Commercial Law and Preliminaries of Auditing · Ch 3 — Audit Procedure
Audit Working Papers
Audit Working Papers
Definition. Audit Working Papers are the complete set of documents — prepared by the auditor and the audit team, or obtained from the client and others — that record the audit evidence gathered, the procedures performed, and the conclusions reached during the course of an audit engagement.
Contents. Working papers typically include:
- The audit programme used for the engagement (Section c) and the completed Audit Notebook entries (Section d).
- Correspondence with the client and with third parties (e.g. confirmation letters from debtors, creditors, or the bank).
- Copies of important documents such as the Memorandum and Articles of Association, the Partnership Deed, and relevant minutes of meetings.
- Schedules and analyses prepared during the audit — e.g. a schedule of debtors, creditors, or fixed assets, reconciliations, and computations.
- Management representation letters, where the client's management has given written confirmations on specific matters.
- Notes on the internal control system examined and evaluated.
- Draft financial statements and a copy of the final audit report.
Ownership. Audit Working Papers are the property of the auditor, not of the client — even though they are prepared in the course of auditing the client's own accounts. This is a well-established principle under professional auditing standards (Standards on Auditing, SA 230, "Audit Documentation"): the working papers reflect the auditor's own procedures, judgment, and professional opinion-forming process, so they belong to the auditor who created them. The auditor may, at their own discretion, make portions of the working papers available to the client, but is under no legal obligation to hand the entire file over.
Protection and preservation. Because working papers may contain sensitive and confidential information about the client's business, the auditor is responsible for:
- Maintaining strict confidentiality — working papers must not be disclosed to any unauthorised third party without proper cause or the client's consent (subject to any overriding legal or professional-body requirement to disclose).
- Adopting adequate physical and procedural safeguards against loss, damage, tampering, or unauthorised access — proper filing, indexing, and (for electronic files) access controls and backups. …