Please enable JavaScript.
Coggle requires JavaScript to display documents.
COMMUNICATING AUDIT RESULTS and AUDIT REPORT STRUCTURE AND CONTENTS (Exit…
COMMUNICATING AUDIT RESULTS and AUDIT REPORT STRUCTURE AND CONTENTS
Exit interview : at the end of the audit, provides the IS auditor with the opportunity to discuss findings and recommendations with management . During the exit interview, the IS auditor should:
• Ensure that the facts presented in the report are correct
• Ensure that the recommendations are realistic and cost-effective and, if not, seek alternatives through negotiation with auditee management
• Recommend implementation dates for agreed-on recommendations
The IS auditor should have a thorough understanding of the presentation techniques necessary to communicate these results.
Presentation techniques could include the following:
Executive summary
An easy-to-read, concise report
that presents findings to management in an understandable manner
Findings and recommendations should be communicated from a business perspective
Detailed attachments can be more technical in nature because operations management will require the detail to correct the reported situations.
Visual presentation
include slides or computer graphics
goal of such a discussion would be to gain agreement on the findings and develop a course of corrective action.
IS auditor should elaborate on the significance of the findings, risk and effects of not correcting the control weakness
auditee's management may request
assistance from the IS auditor
The IS auditor should communicate the difference between the IS auditor's role and that of a consultant and give careful consideration to how assisting the auditee may adversely affect the IS auditor's independence.
Audit report
skilled IS auditor should understand the basic components of an audit report and how it communicates audit findings to management.
Structure and contents
An introduction to the report
general statement on the nature and extent of audit procedures conducted and processes examined during the audit
period of audit
coverage
limitations to the audit and scope
statement of audit
objectives
Before communicating the results of an audit to senior management, an IS auditor should discuss the findings with the auditee management to gain agreement on the findings and develop an agreed-upon course of corrective action.
In cases where there is disagreement, an IS auditor should elaborate on the significance of the findings, risk and effects of not correcting the control weakness.