Summary
In short
- A finding needs three elements: what was observed with enough specificity to be verified, the requirement it fails, and why it matters.
- Record what was not covered as well as what was. Scope limitations, areas unavailable and shifts not visited are all context the reader needs to weigh the conclusion.
- State the method: what was examined, how many samples, who was interviewed, what was observed. A conclusion drawn from three documents is different from one drawn from thirty.
- Grading definitions must be published and applied consistently, or a major from one auditor and a major from another mean different things and cannot be compared.
- Positive observations are worth recording where genuine, because they identify practice worth spreading and they make the report readable rather than purely adversarial.
- The conclusion should address the effectiveness of the area audited rather than summarising the finding count.
What it is
What it is
What is an internal audit report?
The record of a single audit: who conducted it and on what basis of independence, what was covered and what was not, the method and evidence used, the findings with their grading, and a conclusion about the effectiveness of the area audited against the criteria.
What makes a finding usable?
Objective evidence, the requirement it fails against, and the significance. Without evidence the finding is contestable, without the requirement it is an opinion, and without significance the recipient cannot judge priority against everything else on their list.
When to use it
When to use it, and when not to
This is the report of one audit. The programme and the corrective actions sit separately.
Use it for
- Reporting a single internal audit against defined criteria
- Recording scope, coverage and any limitations encountered
- Documenting findings with evidence, requirement and significance
- Concluding on the effectiveness of the area or process audited
- Providing the basis for corrective action and for management review input
Not for
- The audit programme, which plans the set of audits and reviews their collective effectiveness
- Corrective action records, which track each finding through to verified closure
- Supplier and second-party audit reports, which have different scope and competence requirements
- Certification and surveillance audit reports, produced by the certification body
- Management review, which consumes audit results in aggregate
Standards
What it is built against
Audit conduct is governed by ISO 19011, with the requirement to audit coming from the management system standards.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.6.4 | Collecting and verifying information, with audit evidence based on verifiable information | Method and evidence |
| ISO 19011 cl.6.4.8 | Generating audit findings, evaluating evidence against criteria and recording conformity and nonconformity | Findings |
| ISO 19011 cl.6.4.9 | Determining audit conclusions covering the extent of conformity and effectiveness | Conclusion |
| ISO 19011 cl.6.5 | Audit report content including scope, criteria, findings, conclusions and any scope limitations | Coverage |
| ISO 19011 cl.5.5.4 | Audit team selected for competence to achieve the audit objectives | Team and independence |
| ISO 9001 cl.9.2.2 | Auditors selected to ensure objectivity and impartiality; not auditing their own work | Team and independence |
| ISO 45001 cl.9.2.2 | Results reported to relevant managers, workers and worker representatives | Conclusion |
| ISO 45001 cl.10.2 | Corrective action arising from nonconformity, including determining causes | Findings |
What it does not cover
- The audit programme, planning the set of audits and reviewing their collective effectiveness.
- Corrective action records, tracking findings through cause analysis to verified closure.
- Second-party supplier audit reports, with different scope and competence requirements.
- Certification body reports, produced independently against a scheme.
- Management review, which consumes audit results in aggregate.
Filling it in
Filling it in well
Write findings that can be acted on, state what you did not see, and conclude on effectiveness.
What was observed, specifically enough that another person could verify it. Which requirement it fails, cited to the clause or procedure. Why it matters, which is what lets the recipient rank it against everything else competing for their attention. Findings missing the third element get deprioritised regardless of severity.
What was audited, what was sampled, what could not be examined and why. An area unavailable, a shift not visited, a person on leave, a system inaccessible. Scope limitations are explicitly part of the report under ISO 19011 and they let the reader judge how much weight the conclusion carries.
How many records, which period, who was interviewed, what was observed directly. A conclusion drawn from a walk and two conversations is different from one drawn from thirty records and eight interviews, and the report should make clear which it is.
The conclusion should say whether the area audited is achieving what the system intends, drawing on the findings rather than listing them. Three findings can indicate a well-run area with specific gaps or a system that is not working, and only a conclusion distinguishes them.
Audit findings
Common audit findings
Report findings concentrate on whether the report is usable.
| Finding | Clause | What fixes it |
|---|---|---|
| Findings state conclusions without objective evidence. | ISO 19011 cl.6.4 | Record what was seen, specifically enough to be verified independently. |
| Requirement not cited, so the finding reads as an opinion. | ISO 19011 cl.6.4.8 | Cite the clause or procedure the evidence fails against. |
| Significance not stated, so recipients cannot prioritise. | ISO 19011 cl.6.5 | Explain why it matters; findings without significance get deprioritised. |
| Scope limitations not recorded. | ISO 19011 cl.6.5 | State what could not be examined; it changes the weight of the conclusion. |
| Sample size and method not described. | ISO 19011 cl.6.4 | Record how much was examined; conclusions depend on it. |
| Grading applied inconsistently between auditors. | ISO 19011 cl.6.4.8 | Publish definitions and calibrate against worked examples. |
| Conclusion summarises the finding count rather than addressing effectiveness. | ISO 19011 cl.6.4.9 | Conclude on whether the area achieves what the system intends. |
| Auditor independence not evidenced. | ISO 9001 cl.9.2.2 | Record the basis of independence; it is the first thing questioned. |
| Results not reported to workers or their representatives. | ISO 45001 cl.9.2.2 | An explicit ISO 45001 requirement frequently omitted. |
| Positive observations absent, making the report purely adversarial. | ISO 19011 cl.6.4.8 | Record good practice where genuine; it identifies what to spread. |
Worked case
Case in point: two ways to write the same finding
An auditor examining a packing area found gaps in refresher training. The finding as first written read: training records for the packing line are not adequately maintained and refresher training is not being completed as required.
The area manager disputed it. The conversation ran for twenty minutes, covered which records the auditor had looked at and whether agency staff were included, and concluded with an action to review training records, assigned to the manager, with a date.
The finding as rewritten read: of twelve packing line training records reviewed, four showed no annual refresher against procedure QP-14, with the most recent refresher recorded in March two years earlier. All four were permanent employees. The action that followed was specific, the four people were identified within an hour, and there was nothing to dispute.
Definitions
Definitions and key terms
- Audit evidence
- Records, statements of fact or other verifiable information relevant to the audit criteria.
- Audit criteria
- The requirements audited against: the standard, procedures, legal obligations or customer requirements.
- Audit finding
- The result of evaluating evidence against criteria, indicating conformity or nonconformity.
- Scope limitation
- Something preventing part of the planned audit, recorded because it affects the weight of the conclusion.
- Objective evidence
- Information that can be verified independently, distinguishing a finding from an impression.
- Audit conclusion
- The outcome of the audit after considering the objectives and all findings, addressing effectiveness.
- Grading
- Severity classification of a finding, meaningful only where definitions are published and applied consistently.
- Positive observation
- Recorded good practice, useful for identifying what to spread and for making the report readable.
FAQ
Frequently asked questions
What makes a finding usable?+
Three elements. Objective evidence, described specifically enough that someone else could verify it. The requirement it fails, cited to the clause or procedure. And why it matters, so the recipient can rank it against everything else. Findings missing the third element reliably get deprioritised regardless of how serious they are.
Why record what was not covered?+
Because it changes how much the conclusion means. An area unavailable, a shift not visited, a system inaccessible: ISO 19011 treats scope limitations as part of the report, and without them a reader assumes the audit covered what it planned to cover. It also protects the auditor when something surfaces later in an area that was never examined.
Should the report describe the sample?+
Yes. A conclusion drawn from a walk and two conversations is materially different from one drawn from thirty records and eight interviews, and the report should let the reader tell which it is. It also allows the finding rate to be interpreted, since four failures in twelve records is a different signal from four in two hundred.
How should the conclusion be written?+
As a judgement about whether the area audited is achieving what the system intends, drawing on the findings rather than listing them. Three findings can indicate a well-run area with specific gaps or a system not working at all, and the finding count alone cannot distinguish those. The conclusion is where the auditor's judgement earns its place.
Are positive observations worth recording?+
Where they are genuine. They identify practice worth spreading to other areas, which is a real output of an audit programme and one that is otherwise lost. They also make the report readable rather than purely adversarial, which affects how the rest of it is received. Manufactured positives to soften a report have the opposite effect.
The agents
What the agents do with it
The report is one audit. What fails is a finding written as a conclusion and a scope limitation nobody recorded.
Structures findings around evidence, requirement and significance, records coverage and limitations, and applies published grading definitions.
Compares finding quality and grading across auditors, which reveals calibration drift faster than reviewing the criteria.
Routes findings to corrective action with cause analysis proportionate to grading, and to worker representatives where ISO 45001 requires.
Connects recurring findings to auditor competence and calibration, where the pattern sits with the auditor rather than the area.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Sources
Sources
- ISO 19011:2018 clause 6, conducting an audit, including 6.4 and 6.5
- ISO 9001:2015 clause 9.2, internal audit
- ISO 45001:2018 clause 9.2, internal audit, including reporting to workers
- ISO 19011:2018 clause 5.5.4, audit team selection
- ISO 45001:2018 clause 10.2, incident, nonconformity and corrective action