An audit checklist means something different depending on who holds it. 

For an external auditor, it’s an engagement execution framework, a structured way to move from client acceptance through workpaper sign-off without losing documentation integrity along the way. 

For an internal audit function, it’s a risk-based program structure, a way to turn an approved annual plan into fieldwork that’s consistent, defensible, and review-ready.

Both contexts share the same underlying architecture: planning, execution, documentation, and reporting. But the standards they answer to, the risks they address, and the documentation they produce are meaningfully different.

This guide covers both. Each phase includes the specific procedures practitioners work from, grounded in the standards that govern them: AU-C, PCAOB, and the 2025 IIA Global Internal Audit Standards. 

What Is An Audit Checklist?

An audit checklist is a structured reference that sequences and documents the procedures an auditor performs across every phase of an engagement. Each item ties back to a documented risk, a standard requirement, or an evidence objective. 

It’s also worth separating a checklist from an audit program. The audit program defines scope and overall strategy: which risks are in scope, what approach the team will take, and why. The checklist operationalizes that strategy step by step. One informs the other, but they’re not the same document.

External vs. Internal Audit Checklists At A Glance

External audit engagement Internal audit
Driven by GAAS / PCAOB standards, engagement letter Approved annual plan, IIA Standards
Starts with Client acceptance and independence checks Audit universe and risk-based plan
Core phases Planning, controls evaluation, substantive testing, completion Planning memo, fieldwork, reporting, follow-up
Key output Audit opinion, workpaper file Findings report, remediation tracking
Governing body Engagement partner, peer review Audit committee, QAIP

 

The External Audit Engagement Checklist

Pre-engagement and acceptance

Before fieldwork starts, the team works through the decisions that determine whether the engagement should proceed and on what terms.

  • Independence and conflicts. Every team member needs a documented independence check. PCAOB-registered firms confirm compliance with Rule 3520 and review any relationships that could impair independence.
  • Acceptance and continuance. New engagements get a risk assessment covering business model, management integrity, industry risk, and firm capacity. Continuing engagements get an annual continuance review.
  • Prior-year file review. The prior file carries forward judgments, open items, and adjustments that affect current-year scoping. Rolling it forward without review is one of the most common shortcuts that comes back to bite a team.
  • Engagement letter. Sets scope, fees, client responsibilities, and the applicable standards (GAAS, PCAOB, or IAASB).
  • Staffing plan. Experience levels should match engagement risk. Complex estimates and related-party activity need senior judgment in the field, not just at review.

Engagement planning

Planning is where audit quality is largely decided. A compressed planning phase almost always shows up in fieldwork later.

  • Understand the entity. According to AU-C 315 (PCAOB equivalent: AS 2110), build a working understanding of the business model, industry dynamics, transaction flows, IT environment, and related-party relationships.
  • Confirm the reporting framework. US GAAP, IFRS, or a sector-specific framework. This drives materiality and assertion risk.
  • Set materiality. Overall materiality, performance materiality, and the clearly trivial threshold, each with a documented basis.
  • Identify significant accounts and disclosures. This is the output that determines where the team spends its time.
  • Assess risk by assertion. Completeness, accuracy, existence, cutoff, valuation, and rights and obligations for each significant account.
  • Document fraud risk factors. AU-C 240 (ISA 240 internationally) requires specific inquiries, and the journal entry testing approach flows directly from this assessment.
  • Write the audit strategy memo. The planning capstone. A reviewer should be able to read it and understand the engagement approach without reconstructing it.

Internal controls evaluation

Controls work varies by engagement type. For private companies under GAAS, controls assessment shapes the nature and extent of substantive testing. For SEC registrants under PCAOB AS 2201, integrated audit procedures are mandatory.

  • Walkthroughs. For each significant process (revenue, procurement, payroll, financial close), trace a transaction from origination to financial reporting and identify the controls along the way. A narrative description isn’t enough.
  • Design and operating effectiveness. Does the control, as designed, address the risk? And has it actually operated that way throughout the period?
  • Deficiency evaluation. Classify exceptions as a control deficiency, a significant deficiency, or a material weakness, each with a documented basis. The classification drives everything that follows.
  • Reliance on internal audit. If the client has an internal audit function, assess under AU-C 610 whether its work can reduce external procedures.

Substantive procedures

Substantive procedures are how auditors get direct evidence about account balances, transaction classes, and disclosures. 

  • Analytical procedures. Develop an independent expectation, compare it to the recorded amount, and investigate variances over the threshold.
  • Tests of details. Match the procedure to the assertion: vouching for existence, tracing for completeness, confirmation for existence and rights, recalculation for accuracy.
  • Sampling. Document the sample size basis, selection method, and how results get extrapolated to the population.
  • Revenue testing. Under ASC 606 (IFRS 15 internationally), focus on the five-step recognition model, with extra scrutiny on variable consideration and contract modifications.
  • Liabilities and expenses. Completeness is the primary risk here. The search for unrecorded liabilities looks at subsequent disbursements and open purchase orders.
  • Related-party transactions. Confirm management properly authorized, executed at arm’s length where required, and disclosed each material related-party transaction.

Completion and reporting

  • Summary of audit differences. Track proposed and passed adjustments, and evaluate the uncorrected total against materiality.
  • Subsequent events. Procedures run through the report date under AU-C 560.
  • Going concern. When indicators exist, AU-C 570 requires documented procedures, a conclusion, and an assessment of disclosure adequacy.
  • Management representations letter. Required before report issuance. Not a substitute for audit evidence, but a required part of the file.
  • Communication to governance. AU-C 260 requires communication of significant matters, including any material weaknesses or significant deficiencies.
  • Review and sign-off. Engagement partner review, plus a concurring partner review where required.
  • Archiving. File assembly within 60 days (PCAOB) or 45 days (AICPA) of the report date, retained for seven years (PCAOB) or five years (AICPA).

The Internal Audit Checklist

Internal audit runs on a different set of standards. The 2025 IIA Global Internal Audit Standards, effective 9 January 2025, are the biggest update to the framework in decades: 52 mandatory requirements across 15 guiding principles and five domains, with new topical requirements for AI, cybersecurity, and third-party risk.

Annual planning

  • Audit universe. Inventory all auditable entities, processes, and systems, updated at least annually.
  • Risk assessment and prioritization. Score each unit by inherent risk and control effectiveness to build the plan.
  • Audit committee approval. Standard 9.1 requires documented board or committee approval. This is a governance requirement, not a formality.
  • Resource and co-sourcing planning. Staffing, specialized expertise (IT, forensic, actuarial), and co-sourcing arrangements.

Engagement execution

  • Planning memo. Scope, objectives, the specific risks the team is addressing, timing, and team composition.
  • Walkthrough and process mapping. Done before fieldwork starts. Skip it under time pressure, and it shows in the quality of the conclusions.
  • Control testing. Design effectiveness first, then operating effectiveness, documented at the test-step level.
  • Fieldwork documentation. The IIA’s Five C’s structure (criteria, condition, cause, consequence, corrective action) keeps findings consistent.
  • Real-time issue logging. Log findings as they’re identified. Reconstructing them at report-writing time introduces risk, and reviewers can usually tell.

Reporting and follow-up

  • Draft report. Findings with risk ratings (critical, high, medium, low), plus management responses and remediation commitments.
  • Issuance and distribution. Per the function’s policy. Audit committee distribution is standard for publicly traded companies.
  • Open issue tracking. A defined follow-up schedule, with escalation for items that age past the deadline.
  • Audit committee reporting. Periodic summaries of completed work, open findings, and emerging risk.

Quality assurance

Functions that conform to IIA Standards maintain a quality assurance and improvement program (QAIP), including a formal external quality assessment at least every five years. That assessment is what lets a CAE declare conformance with the Standards.

Where Audit Checklists Break Down

Most quality issues trace back to the same handful of problems, the ones that show up in PCAOB inspection reports and IIA quality assessments year after year.

The file says “done.” The evidence says otherwise. A procedure gets signed off, but the workpaper that supports it never makes it into the file. This is consistently the most frequent PCAOB inspection finding, and it’s rarely intentional. It’s what happens when documentation gets deferred.

Last year’s checklist, this year’s engagement. A rolled-forward checklist that nobody updated can miss a new system, a changed control environment, or a new standard that affects scope. A real review of the existing checklist, not a brand-new one each year, closes that gap.

The checklist replaces the thinking instead of supporting it. When teams treat completion as the goal, inspection risk goes up. A checklist should scaffold judgment, not stand in for it.

Evidence gathered now, documented later. Fieldwork notes that wait until file wrap-up to become workpapers introduce accuracy and completeness risk. Contemporaneous documentation is a standard requirement, the kind inspectors check first.

From Checklist to Confidence

The quality of an audit checklist comes down to two things: the structure behind each phase, and the documentation trail that supports every step.

The first is largely a matter of discipline: reviewing the checklist at the start of each engagement, matching procedures to the right standards, and assigning the right level of judgment to each phase. The second is where most teams feel the strain. 

Defensible conclusions depend on traceability, on each procedure connecting back to the evidence that supports it, in a way that holds up under review. Manual, spreadsheet-driven workflows are where that connection most often breaks.

Trullion’s platform connects audit procedures to source documents, automates extraction from document-heavy workstreams, and keeps every step traceable from planning through conclusion.

For firms and internal audit functions working together on the same engagement, that connection extends further. Trullion’s connected audit platform helps bridge the gap between internal audit teams and external audit firms. Connectivity with other audit tools and visibility throughout engagements helps keep auditors on both sides aligned, working from the same evidence instead of reconciling separate files after the fact.

See how it works

FAQs

What’s the difference between an audit checklist and an audit program?

The audit program defines scope, strategy, and approach: which risks are in scope and why. The checklist operationalizes that program step by step, documenting each procedure, the evidence obtained, and the conclusion reached.

What should be on an internal audit checklist?

The full engagement lifecycle: planning (scope, objectives, risk identification, process mapping), fieldwork (control testing, Five C’s documentation, real-time issue logging), and reporting (findings with risk ratings, management responses, remediation tracking). Annual activities like audit universe maintenance and committee plan approval round it out under the 2025 IIA Standards.

What’s on an external audit engagement checklist?

Pre-engagement and acceptance (independence, engagement letter, continuance), planning (entity understanding, risk assessment, materiality, fraud risk, strategy), controls evaluation (walkthroughs, effectiveness testing, deficiency classification), substantive procedures (analytical procedures, tests of details, revenue testing), and completion (summary of differences, subsequent events, going concern, representations, archiving).

How often should an audit checklist be updated?

At the start of every engagement, not just the date field. For continuing engagements, that means reviewing the prior-year file for open items, new risks, control environment changes, and any standard changes affecting scope.

What are the most common audit checklist failures?

Evidence gaps between sign-off and workpapers, rolled-forward checklists that miss current-year changes, over-reliance on completion as a proxy for quality, and documentation recorded after the fact instead of during fieldwork.

Trullion helps audit and accounting teams move through each engagement phase with traceable, workpaper-ready outputs.

See how it works