SA 230 Audit Documentation explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SA 230 tells the auditor what to write down, when, and for how long to keep it. The test is simple: an experienced auditor with no link to the audit should be able to understand what was done, what was found and why the conclusions were reached.
SA 230, as effective for audits of financial statements for periods beginning on or after 1 April 2009, applies to every audit. ICAI may revise standards, so check icai.org for the current text. Our existing explainer on audit documentation and working papers gives a short introduction.
The auditor must prepare documentation on a timely basis that lets an experienced auditor with no previous connection to the audit understand the procedures, results, evidence, significant matters and judgments. The file is assembled soon after the report (ordinarily within 60 days), nothing is discarded during the retention period, and later changes are recorded with reasons. The retention period is seven years from the report date, following ICAI's Council decision of August 2009.
Purpose and objective (paragraphs 1-6)
Documentation is the evidence for the basis of the report and for the fact that the audit was planned and performed in line with the SAs and the law (paragraph 2). It also helps the team plan, supervise and review, keeps a record of matters that matter in future years, and enables quality reviews and inspections by the firm and external bodies (paragraph 3). The specific documentation requirements in other SAs do not limit SA 230 (paragraph 1).
The objective is a sufficient and appropriate record of the basis for the report, plus evidence of compliance (paragraph 5). Paragraph 6 defines audit documentation (the record of procedures, evidence and conclusions, also called working papers), the audit file (the folders or media holding it, physical or electronic) and the experienced auditor (someone with practical audit experience and a reasonable understanding of audit processes, SAs and law, the business environment, and the audit and reporting issues in the industry).
What the auditor must record
| Requirement | What it means | Paragraph |
|---|---|---|
| Timely preparation | Prepare documentation as the work is done; later notes are likely to be less accurate | 7, A1 |
| The "experienced auditor" test | Documentation lets such a person understand the nature, timing and extent of procedures, the results and evidence, and significant matters, conclusions and judgments | 8 |
| Identifying characteristics | Record what items or matters were tested, who did the work and when, who reviewed it and when and how far | 9 |
| Discussions | Record discussions of significant matters with management, those charged with governance and others: what, when and with whom | 10 |
| Inconsistencies | If information is inconsistent with the final conclusion on a significant matter, record how it was addressed | 11 |
| Departures | In exceptional circumstances, record the alternative procedures and the reasons for departing from a requirement | 12 |
| After the report date | If new procedures or conclusions arise in exceptional circumstances, record the circumstances, the work done, the effect on the report, and when and by whom changes were made and reviewed | 13 |
Application points to know
- Form and extent depend on the size and complexity of the entity, the risks, the significance of the evidence and exceptions and the audit methodology (A2). Documentation can be on paper or electronic media, and includes audit programmes, analyses, issues memoranda, confirmations and representation letters, checklists and correspondence including email (A3).
- What need not be kept: superseded drafts, incomplete or preliminary notes, corrected copies and duplicates (A4). Oral explanations alone are not adequate support (A5).
- No need to document everything. It is neither necessary nor practicable to record every matter or judgment, and no separate checklist is needed where the file itself shows compliance, for example a signed engagement letter shows the terms were agreed (A7).
- Significant matters include significant risks, results suggesting the statements could be materially misstated, serious difficulty in applying procedures, and findings that could lead to a modification or Emphasis of Matter (A8). A completion memorandum summarising significant matters is optional but useful (A11).
- Specific items tested. Record, for example, purchase orders by date and number, the scope for an all-items-above-a-limit test, the starting point and interval for a systematic sample, dates and names for inquiries (A12).
- Review evidence means documenting what was reviewed, by whom and when; it does not mean a sign-off on every working paper (A13).
- Smaller entities need less extensive documentation, and may combine strategy, plan, materiality and assessed risks in one document with cross-references, but the experienced-auditor test still applies (A16-A17).
Assembling the final file (paragraphs 14-16)
The auditor must complete the administrative process of assembling the file on a timely basis after the report date (paragraph 14). SQC 1 expects the firm to set a time limit, and A21 says that is ordinarily not more than 60 days after the date of the auditor's report. Assembly is administrative: no new procedures or conclusions. Allowed changes include deleting superseded papers, sorting and cross-referencing, signing completion checklists and documenting evidence already obtained and agreed with the team before the report date (A22).
After assembly the auditor must not delete or discard documentation before the end of the retention period (paragraph 15). If it becomes necessary to modify or add documents after assembly, in circumstances other than paragraph 13, the auditor records the specific reasons and when and by whom the changes were made and reviewed (paragraph 16). A24 gives the example of clarifying existing papers after comments from a monitoring inspection.
Retention: seven years
A23 says the retention period for audits is ordinarily no shorter than seven years from the date of the auditor's report, or, if later, the date of the group auditor's report. A footnote explains that ICAI's Council amended the audit documentation retention period from ten years to seven years in August 2009, covering paragraph 83 of SQC 1 and paragraph A23 of SA 230 as first issued in January 2009. Anyone reading an older copy or secondary material that still says ten years should treat seven years as the ICAI period, while checking whether any law or regulation requires longer. The ICAI note to the SA also says the seven-year period reflects the minimum retention of working papers under the Chartered Accountants Act, 1949 and regulations made under it, in place of five years in the international text.
A25 adds that, unless law says otherwise, audit documentation is the property of the auditor, who may give clients portions or extracts if that does not undermine the work or independence. It is not a substitute for the entity's own accounting records (A3).
How SA 230 connects to other standards
Many SAs contain their own documentation lists, for example on planning (SA 300), sampling (SA 530) and engagement quality review (SQC 1 part 2). SA 230 is the general rule that sits under all of them. For a tax audit working-paper angle, see audit procedures and working papers in a tax audit.
Illustrative example
Jain & Associates audits Trivedi Logistics Pvt Ltd. The manager tests 40 freight invoices and records each by invoice number and date, the vendor, the agreed rate, the person who tested it and the date, and the reviewer and review date. A freight rate on one invoice does not match the contract. The team records the discussion with the finance head on 14 June, the explanation received, the extra invoices tested and the conclusion that the difference is trivial. The report is dated 28 June; the file is assembled by 20 August, within 60 days. In October an inspection comment prompts a clarifying note, recorded with the reason, date and name of the person who made and reviewed it.
Need help with documentation discipline?
If your firm or finance team wants file indexes, sign-off templates and retention schedules that match what SA 230 expects, TaxClue's compliance documentation service can help you set them up. Audited companies can also use our compliance documentation support to organise the schedules an auditor will ask for.
Key takeaways
- Write up the work when it is done, and for a reader with no prior knowledge of the audit.
- Record what was tested, by whom, when, and who reviewed it.
- Assemble the file ordinarily within 60 days of the report and do not discard anything during retention.
- Keep audit documentation for seven years from the report date, longer if law requires.
- Record the reasons, date and person for any change after the file is assembled.
Read next
- SA 200: overall objectives of the auditor
- SQC 1, part 2: file assembly and retention for the firm
- SA 530: audit sampling
- Audit documentation and working papers
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
