Why the Audit Report Is the Whole Point
You can run a technically brilliant audit, ask sharp questions, gather solid evidence, and correctly classify every finding. But if the report that comes out the other end is vague, disorganised, or missing critical information, the audit has not done its job. The report is what the client, the auditee, and anyone acting on the findings will rely on. Everything else is preparation.
On this page
On site audit reports are not just a formality. They are the formal record of what was examined, what was found, and what conclusion was reached. They need to stand up to scrutiny, sometimes months or years later, when someone asks why a particular decision was made or whether a corrective action was properly verified.
This article walks through what belongs in an on site audit report, why each element matters, and how to structure it so that it actually gets read and acted upon. The focus here is on reports produced during or immediately after the on site phase of an audit, whether that is an internal audit, a supplier audit, or a certification audit.
The Difference Between an Audit Report and Audit Notes
Before getting into content, it is worth being clear on what an on site audit report actually is. During fieldwork, auditors take notes, fill in checklists, and record evidence in working papers. Those are not the report. The report is the formal document that summarises the audit, communicates findings to the relevant parties, and provides a basis for follow up action.
Some auditors confuse detailed working papers with the report itself. The working papers are your internal record. The report is the output that goes to the audit client and the auditee. It needs to be readable by someone who was not in the room during the audit.
In practice, for internal audits, the same person often writes both. But the discipline of treating them as separate outputs matters. Your notes can be messy and detailed. Your report needs to be clear, structured, and complete.
Exemplar Global Recognised Training ProviderRTP No. 310970Core Elements Every On Site Audit Report Must Include
Audit Identification Information
Every report needs a header section that identifies the audit clearly. This sounds obvious, but reports without proper identification cause real problems when organisations have multiple audits running across different departments or sites.
The identification section should include the name of the organisation or department audited, the audit date or dates, the audit type (internal, second party, or third party), the standard or criteria audited against, the report number or reference, and the date the report was issued. For multi site or multi day audits, you also want the specific location or scope covered by that particular report.
This information lets anyone picking up the report six months later know exactly what they are looking at without having to dig through attachments or email threads.
Audit Scope and Objectives
The scope tells the reader what was included and, just as importantly, what was excluded. A report that says nothing about scope leaves the reader guessing whether a finding represents a gap in the system or simply something that was not examined.
State the scope plainly. For example:
This audit covered the design and development process under Clause 8.3 of ISO 9001:2015, including design inputs, design outputs, design reviews, verification, and validation activities at the Brisbane facility. Purchasing and production were excluded from this audit cycle.
The objectives explain what the audit was trying to achieve. For an internal audit, this might be to determine conformity with the standard, to evaluate the effectiveness of the quality management system, or to identify opportunities for improvement. For a supplier audit, the objective might be to assess the supplier's capability to meet specified requirements before contract award.
Stating objectives matters because it frames the findings. A finding that looks minor in isolation might be significant in the context of the audit's objective.
Audit Team and Auditee Representatives
Record who conducted the audit and who participated on behalf of the auditee. This includes the lead auditor, any team members, technical experts, and observers. On the auditee side, note the names and roles of the people interviewed or who accompanied the audit team.
This is not just administrative housekeeping. It establishes accountability. If a finding is later disputed, the record of who was present and who provided information matters. It also confirms that the audit was conducted by someone with appropriate independence, which is a requirement under ISO 19011.
Audit Criteria
The audit criteria are the reference against which conformity is assessed. For an ISO 9001 internal audit, the criteria include the standard itself, the organisation's own documented procedures and policies, and any relevant statutory or regulatory requirements.
List the criteria explicitly. Do not assume the reader knows. A report that simply says
nonconformity foundwithout stating what requirement was not met is not a usable document. The criteria section provides the baseline that makes every finding meaningful.
Summary of Activities Conducted
Include a brief summary of what the audit team actually did during the on site phase. This covers the processes reviewed, the areas visited, the records sampled, and the interviews conducted. You do not need to reproduce your working papers here. A concise paragraph or short list is sufficient.
For example:
The audit team reviewed the documented quality management system, sampled 12 customer orders from the past quarter, inspected the production floor and raw material storage areas, and conducted interviews with the production manager, two shift supervisors, and the quality technician.
This gives the reader confidence that the audit was substantive and helps contextualise the findings. If a major process was not covered, this section makes that visible.
Findings: The Heart of the Report
How to Classify and Present Findings
Findings are where most of the report's value sits, and where most poorly written reports fall apart. Each finding needs to be clearly classified, clearly described, and linked to specific evidence and specific requirements.
The standard classifications used in ISO auditing are nonconformity (which can be major or minor), observation or opportunity for improvement, and sometimes a positive finding. Each classification has a different implication for what the auditee needs to do next.
A major nonconformity indicates a systematic failure or absence of a required element that is likely to affect the ability of the management system to achieve its intended outcomes. A minor nonconformity is an isolated lapse or a less critical gap. An observation or opportunity for improvement is a situation that does not constitute a nonconformity but where improvement would be beneficial.
For a deeper look at how these classifications work in practice, the article What Is an Audit Finding vs Observation vs Nonconformity is worth reading before you sit down to write your report.
Writing Each Finding Properly
Each finding in the report should follow a consistent structure. State the requirement, describe the observed situation, provide the specific evidence, and classify the finding. This four part structure is not bureaucratic padding. It is what makes a finding defensible and actionable.
Consider the difference between these two versions of the same finding:
Version one:
Calibration records were not up to date.
Version two:
ISO 9001:2015 Clause 7.1.5.1 requires that the organisation retain documented information as evidence of fitness for purpose of monitoring and measurement resources. During the audit, calibration records for three of five pressure gauges used in the production process (serial numbers PG-004, PG-007, and PG-011) were found to be overdue by between 3 and 8 months. The last calibration dates recorded were March, January, and October of the prior year respectively. This is classified as a minor nonconformity.
The second version can be acted on. The first version cannot. Someone reading version one does not know which records, which equipment, how overdue, or against which requirement. They cannot write a corrective action without going back to the auditor for clarification, which defeats the purpose of the report.
The article How to Write a Nonconformity Report That Actually Gets Fixed covers this in more detail and is worth reading alongside this one.
Positive Findings
Not every audit report needs to be a catalogue of problems. Where the audit team observes genuinely strong practice, particularly practice that goes beyond the minimum requirements of the standard, noting it in the report adds value. It tells the auditee what is working, which is useful for management review and for internal benchmarking.
Keep positive findings brief and specific. A vague statement like
the team was very professionaladds nothing. A specific observation like
the organisation has implemented a real time production monitoring dashboard that provides immediate visibility of defect rates by shift, which represents a well developed approach to performance monitoring under Clause 9.1.1is meaningful.
The Audit Conclusion
The conclusion section is where the lead auditor states the overall outcome of the audit. This is not a summary of individual findings. It is a considered judgement about the state of the management system based on the totality of evidence gathered.
For a certification audit, the conclusion will typically state whether the auditor recommends certification, recommends certification subject to corrective action, or does not recommend certification. For an internal audit, the conclusion might state that the system is generally conforming with identified gaps, or that significant systemic issues were found that require priority attention.
The conclusion should be proportionate and honest. It should not overstate the severity of minor issues or downplay significant gaps to avoid an uncomfortable conversation. Auditors who write conclusions designed to please rather than inform are not doing their job.
The conclusion should also reference the number and classification of findings. For example:
Based on the evidence gathered, the audit team identified one major nonconformity, three minor nonconformities, and two observations. The major nonconformity relates to the absence of a documented internal audit programme as required by Clause 9.2. The overall conclusion is that the management system does not currently meet the requirements for certification recommendation. A follow up audit is required to verify closure of the major nonconformity.
Required Follow Up Actions
The report should clearly state what the auditee is required to do as a result of the findings, and by when. For nonconformities, this means specifying the requirement to conduct root cause analysis and implement corrective action. For certification audits, the timeframes for corrective action response are usually defined by the certification body.
For internal audits, the report should specify who is responsible for responding to each finding and what the expected timeframe is. Leaving this vague creates the conditions for findings to be forgotten or deprioritised.
If your organisation uses a corrective action register or a nonconformity tracking system, the report should reference how findings will be transferred into that system. The audit report is the trigger for corrective action, not the mechanism for tracking it.
Formatting and Presentation
Structure That Aids Readability
A well structured report is not just easier to read. It is more likely to be read at all. Long blocks of unbroken text, inconsistent numbering of findings, and buried conclusions all reduce the chance that the report will be properly understood and acted upon.
Use a consistent structure for every finding. Number each finding so it can be referenced in corrective action responses and follow up audits. Use clear headings to separate the different sections of the report. Keep the executive summary or conclusion near the top so that senior managers can quickly understand the overall outcome without reading every finding in detail.
Language and Tone
Audit reports should be factual, specific, and neutral in tone. They are not the place for editorial commentary, expressions of frustration, or language that could be read as personal criticism of individuals. Findings are about systems and processes, not about people.
Avoid vague language like
it appears thator
it seems as though. If you observed it and have evidence, state it directly. If you are uncertain, do not include it as a finding. The report should reflect what was confirmed, not what was suspected.
For practical guidance on writing reports that people actually engage with, the article Audit Report Writing: How to Communicate Findings Clearly covers the writing side in depth.
Distribution and Confidentiality
The report should include a distribution list that records who receives a copy. For internal audits, this typically includes the auditee, the quality manager, and top management. For supplier audits, the report goes to the audit client and may or may not be shared with the supplier in full, depending on the agreement made before the audit.
Audit reports contain sensitive information about an organisation's systems and gaps. The confidentiality obligations that apply to auditors under ISO 19011 extend to the handling and distribution of the report. Note on the report itself that the contents are confidential and intended for the named recipients only.
Exemplar Global Recognised Training ProviderRTP No. 310970Common Mistakes in On Site Audit Reports
After conducting and reviewing hundreds of audits, the same report writing problems come up repeatedly. Findings without evidence references. Conclusions that do not match the findings. Nonconformities that cite the wrong clause. Reports that list observations but never state a conclusion. Corrective action timeframes that are missing entirely.
One of the most common mistakes is writing findings that describe the symptom without identifying the requirement that was not met. Another is writing findings in a way that is so general they could apply to almost any organisation, which means the auditee cannot tell what specifically needs to be addressed.
The discipline of writing a good audit report is a skill that develops with practice. New auditors benefit significantly from having their reports reviewed by an experienced lead auditor before they are issued. That review process is one of the most valuable forms of on the job development available.
Building Your Report Writing Skills Through Training
Understanding what goes into an on site audit report is one thing. Being able to produce one under time pressure, after a full day of fieldwork, is another. Report writing is a core competency that is assessed in lead auditor courses and in witness audits conducted for auditor certification.
At Audit Workshop, report writing is treated as a practical skill throughout the Internal Auditor and Lead Auditor training programmes. Participants work through real audit scenarios, draft findings, and receive feedback on how to structure and word their reports. The lead auditor courses, which are recognised by Exemplar Global, include report writing exercises that reflect the conditions of actual certification audits.
If you are building your auditing skills and want to develop confidence in producing reports that are clear, defensible, and useful, the training courses at Audit Workshop are designed to get you there through practice, not just theory.













