Need to write an audit report that gets read and acted on? In this guide, we focus on how to structure and write audit reports that are clear, relevant, and support continual improvement. We also explore how tools like Artificial Intelligence (AI), strong stakeholder communication, and report structure can make your audit reporting more effective and easier to deliver.
Whether you’re using a standard template or building your own, your goal is the same: deliver a useful, evidence-based document that supports accountability and improvement.
Key elements to include in an audit report
Every audit report should include these core components:
- Objective – Why the audit was performed
- Scope – What areas or processes were reviewed
- Criteria – The standards, legislation, or internal requirements you audited against
Also, document:
- Audited location(s)
- Audit dates
- Lead auditor and key contacts
- Audit findings and supporting evidence
- Any disclaimers or mandatory inclusions specified in your organisation’s template
Stakeholder engagement: It’s not just a report
An effective audit report reflects ongoing communication with stakeholders before, during, and after the audit. Stakeholders, including senior management, audit sponsors, and frontline staff, should understand:
- The purpose and relevance of the audit
- What was found
- What actions are needed next
When stakeholders are informed and engaged throughout the process, they’re more likely to act on the report’s findings. Your report should be written with this audience in mind, helping them understand risks, gaps, and actions clearly and concisely, without unnecessary complexity.
Logical structure: Start strong and keep it simple
A well-structured audit report makes your findings easy to interpret. A suggested structure is:
-
Executive summary
Provide a high-level summary of:
- Whether the audit objectives were met
- Number and severity of findings
- Key themes or risks
- Follow up actions required
Use summary tables, red-amber-green indicators, or dashboards to visualise results, where possible. Leveraging these tools and technology can improve clarity and make key findings easier to interpret.
-
Audit scope
Detail the boundaries of the audit, including timeframe, locations, departments, or systems reviewed. Be clear about exclusions or limitations, or if any areas within the scope of the audit could not be covered due to time constraints or other restrictions during the audit.
-
Findings – Use the 5 Cs
Structure findings consistently using the 5 Cs:
- Criteria – What requirement was not met?
- Condition – What did you observe?
- Cause – Why did it happen (if known)?
- Consequence – What is the impact or risk?
- Corrective Action – What needs to happen next (without prescribing the solution in certification audits)
Tip: Back up your findings with robust evidence. In clinical or data-intensive audits, include sample sizes, trends, or analysis methods where appropriate.
Example:
Criteria: ISO 14001:2015 Clause 7.2 – Competence requires organisations to retain documented information as evidence of competence
Condition: No documented evidence of training completion for new spill response procedures
Cause: Training register had not been updated post-policy change
Consequence: Increased risk of environmental harm due to incorrect spill response
Corrective Action: Organisation must ensure relevant personnel are trained and records are maintained
Group findings logically, by department, process, or site, so they’re easier to interpret and act upon.
Depending on your personal style, these 5 C’s can be reorganised into more of a sentence-based structure, rather than individual points. Think about your intended audience and the way they are likely to interpret the information – what works best for them?
Note: In some audits, such as certification audits, it may be inappropriate to provide a recommended corrective action to the auditee due to the need to maintain independence.
More on audit findings
Findings are the things you identify during an audit that aren’t as they should be. Officially, they’re called nonconformances (or noncompliances in legal settings), but many organisations use alternative terms like CAR (Corrective Action Request), OFI (Opportunity for Improvement), PIN (Potential Improvement Note), CAPA (Corrective and Preventive Action), or Area of Concern.
No matter the label, the purpose is the same: to highlight gaps and support improvement.
In this article, we’ll stick with nonconformance for simplicity. These are usually graded by severity:
- Critical – Only used in high-risk audits (like food safety). A serious failure with direct impact on public health or a breach of legislation.
- Major – A key process is missing or not effective.
- Minor – The requirement is only partly met, or the outcome is only partly effective.
All nonconformances should be described clearly, using the 5 Cs to keep your report logical, consistent, and actionable.
Opinion and recommendations
Use this section to summarise your professional judgment about the overall system or process effectiveness. Highlight:
- Any systemic or recurring issues
- Key risks or opportunities
- Recommendations or improvement areas
Be cautious when prescribing solutions, particularly during third-party or certification audits. Instead, identify areas of concern or opportunity in neutral terms.
Instead of:
“You should implement automated alerts for overdue training.”
Say:
“There may be an opportunity to enhance visibility of overdue training records through automated reporting.”
Measurable action plans
Findings without action won’t drive improvement. While you may not prescribe the fix, your report should prompt the organisation to develop clear, measurable action plans, including:
- Who is responsible
- What needs to be done
- By when it should be addressed
- How it will be verified
Including a simple action tracking table or linking findings to risk ratings can make it easier for the organisation to follow through.
Using AI to streamline audit reporting
AI can reduce the time and effort spent on routine reporting tasks, such as:
- Drafting sections of the report
- Summarising field notes
- Highlighting inconsistencies
- Standardising nonconformance language
Real-world example: WestRock
In 2024, global packaging company WestRock partnered with Deloitte to introduce generative AI into their internal audit process [1]https://deloitte.wsj.com/riskandcompliance/how-westrock-harnessed-genai-to-enhance-internal-audit-f0926363. The AI tool helped draft audit objectives, programs, and even structured report content under auditor supervision.
Benefits included:
- Faster reporting
- Improved consistency
- More time for auditors to engage with stakeholders and analyse risk
Used properly, AI supports, not replaces, auditor expertise. It helps streamline documentation so auditors can focus on value-adding insights.
Timeliness matters
Audit reports lose value if delivered too late. Aim to send the report within 3–5 business days of the audit, or sooner if possible. If a review process is required, set expectations early to avoid delays.
Delays create risk:
- People forget what was said
- Corrective actions get postponed
- The audit loses relevance
Build in report-writing time as part of your overall audit schedule, and leverage tools (including AI) to reduce bottlenecks.
Final tips for writing better audit reports
- Start with a strong executive summary
- Use a clear, logical structure
- Apply the 5 Cs to findings
- Avoid consulting advice in certification reports
- Use AI and visual tools where appropriate
- Deliver the report promptly
A well-written audit report doesn’t just tick boxes – it supports improvement, builds trust, and creates a roadmap for stronger systems.
Want to sharpen your audit communication skills even further? Explore our Report Writing Fundamentals and Audit Interview Skills eLearn modules. In just 45 minutes each, you’ll gain practical strategies to write clearer reports and conduct more effective audit interviews – key skills for any auditor looking to add value and drive improvement.
Enrol today and build confidence in your audit delivery from start to finish.
Further reading
Find out how to harness the Hawthorne Effect in management systems auditing
Learn all about the ISO Harmonised Structure
Get the lowdown on how the upcoming ISO 19011:2026 Revision Means for Auditors and Organisations
References
| ↑1 | https://deloitte.wsj.com/riskandcompliance/how-westrock-harnessed-genai-to-enhance-internal-audit-f0926363 |
|---|

