Internal Audit Report
Internal Audit Report
Report Information
| Field | Entry |
|---|---|
| Organization | [________________________________] |
| Engagement title | [________________________________] |
| Report number | [________________________________] |
| Business unit, process, or location | [________________________________] |
| Audit period | [__/__/____] through [__/__/____] |
| Fieldwork period | [__/__/____] through [__/__/____] |
| Report date | [__/__/____] |
| Report status | ☐ Draft ☐ Final |
| Chief audit executive | [________________________________] |
| Engagement supervisor | [________________________________] |
| Engagement team | [________________________________] |
| Primary management owner | [________________________________] |
| Authorized recipients | [________________________________] |
| Information classification | ☐ Public ☐ Internal ☐ Confidential ☐ Restricted |
Use note: This is an internal audit communication, not a contract between the internal audit function and management. Remove sections that do not fit the organization's charter, methodology, industry, or applicable law.
1. Executive Summary
1.1 Engagement Objective
The objective of this engagement was to [ASSESS / REVIEW / EVALUATE]:
[____________________________________________________________]
1.2 Overall Conclusion
Conclusion or rating: [________________________________]
Summary basis:
[____________________________________________________________]
[____________________________________________________________]
1.3 Results at a Glance
| Priority or rating | Number of findings | Accepted by management | Action overdue at report date |
|---|---|---|---|
| [Critical / equivalent] | [____] | [____] | [____] |
| [High / equivalent] | [____] | [____] | [____] |
| [Moderate / equivalent] | [____] | [____] | [____] |
| [Low / equivalent] | [____] | [____] | [____] |
| Total | [____] | [____] | [____] |
1.4 Significant Matters
- Matter: [________________________________]
- Why it matters: [________________________________]
- Management response: [________________________________]
-
Target date: [__/__/____]
-
Matter: [________________________________]
- Why it matters: [________________________________]
- Management response: [________________________________]
- Target date: [__/__/____]
1.5 Positive Practices Observed
[____________________________________________________________]
2. Background and Context
2.1 Process Overview
[Describe the audited activity, responsible functions, systems, transaction volume, locations, and material changes during the audit period.]
[____________________________________________________________]
2.2 Reason for the Engagement
☐ Approved risk-based audit plan
☐ Board or audit committee request
☐ Management request
☐ Regulatory or contractual commitment
☐ Follow-up engagement
☐ Incident or emerging risk
☐ Other: [________________________________]
2.3 Relevant Criteria
List only criteria actually used to evaluate the activity.
| Criterion | Version or effective date | Application to this engagement |
|---|---|---|
| Law or regulation: [________________________________] | [________________________________] | [________________________________] |
| Internal policy or procedure: [________________________________] | [________________________________] | [________________________________] |
| Contractual requirement: [________________________________] | [________________________________] | [________________________________] |
| Control framework: [________________________________] | [________________________________] | [________________________________] |
| Industry or professional standard: [________________________________] | [________________________________] | [________________________________] |
3. Objectives, Scope, and Approach
3.1 Objectives
- [____________________________________________________________]
- [____________________________________________________________]
- [____________________________________________________________]
3.2 Scope
Included processes, entities, systems, and locations:
[____________________________________________________________]
Period tested: [__/__/____] through [__/__/____]
Population: [________________________________]
Sample selected: [________________________________]
3.3 Exclusions and Scope Limitations
☐ No material scope limitation
☐ Scope limitation identified:
- Limitation: [________________________________]
- Reason: [________________________________]
- Effect on procedures or conclusion: [________________________________]
- Escalated to: [________________________________]
- Date escalated: [__/__/____]
3.4 Procedures Performed
☐ Process walkthroughs
☐ Interviews or inquiry
☐ Document inspection
☐ Control design assessment
☐ Control operating-effectiveness testing
☐ Transaction or substantive testing
☐ Data analytics
☐ System-configuration review
☐ Physical observation
☐ Third-party confirmation
☐ Other: [________________________________]
3.5 Standards and Methodology Statement
Select one and explain any qualification.
☐ The engagement was performed in conformance with the organization's approved internal audit methodology and the Global Internal Audit Standards.
☐ The Global Internal Audit Standards informed the engagement, but this report does not assert full conformance.
☐ Other standards or methodology applied: [________________________________]
Known departures and their effect: [________________________________]
4. Rating Methodology
The organization should use its approved rating definitions. Do not imply that the following labels are required by the Global Internal Audit Standards.
| Rating | Organization-approved definition | Escalation level | Target remediation period |
|---|---|---|---|
| [Critical] | [________________________________] | [________________________________] | [________________________________] |
| [High] | [________________________________] | [________________________________] | [________________________________] |
| [Moderate] | [________________________________] | [________________________________] | [________________________________] |
| [Low] | [________________________________] | [________________________________] | [________________________________] |
5. Detailed Findings
Repeat this section for each finding.
Finding [____]: [TITLE]
| Field | Detail |
|---|---|
| Rating | [________________________________] |
| Process owner | [________________________________] |
| Criterion | [________________________________] |
| Condition | [________________________________] |
| Cause | [________________________________] |
| Effect or risk | [________________________________] |
| Population and sample | [________________________________] |
| Exceptions identified | [________________________________] |
| Evidence reference | [________________________________] |
Observation:
[____________________________________________________________]
Recommendation or agreed outcome:
[____________________________________________________________]
Management response:
☐ Agreed ☐ Partially agreed ☐ Not agreed ☐ Risk accepted subject to approval
[____________________________________________________________]
Action plan:
| Action | Responsible owner | Milestone | Target date | Evidence of completion |
|---|---|---|---|---|
| [________________________________] | [________________________________] | [________________________________] | [__/__/____] | [________________________________] |
| [________________________________] | [________________________________] | [________________________________] | [__/__/____] | [________________________________] |
Residual-risk or disagreement escalation:
[____________________________________________________________]
Required approver for risk acceptance: [________________________________]
Approval date: [__/__/____]
6. Management Action Plan Summary
| Finding | Rating | Agreed action | Owner | Target date | Status | Validation method |
|---|---|---|---|---|---|---|
| [____] | [________________________________] | [________________________________] | [________________________________] | [__/__/____] | ☐ Open ☐ In progress ☐ Complete ☐ Risk accepted | [________________________________] |
| [____] | [________________________________] | [________________________________] | [________________________________] | [__/__/____] | ☐ Open ☐ In progress ☐ Complete ☐ Risk accepted | [________________________________] |
7. Follow-Up and Monitoring
Follow-up owner: [________________________________]
Reporting cadence: [________________________________]
First follow-up date: [__/__/____]
Validation approach:
☐ Document review
☐ Retesting
☐ Data analysis
☐ Management certification
☐ Separate follow-up engagement
☐ Other: [________________________________]
Closure criteria: [________________________________]
Overdue-action escalation path: [________________________________]
8. Distribution and Records
8.1 Authorized Distribution
| Recipient | Role | Draft or final | Delivery date |
|---|---|---|---|
| [________________________________] | [________________________________] | ☐ Draft ☐ Final | [__/__/____] |
| [________________________________] | [________________________________] | ☐ Draft ☐ Final | [__/__/____] |
Restrictions on use or redistribution: [________________________________]
8.2 Sensitive Information Review
☐ Personal information minimized or redacted
☐ Security-sensitive details limited to need-to-know recipients
☐ Trade secrets and confidential business information classified appropriately
☐ Allegations and investigation materials reviewed with counsel or the responsible investigations function
☐ Privilege label used only if authorized by counsel
8.3 Workpaper and Report Retention
Applicable retention policy: [________________________________]
Retention period: [________________________________]
Legal hold checked: ☐ Yes ☐ No ☐ Not applicable
System of record: [________________________________]
9. Conditional Legal and Regulatory Overlays
Complete only after counsel or compliance confirms applicability.
9.1 SEC Reporting Company
☐ Confirm whether the audited organization is subject to Exchange Act Rule 13a-15.
☐ If in scope, distinguish internal audit testing from management's required evaluations of disclosure controls and procedures and internal control over financial reporting.
☐ Route potential material control issues through the organization's disclosure, certification, and escalation procedures.
9.2 Listed Issuer Audit Committee
☐ Confirm the applicable exchange listing standards, audit committee charter, and Rule 10A-3 requirements.
☐ Confirm that the report's recipient, escalation route, and access restrictions are consistent with the audit committee's authority and responsibilities.
9.3 External Auditor Independence
☐ If a registered public accounting firm audits an issuer's financial statements, assess whether any proposed internal-audit outsourcing service is prohibited by 15 U.S.C. § 78j-1(g).
☐ Obtain audit committee, legal, and independence review before engaging the external auditor or an affiliate for additional services.
9.4 Other Regulated Entities
☐ Identify industry-specific reporting, escalation, examination, retention, and notification duties.
☐ Record each current official source in Section 2.3 before making a legal-compliance conclusion.
10. Quality Review and Finalization
☐ Objectives and scope are stated clearly.
☐ Findings are supported by sufficient, reliable, relevant, and useful evidence.
☐ Each finding links condition, criterion, cause, effect or risk, and action.
☐ Factual accuracy was checked with responsible management.
☐ Management responses and target dates are included or the absence is explained.
☐ Scope limitations and their effect are disclosed.
☐ Ratings follow the approved methodology.
☐ Legal and regulatory citations were checked against current official sources.
☐ Sensitive information and distribution restrictions were reviewed.
☐ Supervisory and chief audit executive review is documented.
11. Approval and Acknowledgment
Approval indicates authorization to issue the report. Management acknowledgment records receipt and does not convert the report into a contract.
| Role | Name | Signature or approval record | Date |
|---|---|---|---|
| Prepared by | [________________________________] | [________________________________] | [__/__/____] |
| Reviewed by | [________________________________] | [________________________________] | [__/__/____] |
| Chief audit executive | [________________________________] | [________________________________] | [__/__/____] |
| Management acknowledgment | [________________________________] | [________________________________] | [__/__/____] |
| Audit committee or board acknowledgment, if applicable | [________________________________] | [________________________________] | [__/__/____] |
Appendices
- Appendix A: Detailed testing schedule
- Appendix B: Evidence index
- Appendix C: Process map or control matrix
- Appendix D: Rating methodology
- Appendix E: Management action plan
- Appendix F: Distribution list
Sources and References
- The Institute of Internal Auditors, 2024 Global Internal Audit Standards: https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
- GovInfo, 15 U.S.C. § 78j-1: https://www.govinfo.gov/app/details/USCODE-2024-title15/USCODE-2024-title15-chap2B-sec78j-1
- eCFR, 17 C.F.R. § 240.10A-3: https://www.ecfr.gov/current/title-17/part-240/section-240.10A-3
- eCFR, 17 C.F.R. § 240.13a-15: https://www.ecfr.gov/current/title-17/part-240/section-240.13a-15
About this template
- Last updated
- July 19, 2026
- Citations checked
- July 19, 2026
- Jurisdiction
- All states
- Category
- Compliance & Regulatory
Legal authority
- 15 U.S.C. § 78j-1(g) (conditional issuer-auditor independence restriction on internal-audit outsourcing)
- 17 C.F.R. § 240.10A-3 (conditional listed-issuer audit committee requirements)
- 17 C.F.R. § 240.13a-15 (conditional Exchange Act disclosure controls and internal control over financial reporting)
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on July 19, 2026.
Draft your Internal Audit Report in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.