Audit Software in Nigeria: A Buyer's Guide for Audit Firms and Internal Audit (2026)

How to choose audit software in Nigeria: the FRC's Audit Regulations 2020, six-year retention, risk-based internal audit, hosting, types of provider, evaluation criteria, cost and red flags.

CS
Creodata Solutions Team
Audit Software in Nigeria: A Buyer's Guide for Audit Firms and Internal Audit (2026)

Short answer: "Audit software" in Nigeria covers several different products: working papers, engagement and practice management, document custody, client request lists, time and billing, and internal audit management. Decide which of those jobs you need done, then test each vendor against what the FRC's Audit Regulations 2020, ICAN's practice monitoring and your audit committee will ask to see, using scripted demos on your own files.

This guide is for managing partners and practice managers at FRC-registered audit, tax and accounting firms, heads of internal audit in banks, insurers, listed and private companies and federal MDAs, and the IT and procurement teams who support them. It assumes you are replacing shared drives, spreadsheets and email.

Creodata sells AuditEDMS, so we say plainly where it fits, and where it does not, near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal or professional advice: confirm requirements with the FRC, ICAN or your regulator.

What audit software does

Buyers often compare products that do different jobs. These are separate categories, and few products do all of them well.

CategoryWhat it doesWho uses it
Working papersAudit methodology, risk assessment, lead schedules, tests and financial statement draftingThe engagement team, during the audit
Practice and engagement managementTracks each engagement through its stages, from acceptance and engagement letter to sign-off and file closePartners, managers, practice managers
Document custodyHolds client and auditee documents with who sent them and when, versions, retention dates and legal holdEveryone; FRC and ICAN inspectors when they review
Requests for information (PBC or request lists)Sends the client or auditee a list of what is needed, collects uploads and chases what is lateSeniors and managers
Time and billingTimesheets, charge-out rates, fee notes or invoices, work in progressStaff, managers, finance
Internal audit managementAudit universe, risk-based plan, engagements, findings and follow-up of management actionsHeads of internal audit, audit committees

Many firms run two or three of these side by side, which works if they share one client and engagement record.

Who needs audit software in Nigeria

Audit firms. Every auditor, audit firm, audit committee member and other assurance services provider must register with the Financial Reporting Council of Nigeria (Audit Regulations 2020, reg. 3), and the FRC now publishes a National Register of Audit Firms, updated weekly. Every company appoints an auditor at each annual general meeting (CAMA 2020, s.401). Small private companies within the s.394 thresholds are exempt from audit, but never banks or insurers (s.402). ICAN reviews its members' practice firms and issues practice licences.

Internal audit. In Nigeria, the audit regulator's own instrument requires internal audit in every company.

WhoWhat requires internal audit
Every company"All companies shall have an effective risk-based Internal Audit function" (Audit Regulations 2020, reg. 30). A board that decides against one must explain why in the annual report
Companies following the governance codePrinciple 18 of the Nigerian Code of Corporate Governance 2018: a charter, a head in senior management, quarterly reporting to the audit committee, applied on an "Apply and Explain" basis
Public companiesA statutory audit committee of five, which reviews the scope and planning of audit requirements and may authorise the internal auditor to investigate (CAMA s.404)
Federal MDAsInternal audit units reporting monthly, quarterly, half-yearly and annually to management, the Accountant-General and the Auditor-General for the Federation, as the Office of the Secretary to the Government of the Federation describes its own unit

Banks and insurers carry the same duty, alongside their own regulator's rules.

The Nigerian requirements that shape the choice

Most demos look alike until you test them against the rules you work under.

  • The Audit Regulations 2020. Gazetted on 26 January 2024 as S.I. No. 36, and in force since 1 January 2021, the FRC's instrument covers registration, rotation, the audit file, quality management and internal audit in one place.
  • One audit file, closed within 60 days. The auditor creates an audit file for each statutory audit and closes it "not later than 60 days after the date of signing of the Audit report" (reg. 10). Under ISA 230, nothing may then be deleted before the retention period ends, and any later change records why, when and by whom. A system should count down from the signed report and log every change after close.
  • Six years, from different start dates. Working papers, memoranda, correspondence and other records, "including electronic records", are kept at least six years (reg. 13). Companies keep accounting records six years from the date they were made (CAMA s.375), and the Nigeria Tax Administration Act 2025 requires books to be kept not less than six years after the year of assessment (s.31). The period is similar; the clock is not. Retention should be set by document type, with a legal hold.
  • More than working papers. Regulation 10 also requires a record of each client's key audit partners and fees, and of breaches, complaints and experts' advice. Ask where each lives in the product.
  • ISQM and a fixed inspection cycle. Every firm must run a quality management system that complies with ISQM as issued by the IAASB. The FRC inspects firms auditing more than 20 public interest entities every year and others every three years, reviews each engagement partner at least every six years, and may order a special review at any time (regs 21 and 23). ICAN monitors non-PIE auditors under delegation (reg. 24). Software should make one engagement's history quick to produce for a quality assurance review.
  • Rotation and irregularities. For PIE audits, a firm serves at most ten continuous years, or 15 under a joint audit, and engagement partners rotate after at most five (reg. 9). Irregularities an external auditor observes must be reported to the FRC within 30 days (reg. 8). Decide whether software should track these or your quality manual.
  • Professional clearance. The IESBA Code (R320.8), which ICAN has adopted directly since 2018, requires a proposed auditor to ask the predecessor for any facts it needs before accepting. The software should let you set a waiting period and record whether a reply came.
  • Risk-based internal audit. Regulation 30 requires a board-approved charter, a head registered with the FRC or the relevant regulator who reports to the audit committee at least quarterly, an approved annual risk-based plan, and an external assessment "at least once every three years". That is more often than the IIA's five-year minimum. If you need the plan and findings follow-up in software, test for them.
  • Data protection and hosting. Under the Nigeria Data Protection Act 2023 and the NDPC's implementation directive (GAID), every data controller and processor carries out a compliance audit each year, and those "of major importance" file compliance audit returns. Cross-border transfers fall under Part VIII of the Act, and until the NDPC issues transfer guidelines, adequacy is judged under the directive's Schedule 3. Azure has no region in Nigeria; its only African regions are South Africa North and South Africa West. Confirm your own position with your data protection officer before you choose a hosting model.

The types of audit software provider in Nigeria

A search for audit software in Nigeria returns a few local vendors, global suites and blog lists. These are the kinds of supplier you will meet.

Provider typeExamples seen in Nigerian searchesTypical strengthsWatch for
Working-paper softwareCaseWare Africa; PML AuditmateISA methodology, lead schedules, financial statementsClient document custody, request lists and billing are usually elsewhere
Local internal audit systemsPML's Laser Audit Reporting System (LARS)Planning, audit programmes, work papers, auditor and auditee coordination, local presenceFit for an external audit firm's engagements and billing
Enterprise internal audit and GRC suitesTeamMate+, Ideagen Pentana, AuditBoardFull lifecycle: universe, plan, working papers, findings, follow-upCost, implementation time, local support through partners
Nigerian practice managementPraktaTax and compliance deadlines for NRS and state revenue services, document requestsAudit engagement stages, file close and custody
Global practice managementIRIS, Uku, SageWorkflow, time, billing, portalsNigerian billing practice, data location
Request-list (PBC) toolsSuralink, AuditDashboardClient document requests and chasersStandalone: engagement stages and file close live elsewhere
Spreadsheets and shared drivesMost small firmsLow starting costNo audit trail, key-person risk, slow to answer an inspector

Evaluation criteria

Weight the criteria before the first demo, and score every vendor on the same sheet.

AreaWhat to test
Category fitWhich of the six jobs the product does, and how it works alongside the tools you keep
Inspection readinessA per-engagement record of stages, evidence, dates and who completed each, ready for an FRC inspection or ICAN monitoring visit
File close and retentionA countdown from the signed report to your 60-day close; retention by document type with the right start date; legal hold; changes after close logged
Regulation 10 recordsWhere key audit partners, fees by service, complaints, breaches and experts' advice are kept
Clearance and acceptanceA clearance wait you set, with the reply recorded before the engagement letter; the signed engagement letter required before work starts
Requests for informationClient and auditee uploads without accounts; outstanding items visible; chasers
Internal auditStages for your methodology; request lists to auditees; a findings register with management's actions followed to implementation; the risk-based plan if you need it in the same tool
Time and feesTimesheets by grade, billing with VAT, work in progress; whether it posts to your accounting system
Hosting and accessWhere data is processed and stored; who at the vendor can reach it and how that is logged; fit with your NDPA assessment
CommercialsThree-year cost, currency, implementation plan, references, exit and data export

How to run the evaluation

  1. Agree the jobs with partners or the head of internal audit, IT and procurement before meeting vendors.
  2. Long-list by category, and drop suppliers that fail a must-have.
  3. Run scripted demos on your own data, the same script for every vendor:
    • an audit report signed today: show the 60-day countdown, the reminders, and what the log shows when someone edits a document after the file closes;
    • a client that uploads a trial balance, bank statements and a tax computation through a link, and the retention date and start date each gets;
    • an outgoing auditor who has not replied to your clearance letter by the end of your firm's waiting period;
    • an FRC inspector asking for one engagement's full history, and for the client's key audit partners and fees;
    • for internal audit, a request list to a branch with three late items, and the evidence behind a quarterly report to the audit committee.
  4. Call references of your size, and ask what went wrong.
  5. Score independently, then calibrate as a panel, and keep the sheet with the decision.

What audit software costs in Nigeria

Ask every shortlisted vendor to itemise the same lines over three years:

  • Licence or subscription: per user, per engagement, per module, or flat.
  • Implementation: configuration of your stages and templates, importing clients, migrating existing files, training.
  • Hosting: the vendor's cloud, your own cloud subscription, or your own servers.
  • Prerequisite licences: Microsoft 365 or other platforms the product depends on.
  • Support and updates, including changes when the FRC or the standards move.
  • Currency: US dollars or naira, and who carries the exchange-rate risk.
  • Internal effort: your staff's time during set-up and migration.
  • Exit: the cost and format of getting your records out.

For AuditEDMS: on Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.

Red flags

  • A working-paper tool sold as a complete practice system, or the reverse, without saying which jobs stay in spreadsheets.
  • No countdown from the signed report, or a file that can still be changed after close with no record of who, when or why.
  • One retention period for every document, or retention that deletes files without a hold.
  • Clearance is a tick-box with no date, no waiting period and no record of the reply.
  • The vendor cannot produce one engagement's full history for an inspector in minutes.
  • Vague or changing answers on where data is processed, or on who at the vendor can access it.
  • Must-haves answered with roadmap dates.

Where Creodata fits

Creodata is a Nairobi software company, and AuditEDMS covers the middle of the table above (engagement management, document custody, requests for information, and time and billing) and the engagement and follow-up part of internal audit management.

It keeps every client or auditee document in your own SharePoint, filed by client, engagement and document type with who sent it, when and how, versioned and checksummed, with retention dates by document type and legal hold. The statutory audit template runs 13 stages from tender to archive, with evidence gates that stop a stage completing until its document is filed, a clearance timer before the engagement letter that waits the period you set and closes early only when the outgoing auditor's reply is recorded, and an archive clock from sign-off to your file-close deadline, 45 days by default with a ceiling of 60. A printable compliance view shows every stage, its evidence, dates and who completed it. Clients and auditees upload through expiring links with a one-time code and no account, against request lists with chasers. An internal audit template, from notification to final report and archiving, is ready to use. Findings, including management letter points, are recorded with severity, recommendation, management's response and an agreed action with owner and due date; each action is followed to implementation and confirmed by someone other than the person who recorded it implemented, and a follow-up register shows what is open and overdue for the quarterly report to the audit committee. Timesheets, rates by grade, milestone fee notes with VAT, part payments and work in progress are included. Templates are configuration, set up with you during implementation.

The deployment is set up for Nigeria at implementation: fee notes in naira with VAT at 7.5 percent, a rate we confirm with you at implementation, a tax template whose filing stage records the return filed with the tax authority, and retention defaults of six years for working papers (FRC Audit Regulations 2020, reg. 13) and six years for company accounting records (CAMA s.375).

AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint; no client data sits in Creodata's cloud. Creodata operates it and holds standing management access to the deployment's managed resource group, and every action it takes is recorded in your Azure activity log.

What it does not do: it holds no working papers or audit methodology, so keep CaseWare, Auditmate or whatever you use. It has no audit universe or risk-based annual plan, which matters for a regulation 30 function, and it does not email action owners about their actions. It does not connect to an accounting system, does not track firm or partner rotation, and does not track NRS or state tax filing deadlines for your clients. If your internal audit function needs the risk-based plan and working papers in one system now, a full internal audit suite fits better today. See AuditEDMS in Nigeria for how each Nigerian duty maps to a capability.

Frequently asked questions

Does the FRC require audit firms to use audit software?

We found no such requirement in the Audit Regulations 2020. But inspectors look for evidence of who did what and when, which is far easier to produce from a system than from shared drives.

Does every Nigerian company need internal audit?

Regulation 30 says all companies shall have an effective risk-based internal audit function. A board that decides not to have one must give its reasons in the annual report, so the choice is to comply or explain it in public.


See how AuditEDMS in Nigeria meets these criteria, and request a pilot with your own engagements.

More guides for Nigeria

See Audit Management Software in action.