Keeping ISA (UK) documentation consistent across locations requires one file standard, one review protocol and one sign-off trail that every team follows, whether work happens in a UK office, at the client's premises or in an offshore delivery centre. ISA (UK) 230 judges the audit file as a whole, so location differences must never show up as quality differences.

Split fieldwork is now normal. Hybrid working, regional offices and offshore audit support mean a single engagement can involve four or five teams, each with its own habits, templates and review rhythms. This guide explains what the standards require and the practical controls that keep a multi-location file inspection-ready.

Key Takeaways

  • ISA (UK) 230 requires documentation that an experienced auditor with no previous connection to the audit could understand.
  • Under ISA (UK) 220 (Revised July 2021), the engagement partner remains responsible for direction, supervision and review of every team member, wherever they sit.
  • A shared referencing structure, locked templates and defined evidence standards prevent most inconsistencies.
  • Review sign-offs must show who reviewed what, when and to what extent, across time zones.
  • The final file should be assembled within 60 days of the auditor's report, with one owner controlling that process.

 

Why Does Split Fieldwork Create Documentation Risk?

Inconsistency rarely comes from poor work. It comes from teams working correctly to different conventions. One location references working papers numerically, another alphabetically. One records sample selections by invoice number, another by value. Tickmarks differ. Review notes are resolved in one team and simply deleted in another.

Individually, these differences look minor. Together, they break the audit trail. The FRC's Audit Quality Review team and ICAEW's Quality Assurance Department regularly report documentation weaknesses, including unclear evidence of review and thin records of work performed. Multi-location files are especially exposed because nobody sees the whole file until assembly.

Consider a statutory audit where the UK team handles planning and partner meetings, a site team tests inventory, and an offshore team tests revenue and payables. If each team documents to its own conventions, the reviewer spends hours reconciling formats instead of evaluating evidence, and an inspector sees three files stitched together rather than one.

What Do ISA (UK) 220 and ISQM (UK) 1 Require?

ISA (UK) 220 (Revised July 2021) places overall responsibility for managing and achieving quality on the engagement partner. That includes direction, supervision and review of the engagement team. The revised standard defines the engagement team broadly, covering individuals from network firms and service providers who perform audit procedures. In practice, the partner cannot delegate that accountability to a delivery centre manager or an outsourcing contract, even when day-to-day supervision sits elsewhere.

ISQM (UK) 1 then requires the firm to ensure that resources obtained from service providers are appropriate for its system of quality management. This applies directly to firms using Offshore Accounting Services for audit support, where preparers in another country may draft lead schedules, perform substantive testing or roll forward prior-year files.

Note the distinction from group audits. Where another firm audits a component, ISA (UK) 600 (Revised) applies. Where remote staff work directly on your engagement, they are part of your team, and your documentation standards apply to them in full.

1. Build a Single File Architecture

Every location should work inside the same audit software file, using the same index. Whether the firm uses CaseWare, Inflo or another platform, the structure must be set centrally and locked. Local teams should not create their own sections, rename folders or import outside templates.

Publish a one-page referencing guide covering section numbering, cross-reference format and file naming for supporting evidence. Make it part of onboarding for every new team member, in every location.

2. Standardise Evidence and Testing Records

ISA (UK) 230 requires the auditor to record the identifying characteristics of the specific items tested. Define exactly what that means for each test type. For a sales cut-off test, it might be invoice number, date, amount and dispatch note reference. Build those fields into the template so every team captures the same data.

Agree one tickmark legend for the whole engagement and embed it in the file. Set a rule for client documents too: evidence is attached to the working paper, never left in email threads or local drives.

 

3. Control Review and Sign-Off Across Time Zones

The file must show who performed each procedure, who reviewed it, the dates and the extent of review. Time zones create a specific risk. Work completed overnight offshore can be signed off by a UK reviewer the next morning without real scrutiny, simply to clear the queue.

Set review tiers. A senior in the same location performs first-level review, then a UK manager reviews higher-risk areas and significant judgements. Require review notes to be answered in the file, with a clear resolution, before sign-off.

Record handoffs explicitly. A short handover note at the end of each offshore shift, filed in the engagement, shows open queries, work in progress and anything waiting on the client.

4. Manage Version Control and File Assembly

ISA (UK) 230 expects the final audit file to be assembled ordinarily within 60 days of the auditor's report. Appoint one assembly owner for multi-location engagements. After assembly, any change must be documented with the reason, the person making it and the date. Assign section ownership in the planning memo so every reviewer knows who holds the pen.

Restrict editing rights by section and by location. When two locations can edit the same working paper at once, conflicting versions follow.

5. Protect Access and Confidentiality in Every Location

ISQM (UK) 1 requires policies that maintain the confidentiality, safe custody, integrity and accessibility of engagement documentation. Give each location role-based access, use firm-managed devices and block local downloads of client data. Where offshore staff access UK client personal data, the firm must also meet UK GDPR transfer rules, usually through an IDTA or UK Addendum supported by a transfer risk assessment.

Best Practices for Multi-Location Audit Documentation

  • Hold a documentation kick-off call with every location before fieldwork starts.
  • Review a sample of offshore working papers weekly during the first engagements.
  • Share a completed example working paper for each key area as the benchmark.
  • Run a mid-fieldwork consistency check, not only a final one.
  • Use the same methodology version across all teams.
  • Appoint a documentation lead in each location who owns template compliance.
  • Track review notes centrally so open points stay visible to the engagement partner.
  • Train remote staff on ISA (UK) requirements, including UK supplementary paragraphs that differ from the international ISAs.

Common Mistakes to Avoid

  • Letting offshore teams use their own templates "just for this client".
  • Treating remote preparers as outside the engagement team.
  • Signing off reviews without written evidence of what was checked.
  • Leaving supporting evidence in email threads.
  • Allowing sign-offs to be backdated or batch-applied at the end of fieldwork.
  • Starting file assembly when the 60-day window is already under pressure.

Conclusion

Multi-location audit delivery is here to stay, and regulators will judge the file, not the organisation chart. Firms that set one file architecture, one evidence standard and one review protocol can use distributed teams without weakening quality. Providers such as MYCPE ONE, which supports UK firms with offshore audit and accounting teams, work best inside that structure, trained on the firm's templates and reviewed under the same ISA (UK) standards as the UK team. Consistency is a design choice, and it is one every audit firm can make.

Frequently Asked Questions

What does ISA (UK) 230 require for audit documentation?

It requires documentation that allows an experienced auditor, with no previous connection to the audit, to understand the procedures performed, the evidence obtained, and the significant matters, conclusions and judgements reached.

Are offshore audit staff part of the engagement team?

Generally yes. Under ISA (UK) 220 (Revised July 2021), individuals from service providers who perform audit procedures on the engagement are part of the engagement team and fall under the engagement partner's supervision.

How long do auditors have to assemble the final audit file?

ISA (UK) 230 guidance sets an assembly period that is ordinarily no more than 60 days after the date of the auditor's report.

Can review notes be deleted from the audit file?

Firms may remove superseded review notes, but the file must still evidence who reviewed the work, when and to what extent. Many firms retain resolved notes to strengthen the trail.

Does ISA (UK) 600 apply when fieldwork is split across offices?

Not usually. ISA (UK) 600 (Revised) applies to group audits involving components. Work split between offices or delivery centres on one engagement falls under ISA (UK) 220 and ISA (UK) 230.