Audit workpapers and documentation: what AS 1215 requires

Under the current version of AS 1215, an audit file has to be locked down within 14 days of the report release date, not the 45 days auditors had for the past two decades. The PCAOB cut the documentation completion window by more than two-thirds, and for firms that issued audit reports for more than 100 issuers during calendar year 2024, the new rule already applies. Every other registered firm follows for fiscal years beginning on or after December 15, 2025, which means essentially every calendar-year 2026 audit is covered.

That shorter window raises the cost of the usual loose ends: a confirmation that never got a final tick mark, a PBC item that arrived late and never made it into the workpapers, a disagreement between reviewers that only ever got resolved out loud. There is a lot less runway now to catch and fix a gap like that before the file closes for good.

This guide walks through what AS 1215 actually requires, how that connects to the PBC list and the evidence standard in AS 1105, where engagement letters fit for issuer and nonissuer audits, and the two dates that determine when a workpaper file is truly done.

Key takeaways

  • AS 1215 requires audit documentation to show the procedures performed, evidence obtained, and conclusions reached, in enough detail that an experienced auditor with no prior connection to the engagement could understand what was done and why.
  • The documentation completion date, the deadline to assemble a complete and final audit file, was cut from 45 days to 14 days after the report release date. Large firms have complied since fiscal years beginning December 15, 2024; all other registered firms follow for fiscal years beginning December 15, 2025.
  • Issuer audit documentation must be retained for seven years from the report release date. Nonissuer audits under AICPA standards use a 60-day assembly window and a five-year retention period instead.
  • After the documentation completion date, nothing can be deleted or discarded. Information can still be added, but the addition must show the date, the preparer's name, and the reason.
  • A PBC list is not itself a PCAOB requirement. It is the practical tool that turns AS 1105's evidence needs into a dated, trackable request, which is why a late or incomplete PBC list so often shows up as a documentation gap later.
  • Issuer audits have no standalone engagement-letter standard, but AS 1301 requires the auditor to record the understanding of the engagement terms in an engagement letter and give it to the audit committee annually. AS 2101 lists establishing that understanding as a preliminary engagement activity. Nonissuer audits follow AU-C 210, which requires a written engagement letter with specific elements.
  • Sufficiency and appropriateness are two different tests under AS 1105. Sufficiency is about quantity, appropriateness is about quality, and more of the same low-quality evidence never substitutes for better evidence.

What counts as audit documentation under AS 1215

AS 1215 defines audit documentation as the written record that supports the representations in the auditor's report, whether those representations appear in the report itself or elsewhere. It includes memoranda, confirmations, correspondence, schedules, audit programs, and letters of representation, in paper, electronic, or other form. The standard also uses work papers and audit working papers interchangeably with the formal term.

The documentation has to do three things at once:

  • Demonstrate that the engagement complied with PCAOB standards.
  • Support the auditor's conclusions on every relevant financial statement assertion.
  • Show that the underlying accounting records agreed or reconciled with the financial statements.

The experienced auditor test

The standard sets a specific bar: documentation must contain enough information for an experienced auditor, someone with no previous connection to the engagement but a reasonable understanding of audit activities and the client's industry, to understand the nature, timing, and extent of the procedures performed, the evidence obtained, and the conclusions reached, and to determine who performed the work and when it was completed, and who reviewed it and when.

That test is also why vague narrative ("tested the sample, no exceptions noted") fails inspection even when the underlying work was sound; the file has to carry its own explanation.

How much documentation is enough

AS 1215 lists five factors that determine the nature and extent of documentation for a given assertion:

  • The nature of the procedure.
  • The risk of material misstatement tied to the assertion.
  • How much judgment the work required.
  • How significant the evidence is to the assertion.
  • Whether the conclusion is readily apparent from the documentation of the procedures themselves.

An accounting estimate, which involves more judgment, needs more extensive documentation than a routine recalculation.

Engagement letters: where the file actually starts

Before any evidence gets gathered, the terms of the engagement have to be agreed. That agreement looks different depending on whether the client is an issuer or a nonissuer.

Issuer audits have no standalone engagement-letter standard

PCAOB standards do not have a standalone engagement-letter standard the way AICPA standards do, but the requirement is there. AS 2101, Audit Planning, requires the auditor to complete preliminary engagement activities, including client acceptance and continuance and establishing an understanding of the engagement terms with the audit committee. AS 1301, Communications with Audit Committees, then requires the auditor to establish that understanding (the objective of the audit, the auditor's responsibilities, and management's responsibilities), record it in an engagement letter, and provide the letter to the audit committee annually. If the understanding can't be established, the auditor should decline to accept, continue, or perform the engagement.

Nonissuer audits follow AU-C 210

For audits conducted under AICPA standards, AU-C 210, Terms of Engagement, requires the agreed terms to be recorded in a written engagement letter or other suitable form of written agreement before the auditor accepts the engagement. The terms have to cover:

  • The objective and scope of the audit.
  • Management's and the auditor's respective responsibilities, including the inherent limitations of an audit.
  • The applicable financial reporting framework.
  • The expected form and content of the auditor's reports, and a statement that a report may differ from that expected form and content.

The engagement is accepted only once the preconditions for an audit are confirmed and a common understanding of the terms is reached.

The PBC list: turning evidence needs into a request

A PBC list, sometimes called an audit PBC list, the items prepared by client list, is where audit planning becomes a concrete set of asks. It is not itself a named PCAOB or AICPA requirement. It is the operational tool that makes AS 1105's evidence-sufficiency standard workable in practice: before the team can test anything, someone has to request the trial balance, the bank statements, the lease schedules, the fixed asset roll-forward, and dozens of other items, each tied to a specific assertion the audit needs to support.

A PBC list that goes out late, or without a firm due date, tends to produce the exact documentation gaps AS 1215 inspections catch: evidence obtained close to or after the report release date, with no time left to review it properly before the file has to be locked down. Three habits reduce that risk:

  • Tie each PBC item to the assertion or risk it supports, not just a generic account name, so a reviewer can see why the item was requested.
  • Set a due date tied backward from the documentation completion date, not forward from the engagement letter, since the 14-day issuer window leaves little room for a request that arrives in week three.
  • Log the date each item was actually received and who on the team reviewed it, since that date becomes part of the evidential record under AS 1215's documentation requirements.

Sufficient appropriate audit evidence under AS 1105

Every workpaper exists to record evidence, and AS 1105 sets the bar for what counts. The standard requires the auditor to plan and perform procedures to obtain sufficient appropriate audit evidence, a reasonable basis for the opinion.

Sufficiency and appropriateness are not the same test

Sufficiency measures quantity: the amount of evidence needed rises with the risk of material misstatement and falls as the quality of the evidence improves, but obtaining more of the same low-quality evidence never makes up for evidence that is weak to begin with.

Appropriateness measures quality: specifically, relevance and reliability. Evidence from a knowledgeable source independent of the company is generally more reliable than evidence from inside the company alone; evidence the auditor obtains directly is more reliable than evidence obtained secondhand; and original documents are more reliable than photocopies or converted files, whose reliability then depends on the controls over that conversion.

The procedures that produce the evidence

AS 1105 names seven specific procedures:

  • Inspection.
  • Observation.
  • Inquiry.
  • Confirmation.
  • Recalculation.
  • Reperformance.
  • Analytical procedures.

Inquiry of company personnel is explicitly called out as insufficient on its own; the standard requires that it be combined with other procedures to reduce audit risk to an appropriately low level.

Selecting what to test

When testing an account or a control, the auditor chooses among three approaches:

  • Selecting all items (100% examination).
  • Selecting specific items, such as those over a dollar threshold or exhibiting unusual characteristics.
  • Audit sampling.

Selecting specific items does not constitute sampling, and the results of testing those items cannot be projected across the rest of the population. That distinction matters in documentation, since a workpaper that treats a specific-item test as if its results applied to the whole population misstates what the evidence actually supports.

The two dates that end an audit file

Two dates govern everything that happens after fieldwork: the report release date, when the auditor grants permission to use the report, and the documentation completion date, the deadline to assemble a complete and final file for retention.

Issuer (PCAOB, AS 1215)Nonissuer (AICPA, AU-C 230)
Assembly deadline14 days after the report release date60 days after the report release date
Retention period7 years from the report release date5 years from the report release date
Can documentation be deleted after assembly?NoNo
Can documentation be added after assembly?Yes, with date, preparer, and reason documentedYes, with similar documentation

The 14-day figure is new. Since 2004, AS 1215 gave issuer auditors 45 days to assemble the file, and the amendment compresses that window through PCAOB Release No. 2024-004.

The cut phases in by firm size: firms that issued audit reports for more than 100 issuers during calendar year 2024 had to comply for fiscal years beginning on or after December 15, 2024, and every other registered firm follows for fiscal years beginning on or after December 15, 2025. For a firm on a calendar fiscal year, that means the 2026 audit cycle is covered either way.

Once the documentation completion date passes, the rule is absolute: nothing gets deleted or discarded, for the full retention period. Circumstances can still require additions, and the standard allows them, but every addition has to carry the date it was added, the name of the person who added it, and the reason.

Where this tends to go wrong

Three patterns show up repeatedly in documentation deficiencies:

  • Evidence gets obtained late, often tied to a PBC item that arrived close to fieldwork's end, leaving no real review window before assembly.
  • Significant findings get resolved in conversation rather than in the file, so the engagement completion document that AS 1215 requires for significant issues ends up thin.
  • Specific-item testing gets documented as though it were a representative sample, which overstates what the work actually supports.

None of these are new failure modes. What changed is the margin for catching them before the file locks: a 45-day window left room to notice a gap and go back for more evidence, and a 14-day window does not.

That is why the documentation discipline has to happen during fieldwork rather than after it, and it matters whenever an engagement crosses standard-setters, not just inside a single AS. A single audit that layers GAGAS requirements on top of a financial statement audit, for instance, needs the Yellow Book's independence and CPE rules documented alongside the AS 1215 file, not as an afterthought.

Keeping the citation attached to the conclusion

Every rule in this guide traces back to a specific paragraph: AS 1215 for what documentation has to show, AS 1105 for what counts as sufficient appropriate evidence, AU-C 210 and 230 for the nonissuer side. Getting the paragraph number right matters more now that the issuer assembly window has shrunk to 14 days, because there is less time to go back and fix a citation error after the fact.

Bizora's Audit Research traces answers back to the specific PCAOB, AICPA, FASB, or GASB paragraph behind them, with a View Steps reasoning path showing how the conclusion was reached, so the citation is something a reviewer can check directly rather than take on faith.

Before the file gets locked

The sequence that keeps a file clean is the same one that keeps it compliant:

  • Agree the engagement terms.
  • Send a PBC list tied to specific assertions, with a due date set from the documentation completion date backward.
  • Gather evidence that is both sufficient and appropriate under AS 1105.
  • Document significant findings as they happen rather than reconstructing them later.
  • Assemble the complete file inside the 14-day window if the client is an issuer, or the 60-day window if it is not.

Research your next audit documentation or evidence question in Bizora AI, with a 7-day free trial, no credit card required.

Sources

Frequently Asked Questions

What does AS 1215 require for audit documentation?

AS 1215 requires documentation detailed enough for an experienced auditor with no prior connection to the engagement to understand the procedures performed, the evidence obtained, the conclusions reached, and who performed and reviewed the work. It must demonstrate compliance with PCAOB standards and support every relevant financial statement assertion.

How long must audit workpapers be retained?

Issuer audit documentation must be retained for seven years from the report release date under AS 1215. Nonissuer audits under AICPA's AU-C 230 require a minimum of five years from the report release date instead.

What is the documentation completion date under AS 1215?

It is the deadline to assemble a complete and final set of audit documentation for retention. For issuer audits, that deadline was cut from 45 days to 14 days after the report release date, phased in by firm size between 2024 and 2025.

What is a PBC list in an audit?

A PBC list, items prepared by client, is the list of documents and schedules the client needs to provide so the audit team can test specific assertions. It is not itself a named auditing standard requirement, but a late or vague PBC list is a common root cause of the evidence and timing gaps auditing standards flag.

Does a PCAOB audit require an engagement letter?

Yes, in effect. PCAOB standards have no standalone engagement-letter standard, but AS 1301 requires the auditor to record the understanding of the engagement terms in an engagement letter and provide it to the audit committee annually, and AS 2101 lists that understanding as a preliminary engagement activity. Nonissuer audits follow AU-C 210, which requires the agreed terms to be recorded in a written engagement letter or other suitable written agreement.

What is sufficient appropriate audit evidence?

Under AS 1105, sufficiency is the quantity of evidence needed, which rises with the risk of material misstatement, and appropriateness is the quality of that evidence, meaning its relevance and reliability. Both tests have to be met; more low-quality evidence cannot substitute for evidence that is actually reliable.

Can audit documentation be changed after the report is issued?

Additions are allowed before the documentation completion date without restriction. After that date, documentation cannot be deleted or discarded, though information can still be added if the addition records the date, the preparer's name, and the reason for adding it.

Your Next Answer Is One Search Away

Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.

Start Free Trial