Audit Evidence for Exchange Rates: Proving Which Rate You Used, Who Published It and When
What auditors and tax inspectors ask for when they test a currency conversion, the five fields to retain for every rate, retention periods, and how to make the evidence come out of the system instead of a spreadsheet.
When an auditor tests a foreign-currency transaction, the procedure is to recompute it. They take the foreign amount, obtain the rate from the source your policy names for the date your policy says, and compare. ISA 500 asks for evidence that is relevant and reliable, and a rate from a named public institution is both. The test fails not when the rate is wrong but when nobody can say where it came from. This page lists what to keep so the recomputation is a formality.
Five fields for every rate
| Field | Why it matters | Example |
|---|---|---|
| Publisher | The regulation or policy names an institution; the evidence must name the same one | European Central Bank |
| Table | Institutions publish more than one series; reference, buying, selling, customs | Euro foreign exchange reference rates |
| Publication date | The date the institution released the figure, which is not always the date you applied it to | 2026-03-31 |
| Applied-to date and rule | Shows how a weekend or holiday was handled | Applied to 2026-04-01; last published rate before date |
| Value and direction | Which currency is the base and how many decimals the institution published | 1 EUR = 1.0824 USD |
Every rate returned by our central bank and tax authority endpoints carries these fields, including a flag when a value was derived as a cross rate rather than published directly. The methodology page documents the collection and the checks, and the data sources register links each table to the institution's own publication page, which is the primary source an auditor can open.
Evidence that comes out of the system
- Store the fields with the posting. ERPs hold the rate value; few hold the publisher and date. Where the system allows, load rates into a dedicated exchange rate type named after the source so the type itself is the evidence. The SAP and Business Central guides show this.
- Archive the table per period. One CSV or XLSX of the full published table for each reporting date, filed with the close. Our endpoints return any table in CSV, XML or XLSX so the archive is an export, not a retype.
- Log the policy. The accounting policy that names the source, with its version history, sits next to the archive. A rate without a policy invites the question of why that source.
- Reproduce on demand. For a sample the auditor picks, being able to pull the published table for that date in seconds ends the conversation. Keep the credentials and the procedure with the finance team, not only with IT.
What tax inspectors look for specifically
VAT inspectors check that the rate is the one the VAT law permits and that the method is consistent (see VAT invoice rates). Customs auditors recompute duty at the fixed monthly rate for the acceptance month (customs rates). Transfer pricing reviewers look for changes in method between periods and differences between related entities (transfer pricing). The five fields above answer all three.
Frequently asked questions
Is a screenshot of a currency website acceptable evidence?
It is weak evidence. It shows a number at a moment, from a source that is usually unnamed and not the one the regulation names. A retained copy of the institution's published table for the date, or a record that identifies the institution, table and publication date, is what an auditor can verify independently.
How long do we need to keep exchange rate records?
As long as the underlying records. Typically six years for UK VAT and company records, ten years in Germany, five to seven in most other jurisdictions, and longer where transfer pricing or losses carried forward extend the review window. Keep the rate evidence with the transaction records so they share the retention period.
Can the API itself be the evidence?
The API can reproduce any past published table, and the record it returns states the institution, the table, the publication date and whether a date was rolled back. That is strong supporting evidence. Auditors still prefer a copy held in your own records at the time, so archive the table you used rather than relying on re-querying it later.
Preparing for an audit or building the archive?
Tell us the sources and periods you need to evidence, and we will set up the exports and the retention routine with your team.
Talk to us Read the methodology