AU-C Section 230 sets the audit documentation requirements that apply when you perform a financial statement audit under Generally Accepted Auditing Standards. The rule is built around one idea: your working papers must show what you did, what you found, and how you reached your conclusions, in enough detail that an experienced auditor unfamiliar with the engagement could pick up the file and follow the work from start to finish. Everything else in the standard, from the content of individual working papers to the 60-day assembly deadline and the five-year retention floor, flows from that principle.
The standard governs audits of non-issuers under the AICPA Professional Standards. If the engagement is an audit of an SEC issuer, PCAOB Auditing Standard 1215 controls instead, with a shorter 14-day assembly window and a longer retention period. The rest of this article addresses AU-C 230.
The Experienced Auditor Standard
Every content requirement in AU-C 230 runs through a single test. Could an experienced auditor with no prior connection to the engagement understand what was performed? That hypothetical reviewer has a reasonable grasp of audit activities and has studied the industry’s accounting and auditing issues, but knows nothing about the specific client or team.
This is not just a guiding principle. It is the yardstick peer reviewers, quality control reviewers, and regulators actually use. Documentation that felt complete to the engagement team often fails the test because the team was unconsciously leaning on shared context that never made it onto the page. Write for the outsider.
What Every Working Paper Must Contain
AU-C 230 requires documentation of the nature, timing, and extent of every audit procedure performed, together with the results of those procedures and the audit evidence obtained. The working papers must also identify significant findings or issues and the conclusions reached on each.
Beyond the substance of the work, each working paper needs identifying details:
- The specific items tested: the transactions, account balances, or disclosures examined.
- The name of the person who performed the work and the date it was completed.
- The name of the reviewer and the date the review was finished.
These identification requirements apply to paper and electronic working papers alike. If your audit software auto-stamps names and dates, confirm the stamps capture information a reviewer outside the firm could actually trace, not just an internal login ID.
Judgments and Findings That Need Deeper Documentation
The bar rises whenever the work involves significant findings, complex estimates, or areas requiring substantial professional judgment. Stating a conclusion is not enough. The file must show the reasoning, including the alternatives that were considered and why the chosen approach won out.
Departures From Presumptively Mandatory Requirements
Certain AICPA requirements are presumptively mandatory, meaning you must follow them unless a specific circumstance makes them irrelevant. When you depart from one, AU-C 230 requires you to document why the departure was justified and how the alternative procedures still achieved the objective the original requirement was designed to meet. Skipping this write-up is one of the fastest routes to a peer review finding.
Understanding the Entity and Testing Controls
Documentation of the auditor’s understanding of the entity and its environment, including internal control components, must be substantial enough to show how that understanding was obtained. When the audit plan calls for testing the operating effectiveness of controls, the files must preserve the evidence of the tests and their results. Thin work here tends to draw questions about whether there was any real basis for reducing substantive testing.
Risk Assessment and Materiality
The identification and assessment of risks of material misstatement must be documented, and each assessed risk needs to be linked to the procedures designed to address it. The rationale for concluding that a particular risk is not significant belongs in the file too. Reviewers pay close attention to what the auditor decided not to investigate, and an undocumented risk decision looks like a decision that was never made.
Materiality determinations sit inside the same obligation. The files must show the factors considered in setting materiality for the financial statements as a whole and for particular classes of transactions or account balances, along with any revisions as the audit progressed.
Complex Estimates and Specialists
For complex accounting estimates, the files must show how the auditor evaluated the methods, data, and significant assumptions management used. When an external specialist contributed (a valuation expert, actuary, or similar professional), the documentation must cover the auditor’s evaluation of the specialist’s competence and objectivity, the auditor’s understanding of the specialist’s work, and the basis for accepting or rejecting the specialist’s findings. Dropping the specialist’s report into the file without any auditor analysis does not satisfy the standard.
Inconsistent Evidence and Consultations
When you encounter conflicting evidence, the working papers must show how the inconsistency was resolved and what additional procedures were performed. Burying contradictory evidence, or leaving it out, is itself a documentation failure. Consultations on difficult or contentious matters, whether internal or with outside advisors, need to be documented too: the substance of the issue, who was consulted, and the conclusions reached.
Discussions With Management and Those Charged With Governance
When significant findings or issues are discussed with management or those charged with governance, the documentation must capture the nature of the findings, the timing of the discussions, and who participated. These memos often become the critical record in hindsight, particularly if a restatement or fraud surfaces later.
Prepare Documentation as the Audit Happens
AU-C 230 expects working papers to be prepared concurrently with the procedures being performed. Writing them up weeks after fieldwork invites errors and omissions, because the reasoning behind a particular approach fades quickly. Contemporaneous preparation also keeps the file honest about what evidence was actually available when the procedure was performed, rather than what became clear later.
All documentation must be completed no later than the date of the auditor’s report. The report date and the documentation completion date are not the same thing, though. The report date marks when the auditor has obtained sufficient evidence to support the opinion. The completion date marks the end of file assembly, which comes next.
The 60-Day File Assembly Window
After the report release date, you have up to 60 days to assemble the final audit file. This window is for administrative work: organizing working papers into a logical structure, clearing review notes, cross-referencing documents, and signing off checklists. No new audit procedures should be performed during the assembly period. Anything added must be administrative in nature.
The 60-day deadline is a hard cutoff. Once it passes, the file is locked, and the auditor cannot delete or discard any documentation through the end of the retention period. Firms using electronic audit platforms should confirm the software enforces this lockdown automatically, because a manual “don’t touch the file” policy tends to erode over time.
Additions After the File Is Locked
Circumstances occasionally require additions after the completion date. AU-C 230 permits additions but prohibits deletions. Any addition must be documented in a way that does not alter or obscure the original record, with the nature and date of the revision made clear.
The most common trigger is a subsequent event that comes to the auditor’s attention after the report date. Even then, the addition follows the same protocol: identify who added it, when, and why.
How Long to Keep the Files
AU-C 230 sets the retention floor at five years from the report release date. Firms must retain all forms of documentation, whether electronic, hard copy, or any other medium used to store audit evidence. If the firm’s technology changes during that window, the files still need to remain accessible and readable, which means periodic migration or maintaining legacy systems that can open older formats.
State boards of accountancy can impose their own retention requirements on top of the AICPA floor, and some states require periods longer than five years. Firms operating across multiple states should track the most restrictive applicable requirement for each engagement. Issuer audits carry longer federal retention obligations under separate PCAOB, SEC, and criminal statutes, but those do not apply to non-issuer engagements governed by AU-C 230.
Who Owns the Working Papers
Audit working papers are the property of the auditor, not the client, and many states have statutes reinforcing that ownership. Ownership does not mean unrestricted use, though. The AICPA Code of Professional Conduct imposes a confidentiality obligation that limits disclosure of client information without consent.
Recognized exceptions to the consent requirement include complying with professional standards, responding to a valid subpoena or court order, cooperating with a peer review or ethics investigation, and disclosures made in connection with the sale or merger of the auditor’s practice under appropriate nondisclosure agreements. When a regulator requests access, the auditor should ordinarily keep ownership of the files and should not share client information without client authorization. If the client asks to review the working papers before a regulator receives them, the auditor may allow the client to understand what is being shared while retaining physical control of the files throughout.1Public Company Accounting Oversight Board. AU 9339A Working Papers – Auditing Interpretations of Section 339A
What Happens When Documentation Falls Short
Documentation failures rarely stay theoretical. In peer reviews of non-issuer engagements, incomplete or unclear working papers are among the most common deficiency findings. These can lead to corrective action requirements, additional monitoring, or restrictions on the firm’s enrollment in the AICPA Peer Review Program.
The deeper problem is evidentiary. If a procedure was performed but not documented, and no persuasive alternative evidence exists that it was performed, the practical conclusion is that it was not performed. Oral explanations after the fact do not fill the gap. A missing piece of documentation in a significant area can call the entire conclusion into question, and from there an engagement can unravel quickly.