What Auditors Need From a Client's Accounting Software

Accounting, HR, payroll & inventory6 min read

Read-only access, a real audit trail and exportable ledgers turn an audit from reconstruction into review. What to ask your clients' software to provide.

Most audits in Nepal start with a week nobody bills for properly: chasing missing vouchers, reconciling a stock register against a ledger that was maintained separately, and establishing whether the figures presented were the figures at the time.

Almost all of that work exists because of how the client’s software behaves, not because of anything the auditor chose. Which means it is fixable — and increasingly, auditors are the ones telling clients which software to use.

Here is what actually makes the difference.

Read-only access with its own login

The most common arrangement — the client exports some reports and emails them — is the worst one. The auditor sees what the client chose to send, in a format the client produced, at a moment the client picked.

An auditor login solves this: read-only, scoped to the entity and periods in scope, with the ability to run any report and drill into any transaction. No ability to post, edit or delete anything.

It also removes an entire category of back-and-forth. Most requests during fieldwork are “can you send me the ledger for this account for these months”, and every one of those is a day of waiting.

An audit trail that actually records changes

The single most valuable feature. For every transaction the system should hold:

  • Who created it, when, and from where
  • Every subsequent modification, with the previous and new values
  • Who approved or posted it, if approval workflow exists
  • Whether it was reversed or superseded, and by what

The reason this matters is not suspicion. It is that without it, you cannot establish that the trial balance you are auditing is the trial balance that existed at year end. Any figure could have been changed after the fact, and you have no way to know, so testing has to be much broader.

With a complete trail, an auditor can see whether post-period-end entries were made, which is one of the highest-risk areas in a small-company audit.

Documents that cannot be silently altered

Once an invoice is issued it should be immutable. Corrections happen through credit and debit notes, which leave both the original and the correction visible.

Software that permits editing a posted invoice — changing the amount, the date, the party — is common, and it is the reason auditors ask for physical vouchers. If the electronic record can be changed at will, it is not evidence.

Cancelled documents should be retained as cancelled, keeping the numbering sequence complete. A gap in an invoice sequence is a question the client will have to answer; a document marked cancelled with a reason and a timestamp is not.

Period locking

Once a period is closed, it should be locked. Postings into a locked period should either be impossible or require a specific authorisation that is itself logged.

Without this, the accounts for a year under audit remain live, and figures can move while fieldwork is in progress. Auditors know the feeling of a balance changing between the tie-out and the report.

Exports that are usable

Reports designed for reading are not reports designed for testing. An auditor needs:

  • Full general ledger for a period, as data — every line with date, voucher number, account, narration, debit, credit and running balance
  • Trial balance at any date, not just period end
  • Sales and purchase registers with tax breakdown
  • Party ledgers with ageing
  • Stock movement with valuation and the method used
  • Fixed asset register with additions, disposals and depreciation

In a format that opens in a spreadsheet without reformatting. A PDF of a ledger is not an export; it is an obstacle.

Stock valuation that shows its working

Inventory is where small-company audits most often get stuck. The system should be able to show not just the closing stock value but how it was arrived at: the valuation method, the movements that produced the closing quantity, and the costs applied.

If closing stock is a number someone typed in after a physical count, with no transactional history behind it, that is a finding, and it is one the software could have prevented.

User rights that mean something

Segregation of duties is hard in a small business where three people do everything. Software cannot fix that, but it can document it: who has rights to create a supplier, post a payment, change a price, apply a discount, or edit a master record.

An auditor can then assess actual control rather than asking what the policy is. And where segregation genuinely is not possible, compensating controls — approval workflows, exception reports on high-value or after-hours transactions — are at least visible.

The practical ask

If you advise clients on systems, the shortlist of questions that separates auditable software from the rest:

  1. Can you give me a read-only login scoped to this entity?
  2. Show me the change history on a posted invoice.
  3. Can a posted entry be edited or deleted, and by whom?
  4. Can a period be locked, and what does it take to post into a locked period?
  5. Export me the full general ledger for last year as a spreadsheet.
  6. Show me how closing stock was valued.

A client whose software answers all six has a materially cheaper audit, and knows their own numbers better the rest of the year too.

We build accounting, inventory and HR software for businesses in Nepal with auditor access, immutable posted documents, period locking and full change history. If you are an auditor or an accountant with clients on systems that make your work harder than it needs to be, talk to us.

Read next

Stay Updated with the Latest Tech