The draft audit report is the primary formal communication vehicle used by the internal audit function to share its findings, conclusions, and assurance ratings with executive leadership. The report must be written with an objective, balanced, and constructive tone, focusing on process improvements rather than assigning individual blame.
[Compile Final Audit Program Data] ---> [Draft Executive Summary View] ---> [Format Detailed Observations]

To support executive scannability, the report architecture is organized hierarchically:
  1. Executive Summary Page: A high-level overview containing the final engagement assurance rating, a brief description of the audited entity’s operational context, a summary of core findings, and a high-level conclusion statement from the CAE.
  2. Overall Engagement Assurance Rating: A standardized rating scale used to communicate the overall health of the control environment:
    • Satisfactory: Controls are designed effectively and operating reliably, providing reasonable assurance that process objectives will be achieved.
    • Needs Improvement: Control weaknesses were identified that create moderate risk exposure; however, core operational processes remain functional.
    • Unsatisfactory: Systemic control failures or material weaknesses were identified that threaten the achievement of process objectives and require immediate remediation.

  3. Detailed Observations Table: A section containing the fully developed audit findings, structured around the five attributes framework and sorted by risk severity.