Audit Software in Rwanda: A Buyer's Guide for Audit Firms and Internal Audit (2026)
How to choose audit software in Rwanda: ICPAR quality assurance reviews, ten-year retention, BNR-accredited auditors, public sector internal audit, where personal data may be stored, cost and red flags.

Short answer: In Rwanda, two questions come before features. Where will the system store personal data, given that the law keeps it in Rwanda unless your NCSA registration certificate allows otherwise? And can it keep records for ten years, the period for company accounts, tax records and BNR-accredited auditors' working papers? Then pick the kind of audit software you need and test it on your own files.
This guide is for managing partners and practice managers at ICPAR-registered firms, including those accredited by the National Bank of Rwanda, heads of internal audit and chief audit executives in public entities, districts, banks and listed companies, and the IT, legal and procurement teams who support them.
Creodata sells AuditEDMS, so we say plainly where it fits, and where it does not, near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal or professional advice: confirm requirements with ICPAR, the National Cyber Security Authority (NCSA), BNR or your regulator.
What audit software does
"Audit software" covers several different categories of product, and a vendor that does one well may not do the others at all.
| Category | What it does | Who uses it |
|---|---|---|
| Working papers | Audit methodology, risk assessment, testing, lead schedules, financial statements | The engagement team |
| Practice and engagement management | Tracks each engagement through its stages, from acceptance to sign-off and archive | Partners and managers |
| Document custody | Holds client and auditee documents with who sent them and when, versions, retention dates and legal hold | Everyone; ICPAR and BNR when they ask |
| Requests for information (PBC lists) | Sends a list of what is needed, collects uploads, chases late items | Seniors, managers, internal auditors |
| Time and billing | Timesheets, rates, invoices, work in progress | Staff, managers, finance |
| Internal audit management | Audit universe, risk-based plan, engagements, findings and follow-up of recommendations | Heads of internal audit, audit committees |
Most practices use two or three of these together. Where each one stores its data matters more in Rwanda than in most markets.
Who needs audit software in Rwanda
Audit firms. ICPAR, established by Law N° 11/2008, registers certified public accountants and practising firms, grants practising certificates, monitors standards and disciplines members. Renewal forms for practising certificates are due by 1 December each year. Under the companies law (Law N° 007/2021), every company appoints an external auditor, who must be a member of a recognised institute of chartered accountants (for a firm, every partner); a ministerial order may let some private companies opt out by unanimous resolution. Auditors of banks and other regulated institutions must be accredited by BNR (Regulation N° 44/2022): Tier I firms have at least two partners with ICPAR practising certificates, Tier II firms one, and an appointment lasts three years, extendable by at most two, followed by a three-year cooling-off period.
Internal audit.
| Sector | What requires internal audit |
|---|---|
| Central and decentralised public entities | The Internal Auditor General sets internal audit and risk management standards and coordinates internal auditors; boards and councils follow up recommendations through the audit committee (Organic Law N° 002/2022.OL on public finance management) |
| Banks | A board audit committee and an independent internal audit function (BNR Regulation N° 01/2018; confirm it is still current) |
| Listed companies | An internal audit function with a charter, its head reporting to the audit committee chair, and a plan the audit committee approves (CMA Corporate Governance Code 2024) |
The Office of the Auditor General audits all public-sector entities and may require any document, and the Chief Budget Manager must implement its recommendations. Its 2024 annual report, presented on 9 May 2025, covered 239 entities and reported a 60 percent rate of implementation of recommendations. Following up recommendations is a measured, reported part of public-sector audit in Rwanda.
The Rwandan requirements that shape the choice
- Where personal data is stored. Under Law N° 058/2021 on the protection of personal data and privacy, personal data is stored in Rwanda unless the controller's or processor's NCSA registration certificate authorises storage abroad, and transfers out of Rwanda need authorisation or a contract (Arts. 48 to 50). Controllers and processors register (Art. 29), and a breach is notified to the authority within 48 hours. Audit files are full of personal data: payroll, staff records, customer lists, IDs. Microsoft Azure has no region in Rwanda; its only African regions are in South Africa. So any system on Azure, and many other global clouds, will store data outside the country. That is not necessarily a bar, but it depends on what your registration certificate authorises. Settle this before you shortlist.
- Ten-year retention. Companies keep annual accounts, auditors' and directors' reports for the last ten accounting periods, and minutes and the beneficial ownership register for at least ten years, with records kept in Rwanda (Law 007/2021, Arts. 111 and 121). Tax books and documents are kept ten years from 1 January following the fiscal year (Law N° 020/2023, Art. 15; it was five). Auditors accredited by BNR undertake to keep working papers and audit documents for at least ten years and produce them on request. ISA 230's ordinary minimum for other audit files is five years from the auditor's report. A system has to hold files, and their audit trail, for a decade, and still find them.
- ICPAR quality assurance reviews. There is no independent audit oversight body; ICPAR runs mandatory, risk-based external quality assurance reviews of every firm and practitioner authorised for statutory audit. One cycle covered 50 firms between 2018 and 2021. Expect a reviewer to ask for selected engagement files and the firm's quality policies.
- Standards as issued. ICPAR's founding law adopts the ISAs without modification for all statutory audits, and the IESBA Code is adopted as issued. ISA 230 expects the final audit file to be assembled ordinarily within 60 days of the auditor's report, with any later change recorded: why, when and by whom. Confirm with ICPAR how ISQM 1 applies to your firm.
- Communication with the predecessor. The IESBA Code (R320.8) requires a proposed auditor to ask the existing auditor for facts it needs before accepting. We found no Rwandan deadline for the reply, so the waiting period is your policy. BNR's rotation rules mean bank auditors change regularly, so this step recurs.
- Public sector internal audit. Internal auditors in central and decentralised entities work to the Internal Auditor General's standards, and recommendations are followed up through the audit committee. Test whether a vendor can hold your engagements, your auditee requests and, if you need it, a register of recommendations and their implementation.
For East African neighbours, see our buyer's guides for Kenya, Uganda and Tanzania.
The types of audit software provider in Rwanda
Searches for audit software by Rwanda's name return almost nothing local, so the choice is among global and regional suppliers, and hosting often decides it.
| Provider type | Examples seen in regional searches | Typical strengths | Watch for |
|---|---|---|---|
| Working-paper software | CaseWare Africa; AuditFlow Pro (Excel-based, marketed in Rwanda) | ISA methodology, financial statements | Documents, requests and billing live elsewhere; where cloud files are held |
| Enterprise internal audit and GRC suites | TeamMate+, Diligent HighBond, Ideagen Pentana, AuditBoard | Full lifecycle, including recommendation follow-up | Cost; hosting location; support through partners |
| Regional GRC vendors | Trigarc (East Africa) | Regional regulator settings, findings follow-up | Hosting options; fit for an audit firm's billing |
| Global practice management and PBC tools | Karbon, TaxDome, Suralink | Workflow, portals, request lists | Data stored in the vendor's cloud abroad |
| Locally hosted or on-premises systems | In-house builds, local integrators | Data stays in Rwanda | Maintenance, audit trail, ten-year durability |
| Spreadsheets and shared drives | Common | Low starting cost | No audit trail; files lost across a decade |
Evaluation criteria
| Area | What to test |
|---|---|
| Data location | Exactly where personal data and documents are stored and backed up; whether your NCSA certificate covers that; the vendor's own access |
| Ten-year retention | Periods by document type up to ten years; legal hold; files and history still retrievable after staff and system changes |
| Category fit | Which of the six jobs the product does, and what stays elsewhere |
| Quality review readiness | Each engagement's stages, evidence, dates and sign-offs, printable or exportable for ICPAR or BNR |
| File assembly | An archive clock from the report date; changes after assembly logged |
| Acceptance and clearance | A waiting period you set, with the predecessor's reply recorded before the engagement letter |
| Public sector internal audit | Engagement stages to the Internal Auditor General's standards; requests to auditees; recommendation follow-up if required |
| Breach handling | How the vendor would help you meet the 48-hour notice |
| Commercials | Three-year cost, currency, implementation plan, references, exit and export |
How to run the evaluation
- Ask legal first what your NCSA registration certificate authorises, and make storage location a pass or fail criterion.
- Agree the jobs with partners or the head of internal audit, IT and procurement.
- Run scripted demos on your own data, the same script for each vendor:
- show on screen, or in writing, where a client's uploaded payroll file is stored and backed up;
- a bank audit by a BNR-accredited firm: set a ten-year retention date on its working papers and show them retrieved;
- a client uploads ten years of annual accounts and tax records through a link, each with its retention date;
- a new appointment where the predecessor has not replied by the end of your waiting period;
- a district internal audit engagement with a request list and two late items, and how recommendations are followed up.
- Call references, ideally Rwandan ones, and ask about hosting and support.
- Score independently, then calibrate as a panel, and file the scoring sheet.
What audit software costs in Rwanda
Ask each shortlisted vendor to itemise the same lines over three years:
- Licence or subscription: per user, engagement, module or flat.
- Implementation: configuration, importing clients, migrating files, training, and travel if the team is outside Rwanda.
- Hosting: a cloud abroad, a local data centre, or your own servers, and what each means for your NCSA registration.
- Storage growth: ten years of files add up.
- Prerequisite licences, such as Microsoft 365.
- Support and updates, including standards changes.
- Currency: US dollars or Rwandan francs, and who carries the exchange-rate risk.
- Internal effort and exit costs, including export in a usable format.
For AuditEDMS: on Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.
Red flags
- The vendor cannot say in which country your data is stored, or says "the cloud".
- "Data residency" promised without naming a location in Rwanda.
- Retention capped at five or seven years, or fixed in code.
- Files older than a few years moved to an archive nobody can search.
- No record of who changed a file after assembly.
- A public-sector demo with no way to show recommendations being followed up, if you need that.
- Must-haves answered with roadmap dates.
Where Creodata fits
Creodata is a Nairobi software company, and AuditEDMS covers engagement management, document custody, requests for information, and time and billing for audit, tax and accounting firms, with an internal audit template and a findings register with follow-up for internal audit.
It files every client or auditee document to your own SharePoint by client, engagement and document type, recording who sent it, when and how, versioned and checksummed, with retention dates by document type, so ten-year periods can be set where they apply, and legal hold. The statutory audit template runs 13 stages from tender to archive, with evidence gates, a clearance timer before the engagement letter that waits the period you set and closes early only when the predecessor's reply is recorded, and an archive clock from sign-off. A printable compliance view shows every stage, its evidence, dates and who completed it. Clients and auditees upload through expiring links with a one-time code and no account, against request lists with chasers. An internal audit template, from notification to final report and archiving, is ready to use. Findings, including management letter points, are recorded with severity, recommendation, management's response and an agreed action with owner and due date; each action is followed to implementation and confirmed by someone other than the person who recorded it implemented, and a follow-up register shows what is open and overdue across engagements. That is the record an audit committee needs to follow up recommendations; action owners are recorded by name and are not emailed by the system. Timesheets, milestone billing with VAT, part payments and work in progress are included. Stage templates are set up with you during implementation; at implementation it is set up for Rwanda: fees in francs, VAT at 18 percent, an RRA filing stage, and accounting records kept ten years. Where the deployment runs is still your decision under the data protection law, above.
On hosting, be clear-eyed. AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint; no client data sits in Creodata's cloud. Azure has no region in Rwanda, so AuditEDMS cannot keep data in Rwanda; it fits only if your NCSA registration certificate authorises storage abroad. Creodata operates the deployment and holds standing management access to its managed resource group, and every action it takes is recorded in your Azure activity log.
What it does not do: no working papers or audit methodology, no audit universe or annual plan, no automated reminders to action owners, and no connection to an accounting system or to RRA's systems. See AuditEDMS in Rwanda for how each duty maps to a capability.
Frequently asked questions
Can audit files be stored in the cloud outside Rwanda?
Only where your registration certificate from the NCSA authorises storage abroad; otherwise personal data is stored in Rwanda. Most audit files contain personal data, so ask your legal team before choosing any cloud system hosted elsewhere.
How long must records be kept in Rwanda?
Ten years is common: company accounts and reports for the last ten accounting periods, tax records for ten years, and BNR-accredited auditors' working papers for at least ten. Other audit files follow ISA 230's ordinary minimum of five years from the report, or your firm's longer policy.
See how AuditEDMS in Rwanda meets these criteria, and whether its hosting fits your registration, then request a pilot.