A tired detective in a rumpled suit stands at a desk in a dim, run-down office, holding a flashlight and a plastic evidence bag with a printed spreadsheet sealed inside. Numbered evidence tents sit on the desk and on stacks of binders, and investigation tape crosses the filing cabinets behind him. The word AUDIT runs across the top in large capital letters.

  • Jul 12

Readiness Is a Byproduct, Not a Season

Composite case: 260 audit requests, 73 already existed. Readiness is whether your process keeps its own proof all year. First of eight, one Lean tool each.

One year-end, a mid-sized manufacturer fielded 260 audit requests. 73 of them already existed when the auditor asked. The other 187 had to be rebuilt during fieldwork. Most of that rebuilt column was the same reconciliations, approvals, and schedules the company produces every period and never kept. Call it what it is: archaeology.

Audit prep is the cost of evidence your process failed to create.

This is the first article in the Practical Lean Finance series on audit readiness. Eight articles, one Lean tool each, built on one composite worked case: a CHF 220M industrial manufacturer running four entities on SAP S/4HANA, assembled from years of manufacturing finance and traceable to no single company. The thesis runs underneath all eight. You do not prepare for an audit. The audit measures whether your process already keeps its own proof.

If you followed the earlier series on the month-end close and working capital, this picks up where they left off: the numbers arrive on time and the cash is visible, and the next question is whether each number can prove itself when someone asks. If you are new here, no prerequisite. Start here. The question this article answers: of everything you will hand the auditor, how much exists today?

The teardown

Of the 187 rebuilt items, about 60 were genuinely year-specific: a lease judgment, a financing round, a one-time estimate. Those get built once because they happen once. The other 127 were recurring. Same reconciliations, same management reviews, same approvals the company runs every close. They got rebuilt because the process generated the number and kept nothing behind it. The top five rebuilds alone stretched fieldwork by twelve days.

Readiness is how much of that binder already existed when the period closed, before the request landed. Everything a recurring process only produces during fieldwork is backlog.

Grid of 260 small squares, one for each audit request from one year-end. 73 squares existed when the auditor asked, 28 percent of the total. 60 squares were one-off items built once, in fieldwork. 127 squares, the largest block, were recurring items rebuilt during fieldwork, and the number 127 sits large on that block, labeled recurring, rebuilt every year. A callout adds 12 extra days of fieldwork from the top five rebuilds alone. Takeaway: Everything a recurring process only produces during fieldwork is backlog.

One square per request: 73 existed when asked, 60 were one-off judgments written up late, 127 were recurring items made a second time in fieldwork.

The request counts and the worked examples in this article come from a composite audit-readiness case I built for GoFast.Finance, assembled from years of manufacturing finance and traceable to no single company and no current employer. The numbers are illustrative. The mechanics are what you will find in your own PBC list.

Three kinds of built

Built once still means built at the decision. A lease judgment reached in March belongs in the file that week, memo, assumptions, and approvals included; written up in October, it is a rebuild too, only a rarer one. A third kind of work sits on every list and belongs to neither column: the sample the auditor picks, the confirmation they send, the rollforward in their format. That is fieldwork, and it is legitimate. The 127 is the column this series is about.

What counts as existing

For a recurring control artifact the test is plain. It was dated, it named who prepared it and who reviewed it, it tied to the ledger, and it sat where someone other than its author could find it. An automated control keeps its proof elsewhere, in the configuration, the exception log, and the change history, and the test bends to fit. Existing is the first gate, and this article stops there. The next two gates, whether it explains the number and whether a stranger can find and use it, get an article each later in the series.

One more thing about that proof. In the auditor's vocabulary it is company-produced information. They decide whether it is enough, and they may check it is complete and accurate before they lean on it. On the first gate the composite scored 73 of 260, or 28 percent. Your file has a score too, and it costs an afternoon to find; the controller move at the end shows how.

What the inspectors find

The composite is fictional. Public data shows the same evidence problem from the auditor's side. When U.S. regulators inspect the audit firms themselves, they regularly find engagements where the auditor did not obtain sufficient appropriate evidence to support the opinion. PCAOB staff estimated in their March 2025 Spotlight that 39 percent of inspected engagements in 2024 carried at least one such finding, down from 46 percent the year before, with the Big Four U.S. firms around 20 percent. Read it precisely. That figure is a finding about audit firms, not a control-failure rate for the companies they audit, and since the PCAOB picks most of those audits for risk, it describes that set and nothing wider. It tells you what an audit runs on. The evidence behind the number is the raw material, and it is where the work gets tested.

When private companies meet that level of scrutiny for the first time, the gaps surface fast. PwC's review of domestic and foreign-issuer IPOs listed on NYSE and Nasdaq from 2019 to 2024 found roughly 46 percent disclosed at least one material weakness while going public, 79 percent among foreign private issuers against 37 percent of domestic filers. Control gaps were common across that IPO population, and few of them were pure filing problems: people, oversight, systems, and review process all show up in the disclosed themes.

Write down the five requests that cost you the most fieldwork time last year, one line each. No fixes yet. Those five carry the rest of this article.

One caveat on scope

One honest caveat before the method. This series uses SOX and PCAOB concepts as the stress test, because they are public, rigorous, and well documented. Your audit may be lighter. In a private-company statutory audit, a local audit, or a group audit where you feed the parent rather than sign as the registrant, the auditor may understand your controls for risk assessment without testing how they operate, unless they plan to rely on those controls, cannot get enough evidence from the balances alone, or are engaged to audit internal control over financial reporting. The depth changes. The operating lesson holds across all of them: if the number matters, the evidence trail behind it matters.

Why the depth changes

How deep the auditor goes depends on what they are signing and where they see risk. With an opinion on internal control, the key controls get tested as a matter of course. Without one, controls get tested when the auditor plans to lean on them, or when testing the balances alone would not be enough. A control that leaves no trace makes that harder: with little to inspect, they lean on it less, test the balances more, and the request list usually gets longer. If you feed a group audit, the group auditor sets the depth, light or heavy. A different scope changes what is on the list. A list still arrives.

Three bars of decreasing height showing how deeply the auditor tests controls under each audit approach. Where there is an opinion on internal control: key controls tested. Where the auditor relies on your controls: relied-on controls tested. Where the auditor tests the balances instead: controls understood, not tested. A fourth position, a group component, is drawn as a dashed outline spanning the full range, labeled any of the three, the group auditor decides. All of them stand on one continuous slab labeled the evidence trail behind the number. Takeaway: If the number matters, the evidence trail behind it matters.

Three testing depths, one slab they all stand on. A group component sits wherever the group auditor puts it.

This is education and enablement, not an audit or controls opinion. Where a treatment is genuinely in question, that judgment belongs with a qualified professional. Ask your auditor one question at planning anyway: which of your controls do they plan to lean on this year? The answer tells you which artifacts will be tested and which will only be read.

Where evidence gets born

So why does the recurring column come back every year? Because the evidence never got created as part of the work. The reconciliation lived in a spreadsheet that got overwritten next month. The review happened on a call with nothing logged. The approval sat three inboxes deep by the time anyone needed it. The number was right. The proof was gone.

Value stream mapping is the Lean tool for exactly this. On a factory floor you follow one unit through every step it passes, and you mark each step as value or waste. Do the same with one piece of audit evidence. Follow it from the transaction that posts, through the control that should catch it, to the artifact that records it, to the auditor's request, to inspection. Then ask one question at each step: where does the evidence actually get born?

The map, taught from zero

A value stream map is a drawing of one thing's path through a process, with the waits and the hand-offs written on it. On a shop floor the one thing is a part: it gets cut, waits, gets welded, waits, gets painted. The waits are usually longer than the work, which is why anyone bothers to draw it. For audit evidence the one thing is one artifact, say the bank reconciliation for March. Its path has five stops: the transaction posts, the control runs, an artifact gets made, the request arrives, the auditor inspects. Draw the five stops on a line and write under each one what exists at that point, who holds it, how long the work took, how long it waited, and whether it came back for rework. A first pass takes minutes per artifact.

In a clean stream, the evidence gets born at the control. The reconciliation runs, and the act of running it drops a dated, owned, tied-out artifact into the same place every period. Months later the request arrives and the answer takes minutes, because the proof was kept the first time. In a broken stream, the control runs and leaves nothing. The review may genuinely have happened, but a control that leaves no durable trace is hard to test and weak as audit support. So when the request lands, someone rebuilds the proof from emails, old files, and memory, under fieldwork deadline. The evidence gets made twice: once when the work happened, again when someone has to prove it did. That second pass is the waste. And the rebuilt file is weaker than it looks. It supports the number, at best. It says little about whether the review ran on time and at the depth the control promised. On the map, the broken stream is your current state and the clean one is the future state. Draw both for the same artifact.

One piece of audit evidence followed through five numbered stops: transaction posts, control runs, artifact, request, inspection. After stop two the path forks. On the upper path the artifact is kept at stop three, dated, owned, and tied out, marked made once, and the request at stop four is answered in minutes. On the lower path nothing is kept at stop three, and at stop four the proof is rebuilt from emails, old files, and memory under fieldwork deadline, marked made twice. Both paths end at stop five, inspection. Takeaway: That second pass is the waste.

One artifact, five stops, and the fork at stop three where the proof is either kept or made a second time.

Run it on your own top five rebuilds. Map each one back through those steps and find where the artifact step went missing. That gap is the fix.

Three levers upstream

The 127 recurring rebuilds do not disappear by working harder in October. They get prevented upstream, where the work actually happens, and they sort into three levers.

Upstream means the point where the number gets made. For the 127 recurring items that is the close. For a contract, a rebate program, or a capex approval, it is the day the decision is signed. Kept at the close, each artifact costs a few minutes of filing, twelve times a year, by the person who just made it. Rebuilt in October, the same artifact costs the reconstruction, on the auditor's clock, with the twelve extra days attached. Twelve small filing jobs at the close replace one October rebuild.

Two rows on the same January to December axis. The top row, kept at the close, shows twelve small equal bars: a few artifacts filed each month. The bottom row, rebuilt in October, is flat all year except one tall spike at October labeled 127 items rebuilt, with a note that the top five alone cost 12 extra days. A strip underneath names where the upstream fix lands: controls in articles 2 and 3, evidence in articles 4 and 5, interface in articles 6 and 7, root cause in article 8. Takeaway: Twelve small filing jobs at the close replace one October rebuild.

The same artifacts as a steady drip through the year, or as one spike in fieldwork, and the four places the series puts the fix.

Controls, evidence, interface

Start with the controls. A recurring control that produces no artifact is slow and expensive to test, and usually gets tested only after the evidence is rebuilt. A control one person can run, approve, and reconcile alone has no independent check behind it, unless a compensating review covers the gap. The next two articles redesign controls so they emit an artifact, and set who does what so the artifact can be trusted.

Then the evidence itself. Sometimes the artifact exists but does not explain the number. Sometimes it exists but no one can find it or trust it six months on. Those articles cover which reconciling items actually matter and how to keep evidence so a new controller can pick it up cold.

Last, the interface between the work and the request. Produce evidence to a steady cadence instead of a year-end batch, and spend the most effort where judgment enters the number, because that is where the file gets heavy. The capstone closes the loop on findings that come back every year because the symptom got patched and the root never got fixed.

Which lever, for each of your five

Take your five rebuilds and tag each one with the lever that would have prevented it: the control left nothing behind, the artifact existed but explained nothing or could not be found, or the request arrived and nobody knew what to send. The tags tell you which pair of articles to read first.

Whose evidence is it

Look down the rebuilt column and a lot of it sits outside accounting. FP&A and the business partners own the evidence behind contract terms, rebate accrual logic, forecast-based accruals, capex approvals, and margin explanations. Take one rebate accrual. Sales confirms the program terms, FP&A estimates the payout, accounting books it, a controller reviews the bridge. Saved as one dated file with the terms, the calculation, the preparer, the reviewer, and the GL tie-out, next year's request is a pull. Left in emails and an overwritten spreadsheet, it is a rebuild. Most of this evidence never gets filed at the moment the judgment is made, which is exactly when it is cheapest to capture. The fix is the same everywhere: keep the proof when the decision happens, not when the auditor asks.

The audit follows risk across the whole system, and the ledger is only part of it. Operations owns the inventory evidence, IT owns the access evidence, Sales owns the contract evidence. Finance orchestrates the trail. It does not hoard it.

Orchestrating, in practice

Orchestrating means two things. Finance names, for each recurring request, who owns the artifact and where it lives, and checks at each close that it landed there. Nobody in Sales will file a rebate calculation for an audit they will never sit in unless someone asks, in the week the number is booked, with a place to put it. That ask is the job.

Four owners of one rebate accrual in a row: Sales confirms the program terms, FP&A estimates the payout, Accounting books it, the Controller reviews the bridge. Four connectors converge into one dated file holding five fields: terms, calculation, preparer, reviewer, GL tie-out, with the owner and the home named by Finance. An arrow leads from the file to the result: next year's request is a pull. Takeaway: Keep the proof when the decision happens, not when the auditor asks.

Four people touch one accrual; the file they all drop into is what turns next year's request into a pull.

Write the owner's name next to each of your five rebuilds. If most of them sit outside accounting, readiness is an orchestration problem, and the fix starts with a conversation.

Common pushback

  • "Our audit is a statutory audit. The auditor barely tests our controls, so this is a SOX problem." Some of it is. The depth is lighter, and nobody will ask you for an opinion on internal control. The list still arrives. A control that leaves no trace pushes the auditor into the balances instead, and testing balances means more requests, larger samples, and more of your October. The evidence trail behind the number is what every version of the audit runs on. Keep the proof where the number matters and let the depth be the auditor's call.

  • "Our reconciliations exist. We just have to find them in October." Then they exist for one person, which is the problem. The test in this article has four parts, and the last one is that someone other than the author can find the file where it is supposed to be. A reconciliation the preparer digs out of a mailbox during fieldwork passed the first three and failed the fourth, and in the auditor's week it costs about the same as a rebuild. Count it in the built column. The retrieval side gets its own article later in the series.

  • "We cannot ask Sales and FP&A to file audit evidence. They will never do it." They will file a rebate calculation the week they book it if someone asks for exactly that, once, with a place to put it and a name on the request. The ask is one line at the moment the number is made, and it is finance's line to say. The version that fails is the October one, when the ask arrives from an auditor through you, about a decision nobody remembers.

  • "We ran an audit readiness project two years ago. It did not stick." It probably worked, for one October. A project builds the binder once, as a batch, and a batch has no reason to repeat itself the next year. Readiness is a property of how the process runs, so the fix has to live where the process runs: in the control that saves its own output and in the close that files it, twelve small filing jobs instead of one push. The next article starts there.

FAQ

  • How is this different from the close series and the working capital series? Those two fixed when the numbers arrive and where the cash sits. This one asks whether each number can prove itself when someone other than its author asks. Same Lean tools, new process: the value stream map you draw here follows an artifact instead of a task or a dollar.

  • Our key controls are automated. What is the artifact? Whatever the system keeps: the configuration that runs the check, the exception log it writes, the change history that shows nobody altered it, and the access list that shows who could have. The test bends to fit, and the readiness question stays the same: does that proof exist before the request, and can someone other than the administrator produce it? The second article covers the wrapper that lets a system report stand on its own.

  • What about the sample the auditor picks? We cannot pre-build that. Correct, and this article does not ask you to. Work that only exists after the auditor defines it, a sample, a confirmation, a rollforward in their format, is the third kind on every list and sits outside the 127. What you can have ready before the request is the population the sample is drawn from and the tie-out that shows it is complete, which is most of what the sample costs. The interface articles later in the series take that up.

  • Do I need a tool for this? No. The controller move runs on last year's request list and two extra columns in a spreadsheet, and the value stream map is five stops on a page. The diagnostic costs an afternoon. The year-round system, the control-evidence register, the reconciliation tracker, the PBC pull board, and the findings log, is what the course builds.

  • The close is already tight. Where does the time for filing come from? From October. Each artifact costs the person who just made it a few minutes to file at the close, and the composite's top five rebuilds alone cost twelve days of fieldwork. The better answer is the one the next article gives: a control designed to leave its artifact behind files it for free, and the close only checks that it landed.


Readiness is a property of how the process runs all year: whether each number, as it gets made, drops the proof that it was made right. The binder in October only collects what the process already kept. Everything in this series builds toward that one habit. The audit just reads the result.

Ask this before year-end: Of everything you will hand the auditor, how much exists today, and how much will you build in October?

Controller move: Pull last year's PBC list, the prepared-by-client request file (some firms say provided by client). Add one column: existed before the request, or built after. Add a second: recurring, one-time judgment, or work only the auditor can define, such as a sample pull. Sort by the built column and set the auditor-defined rows aside. The recurring items there are your readiness backlog. Fix the top five first, starting with the ones that cost the most fieldwork time, and move any judgment-heavy estimate or manual journal to the front regardless of hours.

Last year's audit request list drawn as a table with two added columns, existed or built, and kind of work, sorted once. Three rows at the top are built and recurring, the readiness backlog: bank reconciliation for December, rebate accrual, margin review note. Below them a lease memo, built and one-time; then an auditor-format rollforward, built and auditor-defined, set aside; then inventory count sheets, which existed. A summary line reads 127 built and recurring, fix the top five, judgment-heavy first. Takeaway: The recurring items there are your readiness backlog.

Two columns on last year's list, one sort, and the readiness backlog is the block at the top.

Next in the series: the control that leaves no artifact, and how to redesign it so proof falls out of the work. Article 2


CC-AA03, the audit-readiness course in the GoFast path, is on GoFast.Finance. It builds the year-round system behind this series: the control-evidence register, the reconciliation tracker, the PBC pull board, and the findings log. Education and enablement only, no audit opinions. Take the course

This article originally appeared in the Practical Lean Finance newsletter on LinkedIn. Read it there, or subscribe for the weekly piece.


Sources

  1. PCAOB staff, Spotlight: Staff Update on 2024 Inspection Activities (March 2025). https://pcaobus.org/documents/staff-update-2024-inspection-activities-spotlight.pdf. Staff estimated the aggregate Part I.A finding rate at 39 percent of inspected engagements for 2024, down from 46 percent in 2023, with Big Four U.S. firms at 20 percent, down from 26; some 2024 results were estimates at publication. Part I.A means the firm had not obtained sufficient appropriate evidence to support its opinion, an audit-firm finding rate and not a company-level control-failure rate. The Big Four audit roughly 80 percent of U.S. listed market capitalization. Inspected engagements are selected mostly on risk, with a random share (stated in each PCAOB inspection report), so the rate describes inspected engagements only.

  2. PwC, Material weakness disclosures in an IPO. https://www.pwc.com/us/en/services/consulting/deals/library/ipo-material-weakness.html. Domestic and foreign-issuer IPOs listed on NYSE and Nasdaq, 2019 to 2024: roughly 46 percent disclosed at least one material weakness while going public; 79 percent among foreign private issuers against 37 percent of domestic filers. Used as illustrative context for first-time scrutiny, and not as a benchmark.

  3. PCAOB AS 2301, the standard on the auditor's responses to the risks of material misstatement in public-company audits. https://pcaobus.org/oversight/standards/auditing-standards/details/AS2301. Paragraph .16: relying on controls requires evidence they operated through the period of reliance, and the auditor is never required to rely. Paragraph .17: tests of controls are required in a financial statement audit for each relevant assertion where substantive procedures alone cannot provide sufficient appropriate evidence. Your audit may run under other standards; the operating lesson travels anyway.

  4. PCAOB AS 1105, the standard on audit evidence in public-company audits. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105. Paragraph .10: when information produced by the company is used as evidence, the auditor tests its accuracy and completeness, or the controls over them, and evaluates whether it is precise and detailed enough for the audit.

Further reading: Value Stream Mapping: How to Visualize Work and Align Leadership for Organizational Transformation by Karen Martin and Mike Osterling. The value stream map taken off the shop floor and into office and knowledge work, which is where audit evidence lives; the current-state and future-state walkthroughs are what the five-stop map in this article borrows from. View on Amazon

As an Amazon Associate I earn from qualifying purchases. Book links are affiliate links; using them costs you nothing extra and supports this newsletter.

0 comments

Joinor login to leave a comment