CA Helper
Audit & Assurance

Audit Documentation Under SA 230: What the File Must Actually Show

An audit that was performed well but documented thinly is indistinguishable, in a file, from one that was not performed at all. SA 230 defines the difference, and it is the standard peer reviewers and inspectors read your work against.

CH

CA Helper Editorial Team

How we research and review

Published · 7 min read

Audit working paper files and binders organised on an office shelf

Key takeaways

  • SA 230's test is whether an experienced auditor with no previous connection to the engagement could reconstruct your procedures, results, and reasoning from the file alone.
  • Documentation must identify what was tested specifically enough to be reconstructed, and record who prepared the work and who reviewed it, with dates.
  • Significant judgements, including how materiality was arrived at, must show the reasoning, not just the conclusion. This is the most commonly missing element.
  • The final file is assembled on a timely basis after the report date, with sixty days treated as an appropriate limit, and retained for not less than seven years.
  • Peer review and NFRA inspection both read your audit exclusively through the file, so a well-performed but thinly documented audit reads as a poorly performed one.

There is a sentence every reviewer eventually says to a practitioner, and it is never received well: I am not saying you did not do the work, I am saying the file does not show you did. It sounds like pedantry. It is not. Once the engagement is over and the team has moved on, the file is the only surviving evidence of what happened, and a file that cannot demonstrate the audit is, for every purpose that matters afterwards, an audit that cannot be defended. SA 230 is the standard that defines what demonstrating it requires.

The Experienced Auditor Test

SA 230 sets a single test that resolves almost every argument about whether a working paper is adequate. Documentation must be sufficient to enable an experienced auditor, having no previous connection with the engagement, to understand the nature, timing, and extent of the procedures performed; the results of those procedures and the evidence obtained; and the significant matters arising, the conclusions reached on them, and the professional judgements made in reaching those conclusions.

Read carefully, that test is demanding in a specific way. It is not asking whether you could explain the file, or whether your partner could. It is asking whether a competent stranger could reconstruct your reasoning from the paper alone, without you in the room. That is precisely the position a peer reviewer, an NFRA inspector, a successor auditor, or a court occupies. Applying the test honestly to your own file, imagining a capable person who has never met the client, is the fastest way to find what is missing.

What Must Be Recorded

  • The identifying characteristics of the items tested, so the sample can be reconstructed. 'Tested 25 invoices' fails; the invoice numbers or the selection basis passes.
  • Who performed the work and the date it was completed.
  • Who reviewed the work, and the date of review. Evidence of review is among the most commonly missing items in small-practice files.
  • Significant matters arising during the audit, the conclusions reached, and the significant professional judgements made in reaching them.
  • Discussions of significant matters with management and those charged with governance, including when they happened and with whom.
  • How any inconsistency between information obtained and the final conclusion was resolved.
  • Where a requirement of a standard was departed from, the reason and the alternative procedures performed to achieve its objective.

The judgement items are the ones practitioners skip, and they are the ones reviewers look for hardest. Materiality is the clearest example. Almost every file has a materiality figure; a much smaller share records why that benchmark was chosen for this entity, why that percentage, and what caused performance materiality to be set where it was. The number without the reasoning tells a reader nothing about whether the judgement was sound, which is the entire point of documenting it.

Assembly and Retention

Two timelines govern the file after the report is signed. The final audit file must be assembled on a timely basis after the date of the auditor's report, and the standard treats sixty days as an appropriate limit for that assembly. Assembly is an administrative process: collating, cross-referencing, discarding superseded drafts, and completing the file. It is expressly not an opportunity to perform new procedures or to reach conclusions that were not reached before the report was signed.

After assembly, documentation must be retained for a period not shorter than seven years from the date of the auditor's report. Once the file is assembled, the auditor must not delete or discard documentation before the end of that period. Where something genuinely does need to be added or modified after assembly, the standard requires recording the specific reason for the change, when it was made, and by whom. A file that shows an amendment with its reason is defensible; one that shows an amendment nobody can date or explain is considerably worse than one that was never amended.

Where Files Actually Fail

The gapWhat it looks like in the fileThe fix
No evidence of reviewWorking papers prepared by an article with no reviewer sign-off anywhereA review column on every schedule, initialled and dated before the report is signed
Materiality without a basisA figure on a summary sheet with no derivationA short memo: benchmark chosen, percentage applied, why both suit this entity
Unreconstructable samples'Verified on a test-check basis' with no identification of what was testedRecord the selection method and the identifying characteristics of every item
Missing engagement letterNo signed letter for the year under audit, or last year's on fileA signed letter for each year, filed before fieldwork starts
Significant judgements undocumentedA provision accepted with no record of what was consideredA memo on each significant matter: the issue, what was considered, the conclusion
Late or open-ended assemblyFiles still being completed months after the report dateA hard internal deadline inside the sixty-day limit, tracked per engagement

Why This Has Become Higher Stakes

Documentation used to be examined mainly when something had already gone wrong. That is no longer true. ICAI's peer review process examines files routinely as a condition of the certificate a growing number of practice units now need, and NFRA conducts audit quality inspections of firms within its jurisdiction and publishes reports naming the firm and describing what its files contained. In both settings the reviewer's only access to your audit is the paper. A practice that has been diligent for years but casual about evidencing it will read, in those reports, as a practice that was casual.

The encouraging part is that this is a template and habit problem rather than a competence problem. Firms that fix it usually do so with a handful of standard schedules carrying preparer and reviewer columns, a materiality memo, an independence memo, and a rule that no report is signed until the file is complete. None of it requires expertise the firm does not already have. It requires that the reasoning already happening in someone's head be written down while it is still fresh.

Frequently asked questions

Sources and official references

Rules and rates change. These are the primary sources for the topics covered above, and the place to confirm anything before you act on it.

Disclaimer

This article is for general informational purposes only and does not constitute professional tax, legal, or financial advice. Rules and rates change, so consult a qualified Chartered Accountant for advice specific to your situation.

Related reading