An external quality assessor spends most of the first day with your workpapers, not with you. The assessor picks three to five engagements from the last plan year, opens each report, chooses a finding, and tries to walk it back to the evidence: report to findings summary, summary to test workpaper, test workpaper to the source document, and from there back to the work program step that called for the test. Where that chain breaks, the rating on Standard 14.6 breaks with it. The failure is rarely dramatic. In an April 2026 quality control review of a California state department’s internal audit engagement, the entire documentation finding came down to three items: no names or initials showing who performed and supervised the work, workpapers that were not cross-referenced, and no written summary for each audit step of the tests conducted, analyses performed, and conclusions reached. Nobody on that team thought their papers were weak until a stranger tried to read them.
This guide is the documentation standard I would hand a new audit manager: what the Global Internal Audit Standards actually require of engagement documentation and which standard says so, a twelve-element anatomy of a workpaper with the way each element fails, a tickmark legend and an indexing scheme, a 20-item reviewer checklist, a before-and-after rewrite of a weak MidState Beverage test workpaper, the five ways workpapers fail a quality assessment, and the retention, access, and tool settings that keep an archive defensible. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, which replaced the 2017 Standards on 9 January 2025, and it pairs with the site’s annotated audit workpaper example and the guide to audit evidence, which cover a single test workpaper and the evidence hierarchy in more depth than this page can.
In this guide
- What the Global Internal Audit Standards require of your workpapers
- The anatomy of a workpaper: twelve elements and how each one fails
- Tickmarks, cross-references, and an index a stranger can follow
- The reviewer’s job: sign-offs, review notes, and a 20-item checklist
- Before and after: rewriting a weak MidState Beverage settlement workpaper
- Five ways workpapers fail a quality assessment
- Retention, access, and electronic workpaper tools
- Adapting the standard: small functions, co-sourcing, advisory work, and analytics
- A 30-day documentation reset
What the Global Internal Audit Standards require of your workpapers
Engagement documentation has one standard of its own and half a dozen that lean on it. Standard 14.6, Engagement Documentation, sits in Domain V (Performing Internal Audit Services) under Principle 14, Conduct Engagement Work; the site’s Domain V guide traces all fourteen standards in that domain through a single engagement. The operative sentence of 14.6 is the test every reviewer should apply: the analyses, evaluations, and supporting information relevant to an engagement must be documented such that an informed, prudent internal auditor, or similarly informed and competent person, could repeat the work and derive the same engagement results. That wording is deliberately stronger than the 2017 Standard 2330 it replaced. “Repeat the work” means the workpaper must carry the population, the selection, the attributes, and the source, not just the result. “Derive the same engagement results” means the reasoning from exception to finding to conclusion has to be on the page rather than in the preparer’s head.
The same standard carries further requirements that functions tend to under-document. Internal auditors and engagement supervisors must review the documentation for accuracy, relevance, and completeness, and the chief audit executive must review and approve engagement documentation; in a function of any size that approval is delegated to a designated engagement supervisor through the methodologies Standard 9.3 requires, but the delegation itself has to be written down. Documentation must be retained according to relevant laws and regulations and the policies of both the internal audit function and the organization, and there is no fixed period anywhere in the Standards. The access and release expectations the 2017 Standards spelled out in 2330.A1, under which the chief audit executive controls access to engagement records and obtains senior management or legal counsel approval before releasing them to external parties, carry forward as the working rule, because the IIA’s two-way mapping folds 2330 and its implementation standards into 14.6; the site’s IPPF-to-GIAS mapping traces each of those moves standard by standard.
Supervision moved. Under the 2017 Standards, engagement supervision was 2340, next door to documentation. In the Global Standards it is Standard 12.3, Oversee and Improve Engagement Performance, in Domain IV under Principle 12, Enhance Quality: the chief audit executive must establish and implement methodologies for engagement supervision, quality assurance, and the development of competencies. The practical consequence is that a reviewer’s sign-off is now evidence for two standards at once. It shows the 14.6 review happened, and it shows the 12.3 supervision methodology is operating. An assessor who finds reviewer sign-offs dated after the report went out will write it up under both, and the Domain IV guide explains why the IIA treats supervision as quality machinery rather than engagement housekeeping.
| Standard | What it requires of engagement documentation | What a reviewer or assessor will ask to see |
|---|---|---|
| 14.6 Engagement Documentation | Documentation sufficient for an informed, prudent internal auditor or similarly informed and competent person to repeat the work and derive the same results; review for accuracy, relevance, and completeness; chief audit executive review and approval; retention per laws, regulations, and policy | One finding traced from the report to a source document without asking anyone a question; preparer and reviewer names and dates; the written delegation of approval; the retention schedule |
| 14.1 Gathering Information for Analyses and Evaluation | Information that is relevant to the engagement objectives, reliable because it was obtained through appropriate procedures from the best available source, and sufficient in quantity and detail to support the findings and conclusions | System, report ID, run date, and parameters for every extract; populations reconciled to an independent total; the reasoning behind each sample size |
| 14.2 and 14.3 Analyses and Potential Engagement Findings; Evaluation of Findings | Analyses that surface potential findings, then evaluation of each against the criteria to establish condition, cause, effect, and significance | An exception log that shows which exceptions became findings, which did not, and why |
| 14.5 Engagement Conclusions | Conclusions supported by the information gathered and consistent with the evaluated findings and the engagement’s rating criteria | A conclusion sentence that answers the workpaper’s stated purpose in the same terms and does not claim more than the results support |
| 13.6 Work Program | A documented work program designed to achieve the engagement objectives, approved before the work starts, with changes approved as they occur | Program steps that each point to a workpaper reference; a dated approval for any step added, dropped, or narrowed during fieldwork |
| 12.3 Oversee and Improve Engagement Performance | Methodologies for engagement supervision, quality assurance, and the development of competencies | Reviewer sign-offs dated before report issuance; review notes and their clearance; evidence that preparers received feedback |
| 12.1 Internal Quality Assessment | Ongoing monitoring of conformance plus periodic self-assessments | A quarterly workpaper QA sample with scored results and remediation, and the self-assessment that cites it |
| 8.4 External Quality Assessment | An external assessment at least once every five years, with a plan developed by the chief audit executive and discussed with the board | An archive that can produce any engagement from the last five plan years within a day |
| 5.1 and 5.2 Use of Information; Protection of Information | Information used in line with policies, laws, and regulations; confidentiality, privacy, and ownership of information respected | The access list for the workpaper system; masking of personal and account data; the approval trail for any external release |
| 11.4 Errors and Omissions | Corrected information communicated promptly to everyone who received a final communication containing a significant error or omission | Nothing, until a workpaper error reaches a report; then the correction memo and its distribution list |
What conformance looks like on paper
Assessors do not grade prose. They grade traceability, dates, and consistency, and they grade them from the outside in. The California review cited above is instructive because the reviewer never argued with the audit’s conclusions; the finding was that the papers could not show who did the work, could not be followed from one page to the next, and did not summarize what each step established. Every one of those three items is a structural feature you can build into a template and check in a review, which is why the anatomy and checklist sections below are organized around structure rather than writing quality. A function whose workpapers carry the purpose, source, procedures, results, conclusion, sign-offs, and two-way cross-references on every page will generally conform to 14.6 even when the writing is plain. A function whose papers read beautifully but leave the reviewer guessing where a number came from will not.
The evidence hierarchy behind 14.1 is the other thing assessors test without saying so. When a workpaper’s only support is “per discussion with the process owner,” the information is neither reliable in the standard’s sense nor sufficient, however competent the process owner. The site’s audit evidence guide ranks the sources; for documentation purposes the rule is that the workpaper must name the source at a level of detail that lets a second auditor request the same document from the same system for the same period and get the same numbers. “Settlement register, ERP route-accounting module, report RA-214, FY26, all depots, run 8 July 2026 by S. Okafor” meets the test. “Settlement data from the depots” does not.
The anatomy of a workpaper: twelve elements and how each one fails
A test workpaper is an argument with exhibits. The argument runs from a purpose, through a defined population and a stated procedure, to results and a conclusion that answers the purpose; the exhibits are the source documents, extracts, screenshots, and recalculations that make each step checkable. Every element below exists because a reviewer needs it to follow the argument without the preparer in the room. The element that gets skipped most often is the source, because the preparer knows where the data came from and cannot imagine anyone not knowing; the element that gets written worst is the conclusion, because preparers restate the results instead of answering the question the purpose asked. The site’s beginner’s guide to workpapers walks a new auditor through building each of these from scratch; this table is the standard a reviewer holds the finished page to.
| Element | Requirement | How it fails in practice | How a reviewer checks |
|---|---|---|---|
| Index and title | A unique reference in the engagement index; a title naming the control or assertion tested, the period, and the entity or location | Titles such as “Testing” or “Sample”; two papers carrying the same reference after a re-performance; a title that names the process but not the control | Open the index; every reference resolves to exactly one current page and the title alone tells you what was tested |
| Purpose | One or two sentences stating what this page establishes, tied to a work program step and an engagement objective | The purpose restates the control description or the program step instead of the question this test answers | The purpose names the program step, and the conclusion at the bottom answers it in the same terms |
| Source | Where every piece of information came from: system, report name and ID, run date and time, parameters, who ran it, who provided it | “Per client,” “obtained from AP,” or a file name with no report ID, date, or parameters | For every number on the page, a reader can name the document it came from and request it again |
| Information provided by the entity | Completeness and accuracy of any system-generated population or report addressed on the page or by cross-reference to the paper that tested it | The population is a spreadsheet the process owner emailed and nobody tied it to anything | A row count and total reconciled to an independent control total, or a cross-reference to the IPE paper that did the reconciliation |
| Scope and population | The period, the population definition, its count and value, and any exclusions with reasons | The population is implied by the sample; exclusions are silent; the period is “current year” with no dates | Count and value stated; exclusions listed with reasons; the population reconciled before the sample was drawn |
| Sampling | Method, size, rationale (frequency, risk, expected deviation), selection mechanism, and the retained selection list | “Judgmentally selected 25” with no criteria; the sampling tool’s output never saved; the seed or selection date missing | The size traces to the function’s sampling guidance; the selection list is attached; the seed or criteria are recorded |
| Procedures performed | What was done to each item, in the past tense, at the attribute level | The program step pasted in as if it described work done; “reviewed for appropriateness” with no attribute defined | The procedures are specific enough that a second auditor could repeat them without the preparer |
| Results | Item-by-item results per attribute with tickmarks, and totals of items tested, passed, and excepted | Blank cells in the test matrix; a summary “no exceptions noted” with no per-item evidence behind it | Every sample row has a result for every attribute and the totals foot |
| Exceptions and their disposition | Each exception numbered, described, root-caused, quantified, and either carried to the findings summary or explained | Exceptions waived as “isolated” or “immaterial” with no analysis; an exception in the matrix that never reaches the exception log | Each exception has a numbered log entry, a disposition, and a forward cross-reference |
| Judgments | Any judgment (sample size, extrapolation, deviation tolerance, reliance on another party’s work) stated as a judgment with the alternative considered | Judgments are invisible; a reader cannot tell a decision was made, let alone why | Judgments carry the words “we considered,” a reason, and a name |
| Conclusion | Answers the purpose in its own terms, design effective or not and operating effectively or not, with the basis stated | The conclusion claims more than the results support, or uses “satisfactory” and “adequate” without defining either | The conclusion is consistent with the results and every rated finding traces back to a conclusion |
| Sign-offs and dates | Preparer name and date; reviewer name and date after the preparer’s; review notes cleared before the report is issued | Reviewer dates after the report date; initials with no name key; “reviewed” on a paper that never drew a single note | The dates sequence correctly, the reviewer is identifiable, and note clearance is visible |
Put the elements into a header block that every template carries, and most of the anatomy takes care of itself. The block below is the one I use for control tests; substantive and analytic papers swap the sampling lines for the query, parameters, and script version. The bracketed fields are the only placeholders in this guide, because this is an explicit template.
[Reference] [Control or assertion tested] — [attribute(s)] — [period, entity/location]
Purpose. Determine whether [control] [operated as designed / was designed to address risk R-n] during [period], specifically whether [attribute A], [attribute B], and [attribute C]. Supports work program step [A-3.n] and engagement objective [n].
Source. [System], report [ID and name], run [date, time] by [name, role] with parameters [list]; [count] items, [value]. Completeness and accuracy tested at [reference]. Other documents: [list with who provided them and when].
Population and sample. [Count] items totaling [value] after excluding [exclusions and reasons]. Sample of [n] selected by [method] in [tool] on [date] (seed or criteria: [x]; selection list at [reference]), consistent with [sampling guidance reference] for a control operating [frequency].
Procedures. For each sampled item: (1) [procedure, tickmark]; (2) [procedure, tickmark]; (3) [procedure, tickmark].
Results. Attribute A: [x of n], exceptions [E-n]. Attribute B: [x of n], exceptions [E-n]. Totals: [tested / passed / excepted].
Evaluation and conclusion. [Design / operating conclusion in the purpose’s terms, with basis]. Exceptions carried to [E-1 log entries] and [E-2 findings summary, finding n]. Judgments: we considered [alternative] and [decision, reason].
Prepared by [name], [date]. Reviewed by [name, role], [date]. Review notes [RN-n to RN-n] at [G-3], cleared [date].
Tickmarks, cross-references, and an index a stranger can follow
Tickmarks are the shorthand that makes a test matrix readable, and they go wrong in exactly three ways: a mark that means one thing on page C-3 and another on page C-7, a mark that records a conclusion (“OK”) rather than a procedure, and a mark that has no legend at all. The discipline is short. A tickmark records a procedure performed, never a result; every tickmark on a page is defined either on that page or in the engagement-level legend at G-2, and the engagement legend is a copy of the function’s standard legend with any additions listed at the top; and an exception is never a bare tickmark, it is a numbered reference (E-7) that resolves to an entry in the exception log. The legend below is the one I would issue as the function standard. Functions that use electronic workpaper tools should load it as the tool’s tickmark set so that preparers cannot invent new marks page by page.
| Tickmark | Meaning | What must exist for you to use it | Common misuse |
|---|---|---|---|
| ✓ | Agreed to the source document named in the column header | The source document, attached or locatable by the reference given | Used to mean “looks fine” with no source named in the header |
| F | Footed: the column total was recomputed by the auditor | The recomputation and the report total it agreed to | Applied to a total nobody re-added |
| CF | Cross-footed: rows and columns both recomputed | Both recomputations | Used where only the columns were footed |
| R | Recalculated from the inputs shown on the page | The inputs and the formula or method | Used where the auditor only compared two reports to each other |
| GL | Agreed to the general ledger or trial balance at the date stated | A ledger extract or screenshot with the date and account | Agreed to a subledger and called GL |
| SR | Agreed to the system record (screen or table) at the referenced screenshot | A screenshot showing the system, the date and time stamp, and the user | A screenshot of a spreadsheet presented as a system record |
| IPE | Completeness and accuracy of this report were tested at the referenced paper | The referenced IPE workpaper with a reconciliation to an independent total | Placed on any system report to signal “it came from the system,” with no test performed |
| C | Confirmed directly with an independent third party | The confirmation and the record of how it was sent and received under the auditor’s control | Applied to a confirmation the auditee obtained and forwarded |
| I | Corroborated inquiry: statement obtained from the named person and corroborated by the referenced evidence | Name, title, date, and the corroborating reference | Used for an uncorroborated conversation |
| O | Observed by the auditor on the date stated | Date, location, what was observed, and by whom | An observation written in the present tense as if it were a description of policy |
| PY | Agreed to the prior engagement’s workpaper at the reference given | The prior paper, still in the archive and not superseded | Reliance on a prior paper that was itself never reviewed |
| N/A | Attribute not applicable to this item; reason stated in the notes column | The reason | Used to skip an attribute the preparer could not test |
| Ø | Attribute tested, no exception | The per-item procedure actually performed on that item | A column of Ø entered before the testing finished |
| E-n | Exception number n; see the exception log at E-1 | The log entry with description, root cause, quantification, and disposition | Exceptions described in a cell comment with no log entry |
Cross-references only work when they are two-way and specific. A forward reference from a test paper to the findings summary (“carried to E-2, finding 1”) is worth nothing to an assessor tracing backward from the report unless E-2 also points to C-3.2, and a reference to “C-3” is not enough when the exception lives in row 44 of the second matrix on that paper. The rule I enforce is that any number appearing in the report has a reference in the findings summary, every entry in the findings summary references the test paper and row that produced it, and every work program step cites the paper that executed it, so that the trace runs in both directions from any starting point. The site’s work program guide shows the step-to-workpaper column that makes the backward trace mechanical; the indexing scheme below is the engagement structure those references live in.
| Section | Contents | Example references |
|---|---|---|
| A Planning | Engagement memo, engagement risk assessment, objectives and scope, evaluation criteria, resource plan, work program and its approvals | A-1 engagement memo; A-2 risk assessment; A-3 work program; A-3.4 program step 4 with its approval date |
| B Understanding | Walkthroughs, flowcharts, control descriptions, the risk and control matrix, staffing and system inventories used as reference data | B-2 route cash walkthrough; B-3 FY26 depot staffing list; B-4 risk and control matrix |
| C Control testing | One paper per control test; decimal suffixes for separate attributes or re-performances; letter suffixes for selection lists and extended samples | C-3 settlement reconciliation; C-3.2 independence and override test; C-3.2a selection list |
| D Substantive procedures and analytics | Full-population analytics, recalculations, scripts with parameters and version, IPE tests for the extracts they consume | D-1 self-approved override analytic; D-1.1 script, parameters, and completeness test of RA-214 |
| E Findings | Exception log, findings summary with severity ratings, root cause analyses, management’s factual accuracy responses | E-1 exception log; E-2 findings summary; E-2.1 severity rationale for finding 1 |
| F Reporting | Draft reports by version, management responses and action plans, closing meeting notes, final report as issued | F-1 draft v3 of 22 Aug 2026; F-2 management responses; F-4 final report |
| G Administration | Sign-off log, review notes and clearances, engagement tickmark legend, budget versus actual hours, retention and release record | G-1 sign-off log; G-2 tickmark legend; G-3 review notes RN-1 to RN-31 |
The reviewer’s job: sign-offs, review notes, and a 20-item checklist
Review is not editing, and the reviewers who treat it as editing produce the least useful sign-offs in the function. The reviewer’s job under 12.3 and 14.6 is to establish three things: that the work described was performed on the evidence cited, that the results support the conclusion, and that the conclusion supports what the report will say. Everything else, including sentence structure, is secondary. In a function with a manager and staff, I run three levels. The preparer performs a documented self-review against the checklist before signing. The engagement supervisor performs a detailed review of every test paper, re-performing at least one sampled item per paper and tracing every exception to the log. The audit manager or chief audit executive performs a summary review of the findings summary, the conclusions, and the report, plus a detailed review of any paper supporting a finding rated High or above under the function’s severity rating scale. Timing is part of the standard in practice even though the Standards state no number: my house rule is detailed review within five business days of the preparer’s sign-off, and no draft report leaves the function until every review note is cleared.
A review note is a question the workpaper failed to answer, written so that the answer becomes part of the record. Notes fall into four kinds, and the kind should be visible in the note: an evidence gap (the source, the item, or the screenshot is missing), a logic gap (the results do not support the conclusion, or an exception was waived without analysis), a scope gap (the program step was not fully executed, or a change to the step was not approved), and presentation (the page cannot be followed without the preparer). The clearance protocol is one exchange: the reviewer writes the note with a reference to the cell or paragraph, the preparer responds by changing the workpaper (not by replying in the note), and the reviewer clears the note only after confirming the change on the page. Whether cleared notes are retained is a policy decision, and it should be made once and written down. A function whose regulator or external auditor examines its papers should retain notes and clearances because they are the best evidence of supervision; a function under no such examination can delete cleared notes at archive lock provided the sign-off log records how many notes were raised and cleared per paper, which preserves the 12.3 evidence without preserving every exchange.
| # | Reviewer check | What a pass looks like | If it fails |
|---|---|---|---|
| 1 | The purpose ties to a work program step and an engagement objective | Step reference and objective number appear in the purpose sentence | Scope-gap note; if the step is not in the program, get the addition approved and dated at A-3 |
| 2 | Every source is named to the level of system, report ID, run date, parameters, and provider | A second auditor could re-request the same extract without asking | Evidence-gap note; no further review until the source is fixed, because everything downstream depends on it |
| 3 | Completeness and accuracy of each system report are addressed or cross-referenced | Row count and value reconciled to an independent total, or an IPE reference | Evidence-gap note; the population is not yet a population |
| 4 | The population is defined by period, count, value, and exclusions | All four stated before the sample paragraph | Evidence-gap note; ask what was excluded and why |
| 5 | The sample method, size, rationale, and selection list are documented | Size ties to the function’s guidance; selection list attached with seed or criteria | Logic-gap note; an unsupported sample size undermines the conclusion, not just the paper |
| 6 | Attributes tested match the control as documented in the walkthrough | Each attribute maps to a design element on the B-section paper | Scope-gap note; testing a control other than the one in the matrix |
| 7 | Every sampled item shows a result for every attribute | No blank cells; totals foot to the sample size | Evidence-gap note; blanks are untested items |
| 8 | Each exception is numbered, described, root-caused, quantified, and dispositioned | Matrix references E-n; log entry complete; disposition states finding or reason for none | Logic-gap note; “isolated” and “immaterial” require analysis, not assertion |
| 9 | Every tickmark on the page appears in the legend | Marks match G-2 exactly; any addition is listed there | Presentation note; undefined marks are unreadable to an assessor |
| 10 | Evidence is attached or located precisely | File name, page, row, or screenshot time stamp given for each item | Evidence-gap note; re-perform one item to test whether the locator works |
| 11 | Judgments are stated as judgments with the alternative considered | “We considered X; we did Y because Z” with a name | Logic-gap note; an undocumented judgment reads as an oversight later |
| 12 | The conclusion answers the purpose in the same terms | Design and operating effectiveness addressed separately where both were in scope | Logic-gap note; a conclusion on a question the purpose did not ask |
| 13 | The conclusion is consistent with the results | No “operating effectively” above unexplained exceptions | Logic-gap note; the most common QA failure, so re-read the results before clearing |
| 14 | Cross-references run in both directions | Forward to E-1 and E-2, backward to A-3 and B-section; targets reference this paper | Presentation note; fix both ends |
| 15 | Re-performance of at least one item reproduces the recorded result | Reviewer initials the re-performed row with the date | If it does not reproduce, stop and extend the re-performance before any other note is cleared |
| 16 | Preparer name and date precede the reviewer name and date | Full names or an initials key at G-1; dates sequence correctly | Presentation note; initials without a key fail 14.6 by themselves |
| 17 | Prior review notes are cleared on the page, not in the note thread | The change is visible in the workpaper; the note references the change | Do not clear; a reply is not a fix |
| 18 | Superseded versions are marked and no orphan drafts remain | One current version; earlier versions marked superseded with a date | Presentation note; two live versions are a QA finding waiting to happen |
| 19 | Confidential data is minimized | Account numbers, national IDs, and pay data masked or truncated per policy | Evidence-gap note in reverse: remove what the test does not need |
| 20 | The numbers on the page agree to the findings summary, the issue log, and the draft report | Counts, percentages, and dollar amounts identical in all four places | Logic-gap note; fix at the source and re-flow forward |
The wording of a review note matters more than reviewers expect, because notes are read later by people deciding whether supervision was real. A note that says “see me” or “fix” proves nothing; a note that names the gap, cites the cell, and states what would clear it is evidence of supervision in its own right. The three notes below are the pattern. Notice that each one is specific enough that a different reviewer could confirm the clearance.
RN-14 (evidence gap, C-3.2, Source paragraph). The settlement register is cited by file name only. State the ERP report ID, run date and time, parameters, and who ran it, and cross-reference the completeness test at D-1.1. Cleared when the Source paragraph carries all five items and D-1.1 reconciles the 37,400 count to the module control total.
RN-16 (logic gap, C-3.2, Conclusion). The conclusion says the control is operating effectively, but attribute B shows 44 of 60 settlements reconciled by the route supervisor who also prepares the driver’s route sheet. That is a design condition at nine depots, not an operating exception. Restate the conclusion separately for design and for operating effectiveness, carry the design condition to E-2, and state why the three cashier depots are excluded from it.
RN-17 (judgment, C-3.2, Sample paragraph). The paper does not say why the sample was not extended at the three depots with an independent cashier. If the decision was to rely on the D-1 full-population analytic for attribute D, say so in a Judgments sentence with the reason, so that the reader does not conclude the extension was overlooked.
Before and after: rewriting a weak MidState Beverage settlement workpaper
MidState Beverage is the site’s running example: a three-state distributor with 12 depots and 300 delivery routes, where roughly 4,200 smaller customers pay drivers in cash and checks, about $31 million a year and 14 percent of revenue, on a 2013 ERP route-accounting module supplemented by depot spreadsheets. In FY26 a Dayton depot driver diverted $18,400 over five months before a customer complaint exposed it, and the six-person internal audit function put route cash handling first on the FY27 plan. Control C-3 in the risk and control matrix reads: each driver’s daily settlement is reconciled to the handheld and the deposit by depot personnel independent of the route, variances over $25 are investigated and documented, and any override of a variance is approved by a depot manager other than the person who prepared the settlement. The engagement was the one later reported as FY27-01 and rated Unsatisfactory, with five findings that included settlement reconciliations not independent at 9 of 12 depots and variance overrides self-approved on 1,412 of 37,400 settlements. The first draft of the test workpaper supporting those two findings is below, reproduced as the preparer submitted it.
BEFORE — C-3.2 Settlement reconciliation testing
Purpose: To test the settlement reconciliation control.
Work performed: Obtained settlement reports from the depots and selected a sample of settlements for testing. Reviewed the settlements for evidence of reconciliation and approval. Discussed the process with depot managers. Some depots do not have a second person available to perform the reconciliation, so the route supervisor performs it. Overrides are approved in the system.
Results: No exceptions noted in the sample other than the above.
Conclusion: Control is operating effectively.
Prepared by: JT
Read as an assessor would, this page fails almost every element. The purpose does not say which attributes were tested or which program step it serves. The source is “settlement reports from the depots,” which means seven of them came from spreadsheets re-keyed outside the ERP and nobody can tell which. There is no population, no count, no sample size, no selection method, and no attributes; “reviewed for evidence of reconciliation and approval” is a program step, not a procedure. The single most important fact the preparer learned, that the route supervisor reconciles the settlements at most depots, is recorded as an aside and then contradicted by the conclusion. The “no exceptions other than the above” sentence hides a design deficiency inside an operating conclusion, and there is no reviewer, no date, and no way to tell whether JT is one person or two. Nothing here would let a second auditor repeat the work or derive the same result, which is precisely the 14.6 test. The rewrite that cleared review is below. The numbers are the engagement’s actual numbers; the only change is that they are now on the page.
AFTER — C-3.2 Daily settlement reconciliation: independence of reconciler and approval of variance overrides (control C-3, attributes B, C, and D; FY26; all 12 depots)
Purpose. Determine whether control C-3 operated as designed during FY26, specifically whether (B) each settlement was reconciled by a person independent of the route, (C) variances over $25 were investigated and documented, and (D) overrides were approved by a depot manager other than the person who prepared the settlement. Supports work program step A-3.4 and engagement objective 2 (cash collected by drivers is completely and accurately deposited).
Source. ERP route-accounting module report RA-214 (Settlement Register), run 8 July 2026 at 09:14 by S. Okafor (internal audit) with parameters FY26, all depots, status posted: 37,400 settlements, $31.2 million in cash and check collections. Completeness and accuracy tested at D-1.1, where the row count agreed to the module control total and the value agreed to FY26 route cash deposits per the treasury deposit summary within $6,140, the difference being two deposits in transit at year-end. Deposit listings for the seven depots that maintain them outside the ERP were obtained from the depot managers between 9 and 11 July 2026 and are indexed at C-4. FY26 depot staffing and route assignment list from HR at B-3.
Population and sample. 37,400 settlements; no exclusions. Sample of 60 selected at random in mySampler on 8 July 2026 (seed 20260708; selection list at C-3.2a), consistent with the function’s sampling guidance for a control that operates many times daily. No stratification, because the full-population analytic at D-1 covers attribute D for every settlement and the report will distinguish depots by name.
Procedures. For each of the 60 settlements: (1) agreed the settlement total to RA-214 and to the depot deposit listing (✓); (2) identified the preparer from the handheld sync record and the reconciler from the settlement approval field (SR, screenshots at C-3.2b); (3) compared the reconciler’s role and route assignment to B-3 to determine independence from the route; (4) for the 11 settlements with a variance over $25, read the variance note and traced the resolution to the following day’s settlement or a documented write-off (SR); (5) for the 7 settlements carrying an override, compared the override approver’s user ID to the preparer’s user ID (SR).
Results. Attribute A (agreed to register and deposit listing): 60 of 60, no exception. Attribute B (independent reconciler): 16 of 60 reconciled by a dedicated depot cashier, all at the three depots that employ one; 44 of 60, across the other nine depots, reconciled by the route supervisor who also assigns the driver’s route and reviews the same driver’s handheld, and who is therefore not independent of the route. Attribute C (variance investigated): 9 of 11 documented; 2 exceptions (E-7, E-8), both at Dayton, with a blank variance note. Attribute D (override approved by another person): 4 of 7 approved by a different user; 3 of 7 self-approved (E-9, E-10, E-11). Full-population analytic at D-1: 1,412 of 37,400 settlements (3.8 percent) carry an override approved by the same user ID that prepared the settlement, present at all 12 depots.
Evaluation. Attribute B is a design deficiency rather than an operating failure: at nine depots the control as designed assigns the reconciliation to a person who is not independent of the route, so it cannot detect collusion between a driver and a supervisor or a supervisor’s own error, and this is the condition under which the FY26 Dayton diversion of $18,400 continued for five months until a customer complained. Attribute D is an operating deficiency at every depot; the ERP permits self-approval and no one monitors the override log. Attributes A and C do not provide a basis for reliance on the two Dayton settlements with blank variance notes.
Conclusion. Control C-3 is not designed effectively at 9 of 12 depots (attribute B) and is not operating effectively for override approval at any depot (attribute D). Carried to E-1 (entries E-7 to E-11) and to the findings summary E-2 as findings 1 and 2, with severity rationale at E-2.1. No reliance is placed on C-3 for engagement objective 2; substantive procedures were extended at D-2. Judgments. We considered extending the sample at the three cashier depots to conclude on operating effectiveness there separately; we did not, because the D-1 analytic already covers attribute D for the full population and the sample results at those depots showed no attribute B or C exception.
Prepared by J. Tran, 15 July 2026. Reviewed by M. Alvarez, engagement supervisor, 18 July 2026; re-performed items 7 and 41. Review notes RN-14 to RN-17 at G-3, cleared 21 July 2026.
The rewrite is longer, but not by as much as it looks, and every added sentence does a job. The table below maps each change to the anatomy element it repaired and the standard that required it, which is the exercise I ask new supervisors to do on their own first review. Two changes deserve comment. Separating design from operating effectiveness was the difference between a paper that supported the Unsatisfactory rating and one that undermined it, because “operating effectively” over a non-independent reconciler is a conclusion the external auditor would have rejected on sight; the design-versus-operating guide sets out the decision. And the D-1 full-population analytic is what turned three self-approved overrides in a sample of 60 into a finding with a number the audit committee could act on; the site’s sample size guide explains why 60 is the right sample for a control this frequent and why an analytic, not a bigger sample, is the right next step when the exception is systemic.
| Change made in the rewrite | Element repaired | Requirement it satisfies |
|---|---|---|
| Title now names the control, attributes, period, and locations | Index and title | 14.6: a reader can identify what was tested from the index alone |
| Purpose states three attributes and cites program step A-3.4 and objective 2 | Purpose | 13.6 and 14.6: the test traces back to an approved program step |
| Source names RA-214, the run date and time, the runner, the parameters, and the count and value | Source | 14.1: information reliable because its provenance is fixed and reproducible |
| Completeness and accuracy cross-referenced to D-1.1 with the reconciliation result and the $6,140 difference explained | Information provided by the entity | 14.1: a population that is demonstrably complete |
| Sample of 60 with method, tool, date, seed, selection list, and the guidance it follows | Sampling | 14.1 and 14.6: the selection can be repeated exactly |
| Five numbered procedures with tickmarks and screenshot references | Procedures performed | 14.6: a second auditor could repeat the work |
| Results stated per attribute with counts, and each exception numbered to the log | Results; exceptions and disposition | 14.2 and 14.3: potential findings identified and evaluated |
| Evaluation separates the design condition at nine depots from the operating failure on overrides | Judgments; conclusion | 14.3 and 14.5: findings evaluated against criteria before concluding |
| Conclusion answers the purpose in its own terms and states where the findings were carried | Conclusion | 14.5 and 14.6: conclusions supported and traceable forward |
| Judgments sentence records the decision not to extend the sample and why | Judgments | 14.6: reasoning that lets a reader derive the same result |
| Full names, roles, dates, re-performed items, and review note references | Sign-offs and dates | 12.3 and 14.6: supervision performed and evidenced before issuance |
Five ways workpapers fail a quality assessment
Internal assessments under Standard 12.1 and the external assessment under 8.4 use the same method, and the method is the reason the same five failures recur across functions that otherwise have little in common. The assessor selects engagements, not workpapers; a typical external assessment of a mid-sized function samples somewhere between four and eight engagements from the last plan year, weighted toward those with High findings and those performed by co-source partners, and an internal quarterly QA samples two or three. For each engagement the assessor traces forward from the work program to the papers, backward from the report to the evidence, and sideways from the sign-off log to the dates, then interviews the preparer and the reviewer separately about how a specific exception was dispositioned. Prose quality never comes up. The site’s guide to preparing for an external quality assessment covers the whole QAIP; the table below covers the part of it that lives in the archive.
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| The conclusion outruns the evidence | “Operating effectively” above a matrix with unexplained exceptions; “no issues noted” on a paper whose narrative mentions a control that is not performed at most locations; a Satisfactory rating supported by three papers that each conclude “partially effective” | This is the failure an assessor treats as a competence problem rather than a documentation problem, because it means the function’s opinions are not evidence-based; it is also the one an external auditor relying on the work will find first | Enforce reviewer check 13 as a hard stop; require design and operating conclusions to be stated separately; require every rated finding to cite the paper and row that supports its condition statement |
| The source of the population cannot be established | Populations described as “from the system” or “provided by management”; extracts with no report ID, date, or parameters; IPE tickmarks on reports nobody tested; spreadsheets from the auditee used as the population without a reconciliation | Without provenance the information is not reliable under 14.1, and without a completeness test the sample is drawn from an unknown population, so every conclusion downstream is unsupported | Make the Source paragraph mandatory in the template; test completeness and accuracy once per extract at a D-section paper and cross-reference it; follow the IPE testing procedure for any report the test depends on |
| Judgments are invisible | Sample sizes with no rationale; exceptions waived as “isolated” with no analysis; a program step dropped mid-fieldwork with no approval; reliance on a prior-year paper or a co-source deliverable with no statement that reliance was decided | An assessor cannot distinguish a considered decision from an oversight, and 13.6 requires program changes to be approved; undocumented judgments also fail the “derive the same results” test because the reader cannot follow the reasoning | Add a Judgments sentence to the template; require a dated approval entry at A-3 for any step change; log every waived exception in E-1 with the reason it is not a finding |
| Supervision is not visible, or happened after the fact | Reviewer sign-offs dated after the report; initials with no key; papers that show “reviewed” but never drew a note; review notes cleared by a reply rather than a change; the same person as preparer and reviewer with no compensating review recorded | Fails 14.6 (review for accuracy, relevance, and completeness) and 12.3 (supervision methodology) simultaneously, and it is the item most often quoted verbatim in assessment reports because it is so easy to evidence | Configure the tool so a paper cannot be marked complete without a reviewer sign-off dated after the preparer’s; keep a sign-off log at G-1 with full names; set the report issuance checklist to block issuance while any note is open |
| The report does not reconcile to the papers | A percentage in the report that does not appear in any workpaper; a finding in the report with no E-2 entry; an E-2 entry that was dropped from the report with no closing meeting record explaining why; management responses that changed a fact and the workpaper was never updated | The assessor’s backward trace fails at the first step, and the function cannot show that what it told the audit committee was what its evidence showed; if the difference is material, Standard 11.4 requires a correction to everyone who received the report | Reconcile the final report to E-2 line by line before issuance and file the reconciliation at F-3; require any post-draft change to a fact to be made in the workpaper first; use the report template’s findings table so the report and E-2 share a structure |
What the assessor does with your archive, step by step
Knowing the procedure lets you run it on yourself each quarter, which is what 12.1’s ongoing monitoring is meant to be. The assessor opens the final report and lists every finding, rating, number, and percentage. For each, they locate the E-2 entry and the paper it cites, open that paper, and check that the condition statement in the report matches the results on the page, including the counts. They open the work program and confirm each step has a paper reference and each paper has a step, then check the approval dates on any step that changed. They open the sign-off log and check that every paper’s reviewer date follows its preparer date and precedes the report date, and that the reviewer is a different person. They pick one exception and ask the preparer and the reviewer, separately, how it was dispositioned and where that is written down. The functions that pass are the ones where the two answers match and both point to E-1.
Scoring the internal QA sample the same way the external assessor will score it removes the surprise. My scoring sheet has the 20 reviewer checks as rows and the sampled papers as columns, marks each cell pass or fail, and reports three numbers to the chief audit executive each quarter: the pass rate by check, the pass rate by preparer, and the pass rate by reviewer. The third number is the one that changes behavior. A reviewer whose papers fail check 13 (conclusion consistent with results) at twice the function average is not reviewing, whatever the sign-off log says, and the self-assessment required under 12.1 should say so in plain terms, because the external assessor will.
Retention, access, and electronic workpaper tools
Standard 14.6 sets no retention period; it requires retention according to laws, regulations, and the policies of the organization and the function, which means the function must write a schedule and be able to show where each line of it came from. The schedule should be driven by the longest obligation that touches each class of engagement, not by a single number applied to everything, and it should name the trigger date (report issuance, not fieldwork end). The table below is the set of drivers I would expect a retention schedule to address. The periods in the second column are the ones commonly adopted in practice and the reasons for them; the only figures that are legal requirements are the external auditor’s own seven-year obligation under PCAOB AS 1215 and SEC Rule 2-06, which bind the external auditor rather than internal audit but set the horizon over which the external auditor may need to revisit work it relied on.
| Retention driver | Horizon commonly adopted and why | What to write in the policy |
|---|---|---|
| External quality assessment (Standard 8.4) | At least the last full five-year cycle, because the assessor may sample from any plan year since the previous assessment | “Engagement archives are retained for no less than six years from report issuance so that a full assessment cycle plus the year in progress is always available” |
| External auditor reliance for ICFR support (Sarbanes-Oxley section 404) | Seven years from the external auditor’s report date, mirroring the external auditor’s own documentation retention under PCAOB AS 1215 and SEC Rule 2-06 | “Workpapers supporting work relied upon by the external auditor are retained for seven years from the related audit report date”; see the site’s SOX 404 guide for what reliance involves |
| Regulatory examination access (banking, insurance, healthcare, government) | The organization’s records schedule for examination-related records, commonly five to seven years, because examiners request prior-cycle audit work | “Engagements in regulated activities follow the corporate records schedule for [record class], currently [n] years, and are flagged in the archive index” |
| Litigation hold | Indefinite from the date counsel issues the hold until counsel releases it in writing | “Upon notice from the general counsel, the chief audit executive suspends deletion for the named engagements and records the hold at G-5” |
| Investigations and fraud-related engagements | Longer than routine assurance work, commonly ten years or the statute of limitations for the underlying claims, because the papers may be evidence | “Investigation files are retained for [n] years or until counsel confirms all related matters are closed, whichever is later” |
| Advisory and consulting engagements | The same schedule as assurance work unless the engagement agreement set a shorter one, because 14.6 does not distinguish and a later assurance engagement may rely on the advisory papers | “Advisory engagement records follow the assurance schedule; any exception is recorded in the engagement memo at A-1” |
| Personal data in workpapers | The minimum the test requires, masked where possible, deleted at the end of the engagement’s retention period without exception | “Personal data is limited to what the procedure requires; identifiers are truncated or masked in the archive copy; deletion at the end of retention is verified and logged” |
Access is the second half of the same standard, and it has two directions. Inward, the workpaper system’s access list should be role-based, reviewed at least annually as part of the function’s own user access review, and restricted so that auditees never hold write access to an engagement’s papers and preparers cannot alter a paper after archive lock. Outward, release to anyone outside the organization, whether an external auditor, a regulator, an acquirer’s due diligence team, or opposing counsel, follows the rule the Standards inherited from 2330.A1: the chief audit executive controls access and obtains the approval of senior management or legal counsel before release, as appropriate. The practical version is a release log at G-5 recording what was released, to whom, on what date, under whose approval, and whether the release was the archive copy or an excerpt. External auditors relying on the function’s work under their own standards will ask for read access to specific papers rather than the archive; give them the papers, log the release, and do not give them a login. Confidentiality obligations under Standards 5.1 and 5.2 apply to the workpapers as much as to the information in them, which the Domain II guide spells out.
Electronic workpaper tools enforce most of this if they are configured to, and undermine it if they are not. The platforms in common use (TeamMate+, AuditBoard, Workiva, Diligent, and several smaller ones) all offer the settings in the table below; the failures I see come from functions that migrated their Excel habits into the tool without turning the controls on. Two settings matter more than the rest. Sign-off locking, which prevents a paper from being edited after the reviewer signs unless the sign-off is explicitly removed and the removal logged, is the single control that makes the sign-off date mean anything. And archive lock, which freezes the engagement a fixed number of days after report issuance, is what stops the archive from drifting as people “tidy up” papers a year later. My house rule is lock at 60 days from issuance, with anything added afterward filed as a dated addendum rather than an edit; the Standards state no number, and a function with an external auditor relying on its work should align the window with that auditor’s expectations.
| Tool setting | Configure it as | Why |
|---|---|---|
| Role-based access | Preparer, reviewer, manager, read-only, and external read-only roles; auditees limited to a request portal, never the engagement folder | Standards 5.2 and 14.6; prevents the auditee from seeing draft conclusions or altering evidence |
| Sign-off sequencing | Reviewer sign-off cannot be applied until preparer sign-off exists and the reviewer is a different user | Makes the 12.3 supervision evidence self-enforcing; removes the “same person prepared and reviewed” failure |
| Sign-off locking | Any edit after reviewer sign-off removes the sign-off and logs the removal with user and time stamp | The sign-off date is only evidence if the paper is the paper that was signed |
| Review note workflow | Notes carry a category, a cell or paragraph reference, and can be cleared only by the reviewer who raised them or the manager | Preserves the note-response-clearance exchange as evidence and prevents self-clearing |
| Tickmark set | The function’s standard legend loaded as the only available marks; additions require manager approval | Keeps meaning consistent across engagements and stops page-level inventions |
| Program-to-workpaper linking | Every program step must link to at least one paper before the engagement can move to reporting | Makes the 13.6 trace mechanical and surfaces unexecuted steps before the report is drafted |
| Version history | Retained for every attachment and narrative, with superseded versions visible but marked | Answers “what did the paper say when it was signed” without relying on memory |
| Issuance gate | Report cannot be marked issued while any review note is open or any paper lacks reviewer sign-off | Turns the house rule into a control the assessor can test |
| Archive lock | Automatic at the policy window after issuance; addenda allowed as new dated items only | Freezes the record the assessor and the external auditor will see |
| Retention job | Deletion scheduled by engagement class per the retention table, with legal-hold override and a deletion log | Evidence that the 14.6 retention policy is operating rather than aspirational |
What stays out of the archive matters as much as what goes in. Drafts that were superseded before review, personal working notes, emails in which auditors speculate about motives, and any characterization (“fraud,” “cover-up,” “negligent”) that the evidence and the findings summary do not support have no place in an engagement file, because workpapers are discoverable in litigation and are read by regulators and by external auditors who did not attend the closing meeting. The test I give preparers is to write every sentence as if opposing counsel will read it aloud to the process owner. That is not a reason to soften findings; the AFTER paper above names the Dayton diversion and the nine non-independent depots without hedging. It is a reason to confine the file to what was tested, what was found, and what was concluded, and to leave adjectives out.
Adapting the standard: small functions, co-sourcing, advisory work, and analytics
The documentation standard does not scale down; the review structure does. A one- or two-person function cannot separate preparer from reviewer on every paper, and the Standards do not require the impossible, but they do require the chief audit executive to establish a supervision methodology under 12.3 and to have the documentation reviewed under 14.6. The workable answers are a documented self-review against the 20-item checklist with the checklist filed at G-1, a periodic peer review by a co-source provider or a reciprocal arrangement with another company’s function for engagements supporting a High finding, and an explicit statement in the internal audit charter and the QAIP of how supervision is achieved when the chief audit executive prepares the work. The site’s guide to establishing a function in a small company covers the charter language; the point here is that a small function’s assessor will accept a documented compensating review and will not accept silence.
| Situation | Documentation rule | Why it holds |
|---|---|---|
| Chief audit executive prepares the work (one- or two-person function) | Self-review documented against the checklist; peer or co-source review of papers supporting High findings; the arrangement written into the QAIP | 12.3 requires a supervision methodology, not a second employee; an assessor accepts a documented substitute and rejects an undocumented one |
| Co-sourced or outsourced engagement | Provider’s papers filed in the function’s system, in the function’s index, reviewed by the function’s supervisor, with the provider’s own review evidenced; reliance decision recorded at A-1 | The chief audit executive remains accountable for conformance; papers held only on the provider’s platform cannot be produced for an assessment five years later; see the site’s co-sourcing guide |
| Advisory or consulting engagement | Same anatomy; “conclusion” becomes “advice and basis”; objectives and scope agreed with the client documented at A-1; retention per the assurance schedule | 14.6 applies to engagements, not only to assurance; a later assurance engagement will want to know what was advised and on what evidence |
| Analytics-driven testing (full population) | The script or query, its version, its parameters, the extract’s completeness test, the run date, and the reconciliation of output totals to input totals are the procedure; the results table is the evidence | The “repeat the work” test means a second auditor must be able to re-run the query and get the same output; the journal entry analytics guide shows the filing pattern |
| Walkthrough and process understanding | Documented on the walkthrough template with the names, dates, documents inspected, and the single transaction traced; control descriptions carried into the matrix verbatim | Attributes tested in the C section must match the control as understood in the B section, or the test is of a control nobody performs |
| Issue validation and follow-up (Standard 15.2) | A validation paper per action plan with the original finding reference, the evidence of implementation, the re-test performed, and the closure conclusion; the same sign-off rule | Closure is a conclusion like any other and is traced by assessors from the issue log to the evidence; the site’s guide to issue validation workpapers sets the pattern |
| Agile or sprint-based engagements | Each sprint’s papers indexed under the same A to G scheme with the sprint number as a prefix; program changes approved at sprint boundaries and dated | 13.6 still requires an approved program and approved changes; sprints are an approval cadence, not an exemption |
| Regulated institution with examiner access | Retain review notes; keep a release log; maintain an examiner read-only role; tag engagements by regulatory area in the index | Examiners request prior-cycle work by topic and expect supervision evidence, and the release rule under 14.6 applies to them as it does to anyone outside the organization |
Two adaptations are traps. The first is treating the reduced formality of an advisory engagement as reduced documentation; the Standards distinguish assurance from advisory in what the auditor concludes, not in whether the work is evidenced, and an advisory paper that cannot show its source is as deficient as an assurance paper that cannot. The second is treating a management review control test as something that can be documented from the reviewer’s sign-off alone. The site’s guide to management review controls covers the substance; for documentation purposes the paper must show what the reviewer looked at, what threshold would have triggered follow-up, and what evidence exists that follow-up occurred when it should have, because “reviewed and approved” as a result is the same sentence as “reviewed and approved” as a control description, and a reader cannot tell which one they are looking at.
A 30-day documentation reset
The sequence
A function that recognizes its own papers in the BEFORE example does not need a methodology project. It needs a template, a legend, a checklist, a tool configuration, and one engagement to prove them on, and that is about a month’s work for an audit manager alongside a normal load. The sequence below is the one I have used; the numbers are planning figures, not standards. Budget documentation at 15 to 25 percent of fieldwork hours and detailed review at 10 to 15 percent of preparer hours, and if a paper takes longer to review than it took to prepare, the template is wrong, not the reviewer.
- Days 1 to 3: score the last three engagements. Run the 20-item checklist over every test paper in three recent engagements, one per supervisor, and record pass rates by check and by reviewer; this is the baseline the QAIP self-assessment will cite.
- Days 4 to 7: issue the template and the legend. Adopt the header block and the tickmark legend above, load both into the workpaper tool, and retire every other template in circulation with a dated memo at the methodology index.
- Days 8 to 10: write the delegation, retention, and release policy. One page: who approves engagement documentation on the chief audit executive’s behalf, the retention schedule by engagement class with its drivers, the release approval rule, and the archive lock window.
- Days 11 to 14: configure the tool. Sign-off sequencing and locking, the review note categories, program-to-paper linking, the issuance gate, and archive lock, tested on a closed engagement before use on a live one.
- Days 15 to 25: run one live engagement on the new standard. Choose an engagement with a control test and an analytic, apply the template from the planning memo forward, and hold the detailed review to the five-day rule; the site’s planning memo template and risk and control matrix template carry the A and B sections.
- Days 26 to 28: re-score and compare. Run the checklist over the new engagement’s papers and compare the pass rates to the baseline; expect checks 2, 8, 13, and 16 to move most.
- Days 29 to 30: report to the chief audit executive and schedule the quarterly QA. Two pages: baseline versus result, the reviewer-level pass rates, the settings turned on, and the calendar for the quarterly sample under Standard 12.1.
The measure of success is not the pass rate. It is whether a stranger can pick up any paper from the new engagement and, without a conversation, name what was tested, where the data came from, what was done to each item, what was found, what was concluded, who did it, and who checked it. That is the whole of Standard 14.6 in one sentence, and it is the question the assessor will be asking five years from now about the engagement you are documenting this week. For the wider methodology, start with the site’s overview of the Global Internal Audit Standards, use the Tools page for the free sampler and RCM workbench that produce the selection lists and matrices the papers reference, and browse the Topics hub for the fieldwork and evidence cluster this guide belongs to.
Related guides
- Audit workpaper example — a single annotated test workpaper, element by element, with the completed matrix.
- Audit evidence — the hierarchy of evidence sources and what makes information relevant, reliable, and sufficient under Standard 14.1.
- GIAS Domain V: performing internal audit services — all fourteen engagement standards, including 14.6, traced through one engagement.
- Audit work program — building the program whose steps the workpapers execute and reference.
- Walkthrough documentation template — the B-section paper that fixes the control description the test attributes must match.
- Substantive testing: a beginner’s guide — how the D-section procedures are designed and documented when control reliance is not available.
- The beginner’s guide to internal audit workpapers — organizing, documenting, and completing testing from a first-year auditor’s seat.
- QAIP: preparing for an external quality assessment — the full program that the workpaper QA sample feeds.
- The 5 Cs of audit findings — writing the condition, criteria, cause, consequence, and corrective action the E-section supports.
- All guides — the full index of the site’s audit guides by topic.
Leave a Reply