Audit
How to Write an Internal Audit Finding That Drives Change
Most findings fail not because the underlying issue is small, but because the writing gives management nothing specific to act on. Here is how to write one that survives.

A finding lands on a process owner's desk that reads: "Access reviews are not performed consistently." The owner nods, files it, and nothing changes. Three quarters later the same issue surfaces again, now with a repeat-finding flag and an audit committee question about why it was not fixed the first time. The issue was real both times. The first write-up simply gave no one a reason or a route to act.
A finding is not a complaint. It is an argument built to move a specific reader toward a specific decision. When it works, someone with the authority and budget to change a process reads it, agrees, and commits to a date. When it fails, it dies quietly in the report. The difference is usually in the writing, not the fieldwork.
The five elements, and what each one is really for
Internal audit has taught the same anatomy for decades because it works: condition, criteria, cause, effect, recommendation. The trap is treating these as boxes to fill rather than a chain of reasoning.
- **Condition** is what you observed, stated as fact and quantified. Not "controls are weak" but "for 12 of 40 privileged accounts sampled, no access review was completed in the year to March 31."
- **Criteria** is the standard the condition falls short of: a policy, a regulation, a contractual term, a control the organization itself designed. If you cannot name the criterion, you have an observation, not a finding.
- **Cause** is why the gap exists. This is the element most writers skip, and it is the one that determines whether the fix works.
- **Effect** is what the gap puts at risk, expressed in terms the reader cares about: financial exposure, regulatory breach, service disruption, reputational harm.
- **Recommendation** is the change you are asking for, specific enough that someone could act on it tomorrow.
Read as a chain, these answer the reader's real questions in order: What did you find? Says who? Why is it happening? Why should I care? What do you want me to do?
Write for the person who has to act
The reader you are writing for is not the audit committee and not your manager. It is the process owner who must change something. That person is busy, mildly defensive, and reading for one thing: what this costs them and whether it is worth it.
Lead with effect and criteria, not with fieldwork detail. A process owner who understands the exposure in the first two sentences will read the rest with attention. Cut the audit vocabulary that means nothing outside the function; "control deficiency in the provisioning process" is weaker than "new joiners kept access from their previous role for weeks." Concrete language is not less rigorous; it is more, because it commits you to a claim someone can check.
Quantify the effect honestly. If you cannot size it precisely, bound it. "Up to 40 accounts could retain access beyond termination" is defensible and useful; "significant risk" is neither.
Get the cause right, or the fix will not hold
Weak findings recommend the symptom's opposite. The condition is "reviews were not performed," so the recommendation becomes "perform reviews." That treats the surface, not the cause, and the finding returns.
Push past the first answer. Reviews were not performed because the owner was never told they were responsible; because the system produces no report to review against; because the review takes two days no one has. Each cause implies a different fix, and only one of them will actually work. The five whys are a blunt tool, but the instinct behind them is right: keep asking until the answer is something the organization can change.
A recommendation should follow from the cause and stop there. Resist the urge to redesign the whole process. Auditors who over-reach on recommendations invite disagreement over the fix and lose the finding entirely. State the outcome you need and leave management room to choose the mechanism; they own the how.
How weak findings die
Findings die in predictable ways. They die vague, giving nothing to act on. They die unquantified, so no one can rank them against competing work. They die without an owner, addressed to a department rather than a person. And they die soft, watered down in review negotiation until the recommendation says "consider enhancing." "Consider" is not an ask; it is permission to do nothing.
The strongest defense is a management response with a named owner and a committed date, agreed before the report is issued. A finding with a date attached has a future. One without a date has only a past.
Before you write the next one
Draft the effect sentence first and ask whether a reader outside audit would care. Name the criterion or downgrade the finding. Chase the cause until the fix is obvious. Then get a name and a date on the response. A finding that clears those four checks rarely dies in the report; it turns into work someone actually does.