Early in her career, Meredith Mednick, CPA, CA, completed an audit procedure, got a result she liked, and decided to document it later.
Later came. The client had moved on, the files had been reorganized, and Meredith’s senior wanted a step-by-step explanation before signing off. Meredith had only a sticky note with a few bullet points and one mysterious abbreviation: “KINV.” She couldn’t reconstruct exactly what she tested, which evidence she reviewed or why the result was acceptable.
That uncomfortable moment frames Episode 4 of Audit Fundamentals, where Meredith points out that your documentation is your audit. Procedures, conversations, and conclusions that live only in your memory can’t support the audit opinion.
Write for the auditor who wasn’t in the room
Audit documentation is the written record of the procedures performed, relevant evidence obtained, and conclusions reached. Each part matters.
The file must show what you actually did, not simply what the audit program instructed you to do. It must include or clearly reference the schedules, confirmations, invoices, bank statements, and other evidence you examined. Finally, every procedure must lead to a conclusion.
This record supports the audit opinion, allows managers and partners to review the work, and gives next year’s team a reliable starting point. It also shows regulators, peer reviewers, and courts that the engagement complied with professional standards.
Under AU-C 230 and PCAOB AS 1215, documentation should allow an experienced auditor with no previous connection to the engagement to understand:
- The nature, timing, and extent of the procedures performed
- The evidence obtained and results of the procedures
- The significant judgments behind the conclusions
Your work paper can’t depend on what your senior already knows or on a conversation from last Tuesday. It must stand on its own.
Give the reviewer enough detail to retrace your work
Once we write for an unknown reviewer, specificity stops looking like busywork.
A heading such as “Revenue testing” provides almost no context. A useful opening identifies the account, assertion, period, objective, population, and sampling method. Meredith offers a stronger example: testing occurrence and cutoff for revenue transactions over $50,000 recorded from December 18 through 31, using 25 randomly selected items from a population of 142.
Procedure descriptions need the same level of detail. “Reviewed inventory balances” is too vague. Instead, explain that you obtained the December 31 inventory summary, agreed it to the trial balance, randomly selected 30 items, located them during the December 28 observation, counted them, compared the results with perpetual records, and tested the roll-forward of activity from December 28 to December 31.
Then organize the evidence so another auditor can follow it:
- Identify sampled items by invoice number, date, amount, or another unique detail
- Include referenced schedules or clearly cross-reference where they can be found
- Define every tick mark in a legend
- Connect each supporting document to the procedure and conclusion it supports
A document placed in the file without explanation isn’t useful evidence. It’s clutter.
Show the reasoning, especially when the evidence gets messy
Clear documentation does more than report a clean final answer. It shows how you handled uncertainty and contradictory information.
“Allowance reviewed; deemed reasonable” records a conclusion but not the judgment behind it. For a significant estimate, the file should explain the assumptions evaluated, alternatives considered, information tested, and reasons the team accepted or rejected management’s position.
For example, documentation of a goodwill impairment assessment should cover key assumptions, comparisons with market data or industry benchmarks, sensitivity analysis, testing of the underlying data, and the basis for the conclusion.
Contradictions also belong in the file. If a customer confirmation is $5,000 lower than the recorded receivable, document the difference, your investigation, the evidence obtained, and why you concluded it was a timing difference rather than a misstatement. The investigation is the work.
The same principle applies when management says damaged inventory will sell next quarter or that a related-party receivable is fully collectible. Record how you challenged that explanation and what independent support you examined. As Meredith explains, professional skepticism on the page is intellectual rigor.
Document promptly and protect the record
Good details get harder to capture over time. Under AU-C 230, you generally have to assemble the final file within 60 days of the report release date. PCAOB AS 1215 now allows just 14 days, down from 45, for audits of fiscal years beginning on or after December 15, 2025 (a year earlier for firms that audit more than 100 issuers). Those windows are for assembling the file, not finishing the work: procedures, documentation, and reviews must be complete before the report is released. Once the file is final, nothing can be deleted, and anything you add must record when it was added, who added it, and why; you can’t make additions appear as though they were always present.
Firms generally must retain files for five years for nonpublic audits and seven years for public-company audits. That means today’s work paper may need to speak for you years from now.
Aim to document procedures the same day or the next day. As you work, avoid these common mistakes:
- Don’t copy last year’s work paper and merely change the date. Reassess current-year risks and facts.
- Don’t describe a procedure without recording its result.
- Don’t rely on a client-prepared schedule simply because it foots and ties. Test the completeness and accuracy of its data.
- Don’t leave important conversations undocumented. Record who participated, when the discussion occurred, what was said, and how you evaluated it.
Firm templates and review styles may vary, but the professional standard doesn’t.
Treat every work paper as a story
Meredith encourages auditors to think of themselves as authors rather than form-fillers. A strong work paper tells a complete story: what you wanted to prove, what you did, what evidence you examined, what you found, and why the result supports your conclusion.
Before closing a work paper, ask:
- Could another auditor understand exactly what I did, found, and concluded without asking me?
- Does the file show that I independently evaluated management’s representations?
- Would a regulator reviewing it five years from now see that I followed the standards and reached a reasonable conclusion?
If any answer gives you pause, strengthen the file now. Then listen to the full episode for Meredith’s complete examples and guidance. Document your work like it matters, because it does.
