The audit report is the only part of the engagement most of its readers will ever see. Everything upstream — the plan, the memo, the walkthrough, the testing — exists to make six pages credible. Yet most audit functions run on a report template that was inherited rather than designed: a cover page nobody reads, an executive summary that summarises the scope instead of the message, findings laid out differently by every author, and a rating that appears on page four after the reader has already decided what they think. A good template fixes all of this by making the right structure the default, so that the writer’s effort goes into the message and not into deciding where the message goes.
This guide gives you three report shells — the full report, the short-form report, and the advisory memo — with model language for every section and the reasoning under it, a set of house style rules that keep reports consistent across authors, and a fully worked example: the MidState Beverage route cash handling report, written from the findings that the walkthrough surfaced and the analytics in the planning memo confirmed. It is the fourth guide in the Templates Suite, and its findings are the ones the issue log template tracks to closure.
In this guide
- Three shells, and when to use each
- Shell A: the full report, section by section
- Shell B: the short-form report
- Shell C: the advisory memo
- House style rules: ratings, finding layout, language
- Worked example: the MidState route cash handling report
- Six ways audit reports fail
- Adapting the set: committee versions, branding, continuous reporting
Three shells, and when to use each
One template does not fit every engagement, and forcing a two-day advisory review into a twelve-page assurance shell produces a document that is padded where it should be brief and rated where it should not be rated at all. Three shells cover the range. The decision between them is made at planning, recorded in the planning memo, and rarely changed — a report that is upgraded from memo to full report mid-engagement is usually a sign that the scope changed and the memo should say so.
| Shell | Use when | Length | Rated? | Primary reader | Sections |
|---|---|---|---|---|---|
| A — Full report | Assurance engagement with an opinion; findings that require management action plans; anything going to the audit committee in full | 6–12 pages plus appendices | Yes — overall and per finding | Executive sponsor; audit committee | Header, executive summary, background and objectives, scope and approach, overall rating, summary of findings, detailed findings with management responses, action plan summary, appendices |
| B — Short-form report | Assurance engagement with few findings (typically three or fewer, none rated high); follow-up and validation reviews; recurring compliance reviews | 2–3 pages | Yes — overall and per finding | Process owner; sponsor | Header, summary paragraph, rating, findings table in compressed 5-C form, action plan |
| C — Advisory memo | Consulting, pre-implementation reviews, control design input, agile sprint reporting; any engagement where no opinion was sought and no assurance is being given | 1–4 pages | No | Requesting manager | Memo header, purpose, what we did, observations and suggestions, limitations statement |
Two rules cut across all three. First, the executive summary — or in a memo, the first paragraph — carries the whole message: a reader who stops there should know what was found, how serious it is, and what happens next. Second, findings are written the same way everywhere, in the five-element structure below, so that a finding lifted from a short-form report into the committee pack looks identical to one lifted from a full report. The shells differ in what surrounds the findings, never in how findings are written.
Shell A: the full report, section by section
1. Header block
[Engagement title] — Internal Audit Report [number]. Report date: [date]. Overall rating: [rating]. Engagement sponsor: [name, title]. Report addressed to: [name, title]. Distribution: [names and titles; audit committee chair; external auditor if applicable]. Classification: [Confidential — internal]. Prepared by: [lead auditor]. Approved by: [CAE or delegate]. Fieldwork period: [dates]. Draft issued / final issued: [dates].
Drafting guidance. The rating goes in the header. Not on page four, not after the findings — in the block the reader sees first, next to the title. A rating the reader discovers late feels like a verdict sprung on them; a rating they see first frames everything that follows as the evidence for it. The distribution list is a control, not a courtesy: it records who received the report and therefore who is accountable for acting on it, and it is the list the issue log will use for escalation. Two dates matter beyond the report date — draft issued and final issued — because the gap between them is the management-response cycle, and a long gap is itself information for the committee.
2. Executive summary
Why we did this work. [One or two sentences: the risk that put the engagement on the plan, in business terms — what could go wrong and what it would cost. Not the objective statement; the reason behind it.]
What we found. [The overall conclusion first, in one sentence, with the rating. Then the two or three findings that drive the rating, each in one sentence with its rating and, where possible, a number. Then one sentence on what worked — the areas where controls were designed and operating effectively — so the reader has the whole picture, not only the deficits.]
What happens next. [Management has agreed actions to address [n] findings; the earliest due date is [date] and the last is [date]. Any action already taken. Any disagreement, stated plainly. Where the findings will be tracked and when the committee will next see them.]
Drafting guidance. Three paragraphs, one page at most, written last and read first. The test of an executive summary is whether a director who reads nothing else could give an accurate account of the report at the committee meeting; the common failure is a summary that describes what the auditors did (“we reviewed the route settlement process at twelve depots”) rather than what they concluded. Lead with the conclusion. Put numbers in it — a finding with a population and a percentage is remembered, a finding described as “weaknesses were identified” is not. Include the sentence on what worked; it is not softening, it is completeness, and it is what makes the criticism credible. Write the summary in the report’s plainest language: no “IPE,” no “TOE,” no “key control” without saying what the control is. If a sentence in the summary would need a footnote for a non-auditor, rewrite it.
3. Background and objectives
Background. [The process or area in two or three sentences: what it does, its scale in the numbers that matter (volume, value, headcount, locations), the systems involved, and anything that changed recently. Written for a reader who does not know the area.]
Objectives. This engagement assessed whether [controls over X are designed and operating effectively to ensure that Y]. Specifically, we evaluated whether: (1) [objective]; (2) [objective]; (3) [objective].
Drafting guidance. The objectives are lifted from the planning memo, word for word if the memo was written properly. A report whose objectives differ from the memo’s without explanation invites the question of what changed and why. Keep the background short and quantified: “12 depots, 300 routes, $31 million a year in driver-collected cash” tells the reader more than three paragraphs of process description, and it is the frame the findings’ numbers will be read against.
4. Scope and approach
Scope. The review covered [process boundaries] for the period [dates] at [locations or entities]. It did not cover [explicit exclusions, with the reason where the reason is not obvious].
Approach. We [walked through the process at (location)], [analysed the full population of (n) transactions totalling (value)], [tested a sample of (n) items selected (method)], [performed (specific procedure)]. Where we report on a population, the population and any exclusions are stated with the finding.
Standards. This engagement was performed in conformance with the Global Internal Audit Standards. [Any limitation on scope or access, and its effect on the conclusion.]
Drafting guidance. Half a page. The reader needs to know what the conclusion covers and what it does not; the reader does not need the work program. State the exclusions explicitly, including the ones that feel awkward — the acquired subsidiaries not yet on the ERP, the depot that was closed for the period — because an exclusion stated in the report is a scope decision and an exclusion discovered later is a gap. The one-sentence conformance statement is required by the Standards and is where a scope limitation, if there was one, is declared. Quote populations with their values — “37,400 settlements totalling $15.6 million” — so that the findings’ percentages have a denominator the reader has already seen.
5. Overall rating and definitions
Overall rating: [Satisfactory / Needs improvement / Unsatisfactory]. [One sentence linking the rating to its definition and to the findings that drive it: “The rating reflects two high-rated findings concerning the design of the controls intended to detect a short deposit; custody and month-end controls were found to be operating effectively.”]
| Rating | Definition | Typical trigger |
|---|---|---|
| Satisfactory | Controls are designed and operating effectively to achieve the objectives. Findings, if any, are isolated and low-rated. | No high or medium findings; medium findings at most one, with a compensating control |
| Needs improvement | Controls are generally designed and operating effectively, but one or more weaknesses require timely management action to prevent the objective being put at risk. | One or more medium findings; no high findings, or a single high finding with an effective compensating control |
| Unsatisfactory | One or more key controls are not designed or not operating effectively, and the objective is at significant risk. Prompt senior-management action is required. | Any high finding on a key control without compensating control; multiple medium findings on the same objective |
Drafting guidance. The definitions are house standards, published once, and repeated in every report’s appendix so that the rating is read against the same words each time. The rating is derived from the findings by the definitions — not negotiated at the closing meeting and not adjusted for the sponsor’s seniority. If two high findings on the core control objective meet the definition of “unsatisfactory,” the report says unsatisfactory, and the executive summary explains why in a way that respects the reader. The sentence under the rating is where the derivation is shown; it is also the sentence the committee will quote. Finding-level ratings use the same discipline — see finding severity ratings for the criteria — and the overall rating must be reconcilable to them.
6. Summary of findings
| No. | Finding (title states the condition) | Rating | Action owner | Due date |
|---|---|---|---|---|
| 1 | [Condition, as a sentence — not a topic] | [High / Medium / Low] | [Name, title] | [Date] |
| 2 | […] | […] | […] | […] |
Drafting guidance. This table is the report’s index and the issue log’s intake form; its columns are the issue log’s columns. Titles state the condition (“Depot settlement reconciliations are prepared and reviewed by the same clerk at nine of twelve depots”), never the topic (“Segregation of duties”). A reader scanning the table should be able to repeat each finding without opening it. Order by rating, then by process sequence.
7. Detailed findings — the five-element layout
Finding [n] — [Title stating the condition]. Rating: [High / Medium / Low].
Condition. [What is. The facts observed, with population, sample and results: “We analysed all 37,400 route settlements for the six months to 31 December; 1,412 (3.8%) carried a variance override, and all 1,412 were entered and approved by the same clerk.”]
Criteria. [What should be. The policy, procedure, standard or control-design principle, with a reference: “Depot Settlement Procedure rev. FY26 §4.3 requires the depot manager to review and initial variance overrides daily.”]
Cause. [Why the condition exists — the root cause, as established, not assumed: “The exception listing the procedure refers to was never configured to print or distribute after the FY24 module upgrade; no depot manager was aware it existed.”]
Consequence. [What it means — the risk realised or exposed, quantified where honest quantification is possible: “Shortages at or below $25 per route per day are never flagged; across 300 routes this permits approximately $7,500 a day to go unexamined. Analytics identified 38 route-days with recurring shortages at exactly the tolerance, totalling $6,900, concentrated in two routes.”]
Corrective action (agreed). [What management will do, specific enough to validate: the action, the owner by name and title, the due date, and how completion will be evidenced.]
Management response. [Verbatim, dated, attributed. Audit comments only where there is disagreement, and then in a clearly separated paragraph.]
Drafting guidance. Five elements, fixed order, labelled — condition, criteria, cause, consequence, corrective action — followed by the management response. The labels are not optional. They are what makes findings comparable across authors and what stops the two commonest defects: a consequence that is really a restated condition (“as a result, overrides were not reviewed”), and a cause that is really a recommendation in disguise (“because there is no monitoring control”). One finding per root cause. Three conditions with the same cause are one finding with three conditions; one condition with two independent causes is two findings, because they will have two owners and two due dates. Keep each finding to a page; the analysis that supports it lives in the workpapers and, if the reader needs it, in an appendix.
8. Management action plan summary
| Finding | Action | Owner | Due | Evidence of completion | Validation approach |
|---|---|---|---|---|---|
| [n] | [Action, in one sentence] | [Name, title] | [Date] | [The artifact that will exist when it is done] | [What internal audit will do to confirm — inspect, re-test, re-perform] |
Drafting guidance. The “evidence of completion” column is the one most templates omit and the one that saves the most time later. Agreeing at report stage what “done” looks like — a revised procedure issued, a configured report with a distribution list, a role change in ERP with a screenshot — removes the argument at validation. The validation approach column tells management how much scrutiny to expect and tells the issue log what kind of evidence to hold.
9. Appendices
Appendix A — rating definitions, overall and finding-level, verbatim from the house standard. Appendix B — detailed scope: locations, systems, periods, populations and sample sizes by procedure. Appendix C — supporting analysis where a finding’s numbers need showing (the override distribution by depot, for example). Appendix D — distribution list and acknowledgements. Nothing goes in an appendix that the finding needs in order to be understood; appendices carry what the sceptical reader will want to check.
Shell B: the short-form report
[Engagement title] — Short-form Audit Report [number]. Report date [date]. Overall rating: [rating]. Addressed to [name, title]; distribution [names]. Prepared by [name]; approved by [name].
Summary. We reviewed [process] for [period] to assess whether [objective in one clause]. Controls are [rating-consistent conclusion in one sentence]. We identified [n] findings, rated [x medium, y low], concerning [the conditions in a few words each]. [What worked, in one sentence.] Management has agreed the actions below; the last is due [date].
Scope and approach. [Two sentences: boundaries, period, locations, exclusions; the procedures in a list of verbs with populations and sample sizes.] This engagement was performed in conformance with the Global Internal Audit Standards.
Findings and agreed actions. [Table: No. | Condition | Criteria | Cause | Consequence | Rating | Agreed action, owner, due date. One row per finding; each cell one to three sentences.]
Management response. [Verbatim, dated, attributed.] These findings will be tracked in the internal audit issue log and validated on completion.
Drafting guidance. The short form is the full report with the surrounding sections compressed into a paragraph each and the findings turned sideways into a table. The five elements survive as columns — that is the point; a finding that reads identically in the committee pack whether it came from a short-form or a full report. Two page limit, three at most. The signal that you have chosen the wrong shell is a finding that will not fit its row: if the condition needs three paragraphs, or the consequence needs a table of its own, the finding is a full-report finding and the engagement is a full-report engagement. Follow-up and validation reviews live naturally here — the table’s condition column becomes “status of the original finding” and the action column becomes “closed / open / revised due date.”
Shell C: the advisory memo
To: [requesting manager, title]. From: [auditor, Internal Audit]. Date: [date]. Subject: [Advisory review of …]. Copy: [CAE; others].
Purpose. At the request of [name], we [reviewed the design of / provided input on / observed] [subject] to [help management achieve what]. This work was advisory. No assurance is given and no rating is assigned.
What we did. Between [dates] we [met with (roles)], [reviewed (documents, designs, configurations)], and [performed (any limited procedures)]. We did not [test operating effectiveness / review (excluded area)].
Observations and suggestions. 1. We observed that [fact]. We suggest [specific, optional action] because [risk or benefit]. 2. […] 3. […]
Matters for attention. [If any observation would, in an assurance engagement, constitute a high-rated finding, say so here plainly and state how it is being escalated under the audit charter. Otherwise: “None.”]
Limitations. This memo does not constitute an audit opinion. The work was advisory in nature, was not performed to the extent necessary to express assurance, and has not been rated. The observations are for management’s consideration and have not been recorded as audit findings except as stated under “matters for attention.”
Drafting guidance. The memo’s discipline is what it leaves out: no rating, no findings vocabulary, no five-element layout, no mandatory management response. Observations are phrased as “we observed … we suggest …,” and a suggestion is optional by definition. The one place the memo must be as firm as a report is “matters for attention.” Advisory engagements regularly surface things that would be high findings anywhere else — a payment system being designed with no maker-checker step, say — and an auditor who buries that among the suggestions because “this was only advisory” has misread the charter. State it, escalate it, and record it in the issue log as an advisory-sourced item. The limitations paragraph is not boilerplate to be shrunk; it is what prevents the memo being quoted a year later as an audit opinion that the process was fine.
House style rules: ratings, finding layout, language
Templates give reports the same shape. Style rules give them the same voice, which matters more than it sounds: a committee that reads eight reports a quarter learns to read them fast only if the eight are written the same way. These twelve rules are the ones that do the most work. Publish them with the templates and apply them at review.
| Rule | Why | Instead of → write |
|---|---|---|
| 1. The rating appears in the header and the executive summary; definitions go in the appendix. | The rating frames the reading. Discovered late, it reads as an ambush. | Rating on page 4 → “Overall rating: Unsatisfactory” beside the title |
| 2. A finding’s title states the condition as a sentence. | Topic titles hide the message; condition titles carry it into the committee pack unchanged. | “Segregation of duties” → “Settlement reconciliations are prepared by the clerk who handles the cash at nine of twelve depots” |
| 3. Five labelled elements in fixed order: condition, criteria, cause, consequence, corrective action. | Labels make findings comparable and expose a missing element instantly. | A four-paragraph narrative → five labelled paragraphs |
| 4. Every number has a denominator. | “1,412 overrides” means nothing; “1,412 of 37,400 (3.8%)” means something. | “a significant number of overrides” → “1,412 of 37,400 settlements (3.8%)” |
| 5. No evasive passives. | “It was noted that” hides who noted, who did, and when. | “It was noted that approvals were not evidenced” → “Four of ten non-PO invoices had no attached approval” |
| 6. Actions are agreed, specific, owned and dated. | “Management should consider” produces nothing to validate. | “Management should consider strengthening review” → “The Director of Route Accounting will move the daily reconciliation to HQ by 1 May” |
| 7. Management responses are verbatim, attributed and dated. Audit comments appear only where there is disagreement. | Paraphrased responses become audit’s words, and the disagreement is lost. | “Management agreed” → the response, in quotation marks, with name, title and date |
| 8. No auditor jargon in the summary. | The reader who matters most is the one who does not know what IPE means. | “IPE over the override report was not validated” → “nobody checks that the override report is complete” |
| 9. Length caps: summary one page; each finding one page; report twelve pages before appendices. | Beyond these, the summary is all that is read — and it was written first and never updated. | Supporting analysis in the finding → supporting analysis in Appendix C |
| 10. Neutral adjectives. Let the number and the rating carry the weight. | “Serious,” “alarming” and “egregious” invite argument about the adjective instead of the fact. | “a serious control failure” → “a high-rated finding: 1,412 overrides, all self-approved” |
| 11. Past tense for what we did and found; present tense for the condition as it stands; first person plural. | “Internal Audit noted” is a body speaking about itself in the third person; “we found” is a person taking responsibility. | “Internal Audit identified that reviews are not being performed” → “We found that no depot performs the daily review” |
| 12. Absolute dates and periods. | “Recently” and “within a reasonable time” cannot be validated. | “recently upgraded” → “upgraded in FY24”; “timely” → “within one business day” |
Worked example: the MidState route cash handling report
Shell A, completed. This is the report that engagement FY27-01 produced after the Dayton walkthrough (gaps G1–G4), the full-population analytics, the forty traced settlements, the surprise counts and the ERP role review from the planning memo. Findings 1 and 2 are shown in full; findings 3 to 5 are summarised, as they would be in a committee version. Read it against the twelve rules above — every one of them is applied somewhere.
Header
Route Cash Handling — Internal Audit Report FY27-01. Report date: 21 March FY27. Overall rating: Unsatisfactory. Engagement sponsor: VP Operations. Addressed to: VP Operations; Director of Route Accounting. Distribution: CEO; CFO; Audit Committee Chair; external audit engagement partner. Classification: Confidential — internal. Prepared by: senior auditor. Approved by: Chief Audit Executive. Fieldwork: 12 January – 6 March. Draft issued: 10 March. Final issued: 21 March.
Executive summary
Why we did this work. MidState’s 300 route drivers collect about $31 million a year in cash and checks from 4,200 smaller customers — 14 percent of revenue — and settle it at twelve depots through a 2013 route-accounting module and depot spreadsheets. In FY26 a Dayton driver diverted $18,400 over five months before a customer complaint exposed it. This engagement asked whether the controls between a customer’s payment and the bank deposit would detect a similar diversion, and detect it sooner.
What we found. Controls over route cash handling are unsatisfactory. The two controls designed to detect a short deposit — the settlement variance flag and the settlement-to-deposit reconciliation — are performed by the clerk who handles the cash at nine of twelve depots, and the daily manager review the procedure relies on is not performed at any depot (Findings 1 and 2, both rated High). Of 37,400 settlements in the six months to 31 December, 1,412 (3.8%) carried a variance override, every one entered and approved by the clerk who keyed it; 38 route-days on two routes showed shortages at exactly the $25 tolerance on consecutive days, totalling $6,900, and have been referred to management for investigation. Three medium-rated findings concern handheld sync failures that nobody monitors (61 route-days recorded late, four by more than a week), deposit listings re-keyed outside the ERP at seven depots, and the 1,130 customers — 27 percent — who receive no monthly statement, the only control that detected the FY26 loss. Physical custody controls — dual counts, sealed bags, safe logs, daily courier collection — were designed and operating effectively at all three depots visited, and surprise counts of 22 routes found no exceptions.
What happens next. Management has agreed actions for all five findings; the earliest is due 30 April (sync monitoring) and the last 31 July (statement coverage). The Director of Route Accounting moved the Dayton reconciliation to head office on 23 February, during fieldwork. Findings 1 and 2 will be reported to the Audit Committee in May, and internal audit will validate all five actions in the third quarter.
Background, objectives, scope and approach
Background. Drivers on 300 routes collect payment from about 4,200 customers who do not pay on account, settling cash and checks daily at one of twelve depots. Settlements are keyed into the ERP route-accounting module, deposited by armored courier, and reconciled at the depot; HQ Route Accounting posts the daily batch to the general ledger and reconciles the depot cash clearing accounts monthly. Depot finance staffing was reduced to a single settlement clerk at nine depots in FY24.
Objectives. We assessed whether controls are designed and operating effectively to ensure that (1) cash and checks collected by drivers are completely and accurately recorded at settlement; (2) settlements are deposited intact and within one business day; and (3) differences between settlements, deposits and customer accounts are detected and resolved by someone independent of cash handling.
Scope. Route settlement through bank deposit and general-ledger posting at all twelve depots for the six months to 31 December FY26, with on-site work at Dayton, Toledo and Fort Wayne. The review did not cover the two acquired distributors, which are not on the ERP and are the subject of engagement FY27-02; customer credit and collections; or driver recruitment and vetting.
Approach. We walked through the process at Dayton; analysed the full population of 37,400 settlements totalling $15.6 million, the override reason-code data, handheld sync logs and the unapplied-cash accounts for all depots; traced 40 settlements from count sheet to bank deposit; performed unannounced cash counts of 22 routes at three depots; and reviewed ERP depot role assignments for all 27 depot finance users. This engagement was performed in conformance with the Global Internal Audit Standards. There were no limitations on scope or access.
Overall rating and summary of findings
Overall rating: Unsatisfactory. The rating follows the definition: two high-rated findings concern the design of the key controls intended to detect a short deposit, and no compensating control exists at depot or head-office level that would detect a route-level diversion within the month. Custody and month-end controls were operating effectively, which limits the exposure to the interval between settlement and the monthly clearing-account reconciliation, but does not change the rating.
| No. | Finding | Rating | Action owner | Due |
|---|---|---|---|---|
| 1 | Depot settlement reconciliations are prepared and reviewed by the same clerk who keys settlements and prepares deposits at nine of twelve depots | High | Director of Route Accounting | 30 June |
| 2 | Settlement variance overrides are self-approved at every depot; the daily manager review required by procedure is not performed anywhere | High | VP Operations | 31 May |
| 3 | Handheld sync failures are not monitored; 61 route-days were recorded late, four by more than a week | Medium | IT Director | 30 April |
| 4 | Deposit listings are re-keyed outside the ERP at seven depots without an independent check, and the procedure does not describe the process as performed | Medium | Director of Route Accounting | 30 June |
| 5 | 1,130 of 4,200 route customers receive no monthly statement, leaving no control over lapping for 27 percent of accounts | Medium | Director of Route Accounting | 31 July |
Finding 1 (in full)
Finding 1 — Depot settlement reconciliations are prepared and reviewed by the same clerk who keys settlements and prepares deposits at nine of twelve depots. Rating: High.
Condition. At nine of twelve depots the settlement clerk who keys route settlements and prepares the deposit slips also performs the daily deposit-to-settlement reconciliation. The depot manager’s weekly initial confirms only that the weekly total agrees to the ERP; at Dayton the manager confirmed that he does not review routes, variances or overrides. ERP depot roles at the nine depots grant a single user both settlement entry and reconciliation functions. The three remaining depots have two clerks and divide the duties between them.
Criteria. Route Cash Handling Policy v4 §3: “reconciliation of deposits to settlements is performed by a person independent of cash handling and settlement entry.” Depot Settlement Procedure rev. FY26 §6.1 assigns the reconciliation “to the depot” and its review to the depot manager.
Cause. Depot finance staffing was reduced to one clerk at nine depots in FY24. The procedure’s assignment of the reconciliation “to the depot” was not revisited when the second clerk role was removed, and the ERP depot role was built as a single role covering entry, deposit preparation and reconciliation.
Consequence. A clerk who diverted cash before settlement or altered a deposit listing would also be the person expected to detect it, and the manager’s total-only review would not identify a route-level difference. The exposure is the full daily settlement at the nine depots — approximately $90,000 a day in aggregate — for the interval until the monthly clearing-account reconciliation, which operates at depot-month level and investigates only differences over $500.
Corrective action (agreed). (a) The daily reconciliation at the nine single-clerk depots will be performed by HQ Route Accounting from bank-portal data against ERP settlements by route, not by depot total, from 1 May. (b) The ERP depot role will be split into “settlement entry” and “reconciliation,” and reconciliation removed from clerk users, by 30 June. (c) The Depot Settlement Procedure will be reissued to reflect (a) and (b). Owner: Director of Route Accounting. Due: 30 June. Evidence of completion: HQ reconciliation workpapers for May; ERP role assignment report; procedure rev. FY27.
Management response. “Agreed. HQ Route Accounting has performed the Dayton reconciliation since 23 February and will extend it to the other eight depots by 1 May. The role split has been requested from IT under change request 27-114.” — Director of Route Accounting, 18 March.
Finding 2 (in full)
Finding 2 — Settlement variance overrides are self-approved at every depot; the daily manager review required by procedure is not performed anywhere. Rating: High.
Condition. All 1,412 variance overrides recorded in the six months to 31 December — 3.8 percent of 37,400 settlements — were entered and approved by the clerk who keyed the settlement. No depot performs the daily manager review of overrides, and no exception listing exists for a manager to review. The tolerance of $25 per route per day means that shortages at or below that amount are never flagged. Analysis of settlements by route identified 38 route-days on two routes — one at Toledo, one at Fort Wayne — with shortages of between $24 and $25 on consecutive days, totalling $6,900.
Criteria. Depot Settlement Procedure rev. FY26 §4.3: “variance overrides are reviewed daily by the depot manager and initialled on the exception listing.” Route Cash Handling Policy v4 §4: variances are investigated and resolved within one business day.
Cause. The exception listing referred to in the procedure was not configured to print or distribute after the FY24 module upgrade, and no depot manager was aware that it existed. The $25 tolerance was set when the module was implemented in 2013 and has not been reviewed. The module permits the user entering an override to approve it.
Consequence. Across 300 routes the tolerance permits approximately $7,500 a day of shortages to occur without any flag, and overrides above it are approved by the person recording them. The pattern on the two routes identified is consistent with deliberate shortages held under the tolerance; it has been referred to the VP Operations and the General Counsel for investigation, and no conclusion on it is expressed in this report.
Corrective action (agreed). (a) The override exception listing will be configured to email each depot manager and HQ Route Accounting daily, with a weekly trend report by route, by 15 April. (b) The tolerance will be reduced to $5 and a reason code required for every shortage, by 15 April. (c) Override approval will require depot-manager credentials, removing self-approval, by 31 May (IT change). Owner: VP Operations. Due: 31 May. Evidence of completion: configuration screenshots and the first month of distributed listings; change ticket closure for (c).
Management response. “Agreed. We were not aware the listing had stopped distributing after the upgrade. The two routes identified were referred to the General Counsel on 4 March.” — VP Operations, 17 March.
Findings 3 to 5 (summarised) and the action plan
| No. | Condition (summary) | Cause | Agreed action | Owner / due | Evidence of completion | Validation |
|---|---|---|---|---|---|---|
| 3 | The nightly handheld sync exception report is unread at every depot. 61 route-days in the period synced late; 57 within three days; four (collections of $11,300) were entered manually nine to fifteen days later. | Report was designed for depot use but never assigned to a role after the FY24 upgrade. | Sync exceptions routed to HQ Route Accounting daily; unsynced route-days chased within one business day. | IT Director / 30 April | Distribution configuration; April exception log with resolution dates | Inspect May log; re-perform for one week |
| 4 | Seven depots re-key check details into a spreadsheet to produce the bank deposit listing; three keying differences in 40 traced settlements, all under $50. The procedure does not describe the step. | The 2013 module cannot produce a listing in the bank’s format. | ERP deposit-listing report in bank format (IT); procedure reissued to describe the interim process and its check. | Director of Route Accounting / 30 June | Report in production; procedure rev. FY27 | Inspect; trace ten listings |
| 5 | Monthly statements are emailed only; 1,130 of 4,200 route customers have no email on file and receive no statement, so no control over lapping exists for 27 percent of accounts. | Paper statements were discontinued in FY23 to save cost; the email gap was not measured. | Paper statements reinstated for customers without email; email capture added to the driver handheld. | Director of Route Accounting / 31 July | July statement run showing 100% coverage | Re-perform coverage analysis in August |
Some things to notice. The executive summary carries every number the committee will quote, and a director who reads only that page can defend the rating. The rating sentence shows its derivation from the definitions, and says what worked without softening what did not. Finding titles are conditions; a reader scanning the table knows the message. Consequences are quantified where quantification is honest — the $90,000-a-day exposure, the $7,500 tolerance — and explicitly unquantified where it is not: the 38 route-days are described as a pattern referred for investigation, because concluding on intent is not the auditor’s job and a report that did so would be quoted back at the function for years. Management responses are verbatim, dated and attributed, and the one that says remediation started during fieldwork gets credit for it in the summary. And every finding traces back to a walkthrough gap or a memo procedure by number — the issue log will carry those references forward.
Six ways audit reports fail
| Failure | Symptom | What it costs | Fix |
|---|---|---|---|
| The buried conclusion | Summary opens with scope and method; the rating appears on page four. | The reader forms a view before seeing yours, and reads the rest looking for reasons to disagree. | Rating in the header. Summary leads with “what we found.” |
| Topic titles | “Segregation of duties.” “User access.” “Procedures.” | The committee pack, built from titles, says nothing; the finding has to be re-explained every time. | Titles are condition sentences. |
| The negotiated rating | Rating changes after the closing meeting without any change to the findings. | The definitions stop meaning anything; the next sponsor negotiates too. | Rating derives from the findings by published definitions; changes require a change to a finding. |
| Consequence as restatement | “As a result, overrides were not reviewed.” | The reader cannot tell whether the finding matters; the rating looks arbitrary. | Consequence states the risk exposed — what could happen, to what value, undetected for how long. |
| Recommendations instead of actions | “Management should consider strengthening …”; no owner, no date. | Nothing to validate; the finding reappears in the next cycle as “still open.” | Agreed action, named owner, date, evidence of completion. |
| The forty-page report | Every test result in the body; the summary written first and never revised. | Only the summary is read, and it no longer matches the findings. | Length caps. Analysis to appendices. Summary written last. |
Adapting the set: committee versions, branding, continuous reporting
The committee version
The audit committee should not receive twelve-page reports in the pack; it should receive one page per report — header, the “what we found” paragraph verbatim, the summary-of-findings table, and a status line — with the full reports available on request. Because the shells put the message in the summary and the findings in a table, the committee page is an extraction, not a rewrite, and it says exactly what the report says. The quarterly view of open findings, ageing and overdue actions is a different document, and it comes from the issue log, not from the reports.
Branding and house style
Consistency matters far more than design. A fixed report-numbering scheme (FY27-01), one typeface, one rating colour convention used identically in every report and every committee page, and a one-line footnote on the first page pointing to the rating definitions. Resist the redesign that arrives with each new CAE; readers learn a format, and every change costs them the ability to read fast. If the function reports under a corporate brand, the brand governs the cover and the fonts, never the structure of the findings.
Continuous and agile reporting
Functions that run engagements in sprints report per sprint with Shell C — an advisory-style memo of observations, unrated — and compile a Shell B short-form report at the end that carries the rating and the agreed actions. The rule that keeps this honest: the rating attaches only to the compiled report, and any sprint observation that would be a high finding is escalated when found, not held for the compilation. Continuous auditing outputs — monthly analytics exceptions, say — are reported as memos until a pattern warrants an engagement, at which point the pattern becomes a finding in a rated report.
External readers and the Standards
Reports are read by external auditors deciding how much to rely on the function, by regulators, and occasionally by lawyers. Write findings so each stands alone — condition, criteria, cause, consequence complete in themselves — and avoid the hedged phrasing (“may not be operating as intended”) that invites the question of whether the auditor actually concluded anything. The Global Internal Audit Standards, Domain V require that final communications include the objectives, scope, conclusions, and the conformance statement, and that findings state criteria, condition, cause and effect; the shells above are built so that a report which follows them conforms without the author having to think about it. Where a finding is a control deficiency for financial reporting purposes, rate its severity using the same logic as control deficiency evaluation and say so in the finding, because the external auditor will ask.
Where this sits in the engagement
The report is the last document the engagement writes and the first one anyone reads, and it is only as good as the trail behind it: objectives from the planning memo, conditions from the walkthrough gap log and the work program results, ratings from the severity criteria, and the agreed actions handed to the issue log the day the final is issued. Where a finding touches fraud, as Finding 2 does, the red-flag discipline applies to the wording: describe the pattern, refer it, and conclude on nothing you did not test.
The Templates Suite
- The Annotated Internal Audit Plan Template — the FY27 plan that scheduled this engagement
- The Engagement Planning Memo Template — the objectives and procedures this report reports against
- The Walkthrough Documentation Template — where Findings 1 to 4 were first seen as gaps G1–G4
- The Audit Report Template Set — this guide
- The Finding and Issue Log Template — where these five findings are tracked to closure
Leave a Reply