
The most practical internal audit report structure follows this sequence: executive summary → scope and objectives → methodology → findings (using standard finding blocks) → recommendations → management response → action plan → appendices. That is the format used across U.S. federal agencies, state auditors, and major universities, and it aligns with IIA reporting expectations.
TL;DR: Copy the section-by-section template in this guide, fill in your findings using the Condition / Criteria / Cause / Effect / Recommendation block, and download an editable DOCX version via the Ismscalculator readiness assessment to adapt it for your organization.
Table of Contents
- What does a complete internal audit report example include?
- A complete, editable internal audit report example you can copy
- How do you classify findings and set remediation timelines?
- What makes audit report writing actually work?
- How do you collect and track management responses?
- What should you attach as appendices?
- One-page memo template and pre-publication checklist
- Key Takeaways
- The part most auditors skip — and why it costs them
- Ismscalculator speeds up ISO 27001 audit scoping
- Useful sources
What does a complete internal audit report example include?
Every section below is a required element, not optional padding. Use this as your drafting checklist.
Required sections and minimum content
- Cover memo / header: — Audit title, entity audited, period of review, report date, auditor names, distribution list, and classification (e.g., Confidential).
- Management response: — Required per IIA standards. Must include agreement or disagreement, corrective action description, responsible owner, and target completion date.
The University of Michigan sample report uses summary tables to map each audited area to its objective and result, which significantly improves readability for audit committees. Adopt that approach whenever you have three or more findings.
Standard finding block (copyable table)
| Field | What to write |
|---|---|
| Criteria | The standard, policy, or regulation that should be followed (e.g., “Per Policy 4.2, all vendor contracts must be reviewed annually.”) |
| Condition | What you actually observed (e.g., “15 of 40 vendor contracts sampled had not been reviewed in over 24 months.”) |
| Cause | Why the gap exists (e.g., “No automated reminder or ownership assignment exists in the contract management system.”) |
| Effect / Impact | The business risk created (e.g., “Expired contracts expose the organization to unenforceable terms and potential regulatory penalties.”) |
| Recommendation | The specific corrective action, with a measurable outcome and target date. |
| Management response | Management’s agreement or disagreement, planned action, owner, and target date. |
The IIA audit report template confirms that management response, including corrective action, owner, and target date, is a required component of every finding block.
Formatting and sequencing guidance
Executives read the executive summary and stop. Auditors and compliance staff read the findings. Regulators and legal teams go straight to the appendices. Structure accordingly: put the most material findings first, move sensitive personnel matters to a restricted appendix, and never bury the overall opinion at the end of the report.
A complete, editable internal audit report example you can copy
Below is a fully written sample you can adapt. Customize the bracketed fields for your organization.
INTERNAL AUDIT REPORT MEMORANDUM
To: [Audit Committee / Board of Directors] From: [Chief Audit Executive / Internal Audit Department] Date: [Month DD, YYYY] Subject: Internal Audit Report — [Audit Name], [Audit Period] Classification: Confidential Distribution: [See Section 7]
Executive summary
The Internal Audit Department completed a review of [Process/Department] for the period [Start Date] through [End Date]. The audit objective was to assess the adequacy and effectiveness of internal controls over [control area]. Three findings were identified with varying severity levels. Overall, controls are partially effective and require targeted remediation in [specific area]. Management has agreed to all recommendations with target completion dates set in the next several months.
Background and scope
[Organization Name] relies on [Process] to [brief description of business purpose]. This audit was included in the [Year] Annual Audit Plan approved by the Audit Committee. The scope covered [specific systems, locations, transactions, or time periods]. Out of scope: [list exclusions].
Audit objectives:
- Verify that [control objective 1]
- Confirm that [control objective 2]
- Assess compliance with [Policy / Regulation / Standard]
Methodology
Evidence was gathered through structured interviews with [number] process owners, review of [document types], and transactional testing of a sample of [N] items selected using [random / risk-based] sampling. Fieldwork was conducted from [date] to [date]. The audit was performed in accordance with the International Standards for the Professional Practice of Internal Auditing (IIA Standards).
Findings
Finding 1 — Vendor Contract Review Process (High)
- Management response: — Agreed. The Procurement Manager will assign owners and configure alerts by [date]. Full review of overdue contracts will be completed by [date].
Finding 2 — Access Provisioning Controls (Medium)
Finding 3 — Expense Report Documentation (Low)
- Cause: — The expense submission portal accepts submissions without a receipt attachment for amounts under $100 (a misconfigured threshold).
Audit opinion
Based on fieldwork and evidence reviewed, internal controls over [Process] are partially effective. The High finding related to vendor contract management requires prompt remediation. Controls in [other areas tested] are operating as intended.
Distribution list
Final report: Audit Committee, CFO, [Process Owner], Chief Audit Executive. Draft for management response: [Process Owner], [Department Head].
The EPA sample audit report recommends distributing the formal report within two weeks of fieldwork completion, a timeline worth building into your audit plan. For executive audiences, condense the full report to the executive summary plus the findings table. The Washington State Auditor’s Office provides strong examples of quantified findings with management responses and timelines you can use as additional wording models.
For an editable DOCX version of this template, the Ministry of Finance IA report template offers a structured alternate layout with header fields and appendix format worth reviewing alongside this example.
How do you classify findings and set remediation timelines?
Severity ratings give management a clear signal about where to focus first. Use a three-tier or four-tier scale consistently across all audits so the Audit Committee can track trends over time.
Severity rating matrix
| Severity | Criteria | Recommended remediation timeline |
|---|---|---|
| Critical | Immediate financial loss, regulatory violation, or material control failure with no compensating control | 30 days or immediate escalation |
| High | Significant control gap; likely to result in material error, fraud exposure, or compliance breach if unaddressed | 60–90 days |
| Medium | Control weakness with moderate risk; compensating controls exist but are insufficient | 90 days |
| Low | Minor policy deviation; low financial or operational impact; compensating controls are effective | Track in next audit cycle |
Washington State Auditor reports consistently pair quantified findings with specific corrective action timelines, which is the model to follow when presenting findings to a board or regulator.
Pro Tip: Translate technical impact into business impact before presenting to nontechnical executives. Instead of “the access provisioning workflow lacks an approval gate,” write “eight employees received system access without manager approval, creating a risk of unauthorized data exposure.” The second version gets action; the first gets a blank stare.

What makes audit report writing actually work?
The single most effective structural choice is leading every finding with the conclusion, not the background. Executives do not read linearly. State the problem and its business impact in sentence one, then provide the evidence.
How do you collect and track management responses?
Management response is not optional. Per IIA standards, every finding must include management’s agreement or disagreement, the planned corrective action, the responsible owner, and the target date.
Recommended timeline and process
- Issue the draft report — to management within two weeks of fieldwork completion (consistent with the EPA sample report guidance).
- Report open items — to the Audit Committee quarterly, showing finding age, owner, and current status.
Action plan template (copy into your report)
| Finding ref. | Corrective action | Owner | Target date | Status |
|---|---|---|---|---|
| Finding 1 | Assign contract owners and configure renewal alerts | Procurement Manager | [Date] | Open |
| Finding 2 | Reconfigure onboarding approval workflow | IT Security Manager | [Date] | Open |
| Finding 3 | Correct portal expense threshold to $25 | Controller | [Date] | Open |
Pro Tip: When management disagrees with a finding, document their position verbatim and note the auditor’s assessment in a separate field. Never remove a finding because management objects. Escalate unresolved disagreements to the Audit Committee with a brief summary of both positions.
Closure requires evidence, not just a status update. Before marking a finding closed, obtain and retain documentation showing the corrective action was implemented (a screenshot, a revised policy, a system configuration log). The UNCW Internal Audit common findings list is a useful reference for scoping follow-up test steps across common control categories.
What should you attach as appendices?
Appendices hold the evidence that supports findings without cluttering the main report. Anything a reviewer might need to verify a finding goes here; anything a reader needs to understand the finding stays in the body.
Common appendix contents:
- Appendix F: — Prior audit findings and remediation status (for repeat findings)
Label each appendix with a letter and a descriptive title. Reference appendices in the body text by letter (“see Appendix B”). The Ministry of Finance IA report template demonstrates a clean appendix layout with cross-referenced header fields.
Retain working papers (the full evidence file behind the appendices) per your organization’s records retention policy, typically three to seven years. Restrict access to working papers containing sensitive personnel data, PII, or security configurations to authorized audit staff only. For IT-related audits, the types of evidence for ISO 27001 audits guide covers evidence categories and handling practices worth referencing in your methodology section.
One-page memo template and pre-publication checklist
For executive or Audit Committee updates, a short memo plus the findings table is often more effective than the full report. The internal audit report sample template demonstrates both a full report and a short memorandum format suitable for rapid executive review.
One-page memo template (paste into email or Word):
MEMORANDUM To: [Audit Committee / Executive Sponsor] From: [Chief Audit Executive] Date: [Date] Re: [Audit Name] — Summary of Findings
Fieldwork for the [Audit Name] audit is complete. [N] findings were identified: [X] High, [Y] Medium, [Z] Low. The most significant issue is [one-sentence description of top finding and its business impact]. Management has agreed to all recommendations. Full remediation is expected by [date]. The complete report is attached.
Pre-publication checklist
Before issuing any audit report, confirm:
- Every finding references specific evidence (appendix letter or document name)
- Each recommendation has a named owner and a realistic target date
- Management responses are included for all findings
- The executive summary matches the findings section (no contradictions)
- Severity ratings are consistent with the organization’s approved rating scale
- The distribution list is current and approved
- The report is spell-checked and reviewed by a second auditor
- Sensitive data (SSNs, passwords, PII) has been redacted from appendices
For a pre-audit scoping checklist that feeds directly into the scope and methodology sections, the pre-audit assessment guide covers ISO 27001 control areas in detail.
Key Takeaways
A well-structured internal audit report uses the executive summary → findings → management response sequence, with every finding documented in the standard five-field Condition / Criteria / Cause / Effect / Recommendation block.
| Point | Details |
|---|---|
| Use the standard finding block | Every finding needs Condition, Criteria, Cause, Effect, and Recommendation to be actionable and defensible. |
| Classify findings by severity | A three-tier scale (Critical / High / Medium / Low) maps directly to remediation timelines of 30, 60–90, and 90 days. |
| Management response is required | Per IIA standards, every finding must include agreement or disagreement, corrective action, owner, and target date. |
| Distribute the draft within two weeks | Issue the draft to management within two weeks of fieldwork; allow 10 business days for responses before finalizing. |
| Ismscalculator for ISO 27001 scoping | Use Ismscalculator’s readiness assessment to scope IT control areas and estimate remediation effort before drafting the methodology section. |
The part most auditors skip — and why it costs them
Most internal audit reports fail not because the findings are wrong, but because the report is written for the auditor, not the reader. The findings section reads like a compliance checklist. The executive summary buries the lead. Management gets a 40-page document when they needed a one-page memo.
The template in this guide is built around one principle: the reader’s job determines the format. An Audit Committee member needs the overall opinion and the top two risks in 90 seconds. A process owner needs the specific corrective action and the deadline. A regulator needs the evidence trail in the appendices. Writing one document that serves all three audiences means structuring it in layers, not writing it as a single narrative.
The other thing auditors consistently underweight is the management response. A finding without a management response is an observation. A finding with a specific owner, a concrete corrective action, and a date is a commitment. That distinction determines whether the report drives change or sits in a shared drive.
One practical note: the sample wording in this guide is intentionally generic. The most common mistake when adapting a template is leaving the generic language in place. Every condition statement should contain a specific number, a specific system, or a specific date. “Several contracts were not reviewed” is not a finding. “15 of 40 contracts sampled had not been reviewed in over 24 months” is.

Ismscalculator speeds up ISO 27001 audit scoping
When your audit covers IT controls or ISO 27001 compliance, the hardest part is often scoping: which of the 93 Annex A controls are in play, and how much remediation effort is realistic? Ismscalculator’s ISO 27001 readiness assessment gives you a domain-by-domain maturity snapshot across all 14 ISO control areas in minutes, with industry benchmarks you can cite directly in your methodology section.

The assessment exports to PDF, so the output drops straight into your report as supporting evidence for the audit scope and risk prioritization. For a faster pre-audit input, the 2-minute readiness check gives you a quick control-coverage baseline before fieldwork begins. Run it before you finalize scope, and you will spend less time in fieldwork discovering gaps you could have anticipated.
Useful sources
The following authoritative references back the guidance in this article and are worth bookmarking for ongoing use:
- Audit report template — The IIA executive tool
- Sample internal audit report — University of Michigan (sample report)
- Common recommendations for common audit findings — University of Minnesota Office of Internal Audit
- Example audit report (EPA) — Appendix A: Sample audit report (Final 7/96)
- State auditor report with detailed findings and recommendations — Washington State Auditor’s Office
- Common audit findings — UNCW Internal Audit
- Internal audit report sample (template PDF)
- Template for IA Report — Ministry of Finance (template PDF)