External auditors do not need a perfect ERP. They need a population they can reconstruct. When finance teams send a spreadsheet labeled “all invoices” without stating the ledger source, open period, or filter for credit memos, the first follow-up is inevitable.
Write the definition before the extract
Start with a one-page definition: system, module, date basis (document date vs posting date), entities included, and currencies. Tie the definition to the assertion under test — completeness for revenue looks different from existence for inventory counts.
In App Data Bridge cohorts, teams that draft this page before IT runs a query cut at least one round of “please re-extract” messages.
Capture filters as evidence, not folklore
Every filter belongs in the pack: inactive SKUs removed, intercompany tags excluded, voided documents dropped. If a filter lives only in someone’s memory of last year’s workbook, it will fail a walkthrough with a new senior.
Exclusions come next, not last
List what you removed and why, with counts. Auditors can disagree with an exclusion; they cannot work with a silent one. Keep the residual population total visible so sampling math stays grounded.
Completeness language that can be tested
Prefer statements like “population equals the AR subledger balance as of 31 Dec after eliminating codes X and Y, tied to TB line 1200” over “complete listing of customers.” The first can be reperformed; the second invites philosophy.
For a full rehearsal of this sequence, see External Audit Evidence Across Workflows.