Organising audit evidence - folder structures and naming conventions that work
- The SOC 2

- Aug 12
- 9 min read

Audit evidence documentation rarely breaks down because auditors do their job poorly. It breaks down because nobody can find anything. A file sits on someone's desktop as scan001.pdf, the confirmation email lingers in the inbox of a colleague who left six months ago, and the screenshot of a source report disappears into a shared drive nobody has opened since the last engagement. Then review season arrives, and the hunt begins.
Folder structures and naming conventions solve this problem at its root. The point is not tidiness for its own sake. The point is whether your evidence speaks for itself or forces you to trace its history across five network drives before you can explain a single conclusion.
Why documentation structure underpins every audit
IIA Standard 2330 requires audit evidence to be sufficient, reliable, relevant, and useful. Without organised documentation, proving that standard becomes nearly impossible, no matter how diligently the work was performed.
The cost of disorganisation is measurable. The average office worker loses 1.8 hours every day searching for information, according to McKinsey research. That number climbs higher for audit teams juggling hundreds of control files, email threads, and screenshots from client systems. Every hour spent searching is an hour lost to the audit itself.
The consequences run deeper than wasted time. The PCAOB has already issued multi-million dollar fines for inadequate documentation. Research from the American Accounting Association found that documentation aligned with the "experienced auditor" concept is 40% more likely to pass peer review. Similarly, the Journal of Accountancy reported that audit files built around focused, relevant evidence clear quality reviews 30% more often than those weighed down with excessive material.
One statistic stands out above the rest: audits with contemporaneous documentation show 50% fewer significant deficiencies, based on PCAOB data. When you record evidence matters far more than how you format it.
The experienced auditor test
Before diving into structure, one benchmark deserves attention. Known as the experienced auditor concept, it works as a litmus test for any documentation you produce.
The question is straightforward. Could a competent auditor who has never touched this engagement understand your procedures from the documentation alone, repeat them, and arrive at the same conclusions? If yes, your structure holds up. If not, something needs attention.
This test keeps discipline in place. It guards against two opposing failure modes: overloading files with every conceivable document "just in case," and leaving documentation so sparse that it relies on the assumption that "everyone on the team already knows." Both derail an audit, and both become visible the moment an outsider opens the file.
Seven practices that keep evidence organised
Professional practice ultimately boils down to seven principles, and each one has direct implications for how you structure files and folders.
First, document so that an experienced auditor with no prior context can follow your work. Second, adopt a standardised documentation structure, including uniform formats, conventions, and hierarchy. Third, use technology to automate routine tasks and centralise your repository. Fourth, document contemporaneously, capturing evidence as the work happens rather than days later. Fifth, stay focused on relevance and sufficiency, because not every file belongs in the record, but every conclusion must have supporting evidence behind it. Sixth, build a multi-level review process into the workflow. Seventh, protect confidentiality through access controls and encryption.
These principles sound obvious on paper. In practice, they rise or fall on the quality of your file structure, which is where the real work begins.
A folder structure that holds up in practice
The most resilient hierarchy for external audit and compliance work follows a simple pattern: client, fiscal year, document category. Three levels, at most four. Any deeper and navigation becomes painful, while search quickly loses its reliability.
Here is how it typically looks for an accounting firm:
Client name
Permanent (contracts, authorisations, registration documents)
2026
Tax Returns
Financial Statements
Working Papers
Source Documents
Correspondence
2025
Correspondence (all years)
The Permanent folder plays a central role. It holds documents that do not belong to any single year, such as engagement letters, powers of attorney, and registry extracts. Without it, someone ends up copying or losing these files every twelve months.
Law firms adapt the same pattern by replacing the fiscal year with a matter number:
Client name
Permanent (engagement letters, conflict checks)
Matter 001 (case description)
Correspondence
Pleadings and Court Documents
Discovery
Research and Memos
Billing
Engineering and construction firms take a different route, using numbered prefixes that force a consistent order regardless of how the operating system sorts files:
Project name (number)
01_Contracts and Agreements
02_Drawings and Plans
03_Specifications
04_Permits and Approvals
05_Correspondence
06_RFIs and Submittals
07_Progress Reports
08_Invoicing
09_Handover and Closeout
The industry varies, but the underlying rule does not. Your structure should mirror the way work actually flows, not the place where files happen to land.
What belongs in a separate folder, and why it matters
Even within a well-designed structure, not everything belongs in the main files. A handful of categories demand their own location with restricted access, and mixing them with general records creates legal exposure.
Medical records require a dedicated folder under the ADA and HIPAA. I-9 immigration forms sit separately as well, since the Department of Homeland Security can request them with just 3 days' notice, and you want to produce those forms without exposing the rest of your files. Investigation records, including complaints and internal inquiries, never belong in standard personnel files. Compensation data remains visible only to HR and the direct management chain.
For audit purposes, this all comes down to one design choice: tiered access. Leadership holds full permissions. Coordinators reach the non-restricted files they need. Managers see read-only views of their direct reports. IT administers the system but never opens the contents.
A naming convention that survives staff turnover
Even the best folder structure falls apart without consistent naming. A file called smith_review.pdf undermines everything else you have built.
The pattern that holds up in practice follows a simple template:
[DocumentType][LastNameFirstName]_[YYYY-MM-DD].[extension]
A few examples:
OfferLetter_Martinez_Elena_2024-03-15.pdf
PerformanceReview_Chen_Michael_2024-06-30.pdf
I9_Nguyen_David_2023-11-01.pdf
TerminationLetter_Williams_Sarah_2024-09-22.pdf
Why this particular order? Leading with the document type groups every engagement letter, every performance review, and every protocol in one place. The last name lets you search by person. The YYYY-MM-DD format sorts chronologically by default, sparing you the ambiguity of wondering whether 03/04 means March or April.
The real challenge with naming conventions is not designing one. It is keeping it alive under pressure. Someone in a hurry saves a file the wrong way, someone else swaps underscores for hyphens, and another colleague skips the date entirely. Within a year, the system looks much like it did before implementation. The fix comes in two parts: a written operating standard that everyone can reference, combined with automated renaming wherever possible. Modern AI tools can now identify document types directly from content, which removes human inconsistency from the equation.
The case for documenting in real time
This is where theory and practice collide most directly. The principle is simple: capture evidence the moment you perform the procedure, not a week later. The reasoning is measurable, since contemporaneous documentation cuts significant deficiencies in half.
Memory fade is the auditor's quiet adversary. Three weeks after the fact, nobody remembers why a particular sample was selected, what context surrounded the phone call with the controller, or exactly what appeared on the client's system screen. A screenshot taken in the moment carries far more weight in the record than a note reconstructed from memory.
Documenting information produced by the entity
Information Produced by the Entity, or IPE, refers to data and reports generated by the audited organisation's own systems and used as audit evidence. You cannot take this material at face value, which means verification is part of the job.
Documenting IPE follows a consistent process:
Clearly identify what counts as IPE for each control.
Obtain evidence of accuracy and completeness by understanding where the data originates and how it is produced.
Document the source, typically through screenshots of report generation and records of query parameters.
Document the logic behind the data, including filters, date ranges, and system algorithms.
The PCAOB has tightened its expectations in this area, particularly for SOX frameworks and SOC reports. In practical terms, your folder structure needs a dedicated subcategory within Working Papers for IPE, with its own subfolders for reports, generation screenshots, and parameter documentation.
Multi-level review: who checks whose work
Documentation that has never been reviewed is only half complete, which is why a structured review workflow matters just as much as the initial recording. The standard process moves through four stages.
Self-review comes first, with the auditor who performed the procedure checking their own work for accuracy and completeness. Peer review follows, where a colleague on the team brings fresh eyes and typically catches the minor oversights everyone misses. Manager review confirms alignment with engagement objectives and professional standards. Partner or director review delivers the final approval on significant engagements and keeps the work consistent with firm policy.
Every stage needs to leave a visible trace. Reviewer comments, author responses, and any remediation actions should all land in the audit file. When firms standardise this review process, they typically save up to 30% of the time the workflow used to consume.
Retention and disposal without legal exposure
Retention periods depend on the regulator and the jurisdiction. For audits of US public companies, the PCAOB requires 7 years from the report release date, which gives you a useful reference point.
Retention rules for US employee records break down as follows:
Document category | Minimum retention |
|---|---|
Personnel records (EEOC) | 1 year from personnel action or termination |
Payroll records (FLSA) | 3 years federally, up to 6 years in some states |
Time cards (FLSA) | 2 years |
Injury and illness records (OSHA) | 5 years |
Medical records (OSHA) | Length of employment plus 30 years |
Exposure records (OSHA) | 30 years |
Benefits plan documents (ERISA) | 6 years from filing date |
I-9 forms | 3 years from hire or 1 year from termination, whichever is later |
State-level rules often push these numbers higher. California requires 4 years for personnel records, New York 6 years for payroll records, Texas 4 years, and Illinois 5 years. When federal and state rules conflict, the stricter standard applies.
In practice, 7 years works well as a default retention period. It covers the statute of limitations for most employment matters and aligns with the IRS audit window for payroll-related documents.
The cleanup process itself should run on a quarterly cycle. Review folders by year, compare them against your retention schedule, and move expired files to a Pending Deletion folder for 30 days as a buffer against last-minute needs. Permanent deletion should always be logged, with a clear record of who deleted what, when, and under which policy. Without that log, defending against any future claim of destroyed evidence becomes almost impossible.
Digital audit trail and chain of custody
Compliance tools capture every action automatically, producing an immutable log of who opened a file, who changed it, when, and in what context. This is the digital equivalent of the chain of custody familiar from forensic work.
In practical terms, any platform handling audit evidence should meet four requirements: file versioning, granular access controls at the folder and document level, encryption both in transit and at rest, and a complete operational log that can be exported to regulator-ready reports.
Teams working in this kind of environment consistently report a 25% increase in productivity and a 35% reduction in documentation errors.
Ten practical rules for your team
With the structural pieces in place, a few operating rules help keep the system running day to day.
Start with one template for all clients. Every new engagement inherits the same structure from day one. Deleting an empty folder is far easier than adding a missing one across dozens of cases months later.
Keep the hierarchy to three or four levels. Deeper structures become harder to navigate, and search loses its edge.
Create a Permanent folder for every client. Documents that do not belong to a specific fiscal year need their own home.
Decide once where emails live, and stick with it. Under the client or inside the year, either works, but the team has to follow one rule.
Add a client portal folder. Delivered documents should not mix with internal working files.
Plan the archive from the start. Completed years can leave the active view without losing any data.
Automate folder creation. Adding a new client in your practice management system should trigger the full folder structure automatically.
Control access rather than moving files. Every file relocation introduces risk. Toggling visibility through permissions is far safer.
Consolidate before you organise. One file server, one SharePoint site, one shared drive, plus scattered email attachments. Get everything into a single workspace first, then structure it.
Train the team and document the standard. The best folder structure is the one everyone actually uses, not the one its designer can explain. A short onboarding reference solves the consistency problem for years.
What well-organised documentation delivers
An audit that defends itself in front of a regulator. A peer review that does not require rebuilding context from memory. A team that locates any file in seconds rather than twenty minutes. Retention that runs without manual hunts for expired records. A chain of custody that holds up under procedural questioning.
Folder structures and naming conventions are not a matter of aesthetics. They are the foundation on which the credibility of the entire audit rests. Build them properly once, and they work in the background for years.
Sources:



Comments