Audit

    Audit Working Papers: Standards, Structure and Review Best Practices

    Santhosh Kapalavai
    Aug 28, 2026
    Audit

    What audit working papers are

    Audit working papers are the record of the audit procedures performed, the evidence obtained and the conclusions reached. They are the bridge between the audit plan and the audit opinion. If a reviewer, regulator or successor auditor cannot reconstruct your conclusion from the file alone, the work is effectively undocumented — however well it was performed.

    Working papers serve four purposes:

    • Evidence of work performed in accordance with the applicable standards
    • Basis for review and supervision by the engagement lead or quality reviewer
    • Support for the opinion or report, including significant judgements
    • Knowledge continuity for future audits, remediation tracking and regulatory inspection

    Permanent file versus current file

    FileContentsTypical lifespan
    Permanent (continuing) fileEntity structure, statutory documents, key contracts, IT architecture, system landscape, prior-year findings, control design documentation, accounting or control policiesCarried forward and updated each cycle
    Current fileEngagement letter, audit plan and risk assessment, sampling rationale, testwork, evidence, exceptions, management responses, review notes, final report and sign-offsSpecific to the audit period

    Keeping them separate prevents the current file from becoming an archive and makes the annual update explicit rather than assumed.

    What a well-formed working paper contains

    Every individual paper should stand alone and answer eight questions:

    1. Header — entity, period, process or control reference, paper reference number
    2. Objective — the control objective or assertion being tested
    3. Source of evidence — system, report name, extraction date, who extracted it, and how completeness was established
    4. Population and sampling — population size, selection method, sample size and rationale
    5. Procedure performed — the steps actually executed, in enough detail to be reperformed
    6. Results — attributes tested per item, with tick marks defined in a legend
    7. Exceptions — description, root cause, quantification, management response and remediation owner
    8. Conclusion and sign-off — explicit conclusion on the objective, preparer, date, reviewer, review date

    A working paper that records only "tested, no exceptions" fails the reperformance test.

    Documentation quality principles

    • Reperformability — an experienced auditor with no prior involvement should reach the same conclusion
    • Completeness of population — evidence that the report or extract covers the full period and population, with parameters and record counts retained
    • Source reliability — system-generated extracts with screenshots of parameters beat client-prepared spreadsheets
    • Cross-referencing — every number in the report traces to a paper, and every paper traces back to a risk in the plan
    • Contemporaneous preparation — documented as work is performed, not reconstructed at reporting time
    • Judgement transparency — materiality, scoping and sampling decisions recorded with reasoning, not just outcomes

    Review discipline

    A review is not a signature. Effective review layers are:

    • Preparer self-review against the paper checklist
    • Detailed review by a senior auditor covering evidence sufficiency, sampling adequacy and conclusion logic
    • Engagement lead review focused on risk coverage, significant judgements, exceptions and report linkage
    • Independent quality review for higher-risk engagements

    Review notes must be documented, resolved and cleared before the file is finalised, with the resolution visible. Deleting review notes without a resolution trail removes the evidence that the review happened.

    Archiving, retention and confidentiality

    Assemble the final file promptly after the report date, lock it against edit, and record any post-archive additions with the reason, author and date. Retention is commonly set to a minimum of five to seven years depending on the applicable standards, regulator and contract terms — confirm the longest applicable requirement. Working papers are the auditor's property but contain client confidential data, so access control, encryption and defined release protocols for third parties are mandatory.

    Common documentation findings

    FindingWhy it failsFix
    No evidence of population completenessSample conclusions cannot be extended to the populationRetain extraction parameters, record counts and reconciliation to a source total
    Undefined tick marksTestwork is not reperformableMaintain a legend on each paper
    Screenshots without contextDate, user and system are unverifiableCapture full screen with user, system, filters and timestamp
    Conclusion not linked to resultsOpinion appears unsupportedState the conclusion against the objective, referencing exceptions
    Review notes deletedNo evidence of supervisionRetain notes with documented resolution
    Late assembly or post-archive editsIntegrity of the record is questionableEnforce archive deadlines and log every subsequent change

    Key takeaways

    • The file, not the fieldwork, is what gets inspected — document to a reperformance standard
    • Separate permanent and current files, and update the permanent file deliberately each cycle
    • Population completeness and source reliability are the most frequently challenged areas
    • Review is only credible when notes and their resolution survive in the file
    • Archive promptly, retain per the longest applicable requirement, and control access tightly

    Strong working papers reduce audit cost over time: next year's team starts from a reliable baseline instead of rediscovering the environment.

    Hi! I'm your AI Assistant 💬