Communicating Audit Results to Management and Board
Learn best practices for presenting IS audit findings to management and the board, including report structure and communication strategies for the CISA exam.
Effective communication of audit results is one of the most important skills for an IS auditor. The value of an audit engagement depends not only on the quality of testing and analysis but also on how clearly and persuasively findings are communicated to stakeholders. CISA candidates should understand the principles, formats, and challenges of audit reporting.
The Audit Report Structure
A well-structured IS audit report typically includes the following sections:
- Executive summary: A high-level overview of the audit scope, key findings, and overall conclusions designed for senior management and board members
- Audit objectives and scope: A description of what was audited, why, and the boundaries of the engagement
- Methodology: The standards, frameworks, and techniques used during the audit
- Findings and recommendations: Detailed observations, their risk ratings, root causes, and recommended corrective actions
- Management responses: The auditee's agreement or disagreement with findings and planned remediation actions
- Conclusion: The auditor's overall opinion on the adequacy of controls
Structuring Individual Findings
Each audit finding should follow a consistent format that includes:
- Condition: What the auditor found (the current state)
- Criteria: What was expected (the standard or requirement)
- Cause: Why the gap exists (root cause analysis)
- Effect: The impact or potential impact of the finding
- Recommendation: Suggested corrective action
Risk Rating Findings
Findings should be rated by risk level to help management prioritize remediation efforts. Common rating scales include:
- Critical: Immediate action required; significant risk to the organization
- High: Prompt action needed; material control weakness
- Medium: Action needed within a defined timeframe; moderate risk
- Low: Improvement opportunity; minimal immediate risk
Communicating with Different Audiences
Board and Audit Committee
When presenting to the board, focus on strategic implications, overall risk posture, and trends across audit engagements. Use clear, non-technical language and visual summaries. Board members need to understand the business impact, not the technical details.
Senior Management
Senior management requires more detail than the board but still needs findings framed in business terms. Emphasize the risk exposure, resource requirements for remediation, and alignment with organizational objectives.
IT Management
IT management needs technical detail sufficient to understand and address the findings. Include specific system names, control references, and technical recommendations.
Best Practices for Audit Communication
- Present findings factually, without bias or exaggeration
- Ensure findings are supported by sufficient, relevant evidence
- Discuss findings with management before finalizing the report to ensure accuracy
- Include positive observations alongside findings to provide a balanced view
- Set realistic timelines for remediation actions
CISA Exam Tips
The CISA exam tests your understanding of reporting protocols. Remember that material findings should always be reported to the audit committee, even if management disagrees. The auditor's report should be objective, and the auditor should not allow management pressure to suppress or alter significant findings.
Also note that exit interviews with management should occur before the final report is issued, giving management an opportunity to respond and correct any factual errors.