Audit Documentation Under SA 230: What the File Must Actually Show
An audit that was performed well but documented thinly is indistinguishable, in a file, from one that was not performed at all. SA 230 defines the difference, and it is the standard peer reviewers and inspectors read your work against.
CA Helper Editorial Team
How we research and reviewPublished · 7 min read
Key takeaways
- SA 230's test is whether an experienced auditor with no previous connection to the engagement could reconstruct your procedures, results, and reasoning from the file alone.
- Documentation must identify what was tested specifically enough to be reconstructed, and record who prepared the work and who reviewed it, with dates.
- Significant judgements, including how materiality was arrived at, must show the reasoning, not just the conclusion. This is the most commonly missing element.
- The final file is assembled on a timely basis after the report date, with sixty days treated as an appropriate limit, and retained for not less than seven years.
- Peer review and NFRA inspection both read your audit exclusively through the file, so a well-performed but thinly documented audit reads as a poorly performed one.
There is a sentence every reviewer eventually says to a practitioner, and it is never received well: I am not saying you did not do the work, I am saying the file does not show you did. It sounds like pedantry. It is not. Once the engagement is over and the team has moved on, the file is the only surviving evidence of what happened, and a file that cannot demonstrate the audit is, for every purpose that matters afterwards, an audit that cannot be defended. SA 230 is the standard that defines what demonstrating it requires.
The Experienced Auditor Test
SA 230 sets a single test that resolves almost every argument about whether a working paper is adequate. Documentation must be sufficient to enable an experienced auditor, having no previous connection with the engagement, to understand the nature, timing, and extent of the procedures performed; the results of those procedures and the evidence obtained; and the significant matters arising, the conclusions reached on them, and the professional judgements made in reaching those conclusions.
Read carefully, that test is demanding in a specific way. It is not asking whether you could explain the file, or whether your partner could. It is asking whether a competent stranger could reconstruct your reasoning from the paper alone, without you in the room. That is precisely the position a peer reviewer, an NFRA inspector, a successor auditor, or a court occupies. Applying the test honestly to your own file, imagining a capable person who has never met the client, is the fastest way to find what is missing.
What Must Be Recorded
- The identifying characteristics of the items tested, so the sample can be reconstructed. 'Tested 25 invoices' fails; the invoice numbers or the selection basis passes.
- Who performed the work and the date it was completed.
- Who reviewed the work, and the date of review. Evidence of review is among the most commonly missing items in small-practice files.
- Significant matters arising during the audit, the conclusions reached, and the significant professional judgements made in reaching them.
- Discussions of significant matters with management and those charged with governance, including when they happened and with whom.
- How any inconsistency between information obtained and the final conclusion was resolved.
- Where a requirement of a standard was departed from, the reason and the alternative procedures performed to achieve its objective.
The judgement items are the ones practitioners skip, and they are the ones reviewers look for hardest. Materiality is the clearest example. Almost every file has a materiality figure; a much smaller share records why that benchmark was chosen for this entity, why that percentage, and what caused performance materiality to be set where it was. The number without the reasoning tells a reader nothing about whether the judgement was sound, which is the entire point of documenting it.
Assembly and Retention
Two timelines govern the file after the report is signed. The final audit file must be assembled on a timely basis after the date of the auditor's report, and the standard treats sixty days as an appropriate limit for that assembly. Assembly is an administrative process: collating, cross-referencing, discarding superseded drafts, and completing the file. It is expressly not an opportunity to perform new procedures or to reach conclusions that were not reached before the report was signed.
After assembly, documentation must be retained for a period not shorter than seven years from the date of the auditor's report. Once the file is assembled, the auditor must not delete or discard documentation before the end of that period. Where something genuinely does need to be added or modified after assembly, the standard requires recording the specific reason for the change, when it was made, and by whom. A file that shows an amendment with its reason is defensible; one that shows an amendment nobody can date or explain is considerably worse than one that was never amended.
Where Files Actually Fail
| The gap | What it looks like in the file | The fix |
|---|---|---|
| No evidence of review | Working papers prepared by an article with no reviewer sign-off anywhere | A review column on every schedule, initialled and dated before the report is signed |
| Materiality without a basis | A figure on a summary sheet with no derivation | A short memo: benchmark chosen, percentage applied, why both suit this entity |
| Unreconstructable samples | 'Verified on a test-check basis' with no identification of what was tested | Record the selection method and the identifying characteristics of every item |
| Missing engagement letter | No signed letter for the year under audit, or last year's on file | A signed letter for each year, filed before fieldwork starts |
| Significant judgements undocumented | A provision accepted with no record of what was considered | A memo on each significant matter: the issue, what was considered, the conclusion |
| Late or open-ended assembly | Files still being completed months after the report date | A hard internal deadline inside the sixty-day limit, tracked per engagement |
Why This Has Become Higher Stakes
Documentation used to be examined mainly when something had already gone wrong. That is no longer true. ICAI's peer review process examines files routinely as a condition of the certificate a growing number of practice units now need, and NFRA conducts audit quality inspections of firms within its jurisdiction and publishes reports naming the firm and describing what its files contained. In both settings the reviewer's only access to your audit is the paper. A practice that has been diligent for years but casual about evidencing it will read, in those reports, as a practice that was casual.
The encouraging part is that this is a template and habit problem rather than a competence problem. Firms that fix it usually do so with a handful of standard schedules carrying preparer and reviewer columns, a materiality memo, an independence memo, and a rule that no report is signed until the file is complete. None of it requires expertise the firm does not already have. It requires that the reasoning already happening in someone's head be written down while it is still fresh.
Frequently asked questions
Sources and official references
Rules and rates change. These are the primary sources for the topics covered above, and the place to confirm anything before you act on it.
Disclaimer
This article is for general informational purposes only and does not constitute professional tax, legal, or financial advice. Rules and rates change, so consult a qualified Chartered Accountant for advice specific to your situation.
Related reading
MEF and Bank Branch Audit: How Allotment Actually Works
Bank branch audits are not applied for directly. They come through ICAI's panel, built from the MEF you file each year, and the category your firm lands in decides the size of branch you are eligible for.
NFRA vs ICAI: Who Actually Regulates Your Audit
Since 2018 an auditor in India answers to one of two bodies depending on who the client is. Here is where the line falls, what powers each side holds, and why the two have been in open disagreement.
Peer Review for CA Firms: Who Needs It and What Gets Examined
A peer review certificate has quietly become a precondition for whole categories of audit work. Here is what the review examines, how a practice unit prepares, and why most observations are about documentation rather than judgement.