Looking at audit reporting
Audit reporting is how the outcome of an audit is conveyed to the client. The audit report shows all the audit information, its noncomplying items, observations, audit conclusions, and other comments. It is the lead auditor who is accountable for the accuracy and completeness of the report. The audit plan is where what goes into the audit report (the content) is decided.
In the audit report, the final results are formally documented and disseminated. In addition to giving a record of the audit’s results, this provides everyone with a reference to the outcome of the audit. It is the client who becomes the owner of the report and decides its distribution. Ideally, an audit report should add value to the organization’s Information Security Management System (ISMS).
The audit report
Reporting audit findings is the responsibility of the lead auditor who must follow the audit plan. To give a full, correct, concise, and complete result of...