Working Papers and Evidence: What to Keep, and for How Long
The test of a working paper file is whether a competent person who was not there can reach the same conclusion from it. Most files fail that test comfortably.
Working papers exist for three audiences and firms usually design for only one. The first is the reviewer, who needs to see how the conclusion was reached. The second is the firm in a year's time, when the client asks a follow-up question and everyone who did the work has moved on. The third, rare and consequential, is whoever challenges the work: a regulator, an insurer, or an opposing party.
A file that serves only the first audience tends to be a set of notes that make sense to someone already familiar with the engagement. That is enough to pass review and not enough for either of the others.
The standard worth applying
The most useful test is the experienced-practitioner test used in several professions: could someone competent, who had no previous connection with the engagement, understand from the file what work was done, who did it, when, what was found, and what conclusion follows.
Applied honestly, that test rules out a surprising amount of what firms keep. A spreadsheet with no explanation of its inputs fails it. A note recording a conversation without saying who said it fails it. A conclusion that cites "discussion with management" without naming the person or the date fails it.
What a complete file contains
- The engagement terms, and any changes to them, with the approvals attached.
- The acceptance decision and its evidence, including independence and conflicts.
- The plan as it was agreed and as it was rebaselined, so the difference is visible.
- The evidence supporting each material conclusion, identified so that a reader can move from the conclusion to the support without asking anyone.
- Records of significant judgments: what was decided, what alternatives were considered, and why the chosen answer was preferred. This is the part most often missing and the most valuable if the work is challenged.
- The review record: who reviewed what, when, and what was resolved.
- Correspondence that changed the work, which is a small subset of correspondence generally.
- The deliverables as issued, by version, with the acceptance record.
Completion, and the date that matters
Many professions set a period after the report is issued within which the file must be assembled and closed, commonly around sixty days, after which changes are restricted or must be recorded as such. Even where no rule applies, adopting a completion date is worth it, because an open file drifts: material is added, notes are tidied, and the record stops being contemporaneous.
After completion, the rule should be that nothing is removed and anything added is marked with the date and reason it was added. A file that can be edited silently after the fact carries much less weight than one that cannot, which is an argument for keeping engagement records in a system with an audit trail rather than in a folder.
Retention: deciding rather than defaulting
Retention periods come from three places: regulatory requirements for the type of work, the limitation period for claims in the relevant jurisdiction, and the firm's own policy. Where they conflict, the longest applies, and the period should run from the completion date rather than from the engagement start.
The default of keeping everything forever is not a neutral choice. It increases the volume of material discoverable in a dispute, it increases the cost and severity of a data breach, and where the file contains personal data it is usually unlawful, because personal data may not be kept longer than the purpose requires. Deciding a period, applying it, and recording the deletion is the defensible position.
The practical failure: evidence held outside the file
The most common gap in an otherwise good file is material that lives somewhere else: the analysis in a spreadsheet on someone's drive, the decision in a message thread, the client's confirmation in an individual's mailbox. Each is real evidence and none is in the file.
The fix is not exhortation. It is that the place people do the work and the place the file is assembled should be the same place, so that recording something takes no additional step. Where that is not possible, the file should at least record where the material is and who holds it, which converts an unknown into a retrievable one.