Guide July 30, 2026 18 min read

How to prepare for a financial audit

An audit is not a test of how tidy your ledger looks. It is a test of whether every material figure can be traced to evidence — a bank statement, a supplier invoice, a signed contract, a calculation someone can follow. This guide covers what auditors actually ask for, how to assemble it once instead of five times, how to prove your transaction listings are complete, and the specific gaps that generate most of the queries.

FlowParse
flowparse.io

Overview: an audit is an evidence exercise

Everything an auditor does reduces to a few questions asked repeatedly. Does this balance exist? Is it complete? Is it valued correctly? Is it in the right period? Does the company actually own it or owe it? Every request they make is an attempt to answer one of those about a specific number.

Preparation, therefore, is not tidying. It is assembling the answers in advance: the third-party document that proves a balance exists, the reconciliation that proves your record agrees with it, the listing that proves nothing is missing, and a short written explanation for anything that would otherwise prompt a question.

Do that and the audit is short and dull, which is the goal. Skip it and the fieldwork becomes a scavenger hunt conducted at your expense — because the cost of an audit is driven far more by how many times an auditor has to ask for something than by the complexity of your accounts.

What auditors are actually testing

AssertionThe questionWhat satisfies it
ExistenceIs this balance real?Bank confirmation, lender statement, supplier statement
CompletenessIs anything missing?Full statements, unbroken date ranges, reconciliations
AccuracyIs the amount right?Invoice, contract, calculation
Cut-offIs it in the right period?Dated documents either side of year end
Rights & obligationsDoes the company own or owe it?Contracts, title documents, agreements
PresentationIs it disclosed properly?Analysis behind each note in the accounts

Completeness is the assertion that most preparation misses, because it is the only one you cannot demonstrate by showing a document. Showing an invoice proves the invoice exists; it says nothing about the three invoices you never recorded. That is why auditors lean so hard on bank data — cash is where completeness can actually be tested.

A realistic timeline

WhenWhat to doWhy then
8–12 weeks beforeConfirm scope, dates and the request listEverything else depends on knowing what is wanted
6–8 weeks beforeCollect statements for every account and periodThird parties are slow; closed accounts slower
4–6 weeks beforeReconcile every balance-sheet accountDifferences take time to investigate
2–4 weeks beforeAssemble schedules, samples and explanationsWhile the team still remembers the year
1 week beforeDeliver the pack; walk the auditor through itFewer questions during fieldwork
During fieldworkAnswer queries from one logPrevents duplicated and lost answers

The single highest-leverage item is the second row. Bank confirmations, statements for closed accounts and lender confirmations all depend on other organisations moving, and they are the requests most likely to take three weeks. Start them first, even before your own reconciliations are finished.

The document request list, in advance

Ask for the prepared-by-client list the day the audit is scheduled. Then treat it as a project: every line gets an owner and a date, and the whole thing is delivered a week before fieldwork rather than during it.

  • Trial balance and general ledger for the period, in a usable format.
  • Bank statements for every account for the whole period — including accounts opened or closed mid-year.
  • Bank confirmations, requested early because banks are slow.
  • Reconciliations for every balance-sheet account, with the supporting document attached.
  • Aged receivables and payables listings agreeing to the ledger.
  • Sales and purchase invoice samples, plus the contracts behind material arrangements.
  • Payroll reports and the reconciliation to the ledger and to what was paid.
  • Loan agreements and lender statements, with interest and principal split.
  • Fixed-asset register with additions, disposals and depreciation calculations.
  • Stock count sheets, valuation basis and cut-off evidence around the count.
  • Post-year-end bank statements, for subsequent receipts and payments testing.

Cash and bank: the anchor of the whole audit

Cash gets tested harder than anything else because it is the one area where independent, complete third-party evidence exists. Expect the auditor to want a confirmation direct from each bank, statements covering the whole period for every account, your reconciliation for each one, and statements for a period after the year end.

Gather them for every account, not the main ones. The account opened in March and closed in September still needs its statements; so does the dormant account with three transactions; so does the personal-name card used for company costs, awkward as that conversation may be. A gap in coverage is a gap in the audit trail, and it will be found.

For accounts with no feed and no export — older cards, foreign banks, closed accounts — you may only have PDFs. Convert them into a transaction listing you can analyse and sample, keeping the PDFs themselves as the evidence: statement conversion and scanned statement handling cover the mechanics, including statements that only exist as scans.

FlowParse
flowparse.io

Proving the statement listing is complete

If you hand an auditor a transaction listing, the first thing worth being able to say is that it contains everything. This is one of the few places in accounting where completeness can be demonstrated rather than asserted.

The test is arithmetic and takes two forms. Within a statement: opening balance, plus every transaction, equals the printed closing balance. Across statements: each period's closing balance equals the next period's opening balance, with no missing months in the sequence. Together they prove the listing has neither dropped a row nor skipped a period.

FlowParse runs the first test automatically on every statement, per account, and names the rows where the arithmetic breaks — which is exactly the assertion the auditor is trying to establish. The second is a five-minute check in a spreadsheet, and it is the one that catches the missing month that would otherwise surface in fieldwork.

Be clear about what this does and does not prove. It proves your listing faithfully contains what the statement said. It does not prove the statement is authentic, and no extraction tool should claim otherwise — verifying authenticity is the auditor's job, done through direct confirmation with the bank.

FlowParse
flowparse.io

Revenue and receivables

Revenue is where the most judgement lives, so expect scrutiny of both the number and the policy behind it. Have ready: the aged receivables listing agreeing to the ledger, the revenue-recognition basis in plain words, contracts for material customers, and evidence of amounts received after the year end — subsequent receipts are the strongest evidence a debtor was real.

Two areas generate questions reliably. Deferred income, where an annual subscription billed in month one is earned across twelve — if the deferral schedule is not documented, expect it to be rebuilt in front of you. And credit notes issued after the year end, which may indicate revenue that should not have been recognised in the first place.

If invoices live as PDFs rather than in a system, build the schedule from them rather than retyping — invoice extraction and an invoice register give you a listing you can total, sort and sample against.

Costs and payables

On the cost side the auditor's main worry is completeness: liabilities that exist but are not recorded. The standard tests are supplier statement reconciliation, a search for unrecorded liabilities in the payments made after the year end, and sampling accruals back to the evidence they were based on.

Prepare accordingly. Reconcile major supplier statements to your ledger and keep the reconciliations. List the accruals with the calculation behind each — an accrual with no basis is an invitation to question everything around it. And have the post-year-end bank statements ready, because that is where an unrecorded liability shows up as a payment for something nobody accrued.

Expect a sample of purchase invoices to be requested by reference. If your documents are scattered across email, a drive and a capture tool, the retrieval is the slow part — which is an argument for a single filing convention long before the audit rather than a heroic effort during it.

FlowParse
flowparse.io

Cut-off testing, and how to pass it

Cut-off is about periods rather than amounts: was this recorded in the year it belongs to? Auditors test it by looking either side of the year end — the last invoices raised, the first of the new year, goods received notes around the date, payments clearing across the boundary.

To prepare, do the same test yourself first. Take the last two weeks of the year and the first two of the next, and check that each sale and cost sits in the period the underlying activity happened, not the period the paperwork arrived. Fix what you find and note what you fixed — an error you found and corrected is a much better story than one the auditor found.

Date handling matters here in a way people underestimate. If any part of your listing came from converted documents, make sure day-first and month-first formats were resolved rather than assumed: a misread date does not just move a transaction, it moves it across the year end, which is precisely the error cut-off testing exists to catch.

Balance-sheet support, account by account

AccountEvidence to have readyCommon query
Bank and cashStatements, confirmations, reconciliationsA missing month or account
ReceivablesAged listing, subsequent receipts, bad-debt basisOld balances with no movement
PayablesAged listing, supplier statement reconciliationsUnrecorded liabilities after year end
AccrualsCalculation and basis for eachRolled forward without being trued up
PrepaymentsInvoice and the spreading calculationAnnual costs left in one month
Fixed assetsRegister, additions, disposals, depreciationAssets sold but still on the register
LoansAgreement and lender statementInterest and principal not split
Tax accountsReturns, payments, reconciliation to the ledgerControl account not agreeing to returns
SuspenseShould not exist at year endAny balance at all

The last row is worth taking literally. A suspense balance at year end says that something happened which nobody could explain, and it invites the auditor to wonder what else was not understood. Clear it, even if clearing it means writing a note about why the amount was treated the way it was.

How sampling works, and why your data quality decides the size

Auditors do not check everything. They test a sample and extrapolate, and the size of that sample is driven by risk — how likely they think errors are, and how well your controls would catch one.

That has a direct practical consequence: the tidier and better-evidenced your records, the smaller the sample and the shorter the audit. Conversely, the first two errors found in a sample tend to expand it, because an error rate implies more errors elsewhere. This is why the completeness work matters commercially and not just principled — it reduces the testing you pay for.

Make sampling easy in practical terms. A clean, sortable transaction listing with a reference back to the source document lets an auditor select a sample and retrieve the evidence without asking you three times. That single property — retrieval speed — probably does more for audit cost than anything else in this guide.

Traceability: from a figure to the document, in one step

The recurring pattern of an audit is: here is a number, show me why. Every extra step between the number and its document costs time and creates doubt.

Build the chain deliberately. Each ledger entry should reference a document; each document should be findable by that reference; each consolidated listing should carry the source file it came from on every row. If you merged twelve months of statements from three accounts into one workbook, Smart Merge keeps a source-file reference per row precisely so that a single line can be tied back to the statement that produced it.

Keep the validation evidence too, not just the data. A record showing that each statement reconciled to its closing balance — and which ones did not, and why — is exactly the sort of contemporaneous evidence that answers "how did you know the listing was complete?" without anyone having to reconstruct the reasoning a year later.

FlowParse
flowparse.io

Digital documents, retention and what a converter is not

Most jurisdictions now accept digital records, subject to conditions about legibility, completeness and the integrity of the copy — and some impose specific requirements before paper originals can be destroyed. The rules differ enough between countries that the only safe advice is to check the ones that apply to you, and to keep both copies when in doubt.

Two boundaries are worth stating plainly, because software marketing blurs them. First, an extraction tool is not an archive: FlowParse deletes the original PDF immediately after extraction, which is good for privacy and means the retention obligation stays with you. Second, extracted data is not evidence in the way the source document is — it is a working listing that must tie to the document, and the document is what an auditor tests.

Practically, keep a structured document store organised by year, entity, account and period, with names that match the references in your ledger. It is unglamorous and it converts an audit request from a search into a lookup.

Handling queries during fieldwork

Run every question through one log with four columns: the query, who owns it, the answer, and the evidence attached. Without it, questions get answered twice, answers get lost in email, and the same item resurfaces in the final review.

Answer with evidence rather than explanation wherever possible. "That is the insurance renewal" invites a follow-up; the invoice and the prepayment calculation ends the thread. Where you genuinely do not know, say so and commit to a date — auditors are far more comfortable with an honest unknown than with a confident answer that unravels.

And when an error is found, resist the urge to minimise it. Understanding its cause and scope quickly is what keeps a single mistake from expanding the testing around it.

The gaps that cause the most queries

Seen in almost every unprepared audit

  • • A missing month of statements for one account, usually a card or a closed account.
  • • A suspense or uncategorised balance at year end that nobody can explain.
  • • Accruals carried forward for years with no calculation behind them.
  • • A processor payout treated as revenue, so gross sales and fees both vanish.
  • • Bank reconciliations forced with a balancing entry rather than resolved.
  • • Invoices that cannot be retrieved quickly because filing has no convention.
  • • Related-party and director transactions with no documentation at all.

Every one of these is cheap to fix in advance and expensive to fix during fieldwork, because during fieldwork you are paying for the auditor's time as well as your own.

Questions about your systems and automation

Auditors do not only test numbers; they ask how the numbers came to exist. If part of your bookkeeping is automated — and by 2026 most of it is — expect questions about that process, and expect them to be more searching than they were five years ago.

The questions are practical rather than technical. How do documents get into the ledger? Who reviews what the automation produced, and against what? What happens when the tool is unsure — is there a queue, and who clears it? How do you know a statement was read completely rather than partially? Can you show an example of an error the process caught?

Have answers with evidence attached. A written description of the workflow, a note of who reviews which step, and — most usefully — the validation results kept alongside the data: which statements reconciled to their closing balance, which did not and what was done about it. That last item answers the completeness question directly instead of relying on assurance.

Two boundaries are worth stating in your own documentation, because auditors will otherwise ask. Automated categorisation proposes and a human accepts; nothing posts to the ledger without review. And an extraction tool is not a system of record — the ledger is the record and the source documents are the evidence, with the extracted listing being a working aid between them. Setting that out plainly usually ends the line of questioning in one paragraph.

If you are still designing that workflow, the control points worth building in are described in bookkeeping with AI — particularly the separation between what automates and what a person approves.

If it is your first audit

A first audit carries extra work that nobody warns you about: the auditor has to establish opening balances they did not audit, which usually means additional testing of the prior year's closing position and any comparatives in the accounts.

Prepare for that specifically. Have the prior-year figures, the reconciliations that supported them and the statements covering the start of the period. If the prior year was compiled rather than audited, expect questions about the basis of the numbers rather than just the numbers.

Also budget management time honestly. A first audit takes more of your team's attention than the fee suggests — walkthroughs of your processes, questions about controls, and the inevitable discovery that something everyone assumed was documented is not.

The preparation checklist

Have ready

  • • Statements for every account, whole period
  • • A reconciliation per balance-sheet account
  • • Complete, traceable transaction listings
  • • Calculations behind every material journal
  • • Contracts for material arrangements
  • • Post-year-end statements

Fix before they arrive

  • • Any suspense balance
  • • Forced reconciliation entries
  • • Missing statement periods
  • • Accruals with no basis
  • • Unfiled or unfindable invoices
  • • Undocumented related-party items

After the audit: make the next one cheaper

The management letter is the free consultancy at the end of an audit, and it is routinely filed unread. Work through it: each point is something an experienced outsider thinks is weak, and fixing three of them meaningfully changes next year's experience.

Then write down what took longest this year while it is fresh — the account whose statements were hard to obtain, the schedule that had to be rebuilt, the invoices nobody could find. That list, acted on in the first quarter rather than the last, is what turns audit preparation from an annual crisis into a routine.

The most durable improvement is a monthly habit rather than an annual project: reconcile everything monthly, prove statement completeness at the point of extraction, and keep documents where their references say they are. An audit is much easier to prepare for when the preparation happened twelve times already — the month-end checklist is where that habit lives.

Frequently asked questions

Keep reading