1. Home
  2. Services
  3. Software Audits
  4. Sample Report
Anonymised sample report

What a software audit report actually looks like.

A representative extract from a comprehensive software audit: the executive dashboard, severity matrix, risk register and remediation roadmap. It shows the structure and quality of the deliverable without exposing any client information.

Illustrative example only. Every finding on this page is synthetic. "Example Ltd" and its order management platform are fictional, and the findings were written to show the report format; they do not describe any Assemblysoft client or real system.

1. Executive assessment

Subject: Example Ltd order management platform (ASP.NET Core API, Blazor admin portal, Azure SQL, Azure App Service). Purpose: supplier transition. Scope: comprehensive audit, read-only access, interviews with the outgoing supplier.

The platform is broadly well structured and can be taken over by another team without a rebuild. The most significant risks are about control and recovery rather than code: the production subscription is held in the supplier's tenant, restores have never been tested, and deployment depends on one person. These should be addressed before the supplier relationship ends. The runtime reaches end of support in November 2026 and should be upgraded in the next quarter.

Overall recommendation: retain and remediate. Replacement is not justified by the evidence.

10Findings
1Critical
4High
4Medium
1Low
2. Severity matrix

Likelihood against impact

Each finding is placed by how likely it is to cause harm and how serious that harm would be for the business. Severity follows the position, then urgency and remediation complexity decide the order of work in the roadmap.

Finding IDs refer to the risk register below.

3. Risk register

Every finding, with its evidence

In a full report each row expands into a detailed write-up. Effort is indicative: S = days, M = weeks, L = months.

Synthetic risk register with ten example findings
IDAreaFindingEvidenceBusiness impactSeverityRecommendationEffort
F-01 Ownership & control Production Azure subscription sits in the outgoing supplier's tenant; client has no Owner role. Azure RBAC export; supplier confirmation A supplier exit could leave the client unable to deploy or recover the service. Critical Transfer the subscription to a client-owned tenant before notice is served. S
F-02 Operational resilience Database backups exist but no restore has ever been tested. Backup policy; absence of restore records Recovery time and data loss in an incident are unknown. High Run a controlled restore into an isolated environment; record actual RTO/RPO. S
F-03 Dependencies & lifecycle API runs on .NET 8, which leaves support on 10 November 2026. Project files; Microsoft lifecycle policy No security patches after that date. High Upgrade to .NET 10 (LTS); low code change expected after dependency review. M
F-04 Security Connection strings and an SMTP password committed to source control. Repository history scan Anyone with repository access, past or present, holds live credentials. High Rotate credentials; move secrets to Azure Key Vault; purge from history. S
F-05 Knowledge risk Deployment depends on one engineer's local scripts; no pipeline. Interview; absence of CI/CD definitions Releases stop if that person is unavailable. High Introduce a build and release pipeline with test gates. M
F-06 Code quality Order pricing logic duplicated in four places with small differences. Static analysis; code review Pricing changes are slow and error-prone. Medium Consolidate into one tested pricing service during the next feature change. M
F-07 Tests Automated test coverage limited to a small set of unit tests; none on checkout. Test project review; coverage report Regressions reach customers before they are noticed. Medium Add integration tests around checkout and invoicing first. M
F-08 Azure cost Premium App Service plan and SQL tier sized for a peak that no longer occurs. Cost Management export; utilisation metrics Avoidable monthly spend; no performance benefit observed. Medium Rightsize after a monitored trial; consider a savings plan. S
F-09 Monitoring Application Insights enabled but no alerts configured. Azure Monitor configuration Failures are reported by customers, not detected. Medium Define alerts for failed requests, dependency failures and job errors. S
F-10 Documentation No architecture overview; integration with the accounting package undocumented. Document review; interviews Slower onboarding for any new team. Low Capture an architecture overview and integration runbook during handover. S
4. Remediation roadmap

Immediate, planned and further investigation

Act now

Before the supplier exit
  • F-01 Move the production subscription into a client-owned tenant
  • F-04 Rotate exposed credentials and move secrets to Key Vault
  • F-02 Prove a database restore and record RTO/RPO

Improve over time

Within 12 months
  • F-07 Integration tests around checkout and invoicing
  • F-06 Consolidate pricing logic alongside feature work
  • F-10 Architecture overview and integration runbooks

5. Limitations of this assessment

  • No penetration testing was performed; security findings come from code and configuration review.
  • Load testing was out of scope; scalability observations are based on architecture and metrics.
  • Legal ownership of the source code was not assessed; contractual questions are listed for the client's advisors.
  • The accounting integration could not be exercised end to end in the time available.

  6. Stakeholder workshop

  • Findings walked through with the business owner, finance and the incoming technical lead.
  • Roadmap priorities agreed against the supplier notice period.
  • Open questions assigned to owners, including two for the legal advisors.

Want this level of clarity about your own software?

Tell us about the application and the decision in front of you. We will scope an audit that answers that question, and confirm timescales and access before any work begins.

Discuss Your Software Audit Requirements All Software Audit Services

Cyber Essentials Plus certified  ·  NDA as standard  ·  UK-based team  ·  Microsoft Partner  ·  No obligation to appoint us for remediation

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor