Your audit fee went up again last year. The PBC list had more items than the year before. Your auditors raised a management letter point about IT controls, or switched to “a primarily substantive approach” and never quite explained what that meant in plain English.
What it meant was this: they didn’t trust your system to tell them the truth, so they checked everything by hand instead. And they billed you for every hour of it.
Most audit-readiness articles never have that conversation. They hand you a checklist and tell you to reconcile your bank early. None of them explain the structural reason your audit keeps getting harder, and why the fix isn’t a better folder structure. It’s a better finance system.
The Shift You Might Not Have Noticed
Your auditors are following a standard you may not have noticed change. ISA 315 (Revised 2019) came into force for accounting periods beginning on or after 15 December 2021, and it expanded what they must do around your IT environment. Before relying on a single balance in your accounts, they now have to identify the IT applications relevant to financial reporting, understand how your data flows through them, and identify the general IT controls — access, change management, data integrity — around those systems.
Your audit’s first half looks different now. It used to mean understanding your business, identifying risks, and testing balances. Now it also means understanding your IT environment, assessing whether your controls are sound, and then deciding how much of your data they can rely on.
If your finance system can answer those questions, your audit becomes shorter and quieter. If it can’t, the audit gets longer and more expensive. Your team isn’t slipping. Your system just can’t produce what your auditor now has to ask for.

Why Your Current System Can’t Produce The Evidence
If you’re on Sage 50 or Xero, this isn’t a criticism. Both do what they were designed to do; they just weren’t designed for audit evidence.
Sage 50: no field-level change history
Sage 50 doesn’t preserve the prior value of a transaction once it’s been edited. If your auditor asks what the invoice amount was before it was amended, you can’t tell them from the system. The change happened, but the system has nothing left to show.
Xero: activity logs without prior values
Xero has activity logs, but they aren’t granular enough for ISA 315. They don’t capture prior values, and the access controls are limited. A shared admin login, common in smaller finance teams, makes segregation of duties demonstrably indefensible.
Spreadsheets: every workbook is a break in the trail
When your auditor asks who changed cell D14 in the cost allocation model on 15 March, the answer is always the same: silence.
“Every Excel workbook in your close process breaks the audit trail.”
What it costs when the evidence isn’t in the system
Without supporting evidence from the system, your auditor moves to substantive testing. Larger samples. More queries. More time. The FRC’s Annual Review of Audit Quality 2025 found that 31% of audits reviewed outside the largest (Tier 1) firms still required significant improvements, with journals testing and general IT controls among the most common areas needing work.
That pressure doesn’t stay with the audit firm. It reaches you as more questions about access controls, user roles, and change management — and more billed hours. Audit Group’s 2026 benchmarks put mid-sized organisations at £15,000–£35,000 for statutory audit, with complex groups at £40,000 and above.
The Six Things Every Auditor Wants — And How Sage Intacct Answers Them
Walk back from the audit fee and you’ll find the same six evidence requests underneath almost every difficult audit. Here’s what each asks for, and what it takes to produce it from the system rather than by hand.
1. A complete, immutable audit trail
A transaction log isn’t enough. Your auditor needs every create, edit, and delete recorded with the user, the timestamp, the prior value, and the new value. Without those four, they can’t separate an error from a correction from a manipulation.
Sage Intacct’s audit trail captures all four on every record, and nothing is overwritten or lost. Your auditor can see what an invoice said before it was amended, alongside the change itself.
2. Demonstrable segregation of duties
Can the same person approve their own invoice? Raise and pay a supplier? Post and approve a journal? Where the system doesn’t enforce role boundaries, your auditor has to assume the worst and test for it.
Sage Intacct enforces separation through roles — AP Clerk, AR Clerk, Controller, Reviewer — each with its own permission set, configured at role level rather than person by person. Your auditor reads the role design instead of interviewing your team.
3. Controlled access and change history
Who has administrator access? Who had it last year? What changed in your chart of accounts, approval limits, or user roles during the period? If answering means calling your IT support line, your auditor has a problem.
Every login, successful and failed, is recorded with user ID, timestamp, IP address, and session duration. Configuration changes to the GL, AP, AR, and user roles are tracked the same way. Whether anyone amended the AP approval limit in October is a thirty-second lookup.
4. Reports they can reproduce from a single ledger
Hand your auditor an Excel export and they’ll ask whether the data could have been altered before extraction. They want a report they can regenerate from the system, with drill-through to the journal beneath it, and numbers that live in one place rather than a parallel spreadsheet universe to reconcile first.
Sage Intacct is a multi-dimensional GL, so every report runs off the same data your transactions sit in. Your auditor opens the trial balance, clicks through to the journal, clicks through to the supporting document. That drill-through is the evidence.
5. Journal entry controls
Journals are the highest-risk area in your general ledger. Does every journal carry a description and supporting documentation? Are they approved before posting? Are the unusual ones flagged — large, late, or posted by someone who doesn’t normally post journals?
Mandatory descriptions, mandatory supporting documentation, and approval workflows are built into posting. Exception reports can flag journals posted outside business hours, above a threshold, or by users without a standard posting role. That’s the exact control pattern the FRC keeps identifying as a gap in mid-market audits.
6. Reconciliation evidence
Your auditor wants the evidence that someone independent checked the reconciliation: who prepared the bank rec, who reviewed it, when, and what happened to the variances.
Close Automation creates a structured, reviewer-evidenced close record, so your auditor sees preparer, reviewer, date, and variance resolution in the system rather than a folder of PDFs. It also compresses the time it takes to reach an audit-ready position each period.
Underpinning all six, Sage Intacct holds an SSAE 18 SOC 1 Type II opinion audited twice yearly, and an annual SOC 2 Type II opinion. Under ISA 315, those attestations cut the work your auditor does on the platform itself, and the hours billed to you.

What Changes When Audit Becomes A Non-Event
A Grant Thornton survey of UK CFOs found that 68% want technology and automation enhancements to improve their close and reporting process. The controls that produce a fast close produce a fast audit. When your auditor can find their own evidence in the system, four things change.
A shorter PBC list and a quieter management letter
Your PBC list shrinks from 120 items to 40. Questions that used to spawn email threads become drill-throughs your auditor runs themselves. The management letter gets quieter too, because the control gaps behind it have been closed at system level rather than patched at year-end.
A controller who isn’t spending three weeks pulling evidence
The three weeks your controller normally spends assembling audit evidence compresses into a few days of pointing your auditor at the right reports. That returns senior finance time to analysis and decisions rather than reconstructing a paper trail that should have existed in the system all along.
An audit fee that stops climbing with testing scope
Your audit fee may not fall, but it stops growing in step with your auditor’s testing scope. When your IT general controls hold up under FRC pressure, your auditor doesn’t have to compensate with more substantive testing. Hours stop expanding, and the fee stops drifting upward.
Engagement-level evidence for regulated services firms
For law firms, wealth managers, and accountancy practices, the effect compounds. Engagement and matter-level data already lives in the system rather than in parallel workbooks, so it reaches your auditor through the same drill-through that produces your monthly P&L.
Where This Leaves Your Next Audit
The real question is about your finance system rather than your audit. Is it producing the controls, the evidence, and the time savings the rest of your business has been waiting for? Audit is simply where the gap shows up most expensively — once a year, in a fee letter you can’t argue with.
If it feels like a disruption rather than a formality, a conversation with us is a practical starting point.