Top 50 Audit Observations & Audit Report Formats

Top 50 Audit Observations & Audit Report Formats | LearnEdition
Audit Intelligence Series

Top 50 Audit Observations & Audit Report Formats

A practitioner's deep-dive into audit findings, internal audit report writing, and real-world examples — with diagrams, stories, and a graded quiz.

📘 ~5,000 words ⏱ 22 min read ✅ 10-question quiz 🗂 Covers IIA Standards

What Is an Audit Observation?

Before diving into the top 50 examples, let's anchor the fundamentals — because precision in language is the first discipline of any auditor.

Definition

An audit observation (also called an audit finding or audit comment) is a factual, evidence-based statement that identifies a gap between the current state (condition) and what should be (criteria), together with its cause, effect, and the recommended corrective action.

The IIA (Institute of Internal Auditors) defines an observation as a formal communication that documents significant differences between expected and actual situations. Every well-formed observation follows the 5C Model: Condition, Criteria, Cause, Consequence, and Corrective Action.

The 5C Anatomy of a Robust Audit Observation

5C Anatomy of an Audit Observation Flowchart showing the five components: Condition, Criteria, Cause, Consequence, Corrective Action AUDIT OBS. Condition What is happening? Criteria What should happen? Cause Why does it happen? Consequence Impact on the business Corrective Action Recommended fix

Think of the 5C model as the skeleton of every audit observation. A finding that misses even one "C" is incomplete — management can dismiss it as vague, and external reviewers (regulators, external auditors) may question the quality of the audit itself.

Key Terms at a Glance

🔍

Audit Observation

A documented gap between actual and expected controls, backed by evidence gathered during the audit fieldwork phase.

⚠️

Audit Finding

Often used interchangeably with "observation," though in some frameworks a "finding" specifically refers to a more severe or material observation.

📋

Management Response

The auditee's formal response to an observation, including the agreed corrective action, owner, and deadline. Critical for closing the audit loop.

🗓️

Follow-Up Audit

A targeted review conducted 3–12 months after the original report to verify that agreed corrective actions have been implemented.

Top 50 Audit Observations — With Examples

Drawn from real-world internal audits across finance, IT, HR, procurement, and operations. Each observation includes the finding and a real-life example you can adapt to your audit report.

💡

How to read these: Severity ratings are indicative. "High" = immediate risk to financials, compliance, or reputation. "Medium" = significant process weakness. "Low" = minor procedural gap.

A. Financial Controls (Observations 1–10)

1

Lack of Segregation of Duties in Accounts Payable

The same employee creates vendors, approves invoices, and processes payments — a classic three-point control failure. This structure allows fraud without detection.

Example: At a mid-size manufacturing company, an AP clerk created 11 fictitious vendors and approved ₹48 lakhs in payments over 14 months before an audit detected the pattern.

HighFinance
2

Journal Entries Posted Without Adequate Supporting Documentation

Manual journal entries were posted near period-end without any supporting journal vouchers, business justification, or dual-authorisation.

Example: A retail chain's finance team posted ₹1.2 crore in top-side entries to "smooth" quarterly results, violating AS-1 (Accounting Standards on Disclosure).

HighFinance
3

Bank Reconciliations Not Performed Timely

Bank reconciliation statements were prepared 45–60 days after month-end, compared to the policy requirement of within 10 working days. Old unreconciled items exceeded ₹30 lakhs.

MediumFinance
4

Fixed Asset Register Not Reconciled with Physical Verification

Physical verification conducted in Q3 revealed 23 assets worth ₹18 lakhs not present at the location recorded in the asset register. No write-off or investigation had been initiated.

MediumFinance
5

Vendor Payments Made Without Valid PO or Contract

18% of vendor payments reviewed exceeded the ₹5 lakh threshold but lacked a corresponding purchase order. Management relied on verbal approvals, creating a contract risk.

HighFinance
6

Imprest Cash Fund Exceeds Authorised Limit

The petty cash imprest balance averaged ₹85,000 against an approved limit of ₹25,000. Monthly surprise counts were not conducted as required by the finance manual.

LowFinance
7

Advances to Staff Not Recovered Within Policy Period

40% of travel advances (totaling ₹7.2 lakhs) were outstanding beyond the 30-day recovery policy. No salary deductions had been initiated despite repeated reminders.

MediumFinance
8

Revenue Recognition Applied Inconsistently

Revenue from long-term contracts was recognised at invoice date rather than on percentage-of-completion basis, inconsistent with Ind AS 115 requirements and the prior-year accounting policy.

HighFinance
9

Statutory Dues Not Deposited Within Due Dates

TDS deducted for six months (April–September) was deposited on average 12 days late, attracting interest of approximately ₹1.1 lakhs under Section 201A of the Income Tax Act.

MediumFinance
10

Absence of Year-End Accrual Policy

No documented process existed for identifying and recording accruals at year-end. As a result, ₹22 lakhs of services rendered but not invoiced were omitted from the books, understating expenses.

MediumFinance

B. IT & Information Security (Observations 11–20)

11

Privileged User Access Not Reviewed Quarterly

System administrators and super-users had not undergone access recertification for 14 months, contrary to the IS policy requiring quarterly reviews. 6 ex-employee accounts remained active.

HighIT Security
12

Password Policy Not Enforced at System Level

The ERP system did not enforce password complexity (minimum 8 characters, special character requirement) as defined in the IT security policy. System testing confirmed passwords like "1234" were accepted.

HighIT Security
13

Data Backups Not Tested for Restorability

Daily database backups are taken but restoration tests were last performed 18 months ago. The BCP policy requires quarterly restore tests. This creates an unquantified recovery risk.

HighIT / BCP
14

Audit Logs Disabled on Production Database

Database audit logging was disabled on the production Oracle DB, meaning unauthorised data modifications by DBAs could not be detected or investigated.

HighIT Security
15

Patch Management — Critical Patches Unapplied

23 servers had critical OS patches (CVSS score ≥ 9.0) pending for over 90 days. The vulnerability management policy requires critical patches within 30 days of release.

HighIT Security
16

No Formal Change Management Process for ERP

Programme changes to the ERP were pushed to production without documented test results, business sign-off, or rollback plans. Of 34 changes reviewed, 28 lacked full documentation.

MediumIT Governance
17

Vendor-Provided Remote Access Not Monitored

Third-party IT vendors (support contracts) had permanent VPN credentials. Sessions were not logged or time-limited. No recent review of third-party access necessity was performed.

HighIT Security
18

Sensitive Data Stored in Unencrypted Format

Customer PAN card numbers and bank account details were stored in plain text CSV files on a shared network drive, accessible to all 240 employees in the finance department.

HighData Privacy
19

IT Asset Inventory Is Incomplete and Outdated

The IT asset register had not been updated in 11 months. Physical count identified 34 devices (laptops, servers) not recorded, including two retired servers still connected to the network.

MediumIT Governance
20

No Formal BYOD (Bring Your Own Device) Policy

Employees routinely access corporate email and ERP on personal devices. No MDM (Mobile Device Management) solution is in place, and no BYOD policy has been communicated or enforced.

MediumIT Security

C. Procurement & Contracts (Observations 21–30)

21

Single-Source Procurement Without Documented Justification

Procurements totalling ₹1.4 crores were awarded to a single vendor without competitive tendering or documented single-source justification as required under the procurement policy.

HighProcurement
22

Vendor Due Diligence Not Performed Prior to Onboarding

12 of 40 vendors onboarded during the year lacked completed KYV (Know Your Vendor) forms, background checks, or financial health assessments required by the Vendor Management Policy.

MediumProcurement
23

Contract Renewals Processed Without Competitive Rebidding

6 contracts (total value ₹3.8 crores) were renewed auto-matically for the 3rd consecutive year without market testing or management approval to waive competitive bidding.

MediumProcurement
24

Conflict of Interest Declarations Not Maintained for Procurement Officers

None of the 8 procurement officers had completed annual conflict of interest declarations for the current fiscal year, as required by the Code of Conduct and Ethics Policy.

HighProcurement
25

Goods Received Notes (GRNs) Not Matched Before Payment

The 3-way match (PO–GRN–Invoice) was bypassed for 22% of payments reviewed due to system configuration override. Payments were processed on invoice alone.

HighProcurement
26

SLA Compliance Not Monitored for Key Vendors

No formal mechanism existed to track vendor SLA adherence. Three critical IT vendors had reported downtime exceeding contracted SLAs, yet no penalties had been invoked in 18 months.

MediumVendor Mgmt
27

Split Purchases to Circumvent Approval Thresholds

Data analysis revealed 14 instances where a single requirement was split into multiple orders just below the ₹2 lakh approval threshold, avoiding the Procurement Committee review.

HighProcurement
28

Expired Contracts Continuing Without Renewal

9 vendor contracts had expired between 3 and 14 months ago, yet services continued and payments were made. The company operated under significant contractual and legal risk.

MediumContracts
29

No Indemnity or Liability Clauses in Several Key Contracts

Review of 15 service agreements revealed that 6 lacked standard indemnity, force majeure, and data protection clauses required under the standard contract template post-2022.

MediumLegal
30

Emergency Purchase Process Overused

The "emergency purchase" route (bypassing competitive bidding) was invoked 41 times in the year, compared to the benchmark of under 5%. Root cause: inadequate demand planning.

MediumProcurement

D. HR & Compliance (Observations 31–40)

31

Employee Exits Not Deprovisioned from Systems Timely

18 employees who had resigned or been terminated retained active system access for an average of 23 days post-separation, creating unauthorised access risk.

HighHR
32

Mandatory Training Completion Below Target

Only 61% of employees completed mandatory POSH (Prevention of Sexual Harassment) training by the statutory deadline. Legal exposure under POSH Act 2013 is significant.

MediumCompliance
33

Hiring Process Does Not Include Background Verification for Senior Roles

Of 12 senior hires (Grade 7+) reviewed, only 4 had undergone formal background verification. 3 candidates had undisclosed employment gaps.

MediumHR
34

Leave Records Inconsistent Between HRMS and Payroll

Reconciliation of HRMS leave data against payroll processing revealed discrepancies for 34 employees, with overpayment of leave encashment totalling ₹3.4 lakhs.

MediumHR / Payroll
35

Performance Appraisal Process Not Completed on Time

Only 58% of performance appraisals were completed by the defined deadline. Delayed appraisals affect merit-based increment accuracy and employee relations.

LowHR
36

Ghost Employees Identified in Payroll

Data analytics on payroll records identified 3 employees with duplicate PAN cards and matching bank account numbers as active employees in different departments — a classic ghost employee scheme.

HighHR / Fraud
37

No Documented Whistle-blower Policy or Reporting Mechanism

The company lacks a formal whistle-blower policy or anonymous reporting hotline, contrary to SEBI LODR requirements for listed entities and Clause 177 of the Companies Act 2013.

HighGovernance
38

Related-Party Transactions Not Disclosed at Board Level

Two vendor payments (total ₹24 lakhs) were identified as payments to companies in which a director held indirect ownership. These were not disclosed to the Audit Committee per RPT Policy.

HighGovernance
39

Overtime Claims Not Approved by Competent Authority

Review of 120 overtime records showed 38% were self-approved by employees or approved by peers rather than the designated supervisor, as required by the HR Manual.

LowHR
40

Anti-Bribery Controls Not Extended to Business Associates

The company's Anti-Bribery and Corruption (ABC) policy applies internally but has not been contractually imposed on agents, distributors, or joint-venture partners — creating third-party FCPA/UKBA exposure.

HighCompliance

E. Operations & Inventory (Observations 41–50)

41

Inventory Counts Show Significant Variances

Annual physical inventory count produced variances exceeding 3% in value (₹41 lakhs), beyond the accepted tolerance of 1%, with no formal investigation or write-off approved.

MediumOperations
42

Slow-Moving and Obsolete Stock Not Written Down

Inventory ageing analysis identified ₹1.8 crores of stock with no movement in over 12 months. No provision for obsolescence had been made, overstating inventory value and profit.

MediumOperations
43

Warehouse Security Controls Are Inadequate

CCTV coverage in Warehouse B had blind spots covering 40% of the storage area. Access logs showed 12 instances of after-hours access by non-authorised staff during the review period.

MediumOperations
44

Scrap Disposal Process Lacks Independent Oversight

Scrap sales totalling ₹12 lakhs were handled by the same team responsible for production, without independent weighment verification or Finance sign-off on proceeds received.

MediumOperations
45

Maintenance Log Records Are Incomplete

Preventive maintenance logs for 7 critical machines were incomplete or missing for Q2 and Q3. One machine subsequently experienced a major breakdown costing ₹8.5 lakhs in repairs and downtime.

MediumOperations
46

Outsourced Logistics Provider Not Audited

The third-party logistics provider (handling 60% of outbound shipments) had not been subjected to a vendor audit in 3 years, contrary to the annually-required Third Party Risk Assessment.

MediumOperations
47

Quality Rejections Not Trended or Root-Cause Analysed

Quality rejection data was collected but not analysed for trends. The rejection rate increased from 1.8% to 4.2% over 6 months without management investigation or corrective action plan.

LowOperations
48

Environmental Compliance Certificates Expired

Consent to Operate (CTO) under the Environment Protection Act had expired 4 months prior. Operations continuing under an expired CTO expose the entity to regulatory shutdown and director liability.

HighCompliance
49

Health & Safety Incident Reports Not Submitted to Regulatory Body

3 reportable workplace accidents (classified as "Lost Time Injuries") were not reported to the State Labour Inspectorate within the 48-hour window required under the Factories Act, 1948.

HighSafety
50

Business Continuity Plan Not Tested in the Past 2 Years

The BCP document was last revised 3 years ago and tabletop exercises have not been conducted for 2 years. Key contact lists and recovery time objectives (RTOs) are outdated.

HighBCP / Risk

The Satyam Fraud: When Audit Observations Are Ignored

In 2009, India's largest corporate fraud was exposed at Satyam Computer Services. Founder Ramalinga Raju confessed to inflating cash balances by ₹5,040 crores. What made this a landmark case was not just the magnitude — it was the number of audit signals that went unheeded.

Internal audit teams had raised observations about bank reconciliation anomalies and unexplained intercompany balances in prior years. External auditors PricewaterhouseCoopers confirmed cash balances without independently verifying them with banks — a textbook failure of audit procedure.

The lesson for every internal auditor: an audit observation that is documented, communicated, and then ignored by management is not the end of the auditor's responsibility. Escalation to the Audit Committee and, ultimately, the Board is both a professional obligation and a fiduciary duty.

💡 Lesson: Follow-up on audit observations is as important as raising them. An observation that sits unresolved is a risk that has been identified but not mitigated — and that responsibility falls on management and the board, not just the auditor.

Internal Audit Report Formats

The audit report is the primary deliverable of the audit function. Its format must balance completeness with readability — a 300-page report that nobody reads delivers no value.

Definition

An internal audit report is a formal written communication that conveys the objectives, scope, methodology, findings, recommendations, and management responses from an internal audit engagement. Per IIA Standard 2400, results must be communicated promptly and accurately.

The Standard Internal Audit Report Structure

Anatomy of an Internal Audit Report

Anatomy of an Internal Audit Report Layered diagram showing the eight sections of a standard internal audit report INTERNAL AUDIT REPORT Confidential — For Audit Committee Use 01 — Executive Summary Overall opinion, key findings count, rating (Satisfactory / Needs Improvement / Unsatisfactory) 02 — Background & Objectives Scope, period covered, audit mandate, key business context 03 — Audit Methodology Sampling approach, data analytics used, interviews conducted, IIA Standards compliance 04 — Detailed Findings & Recommendations Each observation: Condition → Criteria → Cause → Consequence → Recommendation → Management Response → Target Date 05 — Ratings Summary High / Medium / Low matrix 06 — Positive Observations Controls working well 07 — Appendices Process maps, data queries, samples tested, interviewees list 08 — Sign-Off & Distribution CAE signature, distribution list, classification marking, issue date Report Flow ↓

Sample Audit Report Observation Write-up

Here is how a single high-risk observation would appear in a properly formatted internal audit report:

Internal Audit Report — Finance Function

Procurement Cycle · FY 2024–25 · Ref: IA/2025/FIN/04
Issued: 15 May 2025
Rating: Needs Improvement
Observation 1 of 3 — High Risk

Segregation of Duties Failure in Accounts Payable

Condition

The same accounts payable clerk (Employee ID: AP-017) performs vendor creation, invoice approval, and payment release without any independent review or system-enforced controls preventing this combination.

Criteria

Per the Finance Policy Manual (Section 4.2) and COSO Internal Control Framework, no individual should have end-to-end control over a financial transaction. Vendor creation, approval, and payment must be segregated among at least two individuals.

Cause

Staff attrition in the AP team (3 departures over 6 months) resulted in role consolidation without a corresponding reassessment of control adequacy or compensating controls.

Effect

Undetected fraudulent vendor payments are possible. Estimated maximum exposure based on AP transaction volume: ₹2.4 crores per annum. One suspected anomaly (Payment Ref: 448823) is under CFO review.

Recommendation

Immediately restrict AP-017's system role so that vendor creation and payment release require separate approval by the Finance Manager. Implement system-level segregation controls in the ERP within 30 days. Backfill the vacant AP Analyst role within 60 days.

Management Response

"Agreed. The Finance Manager will immediately configure dual-approval controls in the ERP (target: 22 May 2025). The Talent Acquisition team has been briefed on the AP Analyst vacancy (target hire date: 15 July 2025). Monthly SOD reports will be implemented from June 2025." — CFO, 18 May 2025

Types of Internal Audit Report Formats

📄

Traditional Long-Form Report

Full narrative format covering all audit areas in detail. Best for comprehensive assurance engagements or when regulatory filing is required. Typically 15–50 pages.

📊

Executive Flash Report

One to two-page summary with a heat map, finding count by severity, and top 3 issues. Designed for Boards and Audit Committees who need the picture without the prose.

📋

Observation Tracker / Issue Log

A living spreadsheet or GRC-system record of all open, in-progress, and closed findings. The backbone of follow-up audit programmes. Updated monthly or quarterly.

🎯

Thematic / Deep Dive Report

Focuses on one specific risk or process (e.g. "Cybersecurity Review" or "Third-Party Risk"). Contains detailed technical findings and is often shared externally with regulators.

🧠

Audit Knowledge Quiz

10 questions — test your mastery of audit observations and report formats.

1What does the "5C Model" of an audit observation stand for?
A. Compliance, Control, Check, Confirm, Close
B. Condition, Criteria, Cause, Consequence, Corrective Action
C. Context, Concern, Cause, Cost, Correction
D. Coverage, Criteria, Condition, Conclusion, Communication
✅ Correct Answer: BThe 5C Model (Condition, Criteria, Cause, Consequence, Corrective Action) is the internationally recognised framework for structuring audit observations per IIA standards.
2Which IIA Standard specifically governs the communication of audit results?
A. IIA Standard 2100
B. IIA Standard 2300
C. IIA Standard 2400
D. IIA Standard 2600
✅ Correct Answer: CIIA Standard 2400 covers "Communicating Results" — it requires that internal auditors communicate engagement results promptly and accurately. Standard 2300 covers performing the engagement.
3In segregation of duties, a "3-way match" in procurement refers to matching:
A. Requisition, PO, and Delivery Note
B. Purchase Order, Goods Receipt Note, and Invoice
C. Budget, Actual Spend, and Forecast
D. Vendor Quote, PO, and Management Approval
✅ Correct Answer: BThe 3-way match (PO + GRN + Invoice) is a fundamental procurement control that ensures payment is made only for goods/services ordered and actually received at the agreed price.
4Which of the following is the BEST description of a "ghost employee" fraud?
A. An employee who works remotely without physical presence
B. An employee who leaves work without clocking out
C. A fictitious or terminated employee retained on payroll to divert salary payments
D. An employee who performs tasks outside their defined job role
✅ Correct Answer: CGhost employees are fictitious persons (or real terminated employees) kept on payroll so that their salaries can be diverted — typically to bank accounts controlled by the fraudster.
5An auditor finds that critical security patches have not been applied for 95 days. The vulnerability management policy requires patches within 30 days. What is the "criteria" element of this observation?
A. Critical patches are unapplied for 95 days
B. Vulnerability management policy requires patch application within 30 days
C. The company may be exposed to a cyberattack
D. The IT team is understaffed and behind on maintenance
✅ Correct Answer: B"Criteria" is the benchmark — what should happen per policy, law, contract, or best practice. The existing state ("95 days") is the "Condition." The policy requirement of 30 days is the "Criteria."
6In an audit report, "Management Response" refers to:
A. The auditor's assessment of how management is performing
B. The board's approval of the audit report
C. Management's formal reply to each audit finding, including agreed action and deadline
D. The CAE's conclusion on the overall control environment
✅ Correct Answer: CManagement Response is the auditee's formal written reply — agreeing, partially agreeing, or disagreeing — with each finding, along with the planned corrective action, responsible owner, and target completion date.
7Which of the following is an example of a "split purchase" or "purchase splitting" observation?
A. Procuring from two different vendors for the same requirement
B. Delaying a purchase to the next financial year
C. Dividing one procurement into multiple orders to avoid a higher-level approval threshold
D. Splitting a payment between two bank accounts
✅ Correct Answer: CPurchase splitting (also called "invoice splitting") is when a single procurement requirement is broken into smaller transactions, each below the approval threshold, to circumvent the required authorisation. It is a red flag for fraud or policy circumvention.
8Under Ind AS 115, revenue from long-term contracts should generally be recognised:
A. When cash is received from the customer
B. On the date the invoice is raised
C. Over time, using a method that reflects progress toward completion
D. At contract inception when the agreement is signed
✅ Correct Answer: CInd AS 115 (aligned with IFRS 15) requires revenue to be recognised when — or as — performance obligations are satisfied. For long-term contracts, this typically means over time using percentage-of-completion or similar methods.
9A "thematic audit report" is best described as:
A. An annual report covering all audit areas
B. A focused review of one specific risk or topic across the organisation
C. A report prepared exclusively for external regulators
D. A summarised version of the long-form audit report for board circulation
✅ Correct Answer: BA thematic or deep-dive audit report focuses intensely on one risk area (e.g. cybersecurity, anti-bribery, third-party risk) across the entire organisation, often triggered by a regulatory concern or emerging risk.
10Which section of the Companies Act 2013 pertains to audit committees for listed companies?
A. Section 134
B. Section 143
C. Section 177
D. Section 204
✅ Correct Answer: CSection 177 of the Companies Act 2013 mandates the constitution and functioning of the Audit Committee for listed companies and certain classes of companies. It specifies composition, quorum, powers, and responsibilities including reviewing internal audit findings.

Audit Trivia — Did You Know?

📜

Ancient Roots

The word "audit" comes from the Latin audire — "to hear." In ancient Rome, officials would listen to accounts read aloud to verify them, hence "auditor."

🏛️

Oldest Profession in Finance

Evidence of auditing dates back to 3000 BCE in Mesopotamia — clay tablets show accounting records being verified by independent scribes, an early form of internal control.

🌍

Global Standards

The IIA (founded 1941) has over 245,000 members in 170+ countries. The CIA (Certified Internal Auditor) is the world's only globally accepted certification for internal auditors.

💸

Cost of Fraud

The ACFE's Report to the Nations 2024 estimates that organisations lose 5% of revenue to fraud annually. Effective internal audit is the single most impactful anti-fraud control.

🤖

AI in Auditing

Over 60% of large internal audit functions now use data analytics or AI tools for continuous monitoring. The shift from sampling to full-population testing is redefining what "audit coverage" means.

📊

Sarbanes-Oxley Effect

After Enron and WorldCom collapsed in 2001–2002, the US passed SOX (Sarbanes-Oxley Act 2002), making CEOs and CFOs personally liable for the accuracy of financial reports — transforming internal audit globally.

Frequently Asked Questions

Answers to the most common questions from auditors, finance professionals, and students on audit observations and report formats.

What is the difference between an audit observation and an audit finding?
The terms are often used interchangeably, but there is a subtle distinction in some frameworks. An audit observation is any documented note arising from the audit — including informational notes or areas of improvement. An audit finding specifically refers to a significant or material observation that requires corrective action. In IIA parlance, all findings are observations, but not all observations rise to the level of findings. For practical reporting purposes, most audit teams classify all reportable items as "findings" and distinguish them only by severity rating (High, Medium, Low).
How long should a management response period be after an audit report?
Best practice (aligned with IIA guidance) is 10–15 working days for management to provide responses to draft findings. The final report should not be issued without management responses except in exceptional circumstances. For critical (High) findings, many audit functions issue an interim observation immediately rather than waiting for the full report cycle, and some organisations require the CFO or CEO to acknowledge High-risk findings within 48–72 hours of issue.
What does an "unsatisfactory" audit rating mean?
An "Unsatisfactory" (or equivalent — some firms use "Red," "Inadequate," or "Needs Major Improvement") overall audit rating means the internal controls reviewed are fundamentally deficient and present material risk to the organisation. It typically triggers mandatory reporting to the Audit Committee, an accelerated follow-up audit timeline (usually 90 days), and may require Board notification under governance policies. It is the highest severity rating and is used sparingly — most audit functions issue fewer than 5% of reports at this level.
What is a "positive observation" in an audit report?
A positive observation (or "commendation") documents areas where controls are working particularly well — perhaps better than expected or as a result of a significant improvement since the last audit. Including positive observations is considered good practice for several reasons: it demonstrates balance and objectivity, recognises management effort, and creates a performance baseline for future audits. Many organisations require at least one positive observation per audit report to signal that the audit function is not purely fault-finding but also provides constructive assurance.
What is the difference between internal and external audit reports?
An internal audit report is an internal management document — confidential, operational in focus, and addressed to the Audit Committee and senior management. It is prepared by the company's own internal audit team (or co-sourced provider) and covers a wide range of risk areas. An external audit report (statutory audit) is a public document prepared by an independent registered auditor, expressing an opinion on whether the financial statements give a "true and fair view" under applicable accounting standards. External audit reports are filed with the Registrar of Companies and are publicly available. The scope, audience, and legal obligations differ significantly.
How is audit observation severity (High/Medium/Low) determined?
Severity is assessed using a risk matrix combining two dimensions: Likelihood (probability the risk will materialise) and Impact (financial, reputational, regulatory, or operational consequence if it does). High severity typically means high likelihood AND/OR high impact — for example, a control failure that could result in financial loss exceeding a materiality threshold, a regulatory breach, or fraud. Medium is significant but manageable with prompt action. Low indicates minor process improvements with limited risk exposure. Most audit functions have a formally documented Rating Criteria document aligned with the organisation's risk appetite.
Can management "disagree" with an audit observation?
Yes — management has the right to disagree with an audit observation, and the IIA requires that both the auditor's position and management's disagreement be documented in the final report. The auditor should not remove or soften a finding simply because management disagrees. However, genuine factual errors identified by management should be corrected. If the disagreement is substantive and unresolved, it should be escalated to the Chief Audit Executive and, if still unresolved, to the Audit Committee. This is a fundamental quality safeguard for audit independence.
What is a follow-up audit and when should it be conducted?
A follow-up audit (or closure review) is a targeted audit conducted to verify that management has implemented the agreed corrective actions from a previous audit report. IIA Standard 2500 requires that the Chief Audit Executive establish a follow-up process. Typical timelines: High-risk findings — follow-up within 60–90 days of target completion date; Medium — within 90–120 days; Low — at the next scheduled audit or annually. Follow-up findings that remain open beyond the agreed deadline should be escalated to the Audit Committee as "overdue observations."
What is a "Root Cause" and why is it important in audit observations?
The root cause is the fundamental underlying reason a control deficiency exists — not the symptom. For example, the condition might be "vendor payments made without valid POs." Possible root causes include: inadequate training, system configuration error, lack of policy awareness, or deliberate override. Identifying and addressing the root cause prevents recurrence. An audit recommendation that treats only the symptom ("get POs retroactively") will see the same finding reappear next year. A root-cause recommendation ("implement mandatory PO validation in the ERP system and retrain procurement staff") attacks the source. IIA guidance specifically requires root cause analysis for significant findings.
How do data analytics improve audit observation quality?
Data analytics transforms audit from sample-based testing (reviewing 5–10% of transactions) to full-population analysis (examining 100% of transactions). This dramatically improves detection rates for anomalies, patterns, and outliers that sample testing would miss. Examples: running a Benford's Law test on all vendor payments to detect manipulation; analysing all employee expense claims for duplicates; identifying split-purchase patterns across hundreds of purchase orders. Tools like ACL (Galvanize), IDEA, Python, and Power BI are commonly used. Beyond detection, analytics allow auditors to quantify the financial impact of findings precisely — strengthening the observation's credibility and priority.

© 2025 LearnEdition.com — India's Premier Professional Learning Platform

This content is for educational purposes. Always consult a qualified auditor or compliance professional for specific advice.

Scroll to Top