Audit Software in Rwanda: A Buyer's Guide for Audit Firms and Internal Audit (2026)

How to choose audit software in Rwanda: ICPAR quality assurance reviews, ten-year retention, BNR-accredited auditors, public sector internal audit, where personal data may be stored, cost and red flags.

CS
Creodata Solutions Team
Audit Software in Rwanda: A Buyer's Guide for Audit Firms and Internal Audit (2026)

Short answer: In Rwanda, two questions come before features. Where will the system store personal data, given that the law keeps it in Rwanda unless your NCSA registration certificate allows otherwise? And can it keep records for ten years, the period for company accounts, tax records and BNR-accredited auditors' working papers? Then pick the kind of audit software you need and test it on your own files.

This guide is for managing partners and practice managers at ICPAR-registered firms, including those accredited by the National Bank of Rwanda, heads of internal audit and chief audit executives in public entities, districts, banks and listed companies, and the IT, legal and procurement teams who support them.

Creodata sells AuditEDMS, so we say plainly where it fits, and where it does not, near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal or professional advice: confirm requirements with ICPAR, the National Cyber Security Authority (NCSA), BNR or your regulator.

What audit software does

"Audit software" covers several different categories of product, and a vendor that does one well may not do the others at all.

CategoryWhat it doesWho uses it
Working papersAudit methodology, risk assessment, testing, lead schedules, financial statementsThe engagement team
Practice and engagement managementTracks each engagement through its stages, from acceptance to sign-off and archivePartners and managers
Document custodyHolds client and auditee documents with who sent them and when, versions, retention dates and legal holdEveryone; ICPAR and BNR when they ask
Requests for information (PBC lists)Sends a list of what is needed, collects uploads, chases late itemsSeniors, managers, internal auditors
Time and billingTimesheets, rates, invoices, work in progressStaff, managers, finance
Internal audit managementAudit universe, risk-based plan, engagements, findings and follow-up of recommendationsHeads of internal audit, audit committees

Most practices use two or three of these together. Where each one stores its data matters more in Rwanda than in most markets.

Who needs audit software in Rwanda

Audit firms. ICPAR, established by Law N° 11/2008, registers certified public accountants and practising firms, grants practising certificates, monitors standards and disciplines members. Renewal forms for practising certificates are due by 1 December each year. Under the companies law (Law N° 007/2021), every company appoints an external auditor, who must be a member of a recognised institute of chartered accountants (for a firm, every partner); a ministerial order may let some private companies opt out by unanimous resolution. Auditors of banks and other regulated institutions must be accredited by BNR (Regulation N° 44/2022): Tier I firms have at least two partners with ICPAR practising certificates, Tier II firms one, and an appointment lasts three years, extendable by at most two, followed by a three-year cooling-off period.

Internal audit.

SectorWhat requires internal audit
Central and decentralised public entitiesThe Internal Auditor General sets internal audit and risk management standards and coordinates internal auditors; boards and councils follow up recommendations through the audit committee (Organic Law N° 002/2022.OL on public finance management)
BanksA board audit committee and an independent internal audit function (BNR Regulation N° 01/2018; confirm it is still current)
Listed companiesAn internal audit function with a charter, its head reporting to the audit committee chair, and a plan the audit committee approves (CMA Corporate Governance Code 2024)

The Office of the Auditor General audits all public-sector entities and may require any document, and the Chief Budget Manager must implement its recommendations. Its 2024 annual report, presented on 9 May 2025, covered 239 entities and reported a 60 percent rate of implementation of recommendations. Following up recommendations is a measured, reported part of public-sector audit in Rwanda.

The Rwandan requirements that shape the choice

  • Where personal data is stored. Under Law N° 058/2021 on the protection of personal data and privacy, personal data is stored in Rwanda unless the controller's or processor's NCSA registration certificate authorises storage abroad, and transfers out of Rwanda need authorisation or a contract (Arts. 48 to 50). Controllers and processors register (Art. 29), and a breach is notified to the authority within 48 hours. Audit files are full of personal data: payroll, staff records, customer lists, IDs. Microsoft Azure has no region in Rwanda; its only African regions are in South Africa. So any system on Azure, and many other global clouds, will store data outside the country. That is not necessarily a bar, but it depends on what your registration certificate authorises. Settle this before you shortlist.
  • Ten-year retention. Companies keep annual accounts, auditors' and directors' reports for the last ten accounting periods, and minutes and the beneficial ownership register for at least ten years, with records kept in Rwanda (Law 007/2021, Arts. 111 and 121). Tax books and documents are kept ten years from 1 January following the fiscal year (Law N° 020/2023, Art. 15; it was five). Auditors accredited by BNR undertake to keep working papers and audit documents for at least ten years and produce them on request. ISA 230's ordinary minimum for other audit files is five years from the auditor's report. A system has to hold files, and their audit trail, for a decade, and still find them.
  • ICPAR quality assurance reviews. There is no independent audit oversight body; ICPAR runs mandatory, risk-based external quality assurance reviews of every firm and practitioner authorised for statutory audit. One cycle covered 50 firms between 2018 and 2021. Expect a reviewer to ask for selected engagement files and the firm's quality policies.
  • Standards as issued. ICPAR's founding law adopts the ISAs without modification for all statutory audits, and the IESBA Code is adopted as issued. ISA 230 expects the final audit file to be assembled ordinarily within 60 days of the auditor's report, with any later change recorded: why, when and by whom. Confirm with ICPAR how ISQM 1 applies to your firm.
  • Communication with the predecessor. The IESBA Code (R320.8) requires a proposed auditor to ask the existing auditor for facts it needs before accepting. We found no Rwandan deadline for the reply, so the waiting period is your policy. BNR's rotation rules mean bank auditors change regularly, so this step recurs.
  • Public sector internal audit. Internal auditors in central and decentralised entities work to the Internal Auditor General's standards, and recommendations are followed up through the audit committee. Test whether a vendor can hold your engagements, your auditee requests and, if you need it, a register of recommendations and their implementation.

For East African neighbours, see our buyer's guides for Kenya, Uganda and Tanzania.

The types of audit software provider in Rwanda

Searches for audit software by Rwanda's name return almost nothing local, so the choice is among global and regional suppliers, and hosting often decides it.

Provider typeExamples seen in regional searchesTypical strengthsWatch for
Working-paper softwareCaseWare Africa; AuditFlow Pro (Excel-based, marketed in Rwanda)ISA methodology, financial statementsDocuments, requests and billing live elsewhere; where cloud files are held
Enterprise internal audit and GRC suitesTeamMate+, Diligent HighBond, Ideagen Pentana, AuditBoardFull lifecycle, including recommendation follow-upCost; hosting location; support through partners
Regional GRC vendorsTrigarc (East Africa)Regional regulator settings, findings follow-upHosting options; fit for an audit firm's billing
Global practice management and PBC toolsKarbon, TaxDome, SuralinkWorkflow, portals, request listsData stored in the vendor's cloud abroad
Locally hosted or on-premises systemsIn-house builds, local integratorsData stays in RwandaMaintenance, audit trail, ten-year durability
Spreadsheets and shared drivesCommonLow starting costNo audit trail; files lost across a decade

Evaluation criteria

AreaWhat to test
Data locationExactly where personal data and documents are stored and backed up; whether your NCSA certificate covers that; the vendor's own access
Ten-year retentionPeriods by document type up to ten years; legal hold; files and history still retrievable after staff and system changes
Category fitWhich of the six jobs the product does, and what stays elsewhere
Quality review readinessEach engagement's stages, evidence, dates and sign-offs, printable or exportable for ICPAR or BNR
File assemblyAn archive clock from the report date; changes after assembly logged
Acceptance and clearanceA waiting period you set, with the predecessor's reply recorded before the engagement letter
Public sector internal auditEngagement stages to the Internal Auditor General's standards; requests to auditees; recommendation follow-up if required
Breach handlingHow the vendor would help you meet the 48-hour notice
CommercialsThree-year cost, currency, implementation plan, references, exit and export

How to run the evaluation

  1. Ask legal first what your NCSA registration certificate authorises, and make storage location a pass or fail criterion.
  2. Agree the jobs with partners or the head of internal audit, IT and procurement.
  3. Run scripted demos on your own data, the same script for each vendor:
    • show on screen, or in writing, where a client's uploaded payroll file is stored and backed up;
    • a bank audit by a BNR-accredited firm: set a ten-year retention date on its working papers and show them retrieved;
    • a client uploads ten years of annual accounts and tax records through a link, each with its retention date;
    • a new appointment where the predecessor has not replied by the end of your waiting period;
    • a district internal audit engagement with a request list and two late items, and how recommendations are followed up.
  4. Call references, ideally Rwandan ones, and ask about hosting and support.
  5. Score independently, then calibrate as a panel, and file the scoring sheet.

What audit software costs in Rwanda

Ask each shortlisted vendor to itemise the same lines over three years:

  • Licence or subscription: per user, engagement, module or flat.
  • Implementation: configuration, importing clients, migrating files, training, and travel if the team is outside Rwanda.
  • Hosting: a cloud abroad, a local data centre, or your own servers, and what each means for your NCSA registration.
  • Storage growth: ten years of files add up.
  • Prerequisite licences, such as Microsoft 365.
  • Support and updates, including standards changes.
  • Currency: US dollars or Rwandan francs, and who carries the exchange-rate risk.
  • Internal effort and exit costs, including export in a usable format.

For AuditEDMS: on Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.

Red flags

  • The vendor cannot say in which country your data is stored, or says "the cloud".
  • "Data residency" promised without naming a location in Rwanda.
  • Retention capped at five or seven years, or fixed in code.
  • Files older than a few years moved to an archive nobody can search.
  • No record of who changed a file after assembly.
  • A public-sector demo with no way to show recommendations being followed up, if you need that.
  • Must-haves answered with roadmap dates.

Where Creodata fits

Creodata is a Nairobi software company, and AuditEDMS covers engagement management, document custody, requests for information, and time and billing for audit, tax and accounting firms, with an internal audit template and a findings register with follow-up for internal audit.

It files every client or auditee document to your own SharePoint by client, engagement and document type, recording who sent it, when and how, versioned and checksummed, with retention dates by document type, so ten-year periods can be set where they apply, and legal hold. The statutory audit template runs 13 stages from tender to archive, with evidence gates, a clearance timer before the engagement letter that waits the period you set and closes early only when the predecessor's reply is recorded, and an archive clock from sign-off. A printable compliance view shows every stage, its evidence, dates and who completed it. Clients and auditees upload through expiring links with a one-time code and no account, against request lists with chasers. An internal audit template, from notification to final report and archiving, is ready to use. Findings, including management letter points, are recorded with severity, recommendation, management's response and an agreed action with owner and due date; each action is followed to implementation and confirmed by someone other than the person who recorded it implemented, and a follow-up register shows what is open and overdue across engagements. That is the record an audit committee needs to follow up recommendations; action owners are recorded by name and are not emailed by the system. Timesheets, milestone billing with VAT, part payments and work in progress are included. Stage templates are set up with you during implementation; at implementation it is set up for Rwanda: fees in francs, VAT at 18 percent, an RRA filing stage, and accounting records kept ten years. Where the deployment runs is still your decision under the data protection law, above.

On hosting, be clear-eyed. AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint; no client data sits in Creodata's cloud. Azure has no region in Rwanda, so AuditEDMS cannot keep data in Rwanda; it fits only if your NCSA registration certificate authorises storage abroad. Creodata operates the deployment and holds standing management access to its managed resource group, and every action it takes is recorded in your Azure activity log.

What it does not do: no working papers or audit methodology, no audit universe or annual plan, no automated reminders to action owners, and no connection to an accounting system or to RRA's systems. See AuditEDMS in Rwanda for how each duty maps to a capability.

Frequently asked questions

Can audit files be stored in the cloud outside Rwanda?

Only where your registration certificate from the NCSA authorises storage abroad; otherwise personal data is stored in Rwanda. Most audit files contain personal data, so ask your legal team before choosing any cloud system hosted elsewhere.

How long must records be kept in Rwanda?

Ten years is common: company accounts and reports for the last ten accounting periods, tax records for ten years, and BNR-accredited auditors' working papers for at least ten. Other audit files follow ISA 230's ordinary minimum of five years from the report, or your firm's longer policy.


See how AuditEDMS in Rwanda meets these criteria, and whether its hosting fits your registration, then request a pilot.

More guides for Rwanda

See Audit Management Software in action.