Internal Audit Finding Tracker
Track internal audit findings from report to closure — owners, due dates, extensions, overdue ageing and closure statistics, with a report ready for an audit committee. Runs entirely in your browser. Nothing is uploaded.
Version 1.0.0 · Updated Aug 7, 2026
Overview
Frequently asked questions
Is the Internal Audit Finding Tracker really free?
Yes. The Internal Audit Finding Tracker is a free download with every feature included — no trial period, no locked features and no account required.
Does my data stay private when I use the Internal Audit Finding Tracker?
Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.
Does the Internal Audit Finding Tracker work offline?
Yes. Once downloaded it runs completely offline in any modern browser — no internet connection, installation or plugins needed.
Do I need Excel or any other software to use the Internal Audit Finding Tracker?
No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.
How to use Internal Audit Finding Tracker
The complete in-tool guidance, reproduced here so you can read it before you download.
What this tool does
CM8-172 is a follow-up register for internal audit findings. Audits are only worth their cost if the agreed actions actually happen, and the follow-up register is where that either happens or quietly doesn't. You log each finding as it is agreed — audit, reference, area, severity, root cause, the agreed action, an owner and a due date — and the tool tracks it to closure: what is open, what is overdue and by how many days, what has been extended and how often, how long closures actually take, and how much of what closes is genuinely verified rather than written off as accepted risk.
Everything runs inside this single file. There is no account, no upload and no network request of any kind, so findings — which often describe control weaknesses you would not want circulated — never leave the computer you are using.
Logging a finding
Create one record per finding, not per audit. A report with nine findings becomes nine records sharing the same audit name, so each one can carry its own owner, due date and status. Log findings when they are agreed — usually the date of the final report — and use that date consistently, because ageing is counted from it.
Write the summary as the condition found, not the recommendation: what was tested, what was found, how often. Write the agreed action as a commitment with a visible end state — "reinstate the three-quote rule in the purchasing system" can be verified; "improve procurement awareness" cannot. Give every action a named owner or a specific role. Actions owned by a department belong to nobody.
Severity grades
The tool uses a five-point scale: observation (an improvement opportunity, no control failure), low, medium, high and critical. Map your own grading onto it consistently — the labels matter less than the ordering, because the ordering drives the overdue table and the verification rule.
On the Settings tab you can require that findings at or above a chosen severity are closed as verified rather than risk accepted. With the default of "high and above", the tool will refuse to save a high or critical finding closed by risk acceptance. Set the threshold to match your audit charter; set it to "no verification requirement" if your charter allows management to accept any finding.
Root cause categories
The categories describe why the control failed, not who failed it: process gap (there is no process, or it has holes), training (people did not know what was required), resourcing (no one had time to do it properly), system limitation (the software cannot support the control), control not operating (designed correctly, not performed) and control design (performed as designed, but the design cannot work). The distinction between the last two matters: a control that is not operating needs supervision and habit; a control that is badly designed needs redesigning, and no amount of reminding people will fix it.
The root cause chart ranks categories by frequency. If most findings across different audits share one or two causes, that is a message about the organisation, not about any single department — and it is usually the most valuable slide in the pack.
Due dates and extensions
Every finding carries an original due date — the date management committed to. If an extension is formally agreed, enter the revised due date and increase times extended. The tool keeps both dates and works to the effective one:
Effective due date = revised due date if one is recorded, otherwise the original due date
Only the latest revised date is stored, which is why the extension counter exists: a finding on its third revised date has been extended three times, and the counter is the honest record of that. The tool will not accept a revised date without a count, or a count without a revised date, and it rejects a revised date earlier than the original — an extension moves a date later.
The "extended more than once" tile exists because repeated extensions are the classic way findings die without closing. One extension can be legitimate; a second needs explaining to whoever the finding is reported to.
Overdue and ageing
Overdue is calculated, not chosen. There is deliberately no "overdue" status, because a status has to be remembered and updated; a calculation cannot be forgotten. A finding is overdue when it is not closed and today is past its effective due date:
Days overdue = today − effective due date, for findings not yet closed, when the result is positive
Ageing is different and runs from the other end:
Age = today − date raised, for findings not yet closed
A finding can be old without being overdue — a long agreed deadline — and overdue without being particularly old. The ageing chart buckets open findings at 0–30, 31–60, 61–90 and over 90 days from the date raised, and the register flags any open finding older than the ageing warning days set on the Settings tab (30 by default). Both measures use the dates you entered; neither is affected by status changes.
Closing a finding
There are two closed statuses, and the difference between them is the integrity of the whole register. Closed — verified means someone independent of the action owner has seen evidence that the action is complete and working: a re-test, a walkthrough, a sample. Closed — risk accepted means management has decided, with authority to do so, to live with the weakness. Both need a date closed, and the tool insists on it — a closed status without a date, or a date without a closed status, is rejected.
Use awaiting evidence for the common in-between state where the owner says the work is done but the proof has not arrived. It keeps the finding honestly open — and visibly ageing — instead of being closed on someone's word.
Closure days = date closed − date raised, per finding, both dates required
The headline figures
Each tile states its own basis, and the bases differ deliberately:
- Open findings — every finding whose status is open, in progress or awaiting evidence, out of everything in the current filter.
- Overdue findings — open findings past their effective due date today.
- Closed in this view — findings with either closed status inside the current filter. Set a date range on the register to make this "closed this quarter".
- Average closure days — the mean of closure days across closed findings that have both dates recorded. Findings closed without a date are excluded rather than counted as zero, and with nothing to average the tile shows a dash — an average of nothing is not zero.
- Closed as verified — verified closures as a percentage of all closed findings in the view. A falling percentage means more findings are being risk-accepted, which is worth a question even when each individual acceptance was proper.
Average closure days = Σ (date closed − date raised) ÷ number of closed findings with both dates % closed as verified = verified closures ÷ all closed findings × 100
All figures respect the current filter. Filter to one severity or one area and every tile, chart and table recalculates on that population.
Reporting to a committee
Audit committees ask the same four questions everywhere: what is open, what is overdue, what keeps slipping, and are closures real. The tiles answer the first two directly; the extension counter and the overdue table answer the third; the verified percentage answers the fourth. The per-area table shows where the workload and the delays sit, which is usually a better conversation than reading the register aloud.
Be careful with comparisons between periods: the population changes as audits are reported. Ten open findings after a heavy audit season is a different situation from ten open findings after a quiet one. Pair the open count with the "raised per month" chart so the inflow is visible alongside the backlog.
Printing and sharing
Print Report produces a report from whatever the current filter shows: the headline tiles, all four charts, the overdue and per-area tables, the register itself and your closing notes. Print to PDF to circulate it. The scope line under the title states the filter in force — clear the filters before issuing anything described as the complete register, and set a date range when the report is meant to cover a single period.
Saving your work
Findings, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: a different browser, a private window or a clean-up tool that clears site data will not have it.
Treat Export .json as the real save — one file holding everything, which Import .json restores on any machine. Export CSV gives you the register, including the derived columns, for spreadsheet work. Reset asks twice, then erases everything this tool has stored. There is no undo.
Accuracy & disclaimer
This tool tracks what you enter and calculates from it. It cannot judge whether a finding was graded correctly, whether an agreed action truly addresses the root cause, or whether the evidence behind a verified closure was adequate — those judgements belong to the auditor, management and the audit committee, in that order. Internal audit standards, independence requirements and committee reporting expectations differ between organisations and jurisdictions. This is an internal tracking aid, not an audit methodology, not assurance, and not a substitute for either.
Related tools
Record every gift and hospitality item given or received, test each one against your own approval and prohibition thresholds, and catch the cumulative annual total from a single counterparty that item-by-item checks always miss. Runs entirely in your browser — nothing is uploaded.
Log personal data breaches against the clock: hours from awareness to containment and to report, a likelihood-and-severity risk rating, deadline tracking and a printable register. Runs entirely in your browser. Nothing is uploaded.
Keep a project and business risk register — strategic, financial, operational and compliance risks scored on a 5×5 grid, inherent and residual, with the four responses and a board-ready report. Not a workplace safety assessment. Nothing is uploaded.
Build a register of processing activities: purpose, data subjects, data categories, lawful basis, retention, transfers and impact assessments, with a gap list and a printable report. Runs entirely in your browser — nothing is uploaded.