In this guide · 8 sections
- In a peer review, ICAI's reviewer looks at two things: whether the firm's quality control system (SQC 1) is in place, and whether a sample of attestation engagements complied with the standards. The audit file is the evidence for both.
- The reviewer largely judges what you did by what you documented. SA 230's test is whether an experienced auditor with no previous connection to the audit can understand the work, the evidence and the conclusions.
- Twelve items cover most of what a company audit file needs: acceptance, engagement terms, independence, planning and materiality, risk assessment, the programme, working papers, confirmations, analytical review, misstatements, representations and the reports.
- Most gaps are easy to fix if found early: an unsigned engagement letter, materiality set after the fieldwork, an untailored programme, review notes without clearance, a representation letter dated after the report.
- Assemble the file ordinarily within 60 days of the report date and keep it for at least seven years — a peer review covers the three financial years before the year the firm is selected.
Try SignReady: Materiality, programme, review points and queries — documented as you work.
Start freeFor many small and mid-sized firms, the first peer review is the first time someone outside the firm reads their audit files. Often the problem is not that the audit was wrong, but that the file does not show it was right: the work was done, the partner reviewed it, the issues were discussed with the client — and almost none of it is on paper. This guide sets out what a peer review looks at, and twelve things a company audit file should contain before the reviewer opens it.
What a peer review looks at
Peer review is conducted under the Peer Review Guidelines, 2022, prescribed by the ICAI Council and administered by its Peer Review Board. Its objective is to check that, in carrying out assurance engagements, the firm complies with technical, professional and ethical standards, and has proper systems — including documentation — that demonstrate the quality of its work. In broad terms the reviewer:
- examines the firm's policies and procedures on quality control — the elements of SQC 1: leadership, ethics and independence, acceptance and continuance, human resources, engagement performance and monitoring;
- selects a sample of attestation engagements — statutory audits, tax audits, certifications — and examines the working papers to check compliance with the Standards on Auditing and other technical standards; and
- reports to the Peer Review Board. An unqualified report leads to a peer review certificate, ordinarily valid for three years; after a qualified report no certificate is issued, and the Board may issue an advisory or order a follow-on review, ordinarily after a year.
Since April 2022 ICAI has phased in a requirement to hold a valid peer review certificate before accepting certain statutory audits — listed entities first, then large unlisted public companies, entities that have raised more than ₹50 crore and public interest entities, and firms with five, then four, partners or more. The next phase, covering audits of public sector bank branches and any firm with three or more partners, applies from 31 December 2026. Check ICAI's Peer Review Mandate page for the current position.
SQM 1 and SQM 2 were due to replace SQC 1 from 1 April 2026, but ICAI deferred them on 31 March 2026 until further announcement, so SQC 1 continues to apply.
Twelve things a company audit file should contain
| # | Item | Standard / law |
|---|---|---|
| 1 | Acceptance and continuance: letter to the previous auditor with proof of delivery, consent and eligibility certificate, appointment resolution, ADT-1 | CA Act First Schedule Part I cl. (8), (9); s.139, s.141; SQC 1 |
| 2 | Engagement letter acknowledged by management — or, for a recurring audit, the existing letter with a recorded assessment of whether the terms need revising or reminding | SA 210 |
| 3 | Independence confirmations from the partner and team members | Code of Ethics; SQC 1 (annual written confirmation) |
| 4 | Planning memo and materiality — overall, performance and clearly trivial — with the benchmark and reasons | SA 300; SA 320; SA 450 |
| 5 | Understanding of the entity and the risk assessment, including fraud risks | SA 315; SA 240 |
| 6 | An audit programme tailored to the client, with steps signed off and referenced | SA 300; SA 330 |
| 7 | Working papers by area, with lead schedules agreed to the trial balance, conclusions, and preparer and reviewer sign-offs | SA 230 |
| 8 | External confirmations with a control sheet and alternative procedures for non-replies; inventory count attendance where material | SA 505; SA 501 |
| 9 | Analytical procedures — at planning and near the end of the audit — with movements explained | SA 315; SA 520 |
| 10 | Schedule of misstatements, those corrected, and the evaluation of those uncorrected | SA 450 |
| 11 | Management representation letter, dated as near as practicable to, but not after, the report date, and the subsequent events and going concern work | SA 580; SA 560; SA 570 |
| 12 | The signed statements, auditor's report, CARO report (if applicable) and IFC report (if applicable), with UDIN, and the completion checklist with partner sign-off | SA 700; CARO 2020; s.143; ICAI UDIN guidelines |
SignReady keeps materiality, the CY vs PY review, client queries, the work programme, review points, FinalCheck and the checklist in one finalisation — and downloads them as one file pack.
The gaps that are easiest to fix early
These are the kinds of gaps that make a file look weak even when the audit was sound. All of them are cheap to fix during the audit and expensive to explain afterwards:
- Engagement letter not acknowledged, or the same letter from five years ago with no assessment of whether the terms still fit (SA 210 asks for that assessment in recurring audits).
- Materiality set after the work, with no benchmark or reasoning — or a materiality figure that has nothing to do with the sample sizes and thresholds actually used.
- A programme copied from another client: inventory steps ticked for a service company, no steps for this year's new loan.
- Ticks without evidence: "verified" on a lead schedule with no working paper behind it.
- No sign of review: no reviewer initials or date, and review notes that were raised but never shown as cleared.
- Representation letter dated after the report, or unsigned, or a generic letter that does not cover this year's judgements.
- Applicability answered without reasons: "CARO — N.A." with no working of the limits.
- Files assembled late or changed later without a record of what changed, when and by whom.
The firm-level side
The reviewer also looks beyond individual files. Have ready:
- written quality control policies covering the SQC 1 elements, sized to the firm;
- independence declarations, and a record of how threats were assessed for each client;
- evidence of training and CPE for partners and staff;
- criteria for engagement quality control review, and evidence that it was done where required;
- a monitoring record — an internal review of completed files, with findings and follow-up;
- the register of assurance engagements, records showing compliance with ICAI's limits on the number of audits and its fee guidelines, and articled and audit assistant records (attendance, work diaries, stipend payments); and
- the Audit Quality Maturity Model self-evaluation, where your firm is required to do one.
Assembly and retention
SA 230 requires the final file to be assembled on a timely basis after the report date — ordinarily not more than 60 days, as its application material says, drawing on SQC 1 — and nothing to be deleted after that. SQC 1 sets the retention period for audit engagements at ordinarily no shorter than seven years from the date of the auditor's report. A peer review can sample files from earlier years, so the file you close this October may be the one reviewed later.
Build the file as you go
The firms that find peer review straightforward are not the ones that prepare for it — they are the ones whose files are built during the audit: materiality before fieldwork, the programme tailored at planning, working papers signed as they are finished, review notes cleared in the file, and a completion checklist the partner signs before the report. The reviewer then reads the file the way the team worked.
Try SignReady: One download gives the file pack a reviewer expects to see.
Start freeFrequently asked questions
What does an ICAI peer reviewer check?
Under the Peer Review Guidelines, the reviewer checks the firm's quality control policies and procedures (the elements of SQC 1) and examines a sample of assurance engagements to see whether they complied with technical, professional and ethical standards, including the Standards on Auditing.
Which documents should be in a company audit file?
Acceptance and appointment papers, the engagement letter, independence confirmations, planning and materiality, risk assessment, a tailored audit programme, working papers with sign-offs, confirmations, analytical procedures, the misstatements schedule, the representation letter, subsequent events and going concern work, and the signed statements and reports.
Can I complete the audit file after the peer review is announced?
The file should be assembled within the time limit after the report date — ordinarily not more than 60 days — and after that nothing may be deleted. Any later addition must record the reasons, when and by whom it was made and reviewed (SA 230). Adding documents later without that record undermines the file.
How long should audit files be kept?
SQC 1 says the retention period for audit engagements is ordinarily no shorter than seven years from the date of the auditor's report. A firm may set a longer period in its own quality policies.
Sources
- ICAI — Peer Review Guidelines, 2022
- ICAI — Peer Review Board: Peer Review Mandate
- ICAI — Announcement on deferment of effective date of SQM 1 and SQM 2 (31 March 2026)
- ICAI — SQC 1 Quality Control for Firms that Perform Audits and Reviews of Historical Financial Information, and Other Assurance and Related Services Engagements
- ICAI — SA 230 Audit Documentation
- ICAI — SA 210 Agreeing the Terms of Audit Engagements
- ICAI — SA 300 Planning an Audit of Financial Statements
- ICAI — SA 320 Materiality in Planning and Performing an Audit
- ICAI — SA 505 External Confirmations
- ICAI — SA 580 Written Representations
SignReady's finalisation file pack: a summary PDF with materiality, the Analytical Review Note, queries with replies, FinalCheck, the work programme and checklist, plus lead schedules in Excel. First 3 finalisations free.
Version history: 6 Oct 2026 — first published.



