The IS Audit Report: Structure and Contents
No mandated format, but a fixed set of elements. And the auditor, not management, decides what goes in.
The report is the only part of an IS audit most stakeholders will ever see. A board member will not read the risk and control matrix; they will read the executive summary and decide whether the bank's core banking change process is a problem. The report has to carry the evidence, the judgement on significance, and the agreed fixes in a form each reader can act on.
There is no single mandated format. ICAI's Module 1 material says the organisation's audit policies dictate the format, and SIA 370 likewise leaves form and content to the internal auditor's judgement. What is fixed is the set of elements a complete report must contain.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
What an IS Audit Report Must Contain
The ISACA reporting requirements as quoted in ICAI's material.
- checkIdentification of the entity, the intended recipients and any restrictions on circulation
- checkScope, objectives, period covered, and the nature, timing and extent of work performed
- checkFindings, conclusions and recommendations
- checkAny qualifications or scope limitations
- checkSignature, date and distribution as set by the charter or engagement letter
- checkFindings supported by sufficient and appropriate evidence
A Typical Structure
Executive summary
What goes in
Overall conclusion on the adequacy of controls, the few findings that matter, in business terms
Reader
Board, audit committee, senior management
Introduction and scope
What goes in
Objectives, scope, period, approach, standards followed, limitations
Reader
Everyone; sets the boundaries of the opinion
Detailed findings
What goes in
Each observation: condition, criteria, risk or impact, root cause, recommendation, rating
Reader
Process and IT owners
Management response
What goes in
Agreed action, owner, target date; or reasons for disagreement
Reader
Auditee and follow-up reviewer
Annexures
What goes in
Technical detail, sample lists, evidence references
Reader
Technical teams
| Section | What goes in | Reader |
|---|---|---|
| Executive summary | Overall conclusion on the adequacy of controls, the few findings that matter, in business terms | Board, audit committee, senior management |
| Introduction and scope | Objectives, scope, period, approach, standards followed, limitations | Everyone; sets the boundaries of the opinion |
| Detailed findings | Each observation: condition, criteria, risk or impact, root cause, recommendation, rating | Process and IT owners |
| Management response | Agreed action, owner, target date; or reasons for disagreement | Auditee and follow-up reviewer |
| Annexures | Technical detail, sample lists, evidence references | Technical teams |
From Draft to Follow-Up
- 1
Exit meeting
Confirm the facts, test that recommendations are realistic and cost-effective, and agree implementation dates.
- 2
Draft shared with the auditee
SIA 370 says no internal audit report is issued in final form unless a written draft was shared with the auditee first.
- 3
Management responses recorded
Disagreements stay in the report with the auditor's view of the risk of not acting. The auditor, not management, decides what is included.
- 4
Issue to the intended recipients
Significant findings reach the audit committee or those charged with governance. Minor points can go to management separately, for example by memorandum.
- 5
Follow-up
A limited-scope review of whether agreed actions were implemented on time, usually reported separately.
Quick practice on audit concepts. No signup.
When the IS Auditor Is Also the Financial Statement Auditor
Under SA 265, a statutory auditor must communicate significant deficiencies in internal control to those charged with governance in writing and on time, and to management at the appropriate level. A significant deficiency is one important enough, in the auditor's judgement, to merit the attention of those charged with governance. IT control weaknesses found during the audit fall under the same rule.
How the DISA Assessment Test Tests This
- check_circle"Who has the final say on report content?": the IS auditor. Management can respond and disagree, but cannot remove a finding.
- check_circleIndependence traps: if management asks the auditor to implement the fix, the auditor's role shifts to consultant and independence must be considered.
- check_circleBalanced reporting: the material expects effective controls to be acknowledged, not just failures. SIA 370 says the same.
- check_circleExit meeting purpose: confirming facts and agreeing realistic actions, not presenting the report to the board.
- check_circleFollow-up scope: limited to agreed actions, not a re-audit.
FAQs
What are the contents of an IS audit report?expand_more
Identification of the entity and recipients, scope and objectives, period, nature and extent of work, findings with recommendations, the overall conclusion, scope limitations or qualifications, management responses, and signature, date and distribution.
Is there a prescribed format for an IS audit report?expand_more
No. ICAI's material leaves the format to the organisation's audit policies, and SIA 370 leaves form and content to the internal auditor's judgement, provided the required elements are covered.
What is the purpose of an exit meeting in IS audit?expand_more
To confirm that the facts in the findings are correct, check that recommendations are practical, and agree action plans and dates before the report is finalised.
Can management refuse a finding in the IS audit report?expand_more
Management can record disagreement, but the auditor decides what is reported. The report should state the risk of not acting.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
