When a restatement surfaces, the post-mortem conversation almost always gravitates toward intent. Was there manipulation? Did someone obscure a figure on purpose? Regulators ask these questions first, and the press covers the answers. But in the majority of restatement investigations we have studied and participated in, the answer to those questions is no. The number was right. What went wrong was something quieter and more structural: no one could trace the evidence chain from the reported figure back to its source.

That is the gap we built Pramaana to close. And understanding why restatements happen requires understanding why evidence chains break in the first place.

The anatomy of an evidence gap

An audit working paper contains a number. Behind that number is a source document: a board package, a consolidation schedule, an email approval, a system export. The chain between the number and the document is what an auditor calls the evidence trail.

In practice, that chain is assembled manually, often by a different person than the one who originally entered the figure, and often months or years after the fact. When a question arises, say, during a restatement investigation or a regulatory examination, the team responsible for reconstructing that chain discovers it was never consistently documented. The source files exist somewhere. The calculations are probably correct. But no one preserved the explicit link between the figure and its origin.

This is not a documentation failure in the sense of sloppy filing. It is a structural problem. Working paper software was not designed to store provenance. Spreadsheet cells do not carry metadata about what document produced their value. Email approvals live in inboxes that turn over with personnel. The chain degrades silently over time.

Three specific failure modes

Personnel transitions during close

Consider a mid-size financial services company in the middle of a quarterly close. The analyst who built the consolidation model leaves the team six weeks before year-end. Her replacement is competent, but the working papers she inherits contain cells that reference a prior-year board package she does not have access to. She updates the figures for the current period and moves on. A year later, when an auditor asks for the source of a prior-period comparative figure, no one in the current team knows which document produced it.

This is illustrative, but it maps precisely to the pattern we see repeatedly. Evidence chains depend on people retaining implicit knowledge about where numbers came from. When those people leave, the knowledge goes with them.

Version proliferation in source documents

A board package goes through five drafts before the meeting. The final approved version is version five. But the working paper was built from version three, before two revisions were incorporated. The figures in the final working paper match the approved figures in version five, because someone manually reconciled them at the end. But the citation in the working paper still points to version three.

When an examiner asks which document supports the figure, the team produces version five. The examiner spots that the document reference in the working paper does not match. What should be a ten-minute conversation becomes a two-week investigation to reconstruct why the versions differ and whether the final figures were correctly derived.

Calculation intermediaries with no audit trail

A reported figure passes through three intermediate calculations before it reaches the working paper: a system export, a consolidation spreadsheet, and a rounding adjustment applied manually. Each step was performed by a different person. The system export is retained. The consolidation spreadsheet exists on a shared drive in a folder called "Q3 final v2 FINAL." The rounding adjustment was applied directly in the working paper with no notation.

Any one of these gaps is enough to trigger a finding. Together, they make the evidence chain genuinely unrecoverable without significant investigative effort.

Why the problem compounds at scale

The larger the organization, the more sources feed into any given reported figure. A company running 40 legal entities through a consolidation process may have a single balance sheet line that traces back to 15 separate source documents across three systems. The people who know how those sources connect are spread across finance, accounting, and operations teams, and their implicit knowledge is never systematically captured.

This is not a failure of effort. Finance and audit teams at regulated companies work extremely hard. The problem is that the infrastructure they use was not built to capture provenance as a first-class property of each figure. Working papers capture the result of the audit process. They rarely capture the chain of custody for the evidence that produced each result.

What this means for restatement risk

A restatement does not require a wrong number. A restatement can be triggered by the inability to substantiate a correct number to the satisfaction of a regulator or external auditor. If your team cannot produce a traceable path from a working paper figure to a source document, the figure becomes unsupportable, regardless of whether it is arithmetically correct.

This is the distinction that most discussions of restatement risk miss. The risk is not primarily about misstatement. It is about the evidentiary standard required to defend a correct statement. And the evidentiary standard is not satisfied by having the right number. It is satisfied by having the right number plus the traceable, retrievable evidence that produced it.

We are not saying that misstatement risk is irrelevant. There are restatements driven by intentional manipulation, and those require a different response. But the majority of restatement investigations we have observed were triggered by evidence gaps, not by incorrect numbers. That proportion is large enough to deserve specific attention and specific tooling.

Where automated provenance tracking changes the calculus

The traditional response to evidence gap risk is more documentation: require auditors to cite sources explicitly, enforce working paper standards, build checklists. These measures help at the margins, but they do not solve the structural problem. Documentation requirements depend on people remembering to document, on having the source material accessible at the time of documentation, and on documentation remaining linked to figures even as working papers are revised.

Automated provenance tracking captures the link at the moment it is created. When a figure is entered into a working paper cell, the trace back to the source document is recorded automatically, not as a separate documentation step but as a property of the cell itself. Version changes in the source document are reflected in the trace record. Intermediate calculations carry forward their own provenance chain. When an auditor asks for the source of a figure six months later, the answer is already there.

This is what Pramaana's trace engine is built to do. The goal is not to replace the auditor's judgment about whether a figure is correct. It is to eliminate the weeks of reconstruction work that precede that judgment when evidence chains have degraded.

The question worth asking before next quarter

If your external auditor asked you today to produce the source evidence for the five largest figures in last quarter's working papers, how long would it take? If the honest answer is anything longer than a few hours, you have evidence chain gaps that are worth closing before a more consequential question arises.

That window is not primarily about technology. It is about recognizing that evidence provenance is not a documentation nice-to-have. It is a core property of defensible financial reporting. The infrastructure to maintain it continuously, rather than reconstructing it under pressure, is available. The question is whether to put it in place before the next examination or after.

For internal audit teams running quarterly cycles, that choice has a concrete time horizon. The next audit cycle starts before the current one finishes. The evidence chain for this quarter is being built right now. What gets captured now is what will be defensible later.

See provenance tracing in practice

Request a demo and we will trace a figure from one of your actual workpapers back to its source document, live.