Audit management software · Ghana

Audit software for Ghana's ICAG-licensed firms and the internal audit units in every MDA and MMDA.

Client and auditee documents in your own SharePoint with a receipt for each, the statutory audit from tender to archive with clearance and archive clocks, request lists that clients and auditees answer online, and the dated record of every stage an ICAG reviewer will ask for, for licensed firms and for internal audit units under the Internal Audit Agency Act and the PFM Act.

Ghana regulatory fit

Built for ICAG's practice reviews and the PFM Act's internal audit cycle.

ICAG has adopted the ISAs in their entirety and reviews firms' files against them, and since August 2026 a finding that comes back in the next review cycle is referred for discipline. The PFM Act and the Internal Audit Agency Act set the internal audit cycle for every covered entity. Each duty below maps to a capability, so the evidence sits where a reviewer will look for it.

Assemble the audit file promptly after the report and keep it unchanged (ISA 230, adopted in full by ICAG)

An archive clock from sign-off to your firm's deadline (45 days by default, ceiling 60), with reminders and escalation; versioned, checksummed files and an audit trail of any later change

Engagement lifecycleDocument custody

Submit to ICAG's reviews without obstruction; failing to do so is misconduct (Directive ICAG/QAM/016/26)

Every stage, gate and approval recorded against the engagement with who and when, and a printable compliance view per engagement to hand the reviewer

Compliance viewAudit trail

Document a corrective action plan for each accepted review finding before the next review cycle (Directive ICAG/QAM/014/26)

The plan and the evidence of each remediation filed as documents against the reviewed engagements, dated, versioned and kept to their retention date

Document custody

Evaluate the firm's system of quality management each year (ISQM 1 para 53)

Each engagement's printable history of stages, gates, evidence and sign-offs, for the file reviews that feed the evaluation; the evaluation and independence confirmations stay with the firm

Compliance view

Ask the predecessor auditor for relevant facts before accepting an audit (IESBA Code R320.8); the six-year tenure limit makes a change of auditor routine (Companies Act s.139)

A clearance stage before the engagement letter, which waits the period your firm sets and closes early only when the reply is recorded

Engagement lifecycle

Run public sector internal audit to the Internal Audit Agency's standards, with a work plan within thirty days of the year's start and quarterly reports (Act 658 s.16; PFM Act s.83)

Each engagement in the plan runs through stages set to the IAA's manual, with request lists to the auditee and evidence filed against it; the follow-up register of open and overdue actions, dashboards and CSV reports feed the quarterly report

Engagement lifecycleRequests for informationFindings and follow-upReports

Answer a draft internal audit report within ten working days (2023 Follow-Up Instructions, citing L.I. 1994 reg 43(2))

The draft report and management responses as stages, dated and signed off with their documents; management's response and agreed action recorded against each finding

Engagement lifecycleFindings and follow-up

Follow up audit recommendations with a tracking template, and have the audit committee make sure they are acted on (2023 Follow-Up Instructions; PFM Act s.88)

A findings register holding each recommendation, the agreed action, its owner and due date, and its implementation status, verified by someone other than the person who recorded it implemented; a follow-up register of open and overdue actions across engagements

Findings and follow-up

Keep personal data no longer than its purpose needs, unless the law requires or authorises it (Data Protection Act 2012, s.24)

Documents stay in your own SharePoint and Azure; Entra ID sign-in with your multi-factor policies; retention dates by document type

Document custodyAccess control

This maps software capability to obligations; it is not professional advice. AuditEDMS follows internal audit recommendations to implementation in its findings register; it does not hold an audit universe or a risk-based work plan, and ICAG's corrective action plans for the firm's own review findings are kept as documents, not tracked in the register.

Who it is for

For Ghana's licensed firms, and for internal audit wherever the law requires it.

ICAG-licensed audit, tax and accounting firms

Every firm is licensed by ICAG and renews each year, an auditor must be qualified and licensed, and audit reports carry the firm's licence number and the signer's practising certificate number. No auditor may serve a company for more than six years at a time, and from 1 January 2027 ICAG's reviews use a wider definition of public interest entity that adds government entities, public utilities and not-for-profits "operating with public funds".

Ministries, departments and agencies (MDAs) and metropolitan, municipal and district assemblies (MMDAs)

Each has an internal audit unit working to the Internal Audit Agency's standards and reporting to its Director-General. The head of the unit reports administratively to the Principal Spending Officer and functionally to the audit committee, and sends quarterly reports to both, to the Auditor-General and to the IAA. Audit committees of five members meet at least once every quarter and must make sure recommendations are acted on.

The constitutionally independent bodies

Their internal audit units report to the Auditor-General.

Banks, savings and loans companies, finance houses and financial holding companies

Each has a Chief Internal Auditor, independent of the activities audited, reporting directly to the Board's Audit Sub-Committee (Bank of Ghana Corporate Governance Directive 2018).

FAQ

Frequently asked questions.

Does AuditEDMS replace our working-paper software?

No. Working-paper tools hold the audit programme and its tests; AuditEDMS holds what surrounds them: the client's documents with a receipt for each, the engagement from tender to archive with its gates and clocks, the request lists and the time. A firm keeps its working-paper tool and runs AuditEDMS alongside it. AuditEDMS does not connect to any working-paper tool today.

Is AuditEDMS the "ISA compliance audit program" ICAG asks a new firm to show?

No. ICAG's licensing brochure asks a new firm for evidence of an ISA-compliant audit programme and a documented system of quality management under ISQM 1 and 2. The audit programme is methodology, which belongs in working-paper software. AuditEDMS can hold the documents of your quality management system, with versions and retention dates, and the engagement record that shows the system working.

What does ICAG's August 2026 directive on repeated findings change?

A finding against the ISAs, IFRS or the IESBA Code that recurs in two or more consecutive review cycles without remediation is now prima facie evidence of professional misconduct, and the APRC or PASC refers the member to the Disciplinary Committee. A finding you accept needs a documented corrective action plan before the next review cycle begins (Directive ICAG/QAM/014/26). AuditEDMS keeps that plan, and the evidence of each fix, as dated documents. Its findings register follows findings on client and auditee engagements, not the firm's own review findings, so assign and follow ICAG's corrective actions in your own register.

How long must a Ghanaian firm keep client records?

We found no retention period for company accounting records in the Companies Act 2019; it requires proper records, kept in Ghana, which may be electronic (s.127). An auditor's own file is kept for the firm's retention period, ordinarily at least five years from the auditor's report under ISA 230 and ISQM 1. The Data Protection Act asks you to keep personal data no longer than necessary unless the law requires or authorises it (s.24). AuditEDMS sets a retention date by document type, so each record carries the period your policy gives it.

Does it follow the PFM Act internal audit cycle and the IAA manuals?

It runs the engagements and follows up their findings. The internal audit template is ready to use and adjusted at implementation to the manual you work under, whether the IAA's manual for MDAs, its manual for MMDAs or its Risk-Based Internal Audit Manual: notification, planning memorandum, entrance meeting, request for audit information, fieldwork, exit meeting, draft report, management responses, final report and archiving. Each is dated and signed off with its evidence. The risk-based annual work plan is not in AuditEDMS today.

Does it replace the audit follow-up tracking template?

It does the tracking the template is for. Each recommendation is recorded with management's response, the agreed action, its owner and due date, and followed through agreed, in progress, implemented and verified, with a dated follow-up log; a follow-up register shows open and overdue actions across engagements. The 2023 Instructions make the tracking template the main tool, so whether the register stands in for the template's format is for your unit to settle with its guidance; the completed template can still be filed against the engagement.

Does it handle fee notes and VAT?

Yes, set up for Ghana at implementation: fees in cedis, and tax on each fee note at 20 percent, which is VAT at 15 percent plus the NHIL and GETFund levies at 2.5 percent each, all on the same base under the Value Added Tax Act, 2025 (Act 1151), in force since 1 January 2026. A fee note shows the 20 percent as one line; it cannot yet show VAT, NHIL and GETFund separately, so check that against how your firm invoices. Fee notes stay in AuditEDMS: it does not post to an accounting system or file with the GRA.

Where is the data hosted?

In your own Azure subscription, in the region you choose, with documents in your own SharePoint. Azure has no region in Ghana; its only African regions are South Africa North in Johannesburg and South Africa West in Cape Town, which has restricted access. We found no general rule in the Data Protection Act 2012 on sending personal data out of Ghana; the one cross-border provision we found, s.18(2), covers data about foreign data subjects sent into Ghana. That is our reading of the Act, not advice: confirm it with the Data Protection Commission, with which every data controller registers and renews every two years (s.46), and ask us how the deployment fits your assessment.

How much does it cost?

On Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.

See a Ghanaian statutory audit run from tender to archive, and the compliance view an ICAG reviewer would ask for.