Skip to main content
Category: Internal Audit

Audit Findings

Also known as: Audit Observations
Simply put

Audit findings are the formal, evidence-based results an auditor reports after reviewing an organization's operations, controls, or financial statements. They typically point out where actual practice differs from an expected standard, such as a control weakness or process gap, and are meant to prompt corrective action by management. They give management, the board, and stakeholders an objective summary of what the audit uncovered.

Formal definition

Audit findings are formal statements, supported by evidence gathered during an engagement, that document conditions identified by the auditor relative to established criteria. They are commonly structured using the elements often summarized as the five C's, criteria (the expected standard), condition (what was observed), cause (why the gap exists), consequence (the effect or risk), and corrective action (recommended remediation). Findings are an assurance output produced by an independent audit function to inform management, the board, and stakeholders; they are distinct from the management activities that create or operate the controls being examined, and from the audit opinion, which in a financial statement context expresses an overall conclusion such as unqualified, qualified, or disclaimed. Remediation of findings, and tracking that remediation to closure, is typically a management responsibility rather than an audit responsibility, preserving the auditor's independence and objectivity.

Why it matters

Audit findings are the primary mechanism through which an independent audit function communicates what it uncovered to management, the board, and stakeholders. Because they are evidence-based and structured against established criteria, they give decision-makers an objective summary of where actual practice diverges from an expected standard, such as a control weakness or process gap. Without well-articulated findings, an audit engagement produces limited value, as the organization would lack a clear, documented basis for understanding its risks and prioritizing corrective action.

Findings also serve an important accountability role by preserving the separation between assurance and management activities. The auditor identifies and documents conditions; management is typically responsible for remediating them and tracking that remediation to closure. This division supports the auditor's independence and objectivity, since the audit function does not own or operate the controls it examines. Blurring this line, for instance by having auditors remediate their own findings, can compromise the credibility of future assurance.

In a financial statement context, findings are distinct from the audit opinion. A finding documents a specific condition, whereas an opinion expresses an overall conclusion such as unqualified, qualified, or disclaimed. Conflating the two can mislead stakeholders about the scope and significance of what the audit actually concluded.

Who it's relevant to

Internal Auditors
Internal auditors produce findings as a core assurance output, documenting conditions relative to established criteria and supporting each with evidence. Structuring findings clearly, such as through the five C's, helps ensure that reported observations prompt appropriate corrective action while maintaining the auditor's independence from the controls being examined.
Management
Management is typically responsible for remediating audit findings and tracking that remediation through to closure. Because remediation is a management activity rather than an audit responsibility, management owns the corrective action recommended in a finding and the operation of the controls involved.
Boards and Audit Committees
Boards and stakeholders rely on audit findings for an objective, evidence-based summary of an organization's operations, controls, and risks. Findings inform governance oversight and, in a financial statement context, should be understood as distinct from the overall audit opinion.
Compliance and Risk Professionals
Compliance and risk professionals use findings to understand where actual practice diverges from expected standards, helping to prioritize the treatment of control weaknesses and process gaps identified through assurance activities.

Inside Audit Findings

Condition
The factual statement of what the auditor observed, describing the current state of the process, control, or activity examined. It reflects evidence gathered during the engagement rather than opinion.
Criteria
The standard, policy, regulation, or expected state against which the condition is compared. Criteria may derive from external laws and regulations, internal policies and standards, or recognized frameworks, and should be identified explicitly.
Cause
The underlying reason the condition differs from the criteria. Identifying the root cause, rather than the symptom, supports meaningful remediation, though the cause is sometimes not fully determinable during the engagement.
Effect (or Consequence)
The actual or potential impact of the gap between condition and criteria, which may be expressed in terms of risk exposure, control weakness, financial impact, or non-compliance. The effect is commonly characterized qualitatively where a precise quantification is not reliably available.
Recommendation
A suggested course of action to address the cause and close the gap. Recommendations are advisory outputs of an assurance function; management retains responsibility for deciding on and implementing the corrective action or accepting the risk.
Management Response
The auditee's stated position on the finding, typically including agreement or disagreement, the planned remediation, an accountable owner, and a target date. This response is authored by management, keeping the distinction between assurance and management activities clear.

Common questions

Answers to the questions practitioners most commonly ask about Audit Findings.

Does an audit finding mean the auditor has identified a control failure or wrongdoing?
Not necessarily. An audit finding is the result of comparing a condition observed against a defined criterion, and the gap between them. That gap may reflect a control weakness, but findings can also identify opportunities for improvement, minor deviations, or observations that do not amount to a failure. A finding documents a difference from expected criteria; it does not by itself establish wrongdoing, which is a separate determination often outside the auditor's remit.
Is it the auditor's job to fix the issues raised in a finding?
No. This reflects a common blurring of assurance and management responsibilities. Auditors, as an independent and objective assurance function, identify and report findings and may recommend improvements, but designing and implementing remediation is a management responsibility. If auditors were to own the fix, their independence and objectivity over that area could be impaired. Management typically develops and executes the action plan; the audit function may later assess whether it was effective.
What elements are typically included when documenting an audit finding?
Audit findings are commonly structured around several attributes: the criterion (the standard, policy, or expected state), the condition (what was actually observed), the cause (why the gap occurred), and the effect or consequence (the actual or potential impact). Many functions also add a recommendation and a management response. Documenting these elements consistently supports clear communication and helps management understand the basis for the finding.
How are audit findings usually prioritized or rated?
Findings are commonly assigned a severity or risk rating to help direct attention and remediation effort. Ratings often consider the significance of the effect and the likelihood or pervasiveness of the underlying issue. The specific rating scales and thresholds vary by organization and audit function; they are typically defined in the audit methodology rather than prescribed universally. Ratings are a matter of professional judgment applied within an agreed framework.
Who should receive audit findings and how are they escalated?
Findings are typically communicated first to the management responsible for the area under review, giving them an opportunity to respond and agree on action. Depending on severity and organizational reporting lines, findings may be escalated to senior management, the audit committee, or the board. Escalation practices depend on the function's charter and governance structure, so the specific routing varies across organizations.
How is remediation of audit findings tracked and closed?
Remediation is generally tracked through agreed management action plans with assigned owners and target dates. Many functions maintain a follow-up or tracking process to monitor progress and to assess whether actions have been completed and are operating as intended before a finding is considered closed. The rigor of validation before closure varies, and independent verification by the audit function is often used for higher-severity findings.

Common misconceptions

An audit finding is the same as a recommendation, and the auditor is responsible for fixing the issue.
A finding is an evidence-based observation of a gap between condition and criteria, while the recommendation is a separate advisory element. Auditors, as an independent assurance function, identify and communicate findings; management owns the decision to remediate or to accept the risk. Blurring these roles undermines the objectivity that distinguishes assurance from management activities.
All audit findings represent confirmed non-compliance or control failures of equal severity.
Findings vary in nature and significance, and many frameworks apply a rating or prioritization scheme so that deficiencies are distinguished by impact and likelihood. A finding may indicate a design gap, an operating deficiency, or an opportunity for improvement rather than definitive non-compliance, and its effect is often described qualitatively where a precise figure cannot be reliably stated.
Audit findings are exclusively a compliance matter.
Findings can span the GRC pillars. Some relate to adherence to laws, regulations, or internal policies (compliance), while others concern the adequacy of risk identification and treatment (risk management) or the structures, roles, and decision rights that direct the organization (governance). The relevant pillar depends on the criteria against which the condition was assessed.

Best practices

Structure each finding around the recognized elements, condition, criteria, cause, effect, and recommendation, so that readers can trace the observation from evidence to suggested action.
Cite the specific criteria used, whether an external regulation, internal policy or standard, or a recognized framework, and note the applicable jurisdictional or sectoral context rather than presenting a requirement as universal.
Support the condition with sufficient, reliable evidence, and use qualified language for potential effects where a precise quantification or outcome cannot be reliably stated.
Focus on identifying the underlying cause rather than the symptom to enable durable remediation, and acknowledge where the root cause could not be fully determined during the engagement.
Keep the auditor's advisory recommendations distinct from management's response and remediation ownership, preserving the independence and objectivity of the assurance function.
Prioritize or rate findings by significance so that stakeholders can allocate remediation effort proportionately, and confirm each finding is agreed with the responsible owner and assigned a target date through the management response.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps