Internal audit is a cornerstone of governance for South African organisations operating under King IV, the Public Finance Management Act (PFMA), or the Municipal Finance Management Act (MFMA). But many audit teams still rely on spreadsheets, shared drives, and email to manage their entire audit lifecycle, from planning to reporting. The result is inefficiency, version control failures, and findings that get lost between audits. Internal audit software changes this fundamentally. This guide explains what to look for, what to expect, and how to evaluate options in the South African context. Organisations seeking integrated GRC and audit management can explore GRC software built for South Africa.

Why Internal Audit Teams Adopt Software

The move from spreadsheets to dedicated audit software is driven by four persistent problems that manual tools cannot solve:

  • Version control: Multiple versions of audit workpapers circulating simultaneously, with no single source of truth
  • Follow-up failures: Management action plans agreed during audits that are never tracked to completion
  • Reporting bottlenecks: Consolidating findings from multiple engagements into a coherent audit committee report takes days
  • Audit universe management: Without a system, it is difficult to demonstrate that the audit plan is risk-based and covers the full audit universe

In our experience, good internal audit software addresses all four of these problems by providing a centralised platform for the entire audit lifecycle.

Alignment with IIA Standards

The Institute of Internal Auditors (IIA) sets out how internal audit should operate. The Global Internal Audit Standards, published in 2024 and effective from 9 January 2025, replaced the previous International Standards and integrated the Code of Ethics into the Standards. South African internal audit functions are expected to conform with them.

Internal audit software should support:

IIA Standard Area Software Capability Required
Risk-Based Audit Planning Audit universe management, risk scoring, plan documentation
Engagement Management Engagement planning, workpaper management, time tracking
Finding Management Finding documentation, rating, root cause, management response
Issue Tracking Action plan assignment, due dates, status tracking, escalation
Reporting Engagement reports, audit committee reports, dashboard analytics
Quality Assurance Review and approval workflows, supervisor sign-off, QAIP documentation
i

King and Internal Audit

King asks the governing body to ensure that the internal audit function is independent, adequately resourced, and that its work supports the combined assurance model (King IV, and King V Principle 12 on assurance). Audit software that links findings to the organisation's risk register supports combined assurance by helping show the board that assurance activities are coordinated and risk-focused.

Must-Have Features for South African Audit Teams

1. Audit Universe and Risk-Based Planning

The audit universe should be maintained within the system, with each auditable entity linked to risk scores. The annual audit plan should demonstrate coverage of higher-risk areas, with documentation of why lower-risk areas are deferred. This allows the CAE to defend the audit plan to the audit committee.

2. Workpaper Management

Electronic workpapers with review and approval workflows, version control, and cross-referencing to findings. This replaces physical files and email chains with a structured, searchable record of work performed.

3. Finding and Observation Tracking

Findings must be documented with severity ratings, root cause analysis, and recommendations. Management responses must be captured, with agreed action plans linked to named owners and due dates.

4. Issue Management and Follow-Up

In our experience, inadequate follow-up on agreed actions is one of the most common weaknesses in audit functions. Software should provide automated reminders to action owners, escalation to management when actions are overdue, and a live status view for the CAE and audit committee.

5. Audit Committee Reporting

The CAE must report to the audit committee on findings, issue status, and conformance with the audit plan. Good software makes this a matter of clicking a button rather than a multi-day consolidation exercise.

6. Integration with Risk Management

For organisations implementing combined assurance under King IV, audit software that integrates with the risk register provides direct linkage between audit findings and organisational risks, closing the loop between risk identification and assurance.

Evaluating Audit Software: 5 Questions to Ask

  1. Does it support the full audit lifecycle, from universe management and planning through workpapers, findings, action tracking, and reporting?
  2. Is it configurable for your methodology, can you adapt rating scales, report templates, and workflow steps to your organisation's standards?
  3. How does it handle action plan follow-up, automated reminders, escalation rules, and management access to update status?
  4. Does it provide meaningful analytics, not just data storage, but trend analysis, aging issues, and audit plan progress?
  5. Does it integrate with your GRC platform, so that audit findings feed into risk and compliance data rather than sitting in a separate silo?
Key Takeaways

Summary

  • Spreadsheets and email create four structural problems: version control, follow-up failures, reporting bottlenecks, and poor audit universe management
  • Internal audit software should align with the IIA IPPF across all phases of the audit lifecycle
  • King IV's combined assurance model is best supported by software that links audit findings directly to the risk register
  • Issue tracking and automated follow-up are the highest-value features for most South African teams
  • Evaluate software against the full lifecycle, not just workpaper management or reporting in isolation
  • Integration with the GRC platform is a differentiating capability for mature governance functions

Frequently Asked Questions

Is internal audit software required under King IV?

King IV does not mandate specific technology. However, it requires that internal audit be independent, adequately resourced, and effective. In practice, meeting these requirements without appropriate tools, especially for issue tracking and reporting, becomes increasingly difficult as organisations grow. Software is a practical enabler of King IV compliance, not a formal requirement.

What is the difference between internal audit software and GRC software?

Internal audit software manages the audit lifecycle, planning, workpapers, findings, action tracking, reporting. GRC software manages the broader risk, compliance, and governance programme. The best implementations integrate both: audit findings feed into the risk register, and risk data informs audit planning. Some GRC platforms include internal audit as a module, eliminating the need for separate systems.

Does the PFMA or MFMA specify requirements for internal audit software?

Neither the PFMA nor the MFMA specifies audit software requirements. However, National Treasury's public sector risk management and internal audit guidance, together with the IIA standards that apply to public sector audit functions, call for documentation, evidence trails, and quality assurance processes that are very difficult to maintain without proper tools. AGSA audits also scrutinise the quality and adequacy of internal audit work.

How long should audit workpapers be retained?

The IIA does not prescribe a fixed retention period. The Global Internal Audit Standards ask the chief audit executive to set retention requirements that are consistent with the organisation's policies and with any legal or regulatory obligations. In South Africa, for example, the Companies Act generally requires certain records to be kept for seven years, while tax and other laws set their own periods. Organisations should confirm the periods that apply to them and align workpaper retention accordingly. Electronic retention in audit software simplifies retrieval and long-term accessibility.

References
1. Institute of Internal Auditors. Global Internal Audit Standards, 2024.
2. Institute of Directors South Africa. King IV Report on Corporate Governance, 2016.
3. National Treasury South Africa. Public Sector Risk Management Framework and internal audit guidance. treasury.gov.za.
4. Auditor-General of South Africa. Annual reports and audit outcomes. agsa.co.za.
5. Institute of Internal Auditors South Africa (IIASA). iiasa.org.za.

About This Guide

This guide is provided for educational purposes only. It draws on a combination of Dimeri's project and advisory work, interviews with practitioners, our own research, academic literature, and publications from standard-setters, regulators, and professional bodies. It reflects our view of good practice at the date of publication and is not legal, regulatory, audit, or financial advice.

Laws, codes, and standards change, and how they apply depends on your organisation's circumstances. Please consult the primary sources and obtain professional advice before acting. Last reviewed: September 2026.