This page defines the standard for writing audit reports within AuditFlow OS.

It helps users write reports that are clear, concise, evidence-based, risk-focused, and consistent across cyber, AI, data, governance, third-party, and IS4-style audits.

This standard applies to audit reports and reporting notes produced through AuditFlow OS.


Purpose

The purpose of this standard is to:

Reports should communicate the control position clearly, not simply describe audit activity.


Writing Principles

All reports should follow these principles.

1. Clear

Reports should be written in plain, professional language. The reader should understand the main message quickly.

2. Evidence-based

Conclusions, findings, and ratings should be supported by evidence obtained during the audit.