CORAA
Blog/Internal Audit

Internal Audit Report Format in India: Word Template, Observations and ATR

A practical internal audit report format for Indian companies: Word template route, Excel/PDF report pack, executive summary, scope, methodology, observation structure, rating matrix, management response, ATR and audit committee reporting.

CCORAA Team31 August 202613 min read

Internal Audit Report Format in India: Word Template, Observations and ATR

An internal audit report should tell management and the Audit Committee what was reviewed, what evidence was tested, which risks remain open, what action is required and who owns closure. A useful report is not a dump of checklist points. It is a decision document backed by workpapers.

For Indian companies, the report should also fit the Section 138 and Rule 13 frame: the Board or Audit Committee determines the scope, functioning, periodicity and methodology of internal audit in consultation with the internal auditor. That means the report should clearly connect back to the approved scope, period, process cycle, locations and limitations.

If you are looking for a usable file, start here:

Need Use this
Editable Word-style report format Internal audit report template
Excel/PDF report pack with observation register and ATR Internal Audit Report Pack
Draft observation register and committee summary Internal Audit Observation Report Generator
Track closure after report issue Internal Audit ATR Tracker

The open article below explains the structure. The working files are separate because auditors usually need to edit, route, review and retain the report outside the web page.

Section What it should contain Why it matters
Cover page Company, process, period, report date, internal auditor, distribution list Prevents confusion when reports are shared across locations and quarters
Executive summary Overall conclusion, high-risk themes, top observations, management attention areas Gives directors and senior management the decision view
Scope and objectives Entity, location, cycle, period, exclusions and audit objectives Shows what the report covers and what it does not cover
Methodology Walkthroughs, RCM testing, sampling, analytics, interviews and documents reviewed Links findings to the work actually performed
Rating summary High, Medium, Low observations with repeat issue count and overdue ATR status Helps prioritise action
Detailed observations Condition, criteria, cause, effect, recommendation, rating, owner and due date Makes every finding actionable and reviewable
Management response Agreed action, action owner, target date and accepted-risk decision if any Prevents audit reports from becoming one-way memos
Action Taken Report Status of previous observations, closure evidence and retest result Connects reporting with follow-up
Limitations Data unavailable, scope exclusions, pending evidence, management restrictions Protects report quality and avoids implied assurance
Appendices RCM, sample list, analytics rules, data request list, evidence index Keeps the main report readable while preserving support

The right length depends on the audience. A process owner can handle more procedural detail. An Audit Committee pack needs sharper themes, ageing, repeat risks and management accountability.

Executive summary format

The executive summary should answer five questions in plain language:

  1. What was audited?
  2. Why was it audited?
  3. What level of assurance or insight can be taken from the work?
  4. Which risks need management attention?
  5. What decisions, escalations or resources are required?

A practical summary can use this structure:

Heading Example content
Scope reviewed Procure-to-pay controls for April to June 2026 across Mumbai and Pune locations
Work performed Vendor master review, PO approval testing, GRN-invoice match, duplicate payment analytics and MSME ageing
Overall conclusion Controls are partly effective, but vendor master and MSME monitoring need immediate strengthening
High-risk issues Vendor bank changes before payment, non-PO invoices above policy threshold, MSME ageing not monitored
Management action CFO to implement bank-change confirmation workflow by 30 September 2026

Avoid vague executive summaries such as "internal controls need improvement". Name the cycle, risk, exposure and action.

Observation format: condition, criteria, cause, effect and recommendation

Every reportable observation should stand on its own. The reviewer should be able to read one observation and understand the issue without opening five workpapers.

Field Question answered
Condition What did internal audit find?
Criteria What policy, law, control, delegation matrix or agreed standard was not met?
Cause Why did the exception happen?
Effect What risk or consequence can result?
Recommendation What should management change?
Rating How serious is the issue after considering impact, likelihood and compensating controls?
Owner and due date Who will fix it and by when?
Evidence reference Which workpaper, sample, data extract or screenshot supports the finding?

Example observation

Condition: Internal audit noted 18 vendor bank account changes during Q1. Six vendors were paid within seven days of the change. Three cases did not have independent callback evidence.

Criteria: The vendor master policy requires independent confirmation and maker-checker approval before payment to a changed bank account.

Cause: ERP workflow allows bank master change and payment approval to proceed independently. Finance does not receive an automatic alert when a beneficiary change is made.

Effect: Payment diversion or vendor master manipulation may go undetected before funds leave the bank account.

Recommendation: Configure a payment hold for five working days after a vendor bank change unless the Finance Controller approves an exception. Route all same-week payments after bank change to monthly internal-audit review.

Management response: Finance will implement an exception approval workflow and monthly bank-change report by 30 September 2026.

Rating matrix for internal audit observations

Ratings should not be based only on rupee value. A low-value issue can still be High if it indicates fraud, regulatory exposure, repeated control override or a design gap in a critical process.

Rating Practical trigger
High Fraud indicator, regulatory breach, significant financial exposure, repeated issue, management override or weak compensating controls
Medium Control failure with moderate exposure, repeated process weakness, delayed remediation or limited compensating evidence
Low Isolated exception, documentation gap or improvement area with low exposure and available compensating control

Where management disagrees, record the disagreement and the basis. Do not silently downgrade a finding because the action owner is senior or the issue is uncomfortable.

Action Taken Report format

An ATR is more than a status list. It should show whether the risk has actually reduced.

ATR field What to capture
Observation reference Original report, quarter, process and issue number
Agreed action The exact management action committed
Original due date Date agreed in the report
Revised due date Date approved after extension, if any
Status Open, in progress, implemented, partly implemented, overdue, closed after retest
Closure evidence Policy, system configuration, approval trail, report, reconciliation or sample retest
Retest result What internal audit checked after implementation
Repeat issue flag Whether the same issue came back
Escalation Whether Audit Committee visibility is needed

The key test is simple: if the ATR says "closed", can the reviewer see evidence and retest conclusion? If not, it is not closed. It is only management-reported.

Audit committee reporting pack

The Audit Committee does not need every sample exception. It needs risk movement, unresolved exposure, management accountability and limitations.

Include:

  • Plan progress against approved internal audit plan
  • High and repeat observations by cycle
  • Overdue management actions and ageing
  • Scope limitations and data-access issues
  • Significant control themes across locations
  • Accepted risks and compensating controls
  • Emerging risks such as cyber, AI governance, third-party dependence and compliance volatility
  • Private session points, if the committee uses that practice

For dashboards, show exposure, coverage and direction. A red tile by itself is not assurance. The packet should explain what population was reviewed, how many exceptions were found, which exceptions remain unresolved and whether the trend is improving.

Where AI and analytics fit in the report

AI can help draft observation wording, cluster exceptions, summarise management responses and prepare stakeholder summaries. It should not silently assign the final rating or conclude whether a control operated effectively.

If analytics or AI were used, document:

  • Source data and extraction date
  • Population count and filters applied
  • Rule logic or prompt objective
  • Exception count before and after false-positive review
  • Reviewer conclusion
  • Workpaper reference
  • Human approval of final wording

This matters more in 2026 because internal audit teams are using AI widely, but strategy and governance are lagging. Gartner reported on 11 August 2026 that 93% of audit leaders use some AI, but only 38% have an AI strategy. That gap should make internal auditors more disciplined about documentation, not less.

Common report mistakes

Mistake Better approach
Reporting every exception as an observation Aggregate exceptions into root-cause themes and report only what needs action
Writing "management should strengthen controls" State the exact control change, owner and due date
No criteria Link every finding to policy, delegation matrix, law, contract, SOW or control objective
No evidence reference Cross-reference sample, extract, screenshot, report or workpaper
Closing ATR based only on management email Retest the implemented action and retain closure evidence
Hiding limitations Report unavailable data, excluded locations and pending evidence clearly

Internal audit report FAQ

What should an internal audit report include?

An internal audit report should include executive summary, scope, objectives, methodology, observation summary, detailed findings, risk ratings, management responses, action owners, due dates, ATR status, limitations and supporting appendices.

Can I download an internal audit report format in Word?

Yes. Use the internal audit report template for an editable report format. Use the report pack when you also need Excel/PDF observation registers, rating rationale, management response fields and ATR tracking.

Is there a fixed internal audit report format under the Companies Act?

No single report layout is prescribed. Section 138 and Rule 13 require internal audit for prescribed companies and require the Board or Audit Committee to determine scope, functioning, periodicity and methodology. The report format should support that approved scope and the applicable Standards on Internal Audit.

What is the best observation format for internal audit?

Use condition, criteria, cause, effect, recommendation, rating, management response, owner, due date and evidence reference. This format is easier for reviewers, management and Audit Committees to act on.

What is the difference between an internal audit report and an ATR?

The internal audit report communicates findings from a completed review. The ATR tracks management action after the report: status, due date, closure evidence, retest result and escalation for overdue or repeated issues.

Can internal audit reports be generated with AI?

AI can prepare drafts from reviewed exceptions, source data and auditor notes. The final report should still be approved by the internal auditor, supported by retained evidence and reviewed for accuracy, confidentiality and professional judgement.

What is the difference between a report template and a report pack?

A report template gives the narrative structure: executive summary, scope, methodology, observations, management response and conclusion. A report pack adds working registers: observation list, rating basis, ATR status, closure evidence, repeat-finding flag and audit committee summary.

Sources

Topics
internal audit report formatinternal audit report format Indiainternal audit report format icai word formatinternal audit report template Wordinternal audit observation formataudit committee report internal auditATR tracker internal audit
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free