Home > Risk > Death of the Audit Report

Death of the Audit Report

October 18, 2020 Leave a comment Go to comments

I have known my friend Hal Garyn for a long time. He is a gentleman for whom I have great respect and we usually are in full agreement on topics of mutual interest.

But I am only in partial agreement with his recent article, Death of the Audit Report: It’s Time to Reconsider How to Convey Internal Audit Findings.

As usual, I will point to some of his excellent comments:

  • …why do we issue audit reports? Are we required to do so? And are there other options? Does the return on investment outweigh the time spent drafting, editing, reviewing, and issuing traditional internal audit reports? We’ll explore these questions in depth, but the short answer is a resounding “no!”
  • When most internal auditors consider why they issue audit reports, far too many say it is because “the Standards require us to.” Well, that is not true at all. The Institute of Internal Auditors’ Standards for the Professional Practice of Internal Auditing states the following regarding reporting the results of internal audit work:

“Internal auditors must communicate the results of engagements.” – IIA Performance Standard 2400.

  • So, if the Standards do not say, “you must issue an audit report,” why do we do it? Another common response to the “why” question, beyond erroneously thinking that we need to, is: “Because that’s the way we have always done it.” If we are unwilling to accept a statement like that as an answer from an audit client, then that cannot be an acceptable answer for why we continue to issue standard audit reports.
  • Jason Mefford, president of Mefford Associates and CEO of cRisk Academy, agrees that it’s time to rethink the traditional audit report and instead focus on the best way to achieve its objectives. ”We all need to rethink how we communicate the results of our audit work,” he says. “The typical long, jargon-laden internal audit report may not be the most effective way to do that any longer. In fact, if you want to find an extra 30 percent of time in your budget, quit wasting time writing reports,” he asserts. In a time when efficiency matters, the audit report process may be long overdue for an overhaul.
  • Remember when our high school writing teachers advised us to begin with the end in mind.
  • The report, in the end, is just a means of communication. Communication only has value if what the author wants to say is completely and accurately understood as intended by the recipient of the communication. The communication is in a form that is most easily digested so it can be acted upon in some way by the recipient, in the manner originally intended.
  • In a recent poll conducted on LinkedIn of internal audit leaders, 22 percent of respondents said the average length of their standard audit report is more than 10 pages, and another 48 percent said the average length their audit reports ran 5 to 10 pages. With these lengths, it is possible that such reports are not easy to read or digest. Some internal auditors will readily admit that they are not written with the reader in mind.
  • Improving our audit reports starts with considering your audience and asking a few simple questions: What information do they need to know?

Hal sets the table well.

The traditional and long audit report needs to be transformed.

It starts, as he says, with understanding:

  1. Who the intended audience is, the recipients of your communication
  2. What they need to know
  3. What the best way is to communicate that information. It has to be in a way that gets their attention, tells them concisely what they need to know, and enables appropriate actions
  4. How to eliminate what is unnecessary so that the necessary stands out and is easily consumed

My first and perhaps most important disagreement with Hal, and it’s a strong disagreement, is around the purpose of the communication.

I disagree with each of these quotes:

  • “The ultimate objective of internal audit reporting is not to describe what we found or to make recommendations for improvement. It should be to persuade readers to take action,” Richard Chambers
  • “The goal is risk mitigation and operations improvement, not reports,” Amanda “Jo” Erven
  • “Communications must include the engagement’s objectives, scope, and results.” – IIA Performance Standard 2410.

He also makes these statements, with which I strongly disagree:

  • What is the best way to sufficiently document the work that was completed? And, most importantly, what is the best way to convey the findings that, when addressed, will make the biggest impact on the organization.
  • Regardless of how we communicate the results of our audit work, each ‘finding’ must cover certain elements that are fundamental to good internal audit reporting. There are great articles and other material covering the details, but be sure that each finding addresses these elements if you want to completely cover the matter at hand: condition, criteria, cause, effect, and, in most cases, a recommendation.

This is a vitally important topic and I cover it in detail, with examples and practical suggestions, in Auditing that Matters.

Let’s go back to the point that this is about communicating, not writing an audit report.

It is vital that we realize that our obligation is to communicate the results of our work and to whom that communication will be.

We need to communicate to increasingly senior levels of management and then to the audit committee of the board.

As I say repeatedly in the book, we need to communicate:

  • what they need to know rather than what we want to say (and there’s a huge difference)
  • when they need to know it (typically at the speed of decision-making)
  • in a way that is actionable, eliminating the unnecessary that makes the communication hard to receive

What do they need to know?

As we say in the Core Principles and the Definition of Internal Auditing, we provide:

  • Assurance
  • Advice, and
  • Insight

If you are seeking assurance from a doctor, auto mechanic, or other specialist, do you want a formal report? Isn’t it better to talk to that expert and listen to what they have to say, with an opportunity to ask questions, perhaps (and only perhaps) supplemented by a written report? Maybe the written report can summarize the communication for later reference or sharing.

If you want advice from a parent, attorney, tax accountant, or other authority, do you limit the communication to a formal report? Again, isn’t a real discussion better for you? Maybe a formal report with detail can help, but it is usually not sufficient by itself and may be unnecessary. I don’t want to pay an attorney to write a formal report that summarizes what he or she has just told me.

The whole point of insight is that it is typically not included in formal reporting. It’s the enormously valuable professional opinion of the auditor that may be hard to prove with solid evidence. For example, I have discussed both individual managers and the structure of the organization with executives.

Similarly, when have you ever tried to persuade somebody to do something by writing a report when you can talk to them?

I could continue with challenging the need to document our work (we have working papers for that) or to include all the details such as scope and objectives, criteria, condition, and so on. Our customers don’t need to see all of that. It’s for our benefit – or for history (and only regulators and historians will care).

So I repeat:

  • Tell them what they need to know, when they need to know, and in a form that is readily actionable.
  • Put in writing only what our customer will want in writing.
  • Communicate, communicate, communicate – but don’t forget to LISTEN!

If you focus on listening and talking to management and the board, with a thoughtful discussion of the situation, not only will your objectives be achieved but you will have credibility with them.

This is not going to be easy for everybody – but it will pay off in spades.

I welcome your thoughts.

  1. October 19, 2020 at 9:41 AM

    ‘The reports of my death are greatly exaggerated’. (The text of a cable sent by Mark Twain from London to the press in the United States after his obituary had been mistakenly published.)
    I don’t think the audit report is dead, but agree with your blog Norman, that is is frequently written for the benefit of the internal audit department not the customers (Audit Committee, directors, managers, etc.). Internal audit can be more concerned about achieving their own objectives, as opposed to reporting on the likelihood of the customers achieving their objectives, which is what I believe (www.internalaudit.biz).
    The advantage of basing the audit around the customers’ objectives is that it promotes discussion between IA and their customers, plus providing the customers with an interest in the findings of the audit.

  2. October 20, 2020 at 12:00 AM

    My experience is that even external auditors report by using presentation tools (like MS powerpoint) these days instead of word processors (like MS word).
    This more or less automatically should lead to two levels of reporting. A summary to inform management and urge them to action when risk is above acceptable levels. A detailed report with the underlying findings (and hopefully the right) advises to mitigate the riks(s).

  3. Scott Tashlik
    October 21, 2020 at 2:00 PM

    I found the article and your thoughts to be thought provoking. Over my 20-year career in internal auditing I’ve developed my vision of philosophy of internal audit predicated on 3 basic principles: collaboration, communication, and cooperation. I’ve prided myself on not being the “typical” auditor and have developed deep and meaningful professional relationships with my internal clients. I’ve been called upon to help with any number of significant projects, asked for my advice, and been brought in on the strategic direction of the organization. I have also questioned the need for the internal audit report. There is so much extra information that most won’t care about. They want the rating and the significant issues identified. The one other item I added to audit reports that management is intrigued with is “client identified concerns”. This provides an opportunity for internal clients to put on the table what they already know is a concern, almost like a control conscious rating. My team and I can spend time evaluating action plans to remediate rather than finding already known problems. I’d love to hear what your suggestions are to replace the audit report, I’m always looking for ways to innovate.

  4. October 25, 2020 at 4:55 AM

    Excellent and thought-provoking. If communication of findings shift to providing answers to “what” and “when” the management wants and reporting actionable items, the audit report becomes much more digestible. It really boils down to prioritizing those concern areas that are pointing towards top-trending risks faced by the auditee’s organization and communicating them on time for actions and decisions. IMO, this will promote the internal audit function from a mere reporting agency to a strategic partner who brings value to the table.

    • Norman Marks
      October 25, 2020 at 6:39 AM


  1. October 18, 2020 at 1:24 PM
  2. October 18, 2020 at 1:27 PM
  3. December 28, 2020 at 10:37 AM

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: