Skip to content

Presenting Findings to Management and Audit Committees

Forensic auditors must communicate sensitive findings to boards, audit committees, and senior management before a formal report is finalised. This topic covers oral briefing techniques, privileged communications, legal counsel involvement, and the auditor's obligations when findings implicate those at the top of the organisation.

Last updated:

Share

Presenting findings to management and audit committees is the process by which a forensic auditor communicates sensitive investigation results to the organisation's governing bodies before the formal written report is finalised. This communication bridges the gap between the investigative phase, where evidence is still being gathered and analysed, and the remediation phase, where the organisation acts on what has been found. The process requires the auditor to balance transparency about what the evidence shows against confidentiality obligations, legal privilege considerations, and the risk that premature disclosure could prejudice the investigation, alert suspects, or expose the organisation to regulatory sanction.

The audit committee is the auditor's primary reporting line in most corporate governance frameworks. In the US, the Sarbanes-Oxley Act of 2002 (SOX) requires that internal auditors report directly to the audit committee on significant findings. The UK Corporate Governance Code places similar obligations on boards. In India, the Companies Act 2013 mandates an audit committee for listed companies and certain other classes of company, and the committee must review findings from internal and external auditors. These statutory structures exist precisely because management cannot reliably investigate itself: a finding that implicates the CEO or CFO must reach the board through a channel that management cannot block or filter.

The forensic auditor's reporting obligation does not wait for the final written report. Interim oral briefings, sometimes called flash reports, allow the committee or board to take urgent action when the facts warrant it: suspending an employee, freezing accounts, notifying regulators, or securing evidence that might otherwise be destroyed. Managing these interim communications, deciding what to say, in what form, to whom, and in what order, is one of the most professionally demanding aspects of forensic audit practice.

By the end of this topic you will be able to:

  • Explain the governance structure that determines who the forensic auditor reports to and why the audit committee sits above management in the reporting chain.
  • Describe the key techniques for conducting an oral briefing that is clear, accurate, and appropriately confidential.
  • Identify the circumstances in which legal privilege applies to forensic audit communications and the risks that can cause privilege to be lost.
  • Explain the division of roles between forensic auditor and legal counsel in managing information flow to the board and regulators.
  • Describe the auditor's obligations and practical steps when findings implicate a member of senior management.
Key terms
Audit committee
A sub-committee of the board of directors composed principally of independent non-executive directors, responsible for overseeing financial reporting, internal controls, and the internal and external audit functions. The forensic auditor's primary reporting line in most corporate governance frameworks.
Attorney-client privilege (legal professional privilege)
A legal protection that prevents compelled disclosure of confidential communications between a lawyer and their client. In forensic audit engagements structured as legal matters, the audit work product may attract privilege. The scope and conditions vary by jurisdiction.
Work-product doctrine
A US doctrine (and its equivalents in other common-law systems) protecting materials prepared by or for counsel in anticipation of litigation from compelled disclosure to an opposing party. Forensic audit reports commissioned in anticipation of litigation may qualify.
Flash report (preliminary oral briefing)
An interim communication to the audit committee or board during an active investigation, before the formal written report is ready. Used when the findings require immediate action. Should be followed by a written summary to create a contemporaneous record.
Management override
The circumvention of established internal controls by members of senior management. A key fraud risk in any organisation because those who set the controls can also bypass them. Findings of management override must be escalated to the audit committee, bypassing the implicated individuals.
Whistleblower channel
A mechanism for individuals to report suspected misconduct to the audit committee or board directly, bypassing management. Required under SOX in the US for listed companies. Equivalent obligations exist under the UK's Public Interest Disclosure Act 1998 and India's Whistle Blowers Protection Act 2014.

Governance structure and reporting lines

The reporting structure for a forensic audit engagement is not the same as for an ordinary operational audit. In a routine internal audit, findings flow to management, which decides what remedial action to take. In a forensic engagement, particularly one triggered by suspicion of fraud or misconduct, that structure can be compromised if the people the auditor would normally report to are themselves under investigation.

Most corporate governance codes resolve this by giving the audit committee direct oversight of forensic investigations. The committee, composed of independent non-executive directors, sits outside the management hierarchy and can receive findings that management cannot see. The forensic auditor should confirm the reporting line at the outset of the engagement and document it in the engagement letter. If the engagement is triggered by a referral from the audit committee itself, as is common in larger organisations, the reporting line is already established.

ScenarioWho receives preliminary findingsLegal basis
Routine internal fraudCFO and audit committeeAudit committee charter; SOX s.301 (US)
Findings implicate CFOAudit committee only (bypass CFO)SOX s.301; UK CGC Principle M; Companies Act 2013 s.177 (India)
Findings implicate CEOFull board minus CEO; audit committeeBoard duty of care; SRA Code (UK); SEBI LODR (India)
Findings involve external parties onlyManagement and audit committee jointlyStandard engagement terms

In practice, the audit committee chair is usually the first point of contact for urgent oral briefings. The chair decides whether to convene the full committee, bring in additional independent directors, or involve the full board. This decision is theirs, not the auditor's. The auditor's role is to provide accurate, timely information and to flag clearly when the matter is urgent enough to require an immediate meeting rather than the next scheduled session.

Oral briefing techniques

An oral briefing to an audit committee is not an informal conversation. It is a professional communication with legal and practical consequences. The auditor should prepare as carefully as for a written report: organise the findings in a logical sequence, distinguish clearly between what the evidence shows and what it does not yet show, and avoid drawing conclusions that go beyond the evidence at hand.

The standard structure for a forensic briefing is: scope and mandate (what the auditor was asked to do), methodology (how the work was carried out and what its limitations are), findings (what the evidence shows, presented factually and without editorial characterisation), and next steps (what further investigation is needed or what immediate actions are recommended). This structure prevents the common problem of briefings that lead with conclusions without providing the evidentiary basis, which leaves committee members unable to evaluate the quality of the finding.

Confidentiality of the briefing itself must be addressed explicitly. The auditor should ask the committee to confirm who else will receive the information discussed and in what form. In some jurisdictions, committee members have disclosure obligations to regulators that may arise as soon as they receive certain findings. Counsel should advise on these obligations before the briefing begins. The auditor should also document that the briefing occurred, who attended, what was covered, and any decisions made, even if that documentation is itself privileged.

When findings implicate senior management

The most professionally sensitive reporting situation arises when the forensic investigation produces findings that implicate a member of senior management, including the CEO, CFO, or board members themselves. This is not rare: the Association of Certified Fraud Examiners (ACFE) Report to the Nations consistently shows that management and owner-operators commit frauds that are larger in value than employee-level frauds and take longer to detect, precisely because they have the authority to override controls and suppress internal reporting.

The auditor's response to this situation is procedural, not discretionary. Findings that implicate a member of management must be reported to the audit committee directly, bypassing the implicated individual entirely. The auditor should not brief management before the committee in such cases, should not send interim reports to the CFO if the CFO is implicated, and should not seek management's response to preliminary findings before the committee has been informed. The committee, not the auditor, decides the next steps: whether to commission independent legal counsel, whether to suspend the individual, whether to notify regulators, and whether to engage law enforcement.

In some cases, findings implicate members of the audit committee itself or the full board. This is the most difficult escalation scenario. Options include retaining an independent counsel who reports to a special committee of unconflicted directors, appointing a special litigation committee under the company's constitutional documents, or, in extreme cases, engaging the relevant market regulator directly. The auditor should take legal advice before proceeding in any of these scenarios, as the obligations and risks differ significantly by jurisdiction and by the company's constitutional structure.

Structuring the formal findings report

The formal written report to the audit committee or board consolidates the findings from the investigation into a document that will serve multiple downstream purposes: informing the board's governance decisions, providing a basis for regulatory disclosure, supporting disciplinary or legal proceedings, and creating a record that can be reviewed years later. Its structure should reflect all of these uses.

A well-structured forensic report contains: an executive summary that states the mandate, the scope, the key findings, and the recommended actions in a page or two; a methodology section that explains how evidence was gathered and what its limitations are; a findings section organised by issue rather than by chronology; a section on internal control weaknesses identified during the investigation; and appendices containing the underlying evidence documents, transaction analyses, and interview summaries. The findings section should distinguish between findings that are supported by direct evidence, findings that are supported by circumstantial evidence, and matters that require further investigation.

The report should state what it does not cover as clearly as what it does. A forensic audit is necessarily scope-limited, and a committee that relies on the report as a complete picture of the organisation's exposure, when it is actually a targeted investigation of a specific allegation, may fail to commission additional work that is needed. The auditor bears responsibility for communicating the scope boundaries clearly, not for filling every gap that the scope does not address. See Predication and Engagement Planning for how scope decisions are made at the outset of an engagement.

Check your understanding
Question 1 of 4· 0 answered

A forensic auditor discovers evidence that the CFO has been approving payments to a company she owns. Who should receive the initial oral briefing?

Key Takeaways

  • The audit committee is the forensic auditor's primary reporting line because it sits outside the management hierarchy and can receive findings that implicate management without those individuals being able to filter or block the communication.
  • Oral flash reports allow the committee to take immediate protective action during an active investigation; every oral briefing should be followed promptly by a written summary to create a contemporaneous record.
  • Legal professional privilege may protect forensic audit communications if the engagement is structured as a legal matter commissioned by counsel in anticipation of litigation; privilege is easily lost through careless distribution and cannot be reasserted once waived.
  • The forensic auditor's role is to find and report facts; making legal conclusions such as labelling conduct as fraud or embezzlement is counsel's function and auditors must maintain that boundary in briefings and reports.
  • When findings implicate senior management, the auditor must bypass normal management reporting channels and go directly to the audit committee, documenting the reason for the bypass and every step of the escalation.
What is attorney-client privilege and why does it matter in forensic audits?
Attorney-client privilege protects confidential communications between a lawyer and their client from compelled disclosure. In forensic audits, privilege can cover the audit report itself if the engagement is structured as legal counsel directing the work. Losing privilege through careless disclosure can expose sensitive findings to regulators, opposing parties, or the press before the organisation is prepared to act. The rules differ by jurisdiction: US federal courts apply Upjohn principles, UK law uses the dominant-purpose test, and Indian courts apply Section 126 of the Bharatiya Sakshya Adhiniyam 2023.
What should a forensic auditor do if findings implicate the CEO or CFO?
The auditor's primary obligation runs to the audit committee or board, not to management. When findings implicate senior management, the auditor must brief the audit committee directly, bypassing the implicated individuals entirely. The committee then decides whether to retain independent legal counsel, notify regulators, or take other protective action. The auditor should document every briefing and retain copies of communications in case the matter is later disputed.
What is the difference between a preliminary oral briefing and a formal written report?
A preliminary oral briefing is an interim communication to decision-makers before the full written report is ready. It allows the organisation to take immediate protective action, such as suspending access or notifying insurers, while the investigation is still running. The oral briefing carries no less legal weight than a written report, but it is less precise and can be misremembered. The forensic auditor should follow every oral briefing with a written summary, even a brief one, to create a contemporaneous record.
How does the role of legal counsel differ from the role of the forensic auditor in reporting?
Legal counsel manages information flow to protect the organisation's legal position: deciding what is privileged, advising on disclosure obligations, and controlling who sees preliminary findings. The forensic auditor is the finder of fact: gathering evidence, analysing it, and communicating what the evidence shows. The two roles are complementary but distinct. Auditors should not make legal conclusions and counsel should not re-characterise findings to soften their evidentiary meaning.
What is a management representation letter and when is it used in forensic reporting?
A management representation letter is a written confirmation from management to the forensic auditor acknowledging the findings and confirming that management has disclosed all information relevant to the investigation. It is used at the conclusion of the engagement to close any information asymmetry and create a documented record that management was informed. In some engagements, counsel will advise against requesting this letter if it risks alerting implicated individuals prematurely.

Test yourself on Forensic Auditing and Fraud Examination with free, timed mocks.

Practice Forensic Auditing and Fraud Examination questions

Found this useful? Pass it along.

Share

Spotted an error in this page? Report a correction or read our editorial standards.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.