archive
Section titled “103. Report Archive”Retain the report according to:
Audit Retention Policy
Legal Requirements
Regulatory Requirements104. Reporting to Audit Committee
Section titled “104. Reporting to Audit Committee”Audit committee reporting may focus on:
High-Risk Findings
Overall Audit Opinion
Repeat Findings
Overdue Remediation
Management Risk Acceptance
Emerging Themes105. Portfolio-Level Reporting
Section titled “105. Portfolio-Level Reporting”Individual audit findings can reveal broader themes.
Example:
Audit 1:Weak Access Reviews
Audit 2:Weak Vendor Reviews
Audit 3:Weak Change ReviewsPossible theme:
Control Monitoringand AccountabilityWeakness106. Thematic Reporting
Section titled “106. Thematic Reporting”Executives may benefit from:
Cross-Audit Trends
Recurring Root Causes
Common Control Failures
Risk Concentrations107. Report Finding Aging
Section titled “107. Report Finding Aging”Track:
0–30 Days
31–60 Days
61–90 Days
90+ Daysfor remediation reporting.
108. Overdue Action Reporting
Section titled “108. Overdue Action Reporting”Example:
| Severity | Open | Overdue |
|---|---|---|
| Critical | 0 | 0 |
| High | 3 | 1 |
| Medium | 8 | 2 |
| Low | 10 | 1 |
109. Escalation
Section titled “109. Escalation”Overdue high-risk actions may require escalation to:
Senior Management
Risk Committee
Audit Committee
Boardaccording to governance.
110. Report Follow-Up
Section titled “110. Report Follow-Up”The report creates:
RemediationObligationsthat must be tracked.
The lifecycle continues:
Report ↓Action Plan ↓Remediation ↓Evidence ↓Validation ↓Closure111. Audit Reporting Is Not the End
Section titled “111. Audit Reporting Is Not the End”The engagement may be complete, but:
Riskremains until:
Remediationis implemented or formally accepted.
112. Common Audit Reporting Mistakes
Section titled “112. Common Audit Reporting Mistakes”Mistake 1 — Report Is Too Long
Section titled “Mistake 1 — Report Is Too Long”Important risks become buried.
Mistake 2 — Executive Summary Contains Too Much Detail
Section titled “Mistake 2 — Executive Summary Contains Too Much Detail”Executives cannot quickly identify the key message.
Mistake 3 — Scope Is Unclear
Section titled “Mistake 3 — Scope Is Unclear”Readers assume broader assurance than was actually provided.
Mistake 4 — Methodology Is Missing
Section titled “Mistake 4 — Methodology Is Missing”Readers do not understand how assurance was obtained.
Mistake 5 — Findings Are Not Quantified
Section titled “Mistake 5 — Findings Are Not Quantified”Statements such as “several accounts” weaken clarity.
Mistake 6 — Excessive Technical Detail
Section titled “Mistake 6 — Excessive Technical Detail”The report becomes difficult for decision-makers to understand.
Mistake 7 — Emotional or Blame-Oriented Language
Section titled “Mistake 7 — Emotional or Blame-Oriented Language”This reduces professionalism.
Mistake 8 — Severity Is Inconsistent
Section titled “Mistake 8 — Severity Is Inconsistent”Similar risks receive different ratings without justification.
Mistake 9 — Management Actions Are Vague
Section titled “Mistake 9 — Management Actions Are Vague”“Management will improve the process” is difficult to track.
Mistake 10 — No Accountable Owner
Section titled “Mistake 10 — No Accountable Owner”Remediation responsibility becomes unclear.
Mistake 11 — No Target Date
Section titled “Mistake 11 — No Target Date”Actions remain open indefinitely.
Mistake 12 — Urgent Risk Is Held Until Final Report
Section titled “Mistake 12 — Urgent Risk Is Held Until Final Report”Critical issues should be escalated when identified.
Mistake 13 — Draft Distributed as Final
Section titled “Mistake 13 — Draft Distributed as Final”Version control is weak.
Mistake 14 — Excessive Distribution
Section titled “Mistake 14 — Excessive Distribution”Sensitive audit information reaches unnecessary recipients.
Mistake 15 — Report Issued Without Follow-Up Mechanism
Section titled “Mistake 15 — Report Issued Without Follow-Up Mechanism”Findings are communicated but never remediated.
113. Weak Audit Report
Section titled “113. Weak Audit Report”Audit Completed ↓List Every Test ↓List Every Exception ↓Add Technical Details ↓Send 80-Page Report ↓No Clear Priorities114. Strong Audit Report
Section titled “114. Strong Audit Report”Audit Objective ↓Clear Scope ↓Evidence-Based Results ↓Overall Conclusion ↓Concise Executive Summary ↓Prioritized Findings ↓Clear Risk ↓Actionable Recommendations ↓Management Actions ↓Accountable Owners ↓Target Dates ↓Secure Distribution ↓Follow-UpAudit Report Operational Checklist
Section titled “Audit Report Operational Checklist”Report Preparation
Section titled “Report Preparation”-
audit objectives confirmed.
-
scope confirmed.
-
audit period confirmed.
-
methodology documented.
-
scope limitations identified.
-
findings finalized.
-
severity ratings reviewed.
-
management responses obtained.
Executive Summary
Section titled “Executive Summary”-
purpose explained.
-
scope summarized.
-
overall conclusion stated.
-
significant findings summarized.
-
major risk themes identified.
-
management direction summarized.
-
unnecessary detail removed.
Overall Conclusion
Section titled “Overall Conclusion”-
approved rating methodology used.
-
design effectiveness considered.
-
operating effectiveness considered.
-
key-control failures considered.
-
finding severity considered.
-
repeat findings considered.
-
residual risk considered.
-
conclusion supported by evidence.
Findings
Section titled “Findings”-
finding title clear.
-
criteria documented.
-
condition factual.
-
condition quantified.
-
root cause supported.
-
risk reasonable.
-
severity justified.
-
recommendation actionable.
-
evidence traceable.
Management Actions
Section titled “Management Actions”-
management response obtained.
-
action plan specific.
-
owner accountable.
-
target date defined.
-
multiple actions separately tracked.
-
risk acceptance documented where applicable.
Quality Review
Section titled “Quality Review”-
facts accurate.
-
counts accurate.
-
dates accurate.
-
terminology consistent.
-
severity consistent.
-
tone objective.
-
technical jargon minimized.
-
report concise.
-
working-paper traceability complete.
Distribution
Section titled “Distribution”-
report classification assigned.
-
distribution list approved.
-
need-to-know principle applied.
-
secure distribution mechanism used.
-
final version clearly identified.
-
issuance date recorded.
Follow-Up
Section titled “Follow-Up”-
findings entered into tracker.
-
action owners recorded.
-
due dates recorded.
-
risk-accepted findings tracked.
-
repeat findings flagged.
-
validation requirements defined.
Audit Reporting Deliverables
Section titled “Audit Reporting Deliverables”At completion, you should be able to create:
01 Audit Report Template
02 Executive Summary
03 Audit Opinion Worksheet
04 Finding Summary Table
05 Management Action Plan Register
06 Final Report Quality Checklist
07 Audit Report Dashboard
08 Report Distribution List
09 Report Version Control Register
10 Audit Report Issuance RecordPractical Activity — IAM Audit Report
Section titled “Practical Activity — IAM Audit Report”Assume your audit identified:
Finding 01HighDelayed TerminationAccess Removal
Finding 02MediumIncomplete QuarterlyAccess Reviews
Finding 03MediumInsufficient PrivilegedAccess MonitoringOverall control environment:
Generally DesignedAppropriately
Operating ImprovementsRequiredDevelop:
Executive Summary
Overall Conclusion
Finding Summary
Management ActionSummaryPractical Activity — Scope Limitation
Section titled “Practical Activity — Scope Limitation”You planned to test:
12 Monthsof Administrator Logsbut only:
9 Monthswere available.
Determine:
Is This Material?
Does It AffectAudit Assurance?
Should It BeReported?
Does the OpinionNeed Modification?Practical Activity — Critical Finding
Section titled “Practical Activity — Critical Finding”During testing, you identify:
Active AdministrativeAccounts Belonging toFormer Employeeswith access to:
ProductionCustomer SystemsDetermine:
Should You Waitfor the Final Report?
Who ShouldBe Notified?
What InterimControl Is Needed?
How Shouldthe Issue Appearin the Final Report?Practical Activity — Management Disagreement
Section titled “Practical Activity — Management Disagreement”Internal Audit assigns:
HighManagement believes:
LowDetermine:
What EvidenceSupports Severity?
What CompensatingControls Exist?
What Does theApproved Methodology Say?
How ShouldDisagreementBe Documented?Practical Activity — Executive Summary
Section titled “Practical Activity — Executive Summary”Audit results:
25 Controls Tested
18 Effective
4 Partially Effective
3 Ineffective
1 High Finding
2 Medium Findings
2 Low Findings
0 Repeat FindingsWrite an executive summary that communicates:
Overall Risk
Significant Weaknesses
Management Directionwithout simply repeating the numbers.
Audit Reporting Mindset
Section titled “Audit Reporting Mindset”For every report ask:
Who WillRead This?
What Do TheyNeed to Know?
Why Wasthe Audit Performed?
Is the ScopeClear?
Could ReadersMisinterpretthe Assurance?
What Is theOverall Risk Story?
Are the MostImportant IssuesObvious?
Are FindingsEvidence-Based?
Are ConditionsQuantified?
Are RisksReasonable?
Are SeverityRatings Consistent?
Are RecommendationsActionable?
Has ManagementCommitted to Actions?
Who OwnsEach Action?
When WillIt Be Completed?
Are Urgent IssuesAlready Escalated?
Is SensitiveInformation Protected?
Can Every MaterialStatement Be Tracedto Evidence?
Could an ExecutiveUnderstand ThisWithout Readingthe Working Papers?
Does the ReportDrive Action?That is the practical mindset behind professional internal audit reporting.
Key Takeaways
Section titled “Key Takeaways”-
Audit reporting transforms audit work into clear, actionable communication.
-
Reports should focus on what stakeholders need to understand and act upon.
-
Audit objectives explain why the engagement was performed.
-
Scope clearly defines what assurance was and was not provided.
-
Material scope limitations should be transparently communicated.
-
Methodology explains how Internal Audit obtained assurance.
-
Executive summaries should communicate the overall risk story rather than repeat every finding.
-
Overall audit conclusions should follow an approved methodology.
-
Finding counts alone should not determine the overall audit opinion.
-
Detailed findings should consistently communicate condition, criteria, cause, risk, recommendation, and management action.
-
Findings should be quantified wherever practical.
-
Reports should distinguish actual effects from potential risks.
-
Recommendations should focus on required control outcomes and root causes.
-
Management action plans should have accountable owners and target dates.
-
Significant repeat findings should be clearly communicated.
-
Formal risk acceptance should remain visible and governed.
-
Management disagreement does not automatically change an audit conclusion.
-
Urgent issues should be escalated when identified rather than held for final reporting.
-
Draft reports support factual validation but should not turn audit conclusions into negotiations.
-
Audit reports should be accurate, objective, clear, concise, constructive, and traceable.
-
Sensitive reports should follow information-classification and need-to-know requirements.
-
Final report issuance should be controlled through approval, versioning, and distribution.
-
Audit reporting is not the end of the risk lifecycle; findings must move into remediation and follow-up.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What is the purpose of an internal audit report?
-
Who may be the audience for an audit report?
-
What should an executive summary communicate?
-
Why should an executive summary not simply list every finding?
-
What is an audit objective?
-
What is audit scope?
-
Why should out-of-scope areas sometimes be documented?
-
What is a scope limitation?
-
How can a material scope limitation affect the audit conclusion?
-
What should the methodology section explain?
-
What is an overall audit conclusion?
-
What factors may influence an audit opinion?
-
Why should finding counts not automatically determine the overall rating?
-
What information should a finding summary contain?
-
What should be included in a detailed audit finding?
-
Why should conditions be quantified?
-
What is the difference between a recommendation and a management action plan?
-
Why should remediation actions have accountable owners?
-
Why are target remediation dates important?
-
How should critical findings be communicated?
-
Why should Internal Audit not wait for the final report to communicate urgent risks?
-
What is a repeat finding?
-
How should risk-accepted findings be handled?
-
How should management disagreement be addressed?
-
What is the purpose of a draft report?
-
What should happen during an exit meeting?
-
What should a final report quality review evaluate?
-
Why is finding traceability important?
-
Why should audit report distribution be controlled?
-
What happens after the final audit report is issued?
What’s Next?
Section titled “What’s Next?”➡️ Next: 08 — Audit Follow-Up and Remediation Tracking
In the next lesson, you will move from issuing audit findings to ensuring that agreed corrective actions are actually implemented and effective.
You will work through:
Final Audit Report ↓Finding ↓Management Action Plan ↓Remediation Owner ↓Target Date ↓Progress Monitoring ↓Evidence Submission ↓Audit Validation ↓Retesting ↓Residual Risk ↓Closure / Reopen ↓Executive ReportingYou will learn how to manage open findings, remediation plans, due dates, overdue actions, extensions, remediation evidence, retesting, partial remediation, risk acceptance, repeat issues, finding closure, reopened findings, aging analysis, and management escalation.
You will also build practical artifacts including a Finding Follow-Up Register, Remediation Evidence Tracker, Finding Aging Dashboard, Extension Request Record, Closure Validation Worksheet, Retesting Workpaper, Risk Acceptance Tracker, and Executive Remediation Dashboard.