SignReady › Blog › Peer review file checklist
Audit practice

Peer review is coming: 12 things to have in a company audit file before the reviewer asks

By SignReady Team · Published 6 Oct 2026 · 7 min read · Law as at 6 October 2026
Peer review file checklist — SignReady guide
In this guide · 8 sections
  1. What a peer review looks at
  2. Twelve things a company audit file should contain
  3. The gaps that are easiest to fix early
  4. The firm-level side
  5. Assembly and retention
  6. Build the file as you go
  7. FAQs
  8. Sources
Key points
  • In a peer review, ICAI's reviewer looks at two things: whether the firm's quality control system (SQC 1) is in place, and whether a sample of attestation engagements complied with the standards. The audit file is the evidence for both.
  • The reviewer largely judges what you did by what you documented. SA 230's test is whether an experienced auditor with no previous connection to the audit can understand the work, the evidence and the conclusions.
  • Twelve items cover most of what a company audit file needs: acceptance, engagement terms, independence, planning and materiality, risk assessment, the programme, working papers, confirmations, analytical review, misstatements, representations and the reports.
  • Most gaps are easy to fix if found early: an unsigned engagement letter, materiality set after the fieldwork, an untailored programme, review notes without clearance, a representation letter dated after the report.
  • Assemble the file ordinarily within 60 days of the report date and keep it for at least seven years — a peer review covers the three financial years before the year the firm is selected.

Try SignReady: Materiality, programme, review points and queries — documented as you work.

Start free

For many small and mid-sized firms, the first peer review is the first time someone outside the firm reads their audit files. Often the problem is not that the audit was wrong, but that the file does not show it was right: the work was done, the partner reviewed it, the issues were discussed with the client — and almost none of it is on paper. This guide sets out what a peer review looks at, and twelve things a company audit file should contain before the reviewer opens it.

What a peer review looks at

Peer review is conducted under the Peer Review Guidelines, 2022, prescribed by the ICAI Council and administered by its Peer Review Board. Its objective is to check that, in carrying out assurance engagements, the firm complies with technical, professional and ethical standards, and has proper systems — including documentation — that demonstrate the quality of its work. In broad terms the reviewer:

  • examines the firm's policies and procedures on quality control — the elements of SQC 1: leadership, ethics and independence, acceptance and continuance, human resources, engagement performance and monitoring;
  • selects a sample of attestation engagements — statutory audits, tax audits, certifications — and examines the working papers to check compliance with the Standards on Auditing and other technical standards; and
  • reports to the Peer Review Board. An unqualified report leads to a peer review certificate, ordinarily valid for three years; after a qualified report no certificate is issued, and the Board may issue an advisory or order a follow-on review, ordinarily after a year.

Since April 2022 ICAI has phased in a requirement to hold a valid peer review certificate before accepting certain statutory audits — listed entities first, then large unlisted public companies, entities that have raised more than ₹50 crore and public interest entities, and firms with five, then four, partners or more. The next phase, covering audits of public sector bank branches and any firm with three or more partners, applies from 31 December 2026. Check ICAI's Peer Review Mandate page for the current position.

SQM 1 and SQM 2 were due to replace SQC 1 from 1 April 2026, but ICAI deferred them on 31 March 2026 until further announcement, so SQC 1 continues to apply.

Twelve things a company audit file should contain

#ItemStandard / law
1Acceptance and continuance: letter to the previous auditor with proof of delivery, consent and eligibility certificate, appointment resolution, ADT-1CA Act First Schedule Part I cl. (8), (9); s.139, s.141; SQC 1
2Engagement letter acknowledged by management — or, for a recurring audit, the existing letter with a recorded assessment of whether the terms need revising or remindingSA 210
3Independence confirmations from the partner and team membersCode of Ethics; SQC 1 (annual written confirmation)
4Planning memo and materiality — overall, performance and clearly trivial — with the benchmark and reasonsSA 300; SA 320; SA 450
5Understanding of the entity and the risk assessment, including fraud risksSA 315; SA 240
6An audit programme tailored to the client, with steps signed off and referencedSA 300; SA 330
7Working papers by area, with lead schedules agreed to the trial balance, conclusions, and preparer and reviewer sign-offsSA 230
8External confirmations with a control sheet and alternative procedures for non-replies; inventory count attendance where materialSA 505; SA 501
9Analytical procedures — at planning and near the end of the audit — with movements explainedSA 315; SA 520
10Schedule of misstatements, those corrected, and the evaluation of those uncorrectedSA 450
11Management representation letter, dated as near as practicable to, but not after, the report date, and the subsequent events and going concern workSA 580; SA 560; SA 570
12The signed statements, auditor's report, CARO report (if applicable) and IFC report (if applicable), with UDIN, and the completion checklist with partner sign-offSA 700; CARO 2020; s.143; ICAI UDIN guidelines
A file that is ready when the reviewer asks

SignReady keeps materiality, the CY vs PY review, client queries, the work programme, review points, FinalCheck and the checklist in one finalisation — and downloads them as one file pack.

Start free — 3 finalisations

The gaps that are easiest to fix early

These are the kinds of gaps that make a file look weak even when the audit was sound. All of them are cheap to fix during the audit and expensive to explain afterwards:

  • Engagement letter not acknowledged, or the same letter from five years ago with no assessment of whether the terms still fit (SA 210 asks for that assessment in recurring audits).
  • Materiality set after the work, with no benchmark or reasoning — or a materiality figure that has nothing to do with the sample sizes and thresholds actually used.
  • A programme copied from another client: inventory steps ticked for a service company, no steps for this year's new loan.
  • Ticks without evidence: "verified" on a lead schedule with no working paper behind it.
  • No sign of review: no reviewer initials or date, and review notes that were raised but never shown as cleared.
  • Representation letter dated after the report, or unsigned, or a generic letter that does not cover this year's judgements.
  • Applicability answered without reasons: "CARO — N.A." with no working of the limits.
  • Files assembled late or changed later without a record of what changed, when and by whom.

The firm-level side

The reviewer also looks beyond individual files. Have ready:

  • written quality control policies covering the SQC 1 elements, sized to the firm;
  • independence declarations, and a record of how threats were assessed for each client;
  • evidence of training and CPE for partners and staff;
  • criteria for engagement quality control review, and evidence that it was done where required;
  • a monitoring record — an internal review of completed files, with findings and follow-up;
  • the register of assurance engagements, records showing compliance with ICAI's limits on the number of audits and its fee guidelines, and articled and audit assistant records (attendance, work diaries, stipend payments); and
  • the Audit Quality Maturity Model self-evaluation, where your firm is required to do one.

Assembly and retention

SA 230 requires the final file to be assembled on a timely basis after the report date — ordinarily not more than 60 days, as its application material says, drawing on SQC 1 — and nothing to be deleted after that. SQC 1 sets the retention period for audit engagements at ordinarily no shorter than seven years from the date of the auditor's report. A peer review can sample files from earlier years, so the file you close this October may be the one reviewed later.

Build the file as you go

The firms that find peer review straightforward are not the ones that prepare for it — they are the ones whose files are built during the audit: materiality before fieldwork, the programme tailored at planning, working papers signed as they are finished, review notes cleared in the file, and a completion checklist the partner signs before the report. The reviewer then reads the file the way the team worked.

Try SignReady: One download gives the file pack a reviewer expects to see.

Start free

Frequently asked questions

What does an ICAI peer reviewer check?

Under the Peer Review Guidelines, the reviewer checks the firm's quality control policies and procedures (the elements of SQC 1) and examines a sample of assurance engagements to see whether they complied with technical, professional and ethical standards, including the Standards on Auditing.

Which documents should be in a company audit file?

Acceptance and appointment papers, the engagement letter, independence confirmations, planning and materiality, risk assessment, a tailored audit programme, working papers with sign-offs, confirmations, analytical procedures, the misstatements schedule, the representation letter, subsequent events and going concern work, and the signed statements and reports.

Can I complete the audit file after the peer review is announced?

The file should be assembled within the time limit after the report date — ordinarily not more than 60 days — and after that nothing may be deleted. Any later addition must record the reasons, when and by whom it was made and reviewed (SA 230). Adding documents later without that record undermines the file.

How long should audit files be kept?

SQC 1 says the retention period for audit engagements is ordinarily no shorter than seven years from the date of the auditor's report. A firm may set a longer period in its own quality policies.

Sources

One download for the audit file

SignReady's finalisation file pack: a summary PDF with materiality, the Analytical Review Note, queries with replies, FinalCheck, the work programme and checklist, plus lead schedules in Excel. First 3 finalisations free.

Start free — 3 finalisations
About this guide. Written by the SignReady Team at PracticeGuru (Brainy Accountant Solutions Pvt Ltd). SignReady is our product and is mentioned where it fits. The guide reflects the law and standards as at 6 October 2026 and the sources listed above. It is general information, not professional advice: check the primary sources and apply your own professional judgement to each engagement.
Version history: 6 Oct 2026 — first published.