Audit Walkthrough: Procedures, Controls, and Documentation

An audit walkthrough is the procedure in which the auditor selects one real transaction and traces it from the moment it originates through every system, handoff, and control until it posts to the general ledger, using the same documents and screens the client’s own employees use. Under PCAOB Auditing Standard 2201, walkthroughs are “frequently the most effective way” to understand how misstatements could occur and what controls stand in the way.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Done well, it confirms that the process on paper matches the process in practice. Done poorly, it lets the rest of the audit rest on assumptions the auditor never actually tested.

What a Walkthrough Is Meant to Prove

The walkthrough answers one question: could a material error slip through this process undetected? To answer it, the auditor confirms two things about every control along the way. First, that the control is designed to catch the risk it’s supposed to catch. Second, that real people (or real code) are actually using it in daily work, not just describing it in a policy manual.

PCAOB Auditing Standard 2110 ties this directly to the risk assessment: walkthroughs “ordinarily are sufficient to evaluate design effectiveness” and “to determine whether a control has been implemented.”2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement Without one, the auditor is trusting flowcharts and narratives that often describe an idealized version of the process.

For integrated audits of public companies, AS 2201 requires the auditor to perform walkthroughs personally or directly supervise the work. This is one of the few procedures that cannot be delegated to client personnel or outsourced specialists.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Management is not required to perform walkthroughs under Sarbanes-Oxley Section 404, but companies that do run their own before the external team arrives usually have a much stronger grip on their control environment when the audit begins.

Choosing What to Walk Through

Scoping starts with materiality. The team sets a preliminary threshold, often based on a stable benchmark such as pre-tax income, and identifies every account balance or transaction class that exceeds it. Each significant account needs at least one walkthrough of the cycle that feeds it.

The cycles most commonly in scope are revenue recognition, purchasing and accounts payable, inventory, payroll, and treasury. Cycles that involve complex judgments or high transaction volumes get the most attention, since both create distinct opportunities for misstatement.

Outsourced Processes

When a significant process runs at a third party, such as a payroll provider or loan servicer, the walkthrough has to reach into that service organization. The auditor typically obtains a SOC 1 Type II report describing the provider’s controls and an independent opinion on their operating effectiveness. AS 2601 directs auditors on integrated audits to consult the service organization guidance in AS 2201 for these situations.3Public Company Accounting Oversight Board. AS 2601 – Consideration of an Entity’s Use of a Service Organization

SOC reports usually identify complementary user entity controls that the client must operate for the provider’s controls to work. A payroll processor’s controls assume the client restricts who can submit payroll changes; a loan servicer’s controls assume the client reconciles servicer reports to internal records. The walkthrough needs to verify those client-side controls exist. Many audits fall short here by focusing on the SOC report and skipping the client’s own responsibilities.

Management Override

Every scope must account for the risk that management itself circumvents the controls the auditor is evaluating. No matter how clean a control environment looks, senior personnel with enough authority can override approvals, post manual journal entries, or adjust estimates. The walkthrough is the right moment to ask pointed questions: who can post manual entries, what review governs them, has anyone overridden a system control during the period? Reviewing general ledger activity for unusual adjustments affecting revenue, liabilities, or key performance indicators near period end fits naturally into the same work.

The Four Procedures at Each Control Point

AS 2201 specifies four procedures the auditor performs at each control point during a walkthrough: inquiry, observation, inspection of relevant documentation, and re-performance of controls.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements All four apply to the same transaction; the auditor uses each to test a different aspect of the same control.

Inquiry

At each processing point, the auditor asks the responsible employee what they do, why they do it, and what happens when something goes wrong. AS 2201 specifically calls for “probing questions” that go beyond the single transaction being traced, so the auditor understands how the process handles different significant transactions, not just the one selected.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements If an accounts payable clerk says “I check the three-way match before approving,” the follow-up is what they do when the quantities disagree. The answers reveal whether the person understands the control or is reciting a procedure manual.

Observation

Watching an employee perform the control on the selected transaction confirms the stated procedure is the actual procedure. Observation catches what inquiry cannot: the step someone skips because “we never really do that part,” or the supervisor who signs off without reviewing what they’re approving.

Inspection

At each control point, the auditor examines the physical or electronic evidence that the control was performed. For a revenue transaction, that means the customer order, shipping documentation, invoice, and any system-generated approval logs. Signatures, timestamps, and access logs should show the right person performing the control at the right time. Missing or backdated documentation is a red flag.

Re-Performance

Re-performance means the auditor independently executes the control and compares results. If the control matches a purchase order to an invoice and receiving report, the auditor performs that match. This is the most powerful of the four procedures because it tests whether the control actually works, not just whether someone says it does. It’s especially valuable for reconciliations and mathematical checks.

Segregation of Duties

Throughout, the auditor tracks who touches the transaction at each stage. The person initiating a transaction should not be the person approving it or reconciling the account. When one individual can both authorize a payment and release the funds, the risk of fraud or undetected error jumps. Mapping these responsibilities during the walkthrough is the natural place to flag overlaps.

Automated Controls and IT General Controls

Most transactions today pass through automated systems where controls sit inside software rather than in a person’s hands. An automated three-way match runs the same way every time the code executes. The walkthrough of an automated control looks different from a manual one. Instead of watching an employee, the auditor confirms the system is configured correctly and that the IT general controls (ITGCs) support continued reliance on the application.

ITGCs typically cover four areas: logical access (who can get into the system and what they can do), change management (how modifications are authorized, tested, and deployed), computer operations (job scheduling, backup procedures), and program development. During the walkthrough, the auditor verifies that user access follows the principle of least privilege and that changes to financial applications go through formal approval and testing before reaching production.

The payoff is real. When ITGCs are solid and an automated control is properly configured, that control needs far less testing than a manual one because it doesn’t have bad days or skip steps. When ITGCs are weak, particularly around access, the auditor cannot rely on any automated control in that system and has to expand substantive testing.

Documenting the Walkthrough

AS 1215 requires audit documentation detailed enough to provide “a clear understanding of its purpose, source, and the conclusions reached,” organized to give “a clear link to the significant findings or issues.”4Public Company Accounting Oversight Board. AS 1215 – Audit Documentation In practice, workpapers must identify the specific transaction traced, including its unique identifier, and record what the auditor found at each control point.

Most teams use some combination of three formats. A system narrative describes the transaction flow and embedded controls step by step. A process flowchart maps the movement of documents and data visually. A control matrix lists each control alongside the financial statement assertion it addresses and the risk it mitigates. The best documentation combines all three, because a flowchart shows the “what” quickly while the narrative captures “how” and “why.”

Any deviation from the expected process gets documented immediately, however minor it seems. An employee who skips an approval “because it takes too long” is a finding even if no misstatement resulted. The documentation should state what the auditor expected to find, what was actually found, and the implications for the control’s effectiveness.

Deficiencies the Walkthrough Surfaces

When a walkthrough shows that a control is missing, poorly designed, or not operating as management described, the auditor has identified a deficiency. A design deficiency exists when a necessary control is absent, or when the control, even if performed perfectly, would not prevent or detect a misstatement. An operational deficiency exists when a properly designed control isn’t being performed correctly, or is being performed by someone without the authority or competence to do it effectively.5Public Company Accounting Oversight Board. Auditing Standard No. 5 Appendix A – Definitions

Deficiencies sit on a spectrum. A significant deficiency merits attention from those overseeing financial reporting but falls short of the most severe category. A material weakness means there is a reasonable possibility that a material misstatement will not be prevented or detected on time.5Public Company Accounting Oversight Board. Auditing Standard No. 5 Appendix A – Definitions

The auditor must communicate all significant deficiencies and material weaknesses in writing to management and the audit committee before the audit report is issued.6Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements In an integrated audit, a material weakness has a direct consequence: AS 2201 requires the auditor to issue an adverse opinion on the company’s internal control over financial reporting.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements For a public company, that’s a public event.

How the Walkthrough Drives the Rest of the Audit

Walkthrough findings shape the plan for control testing and substantive procedures. When the walkthrough confirms a control is well designed and implemented, the auditor moves to testing operating effectiveness across a larger sample of transactions from the period. For lower-risk controls, the walkthrough itself may provide enough evidence of operating effectiveness, depending on the specific procedures performed and their results.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

When a walkthrough reveals a severe design deficiency, the calculation changes. The auditor typically bypasses control testing for that area and relies on substantive procedures: detailed balance testing, analytical procedures, and expanded sampling. That shift costs both sides more time and evidence than a controls-based approach. Every risk of material misstatement identified during the walkthrough should trace to a specific audit response in the engagement plan; treating the walkthrough as a box-checking exercise and then building a testing strategy independently gets the sequence wrong.

Remote Walkthroughs

Remote walkthroughs are now a standard part of the toolkit. Video conferencing lets the auditor interact with client personnel in real time while an on-site representative provides live visual access to facilities and workstations. The auditor watches shared screens, observes employees performing controls, and inspects documents displayed on camera.

They require preparation in-person visits do not. The team should verify technology compatibility before the walkthrough, confirm that on-site staff can navigate screens and position cameras for clear viewing, and establish a secure platform for sharing sensitive financial information. Defining roles and communication protocols in advance keeps the session from turning into a disorganized video call.

Inquiry and inspection travel well over video. Observation is harder but workable with a competent on-site guide. Re-performance can be done independently by the auditor through remote access to client systems. What’s lost is the informal context: the stack of unprocessed invoices on a desk, the sideways glance when you ask about a control everyone knows nobody follows.