Atlas
  • All-in-one
  • Solutions
  • Compare
  • Pricing
PricingGet started
  1. Atlas
  2. Guides
  3. Working Papers and Evidence: What to Keep, and for How Long
August 30, 2026·10 min read·working papers, documentation, quality, records retention

Working Papers and Evidence: What to Keep, and for How Long

The test of a working paper file is whether a competent person who was not there can reach the same conclusion from it. Most files fail that test comfortably.

Working papers exist for three audiences and firms usually design for only one. The first is the reviewer, who needs to see how the conclusion was reached. The second is the firm in a year's time, when the client asks a follow-up question and everyone who did the work has moved on. The third, rare and consequential, is whoever challenges the work: a regulator, an insurer, or an opposing party.

A file that serves only the first audience tends to be a set of notes that make sense to someone already familiar with the engagement. That is enough to pass review and not enough for either of the others.

The standard worth applying

The most useful test is the experienced-practitioner test used in several professions: could someone competent, who had no previous connection with the engagement, understand from the file what work was done, who did it, when, what was found, and what conclusion follows.

Applied honestly, that test rules out a surprising amount of what firms keep. A spreadsheet with no explanation of its inputs fails it. A note recording a conversation without saying who said it fails it. A conclusion that cites "discussion with management" without naming the person or the date fails it.

What a complete file contains

  • The engagement terms, and any changes to them, with the approvals attached.
  • The acceptance decision and its evidence, including independence and conflicts.
  • The plan as it was agreed and as it was rebaselined, so the difference is visible.
  • The evidence supporting each material conclusion, identified so that a reader can move from the conclusion to the support without asking anyone.
  • Records of significant judgments: what was decided, what alternatives were considered, and why the chosen answer was preferred. This is the part most often missing and the most valuable if the work is challenged.
  • The review record: who reviewed what, when, and what was resolved.
  • Correspondence that changed the work, which is a small subset of correspondence generally.
  • The deliverables as issued, by version, with the acceptance record.

Completion, and the date that matters

Many professions set a period after the report is issued within which the file must be assembled and closed, commonly around sixty days, after which changes are restricted or must be recorded as such. Even where no rule applies, adopting a completion date is worth it, because an open file drifts: material is added, notes are tidied, and the record stops being contemporaneous.

After completion, the rule should be that nothing is removed and anything added is marked with the date and reason it was added. A file that can be edited silently after the fact carries much less weight than one that cannot, which is an argument for keeping engagement records in a system with an audit trail rather than in a folder.

Retention: deciding rather than defaulting

Retention periods come from three places: regulatory requirements for the type of work, the limitation period for claims in the relevant jurisdiction, and the firm's own policy. Where they conflict, the longest applies, and the period should run from the completion date rather than from the engagement start.

The default of keeping everything forever is not a neutral choice. It increases the volume of material discoverable in a dispute, it increases the cost and severity of a data breach, and where the file contains personal data it is usually unlawful, because personal data may not be kept longer than the purpose requires. Deciding a period, applying it, and recording the deletion is the defensible position.

The practical failure: evidence held outside the file

The most common gap in an otherwise good file is material that lives somewhere else: the analysis in a spreadsheet on someone's drive, the decision in a message thread, the client's confirmation in an individual's mailbox. Each is real evidence and none is in the file.

The fix is not exhortation. It is that the place people do the work and the place the file is assembled should be the same place, so that recording something takes no additional step. Where that is not possible, the file should at least record where the material is and who holds it, which converts an unknown into a retrievable one.

Keep reading

  • Quality Review in Professional Services: Who Checks the Work
  • Keeping Diagrams Next to the Work They Describe
  • How to Keep a Decision Log Your Team Will Actually Use
  • Runbook vs Playbook: What Each Is For and Why Teams Confuse Them
  • Writing a Definition of Done That Stops Work From Bouncing Back
  • Best Knowledge Base Software in 2026
  • Free PDF tools
  • The all-in-one work OS

FAQ

Questions, answered.

What standard should working papers meet?
The experienced-practitioner test: a competent person with no previous connection to the engagement should be able to understand from the file what work was done, by whom, when, what was found and what conclusion follows. Notes that only make sense to someone already familiar with the engagement do not meet it.
What belongs in an engagement file?
The engagement terms and any approved changes, the acceptance decision and its evidence, the plan as agreed and as rebaselined, the evidence behind each material conclusion, a record of significant judgments including alternatives considered, the review record, correspondence that changed the work, and the issued deliverables with their acceptance records.
How long should engagement records be kept?
The longest of the applicable regulatory requirement, the limitation period for claims in the relevant jurisdiction, and the firm's own policy, running from the file completion date. Keeping everything indefinitely is not a neutral default: it increases what is discoverable in a dispute and what is exposed in a breach, and for personal data it is generally unlawful.
Can a working paper file be changed after completion?
Nothing should be removed after completion, and anything added should carry the date and the reason it was added. A file that can be edited silently after the fact carries far less weight if the work is challenged, which is a strong reason to keep engagement records in a system with an audit trail.

Ready when you are

One workspace, not ten.

Atlas replaces the stack with one platform for tasks, projects, CRM, contracts, e-signature, PDF tools, and analytics. Start free.

Get started freeSee pricing
AtlasWork, planned itself.

The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

All systems operational
  • SOC 2 II
  • ISO 27001
  • HIPAA
  • GDPR

Product

  • Overview
  • PDF tools
  • Diagram tools
  • People & HR
  • Integrations
  • Marketplace
  • Pricing

Resources

  • Guides
  • Glossary
  • Compare
  • Docs
  • API reference
  • Support
  • Changelog
  • Status

Company

  • About
  • Careers
  • Press
  • Contact

Legal & trust

  • Trust center
  • Security
  • Privacy
  • Terms
  • DPA
  • GDPR
  • SLA
  • Refunds
  • Google API data
Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
PrivacyTermsSecurityStatus