You have planned the work, tested the controls and gathered a stack of evidence. Now comes the phase that determines whether any of it makes a difference. Reporting is where findings become decisions. A brilliant audit with a weak report changes nothing, because the people who can fix the problems never understand them. This article shows you how to turn evidence into a report that management acts on, and how to present it face to face in an exit meeting.
This is part 4 of 5 in the series. In Part 1, What Is an IT and IS Audit?, you met the four phases of an audit. In Part 2, Phase 1 of an IS Audit, you learned to plan the work for BBC Bank. In Part 3, Phase 2 of an IS Audit, you tested controls and wrote the evidence down. The leaver finding in this article is the same kind of gap you tested in working paper WP-A12 in Part 3, where two of the 25 March leavers still had access. Now we turn that kind of evidence into something management will act on.
What Reporting Is
Reporting is the phase where you communicate your findings, rate their severity, recommend fixes, hold an exit meeting with management, and agree an action plan. The deliverable is the final audit report. A deliverable is simply the thing you hand over at the end of the work.
Reporting is not an afterthought stuck on at the end. It is the product the organisation actually pays for, because it is the only part most senior people will ever read. The board will not open your working papers. The head of IT will not open your Excel file. They will read the report. So the report has one job. It must lead to action.
The Anatomy of a Finding
Everything in a report is built from findings, so you must learn to write one well. A finding is a gap between what should be happening and what is happening. The professional standard is the five-part structure, often called the 5C format. Each finding answers five questions in order. We will walk through each part with the leaver example.
1. Condition: what you found
Condition is what you found, supported by evidence. Not a vague worry, but a specific fact with a reference. For example: "A number of staff who left the organisation still had active system accounts at the review date, per working paper X."
Notice the reference to a working paper. Anyone who doubts the fact can go to that paper and see the proof. "Access control seems weak" is a worry. "These accounts were still active on this date, see this paper" is a condition.
2. Criteria: the rule it breaks
Criteria is the standard the condition breaches. This is where you point to the rule. For example: "The ICT policy requires access to be revoked within twenty-four hours of an exit."
Without criteria, a finding is only an opinion. The rule might come from a bank policy, a regulation, a contract or recognised good practice. Always name the source, so the manager can open the policy and find the same words.
3. Cause: why it happened
Cause is the underlying reason it happened. This is the part novices skip, and it is the most important, because the cause is what you actually fix. For example: "There is no automated notification from human resources to the IT department when a person leaves" is a cause.
The symptom is the leftover account. The disease is the missing notification. If you only remove the leftover accounts, you treat the symptom. Next month new leftover accounts will appear, because the disease is still there.
4. Effect: why it matters
Effect is the business or regulatory risk the condition creates. Why should management care? For example: "Former staff retain the ability to access or alter customer data, creating a fraud risk and breaching regulatory requirements."
The effect is what turns a technical note into a business concern. Managers think in money, customers, regulators and reputation. Write the effect in those terms, and be honest. Do not inflate it and do not shrink it.
5. Recommendation: the fix, the owner and the timeline
Recommendation is the fix, with a responsible owner and a realistic timeline. For example: "Automate the exit notification and perform a monthly reconciliation of leavers against active accounts, owned by the Head of IT, within three months."
A reconciliation here means comparing two lists, the HR list of leavers and the list of active system accounts, and following up anyone who appears on both. Look at how the recommendation fixes the cause. The automated notification cures the disease. The monthly reconciliation is a backstop that catches anything the notification misses.
Why all five parts matter
A finding that contains all five parts is persuasive and actionable. A finding missing the cause leads to a fix that treats the symptom and lets the problem return. A finding missing the criteria invites the argument, "Says who?" Learn the five Cs and your findings will carry weight.

Finding the real cause
Here is a simple habit that will help you find the disease and not just the symptom. When you think you have the cause, ask "why?" again. Keep asking until you reach something management can actually change. Usually three or four whys is enough.
Why could former staff still sign in? Because their accounts were never disabled. That is still the symptom.
Why were the accounts never disabled? Because IT did not know those people had left.
Why did IT not know? Because exits are communicated informally, and some messages are missed.
Why are exits communicated informally? Because there is no automated link between the human resources system and the IT service desk.
Now you have the real cause. It is a missing process, and the Head of IT can fix it. "The accounts were not disabled" is not a cause. It only repeats the condition.
Stop when you reach a process, a role or a system. If your next "why" leads to "because people are careless", you have gone too far. Ask what control should have caught the mistake.
Check your cause against your recommendation. If your recommendation does not fix the cause you wrote, one of them is wrong.
Rating the Severity of Findings
Management cannot fix everything at once, so you must tell them what matters most. Each finding is given a risk rating, usually high, medium or low, based on its likelihood and impact. Likelihood is how likely the risk is to happen. Impact is how bad it would be if it did.
A high rating means urgent, with major financial, regulatory or fraud risk.
A medium rating means important and should be fixed within the current cycle.
A low rating means minor, more housekeeping than danger.
The rating is a judgement, but it must be consistent. If two findings carry similar risk, they should carry similar ratings, and your report should explain the basis. A clear rating lets a busy director see in seconds where to direct attention and money.
A simple grid helps you stay consistent. Put likelihood on one side and impact on the other. People often say risk equals likelihood times impact, but you do not need real maths. High likelihood and high impact gives high. Low likelihood and low impact gives low. Everything else falls in between.
Leaver example: Leaver accounts that stay open are likely to happen again while exits are communicated informally. The impact is high, because former staff could access customer data and transact. That gives a high rating.

The Structure of the Report
A professional IS audit report follows a recognisable structure. Knowing it helps you write one and read one.
Executive summary
The executive summary comes first and is the most important page. It gives the overall opinion, the top findings and the high-level risk posture, all in plain language. Risk posture just means how exposed the organisation is overall. Many directors read only this page, so it must stand alone and avoid jargon. Write it last, once your findings are final. You cannot summarise what you have not finished.
The other sections
The background and scope section states the objectives, the systems covered, the period reviewed and the standards referenced.
The methodology section explains the procedures, the sampling, the data analysis techniques used, and the sources of evidence.
The detailed findings and recommendations section presents each finding in the 5C format, grouped by area and ordered by severity.
Testing summaries show the results of key tests, such as reconciliations and recomputations, with the basis of calculation. A recomputation is when you redo a calculation yourself to check the system got it right.
The management action plan consolidates the agreed actions, owners and target dates.
Appendices hold the supporting workpapers, calculations and evidence.
A sample management action plan
Here is what a short action plan might look like for BBC Bank. These are teaching examples built from cases in earlier parts of this series. They are not from a real bank.
Finding | Rating | Agreed action | Owner | Target |
|---|---|---|---|---|
Accounts of staff who had left remained active in the core banking system. | High | Implement an automated exit notification from human resources to IT, supported by a monthly reconciliation of leavers against active accounts. | Head of IT, with Human Resources | Within three months |
Shared night account NIGHT01 used to make and approve reversals on the core. | High | Remove admin rights from NIGHT01. Give each night officer a named login. Block the same user from making and approving a reversal. | Head of Operations, with Head of IT | Within three months |
Disaster recovery restore not tested onto a clean machine. | Medium | Run a full restore test onto a separate machine, record the results, and schedule regular tests. | IT Operations Manager | Within the current cycle |
Every row has an owner who is a named role, not "IT" in general. Every row has a target. That is what makes follow up possible. Why is the restore finding medium? A disaster is less likely on any given day than misuse of an open account, though the impact would be severe. Your team's grid might rate it high. That is fine, as long as you rate every finding the same way and explain the basis.
Forming the Overall Opinion
The report usually carries an overall opinion on the control environment, for example satisfactory, needs improvement, or unsatisfactory. The control environment is the full set of controls in the area you audited. This is your professional judgement, and it must be supported by the findings.
An opinion of satisfactory sitting above a list of high-risk findings is a contradiction that destroys credibility. The opinion and the findings must tell the same story. Forming the opinion is a moment of judgement, and you should be able to defend it by pointing to the pattern of findings beneath it. For our BBC Bank teaching case, two high findings and one medium would never support satisfactory.
Writing for Management, Not for Yourself
New auditors write reports to prove how much they know. Experienced auditors write reports to change behaviour. The difference is the reader. Your audience is management and the board, not fellow technicians. So translate technical conditions into business risk.
Do not write "the password history parameter is set to five." Write "staff can reuse old passwords sooner than policy allows, which weakens protection against compromised accounts," and keep the technical detail in an appendix.
Here is another pair, for the restore finding.
Before: "DR restore test not performed per BCP section 4.2. Backup integrity verification limited to file existence check."
After: "The bank has not proved it can bring back its core banking data after a disaster. The last restore test only checked that the backup file existed, not that the data could be opened. If the backups are damaged, the bank may not be able to serve customers for days."
Lead with what matters. Be concise. Be specific. Avoid blame of named individuals, because audit addresses systems and controls, not personalities.
The Exit Meeting
Before the report is finalised, the auditor holds an exit meeting with management. This is a formal discussion where the findings are presented, management responds, and the two sides agree on the facts and the action plan. The exit meeting matters for several reasons.
It confirms accuracy, because management may hold context the auditor missed, and it is better to correct an error before the report is issued than after.
It secures buy-in, because people are far more likely to fix problems they helped shape the response to.
It produces the management action plan, the list of agreed actions with owners and dates.
It tests the auditor, because you must explain and defend your findings to the very people they concern.
How to present at an exit meeting
Presenting findings to management is a skill in itself.
Open with the overall opinion and the big picture, then move to the most serious findings.
Tell the story clearly, especially where an incident is involved, walking management through what happened and which controls failed.
Be concise and visual, using a short slide deck rather than reading the full report aloud.
Link every finding to its evidence, so that when challenged you can show the basis.
Stay calm and professional under questioning, because a strong defence of a well-evidenced finding is far more convincing than defensiveness.
Where you work in a team, share the speaking, so the panel sees that everyone understands the work.
Avoid the common traps.
Do not read the report aloud.
Do not present a finding you cannot evidence.
Do not blame individuals by name.
Do not overstate or guess, because a single exaggeration lets management dismiss the whole report.
When you do not know an answer, say you will confirm it, rather than inventing one.
A simple exit meeting agenda
Most exit meetings take about 30 to 45 minutes. Here is a practical order you can use for the BBC Bank capstone.
Welcome and purpose (about 3 minutes). Thank people for their time. Say what the meeting is for and how long it will take.
Overall opinion and big picture (about 5 minutes). Remind everyone of the scope, then give the opinion.
Findings, most serious first (about 20 minutes). For each one, give the condition, effect and recommendation, and show the evidence. Listen to management's response and note any new facts.
Agree the action plan (about 10 minutes). Go through each finding and confirm the action, owner and target.
Next steps and close (about 5 minutes). Say when the final report will go out, list anything you promised to confirm, and explain how audit will follow up.
After the meeting, write short notes of what was agreed and keep them on file. They become evidence too.
A Worked Example of a Finding
Here is a complete finding in the 5C format, so you can see the parts working together. It is the same kind of leaver gap you tested as WP-A12 in Part 3.
Condition: At the review date, several user accounts belonging to staff who had already left the organisation remained active in the core banking system, as shown in working paper 02.
Criteria: The ICT policy requires all system access to be revoked within twenty-four hours of an exit being notified.
Cause: There is no automated link between the human resources system and the IT service desk, so exits are communicated informally and sometimes missed.
Effect: Former employees retain the ability to access customer data and transact, creating a significant fraud and data protection risk, and breaching both internal policy and regulatory expectations.
Recommendation: Implement an automated exit notification from human resources to IT, supported by a monthly reconciliation of leavers against active accounts. Owner: Head of IT, with Human Resources. Target: within three months. Rating: high.
Notice how the five parts flow. The condition states the fact, the criteria proves it is wrong, the cause explains why, the effect shows why it matters, and the recommendation fixes the cause, not just the symptom.
Key Terms to Remember
A finding is a gap between what should be and what is, written in the 5C format.
The 5C format is condition, criteria, cause, effect and recommendation.
The executive summary is the stand-alone opening that most senior readers rely on.
The overall opinion is the auditor's supported judgement on the control environment.
The exit meeting is the formal discussion where findings are presented and an action plan agreed.
A risk rating is high, medium or low, based on likelihood and impact, and applied consistently.
The management action plan is the agreed actions, owners and target dates for each finding.
References
ISACA (2024). CISA Review Manual, 28th edition. Schaumburg, IL: ISACA.
ISACA (2020). IT Audit Framework (ITAF), 4th edition. Schaumburg, IL: ISACA.
Institute of Internal Auditors (2024). Global Internal Audit Standards. Lake Mary, FL: The IIA.
Hall, J. A. (2015). Information Technology Auditing, 4th edition. Boston: Cengage Learning.
Pickett, K. H. S. (2010). The Internal Auditing Handbook, 3rd edition. Chichester: Wiley.
Your Reflection and Peer Review
This section is a required learning activity. Reporting is about communication, so your reflection should show you can communicate clearly.
Part A: Write your own reflection (about 300 to 400 words)
In the comments below, post a reflection answering the following.
Explain the 5C format in your own words, and say which of the five you think students most often get wrong, and why.
Take any small problem you have seen, at home, on campus or at work, and write it up as a full finding using all five Cs.
Explain why the overall opinion must match the findings, and what goes wrong when it does not.
List your three key takeaways from this article and why each matters.
Describe one thing that worries you about presenting findings to senior people, and one idea from this article that would help.
Part B: Critique at least five peers' reflections
Read your classmates' reflections and respond to at least five. For each, write two to four sentences that do the following.
Name one thing they did well, especially in their 5C finding, and say why.
Identify one weakness, paying special attention to whether their cause is a real underlying reason or just a restatement of the symptom, and suggest an improvement.
Ask one real question that pushes their thinking further.
What a good critique looks like
Weak: "Good finding, all five Cs are there." Strong: "Your finding about the unlocked computer lab is well structured and your effect clearly explains the theft risk. But your cause, 'the door was left unlocked,' is really just the condition restated. What is the underlying reason the door keeps being left unlocked? If it is that no one is assigned to lock it, then your recommendation should assign that responsibility, which it currently does not."
Ground rules
Critique the idea, not the person. Be specific and constructive, and help the whole class learn to write findings that drive real change.