16.1 Organizing Complete Workpapers with Sufficient Evidence

Key Takeaways

  • CIA Part 2 B7a–b tests organizing information in workpapers and identifying complete elements with sufficient evidence: index, two-way cross-references, headers (objective, source, purpose, conclusion), tick-mark legend, and preparer/reviewer identification
  • GIAS Standard 14.6 requires documentation so an informed, prudent internal auditor or similarly competent person could repeat the work and derive the same engagement results — the Chapter 12.3 reperformance test applied to the file
  • Cross-references run both ways: the finding sheet cites the test, and the test cites the finding; a folder of PDFs named support is not an index
  • Tick marks without a legend, and supervisor initials without exhibits, fail the competent-person test because sign-off reviews evidence and is not a substitute for it
  • Completeness is reperformable evidence organized to the engagement objective; dumping unannotated emails or full extracts is clutter, not a complete workpaper
Last updated: August 2026

16.1 Organizing Complete Workpapers with Sufficient Evidence

Quick Answer: CIA Part 2 B7a–b asks you to organize information in workpapers and to identify elements of workpapers that are complete and include sufficient evidence. A complete workpaper is indexed and cross-referenced, carries headers for objective, source, purpose, and conclusion, uses tick marks with a legend, and shows who prepared and who reviewed it — with enough content that an informed, competent person can reperform the work (Chapter 12.3; GIAS Standards 14.1 and 14.6). Completeness is not dumping every email into the file.

Section B is 40% of CIA Part 2. You have already sourced information (Chapter 11), filtered it for relevance, sufficiency, and reliability (Chapter 12), used technology and analytics (Chapters 13–14), and evaluated findings against criteria (Chapter 15). B7a–b is the proficient documentation skill those chapters assume: the file, not hallway memory, must carry the engagement. GIAS Standard 14.6, Engagement Documentation, requires internal auditors to document information and evidence to support engagement results so that an informed, prudent internal auditor, or a similarly informed and competent person, could repeat the work and derive the same engagement results. Chapter 17 will seat a supervisor in that chair. This section is how you organize the papers so that test can pass.

Indexing and cross-references

Indexing is how a reviewer finds the trail without calling you. A typical engagement file uses a lead-sheet structure: a planning series, a process-understanding series, a testing series per objective, and a findings series. Detail workpapers hang off the lead sheet (C-1 population and IPE, C-2 sample, C-3 tests of details). The index number appears on every page or electronic equivalent.

Cross-references are two-way. The finding sheet F-1 cites C-3 (the test that produced the exception). C-3 cites F-1 (the finding that uses this exception). A lead sheet C cites C-1 through C-3 and states whether the objective was achieved. If a reviewer cannot jump from a sentence in a conclusion to the exhibit that supports it, the file is not organized — even if the exhibits exist somewhere in a zip file.

Electronic workpaper systems do not waive indexing. A folder of PDFs named AP stuff is not an index. A unique reference, a title, and a link from the conclusion to the exhibit are the same elements on paper or in software. B7a is the skill of putting information in a structure a stranger can navigate, not of generating more files.

IndexRoleWhat a reviewer should find
APlanning / risk and criteriaObjectives, scope, evaluation criteria, approved work program
BProcess understandingWalk-through notes, flowchart, control descriptions
CTests for an objectivePopulation, IPE tests, sample, results, conclusion on that objective
F-1Finding sheetCriteria, condition, cause, effect, plus cross-ref to the tests
Lead sheetBridgeMap from objective to workpapers to the conclusion on that objective

Headers: objective, source, purpose, conclusion

Every workpaper needs a header a stranger can read in thirty seconds. CIA Part 2 tests the elements, not your shop's template fonts.

  • Objective — which engagement objective or work-program step this paper serves. If the paper does not serve an objective, it does not belong in the engagement file.
  • Source — where the information came from (ERP disbursement report, warehouse observation on 12 March, vendor confirmation). Source lets the reviewer judge reliability (Chapter 12.2) and reperform the step.
  • Purpose — why you prepared the paper (test operating effectiveness of the three-way match; document the walk-through). Purpose is not a restatement of the title.
  • Conclusion — what you concluded from this paper, in language that matches the evidence on it. Appears OK with no criterion is not a conclusion.

Other header fields that make the paper complete: engagement name and number, period covered, date of work, and the index itself. The usual exam pattern for an incomplete workpaper is a grid of ticks that omits source or conclusion, or a screenshot with no objective.

Tick marks and the legend

Tick marks are shorthand for procedures performed on a figure or a line: traced to invoice, footed, agreed to subledger, exception noted. They save space only if a legend sits on the workpaper or the methodology's standard legend is identified on the paper. Unlabeled ticks are decoration. A competent person cannot reperform a row of unexplained symbols if nobody recorded that one mark means traced to signed receiving report and another means footed.

If you use a standard legend from the internal audit methodology, reference it on the paper. If you invent a one-off symbol for this test, define it on this workpaper. Either way, the legend is part of sufficient evidence, not optional formatting. Copying ticks from last year's file without checking that the legend still matches this year's methodology is how reviewers inherit mystery marks.

Who prepared and who reviewed

GIAS 14.6 expects documentation to be reviewed for accuracy, relevance, and completeness. The paper must show who prepared it and when, and who reviewed it and when. Identity plus date is the minimum. A typed name with no date, or an electronic complete flag that does not capture the reviewer, is weaker than a dated sign-off the system can attribute to a person.

Review notes are part of the file. Open notes (follow up with the AP manager) that were never cleared leave the conclusion unsupported. Clearing a note by deleting it without leaving the disposition is the same problem as oral exception clearance in Chapter 12.3. Chapter 17 covers how supervisors review; here you only need the element: the paper identifies preparer and reviewer. Initials in the header do not replace missing exhibits — sign-off reviews evidence; it is not evidence.

Enough that a competent person can reperform (ties to 12.3)

Chapter 12.3 taught the reperformance test: would a prudent, informed, competent person looking only at the evidence reach the same conclusion? B7b asks whether the workpaper package contains the elements that make that possible. GIAS 14.1 builds the outsider into sufficiency; 14.6 requires the documentation to let that person repeat the work.

A reperformable testing workpaper typically shows all of the following:

  1. The engagement objective and evaluation criterion this procedure addresses.
  2. The population and how information produced by the entity (IPE) was tested for completeness and accuracy.
  3. The procedure and selection method (sample, full extract, judgmental).
  4. Items examined in a way a reviewer can retrieve them (invoice numbers, dates, system document IDs) — not necessarily a photocopy of every page.
  5. Exceptions and how each was disposed of (cleared with evidence, or carried to a finding).
  6. A conclusion that follows from those results, plus a tick-mark legend and preparer/reviewer identification.

If any of those live only in your memory, the paper is not yet complete. The person in 12.3 and 14.6 is a reviewer, another auditor, or an external assessor — not the staff member who was there.

Completeness versus dumping emails

Completeness means the file has the elements above and enough evidence to reperform. It does not mean retaining every email, chat, screenshot, and full-population extract just in case. Unannotated dumps fail two ways: a reviewer cannot find the fact that matters, and confidential data is stored without a purpose (a 16.2 problem). One indexed, annotated email that is the exception — with source, date, parties, and why it evidences the condition — is complete. A 400-message mailbox export is not.

The long-standing warning against happy workpapers still applies under GIAS 14.6: more paper is not better paper. Select, index, annotate, and conclude. If an exhibit does not support an objective, a finding, or a required planning step, leave it out. Dumping is sometimes offered on the exam as the safe answer because it looks thorough. It is the wrong answer. Thorough is navigable and reperformable.

Worked example: three-way match file

Engagement objective: determine whether invoices are paid only after a three-way match. Criterion: Policy AP-14. Workpaper C-1 documents the AP disbursement report, IPE tests, and the in-scope population. C-2 documents random selection of 40 invoices. C-3 is the test grid: invoice number, PO, receiver, match evidence, tick marks, exceptions. F-1 is the finding for twelve unmatched invoices paid, cross-referenced to C-3 lines 7, 11, and 19–28. Each paper's header states objective, source, purpose, and conclusion. Preparer and reviewer signed with dates. A reviewer who never walked the warehouse can still reperform the test from C-1 through F-1. A zip of AP's shared inbox labeled evidence would not pass B7b even if the twelve invoices happened to sit somewhere inside it.

Exam traps

  • Treating volume as completeness (the email dump).
  • Headers that omit source or conclusion.
  • Tick marks without a legend.
  • Relying on supervisor initials to replace missing exhibits.
  • Assuming an electronic system auto-completes the elements — it stores what you put in it.
Loading diagram...
Organizing complete workpapers (GIAS 14.6 and the 12.3 reperformance test)
Illustrative reperformance from the file (0 = not reperformable, 4 = complete packet; teaching scale, not survey data)
Test Your Knowledge

Which package best shows the elements of workpapers that are complete and include sufficient evidence under CIA Part 2 B7b and GIAS Standard 14.6?

A
B
C
D
Test Your Knowledge

A test grid shows three unexplained symbols beside invoice amounts. The auditor says everyone on the team knows what they mean. Why does this workpaper fail the competent-person standard taught in Chapter 12.3 and required by GIAS 14.6?

A
B
C
D
Test Your Knowledge

A staff auditor uploads 400 unannotated emails and a full AP extract into the engagement file and marks the workpapers complete because nothing was left out. Which statement is correct?

A
B
C
D