Skip to content
Reference

Audit Evidence and Workpapers: What They Are and What They Contain

The short version

Audit evidence is the information an auditor or tester obtains to support a conclusion. Workpapers (also called working papers or audit documentation) are the written record of the procedures performed, the evidence obtained, and the conclusions reached. The governing standards (PCAOB AS 1215 for public company audits, AICPA AU-C 230 for other financial statement audits, and Standard 14.6 of the IIA's 2024 Global Internal Audit Standards for internal audit) share one test: the documentation should allow an experienced reviewer with no prior connection to the work to understand what was done and reach the same result.

Audit evidence is the information an auditor, internal auditor, or independent tester obtains and evaluates to support a conclusion about whether a control, process, or assertion meets its criteria. Workpapers, also called working papers or audit documentation, are the record of that work: the procedures performed, the evidence obtained, and the conclusions reached. AICPA AU-C 230 defines audit documentation as "the record of audit procedures performed, audit evidence obtained, and conclusions the auditor reached," and PCAOB AS 1215 describes it as the written record of the basis for the auditor's conclusions. The same concepts apply to compliance testing, including BSA/AML independent testing.

Qualities of audit evidence

Auditing standards judge evidence on two dimensions. PCAOB AS 1105 states that sufficiency is the measure of the quantity of audit evidence and that appropriateness is the measure of its quality, meaning its relevance and reliability (AS 1105.05 to .08). AICPA AU-C 500 uses the same pair for audits of non-issuers.

The IIA's Global Internal Audit Standards (2024), Standard 14.1, state the same idea for internal audit: information must be relevant, reliable, and sufficient, where sufficient means it would enable a prudent, informed, and competent person to repeat the engagement work program and reach the same conclusions.

Documentation standards

StandardApplies toCore requirement
PCAOB AS 1215, Audit DocumentationAudits of public companies and SEC-registered broker-dealersDocumentation sufficient for an experienced auditor with no previous connection to the engagement to understand the work performed, who performed and reviewed it, and the conclusions reached. Retention for seven years from the report release date (AS 1215.14).
AICPA AU-C 230, Audit DocumentationFinancial statement audits of non-issuersDocumentation sufficient for an experienced auditor to understand the nature, timing, and extent of procedures, the results and evidence, and significant findings (AU-C 230.08). Assembly of the final file within 60 days of the report release date and retention of not less than five years (AU-C 230.16 and .17).
IIA Global Internal Audit Standards (2024), Standard 14.6, Engagement DocumentationInternal audit functions that conform to the IIA StandardsDocumentation that would allow an informed, prudent internal auditor or similarly competent person to repeat the work and derive the same results; review by the engagement supervisor and approval by the chief audit executive; retention according to law, regulation, and policy.

Independent testing of a compliance program is often performed by internal audit or by a consulting firm rather than under a financial statement audit standard, but the same reperformance test is commonly used to judge whether its documentation is adequate.

What a workpaper contains

A workpaper for a single test normally records the following elements. IIA Standard 14.6 lists comparable content for an engagement as a whole: the period, risk assessment, objectives and scope, work program, description of analyses and data sources, results, the names of those who performed and supervised the work, and evidence of communication.

ElementWhat it records
ObjectiveThe control or requirement being tested and the criteria it is tested against, with the governing citation where one exists.
PopulationThe complete set of items from which the test draws (for example, all alerts closed in a quarter), its source system, date range, record count, and how completeness was confirmed.
MethodThe procedure performed: inspection, reperformance, inquiry, observation, or data analysis, described precisely enough to repeat.
Sample or full populationWhether every item was tested or a sample was drawn; if a sample, the sampling method, sample size, selection basis, and whether results can be projected to the population.
ResultsThe outcome for each item tested, tied to the evidence examined.
ExceptionsEach item that failed the criteria, with the reason, and the analysis of whether the exceptions indicate an isolated error or a control failure.
ConclusionWhether the control is designed and operating effectively, stated against the objective.
Preparer and reviewer sign-offWho performed the work and when, and who reviewed it and when. AS 1215 requires documentation to show who performed the work and who reviewed it, with the date of review.

Full-population testing, made practical by data analysis tools, removes sampling risk for the attributes tested, but the population's completeness and the accuracy of the underlying data still have to be established and documented.

Retention

Retention periods depend on the standard and on the records involved. The PCAOB requires seven years; AU-C 230 requires at least five years from the report release date; the IIA Standards defer to law, regulation, and organizational policy. Records reviewed during compliance testing may carry their own periods: for example, a bank must keep each suspicious activity report and its supporting documentation for five years from filing (31 CFR 1020.320(d)), and many Bank Secrecy Act records are subject to a five-year period under 31 CFR 1010.430.

Integrity and tamper-evidence

A workpaper is persuasive only if a reader can rely on it being the record as it stood when the work was completed. The standards address this through controls on changes: AS 1215 requires that documentation added after the documentation completion date indicate the date added, the name of the person who prepared it, and the reason, and AU-C 230 similarly governs modifications after the documentation completion date. IIA Standard 14.6 requires supervisory review of engagement documentation, approval by the chief audit executive, and retention under law and policy.

Electronic workpaper systems implement these requirements with several technical controls. Access controls and audit logs record who viewed or changed a file and when. Electronic signatures bind a preparer's or reviewer's sign-off to a specific version. A cryptographic hash, a short fixed-length value computed from a file's contents, changes if any part of the file changes, so a stored hash shows whether a file has been altered. A trusted timestamp, as specified in IETF RFC 3161 (Time-Stamp Protocol, 2001), is a token in which a time-stamping authority signs a hash together with the time, establishing that the file existed in that form at that time. None of these controls is mandated by name in the auditing standards; they are common means of meeting the standards' requirements on change control and retention.

How examiners use independent testers' workpapers

Bank examiners review the work of independent testers and may rely on it. The FFIEC BSA/AML Examination Manual's scoping and planning procedures begin with a review of the bank's risk assessment, independent testing, and prior examination conclusions, and Appendix H (Request Letter Items) asks the bank to provide the results of independent tests performed since the last examination, including the scope or engagement letter, management's responses, and access to the workpapers. Examiners assess whether the independent testing is adequate and whether it can be leveraged in assessing the program. Where the workpapers show a defined population, a stated method, traceable results, and a reviewer's sign-off, the examiner can reduce duplicate testing; where they do not, the examiner generally performs the testing directly. Examination preparation practices are covered in the BSA/AML exam preparation article.

Primary sources

Common questions

What is the difference between audit evidence and workpapers?
Audit evidence is the information obtained to support a conclusion, such as records, documents, system data, and observations. Workpapers are the record of the audit: the procedures performed, the evidence obtained, and the conclusions reached.
What does sufficient appropriate audit evidence mean?
Under PCAOB AS 1105 and AICPA AU-C 500, sufficiency is the quantity of evidence and appropriateness is its quality, meaning relevance to the assertion or control objective and reliability given its nature, source, and the circumstances in which it was obtained.
How long must audit workpapers be kept?
PCAOB AS 1215 requires seven years from the report release date for public company audits. AICPA AU-C 230 requires at least five years from the report release date. The IIA Standards require retention in line with law, regulation, and organizational policy.
What should a compliance testing workpaper include?
It normally records the objective and criteria, the population and its source, the method, whether a sample or the full population was tested, results for each item, exceptions, a conclusion, and the preparer's and reviewer's sign-off with dates.
Do bank examiners look at independent testing workpapers?
Yes. The FFIEC BSA/AML Examination Manual's request letter items include the results of independent tests since the prior examination, the engagement letter, management's responses, and access to the workpapers. Examiners assess whether the testing is adequate and can be leveraged.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.