KITE 2025 New Product Award — Local IT | SACEEC

What Is an Audit Finding? The 5 C's, Severity Ratings and How to Write One

A good audit finding does more than point out a problem. It makes the case for action. Here is the structure, the severity scale, and a worked example.

Free PDF GuideDownload this guide as a PDF

An audit finding is the basic unit of an audit report, the way an issue is communicated so that management understands it, agrees with it, and acts on it. A weak finding gets argued away or ignored. A well-built one is hard to dismiss because it lays out the standard, the gap, the cause, the consequence, and the fix. This guide explains the 5 C's, how to rate findings by severity, and how to write findings that drive change.

Watch: What is an audit finding Watch: Writing audit findings with the 5 C's (short tutorial)
i

What You'll Learn

This article explains what an audit finding is, the five components (the 5 C's) that make a finding complete, how to rate findings by severity, how to write findings clearly, what a good management response looks like, and a fully worked example finding.

What Is an Audit Finding?

An audit finding is a documented conclusion that something is not operating as it should, a gap between what is required and what the auditor observed. Findings emerge from testing during an audit and are the substance of the audit report.

A finding is not just "we noticed a problem." It is a reasoned argument: here is the expectation, here is what we actually found, here is why it happened, here is what it could cost you, and here is what should be done about it. That argument is what persuades management to act, and what holds up if the finding is challenged.

Want the full framework with worked examples?

The 5 C's of an Audit Finding

The classic structure for a complete finding is the 5 C's. Each answers a question the reader will inevitably ask:

Element Question it answers In short
Criteria What should be happening? The standard, policy, law, or control objective
Condition What is actually happening? The factual observation, with evidence
Cause Why is it happening? The root cause of the gap
Consequence So what? Why does it matter? The actual or potential impact (the "effect")
Corrective Action What should be done? The recommendation and agreed remediation

Criteria

The criteria is the benchmark, what the auditor measured the condition against. It might be a law or regulation, an internal policy, a contractual term, an industry standard, or a control objective. Without explicit criteria, a finding is just an opinion. State it precisely: "Policy FIN-04 requires dual authorisation of payments above R50,000."

Condition

The condition is what the auditor actually found, supported by evidence from the working papers. Be factual and specific. Reach for numbers, not adjectives: "In a sample of 40 payments above R50,000, 7 (18%) were released with a single authoriser."

Cause

The cause explains why the gap exists. This is the element auditors most often skip, yet it is what makes remediation possible, because you cannot fix a problem whose root cause you have not identified. Push past the symptom: the cause of unauthorised payments is rarely "people are careless," it is more often "the payment system does not enforce the dual-authorisation rule, so it relies on memory."

Consequence

The consequence (or effect) is the answer to "so what?" It connects the condition to something the organisation cares about: financial loss, regulatory penalty, reputational damage, operational disruption. Quantify it where you can. The consequence is what determines the finding's severity rating and what motivates management to act.

Corrective Action

The corrective action is the recommendation, and after the closing meeting, the agreed remediation with an owner and a due date. The best recommendations address the cause, not just the symptom: configuring the system to enforce dual authorisation is more durable than reminding staff to follow the rule.

i

Pro Tip

If you can only strengthen one element of your findings, strengthen the cause. Findings that name a clear root cause produce corrective actions that actually fix the problem; findings without one produce band-aid fixes that fail and reappear at the next audit.

Rating Findings by Severity

Not every finding is equally important, and a report that treats them all the same buries the issues that matter. Each finding is assigned a severity rating so the reader, especially the audit committee, knows where to focus.

Rating Meaning Typical response
Critical / High Significant exposure; control failure with material impact, fraud risk, or regulatory breach Immediate executive attention; remediate now
Medium Meaningful control weakness with moderate impact Remediate on an agreed near-term plan
Low Minor issue or efficiency opportunity; limited impact Address when convenient; monitor

Severity is driven mainly by the consequence (potential impact) and the likelihood of that impact occurring, the same likelihood-and-impact logic used in risk scoring. A control gap with catastrophic potential consequence rates high even if it has not yet caused a loss. Many functions also assign the audit an overall opinion (for example, Satisfactory, Needs Improvement, Unsatisfactory) that reflects the worst findings.

!

Important

Rate the finding on its risk, not on management's appetite to fix it. If a high-severity issue is downgraded because remediation is awkward or expensive, the rating loses meaning and the audit committee is misled about the organisation's true exposure.

Writing Clear Findings

A finding can be technically complete and still fail because no one acts on it. Clarity is what closes that gap. A few principles:

  • Lead with the issue, not the background. The reader should grasp the problem in the first sentence.
  • Be specific and factual. "7 of 40 payments" beats "several payments." Numbers are harder to argue with than adjectives.
  • Separate fact from opinion. The condition is observed fact; the consequence and recommendation are reasoned judgement. Keep them distinct.
  • Address the cause in the recommendation. A fix that does not touch the root cause is a temporary one.
  • Be constructive, not accusatory. Findings describe process and control gaps, not personal failings. The goal is improvement, not blame.
Example

A complete finding write-up

Title: Dual authorisation not enforced for high-value payments (High)

Criteria: Policy FIN-04 requires two authorisers for any payment above R50,000.

Condition: In a sample of 40 payments above R50,000 processed between January and April 2026, 7 (18%) were released with only one authoriser. Evidence retained in working paper PTP-12.

Cause: The payment system permits single-authoriser release; the dual-authorisation rule is enforced manually and relies on staff remembering to apply it.

Consequence: Without enforced dual authorisation, a single individual can release large payments unilaterally, creating fraud and error exposure. The 7 payments tested totalled R2.3 million; the full-year population is approximately R140 million.

Corrective Action (agreed): Configure the payment system to block release of payments above R50,000 until a second authoriser approves. Owner: Finance Systems Manager. Due: 31 July 2026.

Management Responses

Every finding receives a management response: management's agreement (or disagreement) with the finding and their commitment to act. A good response states what will be done, who owns it, and by when. It is recorded in the report alongside the finding.

Where management disagrees, the disagreement is documented rather than suppressed, so the audit committee can then weigh both positions. Where management accepts the risk instead of remediating, that risk acceptance should be made by someone with the authority to own the residual exposure, and it should be visible to the audit committee. A response of "noted" with no action, owner, or date is not a response. It is a deferral, and it should be challenged.

Once actions are agreed, they feed the follow-up process. Internal audit tracks each one to closure (see tracking audit recommendations) and reports progress, including overdue items, to the audit committee.

Common Mistakes to Avoid

1. Stating the condition without the criteria

"Payments were released by one person" is meaningless until you say what the policy required. Without criteria there is no finding, only an observation.

2. Skipping the cause

A finding with no root cause leads to a symptomatic fix that fails. The cause is what makes remediation durable.

3. A vague consequence

"This is a risk" answers nothing. Connect the condition to a concrete, ideally quantified, impact so severity is justified.

4. Recommendations that do not match the cause

If the cause is a system gap, "remind staff to follow the policy" will not fix it. Align the recommendation to the root cause.

5. Accepting hollow management responses

"Noted" with no owner or date is not a commitment. Insist on a specific action, an accountable owner, and a due date.

Key Takeaways

Summary

  • An audit finding is a reasoned case for action, not just a flagged problem
  • The 5 C's (criteria, condition, cause, consequence, corrective action) make a finding complete
  • The cause is the most-skipped and most important element; it drives durable fixes
  • Rate findings by severity based on impact and likelihood, not on ease of remediation
  • Write findings factually and specifically, with numbers rather than adjectives
  • Every finding needs a management response with an owner and a due date

Frequently Asked Questions

What are the 5 C's of an audit finding?

Criteria (what should happen), Condition (what is happening), Cause (why it happens), Consequence (why it matters), and Corrective Action (what to do about it). Together they turn an observation into a complete, defensible finding.

What is the difference between condition and criteria?

Criteria is the standard, what should be happening (a policy, law, or control objective). Condition is what the auditor actually observed. The finding is the gap between the two. Criteria without condition is just a rule; condition without criteria is just an observation.

How are audit findings rated?

Findings are usually rated High, Medium, or Low based on the severity of the consequence and the likelihood of it occurring, the same impact-and-likelihood logic used in risk scoring. The rating tells the reader where to focus attention.

Why is the cause so important in a finding?

Because you cannot durably fix a problem whose root cause you have not identified. A finding that names the real cause produces a corrective action that actually resolves the issue; one that addresses only the symptom produces a fix that fails and the issue reappears.

What makes a good management response?

A specific commitment: what will be done, who owns it, and by when. "Noted" with no action, owner, or date is not a response. Where management accepts the risk instead of fixing it, that decision should be made by someone authorised to own the exposure and be visible to the audit committee.

What happens to a finding after the report is issued?

The agreed corrective action is tracked to closure by internal audit, which verifies it was implemented and effective, not just marked done. Overdue actions are escalated to the audit committee. See tracking audit recommendations for how this works in practice.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.