# Audit Review Report — reusable template

DRAFT TEMPLATE · Not a finding, contract, adoption record, or completed audit.

## Report record

[Report ID] · [version] · [date] · [distribution: private / separately authorized public copy].
Prepared for [requester or approved identifier]. Responsible reviewer: [name]. Human sign-off: [pending / name and date].

## 1. Summary finding

[Answer the agreed question in ordinary language. Identify strengths, the main concern, and the supported readiness limit. A favorable verdict is not guaranteed. Do not imply certification.]

## 2. Scope, identity, and access

[Agreement ID/date; review question; audience/use; exact file/page set, version, date, digest or preserved snapshot; supplied and actually accessed material; included checks; excluded checks; time/source cutoff. Do not imply full access from a filename or summary.]

## 3. Findings and evidence

[Repeat one record per finding: F01; exact location; relevant claim or function; evidence and actual access; reasoning; importance to stated use; necessary correction / unresolved question / optional improvement; recommended repair; verification needed; confidence and limits. Record strengths and “not established” results too.]

## 4. Repair and recheck checklist

[For each action: finding ID; specific task; responsible owner or “not assigned”; agreed due date or “not agreed”; evidence needed for closure; status: open / claimed repaired / rechecked / not tested. A proposed change is not a verified repair.]

## 5. Sources and tests

[Source ID, title/version/date, exact locator, access method, access extent, checked date, use in findings, unresolved limitations. List actual tests and results separately from planned tests. Record independent, external, human, live-host, and physical-print checks only when performed.]

## 6. Method, permissions, and assistance

[Exact Audit packet, status, digest, owner-selection record; use context and privacy authorization; material AI provider/tool and scope actually used; what was not sent; consent/venue requirements; reviewer conflicts and management; final responsible human judgment. Do not silently promote a candidate.]

## 7. Limits and next step

[What the report does not establish; unresolved expertise, authority, protection, source, human-use, or operational checks; narrowed/referral/stop decision if relevant; actual next action and who decides. No promise of an approval badge or official authority.]

## 8. Delivery, correction, and retention

[Agreed private delivery route and recipients; report version/digest; delivery confirmation; correction contact; how to challenge a finding; correction vs new-scope re-review; next version/supersession note; agreed retention/deletion dates and exceptions. No public reuse without separate permission.]

