Mise en œuvre
12 min de lecture

Internal Audit Report Example: Templates You Can Use Now

support@ismscalculator.com|

Workspace setup for internal audit reporting

The most practical internal audit report structure follows this sequence: executive summary → scope and objectives → methodology → findings (using standard finding blocks) → recommendations → management response → action plan → appendices. That is the format used across U.S. federal agencies, state auditors, and major universities, and it aligns with IIA reporting expectations.

TL;DR: Copy the section-by-section template in this guide, fill in your findings using the Condition / Criteria / Cause / Effect / Recommendation block, and download an editable DOCX version via the Ismscalculator readiness assessment to adapt it for your organization.


Table of Contents

What does a complete internal audit report example include?

Every section below is a required element, not optional padding. Use this as your drafting checklist.

Required sections and minimum content

  • Cover memo / header: — Audit title, entity audited, period of review, report date, auditor names, distribution list, and classification (e.g., Confidential).
  • Management response: — Required per IIA standards. Must include agreement or disagreement, corrective action description, responsible owner, and target completion date.

The University of Michigan sample report uses summary tables to map each audited area to its objective and result, which significantly improves readability for audit committees. Adopt that approach whenever you have three or more findings.

Standard finding block (copyable table)

Field What to write
Criteria The standard, policy, or regulation that should be followed (e.g., “Per Policy 4.2, all vendor contracts must be reviewed annually.”)
Condition What you actually observed (e.g., “15 of 40 vendor contracts sampled had not been reviewed in over 24 months.”)
Cause Why the gap exists (e.g., “No automated reminder or ownership assignment exists in the contract management system.”)
Effect / Impact The business risk created (e.g., “Expired contracts expose the organization to unenforceable terms and potential regulatory penalties.”)
Recommendation The specific corrective action, with a measurable outcome and target date.
Management response Management’s agreement or disagreement, planned action, owner, and target date.

The IIA audit report template confirms that management response, including corrective action, owner, and target date, is a required component of every finding block.

Formatting and sequencing guidance

Executives read the executive summary and stop. Auditors and compliance staff read the findings. Regulators and legal teams go straight to the appendices. Structure accordingly: put the most material findings first, move sensitive personnel matters to a restricted appendix, and never bury the overall opinion at the end of the report.


A complete, editable internal audit report example you can copy

Below is a fully written sample you can adapt. Customize the bracketed fields for your organization.


INTERNAL AUDIT REPORT MEMORANDUM

To: [Audit Committee / Board of Directors] From: [Chief Audit Executive / Internal Audit Department] Date: [Month DD, YYYY] Subject: Internal Audit Report — [Audit Name], [Audit Period] Classification: Confidential Distribution: [See Section 7]


Executive summary

The Internal Audit Department completed a review of [Process/Department] for the period [Start Date] through [End Date]. The audit objective was to assess the adequacy and effectiveness of internal controls over [control area]. Three findings were identified with varying severity levels. Overall, controls are partially effective and require targeted remediation in [specific area]. Management has agreed to all recommendations with target completion dates set in the next several months.

Background and scope

[Organization Name] relies on [Process] to [brief description of business purpose]. This audit was included in the [Year] Annual Audit Plan approved by the Audit Committee. The scope covered [specific systems, locations, transactions, or time periods]. Out of scope: [list exclusions].

Audit objectives:

  • Verify that [control objective 1]
  • Confirm that [control objective 2]
  • Assess compliance with [Policy / Regulation / Standard]

Methodology

Evidence was gathered through structured interviews with [number] process owners, review of [document types], and transactional testing of a sample of [N] items selected using [random / risk-based] sampling. Fieldwork was conducted from [date] to [date]. The audit was performed in accordance with the International Standards for the Professional Practice of Internal Auditing (IIA Standards).

Findings

Finding 1 — Vendor Contract Review Process (High)

  • Management response: — Agreed. The Procurement Manager will assign owners and configure alerts by [date]. Full review of overdue contracts will be completed by [date].

Finding 2 — Access Provisioning Controls (Medium)

Finding 3 — Expense Report Documentation (Low)

  • Cause: — The expense submission portal accepts submissions without a receipt attachment for amounts under $100 (a misconfigured threshold).

Audit opinion

Based on fieldwork and evidence reviewed, internal controls over [Process] are partially effective. The High finding related to vendor contract management requires prompt remediation. Controls in [other areas tested] are operating as intended.

Distribution list

Final report: Audit Committee, CFO, [Process Owner], Chief Audit Executive. Draft for management response: [Process Owner], [Department Head].


The EPA sample audit report recommends distributing the formal report within two weeks of fieldwork completion, a timeline worth building into your audit plan. For executive audiences, condense the full report to the executive summary plus the findings table. The Washington State Auditor’s Office provides strong examples of quantified findings with management responses and timelines you can use as additional wording models.

For an editable DOCX version of this template, the Ministry of Finance IA report template offers a structured alternate layout with header fields and appendix format worth reviewing alongside this example.


How do you classify findings and set remediation timelines?

Severity ratings give management a clear signal about where to focus first. Use a three-tier or four-tier scale consistently across all audits so the Audit Committee can track trends over time.

Severity rating matrix

Severity Criteria Recommended remediation timeline
Critical Immediate financial loss, regulatory violation, or material control failure with no compensating control 30 days or immediate escalation
High Significant control gap; likely to result in material error, fraud exposure, or compliance breach if unaddressed 60–90 days
Medium Control weakness with moderate risk; compensating controls exist but are insufficient 90 days
Low Minor policy deviation; low financial or operational impact; compensating controls are effective Track in next audit cycle

Washington State Auditor reports consistently pair quantified findings with specific corrective action timelines, which is the model to follow when presenting findings to a board or regulator.

Pro Tip: Translate technical impact into business impact before presenting to nontechnical executives. Instead of “the access provisioning workflow lacks an approval gate,” write “eight employees received system access without manager approval, creating a risk of unauthorized data exposure.” The second version gets action; the first gets a blank stare.


Severity rating matrix — overview diagram

What makes audit report writing actually work?

The single most effective structural choice is leading every finding with the conclusion, not the background. Executives do not read linearly. State the problem and its business impact in sentence one, then provide the evidence.

How do you collect and track management responses?

Management response is not optional. Per IIA standards, every finding must include management’s agreement or disagreement, the planned corrective action, the responsible owner, and the target date.

  1. Issue the draft report — to management within two weeks of fieldwork completion (consistent with the EPA sample report guidance).
  2. Report open items — to the Audit Committee quarterly, showing finding age, owner, and current status.

Action plan template (copy into your report)

Finding ref. Corrective action Owner Target date Status
Finding 1 Assign contract owners and configure renewal alerts Procurement Manager [Date] Open
Finding 2 Reconfigure onboarding approval workflow IT Security Manager [Date] Open
Finding 3 Correct portal expense threshold to $25 Controller [Date] Open

Pro Tip: When management disagrees with a finding, document their position verbatim and note the auditor’s assessment in a separate field. Never remove a finding because management objects. Escalate unresolved disagreements to the Audit Committee with a brief summary of both positions.

Closure requires evidence, not just a status update. Before marking a finding closed, obtain and retain documentation showing the corrective action was implemented (a screenshot, a revised policy, a system configuration log). The UNCW Internal Audit common findings list is a useful reference for scoping follow-up test steps across common control categories.


What should you attach as appendices?

Appendices hold the evidence that supports findings without cluttering the main report. Anything a reviewer might need to verify a finding goes here; anything a reader needs to understand the finding stays in the body.

Common appendix contents:

  • Appendix F: — Prior audit findings and remediation status (for repeat findings)

Label each appendix with a letter and a descriptive title. Reference appendices in the body text by letter (“see Appendix B”). The Ministry of Finance IA report template demonstrates a clean appendix layout with cross-referenced header fields.

Retain working papers (the full evidence file behind the appendices) per your organization’s records retention policy, typically three to seven years. Restrict access to working papers containing sensitive personnel data, PII, or security configurations to authorized audit staff only. For IT-related audits, the types of evidence for ISO 27001 audits guide covers evidence categories and handling practices worth referencing in your methodology section.


One-page memo template and pre-publication checklist

For executive or Audit Committee updates, a short memo plus the findings table is often more effective than the full report. The internal audit report sample template demonstrates both a full report and a short memorandum format suitable for rapid executive review.

One-page memo template (paste into email or Word):


MEMORANDUM To: [Audit Committee / Executive Sponsor] From: [Chief Audit Executive] Date: [Date] Re: [Audit Name] — Summary of Findings

Fieldwork for the [Audit Name] audit is complete. [N] findings were identified: [X] High, [Y] Medium, [Z] Low. The most significant issue is [one-sentence description of top finding and its business impact]. Management has agreed to all recommendations. Full remediation is expected by [date]. The complete report is attached.


Pre-publication checklist

Before issuing any audit report, confirm:

  • Every finding references specific evidence (appendix letter or document name)
  • Each recommendation has a named owner and a realistic target date
  • Management responses are included for all findings
  • The executive summary matches the findings section (no contradictions)
  • Severity ratings are consistent with the organization’s approved rating scale
  • The distribution list is current and approved
  • The report is spell-checked and reviewed by a second auditor
  • Sensitive data (SSNs, passwords, PII) has been redacted from appendices

For a pre-audit scoping checklist that feeds directly into the scope and methodology sections, the pre-audit assessment guide covers ISO 27001 control areas in detail.


Key Takeaways

A well-structured internal audit report uses the executive summary → findings → management response sequence, with every finding documented in the standard five-field Condition / Criteria / Cause / Effect / Recommendation block.

Point Details
Use the standard finding block Every finding needs Condition, Criteria, Cause, Effect, and Recommendation to be actionable and defensible.
Classify findings by severity A three-tier scale (Critical / High / Medium / Low) maps directly to remediation timelines of 30, 60–90, and 90 days.
Management response is required Per IIA standards, every finding must include agreement or disagreement, corrective action, owner, and target date.
Distribute the draft within two weeks Issue the draft to management within two weeks of fieldwork; allow 10 business days for responses before finalizing.
Ismscalculator for ISO 27001 scoping Use Ismscalculator’s readiness assessment to scope IT control areas and estimate remediation effort before drafting the methodology section.

The part most auditors skip — and why it costs them

Most internal audit reports fail not because the findings are wrong, but because the report is written for the auditor, not the reader. The findings section reads like a compliance checklist. The executive summary buries the lead. Management gets a 40-page document when they needed a one-page memo.

The template in this guide is built around one principle: the reader’s job determines the format. An Audit Committee member needs the overall opinion and the top two risks in 90 seconds. A process owner needs the specific corrective action and the deadline. A regulator needs the evidence trail in the appendices. Writing one document that serves all three audiences means structuring it in layers, not writing it as a single narrative.

The other thing auditors consistently underweight is the management response. A finding without a management response is an observation. A finding with a specific owner, a concrete corrective action, and a date is a commitment. That distinction determines whether the report drives change or sits in a shared drive.

One practical note: the sample wording in this guide is intentionally generic. The most common mistake when adapting a template is leaving the generic language in place. Every condition statement should contain a specific number, a specific system, or a specific date. “Several contracts were not reviewed” is not a finding. “15 of 40 contracts sampled had not been reviewed in over 24 months” is.


The part most auditors skip — and why it costs them — overview diagram

Ismscalculator speeds up ISO 27001 audit scoping

When your audit covers IT controls or ISO 27001 compliance, the hardest part is often scoping: which of the 93 Annex A controls are in play, and how much remediation effort is realistic? Ismscalculator’s ISO 27001 readiness assessment gives you a domain-by-domain maturity snapshot across all 14 ISO control areas in minutes, with industry benchmarks you can cite directly in your methodology section.

Ismscalculator

The assessment exports to PDF, so the output drops straight into your report as supporting evidence for the audit scope and risk prioritization. For a faster pre-audit input, the 2-minute readiness check gives you a quick control-coverage baseline before fieldwork begins. Run it before you finalize scope, and you will spend less time in fieldwork discovering gaps you could have anticipated.


Useful sources

The following authoritative references back the guidance in this article and are worth bookmarking for ongoing use:

Prêt à estimer vos coûts ISO 27001 ?

Utilisez notre calculateur gratuit pour obtenir une estimation personnalisée des coûts, de l'effort et du calendrier basée sur votre profil d'entreprise.

Retour à tous les articles