WorkpaperIQ: taking a mid-sized audit firm's workpapers out of email attachments and shared drives
A mid-sized audit firm ran statutory audits for hundreds of companies with workpapers in spreadsheets, evidence in email attachments and review notes in the margins of PDFs. We built WorkpaperIQ: engagement planning, a structured workpaper library, client document requests, AI-assisted ledger analytics and review workflows — a single audit file for every engagement that a reviewer can trust.

An audit file spread across forty folders
WorkpaperIQ's managing partner opened a shared drive for us. Each engagement had dozens of folders, spreadsheets with names like "Revenue testing FINAL (2)", evidence scattered across emails, and review notes typed into PDFs. When a peer reviewer asked for the evidence behind a conclusion, it could take hours to assemble.
Audit quality was high because the people were good. The file did not show it.
“Our work is thorough. Our files make it look disorganised.”
Following an engagement
We followed a statutory audit from planning to sign-off. The biggest time sinks were chasing client documents, re-creating sample selections, and reviewers searching for evidence. Analytics on the general ledger — unusual journal entries, weekend postings, round amounts — were done manually and inconsistently.
- One structured file per engagement
- Client document requests with tracking
- Consistent ledger analytics on every audit
- Review notes linked to the work they concern

Structure that follows audit methodology
WorkpaperIQ organises every engagement by audit area and assertion, with standard programmes the firm maintains centrally. Every test links to its evidence, and every conclusion links to its tests. Clients upload requested documents to a portal, and each upload lands against the request it answers.
The ledger analytics engine imports the client's general ledger and runs the firm's standard tests automatically, with AI explaining unusual patterns in plain language for the auditor to investigate.
The team
An audit methodology reviewer from the firm worked alongside our team throughout.
Partner workshops and audit-season rollout.
Audit programmes and workpaper structure.
Audit workspace and client portal.
Workspace, requests and review workflow.
Ledger import and analytics engine.
Anomaly explanations and document extraction.
7 people in total, working as one team.
Decisions we made
Agreed with the managing partner and quality partner.
Generic document store or audit structure?
- Folders and files
- Engagements structured by area and assertion
Our call: Engagements structured by area and assertion. Structure linked evidence to conclusions, which is exactly what reviewers and inspectors look for.
Email or portal for client documents?
- Client portal linked to each request
Our call: Client portal linked to each request. Every document landed against its request, ending lost attachments.
Should AI conclude?
- AI flags and concludes
- AI flags and explains; auditors conclude
Our call: AI flags and explains; auditors conclude. Audit judgement belongs to the auditor. AI helps focus attention.
Cloud or private?
- Public SaaS
- Private deployment
Our call: Private deployment. Client financial data required strict control.
Every feature, module by module
Everything that shipped for audit teams, clients and partners.
- 01Engagement setup
Client, period, team and materiality.
- 02Risk assessment
Risks linked to audit areas.
- 03Standard audit programmes
Firm-maintained programmes by area.
- 04Budget and time tracking
Hours against budget per area.
- 05Structured workpapers
Tests, results and conclusions.
- 06Evidence linking
Documents attached to test steps.
- 07Sample selection
Reproducible samples from populations.
- 08Ledger analytics
Standard tests on the general ledger.
- 09AI anomaly explanations
Unusual patterns explained for investigation.
- 10Document request lists
Requests with due dates and owners.
- 11Client portal
Uploads land against each request.
- 12Request reminders
Automatic follow-ups.
- 13Document OCR
Key fields extracted from confirmations and invoices.
- 14Review notes
Notes linked to workpapers with clearing.
- 15Sign-off workflow
Preparer, reviewer and partner sign-offs.
- 16Partner dashboard
Engagement status and open notes.
- 17File lock and archive
Files locked after sign-off.
- 18Role-based access
Staff, managers, partners and clients.
- 19Audit trail
Every change recorded.
- 20Quality review exports
Files packaged for peer review.

Rollout
We piloted on a handful of engagements in the new audit season, then rolled out firm-wide. The quality partner's peer reviews became noticeably faster once evidence was one click from every conclusion.
- Weeks 1–3Discovery
An engagement followed from planning to sign-off.
- Weeks 4–6Design
Workpaper structure and programmes.
- Weeks 7–15Build
Workspace, portal, analytics and review.
- Weeks 16–18Pilot engagements
A handful of audits in the new season.
- Weeks 19–20Firm-wide rollout
All engagement teams.
What we learned
Structure is the product. Mirroring the firm's methodology made the tool feel natural to auditors.
Standardise analytics. Running the same tests on every audit raised the floor of quality.
- Next.js
- Python / FastAPI
- PostgreSQL
- Ledger analytics engine
- Document OCR
- LLM-assisted anomaly explanations
- Private cloud

