Audit Software in South Africa: A Buyer's Guide for Audit Firms and Internal Audit (2026)
How to choose audit software in South Africa: IRBA inspections and Rule 4's 60-day file assembly limit, retention periods, the PFMA and MFMA internal audit mandates, POPIA and hosting, provider types, cost and red flags.

Short answer: "Audit software" in South Africa covers several different products: working papers and financial statement drafting, practice and engagement management, document custody and archiving, client request lists, time and billing, and internal audit management. Decide which jobs you need done, then test each vendor against what IRBA's inspectors, Rule 4's 60-day limit and the PFMA or MFMA will ask to see, using your own files.
This guide is for partners and practice managers at IRBA-registered firms and accounting practices, heads of internal audit in departments, municipalities and companies, and the IT and procurement teams who support them.
Creodata sells AuditEDMS, so we say plainly where it fits, and where it does not, near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal or professional advice: confirm requirements with IRBA, National Treasury or your regulator.
What audit software does
Buyers often compare products that do different jobs, and few products do all of them well.
| Category | What it does | Who uses it |
|---|---|---|
| Working papers and financial statements | Audit methodology, risk assessment, lead schedules, tests, and drafting the annual financial statements | The engagement team, during the audit or review |
| Practice and engagement management | Tracks each engagement through its stages, from acceptance and engagement letter to sign-off and archive | Partners, managers, practice managers |
| Document custody and archiving | Holds client and auditee documents with who sent them and when, versions, retention dates, legal hold and the file-assembly deadline | Everyone; IRBA's inspectors when they call |
| Requests for information (PBC lists) | Sends the client or auditee a list of what is needed, collects uploads and chases what is late | Seniors and managers |
| Time and billing | Timesheets, charge-out rates, invoices, work in progress | Staff, managers, finance |
| Internal audit management | Audit universe, risk-based plan, engagements, findings and follow-up of management actions | Heads of internal audit, audit committees |
Many practices run two or three of these side by side, which is fine if they share one client and engagement record.
Who needs audit software in South Africa
Audit firms and accounting practices. IRBA had 3,472 registered auditors at 31 March 2025, down from 3,601 two years earlier. Public companies must be audited. A private company must be audited if its public interest score is 350 or more, or 100 or more where it compiles its statements internally, or if it holds fiduciary assets of more than R5 million; otherwise it may be audited voluntarily or independently reviewed under regulation 29 (Companies Act s.30; CIPC). Many practices run audits, reviews, tax and bookkeeping for the same clients, which is where one client file pays off.
Internal audit. The mandates come from public finance law and company law:
| Sector | What requires internal audit |
|---|---|
| National and provincial departments and public entities | The accounting officer keeps a system of internal audit under an audit committee (PFMA s.38); every institution under the Treasury Regulations must have an internal audit function, which may be contracted out in part or in whole (regs 3.2.2 to 3.2.4) |
| Municipalities and municipal entities | An internal audit unit that prepares a risk-based audit plan and an internal audit programme each year and reports to the audit committee; it may be outsourced while capacity is built (MFMA ss.165 and 166) |
| Public and state-owned companies | An audit committee of at least three members elected at each annual general meeting (Companies Act s.94), with the Banks Act rules alongside for banks |
| Companies applying King V | Principle 12: a board-approved internal audit charter, a chief audit executive reporting to the audit committee chair, and a risk-based internal audit plan |
The South African requirements that shape the choice
Most demos look alike until you test them against the rules you work under.
- IRBA inspections. The Auditing Profession Act lets IRBA inspect a registered auditor's practice at any time and copy working papers, correspondence and other documents. It must inspect or review the practice of an auditor of a public company at least every three years, and confidentiality is no ground to refuse (s.47). In 2024/25 IRBA carried out 20 firm-wide and 72 engagement inspections at 25 firms.
- Rule 4's 60-day limit. IRBA's Rule 4 says assembling the final engagement file "shall not exceed 60 calendar days after the date of the engagement report". It applies to audits of periods beginning on or after 15 December 2024, so many reports signed in 2026 fall under it. Where ISA 230 says "ordinarily", Rule 4 sets a limit. A system should count down from the report date, escalate, and record the day the file was assembled.
- Archiving is an inspection theme. In 2024 IRBA ran 18 theme-based inspections across nine firms, reviewing 118 engagement files; half found one or more deficiencies, and archiving of engagement files was one of the five themes. The share of inspected files needing significant improvement or referred for investigation fell from 62 percent in 2019 to 55 percent in 2024. Our article on IRBA's archiving findings sets out a 60-day checklist.
- Changes after assembly. ISA 230 forbids deleting documentation before its retention period ends, and any later change must record the reasons, when it was made and reviewed, and by whom (paras 15 and 16). Test what the log shows when someone edits an assembled file.
- Quality management. South Africa adopted the ISAs without modification and has applied ISQM 1 and 2 since 15 December 2022. IRBA's 2024 report found "Firms' monitoring of their SOQMs was not performed as required by ISQM 1", with gaps in documenting risk assessment and monitoring results. Rules 1 to 3 apply from 15 December 2025, and Rule 4 keeps the system's documentation for at least five years. Ask where the evaluation and independence confirmations will live, and whether each engagement's history can be produced for the file reviews that feed the evaluation.
- Retention periods that differ by record. Engagement documentation: at least five years from the report (Rule 4). Company accounting records, annual financial statements, and directors' and audit committee minutes: seven years (Companies Act s.24). Tax records: five years from the date the return was submitted, longer while a SARS audit, objection or appeal is under way (Tax Administration Act ss.29 and 32). One retention period for every document will be wrong for some of them.
- Rotation and change of auditor. Mandatory audit firm rotation was set aside in 2023, but an individual may not audit a company for more than five consecutive years (Companies Act s.92). When a client changes auditor, the IESBA Code (R320.8) requires the proposed auditor to ask the predecessor for relevant facts before accepting. Software should let you set the wait and record the reply.
- The public sector. On material irregularities the Auditor-General can impose binding remedial action and issue a certificate of debt where it is not taken, so a unit's dated evidence of what it found, and when management responded, matters.
- POPIA and hosting. Personal information may go to a third party abroad only under conditions such as adequate law, binding corporate rules or a binding agreement, the data subject's consent, or a contract that needs it (s.72). Azure has two regions in the country: South Africa North in Johannesburg, and South Africa West in Cape Town, which has restricted access. Hosting in South Africa may not settle the question if the vendor reaches the data from abroad; ask who can access it, from where, and how that is logged.
The types of audit software provider in South Africa
A search for accounting practice management software in South Africa returns directories and several local vendors; a search for audit file archiving software returns generic archiving products. These are the kinds of supplier you will meet.
| Provider type | Examples seen in South African searches | Typical strengths | Watch for |
|---|---|---|---|
| Working papers and financial statements | CaseWare Africa, Draftworx, IT Mates AuditMate | ISA methodology, lead schedules, annual financial statements | Client document custody, request lists and archive deadlines are usually elsewhere |
| Accounting practice management | Fintura, SmartPractice, GreatSoft (which now calls itself CRM for accountants), DataGrows, Xero Practice Manager, Karbon | Jobs, time, billing, CIPC and SARS deadlines, client records | Audit stages, the 60-day assembly clock and a record of changes after assembly |
| Enterprise internal audit and GRC suites | BarnOwl, TeamMate+, Diligent HighBond, Ideagen Internal Audit (formerly Pentana), AuditBoard | Full lifecycle: universe, plan, findings, follow-up, combined assurance reporting | Cost, implementation time, fit for a small internal audit unit |
| Request-list (PBC) tools | Suralink, AuditDashboard | Client document requests and chasers | Standalone: engagement stages and archive live elsewhere |
| Microsoft 365 document management | M-Files, Intapp, HubOne | Documents in the Microsoft stack | Built for general professional services, not audit stages |
| Spreadsheets and shared drives | Most small practices | Low starting cost | No audit trail, key-person risk, slow to answer an inspector |
Evaluation criteria
Weight the criteria before the first demo, and score every vendor on the same sheet.
| Area | What to test |
|---|---|
| Category fit | Which of the six jobs the product does, and how it works alongside the tools you keep |
| Rule 4 readiness | A countdown from the report date to your deadline, inside 60 calendar days; reminders and escalation; the assembly date recorded |
| Changes after assembly | Versions kept, nothing silently overwritten, and every later change logged with who, when and why |
| Inspection readiness | One engagement's stages, evidence, dates and who completed each, produced for an IRBA inspector in minutes |
| Retention | Retention by document type (five, seven and five years above); legal hold for a file under dispute or a SARS objection |
| Acceptance and change of auditor | A wait you set for the predecessor's reply, with the reply recorded before the engagement letter; the signed engagement letter required before work starts |
| Requests for information | Client and auditee uploads without accounts; outstanding items visible; chasers |
| Internal audit | Stages for your methodology; request lists to auditees; a findings register with management's actions followed to implementation; a risk-based plan if you need it in the same tool |
| Time and fees | Timesheets by grade, invoices with South African VAT, work in progress; whether it posts to your accounting system |
| Hosting and access | Azure or other region; who at the vendor can reach the data, from which country, and how that is logged for your POPIA assessment |
| Commercials | Three-year cost, currency, implementation plan, references, exit and data export |
How to run the evaluation
- Agree the jobs with partners or the head of internal audit, IT and procurement, and long-list by category.
- Drop suppliers that fail a must-have.
- Run scripted demos on your own data, the same script for every vendor:
- an audit report signed today: show the countdown to your Rule 4 deadline, the reminders, and what the log shows when a manager edits a document on day 70;
- a client that uploads a trial balance, bank statements and a tax return through a link, and the retention date each gets;
- a new client whose previous auditor has not replied by the end of your firm's waiting period;
- an IRBA inspector asking for one engagement's history and your latest quality management monitoring results;
- for a municipality, a request list with three late items and a draft report awaiting management responses.
- Call references of your size, and ask what went wrong.
- Score independently, then calibrate as a panel, and keep the sheet with the decision.
What audit software costs in South Africa
Ask every shortlisted vendor to itemise the same lines over three years:
- Licence or subscription: per user, per client, per engagement, per module, or flat.
- Implementation: configuring your stages and templates, importing clients, migrating existing files, training.
- Hosting: the vendor's cloud, your own cloud subscription, or your own servers.
- Prerequisite licences: Microsoft 365 or other platforms the product depends on.
- Support and updates, including changes when IRBA, National Treasury or the standards move.
- Currency: rand or US dollars, and who carries the exchange-rate risk.
- Exit: the cost and format of getting your records out.
For AuditEDMS: on Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.
Red flags
- A practice management or working-paper tool sold as the whole answer, without saying which jobs stay in spreadsheets.
- No clock from the report date, or a clock that treats 60 days as a guideline rather than IRBA's limit.
- Documents can be replaced after assembly with no record of who, when or why.
- The vendor cannot produce one engagement's full history for an inspector in minutes.
- "Hosted in South Africa" offered as the whole answer to POPIA, with no account of who at the vendor can reach the data from where.
- Must-haves answered with roadmap dates.
Where Creodata fits
Creodata is a Nairobi software company, and AuditEDMS covers the middle of the table above: engagement management, document custody and archiving, and requests for information, with timesheets and work in progress, and the engagement and follow-up part of internal audit management.
It keeps every client or auditee document in your own SharePoint, filed by client, engagement and document type with who sent it, when and how, versioned and checksummed and never silently overwritten, with retention dates by document type and legal hold. The statutory audit template runs 13 stages from tender to archive, with evidence gates that stop a stage completing until its document is filed, a clearance timer before the engagement letter that closes early only when the outgoing auditor's reply is recorded, and an archive clock that counts down from sign-off to your file-assembly deadline: 45 days by default, with a ceiling of 60. A printable compliance view shows every stage, its evidence, dates and who completed it, and every action is written to an audit trail. Clients and auditees upload through expiring links with a one-time code and no account, against request lists with chasers. An internal audit template, from notification to final report and archiving, is ready to use. Findings, including management letter points, are recorded with severity, recommendation, management's response and an agreed action with owner and due date; each action is followed to implementation and confirmed by someone other than the person who recorded it implemented, and a follow-up register shows what is open and overdue. Templates are configuration, set up with you during implementation.
The deployment is set up for South Africa at implementation: fee notes in rand with VAT at 15 percent, a tax template whose filing stage records the return filed on SARS eFiling, and retention defaults of five years for engagement documentation (IRBA Rule 4) and seven years for company accounting records (Companies Act s.24).
AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint; no client data sits in Creodata's cloud. Creodata operates it from Nairobi and holds standing management access to the deployment's managed resource group, and every action it takes is recorded in your Azure activity log. Include that access in your POPIA assessment.
What it does not do: it holds no working papers or audit methodology, so keep CaseWare, Draftworx, AuditMate or whatever you use. It does not track CIPC or SARS deadlines, submit returns to SARS itself, or post to an accounting system. It has no audit universe or risk-based annual plan, and it does not email action owners about their actions; if your internal audit function needs the plan and working papers in one system now, a full internal audit suite fits better today. See AuditEDMS in South Africa for how each South African duty maps to a capability.
Frequently asked questions
Does IRBA require audit firms to use audit software?
We found no such requirement. IRBA requires the final engagement file to be assembled within 60 calendar days of the report and kept for at least five years, and its inspectors may copy working papers at any time. Meeting both is far easier to show from a system than from shared drives.
Is a South African Azure region enough for POPIA?
Not on its own. Where the data sits is one question; who can reach it, and from where, is another, and POPIA sets conditions for sending personal information abroad (s.72). Ask each vendor about both, and take your information officer's view.
See how AuditEDMS in South Africa meets these criteria, and request a pilot with your own engagements.