Appearance
Audit Fieldwork
Fieldwork is where an engagement produces evidence. Two record types carry it: procedures and workpapers.
Audit procedures
A procedure is a single planned test: what will be examined, how, against what, and what the result was.
| Field | Purpose |
|---|---|
| Ordinal | Its position in the programme |
| Title and objective | What the test is for |
| Scope area | The area it addresses |
| Procedure text | What the auditor will do |
| Test steps | The individual steps |
| Sampling methodology and sample size | How the population was sampled |
| Expected evidence | What the auditor expects to see |
| Linked objects | Control, requirement, obligation, risk, asset, third-party engagement |
| Assigned auditor | Who performs it |
| Test result | The outcome |
| Test conclusion | What the auditor concluded |
| Exceptions summary | What was found |
| Tested by and at | The execution record |
| Review status, reviewer and notes | The review record |
Test results
| Result | Meaning |
|---|---|
not_tested | Not yet performed |
satisfactory | The control operated as expected |
exceptions_noted | Operated, with exceptions identified |
unsatisfactory | Did not operate adequately |
not_applicable | The procedure did not apply |
exceptions_noted is not a soft unsatisfactory
A control that operated on 48 of 50 sampled items with two documented exceptions is a different finding from one that did not operate. Keeping the two results distinct is what lets a reader tell a control with a tolerable error rate from a control that failed.
Procedure review states
| State | Meaning |
|---|---|
pending | Awaiting review |
in_review | Under review |
reviewed | Reviewed and accepted |
returned | Returned to the auditor with comments |
Workpapers
A workpaper documents the work performed and supports the conclusion.
| Field | Purpose |
|---|---|
| Title and type | What it is |
| Description and notes | The auditor's record of work |
| Linked evidence | Evidence records from the Evidence Register |
| Linked assertions | Evidence assertions relied on |
| Prepared by and at | Preparation record |
| Reviewed by and at | Review record |
| Review status | draft, in_review or reviewed |
| Locked | Whether it is locked against further change |
Workpapers link to the same canonical evidence the rest of the platform uses. An auditor examining MFA enforcement relies on the same assertions the continuous assurance layer evaluates — not a separate copy uploaded into an audit silo.
Maker-checker on fieldwork
Procedures and workpapers are prepared by one auditor and reviewed by another. Review is independent: the preparer cannot review their own work.
Requires audit.engagement_execute to perform, and audit.engagement_review to review.
AI assistance in fieldwork
AI can generate advisory suggestions for audit procedures, workpaper summaries and draft findings.
| AI does | AI does not |
|---|---|
| Draft candidate procedures for an objective | Determine a test result |
| Summarise workpaper content | Conclude on a control |
| Draft finding wording | Issue a finding |
| Record its provenance | Sign off anything |
All AI output is advisory and requires explicit human approval. Requires audit.ai_assist and the AI entitlement.
Permissions
| Action | Permission |
|---|---|
| View procedures and workpapers | audit.engagement_read |
| Execute procedures and record results | audit.engagement_execute |
| Review procedures and workpapers | audit.engagement_review |
| Generate AI advisory suggestions | audit.ai_assist |
Example
Engagement AUD-2026-0003, procedure 4 — Privileged access recertification.
| Field | Value |
|---|---|
| Objective | Determine whether privileged access is recertified at the required quarterly frequency across in-scope systems |
| Linked control | CTL-2026-0067 Access Review |
| Linked requirement | A.5.18 |
| Sampling | Judgemental, all 38 in-scope systems |
| Expected evidence | Completed recertification record per system per quarter |
| Assigned auditor | IT Auditor |
Test steps:
- Obtain the recertification records for all four quarters.
- Confirm each in-scope system has a record for each quarter.
- For a sample of 10, confirm the reviewer was independent of the access being reviewed.
- For any exception identified in a recertification, confirm the access was actually removed.
Result: exceptions_noted.
Conclusion: "Recertification was performed for 38 of 38 systems in Q1 and Q2. In Q3, 5 systems were not recertified within the quarter; recertification was completed 22 days late. For the sample of 10, reviewer independence was confirmed in all cases. Of 14 exceptions identified across the year, 12 were removed within 5 working days; 2 remained active at the time of testing."
Workpaper: links the recertification records held in the Evidence Register and the assertions recorded from them.
Finding raised: FND-2026-0119, on the two exceptions that remained active.
Note that the procedure result is exceptions_noted rather than unsatisfactory. The control operated; it operated imperfectly. That distinction is preserved into the finding and into the opinion.
Troubleshooting
"I cannot review a procedure I executed." Segregation of duties. An independent reviewer is required.
"A workpaper is locked." Locked workpapers are protected against further change, typically after review or finalisation.
"AI assistance is unavailable." Requires audit.ai_assist and the AI entitlement.