Audit evidence is the information an auditor or tester obtains to support a conclusion. Workpapers (also called working papers or audit documentation) are the written record of the procedures performed, the evidence obtained, and the conclusions reached. The governing standards (PCAOB AS 1215 for public company audits, AICPA AU-C 230 for other financial statement audits, and Standard 14.6 of the IIA's 2024 Global Internal Audit Standards for internal audit) share one test: the documentation should allow an experienced reviewer with no prior connection to the work to understand what was done and reach the same result.
Audit evidence is the information an auditor, internal auditor, or independent tester obtains and evaluates to support a conclusion about whether a control, process, or assertion meets its criteria. Workpapers, also called working papers or audit documentation, are the record of that work: the procedures performed, the evidence obtained, and the conclusions reached. AICPA AU-C 230 defines audit documentation as "the record of audit procedures performed, audit evidence obtained, and conclusions the auditor reached," and PCAOB AS 1215 describes it as the written record of the basis for the auditor's conclusions. The same concepts apply to compliance testing, including BSA/AML independent testing.
Qualities of audit evidence
Auditing standards judge evidence on two dimensions. PCAOB AS 1105 states that sufficiency is the measure of the quantity of audit evidence and that appropriateness is the measure of its quality, meaning its relevance and reliability (AS 1105.05 to .08). AICPA AU-C 500 uses the same pair for audits of non-issuers.
- Relevance is the relationship between the evidence and the assertion or control objective being tested. A signed policy is relevant to whether a policy exists, but not to whether staff follow it.
- Reliability depends on the nature and source of the evidence and the circumstances in which it was obtained. Evidence obtained directly by the tester or from an independent source is generally more reliable than evidence supplied by the party under review, and original records are generally more reliable than summaries.
- Sufficiency is a matter of quantity. More evidence is needed where risk is higher or where the evidence obtained is of lower quality.
The IIA's Global Internal Audit Standards (2024), Standard 14.1, state the same idea for internal audit: information must be relevant, reliable, and sufficient, where sufficient means it would enable a prudent, informed, and competent person to repeat the engagement work program and reach the same conclusions.
Documentation standards
| Standard | Applies to | Core requirement |
|---|---|---|
| PCAOB AS 1215, Audit Documentation | Audits of public companies and SEC-registered broker-dealers | Documentation sufficient for an experienced auditor with no previous connection to the engagement to understand the work performed, who performed and reviewed it, and the conclusions reached. Retention for seven years from the report release date (AS 1215.14). |
| AICPA AU-C 230, Audit Documentation | Financial statement audits of non-issuers | Documentation sufficient for an experienced auditor to understand the nature, timing, and extent of procedures, the results and evidence, and significant findings (AU-C 230.08). Assembly of the final file within 60 days of the report release date and retention of not less than five years (AU-C 230.16 and .17). |
| IIA Global Internal Audit Standards (2024), Standard 14.6, Engagement Documentation | Internal audit functions that conform to the IIA Standards | Documentation that would allow an informed, prudent internal auditor or similarly competent person to repeat the work and derive the same results; review by the engagement supervisor and approval by the chief audit executive; retention according to law, regulation, and policy. |
Independent testing of a compliance program is often performed by internal audit or by a consulting firm rather than under a financial statement audit standard, but the same reperformance test is commonly used to judge whether its documentation is adequate.
What a workpaper contains
A workpaper for a single test normally records the following elements. IIA Standard 14.6 lists comparable content for an engagement as a whole: the period, risk assessment, objectives and scope, work program, description of analyses and data sources, results, the names of those who performed and supervised the work, and evidence of communication.
| Element | What it records |
|---|---|
| Objective | The control or requirement being tested and the criteria it is tested against, with the governing citation where one exists. |
| Population | The complete set of items from which the test draws (for example, all alerts closed in a quarter), its source system, date range, record count, and how completeness was confirmed. |
| Method | The procedure performed: inspection, reperformance, inquiry, observation, or data analysis, described precisely enough to repeat. |
| Sample or full population | Whether every item was tested or a sample was drawn; if a sample, the sampling method, sample size, selection basis, and whether results can be projected to the population. |
| Results | The outcome for each item tested, tied to the evidence examined. |
| Exceptions | Each item that failed the criteria, with the reason, and the analysis of whether the exceptions indicate an isolated error or a control failure. |
| Conclusion | Whether the control is designed and operating effectively, stated against the objective. |
| Preparer and reviewer sign-off | Who performed the work and when, and who reviewed it and when. AS 1215 requires documentation to show who performed the work and who reviewed it, with the date of review. |
Full-population testing, made practical by data analysis tools, removes sampling risk for the attributes tested, but the population's completeness and the accuracy of the underlying data still have to be established and documented.
Retention
Retention periods depend on the standard and on the records involved. The PCAOB requires seven years; AU-C 230 requires at least five years from the report release date; the IIA Standards defer to law, regulation, and organizational policy. Records reviewed during compliance testing may carry their own periods: for example, a bank must keep each suspicious activity report and its supporting documentation for five years from filing (31 CFR 1020.320(d)), and many Bank Secrecy Act records are subject to a five-year period under 31 CFR 1010.430.
Integrity and tamper-evidence
A workpaper is persuasive only if a reader can rely on it being the record as it stood when the work was completed. The standards address this through controls on changes: AS 1215 requires that documentation added after the documentation completion date indicate the date added, the name of the person who prepared it, and the reason, and AU-C 230 similarly governs modifications after the documentation completion date. IIA Standard 14.6 requires supervisory review of engagement documentation, approval by the chief audit executive, and retention under law and policy.
Electronic workpaper systems implement these requirements with several technical controls. Access controls and audit logs record who viewed or changed a file and when. Electronic signatures bind a preparer's or reviewer's sign-off to a specific version. A cryptographic hash, a short fixed-length value computed from a file's contents, changes if any part of the file changes, so a stored hash shows whether a file has been altered. A trusted timestamp, as specified in IETF RFC 3161 (Time-Stamp Protocol, 2001), is a token in which a time-stamping authority signs a hash together with the time, establishing that the file existed in that form at that time. None of these controls is mandated by name in the auditing standards; they are common means of meeting the standards' requirements on change control and retention.
How examiners use independent testers' workpapers
Bank examiners review the work of independent testers and may rely on it. The FFIEC BSA/AML Examination Manual's scoping and planning procedures begin with a review of the bank's risk assessment, independent testing, and prior examination conclusions, and Appendix H (Request Letter Items) asks the bank to provide the results of independent tests performed since the last examination, including the scope or engagement letter, management's responses, and access to the workpapers. Examiners assess whether the independent testing is adequate and whether it can be leveraged in assessing the program. Where the workpapers show a defined population, a stated method, traceable results, and a reviewer's sign-off, the examiner can reduce duplicate testing; where they do not, the examiner generally performs the testing directly. Examination preparation practices are covered in the BSA/AML exam preparation article.
Primary sources
- PCAOB AS 1215, Audit Documentation: Documentation content, who performed and reviewed the work, changes after completion, and seven-year retention.
- PCAOB AS 1105, Audit Evidence: Sufficiency and appropriateness (relevance and reliability) of audit evidence.
- AICPA AU-C 230, Audit Documentation, and AU-C 500, Audit Evidence: Documentation, assembly within 60 days, and retention of at least five years for audits of non-issuers.
- IIA, Global Internal Audit Standards (2024), Standards 14.1 and 14.6: Information that is relevant, reliable, and sufficient; engagement documentation that permits reperformance.
- IETF RFC 3161, Time-Stamp Protocol (2001): The protocol by which a time-stamping authority binds a hash of data to a time.
- FFIEC BSA/AML Examination Manual, Appendix H (Request Letter Items): Requests for independent testing results, engagement letters, management responses, and access to workpapers.
- 31 CFR 1020.320(d) and 31 CFR 1010.430: Five-year retention of SARs and supporting documentation, and general BSA record retention.