Skip to content
slide-deck.io
BlogGet started free

August 15, 2026

How to Create a Financial Audit Findings Deck

An audit findings presentation bridges the technical work of an audit engagement with the management and governance audience who must act on the results. The goal is not to demonstrate how many issues you found but to ensure the right people understand the right risks and take the right corrective actions.

Who Receives Audit Findings Presentations

  • Audit committee: Governance-focused; interested in risk severity, management's response, and whether controls provide adequate oversight
  • Senior management (CFO, Controller): Operationally focused; need to understand findings deeply enough to design and implement remediation
  • External auditors (for internal audit communications): Need to understand control gaps that may affect the scope or approach of the financial statement audit
  • Regulators: Focused on compliance and systemic risk; require precise, factual language

Tailor the depth and language of your presentation to the audience. An audit committee needs risk-level summary; the controller needs root-cause detail.

The Anatomy of a Well-Written Finding

Before building slides, understand what makes a finding clear and actionable. Each finding should contain:

Condition: What is the current state? What did you observe?

Criteria: What should the state be? What does the policy, procedure, law, or best practice require?

Cause: Why does the gap exist? Root cause, not just symptom.

Effect: What is the actual or potential impact of the condition? Quantify where possible.

Recommendation: What specific action should management take?

Management Response: Management's commitment to address the finding, including responsible owner and target completion date.

Every finding in your deck should have all six elements. Findings that are vague about criteria or effect are difficult to remediate because management cannot determine the standard they are being held to.

Slide Structure

Slide 1: Engagement Overview

  • Audit entity and scope
  • Audit period or point-in-time date
  • Audit objectives
  • Audit standards followed (if applicable: IIA Standards, GAAS, PCAOB)
  • Report date

Slide 2: Executive Summary

One slide with the high-level results:

  • Total number of findings by risk rating (Critical, High, Medium, Low)
  • Number of repeat findings from prior audits
  • Scope areas with no findings (if any)
  • Overall conclusion statement: "The audit identified X high-risk findings that require immediate management attention in the areas of [Y and Z]."

For board-level presentations, some organizations use a one-slide heatmap plotting findings by likelihood and impact. This quickly communicates risk concentration.

Slide 3: Scope and Methodology

Briefly cover:

  • What processes, systems, or accounts were in scope
  • What was explicitly excluded and why
  • Audit methodology: walkthrough procedures, control testing sample sizes, substantive testing approach
  • Any limitations that affected the audit scope

This slide provides context for what the findings do and do not represent. An audit that covered three of fifteen processes cannot be interpreted as a clean bill of health for all fifteen.

Slide 4+: Individual Findings

One slide per finding (or a condensed format showing two findings per slide for lower-risk items). Each finding slide should cover:

Finding Title: Short, descriptive, action-oriented. "Revenue Recognition Controls Over Non-Standard Contracts Are Insufficient" is better than "Finding #3: Revenue."

Risk Rating: Critical / High / Medium / Low with your organization's definition of each rating clearly established in the methodology slide.

Condition: Factual statement of what you observed. "During our review of 25 non-standard contract modifications, 8 (32%) were recorded in the incorrect period based on the terms of the modification agreement."

Criteria: The standard being applied. "Per ASC 606 and company policy [reference], contract modifications that do not add distinct goods or services at their standalone selling price require reassessment of the original contract performance obligations as of the modification date."

Cause: "The revenue team does not have a standardized review process for non-standard contract modifications. The existing contract review checklist was developed before the adoption of ASC 606 and has not been updated."

Effect: "Misapplication of revenue recognition guidance in the eight identified instances resulted in $X of revenue recorded in the wrong period. Based on extrapolation to the full population, the potential impact could be material."

Recommendation: "Management should (1) implement a secondary review requirement for all non-standard contract modifications, (2) update the contract review checklist to include ASC 606-specific guidance, and (3) conduct a retrospective review of all non-standard contract modifications processed in the past twelve months."

Management Response: "Agree. The Controller will update the checklist by [date] and implement the secondary review requirement by [date]. The retrospective review will be completed by [date]."

Slide: Findings Summary Table

After individual finding slides, include a master table:

| # | Finding | Risk | Status | Owner | Due Date | |---|---------|------|--------|-------|---------| | 1 | Revenue recognition controls | High | Open | Controller | [Date] | | 2 | ... | | | | |

This gives management and the audit committee a single reference for tracking remediation status over time.

Slide: Repeat Findings

If any findings are repeats from prior audit cycles, flag them prominently. Repeat findings signal that prior management responses were inadequate or not implemented. They carry more weight in audit committee deliberations and may warrant a more serious remediation commitment.

For each repeat finding, show when it was first identified and what management committed to do at that time.

Slide: Positive Observations

Some audit teams include a brief section on control strengths or notable improvements since the prior audit. This balanced approach is appropriate when the relationship between internal audit and management is collaborative rather than adversarial. It also provides context — management teams that have made genuine improvements deserve acknowledgment.

Slide: Remediation Timeline

Show all open findings plotted against their committed remediation dates:

| Finding | Risk | Target Date | Status | |---------|------|-------------|--------| | | | | |

Use color coding (red = past due, yellow = due within 30 days, green = on track). This slide is particularly useful for audit committee reporting in subsequent quarters.

Language and Tone Considerations

Be precise, not inflammatory. "Controls are insufficient to prevent unauthorized access" is better than "controls are broken" or "there is no security." Precise language supports remediation; loaded language creates defensiveness.

Avoid legal exposure. Internal audit reports are often discoverable in litigation. Avoid characterizing findings as "fraud," "intentional," or "negligent" unless you have concluded a formal investigation with appropriate legal counsel involved. State the condition and effect factually.

Use passive voice carefully. "Revenue was misclassified" may be appropriate in some contexts. "The accounting team misclassified revenue" makes an attribution that may not be warranted by the evidence and can create interpersonal problems that undermine your relationship with management.

Quantify whenever possible. A finding that affects $4.2M of revenue is more actionable than one that "may have a material impact." If you cannot quantify, explain why and provide reasonable bounds.

Presenting to the Audit Committee

Audit committee members are typically experienced financial professionals with limited time. Assume they have read the written report before the meeting. Use the presentation time for:

  • Highlighting the two or three findings you consider most significant and why
  • Discussing management's responsiveness and the adequacy of proposed remediation
  • Addressing any areas of disagreement between audit and management
  • Answering questions from committee members

Do not read findings verbatim from the slides. Explain the business risk in plain language and demonstrate that you understand the control environment well enough to have a real conversation about it.

A well-structured audit findings presentation that is clear, factual, and action-oriented accelerates remediation, strengthens governance, and builds credibility for the internal audit function.

Build your next presentation with AI

Generate editable .pptx decks in minutes. Free to start — no card required.

Try it free →