Audit software for Nigeria's audit firms and the internal audit function every company needs.
One audit file for each statutory audit, with a clock from the signed report to the FRC's 60-day close. Client and auditee documents sit in your own SharePoint with a receipt for each, request lists are answered online without an account, retention runs to six years and beyond by document type, findings are followed up to implementation, and timesheets and fee notes in naira sit beside the work, for FRC-registered firms and for the risk-based internal audit functions the Audit Regulations 2020 expect.
Built for the FRC's Audit Regulations, and for the internal audit function every company must have.
The Audit Regulations 2020 set out what the FRC and ICAN will look for when they inspect a firm: one file per statutory audit, closed within 60 days of the signed report, records kept for six years, and a quality system that meets ISQM. Regulation 30 brings internal audit into the same instrument. Each duty below maps to a capability, so the evidence sits where an inspector will look for it.
Create an audit file for each statutory audit and close it not later than 60 days after the audit report is signed (Audit Regulations 2020, reg. 10(2)–(3))
An archive clock from sign-off to your firm's deadline (45 days by default, ceiling 60), with reminders and escalation; versioned, checksummed files and an audit trail of any later change
Keep working papers, correspondence and electronic records for at least six years (reg. 13), company accounting records six years from the date they were made (CAMA s.375), and tax books six years after the year of assessment (NTAA 2025 s.31)
Retention dates by document type, so each record carries its own period and start date; legal hold for a file under dispute or inspection
Keep records of breaches, written complaints and advice from external experts (reg. 10(4))
Each filed as a document against the client or the engagement, with who sent it, when and how, and a retention date
Run a quality management system that complies with ISQM, open to FRC inspection and ICAN monitoring (regs 21, 23 and 24)
Every stage, gate and approval recorded against the engagement with who and when, and a printable compliance view per engagement to hand the inspector
Evaluate the firm's system of quality management each year (ISQM 1 para 53)
Each engagement's printable history of stages, gates, evidence and sign-offs, for the file reviews that feed the evaluation; the evaluation and independence confirmations stay with the firm
Ask the predecessor auditor for relevant facts before accepting an audit (IESBA Code R320.8, adopted by ICAN)
A professional clearance stage before the engagement letter, which waits the period your firm sets and closes early only when the reply is recorded
Run a risk-based internal audit function under a board-approved charter, reporting to the audit committee at least quarterly, with an external assessment at least every three years (reg. 30)
Engagement stages set to your methodology, dated and signed off; request lists to auditees; evidence filed against each engagement; a findings register whose follow-up register of open and overdue actions feeds the quarterly report; the compliance view as the engagement record for an assessor
Audit your data protection compliance each year, and transfer personal data abroad under Part VIII of the NDPA, with adequacy judged under GAID Schedule 3 until the NDPC issues transfer guidelines (GAID Art. 10 and Art. 46)
Documents stay in your own SharePoint and Azure, in the region you choose; Entra ID sign-in with your multi-factor policies; retention dates by document type
This maps software capability to obligations; it is not professional or legal advice. AuditEDMS follows management's agreed actions to implementation in its findings register, but it does not hold the risk-based annual plan or an audit universe, and it does not track firm and partner rotation.
For Nigeria's registered audit firms, and for internal audit in companies and federal MDAs.
Every audit firm registers with the FRC and appears on its National Register of Audit Firms. Every company appoints an auditor at each annual general meeting, unless it is a small company within the CAMA thresholds; banks and insurers never are (CAMA ss.394, 401 and 402). ICAN reviews its members' practice firms and issues practice licences.
The Audit Regulations require every company to have an effective risk-based internal audit function, with a charter, a head registered with the FRC or the relevant regulator, quarterly reporting to the audit committee and an approved annual plan, or to explain its absence. The Nigerian Code of Corporate Governance 2018 says the same on an "Apply and Explain" basis.
Each has a statutory audit committee of five members, which reviews the scope and planning of audit requirements and may authorise the internal auditor to investigate (CAMA s.404).
They carry the same internal audit duty as every company, alongside their sector regulator's rules.
Internal audit units report monthly, quarterly, half-yearly and annually to management, the Accountant-General of the Federation and the Auditor-General for the Federation. The Auditor-General reports to the National Assembly within 90 days of receiving the Accountant-General's financial statements.
Frequently asked questions.
Does AuditEDMS replace CaseWare, PML Auditmate or TeamMate+?
No. Those hold audit working papers or run the full internal audit cycle; AuditEDMS holds what surrounds the working papers: the client's documents with a receipt for each, the engagement from tender to archive with its gates and clocks, the request lists, the time and the fee notes. A firm keeps its working-paper tool and runs AuditEDMS alongside it. AuditEDMS does not connect to any of them today.
How long must a Nigerian audit firm keep its records?
At least six years, but the start date depends on the record. The Audit Regulations 2020 require working papers, correspondence and electronic records to be kept at least six years (reg. 13). A company keeps its accounting records six years from the date they were made (CAMA s.375), and books for tax are kept not less than six years after the year of assessment (Nigeria Tax Administration Act 2025, s.31). AuditEDMS sets a retention date by document type, so each record carries its own period.
What do the Audit Regulations say about the audit file?
The auditor creates one audit file for each statutory audit and closes it not later than 60 days after the audit report is signed (reg. 10). That matches ISA 230's ordinary maximum. In AuditEDMS, signing the accounts starts an archive clock to your firm's deadline, 45 days by default with a ceiling of 60, with reminders to the manager and escalation to the partner. Any change after the file closes is versioned and written to the audit trail.
How often will the FRC or ICAN inspect our firm?
The FRC inspects a firm that audits more than 20 public interest entities every year, and every other firm every three years; each engagement partner is reviewed at least every six years, and the Council can order a special review at any time (reg. 23). The FRC reviews auditors of PIEs itself and delegates the rest to ICAN (reg. 24). AuditEDMS gives the inspector each engagement's compliance view: when clearance closed, when the engagement letter was signed, who signed off each stage, and when the file was closed.
Does it support the internal audit function regulation 30 requires?
It runs the engagements and follows up their findings. Each internal audit runs on the internal audit template, ready to use and adjusted to your methodology at implementation, from notification and entrance meeting through fieldwork and the draft report to management responses, the final report and archiving, each dated and signed off with its evidence. Findings and management's agreed actions go into the findings register, and the follow-up register lists what is open and overdue for the quarterly report to the audit committee. The risk-based annual plan is not in AuditEDMS today, and the quarterly pack itself is still your own.
Is it set up for Nigeria, or for Kenya?
For Nigeria. At implementation the deployment is set up for Nigeria: fees in naira, VAT on fee notes at 7.5 percent, confirmed at implementation, the tax compliance template's filing stage, and retention of six years for engagement files (Audit Regulations 2020, reg. 13) and accounting records (CAMA s.375). Records you create afterwards take those settings; retention periods remain settings your administrator can change, and we check the set-up end to end with you before go-live.
Where is the data hosted?
In your own Azure subscription, in the region you choose, with documents in your own SharePoint. Azure has no region in Nigeria; its only African regions are South Africa North in Johannesburg and South Africa West in Cape Town. Under the NDPA's implementation directive, cross-border transfers fall under Part VIII of the Act, and until the NDPC issues transfer guidelines, adequacy is judged under the directive's Schedule 3. Settle your own position with your data protection officer before choosing a region; ask us how the deployment fits your assessment.
Does it handle fee notes, VAT and tax deadlines?
Fee notes, yes. Billing milestones raise draft fee notes in naira at the stages you choose (40, 40 and 20 percent of the fee by default), with VAT at the rate configured for your deployment on each, part payments, and work in progress and yield from approved time. Fee notes stay in AuditEDMS; it does not post to an accounting system or a tax authority, and it does not track NRS or state filing deadlines for your clients.
How much does it cost?
On Microsoft Marketplace, Basic is US$200 a month for firms of up to 30 staff and Enterprise US$500 a month for firms of up to 75 staff, with priority support; the pilot is free for 90 days, by invitation. Azure resources are billed to your own subscription, typically US$45 to 80 a month for a firm of 20 to 50 staff. Implementation is quoted separately.