Internal Audit Report

All states Compliance & Regulatory Updated July 19, 2026 Free Word and PDF

Internal Audit Report

Report Information

Field Entry
Organization [________________________________]
Engagement title [________________________________]
Report number [________________________________]
Business unit, process, or location [________________________________]
Audit period [__/__/____] through [__/__/____]
Fieldwork period [__/__/____] through [__/__/____]
Report date [__/__/____]
Report status ☐ Draft ☐ Final
Chief audit executive [________________________________]
Engagement supervisor [________________________________]
Engagement team [________________________________]
Primary management owner [________________________________]
Authorized recipients [________________________________]
Information classification ☐ Public ☐ Internal ☐ Confidential ☐ Restricted

Use note: This is an internal audit communication, not a contract between the internal audit function and management. Remove sections that do not fit the organization's charter, methodology, industry, or applicable law.

1. Executive Summary

1.1 Engagement Objective

The objective of this engagement was to [ASSESS / REVIEW / EVALUATE]:

[____________________________________________________________]

1.2 Overall Conclusion

Conclusion or rating: [________________________________]

Summary basis:

[____________________________________________________________]

[____________________________________________________________]

1.3 Results at a Glance

Priority or rating Number of findings Accepted by management Action overdue at report date
[Critical / equivalent] [____] [____] [____]
[High / equivalent] [____] [____] [____]
[Moderate / equivalent] [____] [____] [____]
[Low / equivalent] [____] [____] [____]
Total [____] [____] [____]

1.4 Significant Matters

  • Matter: [________________________________]
  • Why it matters: [________________________________]
  • Management response: [________________________________]
  • Target date: [__/__/____]

  • Matter: [________________________________]

  • Why it matters: [________________________________]
  • Management response: [________________________________]
  • Target date: [__/__/____]

1.5 Positive Practices Observed

[____________________________________________________________]

2. Background and Context

2.1 Process Overview

[Describe the audited activity, responsible functions, systems, transaction volume, locations, and material changes during the audit period.]

[____________________________________________________________]

2.2 Reason for the Engagement

☐ Approved risk-based audit plan

☐ Board or audit committee request

☐ Management request

☐ Regulatory or contractual commitment

☐ Follow-up engagement

☐ Incident or emerging risk

☐ Other: [________________________________]

2.3 Relevant Criteria

List only criteria actually used to evaluate the activity.

Criterion Version or effective date Application to this engagement
Law or regulation: [________________________________] [________________________________] [________________________________]
Internal policy or procedure: [________________________________] [________________________________] [________________________________]
Contractual requirement: [________________________________] [________________________________] [________________________________]
Control framework: [________________________________] [________________________________] [________________________________]
Industry or professional standard: [________________________________] [________________________________] [________________________________]

3. Objectives, Scope, and Approach

3.1 Objectives

  1. [____________________________________________________________]
  2. [____________________________________________________________]
  3. [____________________________________________________________]

3.2 Scope

Included processes, entities, systems, and locations:

[____________________________________________________________]

Period tested: [__/__/____] through [__/__/____]

Population: [________________________________]

Sample selected: [________________________________]

3.3 Exclusions and Scope Limitations

☐ No material scope limitation

☐ Scope limitation identified:

  • Limitation: [________________________________]
  • Reason: [________________________________]
  • Effect on procedures or conclusion: [________________________________]
  • Escalated to: [________________________________]
  • Date escalated: [__/__/____]

3.4 Procedures Performed

☐ Process walkthroughs

☐ Interviews or inquiry

☐ Document inspection

☐ Control design assessment

☐ Control operating-effectiveness testing

☐ Transaction or substantive testing

☐ Data analytics

☐ System-configuration review

☐ Physical observation

☐ Third-party confirmation

☐ Other: [________________________________]

3.5 Standards and Methodology Statement

Select one and explain any qualification.

☐ The engagement was performed in conformance with the organization's approved internal audit methodology and the Global Internal Audit Standards.

☐ The Global Internal Audit Standards informed the engagement, but this report does not assert full conformance.

☐ Other standards or methodology applied: [________________________________]

Known departures and their effect: [________________________________]

4. Rating Methodology

The organization should use its approved rating definitions. Do not imply that the following labels are required by the Global Internal Audit Standards.

Rating Organization-approved definition Escalation level Target remediation period
[Critical] [________________________________] [________________________________] [________________________________]
[High] [________________________________] [________________________________] [________________________________]
[Moderate] [________________________________] [________________________________] [________________________________]
[Low] [________________________________] [________________________________] [________________________________]

5. Detailed Findings

Repeat this section for each finding.

Finding [____]: [TITLE]

Field Detail
Rating [________________________________]
Process owner [________________________________]
Criterion [________________________________]
Condition [________________________________]
Cause [________________________________]
Effect or risk [________________________________]
Population and sample [________________________________]
Exceptions identified [________________________________]
Evidence reference [________________________________]

Observation:

[____________________________________________________________]

Recommendation or agreed outcome:

[____________________________________________________________]

Management response:

☐ Agreed ☐ Partially agreed ☐ Not agreed ☐ Risk accepted subject to approval

[____________________________________________________________]

Action plan:

Action Responsible owner Milestone Target date Evidence of completion
[________________________________] [________________________________] [________________________________] [__/__/____] [________________________________]
[________________________________] [________________________________] [________________________________] [__/__/____] [________________________________]

Residual-risk or disagreement escalation:

[____________________________________________________________]

Required approver for risk acceptance: [________________________________]

Approval date: [__/__/____]

6. Management Action Plan Summary

Finding Rating Agreed action Owner Target date Status Validation method
[____] [________________________________] [________________________________] [________________________________] [__/__/____] ☐ Open ☐ In progress ☐ Complete ☐ Risk accepted [________________________________]
[____] [________________________________] [________________________________] [________________________________] [__/__/____] ☐ Open ☐ In progress ☐ Complete ☐ Risk accepted [________________________________]

7. Follow-Up and Monitoring

Follow-up owner: [________________________________]

Reporting cadence: [________________________________]

First follow-up date: [__/__/____]

Validation approach:

☐ Document review

☐ Retesting

☐ Data analysis

☐ Management certification

☐ Separate follow-up engagement

☐ Other: [________________________________]

Closure criteria: [________________________________]

Overdue-action escalation path: [________________________________]

8. Distribution and Records

8.1 Authorized Distribution

Recipient Role Draft or final Delivery date
[________________________________] [________________________________] ☐ Draft ☐ Final [__/__/____]
[________________________________] [________________________________] ☐ Draft ☐ Final [__/__/____]

Restrictions on use or redistribution: [________________________________]

8.2 Sensitive Information Review

☐ Personal information minimized or redacted

☐ Security-sensitive details limited to need-to-know recipients

☐ Trade secrets and confidential business information classified appropriately

☐ Allegations and investigation materials reviewed with counsel or the responsible investigations function

☐ Privilege label used only if authorized by counsel

8.3 Workpaper and Report Retention

Applicable retention policy: [________________________________]

Retention period: [________________________________]

Legal hold checked: ☐ Yes ☐ No ☐ Not applicable

System of record: [________________________________]

9. Conditional Legal and Regulatory Overlays

Complete only after counsel or compliance confirms applicability.

9.1 SEC Reporting Company

☐ Confirm whether the audited organization is subject to Exchange Act Rule 13a-15.

☐ If in scope, distinguish internal audit testing from management's required evaluations of disclosure controls and procedures and internal control over financial reporting.

☐ Route potential material control issues through the organization's disclosure, certification, and escalation procedures.

9.2 Listed Issuer Audit Committee

☐ Confirm the applicable exchange listing standards, audit committee charter, and Rule 10A-3 requirements.

☐ Confirm that the report's recipient, escalation route, and access restrictions are consistent with the audit committee's authority and responsibilities.

9.3 External Auditor Independence

☐ If a registered public accounting firm audits an issuer's financial statements, assess whether any proposed internal-audit outsourcing service is prohibited by 15 U.S.C. § 78j-1(g).

☐ Obtain audit committee, legal, and independence review before engaging the external auditor or an affiliate for additional services.

9.4 Other Regulated Entities

☐ Identify industry-specific reporting, escalation, examination, retention, and notification duties.

☐ Record each current official source in Section 2.3 before making a legal-compliance conclusion.

10. Quality Review and Finalization

☐ Objectives and scope are stated clearly.

☐ Findings are supported by sufficient, reliable, relevant, and useful evidence.

☐ Each finding links condition, criterion, cause, effect or risk, and action.

☐ Factual accuracy was checked with responsible management.

☐ Management responses and target dates are included or the absence is explained.

☐ Scope limitations and their effect are disclosed.

☐ Ratings follow the approved methodology.

☐ Legal and regulatory citations were checked against current official sources.

☐ Sensitive information and distribution restrictions were reviewed.

☐ Supervisory and chief audit executive review is documented.

11. Approval and Acknowledgment

Approval indicates authorization to issue the report. Management acknowledgment records receipt and does not convert the report into a contract.

Role Name Signature or approval record Date
Prepared by [________________________________] [________________________________] [__/__/____]
Reviewed by [________________________________] [________________________________] [__/__/____]
Chief audit executive [________________________________] [________________________________] [__/__/____]
Management acknowledgment [________________________________] [________________________________] [__/__/____]
Audit committee or board acknowledgment, if applicable [________________________________] [________________________________] [__/__/____]

Appendices

  • Appendix A: Detailed testing schedule
  • Appendix B: Evidence index
  • Appendix C: Process map or control matrix
  • Appendix D: Rating methodology
  • Appendix E: Management action plan
  • Appendix F: Distribution list

Sources and References

  • The Institute of Internal Auditors, 2024 Global Internal Audit Standards: https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  • GovInfo, 15 U.S.C. § 78j-1: https://www.govinfo.gov/app/details/USCODE-2024-title15/USCODE-2024-title15-chap2B-sec78j-1
  • eCFR, 17 C.F.R. § 240.10A-3: https://www.ecfr.gov/current/title-17/part-240/section-240.10A-3
  • eCFR, 17 C.F.R. § 240.13a-15: https://www.ecfr.gov/current/title-17/part-240/section-240.13a-15

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
internal_audit_report_universal.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the state version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
July 19, 2026
Citations checked
July 19, 2026
Jurisdiction
All states
Category
Compliance & Regulatory

Legal authority

  • 15 U.S.C. § 78j-1(g) (conditional issuer-auditor independence restriction on internal-audit outsourcing)
  • 17 C.F.R. § 240.10A-3 (conditional listed-issuer audit committee requirements)
  • 17 C.F.R. § 240.13a-15 (conditional Exchange Act disclosure controls and internal control over financial reporting)

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on July 19, 2026.

Draft your Internal Audit Report in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.