Audit Software in Ghana: A Buyer's Guide for Audit Firms and Internal Audit (2026)

How to choose audit software in Ghana: ICAG licensing and the repeated-findings directive, the PFM Act internal audit cycle, the 2023 follow-up instructions, hosting, provider types, cost and red flags.

CS
Creodata Solutions Team
Audit Software in Ghana: A Buyer's Guide for Audit Firms and Internal Audit (2026)

Short answer: "Audit software" in Ghana covers several different products: working papers, engagement and practice management, document custody, client request lists, time and billing, and internal audit management with findings follow-up. Decide which of those jobs you need done, then test each vendor against what ICAG's reviewers, the PFM Act and the 2023 follow-up instructions will ask to see, using scripted demos on your own files.

This guide is for partners and practice managers at ICAG-licensed firms, heads of internal audit units in MDAs and MMDAs, chief internal auditors in banks, and the IT and procurement teams who support them, replacing shared drives, spreadsheets and email or an older system.

There is a new reason to look now. Under an ICAG directive that took effect in August 2026, a review finding that recurs in two or more consecutive review cycles without remediation is prima facie evidence of professional misconduct, and a finding a firm accepts needs a documented corrective action plan before the next cycle begins. A firm that cannot show what it fixed, and when, carries that risk into its next review.

Creodata sells AuditEDMS, so we say plainly where it fits, and where it does not, near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal or professional advice: confirm requirements with ICAG, the Internal Audit Agency or your regulator.

What audit software does

Buyers often compare products that do different jobs. These are separate categories, and few products do all of them well.

CategoryWhat it doesWho uses it
Working papersAudit methodology, the audit programme, risk assessment, lead schedules, tests and financial statement draftingThe engagement team, during the audit
Practice and engagement managementTracks each engagement through its stages, from acceptance and engagement letter to sign-off and archivePartners, managers, practice managers
Document custodyHolds client and auditee documents with who sent them and when, versions, retention dates and legal holdEveryone; ICAG's reviewers when they inspect
Requests for information (PBC lists)Sends the client or auditee a list of what is needed, collects uploads and chases what is lateSeniors and managers
Time and billingTimesheets, charge-out rates, fee notes, work in progressStaff, managers, finance
Internal audit managementAudit universe, risk-based plan, engagements, findings and follow-up of management actionsHeads of internal audit, audit committees

A working-paper tool rarely holds the client's original documents or your fee notes, and a document system rarely knows your ISA methodology. Running two or three side by side works if they share one client and engagement record.

Who needs audit software in Ghana

Audit firms. Every firm practising accountancy is registered and licensed by ICAG under s.41 of the Institute of Chartered Accountants, Ghana Act, 2020 (Act 1058), governed by the ICAG Regulations 2023 (L.I. 2476). The licence runs to 31 December and renewal is not automatic, and every audit report shows the firm's licence number and the signer's practising certificate number.

Internal audit. The mandates come from public finance law and the Bank of Ghana:

SectorWhat requires internal audit
MDAs and MMDAsAn internal audit unit in each, auditing to the Internal Audit Agency's standards and reporting to its Director-General (Internal Audit Agency Act 2003, Act 658, s.16)
Every covered entity under the PFM ActAn internal audit unit reporting administratively to the Principal Spending Officer and functionally to a five-member audit committee (PFM Act 2016, Act 921, ss.83 and 86 to 88)
Banks, savings and loans companies, finance housesA Chief Internal Auditor, independent of the activities audited, reporting directly to the Board's Audit Sub-Committee (Bank of Ghana Corporate Governance Directive 2018)

The Ghanaian requirements that shape the choice

Most demos look alike until you test them against the rules you work under.

  • Licensing a new firm. ICAG asks a new firm for its documented system of quality management under ISQM 1 and 2, evidence of an ISA-compliant audit programme, continuity and succession plans and indemnity cover, then makes an assessment visit. The audit programme is working-paper territory; the quality management documents need a controlled home with versions.
  • Oversight inside ICAG. Reviews run through ICAG's Audit Quality Monitoring department, overseen by the Accountancy Practice Review Committee (APRC), under s.32 of Act 1058; the 2026 directives also name the Public Accountancy Supervisory Committee (PASC). Since August 2026, failing to submit to a review, or obstructing one, is itself misconduct.
  • Repeated findings. Under Directive ICAG/QAM/014/26, a finding against the ISAs, IFRS or the IESBA Code that recurs in two or more consecutive cycles without remediation is referred to the Disciplinary Committee. Ask each vendor where the corrective action plan lives, who owns each action, and how you prove the fix.
  • A wider public interest entity definition. For reviews beginning on or after 1 January 2027, ICAG adds government entities, public utilities and not-for-profits operating with public funds.
  • Standards and file assembly. ICAG has adopted the ISAs in their entirety, with ISQM 1, ISQM 2, ISA 220 (Revised) and the IESBA Code. ISA 230 expects the final file ordinarily within 60 days of the auditor's report; nothing may then be deleted before the retention period ends, and any change records why, when and by whom. ISQM 1 expects annual independence confirmations and an annual evaluation of the system.
  • Auditor tenure. An auditor holds office for no more than six years, and may return only after at least six (Companies Act 2019, s.139(11)). Changes of auditor are routine, and with them acceptance and the communication with the predecessor that the IESBA Code requires (R320.8).
  • Retention. We found no retention period for company accounting records in the Companies Act, which allows electronic records kept in Ghana (s.127). ISA 230 sets an ordinary minimum of five years from the auditor's report, and the Data Protection Act 2012 (Act 843) keeps personal data no longer than necessary unless the law requires or authorises it (s.24). Set retention by document type, not one period for everything.
  • The public sector internal audit cycle. Under s.83 of the PFM Act the internal auditor sends a risk-based annual work plan to the Principal Spending Officer and the audit committee "within thirty days after the beginning of the financial year", then reports quarterly to them, the Auditor-General and the IAA. Audit committees meet at least quarterly and must see that recommendations are acted on (s.88). The IAA publishes manuals for MDAs and for MMDAs and a Risk-Based Internal Audit Manual; your stages should follow the one you use.
  • Follow-up with fixed response times. The Ministry of Finance's Audit Recommendations Implementation and Follow-Up Instructions (30 June 2023) make a follow-up tracking template "the main tool". Management answers draft internal audit reports within ten working days (L.I. 1994, reg 43(2)), draft external audit findings within five working days, and the draft Management Letter within thirty working days. The Audit Service Act 2000 (s.29) gives "30 days" for comments on the Auditor-General's observations, on pain of withheld emoluments. The sources word the period differently, so confirm which applies before you set a timer. If follow-up drives your unit's work, a findings register is a must-have.
  • Data protection and hosting. Data controllers register with the Data Protection Commission and renew every two years. We found no general rule in Act 843 on sending personal data abroad; the one cross-border provision we found, s.18(2), covers data about foreign data subjects sent into Ghana. That is our reading, not advice. Azure has no region in Ghana; its only African regions are in South Africa. Confirm the position with the Commission and your legal team before choosing a hosting model.

The types of audit software provider in Ghana

A search for audit software in Ghana returns few vendor pages, and a search for internal audit software in Ghana returns almost none. These are the kinds of supplier you will meet.

Provider typeExamplesTypical strengthsWatch for
Working-paper softwareCaseWare Africa; AuditFlow Pro, built in GhanaISA methodology, the audit programme, financial statementsClient document custody, request lists and billing are usually elsewhere
Enterprise internal audit and GRC suitesTeamMate+, Diligent HighBond, Ideagen Pentana, AuditBoardFull lifecycle: universe, plan, working papers, findings, follow-upCost, implementation time, local support through partners
Global practice management and client portalsKarbon, TaxDomeWorkflow, time, billing, portalsGhanaian billing practice, data location
Request-list (PBC) toolsSuralink, AuditDashboardClient document requests and chasersStandalone: engagement stages and archive live elsewhere
Microsoft 365 document managementM-Files, Intapp, HubOneDocuments in the Microsoft stackBuilt for general professional services, not audit stages
Spreadsheets and shared drivesIn-houseLow starting costNo audit trail, key-person risk, slow to answer a reviewer

Evaluation criteria

Weight the criteria before the first demo, and score every vendor on the same sheet.

AreaWhat to test
Category fitWhich of the six jobs the product does, and how it works alongside the tools you keep
Review readinessOne engagement's stages, evidence, dates and who completed each, produced for an ICAG reviewer in minutes
Repeated findingsWhere ICAG corrective action plans and remediation evidence are kept, dated and owned
File assembly and retentionAn archive clock from the report date; retention by document type; legal hold; changes after assembly logged
Acceptance and clearanceA clearance wait you set, with the predecessor's reply recorded before the engagement letter; the signed engagement letter required before work starts
Requests for informationClient and auditee uploads without accounts; outstanding items visible; chasers
Internal audit cycleStages that follow the IAA manual; request lists to auditees; a findings register and follow-up if the 2023 Instructions drive your work
Time and feesTimesheets by grade, fee notes with your VAT treatment, work in progress; whether it posts to your accounting system
Hosting and accessWhere data is processed and stored; who at the vendor can reach it and how that is logged
CommercialsThree-year cost, currency, implementation plan, references, exit and data export

How to run the evaluation

  1. Agree the jobs with partners or the head of internal audit, IT and procurement before meeting vendors.
  2. Long-list by category, and drop suppliers that fail a must-have.
  3. Run scripted demos on your own data, the same script for every vendor:
    • an ICAG finding your firm accepted last cycle: show where the corrective action plan sits, who owns it, and the evidence of the fix;
    • a new client whose previous auditor has served six years: acceptance, the clearance letter, and a predecessor who has not replied by the end of your waiting period;
    • an audit report signed today: the file-assembly countdown, the reminders, and what the log shows when someone edits a document afterwards;
    • for an MDA or MMDA, a request list with three late items, a draft report with management's ten-working-day response, and the quarterly report to the audit committee.
  4. Call references of your size, and ask what went wrong.
  5. Score independently, then calibrate as a panel, and keep the sheet with the decision.

What audit software costs in Ghana

Ask every shortlisted vendor to itemise the same lines over three years:

  • Licence or subscription: per user, per engagement, per module, or flat.
  • Implementation: configuring stages and templates, importing clients, migrating files, training.
  • Hosting: the vendor's cloud, your own cloud subscription, or your own servers.
  • Prerequisite licences: Microsoft 365 or other platforms the product depends on.
  • Support and updates, including changes when ICAG, the IAA or the standards move.
  • Currency: US dollars or Ghana cedis, and who carries the exchange-rate risk.
  • Exit: the cost and format of getting your records out.

For AuditEDMS: on Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.

Red flags

  • A working-paper tool sold as a complete practice system, or the reverse, without saying which jobs stay in spreadsheets.
  • No answer to where an ICAG corrective action plan lives, or how you prove the fix before the next review.
  • Documents can be replaced after sign-off with no record of who, when or why.
  • The vendor cannot produce one engagement's full history for a reviewer in minutes.
  • A public-sector demo that cannot follow the IAA manual's stages, or treats follow-up of recommendations as an export to Excel when the 2023 Instructions drive your work.
  • Vague or changing answers on where data is processed, or on who at the vendor can access it.
  • Must-haves answered with roadmap dates.

Where Creodata fits

Creodata is a Nairobi software company, and AuditEDMS covers the middle of the table above (engagement management, document custody and requests for information, with time and billing for firms) and the engagement and follow-up part of internal audit management.

It files every client or auditee document to your own SharePoint by client, engagement and document type, with who sent it, when and how, versioned and checksummed, with retention dates by document type and legal hold. The statutory audit template runs 13 stages from tender to archive, with evidence gates, a clearance timer before the engagement letter that closes early only when the outgoing auditor's reply is recorded, and an archive clock from sign-off. A printable compliance view shows every stage, its evidence, dates and who completed it. Clients and auditees upload through expiring links with a one-time code and no account, against request lists with chasers. An internal audit template, from notification to draft report, management responses, final report and archiving, is ready to use. Templates are configuration, set up with you during implementation.

For follow-up, findings are a register. Each internal audit finding or management letter point holds its severity, recommendation, management's response and the agreed action with owner and due date. The action moves from agreed through in progress to implemented, and is confirmed by someone other than the person who recorded it implemented, or closed as risk accepted with a note; every follow-up is logged with its date. A follow-up register shows open and overdue actions across engagements, which is the tracking the 2023 Instructions ask for and what the audit committee needs each quarter. Action owners are recorded by name: the system does not email them, so reminders are still sent by your unit.

AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint; no client data sits in Creodata's cloud. Creodata operates it with standing management access to the deployment's managed resource group, recorded in your Azure activity log.

At implementation it is set up for Ghana: fees in cedis, 20 percent on each fee note as one line (VAT 15 percent plus NHIL and GETFund at 2.5 percent each under Act 1151), a GRA filing stage, and client records kept six years. It cannot yet itemise VAT, NHIL and GETFund separately on a fee note.

What it does not do: it holds no working papers or audit methodology, so it is not the ISA-compliant audit programme ICAG asks new firms for; keep the tool you use. The findings register follows findings raised on engagements; it is not a register of your firm's own ICAG review findings, so keep ICAG corrective action plans with your quality management documents. It has no audit universe or risk-based annual plan, no timer on management's response period, and no connection to an accounting system. If your unit needs the risk-based plan and working papers in the same system, a full internal audit suite fits better today. See AuditEDMS in Ghana for how each Ghanaian duty maps to a capability.

Frequently asked questions

Does ICAG require audit firms to use audit software?

We found no such requirement. ICAG asks a new firm for evidence of an "ISA compliance audit program", and we found no rule that it must be software. Its reviews look for evidence of what was done, which is far easier to produce from a system than from shared drives.


See how AuditEDMS in Ghana meets these criteria, and request a pilot with your own engagements.

More guides for Ghana

See Audit Management Software in action.