Internal audit form template: the fields a working paper needs so the audit can be re-performed by somebody else

An internal audit form is not paperwork, it is a working paper, and the test of a good one is whether another auditor could pick it up a year later and repeat what you did. Most templates fail that test because they capture the conclusion and not the work: a checklist of requirements with a tick, a cross and a comment box. The fields that matter are the ones that record what population you drew from, what you actually looked at, and what you saw, because those are the fields that make a finding survive being argued with by the person it is about.

The header fields, which are more than admin

Audit reference, date, auditor, and the area audited are obvious. The two that get left out and matter most are the criteria, meaning the exact clause, procedure or requirement being tested, and the period covered. Without the criteria, a disagreement about a finding becomes a disagreement about what the rule is, which nobody can settle from the form. Without the period, a sample cannot be judged as representative, and a repeat audit next year has nothing to compare against.

The evidence fields, one row per test

One row per test, and each row needs the population the sample came from, how many items were examined, how they were selected, and identifiers for the actual items. Identifiers are the part people skip, and they are what makes the work re-performable: a row saying five purchase orders were checked is an assertion, while a row listing five purchase order numbers is evidence. Add a field for what was observed, written as fact rather than judgement, and keep the conclusion in a separate column so the two never blur.

The finding fields that let a finding be closed

A finding needs the requirement it fails, the evidence that shows the failure, a grade from a defined scale, an owner, and a due date. It should not contain the solution: an auditor who writes the corrective action has audited their own recommendation at the next visit. Leave a field for the response and one for the effectiveness check after closure, with its own date. Forms that stop at closure are the reason repeat findings recur, because nobody ever went back to see whether the fix worked.

What to leave out

Scoring columns that add up to a percentage, which convert a set of specific failures into a number that hides them. Free-text boxes for general impressions, which invite opinion into a record meant to hold evidence. And pre-printed requirement lists so long that the form becomes a compliance exercise in itself. A shorter form used properly produces better audits than a comprehensive one that gets filled in from memory on the train home.

Questions people ask about internal audit form template

Should the form list every requirement in the standard?

No. The plan decides which requirements this audit covers, and the form records the tests done. A form that restates the whole standard encourages ticking rather than testing.

Paper or a system?

Either, as long as the record is retained, attributable and unaltered after sign-off. A system helps most with the parts people forget: due dates on findings, and the effectiveness check after closure.

How long should working papers be kept?

At least across the certification or audit cycle so the next auditor can compare, and longer where a regulator or a contract sets a retention period. Findings and closures are usually kept longer than the underlying test sheets.

Who signs the form?

The auditor, and the area representative for agreement on the facts rather than on the conclusion. Separating factual agreement from conclusion is what keeps a disputed finding from becoming a disputed transcript.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder