What audit working papers are
Audit working papers are the record of the audit procedures performed, the evidence obtained and the conclusions reached. They are the bridge between the audit plan and the audit opinion. If a reviewer, regulator or successor auditor cannot reconstruct your conclusion from the file alone, the work is effectively undocumented — however well it was performed.
Working papers serve four purposes:
- Evidence of work performed in accordance with the applicable standards
- Basis for review and supervision by the engagement lead or quality reviewer
- Support for the opinion or report, including significant judgements
- Knowledge continuity for future audits, remediation tracking and regulatory inspection
Permanent file versus current file
| File | Contents | Typical lifespan |
|---|---|---|
| Permanent (continuing) file | Entity structure, statutory documents, key contracts, IT architecture, system landscape, prior-year findings, control design documentation, accounting or control policies | Carried forward and updated each cycle |
| Current file | Engagement letter, audit plan and risk assessment, sampling rationale, testwork, evidence, exceptions, management responses, review notes, final report and sign-offs | Specific to the audit period |
Keeping them separate prevents the current file from becoming an archive and makes the annual update explicit rather than assumed.
What a well-formed working paper contains
Every individual paper should stand alone and answer eight questions:
- Header — entity, period, process or control reference, paper reference number
- Objective — the control objective or assertion being tested
- Source of evidence — system, report name, extraction date, who extracted it, and how completeness was established
- Population and sampling — population size, selection method, sample size and rationale
- Procedure performed — the steps actually executed, in enough detail to be reperformed
- Results — attributes tested per item, with tick marks defined in a legend
- Exceptions — description, root cause, quantification, management response and remediation owner
- Conclusion and sign-off — explicit conclusion on the objective, preparer, date, reviewer, review date
A working paper that records only "tested, no exceptions" fails the reperformance test.
Documentation quality principles
- Reperformability — an experienced auditor with no prior involvement should reach the same conclusion
- Completeness of population — evidence that the report or extract covers the full period and population, with parameters and record counts retained
- Source reliability — system-generated extracts with screenshots of parameters beat client-prepared spreadsheets
- Cross-referencing — every number in the report traces to a paper, and every paper traces back to a risk in the plan
- Contemporaneous preparation — documented as work is performed, not reconstructed at reporting time
- Judgement transparency — materiality, scoping and sampling decisions recorded with reasoning, not just outcomes
Review discipline
A review is not a signature. Effective review layers are:
- Preparer self-review against the paper checklist
- Detailed review by a senior auditor covering evidence sufficiency, sampling adequacy and conclusion logic
- Engagement lead review focused on risk coverage, significant judgements, exceptions and report linkage
- Independent quality review for higher-risk engagements
Review notes must be documented, resolved and cleared before the file is finalised, with the resolution visible. Deleting review notes without a resolution trail removes the evidence that the review happened.
Archiving, retention and confidentiality
Assemble the final file promptly after the report date, lock it against edit, and record any post-archive additions with the reason, author and date. Retention is commonly set to a minimum of five to seven years depending on the applicable standards, regulator and contract terms — confirm the longest applicable requirement. Working papers are the auditor's property but contain client confidential data, so access control, encryption and defined release protocols for third parties are mandatory.
Common documentation findings
| Finding | Why it fails | Fix |
|---|---|---|
| No evidence of population completeness | Sample conclusions cannot be extended to the population | Retain extraction parameters, record counts and reconciliation to a source total |
| Undefined tick marks | Testwork is not reperformable | Maintain a legend on each paper |
| Screenshots without context | Date, user and system are unverifiable | Capture full screen with user, system, filters and timestamp |
| Conclusion not linked to results | Opinion appears unsupported | State the conclusion against the objective, referencing exceptions |
| Review notes deleted | No evidence of supervision | Retain notes with documented resolution |
| Late assembly or post-archive edits | Integrity of the record is questionable | Enforce archive deadlines and log every subsequent change |
Key takeaways
- The file, not the fieldwork, is what gets inspected — document to a reperformance standard
- Separate permanent and current files, and update the permanent file deliberately each cycle
- Population completeness and source reliability are the most frequently challenged areas
- Review is only credible when notes and their resolution survive in the file
- Archive promptly, retain per the longest applicable requirement, and control access tightly
Strong working papers reduce audit cost over time: next year's team starts from a reliable baseline instead of rediscovering the environment.
