An internal audit report is useful only when it turns audit work into decisions. A long list of exceptions without context, risk, ownership or corrective action may be technically accurate but still fail the people who must act on it. ICAI's Internal Audit Standards Board publications page lists SIA 370, Reporting Results, within the current Standards on Internal Audit framework. The official Compendium of Standards on Internal Audit contains the detailed SIA 370 text.
What SIA 370 is trying to achieve
SIA 370 deals with reporting the results of a specific internal audit assignment. It distinguishes that assignment-level report from broader periodic reporting covering the entire audit plan. The objective is practical: communicate significant findings, help management understand issues and take corrective action, and provide a sound basis for any assurance derived from the work.
The report should therefore be the end of an evidence chain, not a fresh collection of opinions. SIA 370 states that conclusions are based on audit procedures performed and evidence gathered, and that conclusions should consider the findings as a whole rather than only a few deviations. Effective controls also deserve acknowledgement, while risk and significance help determine which observations should be prioritised.
Core structure of a useful internal audit report
SIA 370 requires a clear, well-documented report and identifies key elements. A practical structure can be built around them.
1. Objective, scope and approach
Start by telling the reader what was reviewed, why it was reviewed, the period and locations or systems covered, and the broad approach used. Avoid a vague statement such as procurement audit completed. A stronger scope explains that the assignment reviewed vendor onboarding, purchase approvals, goods-receipt matching and payment-release controls for a defined period.
2. Executive summary
The executive summary should surface the matters that require senior attention. It should not repeat every detailed observation. Summarise the major control themes, the most significant exposures, positive controls worth preserving, and the overall direction of remediation. A reader should understand the assignment's important messages before entering the detailed findings.
3. Detailed observations
A repeatable observation format improves clarity. For each material issue, document the condition found, the criterion or expected control, the risk or consequence, the cause where it has been established, and the recommended or agreed corrective action. Keep facts separate from assumptions and from management explanations.
For example, saying vendor controls are weak is too broad. A stronger observation could state that a tested vendor was activated without evidence of the prescribed independent approval; identify the onboarding control that should have operated; explain the resulting risk of unauthorised or inadequately verified vendors; record management's explanation; and state the agreed remediation, owner and target date.
4. Management response and action plan
SIA 370 specifically expects a summary of corrective actions required or agreed by management for each observation. A useful action plan should identify what will change, who owns the action and when it is expected to be completed. Avoid accepting responses such as noted or will take care when a concrete control change is needed.
5. Nature of assurance, where applicable
If assurance is being provided, it should be consistent with the nature of assurance agreed at the planning stage and the applicable ICAI framework. Do not let a risk-rating label or an informal conclusion imply a broader level of assurance than the work supports.
Draft first, final later
A particularly important SIA 370 requirement is that a final internal audit report should not be issued unless a written draft was previously shared with the auditee. This is not merely a courtesy step. Draft circulation gives management an opportunity to confirm factual accuracy, provide missing evidence, explain circumstances and agree realistic corrective actions.
The auditor should still preserve independence. Management may correct a factual error or provide evidence that changes a conclusion, but disagreement alone is not a reason to remove a supported significant finding. Where an observation is modified or excluded, the audit file should retain a defensible trail supporting the final decision.
A practical quality checklist before issue
- Can every significant observation be traced to working-paper evidence?
- Does the report state the assignment objective, scope and approach clearly?
- Does the executive summary focus on genuinely important themes?
- Are facts, management explanations and auditor conclusions clearly distinguished?
- Does each significant finding explain why the issue matters rather than merely state an exception?
- Is the corrective action specific enough to be tested later?
- Is there an accountable action owner and a realistic target date where applicable?
- Has the written draft been shared with the auditee before finalisation?
- Are draft and final reports retained and cross-referenced to the underlying observations?
- Can the report be read by senior management without needing the audit team to translate it?
Reporting is connected to follow-up
A good report does not end the audit lifecycle. ICAI's publications framework separately lists SIA 390 on monitoring and reporting prior audit issues. That matters because an agreed action is not the same as a closed risk. The final report should make future follow-up possible by defining actions clearly enough that implementation can later be validated.
Common reporting mistakes
- Exception dumping: reporting every deviation with equal prominence instead of prioritising by risk and significance.
- Unsupported impact language: describing a hypothetical consequence as if it actually occurred.
- Generic recommendations: recommending that management should strengthen controls without saying what control needs to change.
- No ownership: recording an action without identifying who is accountable for implementation.
- Overstated assurance: using language that goes beyond the scope and evidence obtained.
- Late reporting: allowing so much time after fieldwork that the issue loses operational relevance. SIA 370 requires issue within a reasonable time after completion of the work.
Practical takeaway
The strongest internal audit reports connect five things: evidence, finding, risk, action and ownership. Use SIA 370 as the reporting framework, but write for the decision-maker. If a reader can understand what happened, why it matters, what must change, who will change it and how closure can later be verified, the report has moved beyond compliance into useful governance.