Workpaper
The record of what was tested, how, and what was concluded — and, structurally, the single biggest determinant of whether audit work can be automated or re-run.
A workpaper is meant to let a competent reviewer with no prior involvement understand what was done and reach the same conclusion. That is the professional standard, and most audit files meet it in spirit.
The structural question is different and rarely asked: what kind of object is it? A workpaper stored as a document is a picture of a conclusion. It can be read, filed and archived, and that is all. A workpaper stored as a structured record — control, assertion, population, procedure, exceptions, conclusion, approver, evidence links — can be queried across engagements, rolled up into coverage reporting, re-run next period without being rebuilt, and handed to an agent as a task definition.
Nearly all audit software digitised the first kind and stopped. That is why functions that bought a platform a decade ago still cannot answer “which controls addressing this risk did we test last year, and what did we find?” without someone opening files.
If you change one thing about how your team documents work, change this. It is the precondition for everything at level 3 and above of the maturity model.
Related