is-auditing10 min read

Communicating Audit Results to Management and Board

Learn best practices for presenting IS audit findings to management and the board, including report structure and communication strategies for the CISA exam.

CISAPractice|

Effective communication of audit results is one of the most important skills for an IS auditor. The value of an audit engagement depends not only on the quality of testing and analysis but also on how clearly and persuasively findings are communicated to stakeholders. CISA candidates should understand the principles, formats, and challenges of audit reporting.

The Audit Report Structure

A well-structured IS audit report typically includes the following sections:

  • Executive summary: A high-level overview of the audit scope, key findings, and overall conclusions designed for senior management and board members
  • Audit objectives and scope: A description of what was audited, why, and the boundaries of the engagement
  • Methodology: The standards, frameworks, and techniques used during the audit
  • Findings and recommendations: Detailed observations, their risk ratings, root causes, and recommended corrective actions
  • Management responses: The auditee's agreement or disagreement with findings and planned remediation actions
  • Conclusion: The auditor's overall opinion on the adequacy of controls

Structuring Individual Findings

Each audit finding should follow a consistent format that includes:

  • Condition: What the auditor found (the current state)
  • Criteria: What was expected (the standard or requirement)
  • Cause: Why the gap exists (root cause analysis)
  • Effect: The impact or potential impact of the finding
  • Recommendation: Suggested corrective action

Risk Rating Findings

Findings should be rated by risk level to help management prioritize remediation efforts. Common rating scales include:

  • Critical: Immediate action required; significant risk to the organization
  • High: Prompt action needed; material control weakness
  • Medium: Action needed within a defined timeframe; moderate risk
  • Low: Improvement opportunity; minimal immediate risk

Communicating with Different Audiences

Board and Audit Committee

When presenting to the board, focus on strategic implications, overall risk posture, and trends across audit engagements. Use clear, non-technical language and visual summaries. Board members need to understand the business impact, not the technical details.

Senior Management

Senior management requires more detail than the board but still needs findings framed in business terms. Emphasize the risk exposure, resource requirements for remediation, and alignment with organizational objectives.

IT Management

IT management needs technical detail sufficient to understand and address the findings. Include specific system names, control references, and technical recommendations.

Best Practices for Audit Communication

  • Present findings factually, without bias or exaggeration
  • Ensure findings are supported by sufficient, relevant evidence
  • Discuss findings with management before finalizing the report to ensure accuracy
  • Include positive observations alongside findings to provide a balanced view
  • Set realistic timelines for remediation actions

CISA Exam Tips

The CISA exam tests your understanding of reporting protocols. Remember that material findings should always be reported to the audit committee, even if management disagrees. The auditor's report should be objective, and the auditor should not allow management pressure to suppress or alter significant findings.

Also note that exit interviews with management should occur before the final report is issued, giving management an opportunity to respond and correct any factual errors.

Related Tags

IS AuditingAudit ReportingCommunicationAudit Findings

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free