6Reporting & follow-up
- 6.1Audit report and recommendations for improvement
Covers the structure of the audit report that conveys results, how to build each finding on the four points of fact (current state), cause, impact (risk), and recommendation, the principle that the auditor recommends but does not implement the fix themselves (preserving independence), and the judgment of making recommendations feasible and prioritized to match the significance of the risk.
- 6.2Reporting to management and the audit opinion
Covers how to choose the reporting destination (management, or a superior who can maintain independence), the problem of reporting directly to the head of the audited department, the difference between the audit opinion of an assurance engagement (a conclusion giving a level of assurance) and the proposals of an advisory engagement (improvement proposals as the main aim), and the principle that an opinion is expressed within the scope of the audit evidence obtained.
- 6.3Follow-up and audit quality management
Covers the follow-up that tracks whether recommendations were carried out, verifying the effectiveness of remediation (confirming the effect, not merely formal completion), the principle of confirming even in follow-up with objective evidence (not taking oral answers at face value), and audit quality management (review of working papers, supervision, internal evaluation) that keeps the quality of the audit work itself.
- 6.4Related laws and guidelines
Covers the related laws (the Personal Information Protection Act, the Act on Prohibition of Unauthorized Computer Access) on which a systems auditor bases their judgment, and various guidelines such as the Systems Audit Standards and Systems Management Standards that frame the audit and the Information Security Management Standards that serve as the yardstick for control evaluation—from the applied audit viewpoint of against which standard or law a deficiency is evaluated.

