What Is an Audit Checklist? Items, Materiality, and Retention

An audit checklist is a structured list of every document, record, and piece of evidence an auditor needs to examine before forming an opinion on a company’s financial statements or internal operations. It works as both a roadmap for the audit team and a to-do list for the organization being reviewed, spelling out what to gather and when to hand it over. A complete submission compresses the engagement; gaps stretch it out.

Internal Versus External Checklists

Who is running the audit changes what the checklist asks for.

An internal audit checklist focuses on whether a company’s own controls and processes are working as designed. Internal auditors report to management or the board, and their goal is to catch operational weaknesses before they become financial problems. The list might request process flowcharts for a single department, or evidence that a control was performed on schedule.

An external audit checklist focuses on whether the financial statements are materially accurate and prepared according to Generally Accepted Accounting Principles (GAAP) or International Financial Reporting Standards (IFRS). External auditors report to investors, creditors, and regulators. Their list will request the general ledger, every bank statement for the audit period, and detailed support for each major balance on the financial statements.

Financial Records on the Checklist

The financial records section is the backbone of any external audit checklist. Everything starts with the general ledger and trial balance, which must tie precisely to the balance sheet and income statement. Auditors use these as a starting point, then select a sample of individual transactions to test in detail.

Bank reconciliations for every material cash account are standard, and auditors almost always request the bank statements directly from the financial institution to confirm the reconciliations aren’t masking discrepancies. An accounts receivable aging report is required to evaluate whether outstanding balances are collectible, since that report drives the estimated allowance for doubtful accounts.

A fixed asset schedule listing each significant item’s original cost, purchase date, and accumulated depreciation supports the depreciation expense on the income statement. Detailed revenue transaction listings are needed so auditors can test whether revenue was recognized in the correct period and at the right amount.

Inventory

For companies that carry physical inventory, the checklist includes documentation of the most recent physical count. Auditors need to see that the count was conducted systematically: items tagged and tracked by location, counted in pairs (one person counting, another recording), and reconciled to the inventory balance in the accounting system. Count sheets, tagged inventory records, and any reconciling adjustments between the physical count and the books are all expected. Auditors will also look for evidence that management performed spot checks during the count.

Debt and Loans

Auditors verify every material debt balance by requesting the original loan agreements, current amortization schedules, and year-end lender statements. Where loan agreements include financial covenants requiring the company to maintain certain ratios or conditions, auditors verify whether those covenants were met. A covenant violation can force the company to reclassify long-term debt as a current liability, which changes the balance sheet significantly and can trigger lender remedies.

Operational and HR Documentation

An audit examines more than the numbers. Board of directors meeting minutes are requested because they document approvals for major capital expenditures, executive compensation changes, and significant contracts. Those minutes let auditors cross-reference management’s claims against what the board actually authorized.

Key contracts round out the operational picture. Material vendor agreements, customer contracts, and equipment leases all get reviewed because they can create obligations that belong on the financial statements. A long-term lease, for example, may need to be recorded as a liability depending on its terms.

Payroll documentation includes the full payroll register and proof that payroll taxes were filed and remitted on time. Employee benefit plan records, including any required compliance testing, get requested to confirm employee-related liabilities are properly recorded. A current organizational chart and listing of key personnel help auditors evaluate the control environment.

For companies undergoing an information security audit such as a SOC 2 examination, the checklist expands into technology governance. The AICPA’s Trust Services Criteria framework evaluates controls across five categories: security, availability, processing integrity, confidentiality, and privacy.1AICPA. 2017 Trust Services Criteria (With Revised Points of Focus – 2022) Documentation typically covers access control policies, encryption standards, incident response plans, vendor management procedures, and evidence that controls were operating effectively over a sustained period.

Compliance and Legal Items

Auditors verify that the company is legally authorized to operate. The checklist requests articles of incorporation and any amendments filed with the state. Bylaws, while not filed with the state, are reviewed as an internal governance document. Evidence of current business licenses and permits confirms the company can legally conduct its operations.

Copies of the most recently filed federal and state income tax returns are standard items. Auditors use these to reconcile the income reported on the financial statements with taxable income, which is how they verify the deferred tax asset and liability calculations. Where the company uses independent contractors, auditors look for documentation supporting those classifications: written agreements, evidence that the workers were issued 1099-NEC forms rather than W-2s, and proof that the company treated similar workers consistently.

Copies of legal representation letters sent to outside counsel are also standard. These letters ask the company’s attorneys to confirm or deny the existence of pending or threatened litigation, giving the auditor a way to assess legal risks that might not appear in the financial records.

Extra Items for Public Companies

Public companies face an additional layer of documentation centered on the Sarbanes-Oxley Act. Federal law requires every annual report to include an internal control report in which management assesses the effectiveness of internal controls over financial reporting.2Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls For larger public companies, an independent auditor must then separately evaluate management’s assessment.3U.S. Securities and Exchange Commission. Study of the Sarbanes-Oxley Act of 2002 Section 404 Internal Control Over Financial Reporting Requirements

The checklist for a SOX engagement typically requests process narratives, flowcharts for key financial cycles, and the results of management’s own internal control testing. Auditors then test those controls through a combination of inquiry, observation, document inspection, and re-performance.4PCAOB. AS 2201 – An Audit of Internal Control Over Financial Reporting Transaction walkthroughs are common: auditors follow a single transaction from start to finish through the company’s systems, questioning personnel and inspecting documentation at each step.

How Materiality Decides What Gets on the List

Not every dollar gets the same scrutiny. Auditors set a materiality threshold early in the engagement, and that number determines which accounts and transactions receive detailed testing. If an error smaller than the threshold wouldn’t change a reasonable investor’s decision, auditors spend less time on it. If it would, the account goes on the checklist for deeper examination.

The threshold is typically calculated as a percentage of a financial benchmark. Common methods include 5% to 10% of net income, 0.5% to 1% of total revenue, or 1% to 2% of total assets. The choice depends on the company’s industry, stability, and what metric its stakeholders focus on most. A company with volatile earnings might use revenue as the base instead of net income, because revenue is more stable year over year. The practical effect: expect more detailed document requests for accounts that sit near the materiality line.

How the Checklist Evolves During Fieldwork

Documentation is typically submitted through a secure online portal, with each uploaded file labeled with the corresponding checklist item number so there’s no ambiguity about what it supports. The audit team’s first step is confirming that everything requested has arrived and is complete.

The initial checklist then evolves into what the profession calls a Prepared By Client list, or PBC list. Audit firms send the PBC list 30 to 60 days before fieldwork starts, and it functions as the running project plan for the engagement. As auditors work through the evidence and find gaps, they add new requests: supporting invoices for unusual expense items, bank confirmations that didn’t arrive, or clarification on transactions that don’t match the original documentation. Fieldwork closes when the engagement partner or manager signs off on the completed checklist, and that signed list becomes part of the permanent audit file.

What the IRS Requests in a Tax Audit

Financial statement audits by accounting firms are one context; many business owners first encounter an audit checklist through an IRS examination, and the IRS list is broader than most expect:5Internal Revenue Service. Audits Records Request

  • Receipts organized by date with notes explaining the business purpose and how each receipt connects to a claimed deduction.
  • Bills and canceled checks grouped together so the IRS can match payments to the obligations they satisfied.
  • Loan agreements, including the original loan, names of borrowers, property location, loan amount, repayment terms, and year-end interest statements.
  • Travel and vehicle logs showing dates, locations, business purpose, and mileage driven.
  • Legal papers related to lawsuits, property acquisitions, or divorce settlements that affect reported income or deductions.
  • Employment documents including uniform policies, continuing education requirements, and W-2 reimbursement statements.

The recurring theme across every IRS request is proof of business purpose. Having the receipt is necessary; having the receipt with a written explanation of why the expense was business-related is what actually survives scrutiny.

Retention and Penalties Tied to Items on the Checklist

Documents gathered for an audit don’t get discarded once the opinion is issued. Federal law requires registered public accounting firms to maintain audit workpapers and related documentation for at least seven years.6Office of the Law Revision Counsel. 15 U.S. Code 7213 – Auditing, Quality Control, and Independence Standards and Rules The PCAOB gives auditors 45 days after releasing the audit report to assemble the final documentation package, after which no items can be deleted.7PCAOB. AS 1215 – Audit Documentation – Appendix A

Companies themselves should keep their supporting records at least as long as tax rules require. The IRS generally requires business records to be kept for at least three years after the return is filed, but several situations extend that period:8Internal Revenue Service. How Long Should I Keep Records?

  • Three years from the filing date for most returns.
  • Six years if unreported income exceeds 25% of gross income shown on the return.
  • Seven years for worthless securities or bad debts.
  • At least four years after the tax is due or paid for employment taxes, whichever is later.
  • Indefinitely for unfiled or fraudulent returns.

Property records deserve special attention. The IRS requires records related to property to be kept until the statute of limitations expires for the year you dispose of the property, because those records are needed to calculate depreciation and any gain or loss on sale.

Providing false documents to auditors is a federal felony. Anyone who knowingly makes a false statement or uses a falsified document in a matter within the jurisdiction of the federal government faces up to five years in prison and financial penalties, rising to eight years where terrorism-related offenses are involved.9Office of the Law Revision Counsel. 18 U.S. Code 1001 – Statements or Entries Generally Destroying audit records carries steeper consequences: an accountant who fails to maintain audit workpapers for the required retention period can face up to ten years in federal prison.10Office of the Law Revision Counsel. 18 U.S. Code 1520 – Destruction of Corporate Audit Records If a document is on the checklist, produce it honestly or flag the issue with legal counsel. Fabricating, altering, or shredding records turns an accounting problem into a criminal one.