IRBA Inspection Findings on Archiving: the 60-Day Rule, Rule 4 and Changes After Assembly
What IRBA's inspections found on archiving, what Rule 4 and ISA 230 require of file assembly and later changes, and a practical checklist for assembling a file within 60 days.

Short answer: For audits of periods beginning on or after 15 December 2024, IRBA's Rule 4 requires the final engagement file to be assembled within 60 calendar days of the report and kept for at least five years. ISA 230 adds that assembly is administrative only, and that any later change records why, when and by whom. Archiving was one of the five themes in IRBA's 2024 inspections.
This article is for engagement partners, quality leaders and practice managers at IRBA-registered firms. It sets out what IRBA can inspect, what its published inspection report says about archiving and quality management, what Rule 4 and ISA 230 require, and a checklist for assembling a file inside 60 days and recording changes afterwards.
It is a practical guide, not legal or professional advice. Confirm the position for your firm with IRBA's Board Notice and your own quality management system.
What IRBA can inspect
The Auditing Profession Act gives IRBA wide access. It may inspect a registered auditor's practice at any time, and copy working papers, correspondence and other documents (s.47(1)). It "must at least every three years inspect or review the practice of a registered auditor" who audits a public company. And a registered auditor may not refuse to produce information because it is confidential client information (s.47(3)).
In 2024/25 IRBA's inspections covered 20 firm-wide inspections and 72 engagement inspections at 25 audit firms. At 31 March 2025 the register held 3,472 registered auditors.
The practical effect is simple. An inspector can ask for any engagement file, and for evidence of when it was assembled and what happened to it afterwards. If that evidence lives in memory and email, it is hard to produce.
What IRBA's inspection report found
IRBA's 2024 Public Inspections Report is the most recent report we have read in full. Three points in it matter for archiving.
- Archiving is an inspection theme. In 2024 IRBA ran 18 theme-based inspections across nine audit firms and reviewed 118 engagement files. Half of those inspections found one or more deficiencies. "Archiving of engagement files" was one of the five themes. The report's split of findings by theme is in a chart, so we give no per-theme figure; read the report for the detail.
- Quality management monitoring falls short. IRBA found that "Firms' monitoring of their SOQMs was not performed as required by ISQM 1." It also found a lack of documentation of the risk assessment process, of monitoring results, and of evidence that responses to quality risks were in place. Timely assembly is one of those responses: ISQM 1 para 31(f) makes it a quality objective.
- File quality is improving slowly. The share of inspected files that needed significant improvement or were referred for investigation fell from 62 percent in 2019 to 55 percent in 2024.
South Africa has applied ISQM 1 since 15 December 2022, and IRBA began inspecting whether firms' systems of quality management work in early 2024.
Rule 4: 60 calendar days, then at least five years
IRBA published four rules arising from the quality management standards in Board Notice 512 of 2023 (Government Gazette 49757, 24 November 2023). Rule 4 deals with engagement documentation:
- assembly of the final engagement file "shall not exceed 60 calendar days after the date of the engagement report";
- engagement documentation is kept for at least five years from the date of the report, or longer if other law or the firm's policy requires it;
- documentation of the firm's system of quality management is also kept for at least five years.
Rule 4 applies to audits of financial statements for periods beginning on or after 15 December 2024. A financial year that began on 1 January 2025 falls within it, so many audit reports signed during 2026 are the first to which the limit applies.
| ISA 230 | IRBA Rule 4 | |
|---|---|---|
| Assembly period | A timely basis; an appropriate limit is "ordinarily not more than 60 days" after the report (paras 14, A21) | Not more than 60 calendar days after the report |
| Nature of the limit | Guidance on what is appropriate | A limit |
| Retention | Ordinarily no shorter than five years from the report (A23) | At least five years from the report, or longer if law or policy requires |
| Quality management documentation | Not covered | At least five years |
The difference is the word "ordinarily". A firm that used to treat 60 days as a target with room for exceptions now has a hard edge, counted in calendar days from the report date, not from the year end or the partner's last review.
What ISA 230 says about assembly and later changes
Rule 4 sets the clock; ISA 230 still defines the work.
Assembly is administrative. The auditor assembles the documentation in an audit file and completes the administrative process of assembling the final file on a timely basis after the report (para 14). Assembly involves no new audit procedures and no new conclusions (A22). If work is still being done after the report date, that is not assembly, and it raises a different question about the report.
Nothing is deleted before retention ends. After assembly, the auditor "shall not delete or discard" documentation before the end of its retention period (para 15).
Later changes are recorded. If the auditor finds it necessary to change existing documentation or add new documentation after assembly, the auditor documents the specific reasons, and when and by whom the changes were made and reviewed (para 16). Comments received during monitoring inspections are the typical example of what prompts such a change (A24).
ISQM 1 adds the firm-level view. Maintaining documentation includes its safe custody, integrity, accessibility and retrievability, and integrity is compromised if documentation is altered, supplemented or deleted without authorisation, or permanently lost (A83, A84). The IAASB's 2025 revisions to ISA 240 and ISA 570 did not change ISA 230 paras 14 to 16 or A21 to A24.
Checklist: assembling a file within 60 days
The steps below are a practical plan, not text from the standards. Set your own internal deadline inside 60 days so that a late sign-off or a public holiday does not push you over the limit.
| When | Step | Evidence to keep |
|---|---|---|
| Report date | Record the date of the engagement report, and calculate the Rule 4 deadline: report date plus 60 calendar days | The signed report; the deadline in your tracking system |
| Report date | Set the firm's internal target, for example 45 days, and name the person responsible for assembly | The target date and the owner |
| By day 15 | List what is outstanding: final versions of documents, sign-offs of review notes, cross-references, completion checklists | The outstanding list, dated |
| By day 30 | Confirm that no new procedures or conclusions are needed; if any are, stop and escalate to the engagement partner | The partner's decision, dated |
| By day 45 | Manager reviews the assembled file for completeness and file the final versions of client documents against the engagement | The manager's sign-off |
| Before day 60 | Engagement partner confirms that assembly is complete; restrict editing of the assembled file in the tools that hold it | The assembly date, who confirmed it, and the permission change |
| Before day 60 | Set the retention date: at least five years from the report, longer where law or policy requires; apply a legal hold if the file is disputed | The retention date and any hold |
| After day 60 | Report any file that missed the deadline to the quality management function, with the reason | A monitoring record for the SOQM |
The last row matters as much as the others. A missed deadline that is recorded and analysed is monitoring evidence; one that is quietly fixed is the gap IRBA described in its 2024 findings on SOQM monitoring.
Checklist: recording a change after assembly
When an inspection comment, a subsequent event or a query means a document must change after assembly, record each of these (ISA 230 para 16):
- The specific reason for the change or addition, not just "updated".
- Who made it, by name.
- When it was made.
- Who reviewed it, and when.
- The earlier version kept, so the file shows what it looked like at assembly. Do not delete or overwrite documentation before its retention period ends (para 15).
- A link to what prompted it, such as the inspection comment, filed with the change.
If your tools cannot show those six things without someone reconstructing them from email, the record depends on memory, which is where inspections find gaps.
Where software helps, and where it does not
Software cannot decide whether a change is administrative or a new procedure; that is the engagement partner's judgement. What it can do is hold the dates, keep earlier versions, and record who did what.
When you assess a system, ask it to show:
- a countdown from the report date to your deadline, with reminders and escalation;
- the date the file was assembled, and who confirmed it;
- earlier versions kept, and nothing silently overwritten;
- a log of every change after assembly with who and when;
- retention dates by document type, and legal hold;
- one engagement's history, printable, for an inspector.
Where Creodata fits
AuditEDMS is engagement management and document custody software for audit firms and internal audit teams, from Creodata, a Nairobi software company.
Signing the accounts starts an archive clock that counts down to your file-assembly deadline, 45 days by default with a ceiling of 60, with reminders to the manager and escalation to the partner. Record the sign-off on the report date so that the clock and Rule 4 count from the same day. Client documents are filed to your own SharePoint by client, engagement and document type, versioned and checksummed and never silently overwritten, with retention dates by document type and legal hold. Every action is written to an audit trail, and a printable compliance view shows every stage, its evidence, its dates and who completed it, including the archive stage.
The deployment is set up for South Africa at implementation: retention defaults of five years for engagement documentation, from IRBA Rule 4, and seven years for company accounting records, from the Companies Act, with the file-assembly deadline setting described against Rule 4's 60-day limit.
AuditEDMS runs in your own Azure subscription, in the region you choose, with documents in your SharePoint. Creodata operates it with standing management access to the deployment's managed resource group, and every action it takes is recorded in your Azure activity log.
What it does not do: it holds no working papers, so the audit work itself, and locking it at assembly, stay in the tool your team uses. It does not decide whether a change after assembly is permitted. See AuditEDMS in South Africa for how each IRBA and ISA 230 duty maps to a capability.
Frequently asked questions
Is the 60 days counted from the year end or the report?
From the date of the engagement report, in calendar days. Weekends and public holidays count.
Can we add documents after the 60 days?
Yes, if you record the specific reasons, when and by whom the change was made and reviewed (ISA 230 para 16). What you may not do is delete or discard documentation before the end of its retention period (para 15).
Does Rule 4 replace ISA 230?
No. ISA 230 still defines assembly and governs changes after it. Rule 4 turns the ordinary 60 days into a limit for audits of periods beginning on or after 15 December 2024, and sets retention of at least five years.
See how AuditEDMS in South Africa runs the archive clock from sign-off, and request a pilot with your own engagements.