Audit files are records maintained by the auditor containing information and documents relating to an audit engagement. They provide evidence of the audit procedures performed, audit evidence obtained, significant matters considered and conclusions reached by the auditor. Audit files generally include the audit plan, engagement letter, working papers, financial statements, supporting documents, confirmations, correspondence and audit reports. They may be maintained in physical or electronic form. Audit files help the auditor plan, perform, supervise and review audit work effectively. They also provide a record of the basis for the auditor’s opinion and support compliance with applicable Standards on Auditing and professional requirements.
Permanent Audit Files:
Permanent Audit Files contain information of continuing relevance to the auditor for the current and future audit engagements of an entity. These files provide background information about the organisation and generally remain useful for several years. They may include the Memorandum and Articles of Association, important legal documents, organisational structure, details of accounting policies, long term contracts, loan agreements, records of fixed assets and information about internal controls. Permanent files reduce the need to collect the same information repeatedly in every audit. However, they should be reviewed and updated whenever significant changes occur.
Current Audit Files:
Current Audit File is a working paper file prepared specifically for a single financial year’s audit engagement, containing documentation relevant only to that particular period rather than information of continuing, long-term significance. Unlike the permanent audit file, which carries forward stable information across multiple years, the current file is compiled fresh for each audit cycle and captures the year-specific evidence, procedures, and conclusions supporting that year’s audit opinion. It typically includes the engagement letter for the year, the trial balance and financial statements under audit, correspondence during the engagement, the audit program with sign-offs, and details of significant matters and misstatements identified. Once the audit concludes, the current file is retained per SA 230 requirements alongside the permanent file.
Key differences between Permanent and Current Audit Files:
| Basis | Permanent Audit File | Current Audit File |
|---|---|---|
| Meaning | Contains information of continuing relevance to the auditor. | Contains information relating mainly to the audit of a particular period. |
| Purpose | Provides background information for present and future audits. | Provides evidence and records of work performed for the current audit. |
| Period Covered | Relevant over several accounting periods. | Generally relates to one specific accounting period. |
| Nature of Information | Contains long term and relatively stable information. | Contains current year transactions, audit procedures and findings. |
| Examples | Constitutional documents, long term agreements, accounting policies and organisational structure. | Current financial statements, audit programme, confirmations, working papers and audit report. |
| Updating | Updated when permanent information changes. | Prepared and updated during each audit engagement. |
| Use | Used repeatedly in subsequent audits. | Mainly used for the audit of the relevant financial year. |
| Main Benefit | Provides continuity and saves time in future audits. | Provides evidence supporting the auditor’s current year conclusions and opinion. |
Ownership and Custody of Working Papers:
1. Auditor as Legal Owner
Working papers prepared during an audit engagement are the legal property of the auditor, not the client, even though the content relates entirely to the client’s financial affairs and business operations. This ownership principle is well-established in auditing practice and professional standards, recognizing that working papers represent the auditor’s own analysis, judgment, and evidence-gathering process rather than merely a compilation of client-provided documents. As the legal owner, the auditor retains full control over the working papers, including decisions regarding their retention, storage, and disposal, subject to applicable professional and regulatory retention requirements governing minimum periods for which documentation must be preserved.
2. No Automatic Right of Client Access
Since working papers belong to the auditor, clients do not have an automatic legal right to access, inspect, or obtain copies of the auditor’s working papers, even though the underlying transactions and records pertain to their own business. The client’s rights are typically limited to receiving the final audit report and any other deliverables explicitly agreed upon in the engagement letter. This distinction is important because working papers often contain the auditor’s confidential assessments, judgments, and risk evaluations, which if disclosed, could compromise the auditor’s independent analytical process or reveal sensitive methodology used in forming the audit opinion.
3. Auditor’s Duty of Confidentiality
Despite owning the working papers, auditors bear a strict professional and ethical duty of confidentiality regarding the information contained within them, as these papers often include sensitive financial, operational, and strategic details about the client’s business. Auditors must not disclose this information to third parties without proper authorization from the client or unless required by law, regulation, or professional obligation, such as responding to a court order or regulatory investigation. This duty persists even after the engagement concludes and extends to all personnel within the audit firm who have access to the working papers during the engagement.
4. Custody and Physical or Electronic Safekeeping
The auditor is responsible for the proper custody and safekeeping of working papers throughout the engagement and the mandated retention period, ensuring they are protected from loss, damage, unauthorized access, or tampering. This involves implementing appropriate physical security measures, such as locked storage for paper-based files, and robust electronic safeguards, including access controls, encryption, and regular backups, for digital documentation. Proper custody practices are essential not only for maintaining confidentiality but also for ensuring the working papers remain available and intact if needed for quality reviews, regulatory inspections, or legal proceedings arising after the engagement concludes.
5. Limited Disclosure to Third Parties
While auditors own and control working papers, there are specific, limited circumstances under which disclosure to third parties may be required or permitted, such as when compelled by law, court order, or regulatory authority, or when a successor auditor requests access with the client’s consent for continuity purposes. Additionally, working papers may be shared with quality control reviewers, peer reviewers, or professional disciplinary bodies conducting oversight of the audit firm’s practices. Any such disclosure must be handled carefully, ensuring only relevant information is shared and that confidentiality is preserved to the greatest extent possible, protecting the client’s legitimate business interests.