Audit management software · Africa & the Middle East

Every engagement, from acceptance to archive, with its evidence on file.

Know what came in. Prove what was done.

AuditEDMS gives audit, tax and accounting firms, and internal audit departments, one controlled place for client and auditee documents, the engagement lifecycle from acceptance to archive, requests for information, time and fees, and internal approvals. It runs in your own Azure subscription, with your documents in your own SharePoint.

Your Azure, your SharePointArchive clock from sign-offClients upload without an accountAudit firms and internal audit
13
Stages in the statutory audit template
Tender to archive, with evidence gates, a clearance timer and an archive clock
60
Days, the ISA 230 ceiling your archive clock can enforce
Set it to 45, or to whatever your firm's policy says
0
Client accounts needed
Clients upload with a one-time code sent to their email
1
Place for every document
Filed by client, engagement and type, with who sent it, when and how
The problem

An audit practice rarely lacks evidence. It lacks one place to find it.

Client documents arrive by email and stay in whichever mailbox received them. Engagement stages, clearance letters and archive deadlines live in spreadsheets and memory. And when a quality reviewer asks when the signed engagement letter came in, or why a file changed after sign-off, the answer takes a morning to reconstruct.

The cost is not only time. ISQM 1 expects a firm to keep engagement documentation safe from unauthorised change, deletion or loss, and a firm that cannot show when and by whom a file was changed after assembly has a finding waiting.

  • Documents have no single home

    The tax team asks a client for a bank statement the auditors already hold, because nobody can see it.

  • Deadlines are tracked by memory

    The file-assembly deadline after the auditor's report passes without anyone noticing, and an inspection finds it.

  • Evidence is hard to produce on demand

    A quality review, an ISQM 1 monitoring review or an audit committee asks for proof, and the proof is scattered across inboxes and shared drives.

What changes

What changes when every engagement runs on one record.

Every document has a home and a receipt

Each file is filed to your SharePoint against the client, the engagement and the document type, recording who sent it, when, and how it arrived.

Stages cannot be skipped

A stage that depends on a document, such as the signed engagement letter, cannot be completed until that document is filed against it, and stages complete in order.

The archive deadline is a clock, not a memory

Signing the accounts starts a countdown to your file-assembly deadline, with reminders to the manager and then the partner.

Partners see the practice

Engagements by stage, staff load, billed against unbilled, archive deadlines and outstanding client requests, on one dashboard.

Two kinds of audit team, one engine

Built for audit firms. Configured for internal audit.

Who you audit

Audit, tax and accounting firmsClients

Internal audit departmentsAuditees: business units, branches, counties, subsidiaries

Engagements

Audit, tax and accounting firmsStatutory audit (13 stages, tender to archive) and tax compliance templates, ready to use

Internal audit departmentsAn internal audit engagement template (notification, planning memo, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report, archive), ready to use and adjusted to your methodology at implementation

Requests for information

Audit, tax and accounting firmsPBC lists sent to the client's contact

Internal audit departmentsDocument request lists sent to the auditee's contact, starting from a nine-item list

Findings

Audit, tax and accounting firmsManagement letter points, with management's responses, followed to resolution

Internal audit departmentsFindings with severity and recommendations, management's agreed actions with owners and due dates, followed up to verified implementation

Time

Audit, tax and accounting firmsTimesheets at charge-out rates by grade; work in progress and yield

Internal audit departmentsTimesheets against each engagement's planned hours

Money

Audit, tax and accounting firmsMilestone billing, fee notes with VAT, part payments

Internal audit departmentsNot needed; leave billing unused

Oversight

Audit, tax and accounting firmsPartner dashboard; printable compliance view for a quality review

Internal audit departmentsManager and partner dashboards (the head of internal audit takes the partner role); the printable compliance view as the engagement record for an audit committee or external assessment

Regulatory fit

Built for ISA 230, ISQM 1 and the IIA's Global Internal Audit Standards.

The standards that audit teams across Africa and the Middle East follow set the same expectations of their records: assemble the file promptly after the report, keep it unchanged for the retention period, and show who did what and when. Each duty maps to a capability, so the evidence sits where a reviewer will look for it. Each country page sets out that country's own retention periods and inspection regime.

Assemble the final audit file on a timely basis after the auditor's report, ordinarily within 60 days (ISA 230 paras 14 and A21)

Signing the accounts starts an archive clock set to your firm's deadline, with a ceiling you choose, reminders to the manager and escalation to the partner

Engagement lifecycleArchive clock

Keep documentation from being deleted or discarded before the retention period ends, and record any later change: why, when and by whom (ISA 230 paras 15 and 16)

Documents are versioned and checksummed, never silently overwritten; retention dates by document type; legal hold; every action written to an audit trail

Document custodyAudit trail

Maintain the safe custody, integrity, accessibility and retrievability of engagement documentation (ISQM 1 para 31(f) and A83 to A85)

Files live in your own SharePoint, in your own Microsoft 365, with access through Microsoft Entra ID and permissions checked on every request

Document custodyAccess control

Complete client acceptance and engagement terms before the work starts

Evidence gates: the engagement letter stage needs the signed letter filed before the request for information can be issued

Engagement lifecycleEvidence gates

Communicate with the predecessor auditor before accepting an appointment, where the ethics code and national rules call for it

Professional clearance comes before the engagement letter: a clearance timer waits your configured period, and closes early only when the outgoing auditor's reply is recorded

Engagement lifecycleClearance timer

Gather information for the engagement and keep engagement documentation (IIA Standards 14.1 and 14.6)

Document request lists with chasers; auditees upload against the list; everything filed against the engagement, reviewed and retained

Requests for informationDocument custody

Agree recommendations and action plans with management, and confirm they are implemented (IIA Standards 14.4 and 15.2)

A findings register holds each recommendation, management's response and the agreed action with its owner and due date; implementation is verified by someone other than the person who recorded it, and a follow-up register shows what is open and overdue

Findings and follow-up

Document supervision and review (IIA Standard 12.3)

Stage completion records who completed each stage, when and with what evidence; approvals record who approved and on whose behalf

Engagement lifecycleApprovalsAudit trail

Sources: ISA 230 and ISQM 1 in the IAASB 2025 Handbook; the IIA Global Internal Audit Standards, effective 9 January 2025. This maps software capability to obligations in the standards; it is not professional advice, and your national rules and your firm's policies set the periods that apply.

Capabilities

What it does

Engagements, from acceptance to archive

Engagement templates with stages, gates and timers. The statutory audit template runs from tender and award through client acceptance, professional clearance, the engagement letter, the request for information, planning, fieldwork, the closing meeting and the management letter to sign-off and archiving. A shorter tax compliance template and a ten-stage internal audit template, from audit notification to final report and archiving, are ready too. Evidence gates stop a stage completing until the document it depends on is filed, and a printable compliance view shows every stage, its evidence, its dates and who completed it.

Document custody

Every document is filed to your SharePoint by client, engagement and document type, recording who sent it, when and how it arrived. Files are versioned and checksummed and never silently overwritten; duplicates are detected and linked rather than stored twice. Retention dates are set by document type, legal hold keeps a file past its date, and the document register can be searched and exported.

Requests for information, and uploads without accounts

Each engagement carries its request list: what was asked for, when it is due, what has arrived and what is outstanding, with chasers for what is late. Send a client or an auditee an expiring upload link; they confirm their email address with a one-time code and upload against your list. Every upload is receipted and recorded against the client and the engagement.

Findings and follow-up

Record each finding with its severity, the recommendation and management's response, then the agreed action, its owner and its due date. Each action moves from agreed to in progress, implemented and verified, and verification must be done by someone other than the person who recorded it implemented; accepting the risk instead needs a note. A dated follow-up log keeps the history, and a follow-up register shows open and overdue actions across engagements. Audit firms use the same register to follow management letter points to resolution.

Time, fees and work in progress

Weekly timesheets against engagement and stage, with approval, and charge-out rates by grade. For firms: milestone billing at the stages you choose, fee notes with VAT, part payments, and work in progress with yield per engagement. Internal audit teams use the timesheets and leave billing unused.

Internal requests and approvals

Travel, mileage, transport refunds and petty cash, each with its own form and mandatory supporting evidence. Approval chains by service line, request type and amount, with service-level clocks, escalation, and a history that records every approval given on someone else's behalf.

Dashboards, reports and control

Partner, manager and administrator dashboards, and reports on engagements, time, billing, documents and requests, with CSV export. Staff sign in with Microsoft Entra ID under your own multi-factor and conditional access policies; roles and permissions are table-driven, and every action is written to an audit trail. The parameters your firm owns, such as the clearance wait, the archive deadline, retention periods, billing milestones and timesheet rules, are settings your administrator changes without a release.

How it is delivered

In your Azure, with your documents in your SharePoint.

AuditEDMS is a Microsoft Marketplace managed application. It runs in your own Azure subscription, in the region you choose, and your documents stay in your own SharePoint: no client data is stored in Creodata's cloud. Creodata installs, operates, updates and supports it, and holds standing management access to the deployment's managed resource group to do so; every action Creodata takes is recorded in your Azure activity log.

What you need

  • Microsoft 365 with SharePoint Online and Exchange Online, and staff accounts in Microsoft Entra ID.
  • An Azure subscription. Pay-as-you-go is enough, and Creodata can help you set one up.
  • Someone who can register applications, before deployment, and a Microsoft 365 administrator, afterwards.

Getting started, in five steps

  1. 1Request a pilot.
  2. 2Run the registration script from the setup page.
  3. 3Deploy from Microsoft Marketplace, which takes about 15 minutes.
  4. 4Sign in as the first administrator and add your people.
  5. 5Connect SharePoint and your mailboxes with the second script.

Pricing

Pilot by invitation; pricing on request.

The pilot is free for 90 days. Azure resources used by the deployment are billed to your own subscription at standard rates, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation (configuration, client import and training) is quoted separately.

Security and your data

  • Sign-in is through Microsoft Entra ID, under your own multi-factor and conditional access policies.
  • Permissions are checked on every request, and every action is written to an audit trail.
  • Upload links expire and need a one-time code sent to the recipient's email.
  • Records and documents stay in your tenancy. See our privacy policy.

Who it is for

Audit, tax and accounting firms of 10 to 75 staff that audit, file tax and keep books for the same clients, and want one client file across service lines.

Internal audit departments in banks, insurers, SACCOs and microfinance institutions, listed companies and groups, which answer to a board audit committee.

Public-sector internal audit units in ministries, county and local governments and state corporations, which answer to an accounting officer, an audit committee and an internal auditor-general.

Each country page maps one country's audit regulator, retention periods and internal audit mandates to the software: Kenya, Uganda, Tanzania, Rwanda, Zambia, Nigeria, Ghana, South Africa and the UAE.

What it is not

AuditEDMS is not audit working-paper software and does not replace it. It keeps the client file, the engagement record, the requests, the time and the fees around your working papers, whatever tool holds them. It does not connect to an accounting system or to CaseWare today.

Looking for a document management system on SharePoint outside audit work? See our EDMS solutions in Kenya.

FAQ

Frequently asked questions.

Is AuditEDMS audit software or practice management software?

It sits between the two. It manages the engagement (stages, gates, timers, requests for information and the archive deadline), the client documents behind it, and the time and fees it earns. It does not hold working papers or an audit methodology, so a firm that uses working-paper software keeps it and runs AuditEDMS around it.

Can internal audit departments use it?

Yes. An internal audit engagement runs on the same engine as an external audit: stages from notification to final report, document request lists sent to auditees through upload links, a findings register that follows management's agreed actions to verified implementation, time against each engagement, sign-off, an archive stage and an audit trail. The internal audit template is ready to use and adjusted to your methodology at implementation. AuditEDMS does not have an audit universe or a risk-based annual plan; if you need those today, ask us where they are on the roadmap.

Do we need an Azure subscription?

Yes. AuditEDMS runs in your own Azure subscription as a managed application, and it needs Microsoft 365 with SharePoint Online and Exchange Online. A pay-as-you-go subscription is enough, and Creodata can help set one up.

What can Creodata access?

The deployment's managed resource group, to operate and support it, and every action is recorded in your Azure activity log. Creodata cannot reach your other Azure resources, or your Microsoft 365 beyond the SharePoint site and mailboxes your administrator grants.

Does it read our staff mailboxes?

No. Notifications are sent from one mailbox you choose.

Do our clients need an account to send us documents?

No. You send an expiring upload link; the client confirms their email address with a one-time code and uploads against your request list, and receives a receipt.

Where is our data?

In the Azure region you choose, and in your own SharePoint. Microsoft's nearest Azure regions to East Africa are in South Africa, and there are regions in the UAE.

Does it connect to CaseWare or our accounting system?

Not today.

How long does it take to get started?

The deployment itself takes about 15 minutes after the registration script has run. Configuration, importing your clients and training are scoped with you and quoted separately.

What if we stop?

Your documents stay in your SharePoint, whatever happens to AuditEDMS. The records database is in your own Azure subscription, and before you cancel, Creodata exports it and hands it to you: clients, engagements and their stages, requests for information, findings, time, fee notes and the audit trail. Removing the managed application then deletes only the application and its resources, not your documents or your copy of the records.

See AuditEDMS run an engagement from acceptance to archive.

A fictitious firm, a real statutory audit template, and a client upload from the other side, in a live demonstration.

Contact support@creodata.com, +254 772 200025