Top 50 Audit Observations & Audit Report Formats
A practitioner's deep-dive into audit findings, internal audit report writing, and real-world examples — with diagrams, stories, and a graded quiz.
What Is an Audit Observation?
Before diving into the top 50 examples, let's anchor the fundamentals — because precision in language is the first discipline of any auditor.
An audit observation (also called an audit finding or audit comment) is a factual, evidence-based statement that identifies a gap between the current state (condition) and what should be (criteria), together with its cause, effect, and the recommended corrective action.
The IIA (Institute of Internal Auditors) defines an observation as a formal communication that documents significant differences between expected and actual situations. Every well-formed observation follows the 5C Model: Condition, Criteria, Cause, Consequence, and Corrective Action.
The 5C Anatomy of a Robust Audit Observation
Think of the 5C model as the skeleton of every audit observation. A finding that misses even one "C" is incomplete — management can dismiss it as vague, and external reviewers (regulators, external auditors) may question the quality of the audit itself.
Key Terms at a Glance
Audit Observation
A documented gap between actual and expected controls, backed by evidence gathered during the audit fieldwork phase.
Audit Finding
Often used interchangeably with "observation," though in some frameworks a "finding" specifically refers to a more severe or material observation.
Management Response
The auditee's formal response to an observation, including the agreed corrective action, owner, and deadline. Critical for closing the audit loop.
Follow-Up Audit
A targeted review conducted 3–12 months after the original report to verify that agreed corrective actions have been implemented.
Top 50 Audit Observations — With Examples
Drawn from real-world internal audits across finance, IT, HR, procurement, and operations. Each observation includes the finding and a real-life example you can adapt to your audit report.
How to read these: Severity ratings are indicative. "High" = immediate risk to financials, compliance, or reputation. "Medium" = significant process weakness. "Low" = minor procedural gap.
A. Financial Controls (Observations 1–10)
Lack of Segregation of Duties in Accounts Payable
The same employee creates vendors, approves invoices, and processes payments — a classic three-point control failure. This structure allows fraud without detection.
Example: At a mid-size manufacturing company, an AP clerk created 11 fictitious vendors and approved ₹48 lakhs in payments over 14 months before an audit detected the pattern.
Journal Entries Posted Without Adequate Supporting Documentation
Manual journal entries were posted near period-end without any supporting journal vouchers, business justification, or dual-authorisation.
Example: A retail chain's finance team posted ₹1.2 crore in top-side entries to "smooth" quarterly results, violating AS-1 (Accounting Standards on Disclosure).
Bank Reconciliations Not Performed Timely
Bank reconciliation statements were prepared 45–60 days after month-end, compared to the policy requirement of within 10 working days. Old unreconciled items exceeded ₹30 lakhs.
Fixed Asset Register Not Reconciled with Physical Verification
Physical verification conducted in Q3 revealed 23 assets worth ₹18 lakhs not present at the location recorded in the asset register. No write-off or investigation had been initiated.
Vendor Payments Made Without Valid PO or Contract
18% of vendor payments reviewed exceeded the ₹5 lakh threshold but lacked a corresponding purchase order. Management relied on verbal approvals, creating a contract risk.
Imprest Cash Fund Exceeds Authorised Limit
The petty cash imprest balance averaged ₹85,000 against an approved limit of ₹25,000. Monthly surprise counts were not conducted as required by the finance manual.
Advances to Staff Not Recovered Within Policy Period
40% of travel advances (totaling ₹7.2 lakhs) were outstanding beyond the 30-day recovery policy. No salary deductions had been initiated despite repeated reminders.
Revenue Recognition Applied Inconsistently
Revenue from long-term contracts was recognised at invoice date rather than on percentage-of-completion basis, inconsistent with Ind AS 115 requirements and the prior-year accounting policy.
Statutory Dues Not Deposited Within Due Dates
TDS deducted for six months (April–September) was deposited on average 12 days late, attracting interest of approximately ₹1.1 lakhs under Section 201A of the Income Tax Act.
Absence of Year-End Accrual Policy
No documented process existed for identifying and recording accruals at year-end. As a result, ₹22 lakhs of services rendered but not invoiced were omitted from the books, understating expenses.
B. IT & Information Security (Observations 11–20)
Privileged User Access Not Reviewed Quarterly
System administrators and super-users had not undergone access recertification for 14 months, contrary to the IS policy requiring quarterly reviews. 6 ex-employee accounts remained active.
Password Policy Not Enforced at System Level
The ERP system did not enforce password complexity (minimum 8 characters, special character requirement) as defined in the IT security policy. System testing confirmed passwords like "1234" were accepted.
Data Backups Not Tested for Restorability
Daily database backups are taken but restoration tests were last performed 18 months ago. The BCP policy requires quarterly restore tests. This creates an unquantified recovery risk.
Audit Logs Disabled on Production Database
Database audit logging was disabled on the production Oracle DB, meaning unauthorised data modifications by DBAs could not be detected or investigated.
Patch Management — Critical Patches Unapplied
23 servers had critical OS patches (CVSS score ≥ 9.0) pending for over 90 days. The vulnerability management policy requires critical patches within 30 days of release.
No Formal Change Management Process for ERP
Programme changes to the ERP were pushed to production without documented test results, business sign-off, or rollback plans. Of 34 changes reviewed, 28 lacked full documentation.
Vendor-Provided Remote Access Not Monitored
Third-party IT vendors (support contracts) had permanent VPN credentials. Sessions were not logged or time-limited. No recent review of third-party access necessity was performed.
Sensitive Data Stored in Unencrypted Format
Customer PAN card numbers and bank account details were stored in plain text CSV files on a shared network drive, accessible to all 240 employees in the finance department.
IT Asset Inventory Is Incomplete and Outdated
The IT asset register had not been updated in 11 months. Physical count identified 34 devices (laptops, servers) not recorded, including two retired servers still connected to the network.
No Formal BYOD (Bring Your Own Device) Policy
Employees routinely access corporate email and ERP on personal devices. No MDM (Mobile Device Management) solution is in place, and no BYOD policy has been communicated or enforced.
C. Procurement & Contracts (Observations 21–30)
Single-Source Procurement Without Documented Justification
Procurements totalling ₹1.4 crores were awarded to a single vendor without competitive tendering or documented single-source justification as required under the procurement policy.
Vendor Due Diligence Not Performed Prior to Onboarding
12 of 40 vendors onboarded during the year lacked completed KYV (Know Your Vendor) forms, background checks, or financial health assessments required by the Vendor Management Policy.
Contract Renewals Processed Without Competitive Rebidding
6 contracts (total value ₹3.8 crores) were renewed auto-matically for the 3rd consecutive year without market testing or management approval to waive competitive bidding.
Conflict of Interest Declarations Not Maintained for Procurement Officers
None of the 8 procurement officers had completed annual conflict of interest declarations for the current fiscal year, as required by the Code of Conduct and Ethics Policy.
Goods Received Notes (GRNs) Not Matched Before Payment
The 3-way match (PO–GRN–Invoice) was bypassed for 22% of payments reviewed due to system configuration override. Payments were processed on invoice alone.
SLA Compliance Not Monitored for Key Vendors
No formal mechanism existed to track vendor SLA adherence. Three critical IT vendors had reported downtime exceeding contracted SLAs, yet no penalties had been invoked in 18 months.
Split Purchases to Circumvent Approval Thresholds
Data analysis revealed 14 instances where a single requirement was split into multiple orders just below the ₹2 lakh approval threshold, avoiding the Procurement Committee review.
Expired Contracts Continuing Without Renewal
9 vendor contracts had expired between 3 and 14 months ago, yet services continued and payments were made. The company operated under significant contractual and legal risk.
No Indemnity or Liability Clauses in Several Key Contracts
Review of 15 service agreements revealed that 6 lacked standard indemnity, force majeure, and data protection clauses required under the standard contract template post-2022.
Emergency Purchase Process Overused
The "emergency purchase" route (bypassing competitive bidding) was invoked 41 times in the year, compared to the benchmark of under 5%. Root cause: inadequate demand planning.
D. HR & Compliance (Observations 31–40)
Employee Exits Not Deprovisioned from Systems Timely
18 employees who had resigned or been terminated retained active system access for an average of 23 days post-separation, creating unauthorised access risk.
Mandatory Training Completion Below Target
Only 61% of employees completed mandatory POSH (Prevention of Sexual Harassment) training by the statutory deadline. Legal exposure under POSH Act 2013 is significant.
Hiring Process Does Not Include Background Verification for Senior Roles
Of 12 senior hires (Grade 7+) reviewed, only 4 had undergone formal background verification. 3 candidates had undisclosed employment gaps.
Leave Records Inconsistent Between HRMS and Payroll
Reconciliation of HRMS leave data against payroll processing revealed discrepancies for 34 employees, with overpayment of leave encashment totalling ₹3.4 lakhs.
Performance Appraisal Process Not Completed on Time
Only 58% of performance appraisals were completed by the defined deadline. Delayed appraisals affect merit-based increment accuracy and employee relations.
Ghost Employees Identified in Payroll
Data analytics on payroll records identified 3 employees with duplicate PAN cards and matching bank account numbers as active employees in different departments — a classic ghost employee scheme.
No Documented Whistle-blower Policy or Reporting Mechanism
The company lacks a formal whistle-blower policy or anonymous reporting hotline, contrary to SEBI LODR requirements for listed entities and Clause 177 of the Companies Act 2013.
Related-Party Transactions Not Disclosed at Board Level
Two vendor payments (total ₹24 lakhs) were identified as payments to companies in which a director held indirect ownership. These were not disclosed to the Audit Committee per RPT Policy.
Overtime Claims Not Approved by Competent Authority
Review of 120 overtime records showed 38% were self-approved by employees or approved by peers rather than the designated supervisor, as required by the HR Manual.
Anti-Bribery Controls Not Extended to Business Associates
The company's Anti-Bribery and Corruption (ABC) policy applies internally but has not been contractually imposed on agents, distributors, or joint-venture partners — creating third-party FCPA/UKBA exposure.
E. Operations & Inventory (Observations 41–50)
Inventory Counts Show Significant Variances
Annual physical inventory count produced variances exceeding 3% in value (₹41 lakhs), beyond the accepted tolerance of 1%, with no formal investigation or write-off approved.
Slow-Moving and Obsolete Stock Not Written Down
Inventory ageing analysis identified ₹1.8 crores of stock with no movement in over 12 months. No provision for obsolescence had been made, overstating inventory value and profit.
Warehouse Security Controls Are Inadequate
CCTV coverage in Warehouse B had blind spots covering 40% of the storage area. Access logs showed 12 instances of after-hours access by non-authorised staff during the review period.
Scrap Disposal Process Lacks Independent Oversight
Scrap sales totalling ₹12 lakhs were handled by the same team responsible for production, without independent weighment verification or Finance sign-off on proceeds received.
Maintenance Log Records Are Incomplete
Preventive maintenance logs for 7 critical machines were incomplete or missing for Q2 and Q3. One machine subsequently experienced a major breakdown costing ₹8.5 lakhs in repairs and downtime.
Outsourced Logistics Provider Not Audited
The third-party logistics provider (handling 60% of outbound shipments) had not been subjected to a vendor audit in 3 years, contrary to the annually-required Third Party Risk Assessment.
Quality Rejections Not Trended or Root-Cause Analysed
Quality rejection data was collected but not analysed for trends. The rejection rate increased from 1.8% to 4.2% over 6 months without management investigation or corrective action plan.
Environmental Compliance Certificates Expired
Consent to Operate (CTO) under the Environment Protection Act had expired 4 months prior. Operations continuing under an expired CTO expose the entity to regulatory shutdown and director liability.
Health & Safety Incident Reports Not Submitted to Regulatory Body
3 reportable workplace accidents (classified as "Lost Time Injuries") were not reported to the State Labour Inspectorate within the 48-hour window required under the Factories Act, 1948.
Business Continuity Plan Not Tested in the Past 2 Years
The BCP document was last revised 3 years ago and tabletop exercises have not been conducted for 2 years. Key contact lists and recovery time objectives (RTOs) are outdated.
The Satyam Fraud: When Audit Observations Are Ignored
In 2009, India's largest corporate fraud was exposed at Satyam Computer Services. Founder Ramalinga Raju confessed to inflating cash balances by ₹5,040 crores. What made this a landmark case was not just the magnitude — it was the number of audit signals that went unheeded.
Internal audit teams had raised observations about bank reconciliation anomalies and unexplained intercompany balances in prior years. External auditors PricewaterhouseCoopers confirmed cash balances without independently verifying them with banks — a textbook failure of audit procedure.
The lesson for every internal auditor: an audit observation that is documented, communicated, and then ignored by management is not the end of the auditor's responsibility. Escalation to the Audit Committee and, ultimately, the Board is both a professional obligation and a fiduciary duty.
💡 Lesson: Follow-up on audit observations is as important as raising them. An observation that sits unresolved is a risk that has been identified but not mitigated — and that responsibility falls on management and the board, not just the auditor.
Internal Audit Report Formats
The audit report is the primary deliverable of the audit function. Its format must balance completeness with readability — a 300-page report that nobody reads delivers no value.
An internal audit report is a formal written communication that conveys the objectives, scope, methodology, findings, recommendations, and management responses from an internal audit engagement. Per IIA Standard 2400, results must be communicated promptly and accurately.
The Standard Internal Audit Report Structure
Anatomy of an Internal Audit Report
Sample Audit Report Observation Write-up
Here is how a single high-risk observation would appear in a properly formatted internal audit report:
Internal Audit Report — Finance Function
Segregation of Duties Failure in Accounts Payable
The same accounts payable clerk (Employee ID: AP-017) performs vendor creation, invoice approval, and payment release without any independent review or system-enforced controls preventing this combination.
Per the Finance Policy Manual (Section 4.2) and COSO Internal Control Framework, no individual should have end-to-end control over a financial transaction. Vendor creation, approval, and payment must be segregated among at least two individuals.
Staff attrition in the AP team (3 departures over 6 months) resulted in role consolidation without a corresponding reassessment of control adequacy or compensating controls.
Undetected fraudulent vendor payments are possible. Estimated maximum exposure based on AP transaction volume: ₹2.4 crores per annum. One suspected anomaly (Payment Ref: 448823) is under CFO review.
Immediately restrict AP-017's system role so that vendor creation and payment release require separate approval by the Finance Manager. Implement system-level segregation controls in the ERP within 30 days. Backfill the vacant AP Analyst role within 60 days.
"Agreed. The Finance Manager will immediately configure dual-approval controls in the ERP (target: 22 May 2025). The Talent Acquisition team has been briefed on the AP Analyst vacancy (target hire date: 15 July 2025). Monthly SOD reports will be implemented from June 2025." — CFO, 18 May 2025
Types of Internal Audit Report Formats
Traditional Long-Form Report
Full narrative format covering all audit areas in detail. Best for comprehensive assurance engagements or when regulatory filing is required. Typically 15–50 pages.
Executive Flash Report
One to two-page summary with a heat map, finding count by severity, and top 3 issues. Designed for Boards and Audit Committees who need the picture without the prose.
Observation Tracker / Issue Log
A living spreadsheet or GRC-system record of all open, in-progress, and closed findings. The backbone of follow-up audit programmes. Updated monthly or quarterly.
Thematic / Deep Dive Report
Focuses on one specific risk or process (e.g. "Cybersecurity Review" or "Third-Party Risk"). Contains detailed technical findings and is often shared externally with regulators.
Audit Knowledge Quiz
10 questions — test your mastery of audit observations and report formats.
Audit Trivia — Did You Know?
Ancient Roots
The word "audit" comes from the Latin audire — "to hear." In ancient Rome, officials would listen to accounts read aloud to verify them, hence "auditor."
Oldest Profession in Finance
Evidence of auditing dates back to 3000 BCE in Mesopotamia — clay tablets show accounting records being verified by independent scribes, an early form of internal control.
Global Standards
The IIA (founded 1941) has over 245,000 members in 170+ countries. The CIA (Certified Internal Auditor) is the world's only globally accepted certification for internal auditors.
Cost of Fraud
The ACFE's Report to the Nations 2024 estimates that organisations lose 5% of revenue to fraud annually. Effective internal audit is the single most impactful anti-fraud control.
AI in Auditing
Over 60% of large internal audit functions now use data analytics or AI tools for continuous monitoring. The shift from sampling to full-population testing is redefining what "audit coverage" means.
Sarbanes-Oxley Effect
After Enron and WorldCom collapsed in 2001–2002, the US passed SOX (Sarbanes-Oxley Act 2002), making CEOs and CFOs personally liable for the accuracy of financial reports — transforming internal audit globally.
Frequently Asked Questions
Answers to the most common questions from auditors, finance professionals, and students on audit observations and report formats.
