Welcome to Your Guide on Audit Documentation!
Hello there! Today, we are diving into one of the most important practical areas of auditing: Audit Documentation (governed by HKSA 230). Think of this as the "diary" of an audit. If you are an auditor, your documentation is the only proof you have that you actually did your job correctly.
Don't worry if this seems like a lot of paperwork at first. We will break down exactly why we do it, what goes into it, and the rules you need to follow for the HKICPA QP exam. Let’s get started!
1. What is Audit Documentation?
In simple terms, audit documentation (also called working papers) is the record of the audit procedures performed, the audit evidence obtained, and the conclusions the auditor reached.
The Golden Rule of Auditing: "If it isn't documented, it hasn't been done."
Why is it so important?
Documentation serves two primary purposes:
1. It provides evidence of the auditor’s basis for their overall opinion.
2. It provides evidence that the audit was planned and performed in accordance with HKSAs and legal requirements.
Analogy: Imagine you are a scientist conducting an experiment. If you don't write down your steps and your results, no one will believe your conclusion, and you won't be able to explain how you got there if someone asks you a year later!
Key Benefits:
- Helps the team plan and perform the audit.
- Helps supervisors direction and supervise the work.
- Ensures the team is accountable for its work.
- Allows for quality control reviews and external inspections (like those from the HKICPA).
Quick Review: Documentation proves you did the work and explains why you made certain decisions.
2. Form, Content, and Extent of Documentation
How much detail do you need? HKSA 230 says the auditor should prepare documentation that is sufficient to enable an experienced auditor (with no previous connection to the audit) to understand:
- The Nature, Timing, and Extent (NTE) of the procedures performed.
- The results and the evidence obtained.
- Significant matters arising during the audit and the conclusions reached.
Factors affecting the amount of documentation:
Not every audit file looks the same. The "extent" depends on:
- Size and complexity of the entity.
- Nature of the audit procedures (e.g., a complex valuation needs more notes than a simple bank confirmation).
- Risk of material misstatement (higher risk = more documentation).
- Significance of the evidence obtained.
- Exceptions identified (if you found errors, you must document how you resolved them).
Memory Aid: S-R-S-N
Size of the entity
Risks identified
Significance of evidence
Nature of procedures
Key Takeaway:
The documentation must be clear enough that a stranger (who is an auditor) can look at your file and understand exactly what you did and why.
3. Documenting Specific Items
When you are documenting your work, you must record specific details to show exactly what was tested.
Identifying Characteristics
You can't just say "we tested some invoices." You must record the identifying characteristics of the specific items tested.
Example: "We tested 20 sales invoices. The invoices selected were numbers 1001 through 1020."
Who, What, and When?
Your papers must show:
- Who performed the audit work and the date it was completed.
- Who reviewed the work and the date and extent of the review.
Significant Matters and Professional Judgment
This is a big one for the Professional Level exam. You must document significant matters, such as:
- Issues that give rise to significant risks.
- Results that indicate the financial statements might be materially misstated.
- Circumstances that caused the auditor great difficulty.
- Findings that could lead to a modification of the audit report.
Common Mistake to Avoid: Students often forget that professional judgment must be documented. If you had a tough choice to make and decided "Option A" was better than "Option B," you must write down your reasoning!
4. Ownership and Confidentiality
Who owns the audit files?
The audit firm owns the working papers. They do not belong to the client, even though they contain the client's information.
Confidentiality:
Under the HKICPA Code of Ethics, auditors must keep these papers safe and confidential. You cannot show them to third parties unless:
- The client gives permission.
- There is a legal or professional duty to disclose them.
Did you know? Even though the firm owns the papers, they can, at their discretion, share parts of the working papers with the client, provided it doesn't undermine the audit.
5. Assembly and Retention
Once the audit report is signed, you can't just leave the papers in a mess on your desk. There are strict timelines.
Final Audit File Assembly
The auditor should assemble the final audit file on a timely basis.
For HKICPA exams, the administrative deadline is usually:
\( \text{Final Assembly} \leq 60 \text{ days after the date of the auditor's report} \)
During this "60-day window," you can:
- Delete or discard superseded documentation.
- Sort, collate, and cross-reference papers.
- Sign off on completion checklists.
Important: You cannot perform new audit procedures or reach new conclusions during this assembly period.
Retention Period
How long do firms have to keep these files?
According to HKSQC 1 (and HKSA 230), the retention period is usually:
No shorter than 5 years from the date of the auditor’s report.
Note: Many firms in Hong Kong have a policy to keep them for 7 years to align with tax and limitation period laws.
Key Takeaway Summary:
- Assembly: 60 days to tidy up.
- Retention: Minimum 5 years.
- No changes: After the file is assembled, you must not delete or discard any documentation before the retention period ends.
6. Final Summary Checklist for Students
When you are answering a question on Audit Documentation, ask yourself:
- Is the documentation sufficient for an experienced auditor to understand the work?
- Does it show who did it and who reviewed it?
- Are the significant matters and judgments clearly explained?
- Were the identifying characteristics (like invoice numbers) recorded?
- Is the firm following the 60-day assembly and 5-year retention rules?
You've got this! Audit documentation might seem "dry," but it is the shield that protects an auditor. Master these rules, and you'll be well on your way to success in the Business Assurance module!