Internal Audit Report Format in India: Word Template, Observations and ATR
An internal audit report should tell management and the Audit Committee what was reviewed, what evidence was tested, which risks remain open, what action is required and who owns closure. A useful report is not a dump of checklist points. It is a decision document backed by workpapers.
For Indian companies, the report should also fit the Section 138 and Rule 13 frame: the Board or Audit Committee determines the scope, functioning, periodicity and methodology of internal audit in consultation with the internal auditor. That means the report should clearly connect back to the approved scope, period, process cycle, locations and limitations.
If you are looking for a usable file, start here:
| Need | Use this |
|---|---|
| Editable Word-style report format | Internal audit report template |
| Excel/PDF report pack with observation register and ATR | Internal Audit Report Pack |
| Draft observation register and committee summary | Internal Audit Observation Report Generator |
| Track closure after report issue | Internal Audit ATR Tracker |
The open article below explains the structure. The working files are separate because auditors usually need to edit, route, review and retain the report outside the web page.
Recommended internal audit report format
| Section | What it should contain | Why it matters |
|---|---|---|
| Cover page | Company, process, period, report date, internal auditor, distribution list | Prevents confusion when reports are shared across locations and quarters |
| Executive summary | Overall conclusion, high-risk themes, top observations, management attention areas | Gives directors and senior management the decision view |
| Scope and objectives | Entity, location, cycle, period, exclusions and audit objectives | Shows what the report covers and what it does not cover |
| Methodology | Walkthroughs, RCM testing, sampling, analytics, interviews and documents reviewed | Links findings to the work actually performed |
| Rating summary | High, Medium, Low observations with repeat issue count and overdue ATR status | Helps prioritise action |
| Detailed observations | Condition, criteria, cause, effect, recommendation, rating, owner and due date | Makes every finding actionable and reviewable |
| Management response | Agreed action, action owner, target date and accepted-risk decision if any | Prevents audit reports from becoming one-way memos |
| Action Taken Report | Status of previous observations, closure evidence and retest result | Connects reporting with follow-up |
| Limitations | Data unavailable, scope exclusions, pending evidence, management restrictions | Protects report quality and avoids implied assurance |
| Appendices | RCM, sample list, analytics rules, data request list, evidence index | Keeps the main report readable while preserving support |
The right length depends on the audience. A process owner can handle more procedural detail. An Audit Committee pack needs sharper themes, ageing, repeat risks and management accountability.
Executive summary format
The executive summary should answer five questions in plain language:
- What was audited?
- Why was it audited?
- What level of assurance or insight can be taken from the work?
- Which risks need management attention?
- What decisions, escalations or resources are required?
A practical summary can use this structure:
| Heading | Example content |
|---|---|
| Scope reviewed | Procure-to-pay controls for April to June 2026 across Mumbai and Pune locations |
| Work performed | Vendor master review, PO approval testing, GRN-invoice match, duplicate payment analytics and MSME ageing |
| Overall conclusion | Controls are partly effective, but vendor master and MSME monitoring need immediate strengthening |
| High-risk issues | Vendor bank changes before payment, non-PO invoices above policy threshold, MSME ageing not monitored |
| Management action | CFO to implement bank-change confirmation workflow by 30 September 2026 |
Avoid vague executive summaries such as "internal controls need improvement". Name the cycle, risk, exposure and action.
Observation format: condition, criteria, cause, effect and recommendation
Every reportable observation should stand on its own. The reviewer should be able to read one observation and understand the issue without opening five workpapers.
| Field | Question answered |
|---|---|
| Condition | What did internal audit find? |
| Criteria | What policy, law, control, delegation matrix or agreed standard was not met? |
| Cause | Why did the exception happen? |
| Effect | What risk or consequence can result? |
| Recommendation | What should management change? |
| Rating | How serious is the issue after considering impact, likelihood and compensating controls? |
| Owner and due date | Who will fix it and by when? |
| Evidence reference | Which workpaper, sample, data extract or screenshot supports the finding? |
Example observation
Condition: Internal audit noted 18 vendor bank account changes during Q1. Six vendors were paid within seven days of the change. Three cases did not have independent callback evidence.
Criteria: The vendor master policy requires independent confirmation and maker-checker approval before payment to a changed bank account.
Cause: ERP workflow allows bank master change and payment approval to proceed independently. Finance does not receive an automatic alert when a beneficiary change is made.
Effect: Payment diversion or vendor master manipulation may go undetected before funds leave the bank account.
Recommendation: Configure a payment hold for five working days after a vendor bank change unless the Finance Controller approves an exception. Route all same-week payments after bank change to monthly internal-audit review.
Management response: Finance will implement an exception approval workflow and monthly bank-change report by 30 September 2026.
Rating matrix for internal audit observations
Ratings should not be based only on rupee value. A low-value issue can still be High if it indicates fraud, regulatory exposure, repeated control override or a design gap in a critical process.
| Rating | Practical trigger |
|---|---|
| High | Fraud indicator, regulatory breach, significant financial exposure, repeated issue, management override or weak compensating controls |
| Medium | Control failure with moderate exposure, repeated process weakness, delayed remediation or limited compensating evidence |
| Low | Isolated exception, documentation gap or improvement area with low exposure and available compensating control |
Where management disagrees, record the disagreement and the basis. Do not silently downgrade a finding because the action owner is senior or the issue is uncomfortable.
Action Taken Report format
An ATR is more than a status list. It should show whether the risk has actually reduced.
| ATR field | What to capture |
|---|---|
| Observation reference | Original report, quarter, process and issue number |
| Agreed action | The exact management action committed |
| Original due date | Date agreed in the report |
| Revised due date | Date approved after extension, if any |
| Status | Open, in progress, implemented, partly implemented, overdue, closed after retest |
| Closure evidence | Policy, system configuration, approval trail, report, reconciliation or sample retest |
| Retest result | What internal audit checked after implementation |
| Repeat issue flag | Whether the same issue came back |
| Escalation | Whether Audit Committee visibility is needed |
The key test is simple: if the ATR says "closed", can the reviewer see evidence and retest conclusion? If not, it is not closed. It is only management-reported.
Audit committee reporting pack
The Audit Committee does not need every sample exception. It needs risk movement, unresolved exposure, management accountability and limitations.
Include:
- Plan progress against approved internal audit plan
- High and repeat observations by cycle
- Overdue management actions and ageing
- Scope limitations and data-access issues
- Significant control themes across locations
- Accepted risks and compensating controls
- Emerging risks such as cyber, AI governance, third-party dependence and compliance volatility
- Private session points, if the committee uses that practice
For dashboards, show exposure, coverage and direction. A red tile by itself is not assurance. The packet should explain what population was reviewed, how many exceptions were found, which exceptions remain unresolved and whether the trend is improving.
Where AI and analytics fit in the report
AI can help draft observation wording, cluster exceptions, summarise management responses and prepare stakeholder summaries. It should not silently assign the final rating or conclude whether a control operated effectively.
If analytics or AI were used, document:
- Source data and extraction date
- Population count and filters applied
- Rule logic or prompt objective
- Exception count before and after false-positive review
- Reviewer conclusion
- Workpaper reference
- Human approval of final wording
This matters more in 2026 because internal audit teams are using AI widely, but strategy and governance are lagging. Gartner reported on 11 August 2026 that 93% of audit leaders use some AI, but only 38% have an AI strategy. That gap should make internal auditors more disciplined about documentation, not less.
Common report mistakes
| Mistake | Better approach |
|---|---|
| Reporting every exception as an observation | Aggregate exceptions into root-cause themes and report only what needs action |
| Writing "management should strengthen controls" | State the exact control change, owner and due date |
| No criteria | Link every finding to policy, delegation matrix, law, contract, SOW or control objective |
| No evidence reference | Cross-reference sample, extract, screenshot, report or workpaper |
| Closing ATR based only on management email | Retest the implemented action and retain closure evidence |
| Hiding limitations | Report unavailable data, excluded locations and pending evidence clearly |
Internal audit report FAQ
What should an internal audit report include?
An internal audit report should include executive summary, scope, objectives, methodology, observation summary, detailed findings, risk ratings, management responses, action owners, due dates, ATR status, limitations and supporting appendices.
Can I download an internal audit report format in Word?
Yes. Use the internal audit report template for an editable report format. Use the report pack when you also need Excel/PDF observation registers, rating rationale, management response fields and ATR tracking.
Is there a fixed internal audit report format under the Companies Act?
No single report layout is prescribed. Section 138 and Rule 13 require internal audit for prescribed companies and require the Board or Audit Committee to determine scope, functioning, periodicity and methodology. The report format should support that approved scope and the applicable Standards on Internal Audit.
What is the best observation format for internal audit?
Use condition, criteria, cause, effect, recommendation, rating, management response, owner, due date and evidence reference. This format is easier for reviewers, management and Audit Committees to act on.
What is the difference between an internal audit report and an ATR?
The internal audit report communicates findings from a completed review. The ATR tracks management action after the report: status, due date, closure evidence, retest result and escalation for overdue or repeated issues.
Can internal audit reports be generated with AI?
AI can prepare drafts from reviewed exceptions, source data and auditor notes. The final report should still be approved by the internal auditor, supported by retained evidence and reviewed for accuracy, confidentiality and professional judgement.
What is the difference between a report template and a report pack?
A report template gives the narrative structure: executive summary, scope, methodology, observations, management response and conclusion. A report pack adds working registers: observation list, rating basis, ATR status, closure evidence, repeat-finding flag and audit committee summary.
Related CORAA resources
- Internal audit report template in Word
- Internal Audit Report Pack
- Internal Audit Observation Report Generator
- Internal Audit ATR Tracker
- Internal Audit Quality Review Checklist
- Internal Audit Dashboard KPIs