In this guide · 9 sections
- SA 230's test: the working papers must let an experienced auditor with no previous connection to the audit understand what was done, when, what was found, and the conclusions reached on significant matters.
- For each piece of work, record what was tested (identifying characteristics), who did it and when, and who reviewed it, when and how much.
- Keep a permanent file for matters of continuing importance and a current file for the year, linked by a lead schedule for each area with W/P references back to the trial balance.
- Assemble the final file soon after the report date — SA 230's application material, drawing on SQC 1, says ordinarily not more than 60 days. After that, nothing is deleted; any later addition or change records why, when and by whom it was made and reviewed.
- Under SQC 1, the retention period for audit engagements is ordinarily no shorter than seven years from the date of the auditor's report. The working papers are the auditor's property.
Try SignReady: Lead schedules in Excel straight from the TB — W/P reference, tick and remarks columns ready.
Start freeWorking papers are the only proof that an audit was done. When a peer reviewer, a quality reviewer or a disciplinary committee asks a question three years later, the answer has to be in the file — memory does not count. This guide covers what SA 230 requires, how to organise the permanent and current files, what a good working paper looks like, and the rules for assembling and keeping the file.
What SA 230 requires
SA 230 (Audit Documentation) sets one overall test: the documentation must be sufficient to enable an experienced auditor, having no previous connection with the audit, to understand:
- the nature, timing and extent of the audit procedures performed to comply with the SAs and the applicable law;
- the results of those procedures and the audit evidence obtained; and
- the significant matters arising during the audit, the conclusions reached on them, and the significant professional judgements made in reaching those conclusions.
It then requires specific records:
| Record | What it means in practice |
|---|---|
| Identifying characteristics of the items tested | Invoice numbers and dates, the ledger and the sampling basis — enough for someone to re-select the same items |
| Who performed the work and the date it was completed | Initials and date on every working paper |
| Who reviewed the work, the date and the extent of review | Reviewer's initials and date, and what was reviewed — SA 230 does not require review evidence on every single paper, but it must be clear which work was reviewed, by whom and when |
| Discussions of significant matters with management, those charged with governance and others | What was discussed, when and with whom |
| Information inconsistent with the final conclusion on a significant matter | How the inconsistency was addressed |
| Any departure, in exceptional circumstances, from a relevant requirement of an SA | Why, and how the alternative procedure achieved the aim of the requirement |
SA 230 also notes that you need not document every matter considered or every judgement made, and that oral explanations on their own are not adequate support for the work done — they may only clarify what is already in the file.
Permanent file and current file
| Permanent file — continuing importance | Current file — this year |
|---|---|
|
|
Update the permanent file every year — an out-of-date permanent file misleads the next team and the reviewer.
SignReady builds the lead schedules in Excel — one sheet per area with previous year, current year, change, flag, W/P reference, tick and remarks — with totals as formulas and an index.
What a good working paper looks like
Every working paper, paper or electronic, should carry:
- A heading: client name, period end, area and the W/P reference (for example, D2 for the second receivables paper).
- Objective: what the paper sets out to show — "existence and valuation of trade receivables at 31 March 2026".
- Source: where the figures came from — the trial balance, the ledger, the client's ageing report — and the date obtained.
- Work done: the procedure, the sample and how it was chosen, with the items identified.
- Results and exceptions: what was found, and what happened to each exception (adjusted, queried, carried to the misstatements schedule).
- Conclusion: a sentence that answers the objective.
- Sign-offs: prepared by and date; reviewed by and date.
- Tickmarks with a legend, and cross-references to the lead schedule and to other papers.
A schedule of numbers with no objective, source or conclusion is a calculation, not a working paper.
Lead schedules and referencing
A lead schedule summarises one area — every ledger in it, with previous year, current year and change — and agrees the total to the trial balance and the financial statements. It is the index to that area: each line carries the W/P reference of the paper that supports it.
- Reference down and up. The financial statements point to the lead schedule; the lead schedule points to the working papers; each working paper points back to the lead schedule.
- Flag what needs work. Mark movements above performance materiality, or unexplained by your expectations, so the reviewer can see each one was dealt with.
- Use one referencing system for every client — for example A for planning, B for cash and bank, C for revenue, D for receivables — so anyone in the firm can find their way around any file.
Assembly, changes and retention
- Assemble the final file on time. SA 230 requires the file to be assembled on a timely basis after the date of the auditor's report; its application material, drawing on SQC 1, says an appropriate time limit is ordinarily not more than 60 days after that date. Assembly is administrative — sorting, cross-referencing, discarding superseded drafts — not new audit work.
- Nothing is deleted after assembly. Once the final file is assembled, no documentation may be deleted or discarded before the end of the retention period.
- Later changes are recorded. If you need to add or modify documentation after assembly, record the reasons, when and by whom the change was made and reviewed. If new procedures are performed after the report date in exceptional circumstances, document the circumstances, the new or additional procedures performed, the evidence obtained, the conclusions reached and their effect on the auditor's report, and when and by whom the resulting changes were made and reviewed.
- Keep it long enough. SQC 1 (para 83) and SA 230 (para A23) set the retention period for audit engagements at ordinarily no shorter than seven years from the date of the auditor's report or, if later, the date of the group auditor's report. Your firm's quality policy may set a longer period, and some engagements need longer because of litigation or regulatory enquiries. Confirm the period your firm's quality policies require. (ICAI has issued SQM 1 and SQM 2 to replace SQC 1, but in March 2026 the Council deferred their mandatory date until further announcement, so SQC 1 continues to apply.)
- The file belongs to the auditor. Under SQC 1 (para 85), repeated in SA 230 (para A25), unless law or regulation specifies otherwise, audit documentation is the property of the firm. The firm may, at its discretion, make portions of or extracts from it available to the client, provided this does not undermine the validity of the work performed or, for assurance engagements, the independence of the firm or its personnel. Disclosing it to anyone else needs the client's consent or a legal requirement (Clause (1), Part I, Second Schedule to the CA Act).
Electronic working papers
SA 230 applies whatever the medium. For files kept in spreadsheets, cloud folders or software:
- Keep the final file read-only after assembly, with access controlled and a record of any change.
- Store the client's source files (trial balance, ledgers, confirmations) as received, alongside your workings.
- Scanned documents should be legible and complete; keep the original where its form matters, such as a signed representation letter.
- Back up the files, and make sure they can still be opened for the full retention period.
Before the partner signs
- Every line of every lead schedule has a W/P reference or a reason why no work was needed.
- Every working paper has a conclusion and a preparer sign-off, and the review is evidenced.
- Review notes are cleared and the clearance is visible.
- Exceptions have gone somewhere: an adjustment, a query, or the misstatements schedule.
- The audit programme has no blank rows, and the significant matters and judgements are summarised for the partner.
Try SignReady: One download for the current file: materiality, review note, queries, programme and lead schedules.
Start freeFrequently asked questions
How long must audit working papers be kept?
SQC 1 and SA 230 say the retention period for audit engagements is ordinarily no shorter than seven years from the date of the auditor's report or, if later, the group auditor's report. A firm may set a longer period in its quality policies, and some engagements need longer because of litigation or regulatory requirements.
Within how many days must the audit file be assembled?
SA 230 requires the final file to be assembled on a timely basis after the date of the auditor's report. Its application material (A21), drawing on SQC 1 (para 75), says an appropriate time limit is ordinarily not more than 60 days after that date, unless law or regulation prescribes one.
Can I give my working papers to the client or the next auditor?
Unless law or regulation says otherwise, the working papers are the firm's property (SQC 1 para 85; SA 230 para A25). The firm may make portions or extracts available to the client at its discretion, provided the validity of the work and the firm's independence are not undermined. Sharing them with anyone else, including the incoming auditor, needs the client's consent or a legal requirement.
Can working papers be changed after the audit report is signed?
Documentation may be added or modified after the file is assembled, but nothing may be deleted or discarded before the end of the retention period. SA 230 requires you to record the specific reasons for the change, and when and by whom it was made and reviewed.
What is the difference between the permanent file and the current file?
The permanent file holds information of continuing importance across years — constitution documents, appointment papers, the engagement letter, key agreements and accounting policies. The current file holds the evidence for this year's audit — planning, the programme, lead schedules, working papers, confirmations, queries and the signed reports.
Sources
- ICAI — SA 230 Audit Documentation
- ICAI — SQC 1 Quality Control for Firms that Perform Audits and Reviews of Historical Financial Information, and Other Assurance and Related Services Engagements
- ICAI — Announcement on deferment of the effective date of SQM 1 and SQM 2 (31 March 2026)
- ICAI — SA 300 Planning an Audit of Financial Statements
- ICAI — SA 450 Evaluation of Misstatements Identified during the Audit
- ICAI — SA 505 External Confirmations
- Chartered Accountants Act, 1949 — Second Schedule, Part I, Clause (1)
SignReady's finalisation file pack puts materiality, the Analytical Review Note, client queries with replies, FinalCheck, the work programme, the checklist and the lead schedules into one zip for the file. First 3 finalisations free.
Version history: 4 Oct 2026 — first published. 5 Oct 2026 — checked against the primary texts by an independent reviewer; wording made more precise and source links added.



