Skip to main content

Audit report template

A per-audit report setting out scope, findings with severity and management responses, generated from your findings register.

Google Docs PDF export No watermark

Free plan, no credit card. Bring your own design or start from this layout.

The actual template Audit report template shown in Google Docs

What’s in this template

Every block is bound to a field in your data. The layout stays exactly as designed; only the values change from one run to the next.

  • Audit reference, scope and period {{audit.ref}} · {{audit.scope}}
  • Objective and methodology {{audit.method}}
  • Overall opinion and assurance rating {{audit.opinion}}
  • Findings, one block per finding loop: {{findings}}
  • Management response and owner per finding loop: {{responses}}
  • Follow-up actions and due dates loop: {{actions}}

How this template fills itself

Connect Airtable, Google Sheets, a SQL database, a CSV or a REST API, map each field to a placeholder, and generate. One run can produce a single document or one per matching record.

Reports: A per-audit report setting out scope, findings with severity and management responses, generated from your findings register.

Findings · SQL database

RefFindingSeverity
F-014Access reviews not evidencedHigh
F-015Supplier records incompleteMedium
F-016Backup restore test overdueLow

Template: Google Slides or Docs

{{audit.ref}}

{{audit.scope}} · {{audit.period}}

{{audit.opinion}}

loop: {{findings}} → finding block

loop: {{actions}} → table row

one report per audit; findings are filtered to those raised in this engagement

Generated output

DocsPDF

IA-2026-07

Procurement controls · H1 2026

Partial assurance

3 findings: 1 high, 1 medium, 1 low

6 follow-up actions

Who uses this template

Internal audit teams

Issue every engagement in the same house format straight from the findings register.

Read the guide

Compliance and risk

Keep the report, the register and the follow-up tracker showing the same findings at the same severity.

Read the guide

Accounting and advisory firms

Produce client-facing reports across a portfolio of engagements without rekeying the fieldwork.

Read the guide

An audit report is a controlled document. Most of it — the objective, the methodology, the rating definitions — is standing text that must not drift between engagements, and the rest is findings, which vary in number and length. That combination of fixed boilerplate and variable content is exactly what a Google Docs template holds well.

Treat the findings register as the source of record

The risk in audit reporting is divergence: the register says medium, the issued report says high, and the follow-up tracker has neither. Generating the report from the register removes that by construction, because there is only one place a finding exists. Keep severity, recommendation, owner and due date as fields, and let the report print them; when a finding is cleared or downgraded during the management response, change the record and regenerate rather than editing a file that has already been circulated. The follow-up section then falls out of the same data, filtered to actions still open.

Common questions, answered

Where do the findings come from? +
From the register you already maintain during fieldwork, held in Airtable, Google Sheets, a SQL database, a CSV upload or reached through a REST API. Each finding is a record with a reference, severity, recommendation and owner, and the report prints the records belonging to that engagement. Nothing is retyped between the register and the issued report.
How are management responses handled? +
As fields on the finding record, filled in by the owner during clearance. The report is regenerated after responses come back rather than edited, so the issued version always matches the register. If a severity is downgraded during clearance, the change is made once in the data and every reference to it in the document follows.
Can I generate reports for several audits at once? +
Yes. Filter the engagements table to those ready for issue and one run produces a document per audit, each scoped to its own findings and actions. Firms running the same programme across many entities use this to issue a consistent report per entity from a single register.
Can I use our own audit report format? +
Yes, and most audit functions have a mandated one. Rebuild it in Google Docs with your standard wording, section order and rating definitions, mark the variable parts as placeholders, and generate against it. The methodology and boilerplate stay fixed text in the template; only the engagement-specific content is supplied per run.

Generate this document from your data

Start on the free plan, connect a data source, and export a real Google Docs document. No watermark, no credit card.