Every audit begins with a letter, and most of those letters are the reason auditees dread audits. They arrive without warning, cite a charter the reader has never seen, demand documents by a date chosen for the auditor’s convenience, and say nothing about what the audit is for, how long it will take, or what will happen to the results. The rest of the engagement’s communication follows the same pattern: a kickoff meeting that restates the letter, silence for four weeks, and a draft report that is the first the process owner hears of the findings. None of that is required by any standard, and all of it makes the audit slower, the evidence harder to get, and the findings harder to land.
This pack is the four documents that run an engagement’s communication with the people being audited: the notification letter, the kickoff deck, the weekly status one-pager, and the closing meeting agenda. Each is given in full, annotated for tone and content, with the wording for the difficult moments, delays, scope changes, disputed findings, and the finding nobody expected. MidState Beverage’s route cash audit, an engagement that ended in an Unsatisfactory rating with the relationship intact, is the worked example. The pack is written from the auditor’s side; the auditee’s guide on this site is the same engagement seen from the other chair, and the two are meant to be read together.
In this guide
- Four principles, and what the Standards require
- The communication timeline of an engagement
- Template 1: the notification letter
- Template 2: the kickoff deck
- Template 3: the weekly status one-pager
- Template 4: the closing meeting agenda
- Wording for the difficult moments
- Worked example: MidState’s route cash audit, end to end
- Common mistakes
Four principles, and what the Standards require
The Global Internal Audit Standards ask for two things here. Standard 13.1 requires internal auditors to communicate with the auditee about the engagement, its objectives, scope, timing, and expectations, at the start and throughout, and Standard 11.1 requires the function to build relationships and communicate with stakeholders in a way that supports trust and cooperation. Neither standard prescribes a letter or a meeting; both are satisfied by a pack that follows four principles. No surprises: the process owner hears every finding from the auditor before it is written down anywhere. Specific over formal: dates, names, and document titles rather than charter citations. Time is the auditee’s cost: every request states what it is for and how long it should take. And the rating is never negotiated in a corridor: disagreements are handled in the room, recorded, and reported, which is what protects both sides.
| Principle | What it changes in the pack | What it prevents |
|---|---|---|
| No surprises | Findings are shared at the weekly status and confirmed at the closing meeting before any draft; the draft report contains nothing the process owner has not already heard | The draft-report ambush, and the weeks of dispute that follow it |
| Specific over formal | The letter names the auditor, the dates, the documents, and the people; it does not cite the charter or the Standards | The reader’s first reaction being “what is this” instead of “what do they need” |
| Time is the auditee’s cost | Every document request carries a purpose and an estimate; walkthroughs are scheduled in one block; status notes list what is still needed and nothing else | The forty-item request list nobody prioritizes, and the process owner who stops answering |
| Disagreement in the room | The closing agenda has a fixed slot for disagreement; the status note records disputed points as disputed | Ratings changed by email after the meeting, and findings softened without a record |
The guide to what auditees fear covers the other side of these principles; the short version is that auditees fear being blamed, being surprised, and losing time, and every document in this pack is built to remove one of those fears before it takes hold.
The communication timeline of an engagement
| Communication | When | From | To | Purpose | Template |
|---|---|---|---|---|---|
| Heads-up call | Three to four weeks before fieldwork | Audit manager | Responsible executive | No executive learns of an audit from a letter; five minutes on what and when | None; a call |
| Notification letter | Two to three weeks before fieldwork | Audit manager or CAE | Process owner, copied to the executive | What, why, when, who, what is needed first, what happens after | 1 |
| Initial document request | With the letter | Engagement lead | Process owner | The ten to fifteen items needed to plan, each with a purpose and a date | Attached to 1 |
| Kickoff meeting | First day of fieldwork, or the week before | Engagement lead presents; manager attends | Process owner and the people who will be interviewed | Scope, approach, schedule, logistics, how findings will be handled, questions | 2 |
| Weekly status note | Every Friday of fieldwork | Engagement lead | Process owner, copied to the executive and the audit manager | Progress, outstanding requests, emerging observations, next week | 3 |
| Observation discussions | As observations arise | Engagement lead | The person who operates the control | Confirm the facts before anything is written; the first line of no surprises | Within 3 |
| Closing meeting | Last day of fieldwork or within a week | Audit manager chairs; lead presents | Process owner, responsible executive | Every finding, its evidence, the proposed rating, management’s initial response, disagreements recorded | 4 |
| Draft report | Within two to three weeks of the closing meeting | CAE | Process owner and executive | Written confirmation of what the closing meeting agreed; management responses requested by a date | The report template |
| Final report and thanks | After responses | CAE | Distribution list; a separate note to the auditee team | The record; and an acknowledgment of the auditee’s time, which costs nothing and is remembered | None |
Template 1: the notification letter
The letter is one page. It is addressed to the process owner by name, copied to their executive, and sent by email from the audit manager or the CAE after the heads-up call. It answers the six questions every recipient has, in the order they have them, and it attaches the initial document request as a separate page so the letter itself stays readable.
Subject: Internal audit of [process or area], fieldwork from [date]
Dear [first name],
As [executive] mentioned when we spoke on [date], Internal Audit will be reviewing [process or area] this [quarter], as part of the annual plan the Audit Committee approved in [month]. This letter sets out what we will look at, when, who will be involved, and what we need from your team to start.
What we will look at. The review covers [scope in one or two plain sentences: the processes, locations, systems, and period]. The objective is to assess whether [the objective in the auditee’s terms: for example, cash collected on routes is settled, reconciled, and deposited completely and on time, and whether the controls over that process would detect a loss]. It does not cover [the main exclusion], which [is covered by / will be reviewed in] [reference].
Why now. [One or two sentences: the risk assessment reason, a prior finding, a change in the process, a regulatory driver, or simply the cycle. Never leave this out; an unexplained audit reads as an accusation.]
When. Fieldwork runs from [date] to [date], with [n] weeks of testing and interviews. We will hold a kickoff meeting on [date and time] and a closing meeting in the week of [date], and you will receive a short status note from us every Friday. The draft report will follow within [n] weeks of the closing meeting, and we will ask for your management responses within [n] business days of the draft.
Who. [Name, title] will lead the fieldwork and is your day-to-day contact; [name, title] is the audit manager responsible for the engagement; I am accountable for the report. We expect to interview [roles or names] and to visit [locations]; we will schedule interviews in blocks and confirm each one at least [n] days ahead.
What we need to start. The attached request lists [n] items we need to plan the work, with the reason for each and a requested date of [date]. Most are documents your team already maintains; where something does not exist in the form described, tell us and we will work with what you have. Later requests during fieldwork will come through [name] and will be kept as short as we can make them.
What happens with the results. Anything we observe will be discussed with the people involved as it comes up, so that the closing meeting and the draft report contain nothing you have not already heard. Findings are rated on the scale in the attached one-page note, and the final report goes to [distribution] and to the Audit Committee. Your management responses appear in the report alongside the findings.
If any of the dates are impossible for your team, please tell [name] this week and we will adjust; we would rather move the schedule than run it against your close or peak period. Thank you in advance for your team’s time.
[Name], [Title]. Copy: [executive]; [audit manager]. Attachments: initial document request; rating scale.
| Annotation | Why the letter is written this way |
|---|---|
| Opens with the heads-up call | The executive already knows; the letter is a confirmation, not an announcement, and the process owner sees their boss was consulted |
| Objective in the auditee’s terms | “Whether the controls would detect a loss” tells a depot manager what the audit is for; “to assess the design and operating effectiveness of the control environment” tells them nothing |
| “Why now” is mandatory | The unexplained audit is the one the process owner assumes is about them |
| Every date the auditee will care about, up front | Kickoff, fieldwork, closing, draft, response deadline: the auditee can plan their month |
| Named contacts with roles | Three names, three roles; the process owner knows who to call about what |
| Requests carry reasons | A request with a purpose gets answered; a list without purposes gets triaged by the auditee’s guess of what matters |
| “Tell us and we will work with what you have” | Removes the fear that not having a document is itself a finding; it may be, but that is a conversation, not a trap |
| No-surprises promise in writing | The single most relationship-changing sentence in the pack, and one the function must then keep |
| Rating scale attached | The auditee should know before fieldwork what Unsatisfactory means; the severity ratings guide has the one-page version |
| Offer to move the dates | Costs the function little and buys cooperation; an audit run over a close is worse for both sides |
Template 2: the kickoff deck
The kickoff is thirty minutes, eight slides, and its purpose is not to repeat the letter but to let the people who will actually be interviewed meet the people who will interview them, hear how the audit will run day to day, and ask questions. The audit manager attends and says little; the engagement lead presents, because the lead is the person the auditees will work with.
Slide 1. Why we are here. The objective in one sentence, the “why now” in one sentence, and the statement that the audit is of the process, not of the people in the room.
Slide 2. What is in and out of scope. Two columns. In: the processes, locations, systems, and period. Out: the adjacent areas and why (covered elsewhere, out of cycle, deliberately excluded). Invite the room to say if the boundary seems wrong.
Slide 3. How we will do it. The approach in plain words: walkthroughs with the people who do the work, a sample of transactions tested against the records, data analysis of the full population where it exists, interviews. What a sample means and why a sample exception is not an accusation.
Slide 4. The schedule. A week-by-week bar: walkthroughs week one, testing weeks two to four, closing week five, draft two weeks after; interview blocks proposed with names; the Friday status note.
Slide 5. What we need from you. The outstanding items from the initial request, the systems access required, a workspace if on site, and a single point of contact on the auditee side for logistics.
Slide 6. How findings work. The no-surprises rule; the observation discussion with the person involved before anything is written; the closing meeting where every finding is presented with its evidence; the rating scale on one line each; management responses in the report; validation later. The sentence “a finding describes a control, not a person” said aloud.
Slide 7. Who is who. The audit team with roles and a photograph each; the auditee contacts as agreed.
Slide 8. Questions. Ten minutes reserved. The lead writes the questions down and answers the ones they can; the rest go into the first status note with answers.
Tone notes. Slide 1’s “process, not people” line is the one the room is waiting for; say it early and mean it. Slide 3’s explanation of sampling prevents the most common fieldwork friction, the process owner who treats every exception as a personal failure. Slide 6 is where the kickoff earns its time: an auditee who understands the rating scale and the no-surprises rule before fieldwork behaves differently for five weeks. The preparation guide covers the planning that sits behind slides 2 to 4.
Template 3: the weekly status one-pager
The status note goes out every Friday of fieldwork, by email, from the engagement lead to the process owner, copied to the executive and the audit manager. It is one page and five sections, it takes twenty minutes to write, and it is the mechanism by which the no-surprises promise is kept: by the closing meeting, every emerging observation has appeared in at least one status note and been discussed with the person involved.
[Engagement name]: status for the week ending [date]. Week [n] of [n].
1. Where we are. [Two or three sentences: what was completed this week (walkthroughs done, tests performed, sites visited), whether the schedule holds, and the one thing the process owner most needs to know.]
2. Emerging observations. [Each observation in one or two sentences, stated as fact with the number, marked “discussed with [name] on [date]” or “to be discussed with [name] next week”. No ratings, no conclusions; the word “finding” is not used until the closing meeting. If there are none: “No observations to report this week.”]
3. What we still need. [A table of open requests: item, requested date, why it is needed, who has it. Nothing already received appears here; the list gets shorter every week or something is wrong.]
4. Next week. [The interviews scheduled with names and times; the tests planned; any site visits; anything that will need the process owner’s time, with an estimate.]
5. Points to raise. [Questions from the auditee answered; schedule changes proposed; scope questions that have arisen, for the manager’s decision; anything disputed, stated as disputed.]
[Lead’s name and phone]. Next note: [date]. Closing meeting: [date, confirmed or to be confirmed].
Tone notes. Section 2 is the difficult one and the reason the note exists. An observation is written as a fact with a number, “14 of the 60 settlement reconciliations tested were reviewed by the person who prepared them”, and never as a judgment, “reconciliation reviews are inadequate”. The judgment comes at the closing meeting, with the evidence, and by then the fact has been in three status notes and discussed with two people, which is why it is no longer a surprise. Section 3 is the auditee’s friend: a shrinking list of what is still needed, with reasons, replaces the forty-item request nobody can prioritize. And section 5 records disputes as disputes, in writing, every week, so that no one can say at the closing meeting that they were not told.
Template 4: the closing meeting agenda
The closing meeting is sixty to ninety minutes, chaired by the audit manager, attended by the process owner and the responsible executive, with the engagement lead presenting. Its purpose is to confirm every finding’s facts, hear management’s initial response, and record any disagreement before the draft is written. It is not a negotiation of the report, and the agenda says so; it is the last and most formal step in the no-surprises chain.
Closing meeting: [engagement]. [Date, time, location]. Chair: [audit manager]. Attending: [names]. Pre-read sent [date]: findings summary, one page per finding.
1. Purpose and ground rules (5 minutes). Confirm facts, hear responses, record disagreements; the rating is proposed today and confirmed by the CAE in the draft; nothing in the draft will differ from what is discussed here.
2. Scope as performed (5 minutes). What was tested, sample sizes, sites visited, anything in the original scope that was not covered and why; any limitation encountered.
3. Findings, one at a time (10 to 15 minutes each). For each: the condition with its number; the evidence, shown; the criteria; the cause as the team understands it, with an explicit request for management’s view of the cause; the consequence; the proposed rating with the reason; management’s initial response. Facts disputed are recorded with what evidence would resolve them and who will provide it by when.
4. Overall rating (5 minutes). The proposed engagement rating and the basis in the scale; management’s response.
5. Disagreements (10 minutes, reserved whether or not needed). Each disagreement stated by management in their words, recorded by the lead, and read back; the chair explains how it will appear in the report and who decides (the CAE for ratings; the facts by evidence).
6. What happens next (5 minutes). Draft date; response deadline; what a good management response contains (owner, action, date); the validation process and when it will occur; report distribution.
7. Feedback (5 minutes). What the auditee would change about how the audit was run; the survey to follow.
Minutes issued within two business days by the lead, listing findings as discussed, responses, disagreements, and actions with owners.
Tone notes. The pre-read matters: a process owner who reads the findings the day before arrives with a response instead of a reaction. Item 3’s request for management’s view of the cause is not politeness; management often knows the cause better than the team, and the root cause guide shows how much a recommendation changes when they are asked. Item 5 exists on the agenda whether or not there is a disagreement, because its presence tells the room that disagreement is expected and handled, not suppressed. And item 6’s explanation of what a good response contains saves a week of draft-report ping-pong; the five Cs guide has the model response text.
Wording for the difficult moments
| Moment | Where it is communicated | Wording that works | Wording to avoid |
|---|---|---|---|
| The auditee cannot meet the dates | Reply to the letter; heads-up call | “We would rather move than run this against your close. Which two weeks in [month] work for your team? We will re-plan around them.” | “The dates are set by the plan approved by the Audit Committee.” |
| A request is not answered after two chasers | Status note section 3, then a call to the executive | “Three items have been outstanding since [date]; without them we cannot test [area] and the report will say so. Can we agree a date today?” | Silent escalation to the CAE, or testing around the gap without saying so |
| Scope has to change mid-fieldwork | Status note section 5, then a short addendum letter | “What we found in [area] means we need to look at [adjacent area] to reach a conclusion. This adds [n] days; [executive] has agreed. Here is what we will need.” | Expanding scope quietly and surprising the auditee at the closing meeting |
| An observation is disputed on the facts | Observation discussion; status note section 5 | “You may be right. What document or record would show that? If it exists, the observation goes away; if not, it stays as we have it.” | “Our testing is conclusive.” |
| A finding nobody expected, including the executive | A call to the executive before the status note, then the note | “I want you to hear this from me before it is in writing. We found [fact]. We have not concluded on cause or rating; we will discuss both with [process owner] this week.” | Letting the executive read it in the Friday note |
| Management wants the rating lowered | Closing meeting item 5; never by email afterward | “The rating follows the scale, which is attached; here is the criterion this finding meets. Your disagreement will be recorded in the report in your words, and the CAE decides the rating.” | “Let me see what I can do.” |
| Possible fraud indicators | Not in the status note; the CAE and, per protocol, legal | Nothing in writing to the auditee; the protocol in the fraud red flags guide takes over | Raising it in the closing meeting or the note |
| The auditee was helpful and the rating is still Unsatisfactory | Closing meeting; the final report cover note | “The rating is about the controls, and the controls failed. The way your team worked with us is a separate thing, and it will be said in the report and to [executive].” | Softening the rating because the people were pleasant |
Worked example: MidState’s route cash audit, end to end
MidState Beverage’s FY27-01 route cash audit covered twelve depots, three hundred routes, and about $31 million of driver-collected cash, and it followed the FY26 discovery that a Dayton driver had diverted $18,400 over five months. The audit was therefore the kind every depot manager dreads: cash, a known loss, and the suspicion that the audit was looking for the next thief. The communication pack is how the engagement reached an Unsatisfactory rating, five findings, and eleven agreed actions with the depot managers still returning the audit team’s calls.
| Step | What was sent or said | What it did |
|---|---|---|
| Heads-up call | The CAE called the COO and the VP Operations three weeks out: the audit was in the approved plan, it would cover all twelve depots, it was about the settlement process rather than the Dayton individual, and the depot managers would hear it from the VP first | The VP told the twelve managers personally before any letter arrived |
| Notification letter | Sent to the Director of Route Accounting and copied to the twelve depot managers and the VP; “why now” stated plainly: the FY26 loss showed the controls had not detected a diversion for five months, and the audit would test whether they would now; objective phrased as “whether the controls would detect a loss”; a fourteen-item initial request with reasons; fieldwork dates offered with the option to move around the summer peak | Two depots asked to move their site visits by a week; both were moved |
| Kickoff | Held by video with all twelve depot managers; slide 1 said “this is an audit of the settlement process at every depot, not of any depot or any person”; slide 3 explained the 60-item stratified sample of five reconciliations per depot and the full-population override analysis, so no depot could feel singled out; slide 6 walked through the rating scale | Questions in the room: eleven, mostly about the sample; all answered in the first status note |
| Status notes, weeks 1 to 4 | Week 1: walkthroughs at four depots done; observation that at two of the four the reviewer of the reconciliation had also prepared it, discussed with both managers. Week 2: 30 of 60 reconciliations tested, 7 failed; the override analysis showing 1,412 self-approved overrides across all depots, discussed with the Director; request list down from fourteen to three. Week 3: 60 of 60 tested, 14 failed, at nine depots; statement analysis showing 1,130 unstated customers, discussed with AR; one dispute recorded (Fort Wayne’s manager disputed that her reviewer had handled cash; the roster proved it, and the note said so the following week). Week 4: fieldwork complete; closing meeting confirmed; pre-read to follow | By the closing meeting, every one of the five findings had appeared in at least two notes and been discussed with the people involved |
| Closing meeting | Ninety minutes; COO, VP Operations, Director of Route Accounting, and the Fort Wayne and Dayton managers as the two most affected; each finding with the evidence on screen; management’s view of cause invited and, on the override finding, better than the team’s (the ERP role design, not depot behavior); proposed engagement rating Unsatisfactory; the COO’s disagreement, that the Dayton loss was already known and fixed, recorded in his words for the report | Nine of eleven actions agreed in the room with owners and dates; the rating dispute went to the CAE, who held it; the committee later agreed |
| Draft, responses, final | Draft twelve business days after the closing meeting containing nothing the meeting had not covered; responses in eight business days; the final report’s cover note to the depot managers thanked them by name for the site visits and said, separately from the rating, that the team’s cooperation had shortened the audit by a week | The post-engagement survey scored 4.0 on fairness from the depots and 4.6 on professionalism; the lowest score was on timing, the summer peak, which the FY28 plan moved |
The finding the pack could not soften, the Unsatisfactory rating, landed anyway, because the pack is not a technique for making findings pleasant; it is a technique for making sure nobody hears them for the first time in a report. The report examples guide has the findings as they appeared in the final report, and the audit duration guide shows where the week the cooperation saved came from.
Common mistakes
| Mistake | What it looks like | Fix |
|---|---|---|
| The letter as the first contact | The executive learns of the audit from the copy line | The heads-up call, always, three weeks out |
| Charter language | “Pursuant to the Internal Audit Charter approved by the Audit Committee…” | Plain words: what, why, when, who, what we need |
| No “why now” | An audit with no stated reason reads as an accusation | One or two sentences, even if the reason is the cycle |
| The forty-item request | Everything the team might need, no reasons, one date | Ten to fifteen items to plan, each with a purpose; the rest during fieldwork, through the status note |
| Silence during fieldwork | Kickoff, then nothing until the draft | The Friday note, every Friday, with observations as facts |
| Judgments in the status note | “Controls are inadequate” in week two | Facts with numbers; judgments at the closing meeting with evidence |
| Findings first heard in the draft | The process owner disputes the draft for three weeks | Observation discussions and status notes make the draft a confirmation |
| No disagreement slot | Disputes go underground and resurface as emails to the CAE | Item 5 on the closing agenda, reserved whether needed or not |
| Ratings adjusted by email | “After further discussion we have revised the rating to…” | Ratings decided by the CAE on the evidence; disagreements recorded in the report |
| No thanks | The final report is the last the auditee hears | A cover note to the team, separate from the rating, naming what they did well |
Four documents, none of them longer than a page, and a rule that runs through all of them: nobody hears a finding for the first time in writing. Functions that adopt the pack find that their audits get shorter, their evidence arrives faster, and their findings are disputed less, not because the findings are softer but because the people on the other side of the table were told the truth as it emerged and given the chance to answer it. That is what the Standards mean by communicating with stakeholders in a way that supports trust, and it costs an hour a week.
Related guides
- What to expect during an internal audit: the auditee’s guide
- Top fears surrounding internal audits
- Five reasons to welcome an internal audit
- How to prepare for an internal audit
- How long does an internal audit take
- Audit planning memo template
- Internal audit report template set
- Finding severity ratings
- The five Cs of audit findings
- Root cause analysis for audit findings
- Internal audit report examples
- Fraud red flags
- Templates and downloads
- Start here
Leave a Reply