,

Anatomy of an Internal Audit Report: Structures That Serve Every Reader

An internal audit report is one document read by four different people for four different reasons, and its structure either serves all four or fails all of them. The audit committee member reads it for two minutes and wants to know whether something is wrong and whether someone is fixing it. The executive reads it for ten and wants to know what it means for the business she runs and what she has committed to. The process owner reads every word, twice, looking for the sentence that is unfair. The regulator, the external auditor and next year’s auditor read it as a record: what was tested, against what, with what result, and what happened afterward. A report structured for one of them, usually the process owner, because the auditor spent three weeks with him, is a report the other three put down. The structure that serves every reader is a structure by altitude, in which each reader can stop at the layer that answers their question and the layers agree with each other.

Standard 15.1 sets the content: the final engagement communication must include the engagement’s objectives, scope and conclusions, the findings with their elements, the recommendations or action plans, and ratings where the function uses them, along with a statement of conformance with the Standards where that is the function’s practice. Content is not structure, and this guide is about the structure: the four readers and what each needs, the eleven parts of a report and what each is for, a one-page executive summary template, the anatomy of a finding block, the formats a function should keep in its kit and when to use each, the anatomy of MidState Beverage’s payroll audit report with every part’s length and purpose, ten rules for the reader’s eye, and the mistakes that make reports unreadable. It is the structural companion to the report library, which shows three complete reports, and the report template, which gives the skeleton.

In this guide

The four readers and what each needs

ReaderTime spentThe questionWhere the answer has to be
Audit committee memberTwo minutes, often on a phone, often the night before the meetingIs something seriously wrong, is it being fixed, and do I need to ask about it?The title, the rating, and the first three sentences of the executive summary
Executive responsible for the areaTen minutes, before a conversation with the process ownerWhat does this mean for the part of the business I run, what has my team committed to, and will I be embarrassed?The executive summary in full, the findings’ titles and ratings, and the action plans with owners and dates
Process ownerAn hour, twice, with a penIs this fair, is it accurate, and what exactly do I have to do?Every finding block in full, the scope and methodology, and the appendix of detailed results
The record’s readers: regulator, external auditor, next year’s auditor, an external assessorAs long as it takes, months or years laterWhat was tested, against what criteria, with what evidence, and what happened afterward?Scope, methodology, the rating scale, the detailed results appendix, and the finding numbers that the issue log carries forward

The structure by altitude follows from the table. The first layer is a page that the committee member can read on a phone: title, rating, three messages, the count of findings by rating, and the one sentence about what management has committed to. The second layer is the findings at the level of title, rating, owner and date, which the executive scans. The third is the finding blocks in full, which the process owner works through. The fourth is the appendices, which the record’s readers rely on and which nobody else opens. Each layer has to agree with the one above it: the three messages in the summary are the three most important findings, the rating in the summary is the rating the rule produces from the findings, and the finding blocks contain nothing the summary contradicts.

The eleven parts of a report, and what each is for

PartPurposeLengthThe common failure
1. Title and coverName the engagement, the entity, the period covered, the rating and the date, so that the report can be found and understood without opening itOne line and a blockA title that names the process and not the conclusion; a cover without the rating
2. Executive summaryAnswer the committee member’s question in the time she hasOne pageTwo pages of background before the conclusion; the rating buried in paragraph four
3. Objectives, scope and periodState what the engagement set out to conclude on, what was in and out, and for what period, so that the conclusion is read in its limitsHalf a pageScope written as a list of processes without the exclusions; a period that is not stated
4. Methodology and conformanceSay how the work was done: walkthroughs, tests, analytics, samples, criteria, and the statement of conformance with the StandardsHalf a pageMethodology copied from the planning memo and never updated for what was actually done
5. Overall conclusion and ratingState the conclusion Standard 14.5 requires, with the rating and the rule that produced it from the findingsA paragraphA rating with no rule, argued about for weeks; a conclusion that hedges
6. FindingsThe five-Cs blocks with rating, response, owner and date, ordered by rating then by processHalf a page to a page eachFindings ordered by the sequence of testing; responses missing owners and dates
7. Observations and remediated itemsRecord minor items and the findings fixed during fieldwork, so that they are in the record without cluttering the findingsA tableMinor items promoted to findings to make the report look thorough; fixed items omitted so the report looks clean
8. Status of prior findingsReport what happened to the last engagement’s findings in this area, which is the part the committee reads secondA tableOmitted, so that the same finding appears under a new number with no history
9. Rating definitionsDefine the finding and report ratings so that the reader does not have to remember the scaleAn appendixDefinitions that differ from the function’s methodology, or from last year’s report
10. Detailed resultsTest-by-test results, sample sizes, exception counts and the population figures the findings’ numbers come fromAn appendixOmitted, leaving the findings’ numbers unsupported in the document the regulator reads
11. Distribution, confidentiality and acknowledgmentsSay who received the report, the handling restriction, and who was thankedA blockA distribution list that reveals the report went to the wrong people, or an acknowledgment that thanks the auditee for cooperation the file does not show

Scope, methodology and conformance: what the record’s readers look for

The scope and methodology section is the part of the report nobody reads on the day and everybody reads two years later. The regulator reads it to see whether the engagement covered what the plan promised; the external auditor reads it to decide how much reliance to place; the external assessor reads it for conformance; next year’s auditor reads it to know what was tested. It is written for them, and it is short only because it is precise. The elements below are the ones the record’s readers look for and the ones most often missing.

ElementWhat to stateWhy the record’s readers need it
ObjectivesWhat the engagement set out to conclude on, as assurance objectives, not as activitiesThe conclusion is only meaningful against the objective it answers
Scope and exclusionsThe processes, entities, systems and locations in scope, and the ones considered and excluded, with the reasonAn exclusion stated is a scoping decision; one not stated looks like a gap nobody noticed
PeriodThe dates the evidence covers, and the date of the last fieldworkConditions change; the reader needs to know when they were observed
CriteriaThe policies, standards, contracts and control descriptions the conditions were tested againstFindings without criteria are opinions; the record needs the sources
MethodsWalkthroughs, tests of design and operation, analytics on full populations, samples with sizes and selection methods, re-performance, inquiry, with the tests listed or referenced to the appendixReliance decisions depend on what was actually done, and inquiry alone supports nothing
LimitationsData that could not be obtained, populations that could not be proven complete, work not performed and whyA limitation stated protects the conclusion; one omitted undermines it when discovered
Reliance on othersWork of the second line, external auditors or service auditors relied on, and how it was evaluatedThe reader needs to know whose work the conclusion rests on
ConformanceThe statement that the engagement was conducted in conformance with the Global Internal Audit Standards, or the specific departuresRequired by the function’s own charter in most cases, and the first thing an external assessor checks

The executive summary: one page, three decisions

The executive summary is the report for two of the four readers, and it is written last and read first. It makes three decisions for the reader: whether the area is controlled, what the three things that matter are, and whether management’s commitment is adequate. The template below fits on one page in every engagement on this site, and the discipline that keeps it there is that every sentence in it points to something in the body; the summary contains no fact the findings do not.

Executive summary template. 1. Conclusion, first sentence: the overall rating and what it means in the scale’s words, for the area and period named. 2. Why, in three messages: the three findings or themes that drove the rating, each in one sentence with its number and rating, written as a consequence rather than a condition (“the control that verifies vendor bank changes did not operate for 31 of 46 changes, and one attempted diversion was stopped by the bank rather than by MidState”). 3. What is working: one sentence, with evidence, so that the reader knows the scope was not only the failures and so that the process owner’s work is acknowledged where it earned it. 4. Findings by rating: the counts, the count of prior findings closed or still open, and any referral or matter handled outside the report described in one neutral sentence. 5. Management’s commitment: the executive who owns the response, the two or three principal actions with their dates, and the interim measures for any High. 6. Base rates: the denominators that put the numbers in proportion, in one sentence. 7. What the committee is asked to do: note, discuss, or decide, and if decide, what.

Item 7 is the one most summaries omit and most committees want. A report that ends its summary with “the audit committee is asked to note the report” tells the reader they can stop; one that ends with “the audit committee is asked to decide whether the proposed deferral of the depot integration is acceptable” tells them why they are reading. The risk acceptance guide covers the decisions that reach the committee this way.

The summary of findings table: the second layer in one place

Between the executive summary and the finding blocks sits a table that most executives read instead of the blocks, and it deserves more design than it usually gets. It has six columns: the finding number, the title as a consequence, the rating, the process or entity, the action owner by name and role, and the target date, with a seventh for the interim measure where there is one. It is sorted by rating and then by process, it uses the same titles as the blocks word for word, and it fits on one page. Its job is to let the executive see in thirty seconds what her team has committed to and by when, and to let the committee see that every High has a name and a date against it. A report whose table and blocks disagree, a title reworded in one place, a date that moved in the response but not in the table, loses the reader’s trust at exactly the layer where trust is decided, which is why the table is generated from the finding records rather than typed.

Anatomy of a finding block

A finding block is the unit of the report’s third layer, and its anatomy is fixed so that the process owner can find the same thing in the same place in every finding of every report. The five Cs give the content; the block gives the layout. The order below is the one the report library uses, and the reason for the order is the reader: title and rating first because they are what is scanned, condition before criteria because the reader wants to know what happened before what should have, cause before consequence because the cause is what the action plan will address, and the response last because it is management’s voice and it closes the block.

ElementWhat it containsLengthTest before issue
Number and titleThe finding’s number, carried into the issue log, and a title that states the problem as a consequence in under twelve wordsOne lineCould the title stand alone in a list the committee reads?
Rating and its basisThe rating and the scale anchor it meets, in the scale’s wordsOne lineDoes the anchor match the finding’s effect, not its condition?
ConditionWhat was found, as facts with numbers and denominators, the population and the periodThree to six sentencesHas management confirmed every number?
CriteriaWhat should be, with the source citedOne to two sentencesIs the source a document the process owner can open?
CauseWhy the gap exists, at the level the action plan will addressTwo to four sentencesDoes the action plan change the thing this names?
ConsequenceThe effect: mechanism, magnitude, realized instance if anyTwo to four sentencesDoes it justify the rating without an adjective?
Recommendation or agreed actionThe auditor’s recommendation where management has not proposed a plan; otherwise the agreed actionTwo to four sentencesPasses the five tests in the management responses guide?
Management responseManagement’s words: the plan, the owner by name and role, the target date, the interim measure for a HighThree to six sentencesOwner, date, cause-level action, interim measure present?
Auditor’s commentUsed only where the auditor disagrees with the response or the response was returned and not revised; otherwise omittedOne to three sentencesIs it about the plan, not about the person?

The overall conclusion and the rating rule

Standard 14.5 requires an engagement conclusion, and most functions express it as a rating on a three-point scale, Satisfactory, Needs Improvement and Unsatisfactory in the model reports on this site. The rating is only defensible if it follows from the findings under a rule the function has published. The report template carries this site’s model definitions: Satisfactory where the objective is achieved and any findings are contained; Needs Improvement where weaknesses require timely management action, typically one or more Medium findings, or a High finding whose exposure is limited by an effective compensating control or was contained during the engagement; Unsatisfactory where a key control is not designed or not operating and the objective is at significant risk, typically a High with no compensating control, a repeat High, or a pattern of Highs across the process. The rule is in the rating definitions appendix, it is the same in every report, the derivation sentence shows how it was applied (“the rating reflects two High findings on the design of the controls intended to detect a short deposit, both with interim measures in place”), and the rating is applied by the chief audit executive rather than negotiated with the executive. A summary response that disputes the overall rating therefore has to dispute a finding’s rating or the rule’s application, and both are things the function can point to, which is why the rule exists. The severity ratings guide covers the finding scale and the calibration that makes the rule mean the same thing across engagements.

Four formats to keep in the kit

Not every engagement needs the eleven parts. A function keeps four formats, chooses one at planning, and says in the planning memo which it has chosen, because the format decision made at reporting time is always the long one.

FormatStructureLengthWhen to use it
Full assurance reportAll eleven partsEight to twenty pages plus appendicesRisk-based assurance engagements with a rating, findings and an audit committee audience; anything a regulator may read
Short-form reportCover, one-page summary, findings table with title, rating, owner and date, and the finding blocks; scope and rating definitions as a single appendixThree to six pagesFollow-up engagements, small-scope assurance, engagements with three or fewer findings
Dashboard or one-pageRating, three messages, findings by rating, actions and dates, prior status, on one page with the full report as an attachmentOne pageCommittee packs where the full report is available; continuous auditing outputs; program-level reporting across many small engagements
Advisory memoPurpose, what was done, observations and options, without ratings or findings; a clear statement that the work was advisory and no assurance is givenTwo to eight pagesAdvisory engagements under the Standards; pre-implementation reviews; requests for an opinion on a design

Titles and headings: the micro-copy that frames the report

The reader who spends two minutes reads the titles and nothing else, which makes the report’s titles the most consequential sentences in it. The report title names the area and the rating. The finding titles state the problem as a consequence in under twelve words, so that the summary of findings table reads as a list of things that are wrong rather than a list of topics: “Payroll rate changes can be entered and approved by one person” tells the committee what to worry about; “HR workflow segregation” tells them there is a workflow. Section headings do the same work for the process owner, who navigates by them: the finding block’s element labels, Condition, Criteria, Cause, Consequence, Action, Response, are headings, and they are the same words in the same order in every report the function issues. The one place a title should not editorialize is the finding title’s adjective: “Serious weakness in bank change control” adds nothing the rating does not already say and gives the process owner a word to argue about; “Bank changes were not independently verified for 31 of 46 changes” gives him a number, and numbers are argued about with evidence.

Length: how long a report should be

A report is as long as its findings require and no longer, and the arithmetic is simple: one page of summary, one page of scope and methodology, half a page of conclusion, half to one page per finding, half a page of observations and prior status, and the appendices. Eight findings make a twelve-to-fifteen-page report; three findings make a short-form report of five or six. Length grows in two illegitimate ways: background that describes the process for the benefit of a reader who works in it, and findings padded with narrative about how the testing was done, which belongs in the methodology and the appendix. It shrinks in one illegitimate way: findings compressed until the numbers and the cause disappear, which produces a short report that supports nothing. The test is whether each of the four readers gets what they need in the time they have; a fifteen-page report passes that test if its first page does, and a five-page report fails it if its findings have no denominators.

Worked example: the anatomy of MidState’s payroll audit report

MidState Beverage’s payroll audit, written up test by test in that guide, produced eight findings, three of them High, an overall rating of Needs Improvement, and two matters referred under the fraud protocol and kept out of the report. The report ran to fourteen pages and two appendices. The table gives each part, its length and what it did for which reader, because the interesting decisions in a report’s anatomy are the ones about what went where.

PartPagesWhat it contained, and the decision behind it
CoverCover“Payroll: Needs Improvement” as the title line, with the period, the issue date and the distribution; the rating on the cover so that the committee member’s two minutes started with it
Executive summary1Rating first; three messages: the HR workflow that let one administrator enter and approve rate changes, the bank-change verification that did not apply to payroll staff, and the four drivers’ overtime approved by a relative; what was working: the executive channel and the pay-run release; eight findings, three High; “two matters are being handled under the company’s investigation protocol and are not described in this report”; management’s commitment owned by the chief financial officer with the two interim measures; the base rate: 1,400 employees, twelve depots, fourteen months; the ask: note, and confirm the audit committee wishes to receive the protocol’s outcome
Objectives, scope, period, methodology1The twelve tests named with their populations and sample sizes, so that the process owner and the record’s readers could see that the analytics ran on the full population and the samples were where the guide says they were; the outsourced provider’s SOC 1 period stated; the conformance statement
Overall conclusionHalfThe derivation sentence: three High findings on segregation and verification controls, with interim manual reviews in place from the closing meeting, producing Needs Improvement under the definitions in Appendix A
Findings8Eight blocks in rating order, the three Highs first; each with the population numbers management had confirmed; the two findings whose subject matter touched the referred matters written about the control and not the events, with the events’ figures omitted; responses from the HR director and the payroll manager, owners named, dates within two quarters, interim measures for the Highs
Observations and remediated itemsHalfTwo items: the provider’s returned-items resolution by the payroll clerk alone, and the executive payroll’s confidentiality implementation noted as done well; nothing promoted, nothing hidden
Status of prior findingsHalfNone for payroll; the route cash audit’s related segregation finding cross-referenced with its status
Appendix A: rating definitions1The finding scale and the report rule, unchanged from the function’s methodology
Appendix B: detailed results2The twelve tests with populations, samples, exceptions and the analytics’ hit counts before and after corroboration, which is where the “168 to 9” ghost-employee figure lived
Distribution and handlingBlockChief financial officer, HR director, payroll manager, audit committee; confidential; the referred matters’ existence stated, their content withheld

Two of the decisions are worth naming. The referrals were mentioned and not described, which kept the report honest about the fact that something else was happening and kept the investigation’s evidence out of a document with a distribution list, the balance the first 48 hours protocol sets out. And the detailed results went in an appendix rather than into the findings, which let the finding blocks stay at three to six sentences per element while the record’s readers still had every number; the process owner read both, and the committee read neither, which is what the structure by altitude is for.

Ten rules for the reader’s eye

The rating on the cover and in the first sentence, never later. Titles that state consequences, not topics: “Bank changes are not independently verified” rather than “Vendor master maintenance”. Findings in rating order, so that the executive who reads the first two has read the worst two. One idea per paragraph and one paragraph per element, so that the process owner can find the cause without reading the consequence. Numbers with denominators every time, in the summary and in the blocks. Management’s words in management’s voice, marked as such, never paraphrased by the auditor. Dates as dates and owners as names; “Q2” and “management” are not commitments. Prior findings’ status in every report, even when there were none, so that the reader learns to look for it. Appendices for everything the committee will not read and the regulator will. And the same structure in every report the function issues, because a reader who knows where things are reads faster, and a reader who reads faster reads more. The report writing guide covers the sentences; the guide to why reports put everyone to sleep covers what happens when these rules are ignored.

Common mistakes

Background before conclusion, so that the committee member reads about the process for a page before learning whether it works. A rating with no rule, or a rule that changes between reports. Findings in the order they were found. Executive summaries that summarize the report instead of deciding for the reader. Responses paraphrased into the auditor’s voice, which makes the commitment the auditor’s. Detailed results omitted to keep the report short, leaving the findings’ numbers unsupported in the record. Prior findings ignored, so that history restarts every year. Referrals either described in detail or not mentioned at all. Acknowledgments that thank management for a cooperation the file documents as reluctant. And a format chosen at reporting time, which is always the long one, because by then everything seems important.

Where to go next

Structure every report by altitude, keep the four formats in the kit and choose one at planning, write the summary last and the rating first, fix the finding block’s anatomy and never vary it, and put the record in the appendices. The three complete reports in the report library show the anatomy at full length; the report template gives the skeleton to fill; the life of a finding covers what happens to each finding before and after it appears in the block; the management responses guide covers the last element of the block; and the negotiating findings guide covers what happens to the draft between the auditor and the executive.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading