Chapter 9
Reporting & Remediation
Learn how to produce clear, actionable audit reports — from structuring an executive summary for board-level audiences to writing detailed technical findings and tracking remediation through re-testing and closure.
Writing the Audit Report
The Audit Report as the Primary Deliverable
The audit report is the most visible and enduring product of the entire audit engagement. It communicates findings, conclusions, and recommendations to stakeholders who may not have been involved in the day-to-day audit work. A well-written report drives action; a poorly written report is filed away and forgotten. The report must be accurate, clear, objective, and constructive — presenting findings in a way that motivates remediation rather than creating defensiveness. Every statement in the report must be supported by evidence documented in the working papers.
- Executive Summary: A concise, non-technical overview of the audit scope, key findings, overall risk posture, and priority recommendations. Written for senior leadership and board members who need to understand the big picture without technical details.
- Scope and Objectives: A clear description of what was audited, the time period covered, the standards or frameworks used as evaluation criteria, and any scope limitations or exclusions.
- Methodology: A brief description of the audit approach, including the types of testing performed, sampling methods used, and tools employed.
- Findings and Recommendations: The detailed body of the report, presenting each finding with its condition, criteria, cause, effect, risk rating, and recommendation. This is the most substantial section and should be organized by severity or by domain.
- Management Response: The auditee's response to each finding, including whether they agree or disagree, their planned remediation actions, responsible parties, and target completion dates.
- Appendices: Supporting details such as the list of personnel interviewed, documents reviewed, systems tested, and the detailed risk rating methodology used.
Writing Effective Finding Statements
Each finding in the audit report should follow a structured format that clearly communicates what was found, why it matters, and what should be done about it. The most widely used format is the Condition-Criteria-Cause-Effect-Recommendation (CCCER) framework, which provides a logical flow from the observation to the action required. This structure ensures findings are complete, defensible, and actionable.
| Element | Description | Example |
|---|---|---|
| Condition | What the auditor found — the factual observation supported by evidence | MFA is not enabled for VPN access. 85 out of 200 employees access the network via VPN without MFA. |
| Criteria | What was expected — the standard, policy, or best practice against which the condition is measured | The organization's Access Control Policy requires MFA for all remote access methods. NIST SP 800-63B recommends MFA for all remote authentication. |
| Cause | Why the gap exists — the root cause of the deficiency | MFA was implemented for the portfolio management system but was not extended to VPN access due to a lack of centralized identity management. |
| Effect | The risk or impact — what could happen if the condition is not remediated | VPN accounts protected only by passwords are vulnerable to credential stuffing, phishing, and brute-force attacks. A compromised VPN account provides full network access. |
| Recommendation | The specific action to remediate the finding | Implement MFA for all VPN connections within 30 days. Consider deploying a centralized identity provider to enforce MFA consistently across all access methods. |
Executive Summary vs Detailed Findings
Understanding Your Audiences
An audit report serves multiple audiences with different needs. The board of directors and executive leadership need a high-level view of risk posture and strategic implications. IT management needs specific technical findings and actionable recommendations. The compliance team needs to understand regulatory implications and remediation tracking requirements. Writing for multiple audiences requires structuring the report so each audience can find what they need without wading through content intended for others.
| Audience | Primary Interest | Report Section | Tone and Detail Level |
|---|---|---|---|
| Board / C-Suite | Overall risk posture, business impact, strategic investment needs | Executive Summary | Non-technical, business-focused, 1-2 pages maximum |
| CISO / Security Team | Specific control failures, technical root causes, prioritized remediation | Detailed Findings | Technical, specific, evidence-based, actionable |
| IT Operations | Systems affected, remediation steps, implementation guidance | Detailed Findings + Recommendations | Technical, step-by-step, system-specific |
| Compliance / Legal | Regulatory gaps, compliance status, legal risk exposure | Findings mapped to regulatory requirements | Regulatory language, framework references, risk of penalties |
| External Auditors / Regulators | Methodology, evidence sufficiency, professional standards adherence | Full report + Working Papers | Formal, standards-based, thoroughly documented |
Crafting an Effective Executive Summary
The executive summary is often the only section that board members and C-suite executives read in its entirety. It must convey the essential message in one to two pages: what was evaluated, what the key risks are, and what needs to happen next. The executive summary should not simply list all findings — it should synthesize them into a narrative about the organization's overall security posture and the most important actions needed to reduce risk.
- Scope Overview: One to two sentences describing what was audited and the period covered.
- Overall Assessment: A clear statement of the organization's overall security posture — is it strong, adequate, or deficient? Avoid ambiguous language.
- Key Statistics: Summary metrics such as the total number of findings by severity (e.g., 2 Critical, 5 High, 8 Medium, 3 Low) presented as a visual chart or table.
- Top Three to Five Risks: The most significant findings summarized in business language, emphasizing the potential impact to the organization rather than technical details.
- Strategic Recommendations: High-level actions needed, including any resource or investment requirements. Frame recommendations as business decisions, not technical tasks.
- Positive Observations: Acknowledge areas of strength. A balanced report that recognizes effective controls alongside deficiencies is more credible and better received.
Remediation Tracking & Re-testing
From Findings to Remediation
Issuing the audit report is not the end of the audit process — it is the beginning of remediation. The value of an audit is realized only when findings are remediated and the organization's risk posture improves. Effective remediation tracking ensures that findings do not languish in a report but are assigned to owners, tracked against deadlines, and verified through re-testing. Without structured remediation tracking, audit findings become a recurring annual exercise that identifies the same problems year after year.
Building a Remediation Tracking Process
- Remediation Plan: For each finding, the management response should include specific remediation actions, the responsible person or team, a target completion date, and any dependencies or resource requirements.
- Tracking Mechanism: Findings should be tracked in a centralized system — whether a GRC platform, a spreadsheet, or a project management tool — that provides visibility into the status of each finding across the organization.
- Status Updates: Responsible parties should provide regular status updates on remediation progress. Monthly updates are typical for high-severity findings; quarterly for medium and low.
- Escalation Process: Define what happens when remediation deadlines are missed. A clear escalation path ensures that overdue findings receive management attention rather than being quietly extended.
- Risk Acceptance Process: If management decides not to remediate a finding, there should be a formal risk acceptance process requiring documentation of the rationale, the residual risk, and approval by an appropriate authority level (typically a senior executive or the board for high and critical findings).
Re-testing and Closure
When management reports that a finding has been remediated, the auditor should perform re-testing to verify that the remediation was effective. Re-testing applies the same testing procedures used during the original audit to confirm that the control deficiency has been corrected. A finding should not be closed based solely on management's assertion that it has been fixed — independent verification is essential to maintain audit integrity.
- Use the Same Test: Apply the same testing procedure that identified the original finding. If you sampled access requests and found missing approvals, sample a new set of access requests from the period after remediation to verify approvals are now in place.
- Verify the Root Cause Fix: Do not just test whether the symptom is gone — verify that the root cause has been addressed. If the finding was orphaned accounts caused by manual offboarding, verify that the automated deactivation process is now working, not just that the specific orphaned accounts were disabled.
- Document the Re-test: Record the re-testing procedure, evidence obtained, and conclusion in the working papers. The re-test documentation should be as rigorous as the original testing.
- Close or Escalate: If re-testing confirms effective remediation, close the finding. If re-testing shows the remediation was ineffective or incomplete, keep the finding open and escalate to management with a revised target date.
| Stage | Description | Responsible Party |
|---|---|---|
| Identified | Finding documented in the audit report with risk rating and recommendation | Auditor |
| Acknowledged | Management response received — agree or disagree, remediation plan documented | Management |
| In Remediation | Remediation actions are underway with regular status updates | Finding Owner |
| Remediation Complete | Management asserts the finding has been fixed | Finding Owner |
| Re-tested | Auditor independently verifies the remediation through re-testing | Auditor |
| Closed | Re-testing confirms effective remediation; finding is formally closed | Auditor |
Chapter quiz
Reporting & Remediation Quiz
6 questions · passing score 70%
Practice scenario
Drafting Findings for Executive Leadership
You have just completed a cybersecurity audit for NovaTech Industries, a manufacturing company with 1,200 employees and operations across three countries. NovaTech operates industrial control systems (ICS) for its factory floors and has recently migrated its corporate IT infrastructure to Azure. The CISO, Angela Torres, has asked you to prepare the final audit report. The board of directors meeting is in three weeks, and Angela needs the report to support her request for a $2 million cybersecurity budget increase. You have identified 15 findings across the engagement and need to draft the report in a way that is accurate, actionable, and effective for multiple audiences.