Most internal audit reports are read by exactly one person all the way through, and that person wrote it. The audit committee reads the rating and the first finding. The CFO reads the executive summary and skips to the management responses to see who was blamed. The process owner reads their own findings and nothing else. Everyone else reads the subject line of the email. This is not because the readers are lazy; it is because the report was written for the file, in the order the work was done, in the language of the workpapers, with every fact given equal weight and every conclusion cushioned against challenge. A report that took 60 hours to write and transmits nothing to the people who could act on it has failed at the only thing a report is for.
This guide is about writing reports that get read and acted on, without giving up the precision that makes them defensible. It covers the four readers and what each needs, a structure that puts the conclusion first, a formula for a 150-word executive summary, the five Cs applied to findings with eight finding headlines rewritten, twelve language rules with a jargon-to-plain-English table, how ratings and management responses should read, a complete before-and-after rewrite of a real finding from MidState Beverage’s route cash report, a length and layout standard, the drafting process that produces one draft instead of four, and the mistakes that put readers to sleep. It was rewritten in September 2026 to reflect Standard 15.1 of the Global Internal Audit Standards on final engagement communications and current practice in committee reporting. The report’s structure and shells are in the site’s internal audit report template; this guide is about what goes in the boxes.
In this guide
- The four readers and what each one needs
- Structure: the conclusion first, the evidence behind it
- The executive summary in 150 words
- Findings that land: the five Cs and eight headlines rewritten
- Twelve language rules, and the jargon table
- Ratings, tone, and the management response
- Before and after: a real finding rewritten
- Length, layout, and tables
- A drafting process that produces one draft
- Common report-writing mistakes
The four readers and what each one needs
A report has four readers with four different questions, and a report that answers them in the order the readers arrive is the one that gets read. The audit committee member has four minutes and wants to know whether anything is wrong that they will be held accountable for. The executive who owns the area has fifteen minutes and wants to know what they have to fix, by when, and what it will cost them. The process owner has an hour and wants the facts to be right and the cause to be fair. The external auditor, regulator, or external quality assessor has as long as they like and wants the evidence trail. Standard 15.1 requires the final communication to include the engagement’s objectives, scope, conclusions, findings, and management’s action plans, and to be accurate, objective, clear, concise, constructive, complete, and timely; the table below is what those seven words mean for each reader.
| Reader | Time they will give it | Their question | What answers it | Where it must be |
|---|---|---|---|---|
| Audit committee member | 4 minutes | Is anything wrong that matters, and is management dealing with it? | The rating, the one-paragraph conclusion, the High findings by headline, and whether management agreed | Page one, above the fold; repeated in the committee pack summary |
| Executive owning the area (CFO, COO, VP) | 15 minutes | What do I have to fix, by when, at what cost, and does it reflect on me? | Each finding’s headline, its consequence in business terms, the action, the owner, and the date; the cause stated without blame | Executive summary plus the findings table; findings on one page each |
| Process owner | 1 hour | Are the facts right, is the cause fair, and can I do what is asked? | Condition stated with the population, sample, and exceptions; cause traced to a specific gap; actions they agreed at the closing meeting | The finding detail and the management response printed as they wrote it |
| External auditor, regulator, quality assessor | As long as needed | Does the conclusion follow from the work, and does the work meet the Standards? | Objectives, scope, criteria, methodology, limitations; the trail to workpapers | Scope and approach section and the appendix, not the body |
The order matters because reports are read top-down and abandoned early. A report that opens with background, then scope, then methodology, then findings in the order the work was done, then a conclusion, serves the fourth reader first and loses the first three before the conclusion arrives. Inverting it costs nothing: the same content, arranged so that each reader finds their answer where their attention runs out. The report examples guide shows complete reports arranged this way.
Structure: the conclusion first, the evidence behind it
The structure below is the inverted pyramid applied to an audit report: the most important thing first, each subsequent section adding detail for the reader who wants it. The lengths are limits, not targets, and a report that comes in under them is better than one that fills them.
| Section | Purpose | Length | Written for | Rules |
|---|---|---|---|---|
| Title block | Identify the engagement, the rating, the date, and the distribution | Quarter page | Everyone | The rating is on the cover, in words, not buried on page four |
| Executive summary | The conclusion, why, and what happens next | 150 to 200 words | Committee and executive | Formula below; no background, no methodology, no hedging |
| Findings at a glance | Every finding on one line: headline, rating, owner, due date, management position | One table, half a page | Committee and executive | Sorted by rating, then by exposure; this table is what the committee pack reproduces |
| Findings in detail | Condition, criteria, cause, consequence, corrective action, management response | One page per finding, at most | Executive and process owner | Five Cs in a fixed order; the headline is a sentence with a verb and a number |
| Observations and good practice | Points that are not findings: efficiency, accepted risks, practices worth spreading | Half a page | Process owner | Clearly separated so they are not read as findings |
| Objectives, scope, approach, and limitations | What was and was not covered, how, and what the conclusion cannot establish | Half a page to one page | External reader and quality assessor | Limitations stated in terms of the detection risk that remains; never omitted |
| Appendices | Rating definitions, sample details, analytics descriptions, distribution | As needed | External reader | Nothing the first three readers need is allowed to live only here |
The findings-at-a-glance table is the single highest-value page in the report and the one most functions do not have. It is the page the committee pack reproduces, the page the CFO forwards, and the page the issue log is built from; the issue log template uses the same columns so that the two never disagree. Scope, approach, and limitations move toward the back not because they are unimportant but because their reader is the one with time; a quality assessor will find them, and a committee member will never reach page four to look.
The executive summary in 150 words
The summary has four sentences of work to do, and 150 words is enough for all of them. What was audited and why, in one sentence, with the number that shows the stakes. The conclusion and rating, in one sentence, stated without a hedge. The two or three things that drove the rating, each a headline with a number. What management is doing, with the latest date. Everything else, including how hard the team worked, how cooperative the auditee was, and the history of the area, belongs elsewhere or nowhere. The before-and-after below shows the formula on MidState’s FY27-01 report; the first version is representative of what most functions issue.
Before (238 words). Internal Audit has completed its review of the route cash handling process in accordance with the FY27 Internal Audit Plan approved by the Audit Committee. The objective of the review was to assess the design and operating effectiveness of controls over the collection, settlement, reconciliation, and deposit of cash and check payments received by drivers from customers across the Company’s twelve depots. The review was conducted between January and March and included walkthroughs, interviews with depot management and staff, testing of a sample of settlement transactions, data analytics, and site visits to selected depots. Overall, it was noted that while certain controls are in place and operating, a number of opportunities for improvement were identified in relation to the independence of reconciliation activities, the approval of variance overrides, the monitoring of handheld synchronization failures, the recording of deposit listings, and the issuance of customer statements. Management has been responsive and has agreed action plans to address the matters raised, which Internal Audit will follow up in due course. Based on the work performed, the overall rating assigned to the route cash handling process is Unsatisfactory. Internal Audit would like to thank depot management and the finance team for their cooperation during the review. Further details of the findings, including root causes and agreed management actions, are set out in the body of this report, and the scope, approach, and limitations of the review are described in Appendix A.
After (148 words). Drivers on MidState’s 300 routes collect about $31 million a year in cash and checks from 4,200 customers, and a Dayton driver diverted $18,400 over five months in FY26 before a customer complaint exposed it. We audited the controls over settlement, reconciliation, and deposit at all twelve depots and rate them Unsatisfactory. At nine of twelve depots the depot manager both prepares and approves the daily settlement reconciliation, so no one independent checks that cash collected was cash deposited. Settlement variances were written off by the clerks who created them in 1,412 of 37,400 settlements last year, with no review against the $25 tolerance. And 1,130 of 4,200 customers receive no monthly statement, so the customer cannot catch what the depot missed. Management agrees with all five findings; the reconciliation and override controls will be redesigned by 30 June, with regional finance reviewing depot reconciliations from 1 April.
The second version is shorter and contains more information: the exposure, the fraud history, the rating, three findings with populations and counts, the causal chain that connects them, management’s position, and two dates. The first version contains the rating and nothing a committee member could repeat at dinner. Note also what the rewrite removed: the description of the work (which is scope, and goes at the back), “it was noted” (nobody noted anything; the auditors found it), “opportunities for improvement” (they are control failures), “in due course” (a date or nothing), and the thanks (which belong in an email).
Findings that land: the five Cs and eight headlines rewritten
A finding has five parts, and the order in which they are written is the order in which a reader can absorb them: the condition (what is, with the population and the exceptions counted), the criteria (what should be, cited), the cause (why the gap exists, traced to a specific missing or failed control, never to a person), the consequence (what could happen or has happened, in business terms and where possible in dollars), and the corrective action (what will change, who owns it, by when). The site’s 5 Cs guide covers each part in depth. What this guide adds is the headline: the one sentence at the top of the finding that a committee member will read instead of the finding, which should carry the condition and its scale in a form that could be repeated from memory. The table rewrites eight headlines of the kind found in most reports.
| Original headline | What is wrong with it | Rewritten headline |
|---|---|---|
| Segregation of duties weaknesses in settlement reconciliation | Jargon; no scale; no location | At 9 of 12 depots the depot manager both prepares and approves the daily cash reconciliation, so no one independent checks that cash collected was deposited |
| Variance override approval process requires enhancement | “Enhancement” hides a control failure; no numbers | Settlement clerks approved their own variance write-offs in 1,412 of 37,400 settlements last year, with no review against the $25 tolerance |
| Opportunities exist to improve monitoring of system exceptions | “Opportunities exist” is a euphemism; which system, which exceptions? | Handheld sync failures on 61 route-days went unreviewed because the exception report is generated but not assigned to anyone |
| Inconsistent customer statement practices noted | “Noted” and “inconsistent” say nothing | 1,130 of 4,200 cash-paying customers receive no monthly statement, removing the one check outside the depot on what they were charged |
| User access review not performed timely | How late? For what? So what? | The quarterly access review for the route accounting module was last completed 14 months ago; 38 users hold administrator rights, 11 of them in depot roles |
| Documentation gaps identified in vendor onboarding | Gaps in what, for how many vendors? | 23 of 60 vendors added in FY26 have no evidence of the bank-detail callback, the control that prevents payment redirection |
| Control environment could be strengthened | Unfalsifiable; not a finding | Either delete it or state the specific control failure it stands for |
| Management review of journal entries requires improvement | Which entries, how many, what review? | 14 of 25 manual journal entries over $50,000 sampled were approved by the preparer’s direct report, who cannot challenge them |
Every rewrite follows the same pattern: a count against a population, a location or object, and a clause that says why it matters, in one sentence with a verb. The pattern does more than communicate; it disciplines the audit. A finding that cannot be headlined this way usually has not established its condition, and the attempt to write the headline sends the auditor back to the workpapers to count. The severity ratings guide covers how the consequence clause maps to the rating.
Twelve language rules, and the jargon table
Audit prose has a dialect, and the dialect is the problem. It was developed to avoid being wrong, and it succeeds by never saying anything definite enough to be wrong, which is also never definite enough to be acted on. The twelve rules below are the house style of functions whose reports get read; they are compatible with precision, and in most cases they increase it, because a sentence that names the actor, the count, and the consequence is harder to get wrong than one that gestures at all three.
| # | Rule | Instead of | Write |
|---|---|---|---|
| 1 | Active voice, named actor | “Reconciliations were not reviewed independently.” | “The depot manager approved their own reconciliations at nine depots.” |
| 2 | Numbers, not adjectives | “A significant number of overrides were self-approved.” | “1,412 of 37,400 settlements (3.8 percent) had self-approved overrides.” |
| 3 | Name the population and the sample | “Testing identified exceptions.” | “Of 60 settlement reconciliations re-performed across all twelve depots, 14 could not be agreed to the bank deposit.” |
| 4 | One hedge at most | “It would appear that there may potentially be a risk that…” | “There is a risk that…” or, better, state the exposure |
| 5 | Delete “it was noted”, “it was observed”, “Internal Audit noted” | “It was noted that statements were not issued.” | “Statements were not issued to 1,130 customers.” |
| 6 | Consequence in business terms | “This could result in control weaknesses.” | “A driver who skims a route has no independent check between the customer and the bank.” |
| 7 | Cause is a control gap, not a person | “The clerk failed to follow procedure.” | “The module allows the clerk who records a variance to approve it; no role separation was configured at implementation.” |
| 8 | Actions have an owner and a date | “Management should consider enhancing the review process.” | “Regional finance will review all depot reconciliations from 1 April; the depot manager’s approval right is removed by 30 June. Owner: Director of Route Accounting.” |
| 9 | Define or delete evaluative words | “Controls were adequate / appropriate / robust.” | “Controls were designed to detect variances over $25 and operated in all 60 items tested.” |
| 10 | Sentences under 30 words, paragraphs under 100 | A 70-word sentence with three subordinate clauses | Two or three sentences |
| 11 | Present tense for conditions, past for the work | “There was no independent review.” | “There is no independent review. We re-performed 60 reconciliations.” |
| 12 | No thanks, no process narrative, no throat-clearing in the body | “Internal Audit would like to thank…”; “In accordance with the plan…” | Nothing; the email carries the thanks and the scope section carries the plan reference |
The jargon table below is the second half of the style: terms that mean something precise to auditors and nothing to the executives who own the findings. The rule is not to avoid the term but to say what it means in the sentence where it appears, once, and thereafter to use the plain form.
| Audit term | What the executive hears | Plain form |
|---|---|---|
| Segregation of duties | An HR concept | “The same person records and approves; no one checks” |
| Design deficiency / operating deficiency | Nothing | “The control cannot catch this” / “The control exists but was not done” |
| Compensating control | An excuse | “Another check that partly covers the gap” |
| Population / sample / exception | Statistics | “Of the 37,400 settlements last year, we tested 60 and 14 failed” |
| IPE (information produced by the entity) | Nothing | “The report the reviewer relies on has not itself been checked for accuracy” |
| Remediation | Something IT does | “The fix” |
| Root cause | Blame | “Why this keeps happening” |
| Residual risk | Nothing | “What can still go wrong after the controls” |
| Key control | All controls | “The one check that matters here” |
| Management letter point / observation | A finding they can ignore | Say which it is: a finding with an action, or a suggestion with none |
| Reasonable assurance | A hedge | “We tested enough to be confident, not certain; here is what we did not cover” |
| Scope limitation | The auditors’ problem | “We could not test X because Y; this is what that leaves unknown” |
Ratings, tone, and the management response
The rating is the most-read word in the report, and it should be set against the function’s written definitions, not against the temperature of the closing meeting. A report that softens Unsatisfactory to Needs Improvement because the operations vice president objected teaches every reader that ratings are negotiated, and the next Unsatisfactory will be negotiated too. The tone that supports a hard rating is neutral and factual rather than stern: no adjectives about management, no “concerning”, no “disappointing”, just the counts, the criteria, and the consequence. Facts carry the rating; adjectives undermine it, because they invite an argument about tone instead of a conversation about the gap.
Management’s response is printed under each finding as management wrote it, including disagreement. Standard 15.1 requires the final communication to include management’s action plans, and where management has accepted a risk the function considers too high, the chief audit executive escalates to the board; the report is where that disagreement becomes visible, and editing it out of the report does the committee a disservice. A response that says “management disagrees with the rating because the regional finance review, implemented 1 April, addresses the exposure” followed by the audit lead’s one-sentence reason for keeping the rating is the most credible page in any report, because it shows the committee a real disagreement resolved by evidence rather than a consensus reached by softening. The auditee’s guide has the response template management should be using, and functions that share it before the draft goes out receive responses that are shorter, dated, and owned.
Before and after: a real finding rewritten
The finding below is Finding 2 from MidState Beverage’s FY27-01 route cash report, on self-approved variance overrides. The first version is the draft as it left the senior auditor’s hands; it is accurate, complete, and unreadable. The second is what was issued. Both are followed by the same management response, which is printed as management wrote it.
Before. Finding 2: Variance override approval process (High). Condition: During the course of fieldwork, Internal Audit performed data analytics over the population of settlement transactions processed through the route accounting module during the twelve-month period under review. It was noted that in a number of instances, variance overrides had been processed by settlement clerks without evidence of independent approval having been obtained in accordance with the Route Cash Handling Procedure (RCH-04), which requires that variances in excess of the established tolerance be approved by depot management prior to posting. Analysis indicated that approximately 3.8% of settlements were affected. Criteria: RCH-04 section 5.2; COSO Principle 10. Cause: The route accounting module does not currently enforce segregation between the recording and approval of variance overrides, and depot management review of the variance report is not consistently performed. Consequence: In the absence of independent approval, there is an increased risk that variance overrides could be utilized to conceal misappropriation of cash receipts or errors in settlement processing, which may not be detected on a timely basis. Recommendation: Management should consider enhancing system controls to enforce segregation of duties over variance overrides and should reinforce the requirement for depot management review of variance reports.
After. Finding 2: Settlement clerks approved their own variance write-offs in 1,412 of 37,400 settlements, with no review against the $25 tolerance (High). What we found: In FY26, 1,412 settlements (3.8 percent of 37,400) carried a variance override entered and approved by the same settlement clerk, at all twelve depots. The route accounting module lets the clerk who records a variance approve it, and the daily variance report that depot managers are meant to review was not reviewed at nine depots in any of the three months we tested. 38 route-days across four depots showed overrides at exactly the $25 tolerance on consecutive days, a pattern we have referred to the General Counsel. What should happen: Procedure RCH-04 requires a depot manager to approve any variance over $25 before it posts. Why it happened: The approval role was never separated from the recording role when the module was implemented in 2013, and no one owns the variance report. Why it matters: A driver who under-remits and a clerk who writes off the difference leave no trace that anyone independent has seen; this is the mechanism by which the FY26 Dayton diversion of $18,400 went undetected for five months. What will change: Approval rights for overrides are removed from the settlement clerk role and assigned to depot supervisors (IT, by 31 May); the variance report is assigned to regional finance for daily review with sign-off in the module (Director of Route Accounting, from 1 April); overrides at or near tolerance are added to the monthly analytics (Internal Audit, from 1 April).
Management response (VP Operations). Management agrees with the finding. The role change has been requested from IT with a target of 31 May 2027. Regional finance began reviewing the daily variance report on 1 April 2027 as an interim measure. Management does not agree that the pattern of overrides at tolerance indicates misconduct at all four depots and notes that two of the four have high-volume routes where small variances are routine; management supports the referral so that the question is settled.
The two versions rest on the same workpapers. The second is a little longer because it carries more facts: it leads with the number, names the actor in every sentence, replaces the labels (Condition, Criteria, Cause) with the questions a reader is actually asking, ties the consequence to the specific loss the company already suffered, and turns “management should consider” into three actions with three owners and two dates. The management response is printed with its disagreement intact, and the disagreement is more useful to the committee than agreement would have been, because it tells them exactly what the referral will settle. The workpaper example shows the file behind a finding like this one, and the issue validation guide what it takes to close the three actions.
Length, layout, and tables
Length is a decision, not an outcome. A report on a single-process engagement should run six to ten pages including appendices, with the executive summary and findings-at-a-glance on the first page and each finding on one page. A twelve-finding report is usually a report with six findings and six observations that have been promoted, and the promotion costs the six real findings their attention. Layout does three things for the reader: it makes the rating and the headlines findable in a scan, it keeps the five parts of each finding in the same place on every page so the reader learns where to look, and it puts numbers in tables rather than in sentences. A table of depots against exceptions communicates the nine-of-twelve pattern instantly; a sentence listing nine depot names communicates nothing. What layout should not do is decorate: heat maps with no scale, dashboards with no baseline, and stock imagery signal a report written to impress rather than to inform, and committee members know the difference. The report template sets the page layouts and the house rules that produce this consistency.
A drafting process that produces one draft
Reports that go through four drafts are usually reports whose facts were not settled before the writing started. The process below front-loads the settlement of facts and the agreement of actions, so that the draft is the first written form of decisions already made, and it fits inside the ten business days from closing meeting to final that Standard 15.1’s timeliness requirement implies for most engagements.
| Step | When | Who | Output | What it prevents |
|---|---|---|---|---|
| Finding headlines drafted as each finding firms up | During fieldwork | Auditor | One-sentence headline with count and population for each finding | Findings whose condition was never established |
| Facts confirmed with the process owner | Before the closing meeting | Auditor and process owner | Condition and criteria agreed in writing, or the disagreement recorded | Factual disputes in the draft cycle |
| Closing meeting: cause, consequence, rating, actions | Final week of fieldwork | Audit lead, process owner, executive | Agreed actions with owners and dates; rating previewed against the definitions | Actions invented by the auditor and rejected by management |
| Draft written from the closing notes | Two business days after the closing meeting | Auditor | Complete draft in the template | Writing before the decisions are made |
| Readability pass | Same day | Auditor, then audit lead | Twelve rules applied; headlines tested aloud; word counts checked against the limits | Dialect surviving into the issued report |
| Quality review | Next business day | Audit manager or CAE | Facts traced to workpapers; rating checked against definitions; one round of comments | Reviewer rewriting rather than reviewing |
| Draft to management for response | Day 4 | Audit lead | Response window of five business days with the template attached | Late, long, or unowned responses |
| Final issued | Day 10 | CAE | Report with responses printed verbatim; findings table to the issue log | Drift between report and log |
The readability pass is the step most functions do not have and the one that changes the output most. It takes twenty minutes: read the executive summary aloud and cut anything that cannot be said in one breath; check that every finding headline has a number; search the document for “it was noted”, “opportunities”, “consider”, “appropriate”, “adequate”, and “in due course” and replace each; confirm every action has an owner and a date. The business writing guide covers the general craft, and the data storytelling guide covers how to present the numbers the rules above insist on.
Common report-writing mistakes
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Chronological structure | Background, scope, method, then findings, then conclusion | Three of the four readers leave before the conclusion | Conclusion and rating first; scope and method at the back |
| The 400-word executive summary | A summary that describes the work, thanks the auditee, and mentions the rating at the end | The committee reads nothing else; if the summary is empty, the report is | The four-sentence formula; 150 words |
| Headlines without numbers | “Weaknesses noted in reconciliation controls” | Cannot be remembered, repeated, or acted on | Count against population plus consequence, in one sentence |
| Passive voice throughout | “Approvals were not obtained” | No actor, so no owner, so no action | Name who did or did not do what |
| Hedge stacks | “May potentially result in a possible risk” | Reads as the auditor not believing their own finding | One hedge, or the exposure stated plainly |
| Euphemism for failure | “Opportunities for improvement”, “enhancement”, “strengthening” | Management hears a suggestion, not a control failure; the issue log fills with unactioned suggestions | Call a control failure a control failure; reserve “observation” for things that are not |
| Cause as blame | “The clerk did not follow procedure” | Personalizes the finding; the systemic gap is never fixed | Cause is a missing or failed control; people appear only as roles |
| Recommendations instead of actions | “Management should consider…” | Nothing to validate; nothing overdue; nothing in the log | Actions with owner and date, agreed at closing; recommendations only where management has not yet decided |
| Editing the management response | Disagreement smoothed into agreement in the final | Misleads the committee; destroys the response’s value as a record | Print it as written; add the audit lead’s one-line position where there is disagreement |
| Softened rating | Unsatisfactory becomes Needs Improvement after the closing meeting | Every future rating is negotiable | Rate against the definitions; record the disagreement |
| No limitations paragraph | A conclusion with no statement of what the work could not establish | When a loss surfaces, the committee believes it was told the area was clean | Limitations written from the detection risk that remains |
| Decoration instead of information | Heat maps without scales, stock photos, logos on every page | Signals a report written to impress; hides the absence of numbers | Tables with counts; one rating graphic at most |
A report is read by people with four minutes, fifteen minutes, an hour, and all day, in that order, and it succeeds when each of them finds their answer before their time runs out. Everything in this guide serves that: the structure, the 150-word summary, the numbered headlines, the twelve rules, the printed disagreement. The site’s older piece on why no one reads audit reports made the diagnosis in three paragraphs; this is the treatment.
Related guides
- Internal audit report template — the shells and house rules this guide fills
- Internal audit report examples — complete reports arranged conclusion-first
- The 5 Cs of audit findings — condition, criteria, cause, consequence, corrective action in depth
- Finding severity ratings — mapping consequence to rating
- Audit issue log template — the findings table’s second life
- The auditee’s guide — the management response template
- Issue validation — closing the actions the report creates
- GIAS Domain V: performing — Standard 15.1 on final communications
- Effective business writing — the general craft
- Data storytelling and evidence — presenting the numbers
- All Guides — the full index
Leave a Reply