CORAA
Resources · Internal Audit Governance

Internal audit Audit Committee reporting pack.

A quarterly internal audit Audit Committee pack should be a governance decision file, not a slide dump. It should show what internal audit completed, what changed, which high-risk issues need challenge, which actions are overdue, where scope was limited, and what the committee must decide before the next meeting.

Open dashboard KPIsOpen annual report pack
Downloads

Quarterly committee pack workbook

Download the Excel/PDF pack for the meeting agenda, pre-read index, decision register, high observations, ATR ageing, limitations, private-session notes, minutes and product workflow fields.

Definition

What this pack is for committee

An internal audit Audit Committee pack is the periodic reporting file that turns fieldwork, dashboards and action tracking into committee decisions. It should connect internal audit’s approved mandate, annual plan, current risk assessment, significant observations, management action status and scope limitations into a single meeting-ready record.

Pack contents

What the committee pack should include include

Pre-read index

List every paper, dashboard, report, plan change, limitation note and decision item sent before the meeting.

CAE / internal auditor update

Summarise plan status, high-risk work completed, major delays, fieldwork blockers, resourcing constraints and emerging risks.

High observations and repeat themes

Show only matters requiring committee attention: high findings, repeat root causes, management disagreement and overdue closure.

ATR ageing summary

Age open management actions by owner, original due date, revised due date, closure evidence status and escalation level.

Plan changes and scope limitations

Separate approved deferrals, proposed additions, evidence restrictions, unavailable reports and management-imposed limitations.

Decisions required

State exactly what the committee must approve, note, challenge, escalate or send back to management.

Private session notes

Record independence, access, interference, sensitive investigations and resourcing concerns discussed without operating management where appropriate.

Minutes and action log

Convert committee discussion into owner, due date, evidence, next-meeting status and closure criteria.

Agenda

Quarterly meeting agenda decisions

Confirm previous minutes

Open actions from the prior committee meeting and evidence of closure.

Approve agenda and pre-read

Confirm whether members received papers early enough and whether late papers need deferral.

Review plan progress

Completed reviews, in-progress work, slippage, added reviews, deferred reviews and capacity impact.

Discuss high-risk observations

High issues, repeat findings, disputed ratings, fraud indicators, control override and material compliance exposure.

Review ATR ageing

Overdue actions, revised dates, weak closure evidence, repeat owners and accepted-risk items.

Approve plan or scope changes

Changes to annual plan, risk coverage, specialist support, co-source support or timing.

Private session

Independence, access, resourcing, sensitive matters and restrictions on internal audit work.

Close with decisions

Decision owner, due date, report-out path and next committee follow-up.

Decision register

Decisions the pack should make explicit approve

Plan change approval

Add, defer, accelerate or cancel a review because risk, capacity or business change has moved.

Management action escalation

Require executive ownership, revised due date, stronger evidence or committee-level follow-up for overdue actions.

Scope limitation response

Accept alternate procedures, require evidence access, expand testing or disclose limitation in reporting.

Specialist / co-source support

Approve outside expertise for cyber, AI governance, process mining, data analytics, treasury or sector-specific work.

Risk acceptance challenge

Challenge management when residual risk is accepted without authority, evidence or compensating controls.

Special review request

Ask internal audit to perform an unplanned review because of incidents, complaints, regulatory movement or monitoring exceptions.

Private session

Keep independence matters visible independence

The private-session section should not become theatre. Use it for topics that cannot be handled safely in a management-heavy meeting: denied evidence, restricted access, pressure to change ratings, sensitive investigations, unresolved fraud indicators, resourcing constraints and concerns about the independence or authority of internal audit.

Red flags

Where committee packs fail watch

The pack is a status deck only

Committee members see audit completion percentages but not the decisions or escalations they must act on.

High findings are buried in appendices

Significant issues lose urgency and overdue owners avoid visible challenge.

No source for dashboard numbers

Plan status, issue ageing and monitoring exceptions cannot be reconciled to internal audit workpapers.

No limitation register

Evidence restrictions and unavailable system reports disappear before annual assurance reporting.

Private session is skipped by default

Independence, interference and sensitive matters may never reach the committee chair directly.

Minutes do not capture decisions

The same overdue actions return every quarter with no owner, due date or closure evidence standard.

Authority anchors

Use standards without overclaiming law anchored

Companies Act, 2013 — Section 138

Use Section 138 as the statutory anchor for companies required to appoint an internal auditor, but do not overstate it as prescribing a universal quarterly pack format.

Companies (Accounts) Rules, 2014 — Rule 13

Rule 13 connects internal audit scope, functioning, periodicity and methodology with the Audit Committee or Board. That makes plan changes, coverage, limitations and methodology suitable committee-pack subjects.

ICAI Standards on Internal Audit

SIA 250 covers communication with the Board and Audit Committee, SIA 360 covers communication with management, SIA 370 covers reporting results and SIA 390 covers monitoring and reporting prior audit issues.

IIA Global Internal Audit Standards

Use the IIA standards as a governance benchmark for board communication, independence, final communications, action-plan monitoring and communicating accepted risk.

Listed entities

For listed Indian companies, align the committee pack with applicable SEBI LODR audit committee responsibilities and the entity charter. Verify the current listing obligations before finalising board papers.

Product reuse

Reusable product fields workflow

The website download and the product build stay separate, but this format can become the specification for a future CORAA committee-pack workflow: paper index, decision routing, limitation escalation, private-session permissions and ATR follow-up.

ArtifactModuleLikely fields
Committee pack builderBoard reportingMeeting date, period, paper index, dashboard snapshot, pack owner, reviewer approval, version history.
Decision registerGovernance workflowDecision type, approver, owner, due date, source paper, status, next committee date.
ATR escalation modelObservation and ATR workflowIssue rating, owner, original due date, revised due date, ageing, closure evidence, escalation level.
Limitation registerEvidence workflowBlocked source, alternate procedure, assurance impact, management owner, committee direction.
Private session controlPermissions and minutesAttendees, sensitive topic tag, access level, restricted notes, follow-up owner.
Related resources

Connect the committee pack to the rest of IA next

Internal Audit Dashboard KPIs

Use KPI definitions for the committee dashboard portion of the pack.

Annual Report & Assurance Opinion

Roll quarterly issues, limitations and ATR ageing into annual reporting.

Dynamic Risk Assessment & Plan Refresh

Use the plan-change log when risk moves during the year.

Three Lines Assurance Map

Show reliance, duplication and coverage gaps before committee decisions.

Root Cause & Remediation Plan

Strengthen management action quality before committee escalation.

Internal Audit Dashboard Pack Generator

Generate the dashboard export that feeds the committee pack.

FAQ

Common questions answers

What is an internal audit Audit Committee reporting pack?

An internal audit Audit Committee reporting pack is the periodic set of papers used to brief the committee on internal audit plan progress, significant observations, overdue management actions, scope limitations, risk changes and decisions required from the committee.

What should be included in a quarterly internal audit committee pack?

Include a pre-read index, plan status dashboard, high-risk observations, ATR ageing, plan-change requests, evidence blockers, scope limitations, emerging risks, decisions required, private-session topics and a minutes/action tracker.

Is a private session with internal audit mandatory?

A private session is a strong governance practice and is expected in many mature internal audit charters, but requirements depend on the entity, listing obligations and committee charter. Treat it as a recommended independence safeguard unless a specific rule applies.

How is this different from an annual internal audit report?

The quarterly pack supports live governance decisions during the year. The annual report rolls up full-year coverage, assurance basis, unresolved risk, limitations and next-year planning.

Build the next artifact

Pair this with the dashboard pack dashboard

The committee pack is strongest when it is fed by the same dashboard metrics, issue ratings, ATR evidence and plan-change log used by the internal audit team.

Generate dashboard packBack to IA resources