Audit

Audit Documentation Under SA 230: What Good Working Papers Should Contain

A practical guide to ICAI SA 230 covering what audit documentation should show, how to structure working papers, review evidence, file assembly, retention and common documentation failures.

Audit Documentation Under SA 230: What Good Working Papers Should Contain

Audit documentation is not simply a folder of invoices, confirmations and spreadsheets collected during an engagement. Under ICAI's Standard on Auditing (SA) 230, the audit file should create a clear record of the procedures performed, the relevant audit evidence obtained and the conclusions reached. A strong file allows an experienced auditor with no previous connection with the engagement to understand what was done, what was found and how significant judgments were resolved.

That distinction matters in practice. A team may perform the right procedure but still leave a weak file if the working paper does not identify the audit objective, population, items tested, evidence examined, exceptions found and conclusion reached. The official ICAI SA 230 text and ICAI's Implementation Guide to SA 230 are useful primary references.

What should audit documentation achieve?

SA 230 requires documentation that provides a sufficient and appropriate record of the basis for the auditor's report and evidence that the audit was planned and performed in accordance with applicable Standards on Auditing and legal and regulatory requirements. Documentation also supports engagement-team accountability, supervision and review, future audit planning, quality reviews and external inspections.

The key test is usability by another experienced auditor. The file should make the nature, timing and extent of procedures understandable; record the results and evidence obtained; and explain significant matters, conclusions and significant professional judgments.

What can form part of the audit file?

SA 230 recognises that audit documentation may be maintained on paper, electronically or on other media. Examples include audit programmes, analyses, issue memoranda, summaries of significant matters, confirmation and representation letters, checklists and correspondence concerning significant matters. Copies or extracts of important client records may also be included where they support the audit work.

However, collecting a client document is not the same as documenting an audit procedure. If an invoice is placed in the file, the working paper should normally make clear why it was inspected, what attribute was tested, what the auditor observed and how that result affected the conclusion.

A practical working-paper structure

For many audit areas, the following structure produces a file that is easier to prepare and review.

  1. Objective and assertion: State the audit objective and relevant assertion or risk. For example, a receivables test may address existence, valuation or both.
  2. Population and source: Identify the report, ledger or data set used, the period covered and how completeness or reliability was addressed where relevant.
  3. Procedure: Describe what was actually performed rather than using vague language such as checked or verified.
  4. Items tested: Record identifying characteristics of the specific items or matters tested so another reviewer can trace the work.
  5. Evidence and result: Record the evidence inspected or obtained and the outcome of the procedure.
  6. Exceptions and follow-up: Explain deviations, contradictory evidence or unresolved matters and the additional work performed.
  7. Conclusion: State whether the procedure achieved its objective and how the result affects the audit conclusion.
  8. Preparation and review trail: Identify who performed and reviewed the work and the relevant dates.

Worked illustration: trade receivables

Assume a statutory audit team tests a material customer balance. A weak working paper might say that the invoice and subsequent receipt were checked and found correct. A stronger working paper identifies the customer and balance, states that the procedure addresses existence and recoverability, records the invoice and receipt references, shows the amount traced to the bank statement, records any difference between the ledger and confirmation, documents follow-up on that difference and then states the conclusion.

The difference is not extra wording for its own sake. The stronger paper preserves the audit reasoning. A reviewer can understand what evidence supports the conclusion without relying on the preparer's memory or oral explanation.

Document significant judgments, not just mechanical testing

High-risk or judgment-heavy areas need more than a tick mark. If the team concludes that an accounting estimate is reasonable, accepts management's explanation for an unusual transaction or resolves contradictory evidence, the file should record the significant facts, alternatives considered where relevant, evidence relied upon and basis for the conclusion.

SA 230 specifically addresses documentation of significant matters and significant professional judgments. It also requires the auditor to document how inconsistencies in information concerning significant matters were addressed. A useful rule for practice is that the more judgment a conclusion requires, the more important it is to preserve the reasoning that led to it.

What does not need to stay in the final file?

SA 230 explains that audit documentation need not include superseded drafts of working papers and financial statements, notes reflecting incomplete or preliminary thinking, previous copies corrected only for typographical or similar errors, or duplicate documents. Keeping every intermediate file can make the final audit trail harder rather than easier to follow.

Oral explanation is also not a substitute for adequate documentation of work performed or conclusions reached. It may clarify information already documented, but a critical conclusion should not exist only in the memory of the person who performed the work.

Final audit-file assembly

Documentation should be prepared on a timely basis. ICAI guidance also addresses the administrative process of completing the final engagement file after the auditor's report. ICAI has stated that the final audit file should ordinarily be assembled within not more than 60 days after the date of the auditor's report. The assembly process is administrative; it is not an opportunity to perform new audit procedures that should have been completed before the report.

After final assembly, documentation should not simply be deleted or discarded before the end of the applicable retention period. Where modification or addition becomes necessary in permitted circumstances, the file should preserve why the change was made and by whom and when it was made and reviewed.

How long should audit working papers be retained?

ICAI's official announcement on SA 230 retention amended the audit-documentation retention period to seven years. Firms should also consider any engagement-specific law, regulator, contractual requirement or current quality-management requirement that may require a different or longer period.

Common documentation failures

  • Collecting without concluding: attaching evidence but never stating what it proves.
  • Generic procedures: writing verified as per supporting documents without identifying the documents or attributes tested.
  • No population trail: testing samples without documenting the source population or how it was established.
  • Unexplained exceptions: highlighting a difference but not documenting investigation, resolution and impact.
  • Missing judgment rationale: recording the final answer without explaining why a significant accounting or audit judgment was accepted.
  • Weak review trail: leaving no clear evidence of who performed or reviewed the work and when.
  • Over-documentation: retaining duplicates and irrelevant material that obscures the significant audit trail.

A pre-signing documentation checklist

  • Can another experienced auditor identify the objective of each material working paper?
  • Are the nature, timing and extent of procedures clear?
  • Are tested items identifiable and traceable?
  • Are significant exceptions and contradictory evidence resolved in the file?
  • Are significant judgments and conclusions supported by recorded reasoning?
  • Are preparer and reviewer details and dates captured?
  • Are cross-references between lead schedules, testing papers and conclusions usable?
  • Has unnecessary duplication or preliminary material been removed from the final file?
  • Is the final file assembled and protected in accordance with the firm's policy and applicable professional requirements?

Practical takeaway

Good audit documentation tells the story of the audit without requiring the preparer to be present. Start every working paper with the risk or objective, identify exactly what was tested, record the evidence and exceptions, preserve significant judgment and finish with an explicit conclusion. The goal is not the largest possible file; it is a clear, reviewable and defensible record of the work that supports the auditor's report.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj