What this is
What is an internal audit report?
What is an internal audit report?
The record of a single audit: who conducted it and on what basis of independence, what was covered and what was not, the method and evidence used, the findings with their grading, and a conclusion about the effectiveness of the area audited against the criteria.
What makes a finding usable?
Objective evidence, the requirement it fails against, and the significance. Without evidence the finding is contestable, without the requirement it is an opinion, and without significance the recipient cannot judge priority against everything else on their list.
Scope
When is an internal audit report required?
This is the report of one audit. The programme and the corrective actions sit separately.
Use this template when
- Reporting a single internal audit against defined criteria
- Recording scope, coverage and any limitations encountered
- Documenting findings with evidence, requirement and significance
- Concluding on the effectiveness of the area or process audited
- Providing the basis for corrective action and for management review input
Do not use it for
- The audit programme, which plans the set of audits and reviews their collective effectiveness
- Corrective action records, which track each finding through to verified closure
- Supplier and second-party audit reports, which have different scope and competence requirements
- Certification and surveillance audit reports, produced by the certification body
- Management review, which consumes audit results in aggregate
Compliance mapping
Which ISO 19011 cl.6 requirements does this satisfy?
Audit conduct is governed by ISO 19011, with the requirement to audit coming from the management system standards.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.6.4 | Collecting and verifying information, with audit evidence based on verifiable information | Method and evidence |
| ISO 19011 cl.6.4.8 | Generating audit findings, evaluating evidence against criteria and recording conformity and nonconformity | Findings |
| ISO 19011 cl.6.4.9 | Determining audit conclusions covering the extent of conformity and effectiveness | Conclusion |
| ISO 19011 cl.6.5 | Audit report content including scope, criteria, findings, conclusions and any scope limitations | Coverage |
| ISO 19011 cl.5.5.4 | Audit team selected for competence to achieve the audit objectives | Team and independence |
| ISO 9001 cl.9.2.2 | Auditors selected to ensure objectivity and impartiality; not auditing their own work | Team and independence |
| ISO 45001 cl.9.2.2 | Results reported to relevant managers, workers and worker representatives | Conclusion |
| ISO 45001 cl.10.2 | Corrective action arising from nonconformity, including determining causes | Findings |
What it does not cover
- The audit programme, planning the set of audits and reviewing their collective effectiveness.
- Corrective action records, tracking findings through cause analysis to verified closure.
- Second-party supplier audit reports, with different scope and competence requirements.
- Certification body reports, produced independently against a scheme.
- Management review, which consumes audit results in aggregate.
How to complete it
How to complete an internal audit report, step by step
Write findings that can be acted on, state what you did not see, and conclude on effectiveness.
What was observed, specifically enough that another person could verify it. Which requirement it fails, cited to the clause or procedure. Why it matters, which is what lets the recipient rank it against everything else competing for their attention. Findings missing the third element get deprioritised regardless of severity.
What was audited, what was sampled, what could not be examined and why. An area unavailable, a shift not visited, a person on leave, a system inaccessible. Scope limitations are explicitly part of the report under ISO 19011 and they let the reader judge how much weight the conclusion carries.
How many records, which period, who was interviewed, what was observed directly. A conclusion drawn from a walk and two conversations is different from one drawn from thirty records and eight interviews, and the report should make clear which it is.
The conclusion should say whether the area audited is achieving what the system intends, drawing on the findings rather than listing them. Three findings can indicate a well-run area with specific gaps or a system that is not working, and only a conclusion distinguishes them.
What auditors find
Most common internal audit report findings
Report findings concentrate on whether the report is usable.
| Finding | Clause | What fixes it |
|---|---|---|
| Findings state conclusions without objective evidence. | ISO 19011 cl.6.4 | Record what was seen, specifically enough to be verified independently. |
| Requirement not cited, so the finding reads as an opinion. | ISO 19011 cl.6.4.8 | Cite the clause or procedure the evidence fails against. |
| Significance not stated, so recipients cannot prioritise. | ISO 19011 cl.6.5 | Explain why it matters; findings without significance get deprioritised. |
| Scope limitations not recorded. | ISO 19011 cl.6.5 | State what could not be examined; it changes the weight of the conclusion. |
| Sample size and method not described. | ISO 19011 cl.6.4 | Record how much was examined; conclusions depend on it. |
| Grading applied inconsistently between auditors. | ISO 19011 cl.6.4.8 | Publish definitions and calibrate against worked examples. |
| Conclusion summarises the finding count rather than addressing effectiveness. | ISO 19011 cl.6.4.9 | Conclude on whether the area achieves what the system intends. |
| Auditor independence not evidenced. | ISO 9001 cl.9.2.2 | Record the basis of independence; it is the first thing questioned. |
| Results not reported to workers or their representatives. | ISO 45001 cl.9.2.2 | An explicit ISO 45001 requirement frequently omitted. |
| Positive observations absent, making the report purely adversarial. | ISO 19011 cl.6.4.8 | Record good practice where genuine; it identifies what to spread. |
Case in point
Case in point: two ways to write the same finding
An auditor examining a packing area found gaps in refresher training. The finding as first written read: training records for the packing line are not adequately maintained and refresher training is not being completed as required.
The area manager disputed it. The conversation ran for twenty minutes, covered which records the auditor had looked at and whether agency staff were included, and concluded with an action to review training records, assigned to the manager, with a date.
The finding as rewritten read: of twelve packing line training records reviewed, four showed no annual refresher against procedure QP-14, with the most recent refresher recorded in March two years earlier. All four were permanent employees. The action that followed was specific, the four people were identified within an hour, and there was nothing to dispute.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
7 sections
- Reference
- CMP-002
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent, maturity
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011 cl.6
- Links
- Links Clause Register; feeds Finding
- Tags
- Audit, Governance
- Sections
- 7
- Fields
- 65
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 7
Header
12 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Audit Title*
Audit Plan ID
Links to CMP-003 Plan ID
Audit Dates*
Management System Standard*
ISO 45001, ISO 14001, ISO 9001, ISO 50001, BRCGS, SQF, FSSC 22000 or an internal standard.
Clause Or Requirement
Clause ID
Links to FDN-009 Clause ID
Team and independence
6 fieldsLead Auditor*
Auditor Competency ID
Links to CMP-006 Record ID
Team Members
Independent Of The Area*
- Yes3 pts
- Partly1 pt
- No0 pts
Auditee Representative*
Opening Meeting Held*
- Yes3 pts
- No0 pts
Coverage
6 fieldsScope As Planned*
- Yes3 pts
- Reduced1 pt
- Extended3 pts
Scope Changes
Areas Or Processes Audited*
Clauses Audited
Shifts Covered
Contractors Included*
- Yes3 pts
- Not applicable3 pts
- No0 pts
Method and evidence
7 fieldsThree Sources, Not One
Ask somebody, watch them do it, then look at the record. Where all three agree the system works. Where they diverge you have found something.
Records Sampled*
People Interviewed*
Activities Observed*
Sampling Method*
- Random3 pts
- Risk based3 pts
- Stratified3 pts
- Convenience0 pts
Evidence Trail Followed End To End*
Take one incident or one batch and follow it through every step. It finds more than checking each step separately.
- Yes3 pts
- Partly1 pt
- No0 pts
Front Line Workers Interviewed*
- Yes3 pts
- Supervisors only1 pt
- No0 pts
Findings
Repeats7 fieldsFinding Reference*
Clause Or Requirement*
Grade*
- Critical0 pts
- Major1 pt
- Minor2 pts
- Observation3 pts
- Opportunity for improvement3 pts
Finding Description*
Objective Evidence*
Systemic Or Isolated*
- Isolated2 pts
- Possibly systemic1 pt
- Systemic0 pts
Finding ID
Links to FDN-015 Finding ID
Positive observations
2 fieldsGood Practice Identified*
Worth recording. It gets transferred to other areas and makes audits something people do not dread.
- Yes3 pts
- No1 pt
Good Practice Detail
Conclusion
25 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Critical Findings*
Major Findings*
Minor Findings*
Observations
System Conforms*
- Yes3 pts
- With minor findings2 pts
- No0 pts
System Effective*
Conforming and effective are different questions. A system can follow every procedure and still not control the risk.
- Yes3 pts
- Partly1 pt
- No0 pts
Repeat Findings From Last Audit*
Closing Meeting Held*
- Yes3 pts
- No0 pts
Report Issued Within Target*
- Yes3 pts
- Late1 pt
- No0 pts
Follow Up Record ID
Links to CMP-005 Record ID
Feeds Management Review*
Next Audit Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Lead Auditor*
Signature*
Auditee Representative*
Second Signature*
CMP-002 · record IDs look like AUD-2026-000 · Links Clause Register; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The report is one audit. What fails is a finding written as a conclusion and a scope limitation nobody recorded.
Structures findings around evidence, requirement and significance, records coverage and limitations, and applies published grading definitions.

Compares finding quality and grading across auditors, which reveals calibration drift faster than reviewing the criteria.
Routes findings to corrective action with cause analysis proportionate to grading, and to worker representatives where ISO 45001 requires.
Connects recurring findings to auditor competence and calibration, where the pattern sits with the auditor rather than the area.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Internal Audit Report definitions and key terms
- Audit evidence
- Records, statements of fact or other verifiable information relevant to the audit criteria.
- Audit criteria
- The requirements audited against: the standard, procedures, legal obligations or customer requirements.
- Audit finding
- The result of evaluating evidence against criteria, indicating conformity or nonconformity.
- Scope limitation
- Something preventing part of the planned audit, recorded because it affects the weight of the conclusion.
- Objective evidence
- Information that can be verified independently, distinguishing a finding from an impression.
- Audit conclusion
- The outcome of the audit after considering the objectives and all findings, addressing effectiveness.
- Grading
- Severity classification of a finding, meaningful only where definitions are published and applied consistently.
- Positive observation
- Recorded good practice, useful for identifying what to spread and for making the report readable.
FAQ
Frequently asked questions about internal audit report
What makes a finding usable?+
Three elements. Objective evidence, described specifically enough that someone else could verify it. The requirement it fails, cited to the clause or procedure. And why it matters, so the recipient can rank it against everything else. Findings missing the third element reliably get deprioritised regardless of how serious they are.
Why record what was not covered?+
Because it changes how much the conclusion means. An area unavailable, a shift not visited, a system inaccessible: ISO 19011 treats scope limitations as part of the report, and without them a reader assumes the audit covered what it planned to cover. It also protects the auditor when something surfaces later in an area that was never examined.
Should the report describe the sample?+
Yes. A conclusion drawn from a walk and two conversations is materially different from one drawn from thirty records and eight interviews, and the report should let the reader tell which it is. It also allows the finding rate to be interpreted, since four failures in twelve records is a different signal from four in two hundred.
How should the conclusion be written?+
As a judgement about whether the area audited is achieving what the system intends, drawing on the findings rather than listing them. Three findings can indicate a well-run area with specific gaps or a system not working at all, and the finding count alone cannot distinguish those. The conclusion is where the auditor's judgement earns its place.
Are positive observations worth recording?+
Where they are genuine. They identify practice worth spreading to other areas, which is a real output of an audit programme and one that is otherwise lost. They also make the report readable rather than purely adversarial, which affects how the rest of it is received. Manufactured positives to soften a report have the opposite effect.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause
More in Internal Audits
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Auditor Competency Record
Records an internal auditor's training, experience and audits performed
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 clause 6, conducting an audit, including 6.4 and 6.5
- ISO 9001:2015 clause 9.2, internal audit
- ISO 45001:2018 clause 9.2, internal audit, including reporting to workers
- ISO 19011:2018 clause 5.5.4, audit team selection
- ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.