Internal Audit Reporting

Internal Audit Reporting – SIA 370, Format, Process and Best Practices

Table of Contents:-

Internal Audit Reporting is the process through which an internal auditor communicates the results of an audit assignment to management, process owners and, where appropriate, those charged with governance.

An effective internal audit report should do more than list errors. It should clearly explain what was identified, why it matters, what caused the issue, what risk arises and what corrective action management should consider.

The Institute of Chartered Accountants of India (ICAI) currently includes SIA 370 – Reporting Results within its Standards on the Conduct of Internal Audit Assignments.

ICAI’s current standards also separately cover SIA 360 – Communication with Management and SIA 390 – Monitoring and Reporting of Prior Audit Issues, making reporting part of a wider process of communication and follow-up.

For professional assistance, see our Internal Audit Services in India.

Professionals may also refer directly to the ICAI Internal Audit Standards Board for current standards and publications.

What is Internal Audit Reporting?

Internal Audit Reporting is the formal communication of the results of an internal audit assignment.

It generally explains:

  • area audited;
  • audit objectives;
  • scope;
  • period covered;
  • procedures performed;
  • significant observations;
  • associated risks;
  • root causes;
  • recommendations;
  • management responses;
  • responsible persons; and
  • agreed implementation timelines.

ICAI’s reporting framework recognises the internal audit report as the report relating to a specific internal audit assignment and distinguishes it from broader periodic reporting to the Audit Committee.

Purpose of Internal Audit Reporting

The purpose of reporting is to convert audit work into information that management can use.

A good report should help management:

  • understand significant control weaknesses;
  • assess business risks;
  • identify regulatory issues;
  • determine corrective measures;
  • establish accountability;
  • prioritise actions; and
  • monitor implementation.

Internal Audit Reporting is More Than Error Reporting

An internal auditor should not merely report that an exception occurred.

The report should ideally explain:

Condition → Criteria → Cause → Risk/Impact → Recommendation → Management Action

This makes the observation more useful and actionable.

SIA 370 – Reporting Results

Under the current ICAI framework, SIA 370 – Reporting Results deals with the internal auditor’s responsibility for reporting the results of specific internal audit assignments.

Important Update from Earlier SIA 4

The attached existing article was written around SIA 4 – Reporting.

That older framework discussed matters such as:

  • introduction;
  • basic elements of the audit report;
  • communication with management;
  • limitation on scope; and
  • restriction on report circulation.

The page should now be read in the context of ICAI’s current standards framework, which includes SIA 370 – Reporting Results. ICAI’s February 2026 Compendium is applicable from 1 April 2026.

Scope of SIA 370

SIA 370 relates to reporting the results of a specific internal audit assignment.

ICAI distinguishes this from periodic consolidated reporting covering the overall internal audit plan, which may be presented to the Audit Committee or other governing authority.

Reporting and Assurance Reports

SIA 370 primarily addresses internal audit assignment reporting.

Where a specific written assurance opinion is being issued, ICAI’s framework refers separately to the applicable standard governing assurance reports.

Essential Elements of an Internal Audit Report

A well-structured internal audit report should contain sufficient information for the reader to understand what was audited, what was found and what management needs to do next.

Title of the Report

The report should have a clear title identifying the nature of the engagement.

For example:

Internal Audit Report – Procurement Process

or

Internal Audit Report – Accounts Payable

Addressee and Report Recipients

The report should identify the intended recipient or recipients.

Depending upon the organisation, these may include:

  • process owner;
  • functional head;
  • CFO;
  • CEO;
  • senior management;
  • Audit Committee; or
  • Board of Directors.

The original article also recognised the name of the addressee and report distribution list as basic report elements.

Period Covered

The report should clearly state the period covered by the internal audit.

For example:

Audit Period: 1 April 2026 to 30 June 2026

This avoids uncertainty regarding the transactions and controls examined.

Executive Summary

An executive summary provides senior management with a concise overview of the most significant matters arising from the audit.

It may include:

  • overall assessment;
  • high-risk issues;
  • major control weaknesses;
  • significant compliance matters;
  • recurring observations; and
  • immediate management actions required.

The existing article appropriately identifies an Executive Summary as part of internal audit reporting.

Audit Objectives

The report should explain the principal objectives of the audit.

For example:

  • evaluate procurement controls;
  • assess compliance with company policy;
  • identify control weaknesses;
  • test approval processes; and
  • review compliance with applicable regulations.

Audit Scope

The scope should clearly identify what was included in the engagement.

It may specify:

  • functions;
  • processes;
  • branches;
  • locations;
  • departments;
  • legal entities;
  • transactions; and
  • period reviewed.

For the complete planning methodology, see our Internal Audit Process.

Audit Methodology

Where useful, the report may briefly explain how the audit was performed.

This could include:

  • walkthroughs;
  • interviews;
  • analytical procedures;
  • sampling;
  • document inspection;
  • system testing;
  • reconciliations; and
  • physical verification.

Where sampling is used, see our detailed guide on Sampling in Internal Audit.

Internal Audit Observations

The observations are the core of the internal audit report.

Each material finding should be presented in a structured manner and supported by appropriate evidence.

Internal audit working papers supporting the observations should be maintained in accordance with appropriate documentation practices. See our guide on Internal Audit Documentation.

Criteria

The report should identify what should have happened.

Criteria may come from:

  • company policy;
  • standard operating procedure;
  • law or regulation;
  • contract;
  • approved authority matrix;
  • accepted control practice; or
  • management requirement.

Clearly identifying criteria makes the audit observation more objective.

Root Cause

An effective report should identify, wherever reasonably possible, why the issue occurred.

Examples include:

  • inadequate supervision;
  • unclear responsibility;
  • absence of documented policy;
  • system limitation;
  • inadequate staff training;
  • manual error;
  • management override; or
  • weak monitoring.

Without identifying the root cause, corrective action may address only the symptom and the problem may recur.

Risk and Impact

The report should explain why the observation matters.

Potential impact may include:

  • financial loss;
  • fraud exposure;
  • regulatory penalty;
  • incorrect financial reporting;
  • operational disruption;
  • data loss;
  • reputational damage; or
  • inefficient business processes.

The severity of the observation should be proportionate to its actual or potential impact.

Risk Rating

Organisations may classify observations according to risk.

A simple structure may be:

High Risk – Significant exposure requiring urgent management attention.

Medium Risk – Material weakness requiring corrective action within an agreed period.

Low Risk – Improvement opportunity or relatively lower-risk weakness.

The risk-rating methodology should be applied consistently across audit assignments.

For the broader methodology, read our Risk Based Internal Audit guide.

Recommendation

A recommendation should explain the action management should consider taking to address the identified risk.

Good recommendations should be:

  • practical;
  • specific;
  • proportionate;
  • risk-oriented;
  • implementable; and
  • directed towards the root cause.

Avoid vague recommendations such as “management should take care” or “controls should be strengthened.”

Management Response

Management should ordinarily be given an opportunity to respond to significant findings.

A response may include:

  • whether management agrees;
  • proposed corrective action;
  • implementation plan;
  • responsible person; and
  • target completion date.

The original article also appropriately included management comments within the reporting process.

Action Plan and Responsibility

Every agreed corrective action should preferably have:

Action Required

Responsible Person

Target Date

Current Status

This makes subsequent monitoring considerably easier.

Scope Limitations

If the auditor was unable to perform procedures because of restrictions or lack of information, the report should appropriately communicate the limitation.

Examples may include:

  • records not provided;
  • system access unavailable;
  • physical verification not permitted;
  • key employees unavailable; or
  • insufficient supporting documents.

The existing article also emphasises disclosure of limitations affecting the scope of the audit.

Internal Audit Reporting Process

Internal audit reporting normally develops progressively rather than beginning only after fieldwork is complete.

Discussion of Preliminary Findings

Significant findings should ordinarily be discussed with relevant personnel before finalisation.

This allows:

  • factual errors to be corrected;
  • additional evidence to be considered;
  • root causes to be understood;
  • management views to be obtained; and
  • practical recommendations to be developed.

Discussion Draft

A preliminary or discussion draft may be shared with relevant process owners to obtain factual clarification and management responses.

The existing article also identifies a Discussion Draft as an important stage in reporting.

Exit Meeting

An exit meeting may be held with management after fieldwork.

The meeting can cover:

  • major findings;
  • disagreements;
  • risk ratings;
  • recommendations;
  • management action plans; and
  • implementation timelines.

Formal Draft Report

After incorporating appropriate factual clarifications, the internal auditor may prepare a formal draft for management review.

The objective is not to allow inappropriate suppression of findings but to ensure that the report is factually correct and balanced.

Final Internal Audit Report

The final report should incorporate:

  • agreed facts;
  • final observations;
  • risk implications;
  • recommendations;
  • management responses; and
  • agreed action dates.

The report should then be distributed to the intended recipients in accordance with the agreed reporting protocol.

Communication with Management

Internal audit reporting and management communication are closely connected.

ICAI’s current standards separately identify SIA 360 – Communication with Management alongside SIA 370.

Timely Communication

Important matters should be communicated without unnecessary delay.

Where the auditor identifies a serious issue involving:

  • suspected fraud;
  • major regulatory breach;
  • significant financial exposure;
  • major cybersecurity issue;
  • severe control failure; or
  • significant governance concern,

it may be inappropriate to wait until issuance of the final report before escalating the matter.

Communication of Significant Findings

Significant observations may need to be communicated to:

  • process owners;
  • senior management;
  • CFO;
  • CEO;
  • Audit Committee; or
  • Board,

depending upon the nature of the matter and governance structure.

Communication with Those Charged with Governance

Important matters relating to internal controls, risk management, compliance and governance may require communication to those charged with governance.

The current ICAI standards framework also separately lists SIA 250 – Communication with Those Charged with Governance.

Qualities of an Effective Internal Audit Report

A technically correct report can still be ineffective if it is difficult for management to understand or act upon.

Clear

The report should use clear and unambiguous language.

Avoid unnecessary technical terminology where simpler language communicates the issue better.

Concise

Internal audit reports should provide sufficient information without unnecessary repetition.

Long reports containing numerous insignificant issues may cause critical observations to lose visibility.

Accurate

Every material factual statement should be supported by reliable evidence.

Before finalisation, names, amounts, dates, sample results and regulatory references should be checked.

Objective

The language should remain professional and evidence-based.

Avoid:

  • emotional wording;
  • personal criticism;
  • exaggeration; and
  • unsupported conclusions.

Constructive

Recommendations should help improve the organisation rather than merely assign blame.

Timely

A perfect audit report issued too late may have little value.

Reports should be issued sufficiently promptly to allow management to address identified risks.

Internal Audit Observation Format – Practical Example

A practical observation can follow the format below.

Observation

It was observed that certain vendor payments were processed without evidence of the prescribed approval under the company’s authority matrix.

Criteria

The approved authority matrix requires specified payments to be authorised by the designated approving authority before payment.

Risk / Impact

Absence of documented approval increases the risk of unauthorised or inappropriate payments and weakens accountability over expenditure.

Root Cause

The payment processing team did not consistently verify approval documentation before processing payments.

Recommendation

Management should configure or implement a control requiring verification of prescribed approval before payment processing and periodically review exceptions.

Management Response

Management agrees with the recommendation and will implement the required control.

Target Date

30 September 2026.

This structure makes the audit issue significantly easier for management to understand and monitor.

Restriction on Internal Audit Report Circulation

Internal audit reports may contain confidential information relating to:

  • financial matters;
  • employees;
  • commercial arrangements;
  • legal compliance;
  • internal controls;
  • fraud risks;
  • information systems; and
  • management decisions.

Accordingly, report circulation should normally be restricted to authorised recipients.

The existing page also specifically states that circulation should be limited to recipients identified in the report distribution list.

Intended Recipients

The engagement terms or reporting protocol should identify who is authorised to receive the report.

Confidentiality

Reports should be handled in accordance with applicable confidentiality requirements and organisational policies.

Electronic reports may also require appropriate access controls and restrictions on forwarding or reproduction.

Monitoring and Follow-Up of Internal Audit Findings

Reporting should not end when the final internal audit report is issued.

The current ICAI framework includes SIA 390 – Monitoring and Reporting of Prior Audit Issues, reflecting the importance of monitoring previously reported observations.

Action Taken Report

An Action Taken Report can track:

  • original observation;
  • risk rating;
  • recommendation;
  • management action;
  • responsible person;
  • original due date;
  • revised due date;
  • status; and
  • evidence of closure.

The older page also included an Action Taken Report among relevant reporting elements.

Status of Audit Findings

Findings may be classified as:

  • Open;
  • Under Implementation;
  • Overdue;
  • Closed; or
  • Risk Accepted.

Closure of Audit Findings

An observation should not ordinarily be treated as closed merely because management states that action has been completed.

Where appropriate, internal audit should obtain evidence demonstrating implementation.

Common Internal Audit Reporting Mistakes

Poor reporting can significantly reduce the value of otherwise good audit work.

Reporting Too Many Minor Issues

Large numbers of immaterial observations can distract management from significant risks.

No Root Cause Analysis

Reporting only the error without explaining why it happened can lead to ineffective recommendations.

Weak Recommendations

Generic recommendations may not lead to meaningful corrective action.

Unsupported Findings

Observations should be traceable to appropriate evidence and working papers.

Excessive Technical Language

Reports should be understandable to their intended management audience.

Delayed Reporting

Delays can make observations less relevant and postpone corrective action.

For other common weaknesses, see our guide on Common Pitfalls in Internal Audit.

Internal Audit Reporting for Foreign-Owned Companies in India

Internal audit reporting can be particularly important for foreign-owned Indian subsidiaries because overseas management may not have direct visibility over day-to-day operations in India.

Reporting to Overseas Management

Reports may need to provide visibility regarding:

  • financial controls;
  • procurement;
  • payroll;
  • taxation;
  • GST;
  • FEMA compliance;
  • related-party transactions;
  • delegation of authority;
  • regulatory compliance;
  • fraud risks; and
  • implementation of group policies.

Alignment with Group Reporting

Indian internal audit reports may also need to align with:

  • global reporting templates;
  • parent-company risk ratings;
  • group internal control frameworks;
  • overseas Audit Committee requirements; and
  • global remediation tracking systems.

However, Indian regulatory requirements should still be appropriately considered.

Internal Audit Reporting and the Global Internal Audit Standards

Indian organisations may also refer, where appropriate, to the Global Internal Audit Standards issued by The Institute of Internal Auditors.

These international standards address communication of engagement results and monitoring of action plans as part of professional internal audit practice.

For internal audits performed within the ICAI framework, professionals should also refer to the latest ICAI Compendium of Standards on Internal Audit. ICAI states that its February 2026 Compendium is applicable from 1 April 2026.

Frequently Asked Questions

What is Internal Audit Reporting?

Internal Audit Reporting is the process of formally communicating the objectives, scope, findings, risks, recommendations and management responses arising from an internal audit assignment.

Which ICAI standard currently deals with Internal Audit Reporting?

The current ICAI framework includes SIA 370 – Reporting Results for reporting the results of specific internal audit assignments.

Is SIA 4 still the current reporting standard?

The older article was based on SIA 4 – Reporting. ICAI’s current standards framework lists SIA 370 – Reporting Results, and the February 2026 Compendium applies from 1 April 2026.

What should an internal audit report contain?

A report generally includes the audit objective, scope, period, key observations, risk or impact, root cause, recommendations, management responses, responsibilities and corrective-action timelines.

What is an Executive Summary in an internal audit report?

An Executive Summary provides senior management with a concise overview of the most significant findings, risks and actions arising from the audit.

Should internal audit observations have risk ratings?

Risk ratings can help management prioritise observations according to their significance. The methodology should be consistently applied and aligned with the organisation’s risk framework.

What is the difference between an observation and recommendation?

An observation describes the control weakness or issue identified. A recommendation explains the corrective action that could address the underlying risk or root cause.

What is an Action Taken Report?

An Action Taken Report tracks management’s implementation of corrective actions arising from previously reported internal audit observations.

Should internal audit reports be confidential?

Internal audit reports frequently contain sensitive financial, operational, employee and control-related information and should therefore normally be circulated only to authorised recipients.

Is follow-up part of internal audit reporting?

Yes. The current ICAI framework separately includes SIA 390 – Monitoring and Reporting of Prior Audit Issues, highlighting the importance of monitoring previously reported findings.

Related Services & Guides

Prepared By

Anil Agrawal, Chartered Accountant
EzyBiz India Consulting LLP, New Delhi

Chartered Accountant with experience in audit, taxation, regulatory compliance, international taxation and business advisory services.

Last Updated

29 August 2026

Disclaimer

This article is intended for general informational and educational purposes only and should not be considered legal, audit, accounting, tax or other professional advice. Internal audit reporting requirements, professional standards and regulatory requirements may change from time to time. Readers should refer to the latest Standards on Internal Audit, ICAI pronouncements, applicable laws and other professional guidance and obtain appropriate professional advice before acting on the information contained in this article.