An audit report nobody reads is expensive paperwork. Yet its structure is rarely up for discussion: most audit functions rely on a template that emerged at some point and that nobody has tested since. This article walks through what belongs in it, why, and where it goes wrong in practice.
The starting point is the Global Internal Audit Standards (GIAS). On this point, they are more concrete than many auditors think: Standard 15.1 spells out exactly what the final engagement communication must contain.
What Must the Report Contain Under GIAS?
Standard 15.1, Final Engagement Communication, requires a final communication for every engagement that includes the objectives, the scope, recommendations and/or action plans where applicable, and the conclusions.
For assurance engagements, this also includes:
- the findings, with their significance and prioritization;
- an explanation of scope limitations, if any;
- a conclusion on the effectiveness of the governance, risk management, and control processes of the activity under review.
For each finding, the report must also name the responsible person and the planned completion date. If management has already taken action before the report is issued, the report must acknowledge this. And if the engagement was not conducted in accordance with the Standards, the report must state which standard was not met, why, and what this means for the findings and conclusions.
In practice, that last point is almost always skipped. Yet it is the only way a reader can judge how much weight to give the conclusion.
The Seven Quality Requirements
Standard 11.2, Effective Communication, requires communication that is accurate, objective, clear, concise, constructive, complete, and timely. Seven words that are easy to skim past, but that work well as a final check before a report goes out:
- Accurate: does every figure, date, and job title check out? One wrong fact costs the entire report its authority.
- Objective: is there anything in it you cannot support with file evidence?
- Clear: would someone outside the field understand this without explanation?
- Concise: could you cut anything without the reader missing something? Usually yes.
- Constructive: does the wording move the recipient forward, or only the auditor?
- Complete: is anything missing that the reader needs in order to act?
- Timely: a report that appears three months after fieldwork ends describes an organization that no longer exists.
How to Build a Finding
A finding is complete only when four elements appear explicitly in the text. GIAS does not require this exact wording, but it is the structure the Standards assume, and it appears in nearly every audit methodology:
- Criterion: what are you testing against? Policy, legislation, a standards framework, a contractual agreement. Without a criterion, a finding is an opinion.
- Condition, what you found, supported by what you observed, measured, or tested.
- Cause, why does the condition deviate from the criterion? This is the element most often missing, and precisely the one management can act on.
- Effect, what risk does the organization run as a result, and how large is it?
Without a criterion, the finding reads as a personal preference. Without a cause, the recommendation treats a symptom. Without an effect, the recipient cannot prioritize, and the finding lands at the bottom of the pile.
Significance Is a Judgment You Form Together
Standard 14.3, Evaluation of Findings, requires every potential finding to be evaluated for significance, identifying root causes and establishing possible effects together with management. You determine significance itself from the likelihood that the risk occurs and its impact on governance, risk management, or control processes.
That phrase, "together with management," is not a courtesy. It is why a finding no longer needs to be picked apart during the closing discussion: the facts and the cause analysis have already been shared. Auditors who determine significance alone, after the fact, still have that argument, just in the meeting where the report gets finalized.
Recommendation, Action Plan, or Both
Standard 14.4, Recommendations and Action Plans, lets the auditor choose: draft recommendations themselves, request action plans from management, or agree on actions jointly. The goal stays the same either way: close the gap between criterion and reality, bring the risk down to an acceptable level, address the root cause, or improve the activity.
The standard also explicitly requires discussing recommendations with management of the activity under review before they go into the report.
Whether an audit report should offer advice at all is a discussion of its own, with good arguments on both sides. We have worked that out separately in The Sense and Nonsense of Advice in an Audit Report.
The Conclusion: One Paragraph That Carries the Report
For assurance engagements, a conclusion on effectiveness is mandatory. That conclusion is not the sum of the findings, but a professional judgment you base on them. Three moderate findings can together produce a failing conclusion; they can also all sit beside the main question and leave the conclusion untouched.
What makes a conclusion usable:
- it answers the objective of the engagement in the same terms in which that objective was stated;
- it names the period and the scope it covers;
- it makes clear where the boundary lies on what you examined.
If the audit function works with a rating scale (satisfactory / satisfactory with observations / unsatisfactory, or a variant), define in the audit methodology what each rating means. Otherwise the judgment varies by auditor, and the audit committee notices sooner than you'd expect. A worked example of such a definition is in the Audit Manual template.
If You Disagree With Management
This is the moment reports get softened. Standard 13.1, Engagement Communication, is clear about it: when auditors and management disagree on the results, they must discuss it and try to reach mutual understanding. If that fails, the rule holds: internal auditors must not be required to change any portion of the engagement results, unless there is a valid reason to do so.
The standard also requires an established methodology in which both parties can record their position, including the reason for the disagreement. That is considerably stronger than the compromise practice often settles for: the finding stays, the wording gets softened, and the disagreement disappears from the file.
Who Releases the Report
Under Standard 11.3, Communicating Results, the head of the internal audit function reviews and approves the final communication and decides to whom and how the report is distributed. Delegation is allowed, but final responsibility stays with the CAE. If the report goes to parties outside the organization, the CAE must first seek legal advice or senior management's input where needed.
Six Mistakes That Show Up Most Often
- No criterion. "The process is inadequately controlled" without stating the norm is an opinion, not a finding.
- The report as case file. The reader gets the complete record of work performed instead of the answer. The file belongs in the file.
- Recommendations without an owner or a date. Standard 15.1 explicitly requires both, and without them, nothing happens.
- An executive summary that only summarizes. The executive summary should give the conclusion and its consequence, not a shortened version of every chapter.
- Scope limitations in a footnote. If you were unable to examine something, that partly determines the value of the conclusion. It belongs with the conclusion.
- Too late. Timeliness is one of the seven requirements in Standard 11.2, not an optional nicety.
In Closing
The audit report is the only product of the audit function that most stakeholders ever see. The Standards offer more guidance here than is often assumed: 15.1 for content, 11.2 for quality, 14.3 and 14.4 for findings and actions, and 13.1 for the moment things get tense. Walk through those four before sending, and the result is a report that complies and gets read.