Skip to main content
Category: Internal Audit

Working Papers

Also known as: Audit Working Papers, Workpapers
Simply put

Working papers are the documents an auditor or accountant creates and gathers while carrying out an engagement, showing the work performed, the evidence relied upon, and the conclusions reached. They serve as a record of how the auditor arrived at their findings. In the GRC context, the term most commonly refers to audit working papers rather than the unrelated meanings the phrase carries in academic publishing or employment law.

Formal definition

In an assurance context, working papers are the documentation developed by an auditor to record the audit process, including the procedures performed, sources examined, tests conducted, evidence obtained, and conclusions drawn. They provide support for the auditor's findings and demonstrate how those conclusions were reached. Working papers are the product of the assurance function's own work and should not be confused with the controls, records, or management activities being examined; they evidence the independent testing performed rather than the underlying process under review. Note that the phrase 'working papers' also carries distinct, unrelated meanings outside GRC, such as preliminary unpublished academic or discussion papers and, in the United States, official employment authorization documents for certain minors or foreign-born workers; these senses are out of scope here.

Why it matters

Working papers are the primary evidence that an assurance engagement was conducted with due care and that its conclusions rest on documented procedures rather than assertion. Because the value of an audit depends on the credibility of its findings, the working papers provide the record that supports those findings, showing what procedures were performed, which sources were examined, and how conclusions were reached. Without adequate working papers, an auditor's conclusions cannot be readily substantiated, reviewed, or defended.

Working papers also underpin the independence and objectivity of the assurance function. They document the auditor's own testing rather than the controls, records, or management activities under review, and this distinction matters: the working papers evidence independent examination, not the underlying process being examined. This separation allows a reviewer or supervisor to assess whether the work performed adequately supports the reported outcome, and it enables consistency and quality control across engagements.

It is worth noting that the phrase carries unrelated meanings outside the GRC context, including preliminary unpublished academic or discussion papers and, in the United States, official employment authorization documents for certain minors or foreign-born workers. Those senses are out of scope for assurance and audit purposes and should not be conflated with audit working papers.

Who it's relevant to

Internal auditors
Internal auditors develop working papers to document the procedures performed, evidence relied upon, and conclusions reached during an engagement. The papers support their findings and demonstrate how those conclusions were derived, providing a basis for supervisory review and quality assurance.
External auditors and accountants
External auditors, accountants, and tax professionals create and use working papers in the course of their engagements. These documents evidence the work performed and the sources and tests underlying their conclusions.
Audit supervisors and engagement reviewers
Those reviewing an engagement rely on working papers to assess whether the procedures performed adequately support the reported findings. The papers make the auditor's reasoning traceable and reviewable, supporting consistency and quality control across engagements.
Governance and oversight bodies
Audit committees and other oversight bodies benefit indirectly from working papers as the record that substantiates assurance conclusions. Because the papers document independent testing rather than the management activities under review, they help demonstrate the objectivity of the assurance function.

Inside Working Papers

Planning documentation
Records of the scope, objectives, and approach of an engagement, including the risk assessment that informed the audit or review plan and the allocation of resources.
Evidence of work performed
Descriptions of the tests, inquiries, observations, and analyses carried out, typically sufficient to allow an experienced practitioner with no prior connection to the engagement to understand the nature, timing, and extent of the procedures.
Supporting evidence and references
Copies of, or references to, source documents, data extracts, confirmations, and other materials relied upon, cross-referenced so that conclusions can be traced back to their basis.
Findings and observations
Documentation of issues identified, control deficiencies, exceptions, or areas of noncompliance, together with the criteria against which they were assessed.
Conclusions and rationale
The reviewer's judgments, the reasoning connecting evidence to conclusions, and support for any opinion, rating, or recommendation reached.
Review and sign-off records
Evidence of supervisory review, including who prepared and who reviewed each item and when, supporting quality control and accountability within the engagement team.

Common questions

Answers to the questions practitioners most commonly ask about Working Papers.

Are working papers the same as the final audit report?
No. Working papers are the documentation an auditor or reviewer compiles during an engagement to record the work performed, evidence obtained, and conclusions reached. The final report is a summary deliverable communicated to stakeholders. Working papers support and substantiate the report but typically remain internal to the assurance function and are not distributed with the report itself. Confusing the two overlooks the fact that working papers are the underlying record, while the report is the communicated outcome.
Do working papers belong to the auditor personally, or to the organization or firm?
In most cases, working papers are the property of the engaging function or firm rather than the individual auditor, though the specifics can depend on employment arrangements, professional standards, and jurisdiction. It is a common misconception that an auditor may take working papers when leaving. Ownership, retention, and access are generally governed by firm policy, applicable professional standards, and any contractual terms, so the answer varies by context rather than being universal.
What should working papers typically include to support an engagement conclusion?
Working papers commonly capture the objective and scope of the work, the procedures performed, the evidence examined, any samples selected, observations and exceptions noted, and the conclusions reached. Many assurance functions also record who prepared and who reviewed each item, and when. The aim is generally that a reasonably experienced reviewer, not previously connected to the engagement, could understand what was done and how the conclusions were reached. Specific content requirements may differ by framework, standard, and function.
How long should working papers be retained?
Retention periods vary by jurisdiction, sector, professional standard, and organizational policy, so there is no single universal timeframe. Functions typically set a retention schedule that reflects applicable legal and regulatory requirements, any relevant professional standards, and internal record-management policies. This entry does not provide legal advice; determine the applicable retention period by reference to the specific obligations that apply to your organization and engagement type.
Who typically reviews working papers, and why does review matter?
Working papers are commonly subject to review by someone other than the preparer, often a more senior member of the engagement or a quality reviewer, before conclusions are finalized. Review helps confirm that the work performed supports the conclusions, that evidence is sufficient, and that documentation is complete and clear. Recording the reviewer and review date is a common practice that supports accountability and the traceability of conclusions.
How should working papers handle sensitive or confidential information?
Because working papers often contain confidential organizational data, personal data, or sensitive findings, access is typically restricted and controlled in line with the function's security and data-protection policies. Handling requirements may also be influenced by applicable privacy laws and sector rules, which differ across jurisdictions. This entry does not cover specific tooling or technical controls; those should be determined against the organization's information-security and data-protection obligations.

Common misconceptions

Working papers are informal notes that only need to make sense to the person who prepared them.
In many assurance frameworks, working papers are expected to be sufficiently complete and clear that an experienced practitioner not involved in the engagement could understand the work performed, the evidence obtained, and the conclusions reached. They are a formal record supporting the engagement's output, not private notes.
Working papers and the controls or processes being examined are essentially the same body of documentation.
Working papers are produced by the assurance or review function to document its independent examination; they are distinct from the management-owned documentation of the controls, policies, or processes under review. Confusing the two undermines the independence and objectivity that assurance activities are intended to preserve.
Once an engagement is complete, working papers can be discarded or freely altered.
Working papers are commonly subject to retention and access controls, and changes after finalization are typically restricted or tracked. Retention periods and requirements vary by jurisdiction, sector, and applicable professional standards, so specific obligations should be confirmed against the relevant context.

Best practices

Document work contemporaneously so that procedures, evidence, and conclusions are recorded as the engagement progresses rather than reconstructed afterward.
Cross-reference conclusions to the supporting evidence so that any finding or opinion can be traced back to its basis and re-performed if needed.
Prepare papers to a standard clear enough that an experienced practitioner not involved in the engagement could follow the work and understand how conclusions were reached.
Maintain evidence of supervisory review and sign-off, identifying who prepared and who reviewed each item, to support quality control and accountability.
Apply appropriate retention, access, and version controls, confirming specific requirements against the applicable jurisdiction, sector, and professional standards.
Keep the working papers of the assurance function distinct from management's own process and control documentation to preserve independence and objectivity.
Promotional banner for the Pentest Readiness checklist download