← Back to blog

Audit Evidence Examples for Auditors: 8 Types, Standards, Fast Checks

October 10, 2026
Audit Evidence Examples for Auditors: 8 Types, Standards, Fast Checks

Audit evidence is the information auditors gather and evaluate to support the conclusions behind their opinion, and it spans eight recognised categories: inspection, documentation, confirmation, observation, inquiry, analytical procedures, recalculation and reperformance. PCAOB AS 1105 requires that this evidence be both sufficient in quantity and appropriate in relevance and reliability before an auditor can rely on it.


TL;DR:

  • Auditors generally give more weight to independent evidence, such as direct bank confirmations, than internally generated reports or verbal assurances, regardless of document volume.
  • Auditors must validate system reports by testing accuracy and completeness or the IT controls behind them, then inspect source data and transformation mappings.
  • A confirmation that receives no reply does not count as agreement; auditors should send another request or examine subsequent cash receipts instead.
  • Under deadline pressure, teams should prioritize high risk assertions, preserve original system extracts, timestamp and sign off evidence, and link each item to its assertion.
  • Observation proves only what happened at the moment observed, while management inquiry is weak alone; auditors should corroborate both with records or independent testing.

Keystoneconsulting
Strengthen Governance and Audit Readiness
Keystone helps teams improve governance and operational efficiency with mapped workflows and AI-powered reporting tools.
Explore Keystone Consulting

Table of Contents

Types of audit evidence with examples for each category

Every piece of audit evidence falls into one of a handful of recognised categories, and knowing which bucket an item belongs to help you judge how persuasive it actually is. PCAOB auditing standards treat these categories as the building blocks of an audit file, and each one carries its own strengths and blind spots.

Inspection, or physical evidence, involves examining a tangible asset or record directly. A warehouse inventory count, a fixed asset tag matched to a register, or a signed physical inspection sheet all fall here. This category is strong for confirming existence but weaker for confirming valuation or ownership, since seeing a machine on the factory floor tells you nothing about who legally owns it.

Auditor inspecting a tagged plant room pump

Documentary evidence is the backbone of most audit files: invoices, signed contracts, purchase orders, bank statements and payroll registers. Its reliability depends heavily on where the document originated. A bank statement obtained directly from the bank carries more weight than the same statement printed from an internal accounting system, because the latter has passed through the client's own hands.

Confirmation means writing directly to a third party and asking them to verify a balance or fact. Bank confirmations, accounts receivable confirmations sent to customers, and legal confirmations sent to outside counsel are the classic examples. Confirmations are prized because they come from an independent source outside the client's control, which PCAOB guidance and general audit practice treat as inherently more reliable than internally produced records.

Observation captures what the auditor watches happen in real time, such as attending a year-end inventory count or watching a warehouse clerk execute a goods receipt control. The catch is that observation only proves the activity happened at that specific moment. It says nothing about whether the control operated correctly on any other day of the year, which is why auditors pair it with other procedures.

Inquiry covers interviews and written questions put to management or staff, documented as interview notes or formal written responses. Inquiry alone is the weakest form of evidence because it comes from people with an interest in the outcome, so auditors almost always corroborate what they are told with a document, an observation or a recalculation.

Analytical procedures compare recorded amounts against expectations built from ratios, trends or variance analysis, often anchored to source extracts such as prior year trial balances or industry benchmarks. A gross margin that has moved by several points from the prior year with no obvious explanation is the kind of signal analytical procedures are built to surface.

Recalculation and reperformance involve the auditor independently redoing a client's work: re-adding a depreciation schedule, rerunning a bank reconciliation, or re-executing a control such as a three-way match between purchase order, goods receipt and invoice. Because the auditor produces this evidence directly, it ranks among the most reliable categories available.

A quick reference for assembling an evidence pack:

  • Inspection: inventory count sheets, asset tags, signed physical inspection records.
  • Documentation: invoices, contracts, purchase orders, bank statements, payroll registers.
  • Confirmation: bank confirmations, accounts receivable confirmations, legal letters.
  • Observation: inventory count attendance notes, control walkthrough records.
  • Inquiry: documented interview notes, written management representations.
  • Analytical procedures: ratio analysis, trend comparisons, variance schedules with source data attached.
  • Recalculation and reperformance: independently rebuilt reconciliations, re-executed control steps.

How auditors gather evidence through core audit procedures

Each procedure has its own reliability profile, and auditors choose between them based on the assertion being tested and the risk involved.

  1. Inspection works best when auditors can examine originals rather than copies, trace a document's signatures, and follow its audit trail back to the originating transaction. A contract with an authorised signature and a clear reference number is far more persuasive than an unsigned draft pulled from a shared drive.
  2. Confirmation starts with a carefully drafted request, usually sent directly by the auditor rather than routed through the client, with a defined follow-up timeline for non-responses. A non-reply is never treated as silent agreement; auditors escalate with a second request or fall back on alternative procedures such as reviewing subsequent cash receipts.
  3. Observation needs to be written up at the time it happens, noting exactly what was seen, who performed it and when, because its biggest limitation is that it only proves a point in time. Auditors often combine observation with inquiry to understand whether what they watched is representative of how the control runs day to day.
  4. Inquiry is rarely accepted on its own. Professional scepticism means corroborating a manager's explanation with a document or a recalculation, and documenting both the question asked and the follow-up evidence obtained to close the loop.
  5. Analytical procedures depend on a well-built expectation and a defined tolerance for how far actual results can deviate before triggering further testing. When a variance exceeds that tolerance, auditors follow up with inquiry or inspection rather than accepting management's first explanation.
  6. Recalculation and reperformance are common for depreciation schedules, bank reconciliations, and control procedures such as re-executing a purchase approval workflow. Because the auditor generates the result independently, these procedures typically need less supporting corroboration.
  7. Sampling versus full population testing is a judgement call shaped by risk and data availability. Audit data analytics increasingly allows auditors to examine entire populations rather than a sample, which can strengthen the evidence base when the underlying data is validated.

What makes evidence sufficient and appropriate

Sufficiency is a question of quantity, how much evidence is enough, while appropriateness asks whether that evidence is relevant to the assertion being tested and reliable given its source. PCAOB AS 1105 requires auditors to weigh both before forming a conclusion, and the two move in opposite directions: the higher the quality of evidence, the less of it an auditor typically needs.

Source matters enormously to reliability. Evidence the auditor obtains directly, such as a bank confirmation sent and received independently, generally outranks information produced by the entity itself, known as IPE, which in turn outranks informal verbal assurances. When auditors do rely on IPE, such as a system generated ageing report, standards require them to either test the report's accuracy and completeness directly or test the IT general controls and automated application controls that produced it.

A short example shows the trade-off: one signed bank confirmation from an independent third party can outweigh a stack of twenty internally printed account statements, because the confirmation's source carries far more weight than its internal counterpart's volume. The reverse also holds: weak evidence from a single internal memo rarely becomes persuasive no matter how many copies exist.

Documentation that increases persuasiveness shares a few features: a clear timestamp, an explicit link back to the specific assertion being tested (existence, completeness, valuation, rights and obligations), and a visible sign-off trail showing who prepared and who reviewed it.

What makes evidence sufficient and appropriate — overview diagram

Audit evidence examples by financial reporting, IT, compliance and inventory

Generic evidence types become useful once mapped to the specific task in front of you.

  • Financial reporting: bank reconciliations, invoice trails tied to purchase orders, lease and contract schedules, and cut-off shipping documents around period end.
  • IT and security: access logs and change logs, backup restore test records, deployment tickets linked to change requests, and vendor security review reports.
  • Compliance (HIPAA, ISO and similar frameworks): staff training completion records, incident response logs, and signed policy acknowledgement forms. Our guide to audit trail requirements walks through what regulated teams typically need to keep on file.
  • Inventory and operations: physical count sheets, photographic evidence carrying embedded metadata such as date and location, and shipping or receiving records tied to specific consignments.

A short worked example ties this together. Say an auditor is testing the existence assertion for inventory recorded on the balance sheet. A physical count sheet signed at year end, cross-referenced to the perpetual inventory system and observed in person by the auditor, directly supports existence. The same count sheet, paired with a recalculation of unit cost against the purchase invoice, would instead support valuation, showing how one evidence type can serve different assertions depending on how it is used.

How audit data analytics is changing what counts as evidence

Testing an entire population of transactions rather than a sample can increase the persuasiveness of evidence considerably, because it removes the sampling risk that comes with extrapolating from a subset. Audit data analytics makes full population testing practical for many clients, but it supplements traditional techniques rather than replacing them outright.

Before relying on system generated reports, auditors need confidence in the IT general controls and automated application controls that produced the underlying data. Without that assurance, a flawless looking report could simply be reproducing a flawed input.

Typical artefacts auditors request to validate electronic evidence include field mappings showing how source data became the final report, version histories, and raw data exports they can independently recalculate or sample-verify against the system output.

  • Request the underlying data extract, not just the summarised report.
  • Ask for field mappings and transformation notes showing how raw data became the final figures.
  • Independently recalculate a sample of line items against the export to confirm the report ties out.

Pro Tip: Ask for evidence that a process actually worked, such as a documented backup restore test, rather than settling for proof that the backup file simply exists.

Assembling audit-ready evidence under time pressure

When a deadline is tight, the most effective move is prioritising evidence tied to high-risk assertions first, since that is where auditors concentrate their testing and where gaps cause the most rework.

  1. Identify sources for the highest-risk assertions first, such as revenue cut-off or inventory existence, and list exactly which system or team holds the underlying records.
  2. Extract the data directly from source systems rather than relying on summarised reports, keeping the extract in its original format.
  3. Attach timestamps and sign-offs to every item so reviewers can see when it was produced and who approved it.
  4. Map each item to its assertion, labelling evidence clearly so a reviewer can see at a glance what it proves.

Mapped workflows with stage gating, the approach behind our Videra platform, are designed to keep this kind of traceability intact as work moves between teams, rather than leaving it to be reconstructed at audit time. Our 90 day audit readiness checklist and our guide to audit trail requirements go into more depth on building this kind of evidence pipeline before an auditor ever asks for it.

Common challenges in gathering audit evidence and how to address them

The most frequent obstacle is fragmented recordkeeping: evidence scattered across email threads, shared drives and disconnected systems, forcing auditors and preparers alike to hunt for documents that should have been filed together. The fix is a consistent filing structure, built around the assertions being tested, maintained throughout the year rather than assembled retroactively.

A second common problem is incomplete or unsigned documentation, such as approvals given verbally rather than recorded in writing. Building sign-off into the workflow itself, rather than treating it as a separate compliance step, closes this gap before the audit begins.

Non-responses to confirmation requests are another recurring hurdle. Auditors address this with a defined follow-up timeline and alternative procedures, such as reviewing subsequent cash receipts, when a response never arrives.

Finally, reliance on internally generated reports without testing the controls behind them creates a reliability problem that only surfaces late in the audit. Testing IT general controls and automated application controls early, rather than waiting until fieldwork, avoids last-minute scrambles to prove a system report can be trusted.

Impact of emerging technologies like AI and blockchain on evidence verification

Artificial intelligence is increasingly used to flag anomalies across large transaction populations, helping auditors direct their attention towards unusual patterns rather than reviewing everything manually. This changes the shape of evidence gathering: instead of a sample of fifty invoices, an auditor might review a full population flagged by an analytics tool, provided the tool's logic and data inputs have themselves been validated.

Blockchain-based records offer a different kind of promise, since a properly configured distributed ledger can make certain transactions tamper-evident by design. That characteristic does not remove the auditor's responsibility to test the controls around how data enters the ledger in the first place, because a blockchain only guarantees that recorded data has not been altered after the fact, not that the data was accurate when it was recorded.

In both cases, the underlying principle from audit data analytics holds: new technology can expand what evidence auditors can examine, but it does not remove the need to validate the pipeline producing that evidence.

The role of professional judgement in evaluating evidence quality

Standards set the framework, but no checklist can mechanically decide whether a specific piece of evidence is persuasive enough on its own. AICPA AU-C guidance explicitly frames sufficiency and appropriateness as matters of professional judgement, applied case by case rather than through a fixed formula.

This judgement shows up constantly in practice: deciding whether a client explanation needs corroboration, deciding how large a sample needs to be given the risk involved, and deciding whether an unusual variance warrants further testing or has a reasonable explanation. Two auditors can look at the same evidence and reach different, equally defensible conclusions about how much further testing is warranted, which is precisely why documentation of the reasoning behind a judgement call matters as much as the conclusion itself.

Professional scepticism underpins all of this: approaching management's explanations with a questioning mind rather than accepting them at face value, while remaining fair and objective rather than assuming wrongdoing.

Audit evidence examples in specialised and regulated industries

Beyond standard financial statement audits, sector-specific regulation often dictates exactly what evidence auditors and compliance teams need to produce. In healthcare, that typically means training completion records, signed policy acknowledgements, incident response logs and access control reviews tied to protected health information. Our walkthrough of HIPAA audit readiness sets out how a focused evidence assembly effort can be organised around these specific document types.

Construction and facilities management carry their own evidence demands, such as nonconformance reports, inspection sign-offs and maintenance records tied to specific assets or sites. Our field templates for nonconformance reporting show how operational teams typically structure this kind of evidence on site.

For information security programmes, practical guidance on evidence types for ISO 27001 audits outlines the records, logs and control evidence that ISO-aligned compliance teams are generally expected to maintain. Each of these specialised contexts still maps back to the same core categories: inspection, documentation, confirmation, observation, inquiry, analytical procedures, recalculation and reperformance. Only the specific artefacts change.

What the standards get right, and where practice falls short

Standards such as AS 1105 are right to anchor everything in sufficiency and appropriateness rather than a fixed checklist, because evidence quality genuinely depends on context that no template can capture in advance. Where conventional advice falls short is treating evidence gathering as a once-a-year scramble rather than a continuous discipline: teams that only think about audit evidence in the weeks before fieldwork end up substituting volume for quality, producing stacks of weakly sourced documents instead of a smaller set of well-corroborated ones.

The reader's priority should be building traceability into daily work, tagging documents to assertions and keeping sign-offs current, rather than reconstructing that trail retroactively. Evidence gathered this way is not just easier to find. It tends to be more reliable, because it was captured close to the event it documents rather than recreated from memory months later.

— Peter

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

FAQ

What are the 8 types of audit evidence?

The eight recognised types are inspection, documentation, confirmation, observation, inquiry, analytical procedures, recalculation and reperformance. PCAOB AS 1105 sets out these categories as the basis for gathering and evaluating evidence during an audit.

What is audit evidence?

Audit evidence is all the information auditors use, whether obtained directly or provided by the client, to support or contradict management's assertions and form the basis of an audit opinion. Standards require this evidence to be both sufficient in quantity and appropriate in relevance and reliability before an auditor relies on it.

What are some examples of audit documents?

Common audit documents include invoices, signed contracts, bank statements, payroll registers, bank confirmations and signed inventory count sheets. Electronic examples include access logs, change tickets and system generated reports, provided the controls behind them have been tested.

How do auditors evaluate electronic evidence from client systems?

Auditors either test the accuracy and completeness of the system generated information directly or test the IT general controls and automated application controls that produced it. This requirement applies whenever an auditor plans to rely on information produced by the entity, often referred to as IPE.

Sources