Internal Audit Reporting – SIA 370, Format, Process and Best Practices
Table of Contents:-
Internal Audit Reporting is the process through which an internal auditor communicates the results of an audit assignment to management, process owners and, where appropriate, those charged with governance.
An effective internal audit report should do more than list errors. It should clearly explain what was identified, why it matters, what caused the issue, what risk arises and what corrective action management should consider.
The Institute of Chartered Accountants of India (ICAI) currently includes SIA 370 – Reporting Results within its Standards on the Conduct of Internal Audit Assignments.
ICAI’s current standards also separately cover SIA 360 – Communication with Management and SIA 390 – Monitoring and Reporting of Prior Audit Issues, making reporting part of a wider process of communication and follow-up.
For professional assistance, see our Internal Audit Services in India.
Professionals may also refer directly to the ICAI Internal Audit Standards Board for current standards and publications.
What is Internal Audit Reporting?
Internal Audit Reporting is the formal communication of the results of an internal audit assignment.
It generally explains:
- area audited;
- audit objectives;
- scope;
- period covered;
- procedures performed;
- significant observations;
- associated risks;
- root causes;
- recommendations;
- management responses;
- responsible persons; and
- agreed implementation timelines.
ICAI’s reporting framework recognises the internal audit report as the report relating to a specific internal audit assignment and distinguishes it from broader periodic reporting to the Audit Committee.
Purpose of Internal Audit Reporting
The purpose of reporting is to convert audit work into information that management can use.
A good report should help management:
- understand significant control weaknesses;
- assess business risks;
- identify regulatory issues;
- determine corrective measures;
- establish accountability;
- prioritise actions; and
- monitor implementation.
Internal Audit Reporting is More Than Error Reporting
An internal auditor should not merely report that an exception occurred.
The report should ideally explain:
Condition → Criteria → Cause → Risk/Impact → Recommendation → Management Action
This makes the observation more useful and actionable.
SIA 370 – Reporting Results
Under the current ICAI framework, SIA 370 – Reporting Results deals with the internal auditor’s responsibility for reporting the results of specific internal audit assignments.
Important Update from Earlier SIA 4
The attached existing article was written around SIA 4 – Reporting.
That older framework discussed matters such as:
- introduction;
- basic elements of the audit report;
- communication with management;
- limitation on scope; and
- restriction on report circulation.
The page should now be read in the context of ICAI’s current standards framework, which includes SIA 370 – Reporting Results. ICAI’s February 2026 Compendium is applicable from 1 April 2026.
Scope of SIA 370
SIA 370 relates to reporting the results of a specific internal audit assignment.
ICAI distinguishes this from periodic consolidated reporting covering the overall internal audit plan, which may be presented to the Audit Committee or other governing authority.
Reporting and Assurance Reports
SIA 370 primarily addresses internal audit assignment reporting.
Where a specific written assurance opinion is being issued, ICAI’s framework refers separately to the applicable standard governing assurance reports.
Essential Elements of an Internal Audit Report
A well-structured internal audit report should contain sufficient information for the reader to understand what was audited, what was found and what management needs to do next.
Title of the Report
The report should have a clear title identifying the nature of the engagement.
For example:
Internal Audit Report – Procurement Process
or
Internal Audit Report – Accounts Payable
Addressee and Report Recipients
The report should identify the intended recipient or recipients.
Depending upon the organisation, these may include:
- process owner;
- functional head;
- CFO;
- CEO;
- senior management;
- Audit Committee; or
- Board of Directors.
The original article also recognised the name of the addressee and report distribution list as basic report elements.
Period Covered
The report should clearly state the period covered by the internal audit.
For example:
Audit Period: 1 April 2026 to 30 June 2026
This avoids uncertainty regarding the transactions and controls examined.
Executive Summary
An executive summary provides senior management with a concise overview of the most significant matters arising from the audit.
It may include:
- overall assessment;
- high-risk issues;
- major control weaknesses;
- significant compliance matters;
- recurring observations; and
- immediate management actions required.
The existing article appropriately identifies an Executive Summary as part of internal audit reporting.
Audit Objectives
The report should explain the principal objectives of the audit.
For example:
- evaluate procurement controls;
- assess compliance with company policy;
- identify control weaknesses;
- test approval processes; and
- review compliance with applicable regulations.
Audit Scope
The scope should clearly identify what was included in the engagement.
It may specify:
- functions;
- processes;
- branches;
- locations;
- departments;
- legal entities;
- transactions; and
- period reviewed.
For the complete planning methodology, see our Internal Audit Process.
Audit Methodology
Where useful, the report may briefly explain how the audit was performed.
This could include:
- walkthroughs;
- interviews;
- analytical procedures;
- sampling;
- document inspection;
- system testing;
- reconciliations; and
- physical verification.
Where sampling is used, see our detailed guide on Sampling in Internal Audit.
Internal Audit Observations
The observations are the core of the internal audit report.
Each material finding should be presented in a structured manner and supported by appropriate evidence.
Internal audit working papers supporting the observations should be maintained in accordance with appropriate documentation practices. See our guide on Internal Audit Documentation.
Criteria
The report should identify what should have happened.
Criteria may come from:
- company policy;
- standard operating procedure;
- law or regulation;
- contract;
- approved authority matrix;
- accepted control practice; or
- management requirement.
Clearly identifying criteria makes the audit observation more objective.
Root Cause
An effective report should identify, wherever reasonably possible, why the issue occurred.
Examples include:
- inadequate supervision;
- unclear responsibility;
- absence of documented policy;
- system limitation;
- inadequate staff training;
- manual error;
- management override; or
- weak monitoring.
Without identifying the root cause, corrective action may address only the symptom and the problem may recur.
Risk and Impact
The report should explain why the observation matters.
Potential impact may include:
- financial loss;
- fraud exposure;
- regulatory penalty;
- incorrect financial reporting;
- operational disruption;
- data loss;
- reputational damage; or
- inefficient business processes.
The severity of the observation should be proportionate to its actual or potential impact.
Risk Rating
Organisations may classify observations according to risk.
A simple structure may be:
High Risk – Significant exposure requiring urgent management attention.
Medium Risk – Material weakness requiring corrective action within an agreed period.
Low Risk – Improvement opportunity or relatively lower-risk weakness.
The risk-rating methodology should be applied consistently across audit assignments.
For the broader methodology, read our Risk Based Internal Audit guide.
Recommendation
A recommendation should explain the action management should consider taking to address the identified risk.
Good recommendations should be:
- practical;
- specific;
- proportionate;
- risk-oriented;
- implementable; and
- directed towards the root cause.
Avoid vague recommendations such as “management should take care” or “controls should be strengthened.”
Management Response
Management should ordinarily be given an opportunity to respond to significant findings.
A response may include:
- whether management agrees;
- proposed corrective action;
- implementation plan;
- responsible person; and
- target completion date.
The original article also appropriately included management comments within the reporting process.
Action Plan and Responsibility
Every agreed corrective action should preferably have:
Action Required
Responsible Person
Target Date
Current Status
This makes subsequent monitoring considerably easier.
Scope Limitations
If the auditor was unable to perform procedures because of restrictions or lack of information, the report should appropriately communicate the limitation.
Examples may include:
- records not provided;
- system access unavailable;
- physical verification not permitted;
- key employees unavailable; or
- insufficient supporting documents.
The existing article also emphasises disclosure of limitations affecting the scope of the audit.
Internal Audit Reporting Process
Internal audit reporting normally develops progressively rather than beginning only after fieldwork is complete.
Discussion of Preliminary Findings
Significant findings should ordinarily be discussed with relevant personnel before finalisation.
This allows:
- factual errors to be corrected;
- additional evidence to be considered;
- root causes to be understood;
- management views to be obtained; and
- practical recommendations to be developed.
Discussion Draft
A preliminary or discussion draft may be shared with relevant process owners to obtain factual clarification and management responses.
The existing article also identifies a Discussion Draft as an important stage in reporting.
Exit Meeting
An exit meeting may be held with management after fieldwork.
The meeting can cover:
- major findings;
- disagreements;
- risk ratings;
- recommendations;
- management action plans; and
- implementation timelines.
Formal Draft Report
After incorporating appropriate factual clarifications, the internal auditor may prepare a formal draft for management review.
The objective is not to allow inappropriate suppression of findings but to ensure that the report is factually correct and balanced.
Final Internal Audit Report
The final report should incorporate:
- agreed facts;
- final observations;
- risk implications;
- recommendations;
- management responses; and
- agreed action dates.
The report should then be distributed to the intended recipients in accordance with the agreed reporting protocol.
Communication with Management
Internal audit reporting and management communication are closely connected.
ICAI’s current standards separately identify SIA 360 – Communication with Management alongside SIA 370.
Timely Communication
Important matters should be communicated without unnecessary delay.
Where the auditor identifies a serious issue involving:
- suspected fraud;
- major regulatory breach;
- significant financial exposure;
- major cybersecurity issue;
- severe control failure; or
- significant governance concern,
it may be inappropriate to wait until issuance of the final report before escalating the matter.
Communication of Significant Findings
Significant observations may need to be communicated to:
- process owners;
- senior management;
- CFO;
- CEO;
- Audit Committee; or
- Board,
depending upon the nature of the matter and governance structure.
Communication with Those Charged with Governance
Important matters relating to internal controls, risk management, compliance and governance may require communication to those charged with governance.
The current ICAI standards framework also separately lists SIA 250 – Communication with Those Charged with Governance.
Qualities of an Effective Internal Audit Report
A technically correct report can still be ineffective if it is difficult for management to understand or act upon.
Clear
The report should use clear and unambiguous language.
Avoid unnecessary technical terminology where simpler language communicates the issue better.
Concise
Internal audit reports should provide sufficient information without unnecessary repetition.
Long reports containing numerous insignificant issues may cause critical observations to lose visibility.
Accurate
Every material factual statement should be supported by reliable evidence.
Before finalisation, names, amounts, dates, sample results and regulatory references should be checked.
Objective
The language should remain professional and evidence-based.
Avoid:
- emotional wording;
- personal criticism;
- exaggeration; and
- unsupported conclusions.
Constructive
Recommendations should help improve the organisation rather than merely assign blame.
Timely
A perfect audit report issued too late may have little value.
Reports should be issued sufficiently promptly to allow management to address identified risks.
Internal Audit Observation Format – Practical Example
A practical observation can follow the format below.
Observation
It was observed that certain vendor payments were processed without evidence of the prescribed approval under the company’s authority matrix.
Criteria
The approved authority matrix requires specified payments to be authorised by the designated approving authority before payment.
Risk / Impact
Absence of documented approval increases the risk of unauthorised or inappropriate payments and weakens accountability over expenditure.
Root Cause
The payment processing team did not consistently verify approval documentation before processing payments.
Recommendation
Management should configure or implement a control requiring verification of prescribed approval before payment processing and periodically review exceptions.
Management Response
Management agrees with the recommendation and will implement the required control.
Target Date
30 September 2026.
This structure makes the audit issue significantly easier for management to understand and monitor.
Restriction on Internal Audit Report Circulation
Internal audit reports may contain confidential information relating to:
- financial matters;
- employees;
- commercial arrangements;
- legal compliance;
- internal controls;
- fraud risks;
- information systems; and
- management decisions.
Accordingly, report circulation should normally be restricted to authorised recipients.
The existing page also specifically states that circulation should be limited to recipients identified in the report distribution list.
Intended Recipients
The engagement terms or reporting protocol should identify who is authorised to receive the report.
Confidentiality
Reports should be handled in accordance with applicable confidentiality requirements and organisational policies.
Electronic reports may also require appropriate access controls and restrictions on forwarding or reproduction.
Monitoring and Follow-Up of Internal Audit Findings
Reporting should not end when the final internal audit report is issued.
The current ICAI framework includes SIA 390 – Monitoring and Reporting of Prior Audit Issues, reflecting the importance of monitoring previously reported observations.
Action Taken Report
An Action Taken Report can track:
- original observation;
- risk rating;
- recommendation;
- management action;
- responsible person;
- original due date;
- revised due date;
- status; and
- evidence of closure.
The older page also included an Action Taken Report among relevant reporting elements.
Status of Audit Findings
Findings may be classified as:
- Open;
- Under Implementation;
- Overdue;
- Closed; or
- Risk Accepted.
Closure of Audit Findings
An observation should not ordinarily be treated as closed merely because management states that action has been completed.
Where appropriate, internal audit should obtain evidence demonstrating implementation.
Common Internal Audit Reporting Mistakes
Poor reporting can significantly reduce the value of otherwise good audit work.
Reporting Too Many Minor Issues
Large numbers of immaterial observations can distract management from significant risks.
No Root Cause Analysis
Reporting only the error without explaining why it happened can lead to ineffective recommendations.
Weak Recommendations
Generic recommendations may not lead to meaningful corrective action.
Unsupported Findings
Observations should be traceable to appropriate evidence and working papers.
Excessive Technical Language
Reports should be understandable to their intended management audience.
Delayed Reporting
Delays can make observations less relevant and postpone corrective action.
For other common weaknesses, see our guide on Common Pitfalls in Internal Audit.
Internal Audit Reporting for Foreign-Owned Companies in India
Internal audit reporting can be particularly important for foreign-owned Indian subsidiaries because overseas management may not have direct visibility over day-to-day operations in India.
Reporting to Overseas Management
Reports may need to provide visibility regarding:
- financial controls;
- procurement;
- payroll;
- taxation;
- GST;
- FEMA compliance;
- related-party transactions;
- delegation of authority;
- regulatory compliance;
- fraud risks; and
- implementation of group policies.
Alignment with Group Reporting
Indian internal audit reports may also need to align with:
- global reporting templates;
- parent-company risk ratings;
- group internal control frameworks;
- overseas Audit Committee requirements; and
- global remediation tracking systems.
However, Indian regulatory requirements should still be appropriately considered.
Internal Audit Reporting and the Global Internal Audit Standards
Indian organisations may also refer, where appropriate, to the Global Internal Audit Standards issued by The Institute of Internal Auditors.
These international standards address communication of engagement results and monitoring of action plans as part of professional internal audit practice.
For internal audits performed within the ICAI framework, professionals should also refer to the latest ICAI Compendium of Standards on Internal Audit. ICAI states that its February 2026 Compendium is applicable from 1 April 2026.
Frequently Asked Questions
What is Internal Audit Reporting?
Internal Audit Reporting is the process of formally communicating the objectives, scope, findings, risks, recommendations and management responses arising from an internal audit assignment.
Which ICAI standard currently deals with Internal Audit Reporting?
The current ICAI framework includes SIA 370 – Reporting Results for reporting the results of specific internal audit assignments.
Is SIA 4 still the current reporting standard?
The older article was based on SIA 4 – Reporting. ICAI’s current standards framework lists SIA 370 – Reporting Results, and the February 2026 Compendium applies from 1 April 2026.
What should an internal audit report contain?
A report generally includes the audit objective, scope, period, key observations, risk or impact, root cause, recommendations, management responses, responsibilities and corrective-action timelines.
What is an Executive Summary in an internal audit report?
An Executive Summary provides senior management with a concise overview of the most significant findings, risks and actions arising from the audit.
Should internal audit observations have risk ratings?
Risk ratings can help management prioritise observations according to their significance. The methodology should be consistently applied and aligned with the organisation’s risk framework.
What is the difference between an observation and recommendation?
An observation describes the control weakness or issue identified. A recommendation explains the corrective action that could address the underlying risk or root cause.
What is an Action Taken Report?
An Action Taken Report tracks management’s implementation of corrective actions arising from previously reported internal audit observations.
Should internal audit reports be confidential?
Internal audit reports frequently contain sensitive financial, operational, employee and control-related information and should therefore normally be circulated only to authorised recipients.
Is follow-up part of internal audit reporting?
Yes. The current ICAI framework separately includes SIA 390 – Monitoring and Reporting of Prior Audit Issues, highlighting the importance of monitoring previously reported findings.
Related Services & Guides
- Internal Audit Services in India
- Audit and Assurance Services in India
- Standards on Internal Audit in India
- What is Internal Audit?
- Internal Audit Checklist
- Internal Audit Process
- Risk Based Internal Audit
- Internal Audit Documentation
- Sampling in Internal Audit
- Internal Audit Charter
- Compliance with Laws and Regulations in Internal Audit
- Common Pitfalls in Internal Audit
- Characteristics of Internal Audit
Prepared By
Anil Agrawal, Chartered Accountant
EzyBiz India Consulting LLP, New Delhi
Chartered Accountant with experience in audit, taxation, regulatory compliance, international taxation and business advisory services.
Last Updated
29 August 2026
Disclaimer
This article is intended for general informational and educational purposes only and should not be considered legal, audit, accounting, tax or other professional advice. Internal audit reporting requirements, professional standards and regulatory requirements may change from time to time. Readers should refer to the latest Standards on Internal Audit, ICAI pronouncements, applicable laws and other professional guidance and obtain appropriate professional advice before acting on the information contained in this article.