The 5 Most Common Mistakes in Internal Audit Reports

Internal audit is your management system’s self-checking mechanism. Yet it is also one of the most frequently criticized areas in external audits — because weaknesses in report writing devalue the audit itself.

The five mistakes we encounter most often in the field, and how to fix them.

1. Writing an opinion instead of a nonconformity

Wrong: “The tracking of calibration records appears to be inadequate.”

This is not a finding; it is an impression. The audited department does not know what to do with it, no corrective action can be raised, and the closure criterion is unclear.

The correct version has three components:

  • Requirement: What the clause or procedure says
  • Evidence: What was observed on site, which record was examined
  • Deviation: What the difference between the two is

Example: “Procedure XX requires measuring instruments to be calibrated once a year. During the review on 12 March, it was observed that the last calibration date of three calipers on line A (serial no. …) was 18 months ago and no valid calibration certificate was available.”

The difference: with the second statement it is clear what needs to be done.

2. Not referencing the evidence

The report is the repeatable record of the audit. When an external auditor looks at your report six months later, they should be able to see which record, which date and which person you relied on.

Without an evidence reference the finding is not verifiable. A finding that cannot be verified is interpreted in an external audit as a weakness of your internal audit system.

Document number, date, serial number, record name — all of it belongs in the report.

3. Skipping the sampling statement

No audit examines everything. Auditing is built on sampling, and that is the natural limit of an audit.

The problem is that this limit does not appear in the report. When the report is read, the impression is “the whole process was examined and found compliant.” In reality perhaps three records were reviewed.

ISO 19011:2026 emphasizes stating the sampling approach used in the audit report. The aim is transparency about the scope and limits of the audit.

The practical application is simple: “Period reviewed: January–June 2026. Number of records reviewed: 12 records randomly selected from 240 production orders.”

This single paragraph markedly increases the credibility of the report.

4. The auditor writing the root cause

A common role confusion: the auditor writes the finding and then adds “root cause: lack of staff training.”

Root cause analysis is the responsibility of the audited department. The auditor identifies what is nonconforming; finding the cause and fixing it is the process owner’s job.

If the auditor also writes the root cause, two problems arise. First, impartiality is compromised. Second, and more importantly, the process owner receives a ready-made answer without doing any analysis; the real cause is never investigated and the same nonconformity recurs.

5. Confusing correction with corrective action

Correction: Eliminating the detected deviation. Sending the out-of-calibration calipers for calibration.

Corrective action: The system change that will prevent the deviation from recurring. Adding an automatic alert to the calibration tracking system, defining responsibility, tying the periodic check to a procedure.

Findings closed with a correction only are reopened at the next audit. This is exactly what the external auditor looks at under “effectiveness of corrective action”: is the same finding recurring?

If your report format does not ask for these two as separate fields, update your format.

Bonus: if the report reaches no one

A technically flawless report is of no use if it only sits in the quality department’s folder.

The audit report should reach top management, the process owners and the management review input. Follow-up of finding closure should be tied to a defined owner and date.

In practice, what creates the most value is not the quality of the report but how the report circulates in the system.

Checklist

Before you send your next report:

  • Is every finding in the requirement + evidence + deviation structure?
  • Are evidence references (document no., date, serial no.) included?
  • Has the sampling statement been written?
  • Has the root cause field been left to the audited department?
  • Are correction and corrective action separate fields?
  • Is it clear who the report will be distributed to and who will follow up?

Next step

You can join our ISO 19011 training, where we work through audit planning, evidence collection, finding writing and reporting hands-on, or make use of our consulting services to update your audit procedure and report templates.