Auditen
Home / Glossary / Working papers

Working papers

Also known as: Audit documentation, Workpapers, Audit files

Working papers are the records kept by an auditor to document the procedures applied, the evidence obtained, and the conclusions reached during an engagement. They serve as the primary support for the findings reported in a final audit opinion or compliance certificate. These files create a traceable link between raw data provided by a client and the auditor's ultimate judgment.

Why it matters

Without these records, an auditor cannot prove that they actually performed the tests described in their report. If a regulatory body or a certification board reviews the engagement, missing documentation leads to a failure of the quality review process. For the organization being audited, this can result in a qualified opinion or the loss of a critical security certification like ISO 27001. Ultimately, the Lead Auditor and the firm's Quality Reviewer are held accountable for any gaps in the evidentiary trail.

In practice

During the fieldwork phase, an auditor gathers evidence such as system configuration screenshots or user access lists to populate these files. They use standardized templates, such as test scripts or checklists, to document whether a control operated effectively over a specific period. The resulting artefacts include lead schedules that cross-reference raw data to specific audit objectives. In a first-year engagement, the focus is on establishing the baseline and mapping controls; in repeat engagements, they are updated to reflect changes in the environment and current sample sets. This process ensures every conclusion has a traceable path back to source evidence.

Worked example

An auditor assessing CloudScale AI's SOC 2 compliance reviewed the quarterly user access recertification control. They requested the sign-off logs for Q3 2023 and a list of all privileged users from that period. Upon comparing the two, the auditor found that three administrative accounts were not formally approved by management. The auditor documented this discrepancy in their working papers with screenshots of the missing approvals and a reference to Control AC-1. This evidence directly supported a "Control Deficiency" finding in the final report. Consequently, CloudScale AI had to implement a remedial automated workflow before the audit window closed.

Common mistakes

  • Failing to cross-reference evidence to the specific control being tested, making it impossible for a reviewer to follow the logic.
  • Including excessive irrelevant data or raw dumps without summarizing the result, which obscures the actual conclusion.
  • Omitting "tick marks" or legends that explain what symbols (e.g., $\checkmark$ or $\text{X}$) mean during the testing process.
  • Documenting findings after the fieldwork is complete rather than in real-time, leading to inaccuracies and memory gaps.

Frequently asked questions

What is the difference between working papers and an audit report?

Working papers are the internal "scratchpad" and evidence locker used to reach a conclusion; the audit report is the final summary of those conclusions delivered to stakeholders. The reports summarize findings, while the papers prove them.

Can a simple screenshot be considered a working paper?

A screenshot is an item of evidence that goes into a working paper. To become a working paper, that screenshot must be accompanied by context, such as who provided it, when it was taken, and what specific control it proves.

How should I organize these files for a large-scale audit?

Use a hierarchical folder structure based on the control framework (e.g., NIST CSF domains). Each domain should contain sub-folders for "Evidence Requested," "Testing Templates," and "Final Conclusions."

When is it too late to update working papers?

Once the final audit report has been issued and signed, these files should be locked. Any changes made after the reporting date can be seen as tampering or a failure of professional standards during a peer review.

Do I need to keep these records if the client is happy with the result?

Yes, retention policies (often 5-7 years) require keeping them regardless of the outcome. They are necessary for defending the audit's integrity during legal disputes or regulatory inspections.

More terms

Control owner  ·  IT general controls  ·  Compensating control  ·  Inherent risk  ·  Essential and important entities  ·  Material weakness  ·  Residual risk  ·  Statement of Applicability