CORAA
Resources · Internal Audit Reporting

Internal audit annual report opinion.

The annual internal audit report should not be a list of reviews completed. It should tell the Audit Committee or Board what assurance can be taken from the year’s work, what risk remains unresolved, where scope was limited, and what must change in next year’s plan.

Open dashboard KPIsBuild next plan
Downloads

Annual report workbook pack

Download the Excel/PDF pack for plan coverage, assurance basis, issue ageing, scope limitations and committee decisions.

Annual report structure

What the annual report should normally cover cover

Section 138 and Rule 13 do not prescribe a universal annual assurance-opinion pack for every Indian company. Treat this as a recommended structure: the final conclusion depends on the approved mandate, reporting expectations, criteria, scope, evidence access and workpaper review.

Mandate and plan coverage

Approved charter, annual plan, audits completed, audits deferred, scope changes and management-approved exclusions.

Risk coverage

High-risk areas covered, emerging risks not covered, monitoring coverage, ITGC dependency and sector-specific cycle coverage.

Overall conclusion

A clear annual view of whether governance, risk management and internal controls are effective, partially effective or need significant improvement.

Issue themes

Repeat observations, high-rated findings, root-cause themes, control design gaps, overdue management actions and accepted risks.

Scope limitations

Denied evidence, delayed data, unavailable system logs, management restrictions and alternate procedures performed.

Reliance basis

Workpaper quality, sampling basis, analytics use, management representation, external specialist reliance and quality review status.

Forward plan

Next-year audit universe changes, monitoring candidates, talent/capacity needs, co-sourcing, data readiness and AI governance priorities.

Opinion language

Use an opinion only when the basis is defensible basis

Effective

Most planned high-risk areas were covered; high issues are isolated or remediated; evidence supports reliance on the control environment.

Generally effective with improvements needed

Controls are operating in several areas, but repeat themes, overdue actions or design gaps require management attention.

Partially effective

Multiple high-risk cycles have material control gaps, unresolved observations, monitoring exceptions or insufficient evidence.

Needs significant improvement

The internal audit file indicates pervasive control weaknesses, major scope limitations, repeat failures or unacceptable residual risk.

No overall opinion

Use only when mandate, scope, evidence quality or plan coverage is insufficient to support an annual conclusion. Explain why clearly.

Audit Committee pack

What the committee actually needs needs

One-page annual opinion

Overall conclusion, basis, caveats and the top five management actions.

Plan delivery dashboard

Approved vs completed reviews, deferred audits, cycle coverage, hours used and quarter slippage.

High-risk issue register

Open high observations, root causes, owners, due dates, ageing and repeat-finding status.

Scope limitation register

Evidence blockers, unavailable reports, management restrictions, alternate procedures and impact on assurance.

Residual risk view

Accepted risks, overdue actions, recurring exceptions, monitoring failures and emerging areas for next year.

Next-year coverage proposal

Audit universe refresh, monitoring rules, specialist reviews, AI governance and resource plan.

Red flags

Weak annual reporting patterns avoid

Annual report only lists audits performed

The committee cannot see risk coverage, deferred areas, unresolved high issues or assurance limitations.

Opinion ignores scope limitations

A positive conclusion can be misleading if evidence access, ERP logs or key locations were unavailable.

No ageing view for open actions

Management action plans look controlled even when overdue items are repeatedly extended.

No link to approved plan

Internal audit activity becomes a list of assignments rather than coverage against an approved risk universe.

No basis for overall conclusion

Readers cannot see whether the opinion is grounded in evidence, workpaper quality, samples and review status.

No forward-looking section

The next annual plan misses repeated root causes, new systems, outsourced processes and emerging risks.

Authority anchors

Sources to verify before issuing cite

ICAI SIA 220, 250, 360, 370 and 390

Use ICAI internal audit standards for planning, Audit Committee/Board communication, management communication, reporting results and monitoring/reporting prior audit issues.

IIA Global Internal Audit Standards

Useful benchmark for board communication, final engagement communication, monitoring action plans and communicating accepted risk.

Companies Act, 2013 — Section 138

Anchor the annual report to the company internal audit mandate and the class of company for which internal audit is required.

Companies (Accounts) Rules, 2014 — Rule 13

Rule 13 connects internal audit scope, functioning, periodicity and methodology with the Audit Committee/Board and internal auditor.

Product reuse

Website resource now, product dashboard later later

This is a public website resource. The reusable layer for the separate Internal Audit product build is the annual opinion model, coverage reconciliation, scope-limitation tracker, action-ageing logic and next-year planning feed.

Annual opinion builder

Committee reporting: Opinion level, basis, limitation flags, confidence score, reviewer approval, issue themes.

Coverage reconciliation

Audit universe dashboard: Planned reviews, completed reviews, deferred reviews, risk rating, reason for deferral, next coverage date.

Action ageing model

ATR workflow: High issues, repeat findings, owner ageing, revised due dates, closure evidence, accepted risk flag.

Scope limitation tracker

Evidence workflow: Blocked reports, missing logs, unavailable population, alternate procedure, effect on assurance.

Next-year planning feed

Annual plan builder: Residual risk, monitoring candidates, specialist needs, data-readiness gaps, committee direction.

Related resources

Move from annual report to next plan next

Internal Audit Charter & Mandate

Confirm the mandate and reporting line before annual reporting.

Internal Audit Dashboard KPIs

Use dashboard definitions for plan progress, high issues and ATR ageing.

Internal Audit Root Cause & Remediation Plan

Convert issue themes into strong action plans and closure evidence.

Internal Audit Report Pack

Use engagement-report formats before rolling them into the annual report.

Internal Audit Maturity Assessment

Turn annual-report weaknesses into a QAIP roadmap.

Internal Audit Annual Plan Generator

Feed deferred coverage and residual risk into next year planning.

FAQs

Annual report questions answered

What is an internal audit annual report?

An internal audit annual report summarises the internal audit function mandate, approved-plan delivery, risk coverage, significant observations, management action status, limitations, overall conclusion and next-year focus areas for the Audit Committee or Board.

Should internal audit issue an annual assurance opinion?

Internal audit can issue an overall annual conclusion only when plan coverage, evidence quality, scope access, workpaper review and issue follow-up are strong enough to support it. If the basis is weak, the report should say so instead of giving a clean opinion.

What should be reported to the Audit Committee annually?

Report approved-plan completion, high-risk coverage, deferred areas, significant and repeat observations, overdue actions, accepted risks, scope limitations, resource constraints, quality review results and recommended changes for the next annual plan.

How is this different from an engagement report?

An engagement report covers one review or cycle. The annual report rolls up the full-year internal audit plan, unresolved risk, action ageing, assurance basis and future coverage decisions.