Audit working papers are not a clerical archive created after the audit. They are the record that connects the auditor's risk assessment, procedures, evidence, judgments and final conclusions. Under SA 230, the file should be sufficiently clear for an experienced auditor with no previous connection with the engagement to understand what was done, what evidence was obtained and how significant conclusions were reached.
ICAI's Implementation Guide to SA 230, Audit Documentation (Revised 2022 Edition) is the principal practical resource for applying the standard. ICAI's official journal also provides a useful overview of audit-documentation quality and common weaknesses.
What should an audit working paper prove?
A good working paper should answer four questions without relying on the preparer's memory: what audit objective or risk was being addressed; what procedure was performed; what evidence and exceptions were found; and what conclusion was reached. Merely attaching a client schedule does not answer those questions.
SA 230 documentation can include audit programmes, analyses, issue memoranda, summaries of significant matters, confirmation and representation letters, checklists and correspondence on significant matters. The form can be paper, electronic or another medium. The important point is that the documentation supports the audit work; it is not a substitute for the entity's accounting records.
What an experienced auditor should be able to understand
The file should enable an experienced auditor, with no previous connection to the engagement, to understand the nature, timing and extent of procedures performed; the results and audit evidence obtained; significant matters arising during the audit; the conclusions reached; and significant professional judgments used in reaching those conclusions.
This is a useful practical test for every workpaper. If another auditor can see a tick mark or a spreadsheet but cannot tell what was tested, why the item was selected, what exception was found or why the preparer concluded that no further work was needed, the documentation is incomplete even if the procedure was actually performed.
A practical structure for each working paper
- Purpose: state the assertion, risk or audit objective being addressed.
- Population and source: identify the report, ledger, contract, confirmation or other source used and the period covered.
- Procedure: describe what was inspected, recalculated, confirmed, observed or otherwise tested.
- Selection: where sampling or judgmental selection is used, record the population, selection basis and sample rationale.
- Evidence: retain or cross-reference the relevant support, while avoiding unnecessary duplicates.
- Exceptions: document differences, management explanations, corroboration and additional procedures.
- Conclusion: state whether the objective was achieved and how unresolved matters affect the audit.
- Preparation and review: identify who performed and reviewed the work and when, in accordance with the firm's documentation system.
Example: receivables testing
Suppose the audit team tests trade receivables. A weak workpaper may contain only an ageing report with ticks beside selected customers. A stronger file identifies the relevant assertions, records how the sample was selected, links confirmation responses or alternative procedures, explains differences, evaluates exceptions and states a conclusion on whether the evidence obtained addresses the assessed risk.
If one confirmation differs from the ledger, the workpaper should not simply say 'difference explained by client'. It should record the nature of the difference, the explanation obtained, the evidence used to corroborate it and whether the exception changes the risk assessment, sample evaluation or conclusion.
Significant professional judgments need more than a final answer
Judgment-heavy areas deserve documentation of the reasoning, not just the outcome. Examples can include the response to a fraud indicator, the assessment of an accounting estimate, whether an identified misstatement is material, or why contradictory evidence did not alter a conclusion.
The file should capture the significant facts considered, alternatives or contrary evidence where relevant, consultations undertaken and the basis for the conclusion. This creates a reviewable trail instead of requiring a later oral reconstruction of the auditor's thought process.
What does not need to clutter the final audit file?
SA 230 does not require the file to become a warehouse of every draft and duplicate. Superseded drafts, preliminary notes, copies corrected only for typographical errors and unnecessary duplicates ordinarily do not need to be retained merely to make the file look larger. The goal is sufficient, appropriate and understandable documentation, not maximum volume.
Prepare documentation while the audit is happening
Timely preparation improves audit quality because the details of procedures, evidence and judgments are still fresh. Delaying documentation until the report is about to be signed increases the risk that important reasoning, exceptions or review points will be reconstructed incompletely.
A practical engagement policy is to treat documentation as part of each audit procedure: the procedure is not operationally complete until the work, evidence, exceptions and conclusion are recorded and ready for review.
Common working-paper failures
- Client schedule without audit work: a ledger or reconciliation is filed, but the auditor's procedure is not documented.
- Unexplained tick marks: symbols appear without a legend or description of what was checked.
- No link to risk or assertion: extensive testing is performed but its audit purpose is unclear.
- Exceptions disappear: differences are noted but there is no evidence of follow-up or conclusion.
- Judgment without rationale: the file states 'reasonable' or 'not material' without showing the basis.
- Review trail missing: there is inadequate evidence of supervision, review or resolution of review points.
- Oral explanation dependency: the file makes sense only if the engagement partner or preparer later explains what happened.
How much documentation is enough?
There is no useful universal page count. The form, content and extent depend on factors such as the size and complexity of the entity, nature of procedures, identified risks of material misstatement, significance of evidence obtained, exceptions identified, and the need to document conclusions that are not readily apparent from the work performed.
Higher-risk or judgment-intensive matters normally need a clearer reasoning trail than routine low-risk procedures. Conversely, repetitive screenshots and duplicate client documents do not automatically improve audit quality.
Retention and security
Audit documentation must be protected against unauthorised alteration, loss or access and retained in accordance with applicable professional requirements. ICAI's official journal summary of SA 230 notes a minimum retention period of seven years from the date of the auditor's report. Firms should combine that requirement with their quality-management, confidentiality, legal and engagement-specific obligations.
Final file quality checklist
- Can a reviewer identify the objective and risk addressed by each important workpaper?
- Are the nature, timing and extent of procedures clear?
- Can the reviewer trace evidence to the source and understand how it was evaluated?
- Are exceptions and contradictory evidence visibly resolved?
- Are significant judgments supported by reasoning rather than bare conclusions?
- Are preparation, review and significant discussions documented?
- Are cross-references usable and duplicate material controlled?
- Is the file secure, organised and capable of being retrieved throughout the retention period?
Key takeaway
The best audit working paper is not the longest one. It is the one that allows an experienced auditor to reconstruct the audit logic from risk to procedure to evidence to conclusion without depending on undocumented oral explanations. Build the file while performing the audit, document exceptions and judgments explicitly, and use reviewability—not page count—as the quality test.