River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Audit Committee Report Template

Three documents and three sheets that classify every finding by severity, track how many meetings it has stayed open, and escalate on either test.

Free download  ·  No account needed

Open Audit Items

[Company] — findings this committee tracks across meetings

Severity is one test. Age is a separate one. Either alone can put a finding on the full board's own agenda.

FieldWhat goes in it
IDA number that never changes once assigned
SeverityControl deficiency, significant deficiency, or material weakness, the tier the finding's own facts support
Meetings openEvery consecutive meeting the finding has appeared, carried forward, never reset
Escalated to boardYes the meeting a material weakness is raised, or a lesser tier reaches three meetings open
Closed byThe specific test on the Controls Test Log that passed, never a stated intention

Three severity tiers, one auditing standard

Control deficiencyDesign or operation fails to prevent or detect a misstatement on time
Significant deficiencyLess severe than a material weakness, still important enough to merit attention
Material weaknessA reasonable possibility a material misstatement is not prevented or detected on time

A finding is classified once, on the facts. It is never softened because remediation is already underway, and it never resets because a meeting passed without incident.

Page one for this query splits into a generic checklist and one sharper exception. Diligent's explainer names Audit Background, Findings, Dashboard Reports and Financial Values as standard content, with no severity tiers and no line between a finding and a revenue number. The sharper page, a CFO handbook's issue log, ages every item in calendar-day buckets, zero to ninety, ninety-one to a hundred eighty, then beyond. Its severity scale is a self-built High, Moderate or Low matrix that treats significant deficiency as one clause inside Moderate, not as the tier an auditing standard itself defines.

Larkspur Technologies, Inc., an illustrative software company, shows why age is a separate test. Two former employees kept administrator access to the general ledger system 45 and 62 days after leaving, a significant deficiency raised at the committee's first meeting in Q1 2026. It is still open at the third consecutive meeting this pack is built around, which escalates it to the full board automatically, regardless of the remediation date IT has already missed twice. Severity alone never forces that escalation. Only the running count of meetings crossing this space's own threshold does.

None of that belongs next to a revenue or budget number. NYSE Section 303A.07(b) and Exchange Act Rule 10A-3(b) scope a listed company's audit committee to financial statement integrity, the independent auditor's qualifications, internal audit's own performance, and a standing duty to discuss risk assessment, not to operating results. Diligent's own list folds a Financial Values section into the same report anyway. This pack keeps the two apart on purpose: the board's own financial package carries the numbers, and this memo carries only what the charter puts in front of the committee.

One committee meeting, three files, and the escalation the register catches on its own

The Open Audit Items register, the Controls Test Log, and the Audit Committee Memo.

Open Audit Items

Larkspur Technologies, Inc., an illustrative company. Q3 2026 meeting, 2026-08-12. Five findings since the committee's first meeting in Q1 2026.

IDCycleSeverityStatusMeetings OpenEscalated
OAI-01Revenue recognitionSignificant deficiencyClosed 2026-08-042No
OAI-02Procure-to-payMaterial weaknessClosed 2026-03-041No
OAI-03Equity compensationControl deficiencyOpen2No
OAI-04IT general controlsSignificant deficiencyOpen3Yes, this meeting
OAI-05Revenue / contractingControl deficiencyOpen, new1No

OAI-04 is a significant deficiency, one tier below the top, and severity alone would not escalate it. Three consecutive meetings open did, automatically, regardless of the remediation date IT already missed twice.

Controls Test Log

Testing performed since the Q2 2026 meeting (2026-05-13).

ControlSampleResultException RateItem
GL access revoked within 5 days of termination9 of 92 exceptions: 45 and 62 days late22.2%Opens OAI-04
Contract start date, second approver40 of 400 exceptions0.0%Closes OAI-01
AP vendor-create / payment-approve split25 of 250 exceptions0.0%Closes OAI-02
Discount schedule, second signature22 of 223 exceptions: one director, no second signature13.6%Opens OAI-05
Option grant vs. incentive pool checkNo sampleNot yet live, walkthrough onlyOAI-03 stays open

Every closed finding closes on a sampled reperformance passing at zero exceptions, never on a stated intention. The grant-pool check has no result at all, because a control that is not live cannot be tested for operating effectiveness.

Audit Committee Memo — escalated this meeting

Q3 2026, 2026-08-12. Scoped to financial statement integrity, the auditor relationship, and risk. Never revenue or budget performance.

OAI-04, IT general controls, significant deficiency. Two former employees kept administrator access to the general ledger system 45 and 62 days after leaving. Raised at the Q1 2026 meeting, it is now open at its third consecutive meeting, which escalates it to the full board automatically, regardless of the 2026-05-15 target date IT already missed twice.

This meetingCount
Findings open3
Closed this period2
New this period1
Escalated to board1

The severity classification alone would not have forced this escalation. A significant deficiency is not a material weakness. Age is a separate test, and this is the finding it exists to catch.

What's in the pack

01

Open Audit Items sheet

Every finding since the committee's first meeting, with its severity tier, owner, target date and a running count of how many consecutive meetings it has stayed open, never reset while it is still open. Feeds the audit preparation pack's own tracker with what fieldwork will re-test.

02

Controls Test Log sheet

What was actually tested this period, the real sample or population, the result and the exception rate, so a closed finding traces to a passed test. Pairs with the audit confirmation tracker for whatever this cycle also needs confirmed by a third party.

03

Risk Register sheet

The risks this committee's charter puts in its own lane, concentration, key-person dependency, cybersecurity, each carrying likelihood, impact, trend and mitigation status, reviewed every meeting whether or not it moved.

04

Audit Committee Memo

This meeting's assembled memo, opening with whatever escalated to the full board and why, then the register's severity mix, the period's testing, and the risks that moved, with no revenue or budget figure inside it.

05

Controls Update

The narrative behind each row on the Controls Test Log: what was tested, the exact sample, the result, and the specific cause behind any exception. The segregation of duties review is what catches this kind of gap before it is ever tested here.

06

Risk Narrative

What moved on the Risk Register since last meeting and why, in one paragraph per risk that changed, plus one line naming every risk that did not, so the committee sees the whole register was reviewed.

07

Space rule

A finding is classified into one of three severity tiers on its own facts, ages by meetings rather than resetting, and a material weakness or a finding at three consecutive meetings escalates to the board automatically. It governs every prompt in the space.

How to use it

  1. 1

    Open in River, or download it

    Open the pack in River and let the agent build the register from your prior meeting's files, or download the blank Word and CSV files instantly with no account.

  2. 2

    Send the prior register and this period's testing

    The Open Audit Items register from the last meeting if one exists, plus whatever controls testing was performed and any risk updates since. A first meeting starts from whatever findings are already known.

  3. 3

    The register rolls forward, not restarts

    Every open finding carries its ID, severity and meetings-open count forward, closes only on a passed test from the Controls Test Log, and flags anything that crosses this space's escalation rule.

  4. 4

    The memo and narratives draft from the sheets

    The Audit Committee Memo, Controls Update and Risk Narrative get drafted from the two registers once testing and risk information are in, opening with whatever escalated this meeting.

Frequently asked questions

Is this template free?

Completely. Take the Word documents and CSV sheets with no signup, no card and no trial. Edit with AI is an optional second path for anyone who would rather the agent roll the register forward from a real prior meeting than reconstruct it by hand. More packs sit in the template library.

What's the difference between a significant deficiency and a material weakness?

PCAOB AS 1305 defines both. A material weakness carries a reasonable possibility a material misstatement is not prevented or detected on time. A significant deficiency is less severe but still important enough to merit this committee's attention. The pack classifies every finding using those two definitions directly, not a house scale.

What makes a finding escalate to the full board automatically?

Either of two tests, and each one alone is enough. A material weakness escalates the meeting it is raised, regardless of age. A significant deficiency or material weakness still open at its third consecutive meeting escalates too, independent of whatever target remediation date its owner set.

Does this replace the quarterly finance review or the board's financial package?

No. The quarterly finance review and the board's own financial package track performance, department by department and company-wide. This memo carries only what an audit committee's charter puts in front of it: controls, the auditor relationship, and risk, with no performance figure inside it.

What happens at the committee's first meeting, with no prior register?

The register starts from whatever findings, controls testing or risks are already known going in, each gets its severity tier and a meetings-open count of one, and it rolls forward from there. Nothing needs to be reconstructed from an earlier period that never had one.

What format are the downloaded files?

Three .docx documents covering the memo, the controls update and the risk narrative, plus three .csv sheets for the register, the test log and the risk register, all in one zip. Everything opens natively in Word, Excel, Google Docs and Sheets with no conversion step.

Track a finding across meetings, not just inside one report

Download the blank pack as Word and CSV files, or open it in River and let the agent roll your register forward with severity and age both applied.

Edit with AI