is-auditing9 min read

Audit Documentation and Working Papers

Learn best practices for audit documentation and working papers in IS auditing. Understand retention, review, and CISA exam expectations.

CISAPractice|

The Importance of Audit Documentation

Audit documentation, commonly referred to as working papers, is the written record of audit procedures performed, evidence obtained, and conclusions reached during an engagement. Proper documentation is essential for demonstrating that the audit was conducted in accordance with professional standards and provides a basis for the audit report. This is a foundational CISA exam topic.

Purpose of Working Papers

Working papers serve several critical purposes:

  • Evidence of work performed: They demonstrate that audit procedures were planned and executed in accordance with standards.
  • Support for findings: Working papers provide the evidentiary basis for audit findings, conclusions, and recommendations.
  • Quality assurance: They enable supervisory review of audit work to ensure quality and completeness.
  • Future reference: Working papers from prior audits provide background information for subsequent engagements.
  • Legal and regulatory compliance: In some jurisdictions, working papers may be required by regulators or needed as evidence in legal proceedings.

Types of Working Papers

Working papers typically include:

  • Planning documents: Audit programs, risk assessments, scope definitions, and engagement letters.
  • Evidence files: Copies of documents reviewed, screenshots, system configurations, interview notes, and data extracts.
  • Test results: Records of testing performed, including sample selection criteria, test procedures, results, and exceptions identified.
  • Analysis documents: Data analysis results, calculations, flowcharts, and process narratives.
  • Communication records: Correspondence with the auditee, meeting minutes, and status reports.
  • Summary documents: Findings summaries, conclusions, recommendations, and draft reports.

Standards for Documentation

ISACA standards require that audit documentation be sufficient to enable an experienced auditor with no prior connection to the engagement to understand the work performed, the evidence gathered, and the conclusions reached. Key requirements include:

  • Completeness: All significant audit procedures, evidence, and conclusions should be documented.
  • Clarity: Documentation should be clear and understandable without additional oral explanation.
  • Accuracy: Working papers must accurately reflect the work performed and evidence gathered.
  • Organization: Documentation should be logically organized and cross-referenced for easy navigation.
  • Timeliness: Working papers should be prepared contemporaneously with the work being performed, not retroactively.

Review and Approval

Working papers should be reviewed by the audit supervisor or manager before the audit report is finalized. The review process verifies that:

  • Audit objectives were met and the audit program was completed.
  • Evidence is sufficient and appropriate to support findings.
  • Conclusions are logical and well-supported.
  • Working papers comply with documentation standards.

Retention and Security

Working papers must be retained in accordance with organizational policies and regulatory requirements. Retention periods vary but typically range from five to seven years. Working papers must be stored securely because they often contain sensitive information about the organization's systems, controls, and vulnerabilities.

CISA Exam Tips

For the CISA exam, remember that working papers are the property of the audit organization, not the individual auditor. Access to working papers should be controlled, and they should not be shared externally without appropriate authorization. The key standard is that documentation should be sufficient for an experienced IS auditor, with no prior involvement in the engagement, to understand the work performed and the basis for conclusions reached.

Related Tags

IS AuditingCISA ExamAudit DocumentationWorking PapersAudit Standards

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free