Internal Audit Working Papers: Best Practices for Evidence & Review
Practical best practices for internal audit working papers — structure, evidence standards, preparer/reviewer workflow, and version control that holds up under external scrutiny.
Practical best practices for internal audit working papers — structure, evidence standards, preparer/reviewer workflow, and version control that holds up under external scrutiny.
Working papers are where an audit engagement either earns its conclusions or doesn’t. A finding that isn’t traceable to clear, reviewed evidence isn’t a finding — it’s an opinion. This guide covers the practical standards that keep working papers defensible, whether the audience is an audit committee, an external assessor, or a regulator.
A working paper has one job: let someone who wasn’t in the room reconstruct exactly what was tested, against what criteria, with what result, and who reviewed it. If a paper can’t do that on its own — without a verbal explanation from the auditor who wrote it — it isn’t finished, no matter how much testing actually happened.
That standard implies a working paper needs, at minimum:
Free-text narrative working papers are flexible but hard to review consistently and even harder to aggregate across an engagement. Wherever the testing is repeatable — sample-based control testing, reconciliations, exception testing — a typed grid (defined columns: sample item, attribute tested, expected result, actual result, exception Y/N, notes) produces a paper that’s faster to prepare, faster to review, and trivially easy to summarize into a report. Reserve free-text narrative for the things that genuinely need it: walkthroughs, process understanding, and conclusions.
This isn’t an argument against narrative entirely — it’s an argument for matching the format to the testing. A structured grid that gets forced into prose loses its reviewability; a walkthrough that gets forced into a grid loses its nuance.
“Reviewed the reconciliation and it appeared complete” is not evidence — it’s a claim about evidence that no longer exists in the file. The underlying document, screenshot, extract or export needs to be attached and cross-referenced directly from the working paper, with enough context (date pulled, source system, who provided it) that its provenance is clear months later.
This matters more than it sounds: the single most common weakness external quality assessors and peer reviewers cite in internal audit functions is evidence that doesn’t actually support the stated conclusion — either it’s missing, it’s insufficient, or the paper’s narrative doesn’t match what the attached evidence shows.
Every working paper needs an unambiguous record of who prepared it and who reviewed it, with review notes that are visible rather than resolved-and-deleted. A common anti-pattern is reviewers editing the preparer’s paper directly to “fix” it — this destroys the very trail that proves review happened and what it caught. Review comments should be additive: the reviewer raises a note, the preparer responds or revises, and both sides of that exchange stay in the record.
This two-person discipline is also your best defense against a rushed conclusion. A reviewer who has to document why they’re satisfied with a paper — not just tick a box — is a reviewer who’s actually reading it.
Working papers get revised — a reviewer note prompts additional testing, a sample gets expanded, a conclusion gets refined. None of that is a problem. What is a problem is when the current version silently overwrites what came before, because it erases the very evidence of iterative review that makes the working paper trustworthy. Keep every version, with a timestamp and author, so the paper’s evolution is as auditable as the conclusion it reaches.
A finding should never exist in isolation from the working paper that raised it. When an issue traces cleanly back to a specific paper — specific sample, specific exception, specific evidence — the resulting management action and remediation conversation stays grounded in fact rather than becoming a negotiation about interpretation. This linkage is also what makes report writing fast: a report built from properly cross-referenced working papers is largely an exercise in formatting and framing, not re-deriving conclusions from memory.
Good working paper discipline doesn’t start at fieldwork, though — it’s easiest to sustain when the engagement itself was scoped clearly from a risk-based plan. See our guides on building an audit universe and risk-based audit planning for how solid upstream planning makes the working paper stage more focused and less improvised.
Verity Audit’s working papers module gives you typed grids for structured testing, evidence attachments cross-referenced to procedures, an explicit preparer/reviewer workflow, and full version history on every paper — so the discipline described here is built into the tool, not dependent on individual habit.