Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Internal Controls & Audit

Workpaper

Also known as: Working Paper, Working Papers, Workpapers
Simply put

A workpaper is a record an auditor or reviewer keeps that documents the work they performed, the information they gathered, and the conclusions they reached. It serves as evidence of what was examined and how, so the work can be understood and supported later. In practice, workpapers may take the form of physical documents or files maintained within specialized software.

Formal definition

In an audit context, workpapers (also termed working papers) are the records maintained by the auditor of the procedures applied, the tests performed, the information obtained, and the pertinent conclusions reached in the course of an engagement, as described in PCAOB archived standard AU 339A. They typically evidence the basis for findings and conclusions and support the traceability of an engagement's work. The specific documentation requirements, retention obligations, and applicable standards vary by engagement type, jurisdiction, and the governing framework or professional standard in force; practitioners should verify precise requirements against the current authoritative source. Outside of audit, the term is also used loosely for tentative figures, memoranda, data, or analyses set down during a survey or analysis, and, in an unrelated academic sense, for research literature that has not yet been peer reviewed. These non-audit usages fall outside the scope of the assurance-focused definition above.

Why it matters

Workpapers are the connective tissue between an assurance engagement and the conclusions it produces. Because they document the procedures applied, the tests performed, the information obtained, and the conclusions reached, they allow a reviewer, supervisor, regulator, or successor auditor to understand and evaluate what was done long after the fieldwork ends. Without adequate workpapers, findings can appear unsupported and the traceability of an engagement's work becomes difficult to demonstrate, which undermines the credibility of the assurance provided.

For GRC professionals, workpapers underpin the defensibility of both internal and external assurance activities. They provide the evidentiary basis for audit findings and conclusions, and they support accountability by making the reasoning behind a conclusion visible and reviewable. In regulated environments, the adequacy and retention of documentation can itself be a matter of scrutiny, and inadequate documentation may weaken an organization's ability to demonstrate that work was properly performed.

It is important to recognize that documentation standards, retention obligations, and the specific form workpapers must take vary by engagement type, jurisdiction, and the governing professional standard in force. The PCAOB archived standard AU 339A describes what working papers are in an audit context, but practitioners should verify the precise requirements applicable to their engagement against the current authoritative source rather than assuming a single universal rule applies.

Who it's relevant to

Internal Auditors
Internal auditors rely on workpapers to document the procedures they applied and the conclusions they reached, providing a reviewable evidentiary trail that supports their findings and allows supervisory review of the work performed.
External and Financial-Statement Auditors
For external auditors, workpapers evidence the basis for audit findings and conclusions and support the traceability of the engagement. The applicable documentation and retention requirements vary by engagement type and governing standard, and should be confirmed against the current authoritative source.
Compliance Officers
Compliance professionals use documentation of review work to demonstrate that procedures were performed and conclusions were reached on a supportable basis. Retention and documentation obligations differ by jurisdiction and sector, so applicable requirements should be verified rather than assumed.
General Counsel and Legal Advisors
Legal advisors have an interest in how workpapers are prepared and retained because these records may become relevant to demonstrating that work was properly performed. Questions of legal privilege, retention, and admissibility are jurisdiction-specific and warrant professional legal advice.
Audit Committees and Governance Bodies
Those charged with governance depend on the quality of assurance documentation to trust the conclusions presented to them. Well-maintained workpapers support accountability by making the reasoning behind findings visible and reviewable.

Inside Workpaper

Purpose and Scope Statement
A description of the objective of the work performed and the boundaries of what was and was not examined, providing context for the evidence gathered and conclusions reached.
Evidence and Supporting Documentation
The records, data extracts, screenshots, correspondence, and other materials collected to substantiate observations, typically retained so that a reviewer can trace conclusions back to their source.
Procedures Performed
A record of the tests, inquiries, inspections, or analyses undertaken, often including sample selection basis and the steps followed, so the work can be understood and, where relevant, re-performed.
Findings and Observations
Documentation of results, including any exceptions, deviations, or control deficiencies identified, distinguished from the underlying evidence that supports them.
Conclusions
The assessment or opinion drawn from the procedures and evidence, linked clearly to the stated objective and the findings recorded.
Preparer and Reviewer Attribution
Identification of who prepared the workpaper and who reviewed it, often with dates, supporting accountability and the separation between preparation and independent review.
Cross-References and Indexing
Links between related workpapers, source documents, and summary schedules that allow the body of work to be navigated and its internal consistency verified.

Common questions

Answers to the questions practitioners most commonly ask about Workpaper.

Is a workpaper simply the final audit report or a summary of conclusions?
No. A workpaper is the underlying documentation that records the evidence obtained, the procedures performed, and the analysis supporting a conclusion, rather than the conclusion or report itself. The final report typically communicates results to stakeholders, while workpapers form the supporting record behind those results. Conflating the two is a common misconception; in many audit and assurance frameworks the workpapers are expected to be sufficiently detailed that a reviewer could understand the work performed and the basis for conclusions independent of the summary report.
Are workpapers used only by external financial auditors?
Not necessarily. Although the term is strongly associated with external financial audit, workpapers are commonly maintained across internal audit, compliance testing, risk assessment, and other assurance activities. Any function that performs procedures and documents supporting evidence may create workpapers. The specific content, format, and retention expectations often vary by the type of engagement, the applicable standards or internal policies, and the jurisdiction or sector, so the underlying purpose, documenting work performed and its basis, is broader than external audit alone.
What information should a workpaper typically include to be considered sufficient?
Sufficiency is context-dependent, but workpapers commonly identify the objective or procedure performed, the source and nature of the evidence examined, the analysis or testing carried out, the results, and the conclusion reached. Many frameworks also expect identifying details such as the preparer, the date prepared, and evidence of review. What counts as sufficient depends on the applicable professional standards, internal policies, and the significance of the matter, so specific requirements should be verified against the governing standard or engagement methodology.
How should review of workpapers typically be evidenced?
Review is often evidenced by a documented sign-off, notation, or system record indicating who reviewed the workpaper and when, sometimes accompanied by review notes and their resolution. The purpose is generally to demonstrate that a person other than the preparer assessed whether the work performed supports the stated conclusions. The rigor and layers of review typically depend on the risk or significance of the area and on applicable standards or internal quality expectations, which vary by organization and engagement type.
What are common considerations for workpaper retention?
Retention expectations for workpapers often derive from applicable laws, regulations, professional standards, and internal record-retention policies, and these can differ significantly by jurisdiction, sector, and engagement type. Considerations typically include the required retention period, secure storage, protection of confidential or personal information, and controls over subsequent modification. Because specific retention periods and legal obligations vary and may carry consequences, organizations generally verify requirements against the primary source or seek professional advice rather than relying on a single default period.
What controls help protect the integrity of electronic workpapers?
Common controls include access restrictions aligned to role, version control, audit trails or logging of changes, and safeguards that prevent unauthorized modification after a workpaper is finalized or reviewed. Such controls are intended to support the reliability and defensibility of the documentation but do not by themselves guarantee integrity or eliminate risk. Appropriate controls typically depend on the sensitivity of the information, applicable standards, and the organization's broader information and records management practices.

Common misconceptions

A workpaper is simply a copy of the documents a team reviewed.
Beyond retained source material, a workpaper typically documents the purpose, procedures performed, findings, and conclusions, so that the reasoning connecting evidence to conclusions is itself recorded and can be followed by a reviewer.
Workpapers are a formality that primarily exist for audit, and their content is largely uniform across contexts.
Documentation expectations vary by function, framework, jurisdiction, and organization, and the content is often shaped by the objective of the engagement; workpapers can support internal audit, compliance testing, risk assessment, and control validation, among other purposes.
A completed workpaper demonstrates that a control is effective or that compliance has been achieved.
A workpaper documents the procedures performed and the conclusions reached at a point in time; it supports a conclusion rather than guaranteeing an outcome, and its reliability depends on the sufficiency of the evidence and the appropriateness of the procedures.

Best practices

State the objective and scope explicitly at the outset, so any reviewer can judge whether the procedures and evidence align with what the workpaper set out to address.
Retain sufficient supporting evidence and cross-reference it, so that each observation and conclusion can be traced back to its source without relying on the preparer's recollection.
Distinguish clearly between raw evidence, findings, and conclusions, avoiding language that overstates results or implies a control eliminates risk or guarantees compliance.
Document the procedures performed in enough detail that the work could be understood and, where relevant, re-performed by someone independent of the preparer.
Record preparer and reviewer attribution with dates to reinforce accountability and the separation between preparation and independent review.
Align retention, format, and content with the applicable framework, function, and jurisdictional expectations, verifying specific requirements against the relevant primary sources or professional guidance.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.