Prepare for an audit: a practical checklist for SA teams
Back to Blog

Prepare for an audit: a practical checklist for SA teams

August 9, 2026
AI Webhook

Prepare for an audit: a practical checklist for SA teams

Hands labeling audit folder and logging documents

To prepare for an audit, confirm the scope, assign a single document owner, assemble your Provided-by-Client (PBC) pack, run reconciliations and test controls, and set one point of contact for all auditor communications. That five-step sequence covers the ground whether you are facing an external statutory audit, an internal review, or a SARS tax audit.

Start here in the next 48–72 hours:

  • Confirm the audit type and scope in writing with the auditor or audit committee.
  • Name one PBC owner who is responsible for gathering and labelling every document.
  • Open a shared folder (cloud or physical) and begin loading financial statements, bank statements, VAT returns, and payroll records.
  • Run your most recent bank reconciliation and flag any unreconciled items immediately.
  • Notify key staff of likely interview dates and brief them on a factual, document-first approach.
  • Check SARS, SAICA, IIA, and COSO guidance relevant to your audit type (links throughout this article).

Readyaccounting supports South African SMEs through every stage of this process, from clean-up to SARS representation.

Pro Tip: Create a single labelled folder called “PBC Pack [Audit Year]” and log every document handed to auditors in a simple spreadsheet: file name, date sent, recipient, and status. That log alone prevents the most common complaint auditors raise — “we never received that.”


Key takeaways

Audit readiness comes down to five habits: confirmed scope, a named PBC owner, a complete evidence pack, clean reconciliations, and a single auditor contact who responds within 24 hours.

Point Details
Confirm scope first Identify the audit type (statutory, SARS, internal, IT) before gathering a single document.
Five-year retention rule SARS requires all financial records to be kept for a minimum of five years — digital backups must be complete and retrievable.
PBC pack and evidence log Assemble documents in a labelled folder structure and log every file handed to auditors with date and recipient.
Pre-audit sweep Run a quality check across classification, disclosure, tax, and measurement two weeks before fieldwork begins.
Readyaccounting support Readyaccounting provides PBC assembly, pre-audit sweeps, and SARS representation for South African SMEs.

Table of Contents

What type of audit are you facing, and what does it cover?

Getting the scope wrong at the start wastes weeks. The five main audit types each pull different evidence, and knowing which one is coming shapes every decision you make from day one.

External / statutory audit. Required for companies above certain thresholds under the Companies Act and overseen by SAICA-registered auditors. The focus is your Annual Financial Statements: revenue recognition, expense classification, asset valuations, and disclosure completeness. CIPC filings and shareholder agreements are also in scope.

Internal audit. Governed by IIA Global Internal Audit Standards (2024), internal audits assess whether controls are designed and operating effectively. Sample PBC items include process flowcharts, control matrices, exception reports, and board or audit-committee minutes.

SARS tax audit. Triggered by risk profiling, VAT refund claims, or random selection. SARS typically requests income tax returns, VAT201 returns, supporting invoices, bank statements, and payroll records. The SARS audit process has specific notice types and response windows you must respect.

Regulatory / sector audit. Examples include FSCA reviews for financial services firms or Department of Labour inspections for payroll compliance. Evidence centres on licences, compliance registers, and sector-specific reporting.

IT / ISO audit. Covers access controls, change management, data integrity, and cybersecurity. Map your IT control evidence to a recognised framework such as the NIST Cybersecurity Framework or use ISACA guidance to demonstrate control maturity.

For internal control design across any audit type, COSO remains the standard framework auditors reference when evaluating whether controls are fit for purpose.


What type of audit are you facing, and what does it cover? — overview diagram

How do you build an audit plan and assign responsibilities?

A one-page audit plan prevents the two most common failures: missed deadlines and nobody knowing who owns what. A structured audit plan and organised process for delivering requested materials keeps the engagement efficient and reduces disruption to daily operations.

Minimal audit plan template

Your plan needs five columns: deliverable, responsible owner, reviewer, due date, and status. That is it. Keep it in a shared spreadsheet so everyone sees the same version.

Responsibility matrix (RACI-lite)

Deliverable Responsible Accountable Consulted Informed
PBC pack assembly Finance manager CFO / MD External advisor Auditors
Bank reconciliations Bookkeeper Finance manager Readyaccounting CFO
VAT / PAYE schedules Tax accountant Finance manager SARS practitioner CFO
Auditor liaison Nominated contact CFO / MD Legal (if needed) All staff
Management responses CFO / MD Board External advisor Auditors

Suggested timeline for a year-end external audit

8–12 weeks before: Confirm scope and engagement letter. Identify PBC owner. Begin pulling prior-year comparatives and updating the fixed-asset register.

4 weeks before: Complete bank reconciliations, VAT reconciliations, and creditor/debtor ageing. Assemble draft financial statements. Run a pre-audit sweep for classification and disclosure gaps.

2 weeks before: Hold a pre-audit meeting with auditors to align on scope, timing, and key contacts. Deliver the PBC pack. Brief staff on interview protocols.

Week of audit: Maintain the evidence log. Respond to auditor queries within 24 hours. Escalate complex tax positions to your registered tax practitioner or Readyaccounting.

Pro Tip: Build three buffer days into every deadline. Reconciliations always surface one unexpected item, and auditors always ask one follow-up question you did not anticipate. Buffer days mean you fix the issue rather than explain why it is still open.


What documents do you need to gather for your PBC pack?

Good-practice guides consistently show that an organised, complete PBC pack is the single biggest factor in reducing audit disruption. Here is what to gather, structured by category.

Core PBC checklist

Financial records

  • Signed Annual Financial Statements (current and prior year)
  • Trial balance and general ledger (full detail)
  • Bank statements for all accounts (all 12 months)
  • Bank reconciliations, month by month
  • Fixed-asset register with additions, disposals, and depreciation schedules

Tax and statutory records

  • Income tax returns (ITR14 or ITR12) and supporting schedules
  • VAT201 returns and supporting invoices (input and output)
  • PAYE / EMP201 and EMP501 reconciliations
  • CIPC annual return confirmation
  • Dividend tax certificates where applicable

Payroll and HR

  • Payroll journals and payslip summaries
  • IRP5 / IT3(a) certificates
  • Leave liability schedule
  • Employment contracts for key staff (sample)

Contracts and governance

  • Material supplier and customer contracts
  • Shareholder agreements and board minutes
  • Loan agreements (related-party and third-party)
  • Insurance schedules

Suggested folder structure

PBC Pack [Year]
├── 01_Financial Statements
├── 02_Trial Balance & Ledger
├── 03_Bank Statements & Recons
├── 04_Tax Returns (VAT, PAYE, Income Tax)
├── 05_Fixed Assets
├── 06_Payroll & HR
├── 07_Contracts & Governance
├── 08_Correspondence & Notices
└── 00_Evidence Log.xlsx

Use the format YYYY-MM-DD_DocumentName_v1 for every file. Version control matters when auditors request updated schedules.

SARS five-year retention rule: South African taxpayers are required to keep all relevant financial records for a minimum of five years. That means bank statements, invoices, VAT records, payroll records, and tax returns going back five years must be accessible, whether in physical or digital form. A cloud backup with offsite redundancy is not optional — it is the practical minimum for SARS record-keeping compliance.

Pro Tip: Download bank statements directly from your banking portal as PDF files with embedded transaction IDs. Screenshots and Excel exports are not accepted as primary evidence by SARS auditors. The PDF with the bank’s digital signature is the document that holds up.


Which internal controls and reconciliations should you check first?

Auditors sample controls. If your controls have exceptions, they find them. Running your own checks first means you fix the exceptions before they become audit findings.

The highest-priority items to test before auditors arrive:

  • Bank reconciliations: Every account, every month, with no unreconciled items older than 30 days. Unexplained differences are the first thing auditors flag.
  • VAT reconciliation: Reconcile VAT output per the general ledger to VAT201 submissions. Differences between the two are a common SARS audit trigger.
  • Payroll controls: Confirm that every employee on the payroll register has a valid employment contract, that EMP201 submissions match payroll journals, and that IRP5 totals agree to the EMP501.
  • Creditor and debtor ageing: Identify balances older than 90 days and confirm they are either still valid or have been written off with proper authorisation.
  • Fixed-asset existence: Physically verify a sample of assets on the register. Confirm depreciation rates match the accounting policy disclosed in the financial statements.
  • Related-party transactions: List every transaction with directors, shareholders, or connected entities. Confirm each is disclosed in the notes and priced at arm’s length.

How a payment control trace works

An auditor testing a payment will follow this chain: purchase order → supplier invoice → approval email → payment batch → bank statement debit → general ledger entry. Every link must have a document. If the approval email is missing, the control has failed regardless of whether the payment was legitimate.

Map your key controls to COSO’s five components (control environment, risk assessment, control activities, information and communication, monitoring) when documenting control design. Internal audit teams should align scope and sample sizes with IIA standards.

Pro Tip: Run a 10-transaction spot check on your highest-risk process (usually payments or payroll) two weeks before the audit. Log every exception you find and fix it. Auditors respect teams that have already identified and corrected their own gaps.


How should you communicate with auditors on the day?

Audit-day communication is where well-prepared teams lose ground. The documents are ready, but someone says the wrong thing or sends an unreviewed file. Keep it simple and document-driven.

Do:

  1. Designate one person as the auditor’s single point of contact. All requests go through them.
  2. Respond to every information request in writing, even if the conversation started verbally.
  3. Provide exactly what was asked for. No more, no less.
  4. Log every document handed over: file name, date, recipient, and the specific request it answers.
  5. Schedule staff interviews in advance and brief each person to answer only what they know factually.

Do not:

  • Offer opinions on accounting treatments without first consulting your advisor.
  • Send draft or unreviewed documents. Label everything “Final” only when it is.
  • Discuss matters outside the agreed scope without your CFO or external advisor present.
  • Promise a turnaround time you cannot meet. Under-promise and deliver early.

Sample auditor response email

When a query involves a complex tax position, an unusual related-party transaction, or a prior-year restatement, involve an external advisor immediately. That is exactly the situation where Readyaccounting’s role as an accountant adds the most value.

Pro Tip: Brief staff with one sentence: “Answer what you know, say ‘I’ll confirm that in writing’ for anything you are unsure of, and refer anything outside your area to [contact name].” That single instruction prevents most audit-day miscommunications.


What is different about a SARS tax audit?

A SARS audit follows a specific process that differs from a statutory audit in timing, notice types, and the consequences of a slow or incomplete response.

When you receive a SARS notice, take these steps immediately:

  1. Read the notice in full and note the exact response deadline.
  2. Identify the tax type and period under review (income tax, VAT, PAYE, or a combination).
  3. Appoint a registered tax practitioner if you do not already have one.
  4. Begin gathering the specific documents listed in the notice: bank statements, invoices, VAT returns, payroll records, and any supporting schedules.
  5. Preserve all original documents. Do not alter, delete, or overwrite any record.
  6. Submit your response before the deadline, with a covering letter that maps each document to each request.

Five-year retention callout: SARS requires taxpayers to retain all relevant financial records for a minimum of five years. This covers bank statements, invoices, contracts, VAT records, payroll records, and tax returns. For a business that has been trading for more than five years, that means maintaining accessible archives going back to the earliest year still within the window. Digital backups with version control satisfy this requirement provided they are complete and retrievable.

If a SARS audit uncovers historical errors — underreported income, incorrect VAT claims, or missed PAYE submissions — the Voluntary Disclosure Programme (VDP) offers a route to correct those errors with reduced penalties and no criminal prosecution, provided you apply before SARS opens a formal audit on that specific issue. The VDP is not a general amnesty; it applies to specific, undisclosed defaults. Engage a registered tax practitioner before applying.

For a detailed walkthrough of SARS-specific preparation steps, the Ready Accounting SARS audit guide covers notice types, timelines, and response templates.

Pro Tip: Keep a dedicated SARS correspondence folder, separate from your general audit PBC pack, that contains every notice received, every response sent, and every acknowledgement from SARS. If a dispute escalates to the Tax Court, that folder is your primary evidence.


What is different about a SARS tax audit? — overview diagram

What mistakes slow audits down or cause modified opinions?

Most audit delays trace back to the same short list of avoidable errors. Practitioner experience confirms that simple, repeatable habits prevent the majority of them.

Common pitfalls and their quick fixes:

  • Missing supporting documents. Fix: run the evidence log two weeks before the audit and identify every gap. A missing invoice is easier to obtain in advance than under auditor pressure.
  • Classification errors. Capital expenditure coded as an operating expense, or vice versa, triggers immediate queries. Fix: review the fixed-asset additions list against the general ledger before submission.
  • Unreconciled balances. Any balance sheet account with an unexplained difference signals weak controls. Fix: reconcile every balance sheet account, not just bank, before the audit starts.
  • Deferred tax mistakes. Deferred tax is one of the most frequently misstated items in South African SME financial statements. Fix: recalculate the deferred tax balance from scratch using the balance-sheet method and tie it to the tax computation.
  • Related-party under-disclosure. SAICA standards require full disclosure of related-party transactions in the notes. Fix: list every director loan, intercompany transaction, and shareholder payment and confirm each is in the notes.
  • Late responses to auditor queries. Every day of delay extends the audit and increases fees. Fix: commit to a 24-hour response window and assign a backup contact for when the primary is unavailable.

The downstream cost of fixing these issues during an audit, rather than before it, is real: extended fieldwork, higher professional fees, and the risk of a qualified or emphasis-of-matter opinion that affects your ability to raise finance or satisfy CIPC requirements.

Run a pre-audit quality sweep using four categories: classification, disclosure, tax, and measurement. If each of those four areas is clean, the audit moves quickly. For practical guidance on avoiding common bookkeeping mistakes that feed these errors, Readyaccounting’s resource covers the most frequent offenders.

Pro Tip: Treat the pre-audit sweep as a formal internal sign-off. Have the finance manager and CFO both sign a one-page checklist confirming that each of the four error families has been reviewed. That sign-off creates accountability and usually surfaces the last remaining issue before auditors do.


How do cloud accounting and automation cut audit prep time?

Manual audit preparation is slow because evidence lives in multiple places: email threads, shared drives, desktop folders, and physical files. Cloud accounting and document management change that by making evidence retrievable in minutes rather than days.

Tool categories worth knowing:

  • Cloud accounting platforms (Xero, Sage Business Cloud, QuickBooks Online): real-time general ledger, automated bank feeds, and VAT return preparation. Auditors can be given read-only access, which eliminates most document-request cycles for transaction-level testing.
  • Automated bank feeds: reconcile transactions daily rather than monthly. By audit time, your bank reconciliation is current and exceptions are already resolved.
  • Document management systems (DMS): platforms like Google Drive (with structured folders) or dedicated DMS tools centralise contracts, invoices, and correspondence with version control and access logs.
  • PBC portals: some audit firms use portals (such as ShareFile or Suralink) to manage evidence requests. Knowing how to upload to these systems in advance saves time on audit day.
  • Payroll platforms: cloud payroll tools with built-in PAYE calculations and EMP201 export functions make payroll audit preparation straightforward, particularly for startups managing rapid headcount growth.

The starting point for any automation project is standardising your chart of accounts and bank-feed rules. Automation built on inconsistent account codes produces inconsistent evidence. Fix the foundation first, then automate.

For South African SMEs considering a system upgrade before an audit, Readyaccounting’s guide to accounting tasks to automate covers the highest-impact starting points, and the cloud accounting benefits guide explains what the shift looks like in practice.

Pro Tip: Map your IT control evidence to the NIST Cybersecurity Framework if your audit includes IT controls. Auditors assessing access management, logging, and change control respond well to evidence organised against a recognised framework rather than a custom list.


How Readyaccounting helps you get audit-ready

Readyaccounting works with South African SMEs and VC-backed startups as a Fractional CFO and Tax Defense partner, not just a bookkeeper. When an audit is approaching, the practical work we do includes:

  • Books clean-up: identifying and correcting classification errors, unreconciled balances, and missing documentation before auditors see them.
  • PBC pack assembly: building the complete evidence pack, labelled and logged, so your team is not scrambling the week before fieldwork starts.
  • Pre-audit sweep: running the four-category quality check (classification, disclosure, tax, measurement) and producing a findings memo with fixes.
  • Automated evidence flows: setting up cloud accounting, bank feeds, and document management so evidence is always current and retrievable.
  • SARS representation: acting as your registered tax practitioner liaison for SARS notices, audit responses, and VDP applications.
  • Auditor liaison: serving as the single point of contact for external auditors, managing the evidence log and query responses so your operations are not disrupted.

For teams that want to understand the difference between an accountant and an auditor and how each role fits into audit preparation, that resource clarifies the boundaries and helps you assign the right tasks to the right people.

Pro Tip: If your books have not been formally reviewed in the past 12 months, start with a clean-up engagement before the audit begins. Auditors charge for time spent untangling records. A clean set of books handed to auditors on day one is the single fastest way to reduce your audit fee.


Audits are not threats — they are the annual proof of work

Most of the stress around audits comes from treating them as surprise inspections rather than scheduled reviews of work already done. If your records are current, your reconciliations are clean, and your controls are documented, an audit is largely a confirmation exercise.

The teams that dread audits are usually the ones doing a year’s worth of bookkeeping in the two weeks before fieldwork starts. The teams that sail through them have one thing in common: they treat month-end close as a mini-audit. Bank reconciliation done. VAT reconciled to the return. Payroll journals agreed to the EMP201. Fixed-asset register updated. That four-item habit, repeated every month, means there is almost nothing left to do when the auditors arrive.

One behavioural change makes the biggest difference: assign a permanent PBC owner. Not a role that rotates, not “whoever has time,” but one named person who owns the evidence folder year-round and keeps it current. That person becomes the institutional memory of your finance function.

For staff facing auditor interviews, the preparation is simple: answer factually, stay within your area of knowledge, and refer anything uncertain to the designated contact. Calm, evidence-first responses build auditor confidence faster than any amount of preparation documentation.


Readyaccounting makes audit preparation straightforward for South African SMEs

Preparing for an audit does not have to mean weeks of chaos. Readyaccounting’s managed accounting service handles the PBC pack, pre-audit sweep, and SARS representation so your team focuses on running the business. For SMEs that want a done-for-you approach, the engagement is simple: one discovery call to assess your current records, a clean-up phase if needed, and a structured handover to auditors with a fully logged evidence pack.

The difference between a smooth audit and a stressful one usually comes down to whether your books are current and your documents are findable. Readyaccounting builds the automated accounting infrastructure that makes both true year-round, not just at audit time. If SARS is involved, our tax defense team handles the correspondence and representation directly.

Book a discovery call with Readyaccounting to get your audit preparation started today.


Sources

Authoritative references for audit preparation in South Africa and internationally:

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.