INSIGHT / 01
International business · International
When a review finding has no source record: how to make it usable for a decision
A strong sentence in a review report is not yet a usable finding if nobody can trace it back to a specific source record. To make a finding fit for decision-making, link it to a clear review criterion, an identified primary document and an explicit analytical step that another reviewer can reproduce.
## When a report sounds convincing but is still not ready for a decision
In internal reviews, a common weakness is not poor writing. It is the moment when a strong conclusion cannot be taken back to a specific source record. A report may say: “the control did not operate”, “the transaction was not properly supported”, “the risk exceeded the allowed level”, or “the process did not meet the criterion”. But as soon as an owner, functional head or reviewer asks the next question - “which document supports that?” - the answer dissolves into folders, messages and someone’s memory.
That kind of finding is not necessarily wrong. It is weak because it is hard to re-check, defend and use for the next action. If you cannot move quickly from the wording in the report to the primary record behind it, the decision starts to rely on trust in the author rather than on a reproducible chain of evidence.
For an owner or manager this is a practical problem. It is difficult to stop a payment, change a process, dispute a counterparty position or launch remediation where the finding itself cannot be walked back to the source.
## Short answer
To connect a review finding to a specific primary document, it is not enough to attach a pile of files to the working folder. You need a short and reproducible chain made of three parts:
- the review question and criterion;
- the specific primary document or record used as evidence;
- the analytical step that turns that document into the stated finding.
In other words, a good finding answers not only “what do we think is wrong?” but also “how could another person prove this again?” International methodological materials on audit and diagnostic work support that logic: criteria, documentation, evidence quality and a visible path from procedure to conclusion matter. The exact table format, metadata set and storage method, however, remain organisational choices rather than universal mandatory rules for every jurisdiction.
## Why a folder link is not enough
Many teams assume traceability already exists if the file contains the contract, invoice, email and system extract. But keeping files near the report does not explain which document supports which observation and why.
The problem usually looks like this:
- the review criterion is framed too broadly;
- the file contains many documents, but their role is unclear;
- the finding is written as a final judgement with no visible transition from fact to assessment;
- another team member cannot reproduce the logic a week later without speaking to the author.
In that situation a report exists, but an evidence chain does not. That is why it helps to distinguish document storage from finding traceability. Storage answers where the file sits. Traceability answers why that file matters for this finding.
## What traceability means in practice
In simple terms, traceability means being able to travel the route in both directions.
Top down: from the review question to the criterion, from the criterion to the observation, and from the observation to the identified source document.
Bottom up: from the source document to the extracted fact, from that fact to the analytical step, and from the analytical step to the stated finding.
This route is not a methodological luxury. It solves three practical problems:
- it makes disputed findings easier to re-check;
- it shows whether the evidence is strong enough before the team writes a hard conclusion;
- it reduces dependence on the memory of one reviewer.
## The international methodological logic behind it
It is useful here to rely not on one magical template, but on a set of general principles. International materials on performance audit and audit diagnostics emphasise documentation, quality, professional judgement, links between procedures and criteria, and clear terms of the engagement itself.
It is important to separate the roles of the sources.
The 2024 OECD material on performance auditing in Poland is useful as a modern methodological illustration. It shows principles of good audit work and helps frame documentation, quality and the link between findings and methodology. That does not make the Polish example a binding standard for every organisation or country.
The 2006 World Bank ROSC material is useful in a different way. It is a diagnostic and historical tool that helps with scope, engagement terms and comparison between practice and criteria. It does not create a universal mandatory evidence-storage format either. Its value lies in the logic of explicitly recording the terms of the work and checking gaps between requirements and actual practice.
That is why a careful working position sounds like this: here is the general international principle, and here is an illustration of how it can be implemented. Not the other way around.
## The minimum chain a finding needs before it should influence a decision
In practice, a finding is still not ready for management action if the team cannot quickly show five elements behind it.
### 1. The review question
It must be specific enough. Not “document control is weak”, but for example: “is the basis for this payment supported by the required primary records?”
### 2. The criterion
The team must record the rule or expectation against which it compares the fact. That may be an internal policy, an agreed process, a contract term, a control step or a documented workflow.
### 3. The evidence source
Not “deal documents”, but the identified primary record: a numbered contract, an acceptance record, an invoice, a bank statement, a dated email, or a system entry with an ID.
### 4. The analytical step
The reviewer should record what was actually done with the document. For example: matched the beneficiary details; checked the date; compared the amount; identified a missing required appendix; established a gap between the contract and the payment.
### 5. The finding
Only then should the final finding be stated: what is confirmed, what is not confirmed, what gap was found, and where the confidence limit sits.
If one of these elements is missing, the report may still work as a draft for discussion, but it is risky to use as the basis for a firm decision.
## A practical tool: one row for one evidence link
As an author’s practical proposal, not as a regulator’s mandatory form, a simple table works well here. Its strength is that it forces the team to separate the document from the interpretation.
For each evidence link, create one row with fields such as:
- review question;
- criterion;
- finding or observation;
- document;
- document ID;
- storage location;
- who accessed it and when;
- how it was collected or verified;
- analytical step;
- link to the working paper;
- document or file version;
- review mark.
The point of the row is not paperwork for its own sake. It helps answer a simple question: can another person understand why this finding came from this source record?
## A hypothetical example
Imagine an internal review of expenses where the team wants to conclude: “the supplier payment was made without sufficient support for the underlying basis.”
A weak version looks like this: the working file contains the contract, invoice, payment instruction and several emails. The report says the support is insufficient, but it is unclear what the actual gap is.
A stronger version is built differently.
Review question: was the basis for the out-of-cycle payment properly supported?
Criterion: the internal process requires a contractual basis, a supporting invoice and approval by an authorised person for an out-of-cycle payment.
Sources:
- the invoice with its identifier;
- the payment request from the system;
- the approval log;
- the supplier contract.
Analytical step:
- the invoice exists and relates to the supplier;
- the contract exists, but the appendix referred to by the invoice is not there;
- the approval log does not show a separate approval for deviation from the standard payment cycle.
Finding:
- the fact of payment is confirmed;
- the link between the payment and the full required support package is not confirmed within the reviewed sample;
- for decision-making, the issue is not simply that money moved, but that the support chain for the basis cannot be reproduced.
This version makes it clear which documents produced the finding and what gap was actually identified. Even if someone disagrees with the assessment, the disagreement will be about substance rather than about searching for files.
## How to describe the analytical step so it does not disappear between fact and finding
This is the most underrated part. Teams often know how to store documents and write the final finding, but they skip the short explanation of how one became the other.
A useful way to write that transition is very simple:
- the criterion requires A, B and C;
- document 1 confirms A;
- document 2 confirms B;
- confirmation of C was not found in the listed sources;
- therefore the finding is limited to an incomplete support package.
This does not need to become a long essay. A few precise lines are enough for a reviewer to walk the same route again.
## What belongs in the report and what can remain in the working file
Not every table needs to appear in full in the final report. But the report itself should still include at least selective traceability for the most important findings.
Usually it is enough to show:
- the criterion behind the finding;
- the observation that was established;
- the type and identifier of the source record;
- any relevant limitation or incompleteness.
Detailed working notes, access logs, file versions and storage details may remain in the working file. The key point is that the report should not read like a list of finished judgements with no road back to the evidence.
## Where the line sits between international principle and internal method
This line matters.
The international principle can be stated like this: review findings should be documented, linked to criteria, supported by evidence and subject to quality control so that they can be reproduced and re-checked.
The internal method begins where the organisation chooses how to do that in practice. For example:
- which fields to include in the table;
- how to assign document IDs;
- where to store versions;
- how to mark access and review;
- how often to update working records.
Those choices may be very useful, but they should not be presented as universal mandatory requirements unless the source actually confirms that.
## What matters most for the review lead
If you are responsible for internal review quality, it helps to test not only the wording of the finding but also its route.
Useful self-check questions are:
- can each strong finding be tied to a specific primary document or defined set of documents;
- is the criterion clear enough to understand what was tested;
- is the analytical transition from source to finding written down;
- could another reviewer reproduce the same chain in a month;
- is it visible where the finding is firm and where it is limited by evidence quality or completeness.
If the answer is no, the issue is not yet the writing style of the report. The issue is that the finding is not ready to be used.
## A practical sequence for the team
### Step 1. Fix the questions and criteria during planning
Do not wait until the end. If the question is vague, it becomes much harder later to decide which documents belong to the matter at all.
### Step 2. Create one evidence row for each question
One row should capture one chain: criterion -> source -> analytical step -> finding.
### Step 3. Give documents stable identifiers
Do not rely on file names such as final_v3_new. The identifier should help the team return to the same record later.
### Step 4. Write the transition from fact to finding in plain language
Even one or two sentences are better than a silent jump from a folder of files to a categorical statement.
### Step 5. Run independent review over the most sensitive findings
Not necessarily over every file, but at least over the findings likely to trigger a decision, dispute or remediation.
### Step 6. Include a traceability section for key findings in the final report
It does not need to be long. But the reader should have an obvious route back into the evidence.
## What this approach gives you in practice
It does not guarantee that every review will turn out to be right. But it makes finding quality visible.
That becomes especially useful when the team needs to:
- make an uncomfortable management decision;
- discuss the finding with the reviewed side;
- transfer the matter to a new reviewer;
- revisit the report months later;
- move a disagreement away from opinion and toward facts.
That is the real value of traceability: it makes a finding not merely persuasive, but operationally usable.
## Conclusion
Linking a review finding to a specific source record does not mean attaching more files. It means building a reproducible chain: question, criterion, source, analytical step and resulting finding.
If another person can quickly follow that chain without depending on the original reviewer’s memory, the finding is ready for review and far better prepared for a management decision. If not, the report is not finished yet.
## Sources
1. OECD, Performance Auditing in Poland — Best practices. https://www.oecd.org/content/dam/oecd/en/publications/reports/2024/11/performance-auditing-in-poland_115d8b99/34e2353d-en.pdf
2. World Bank, ROSC — Accounting & Auditing Diagnostic Tool – Part 4 (Assessment of Auditing Standards). https://documents1.worldbank.org/curated/en/543461468314052011/pdf/419540v40WP0Di1tIV0321443B01PUBLIC1.pdf
Continue reading
Back to insights