[codicts-css-switcher id=”346″]

Global Law Experts Logo
audit evidence requirements ghana

Audit Evidence Requirements in Ghana (2026): What Businesses Must Keep

By Global Law Experts
– posted 2 hours ago

Audit evidence requirements Ghana finance teams face in 2026 are no longer satisfied by a filing cabinet of paper invoices and a shoebox of receipts. Auditors and quality-review teams now expect a defensible mix of paper originals, high-fidelity scans and, increasingly, system-generated evidence extracted directly from your ERP or cloud accounting platform, complete with timestamps, transaction identifiers and access logs. This practical guide explains exactly what documentary and digital records auditors expect during statutory audits and regulatory reviews, how long you must retain them, and the concrete steps to make electronic evidence audit-ready. It is written for finance managers, audit committees, in-house finance teams and directors of SMEs and medium enterprises preparing for a Ghanaian statutory audit.

By the end you will know:

  • What “audit evidence” means under international standards and Ghanaian statute.
  • The precise list of paper, scanned and system-generated records auditors request.
  • Statutory retention minimums and recommended retention for audit defence.
  • How paper, scanned images and system-generated evidence compare on authenticity and admissibility.
  • A step-by-step method to export, authenticate and archive digital evidence.

What “audit evidence” means in Ghana, standards and statutory framework

Audit evidence is the information an auditor uses to reach the conclusions on which the audit opinion is based. It must be both sufficient (enough of it) and appropriate (relevant and reliable). In practice, that means a Ghanaian business must be able to hand over records that are complete, traceable to the underlying transaction, and verifiable without excessive reconstruction. The audit evidence requirements Ghana businesses meet are set at two levels: the professional auditing standards that govern how auditors work, and the statutes and regulations that dictate what companies must create and keep.

International and local standards that apply (ISA 230 and ICAG guidance)

Ghanaian statutory audits are performed under International Standards on Auditing (ISAs) as adopted locally. The cornerstone standard for documentation is ISA 230, issued by the International Auditing and Assurance Standards Board. ISA 230 requires auditors to prepare and retain audit documentation sufficient to enable an experienced auditor, with no previous connection to the engagement, to understand the work performed and the conclusions reached. While ISA 230 governs the auditor’s own file, it directly shapes what the auditor demands from you: if the auditor must evidence the nature, timing and extent of procedures performed, they will ask you for records that support each figure in the financial statements.

The Institute of Chartered Accountants, Ghana (ICAG) adopts these standards and issues local guidance for its members, including expectations around documentation and the auditor’s responsibilities when relying on system-generated data. Meeting the audit evidence requirements Ghana regulators expect therefore means aligning your recordkeeping to both the global standard and ICAG’s local pronouncements.

Relevant Ghana statutes and regulators

Several statutory and regulatory obligations create the underlying duty to keep records:

  • Companies law. Under the Companies Act, 2019 (Act 992), companies must keep proper accounting records that disclose their financial position with reasonable accuracy and enable financial statements to be prepared and audited. These records are the primary source of audit evidence.
  • Tax rules (GRA). The Ghana Revenue Authority, under the Revenue Administration Act, 2016 (Act 915), requires businesses to keep records supporting tax returns and tax positions and to produce them on demand during reviews.
  • Data protection. Where audit evidence contains personal data, most obviously payroll and employee records, the Data Protection Act, 2012 (Act 843), administered by the Data Protection Commission, requires lawful, secure storage and disciplined retention and deletion.
  • Sector regulation. Financial institutions face additional recordkeeping expectations from the Bank of Ghana, which sets prudential and documentation standards for regulated entities.

The public sector operates under a parallel framework administered by the Ghana Audit Service, which audits public bodies. Private-sector businesses are audited by ICAG-licensed practitioners, but the underlying evidence principles, completeness, authenticity and traceability, are common to both.

Required records, paper, scanned and system-generated audit evidence in Ghana

The single most useful thing a finance team can do before an audit is assemble a complete evidence pack. Below is the practical inventory of what auditors ask for, organised by category. Meeting the audit evidence requirements Ghana auditors apply in 2026 means having each item ready in a format the auditor can verify.

Typical documents auditors request

Core financial and supporting records include:

  • Financial statements and trial balance. Draft and prior-year signed statements, with the trial balance that ties to the general ledger.
  • General ledger and sub-ledgers. Complete GL, accounts receivable and payable sub-ledgers, and fixed asset registers.
  • Journals. Manual and system journals, especially adjusting, reversing and consolidation entries, with narrative and approver identity.
  • Supporting invoices and receipts. Sales invoices, purchase invoices, credit notes and expense receipts matched to ledger entries.
  • Bank statements and reconciliations. Full-period statements for every account with month-end reconciliations.
  • Contracts and agreements. Loan agreements, lease contracts, supplier and customer contracts, and board minutes authorising material transactions.
  • Tax filings. VAT returns, PAYE filings, corporate tax computations and assessment notices.

Provide these in the formats auditors most readily accept: searchable PDF or PDF/A for documents, and native spreadsheet files (XLSX or CSV) for ledgers and reconciliations so figures can be re-totalled and traced.

System-generated evidence (ERP extracts, transaction logs, access logs)

System-generated evidence has become the fastest-growing category of audit evidence Ghana practitioners request. Because it is produced by the accounting system itself, it carries stronger authenticity when the supporting controls are documented. Prepare:

  • ERP transaction extracts. Full-period exports of every transaction with transaction IDs, posting dates, document dates, amounts and account codes.
  • Change logs. Reports showing edits to posted entries, who changed what, when, and the before/after values.
  • Access and user logs. Records of user IDs, login events and permission levels, evidencing segregation of duties.
  • Batch-job and interface reports. Logs of automated postings, imports and integrations, including any error and rejection reports.

Auditors will look for timestamps, user identifiers, digital signatures where available and an unbroken audit trail linking the extract back to source transactions.

Payroll and statutory payroll records

Payroll audit records in Ghana attract particular attention because they combine financial, tax and personal-data obligations. Retain payroll registers, individual payslips, PAYE and SSNIT computations and remittance evidence, timesheets or attendance records supporting variable pay, and the payroll system’s change and approval logs. Because these records contain personal data, storage and deletion must comply with Data Protection Commission requirements as well as tax retention rules.

Retention periods, statutory minimums and recommended practice

Knowing what to keep is only half the task; knowing how long to keep it is where many businesses fall short. Retention obligations for the audit evidence requirements Ghana businesses face come from multiple regulators, so the safest approach is to retain to the longest applicable period.

Statutory retention, mapping regulator to period

Record type Governing regulator / basis Minimum retention Recommended best practice
Tax records (income tax, VAT, PAYE support) Ghana Revenue Authority (Act 915) At least 6 years, as required by the GRA 7–10 years
Accounting records and financial statements Companies Act, 2019 (Act 992) Per statutory accounting-records duty 7–10 years
Payroll and employee financial records GRA + labour compliance Align to tax minimum 7 years, subject to data-protection review
Personal data within records Data Protection Act, 2012 (Act 843) No longer than necessary for the purpose Retain to statutory need, then delete securely
System logs (change, access, batch) Recommended (ISA/ICAG expectation) Match underlying transaction period 7–10 years for defensibility
Regulated financial-institution records Bank of Ghana Per regulatory directive Follow sector guidance, retain conservatively

Note the tension between two obligations: tax rules push you to keep records for a fixed statutory period, while data-protection principles require you not to keep personal data longer than necessary. The resolution is a documented retention schedule that keeps records for the statutory period and then applies secure, logged deletion.

Recommended retention for audit defence and quality reviews

Statutory minimums are the floor, not the ceiling. For audit defence, responding to a later dispute, a tax reassessment or an ICAG quality review, a retention window of 7 to 10 years for core accounting evidence and system logs is prudent. Quality reviewers may examine engagements retrospectively, and if the underlying client evidence has been discarded, the audit trail collapses. Retaining raw ERP exports alongside human-readable reports for the full window gives you the strongest position if a figure is ever challenged.

Comparison table, paper vs scanned images vs system-generated evidence

The decisive question for many finance teams in 2026 is which format to rely on. This is not a matter of preference; each format carries different weight, controls and risks. Our recommendation is direct: lead with system-generated evidence, backed by scanned source documents, and retain paper originals where statute or the transaction type genuinely requires them. System-generated exports, when accompanied by their logs and control documentation, give auditors a strong and efficient audit trail. Paper alone can be the weakest position for a modern audit because it is the hardest to verify at scale and the most vulnerable to loss.

Dimension Paper originals Scanned / PDF images System-generated evidence (ERP/cloud exports & logs)
Legal basis / recognition Traditionally accepted physical evidence; companies and tax rules reference originals Accepted if accurate, legible and a true copy retained with chain-of-custody Increasingly accepted by auditors and regulators when audit trail and authenticity are proven; must meet ISA/ICAG expectations
Typical statutory retention Varies, tax at least 6 years Same as originals; ensure readability for full period Same statutory periods; retain logs longer (7–10 years recommended)
Authentication / audit trail Signature, watermark, original stationery Metadata and scan date; must link to original receipt/transaction Transaction IDs, timestamps, user IDs, change logs, hash/signature, strongest trail
Admissibility in audit High when original available Acceptable when traceable to original and verified High when export includes all fields and controls are documented
Required controls Physical filing controls; signer verification Chain-of-custody log; retention policy proving provenance Access controls, segregation of duties, backup logs, immutability, export procedures
Typical formats Paper PDF/A preferred; high-resolution images; OCR optional CSV/XLSX raw exports; PDF reports; JSON/XML for APIs; compressed archives for bulk
Risks Loss, deterioration, forgery Missing metadata; poor scans; OCR errors Manipulation if no logs; missing context; vendor lock-in
Recommended practice (2026) Keep originals where required; maintain an index Use PDF/A; add a metadata manifest; link scan to original Export raw data plus human-readable report; preserve logs; apply hashing; store read-only

Reading the table as a decision: if a record exists natively in your accounting system, the system export is your primary evidence and you should preserve its logs. If a record originates on paper, a signed contract, a stamped tax assessment, scan it to PDF/A, link the scan to the transaction, and keep the original where the law or the counterparty requires it. Do not rely on scans without provenance, and do not rely on system exports without their supporting logs.

How to make system-generated evidence audit-ready

System-generated evidence only earns its stronger status if it is exported, authenticated and stored correctly. The following method works across common ERP and cloud accounting platforms and directly addresses the audit evidence requirements Ghana practitioners apply to digital records.

Exporting reliable ERP and cloud accounting extracts

Follow a disciplined export routine so the auditor receives complete, reconcilable data:

  1. Use the system’s built-in export function rather than copying data manually, so field integrity is preserved.
  2. Export the full period with no filters applied, then provide filtered views separately if requested, this proves completeness.
  3. Include every key field: transaction ID, posting date, document date, user ID, account code, amount and narrative.
  4. Export in raw format (CSV or XLSX) for reconciliation and a human-readable PDF report for review; for integrations, include JSON or XML API extracts.
  5. Generate and attach the matching reconciliation report so the extract ties to the trial balance and financial statements.
  6. Record the export timestamp and the user who performed it in a short cover manifest accompanying the files.

Ensuring authenticity: timestamps, hashing, e-signatures and reconciliation

Authenticity is what turns an export into evidence. Capture the system timestamp and user ID on every extract. Where your tools allow, generate a cryptographic hash of each exported file at the point of export and record it in the manifest, so any later alteration is detectable. Preserve the change logs and access logs alongside the data extract, these demonstrate that posted figures were not silently edited. Apply e-signatures to approval reports where the system supports them, and always accompany raw data with a reconciliation to the general ledger and financial statements so the auditor can trace every total.

Practical policies: retention schedule, version control and immutable storage

Technology alone is not enough; the controls around it complete the picture:

  • Retention schedule. Maintain a documented schedule mapping each record type to its statutory minimum and recommended period, with an owner accountable for compliance.
  • Version control. Keep the original raw export unaltered; any working copies for analysis must be clearly separated and labelled.
  • Backup and immutability. Store finalised evidence packs in read-only, immutable archives with logged backups, so evidence cannot be quietly overwritten and can be restored on demand.
  • Access governance. Restrict export rights, enforce segregation of duties, and log who can extract and who can approve.

Common auditor queries and how to respond

Example requests

Recurring auditor requests include third-party confirmations (bank, debtor and creditor balances sent independently to counterparties), bank reconciliations tying statements to the cashbook, and subsequent-events documentation covering material transactions or contracts arising after the reporting date but before the audit opinion. Prepare these proactively: draft confirmation letters early, finalise reconciliations at period close, and keep a running log of post-year-end events with supporting documents.

Preparing documents and securing chain-of-custody for remote audits

Remote and hybrid audits are now common, so structure a single, indexed evidence pack rather than sending files ad hoc. Organise folders by audit area, include a manifest listing every file with its export date and hash, and share through a secure, access-logged channel rather than open email. This preserves chain-of-custody, the demonstrable record that evidence has not been altered between your system and the auditor’s file, which is central to how the audit evidence requirements Ghana reviewers apply to electronic records in 2026.

Practical annex, suggested retention schedule and evidence-pack checklist

Use the retention table earlier in this guide as the basis for a formal retention schedule your finance team can maintain as a spreadsheet, with columns for record type, regulator, minimum period, recommended period, storage location and responsible owner. Alongside it, keep a printable evidence-pack checklist so nothing is missed before fieldwork.

A practical “top documents to show auditors” pack should contain:

  • Signed prior-year financial statements and current trial balance.
  • Full-period general ledger and sub-ledger exports (raw plus PDF).
  • Bank statements and completed reconciliations for every account.
  • Sales and purchase invoice registers with samples matched to the ledger.
  • Journals with approver identity, especially adjusting entries.
  • Contracts, board minutes and loan/lease agreements for material items.
  • Tax filings, VAT, PAYE and corporate tax computations with remittance evidence.
  • Payroll register, payslips, SSNIT and PAYE support with system logs.
  • ERP change logs, access logs and batch-job reports.
  • Fixed asset register with additions, disposals and depreciation support.

Next steps: strengthening your audit evidence requirements in Ghana

Meeting the audit evidence requirements Ghana businesses face in 2026 is a matter of preparation, not last-minute scramble. Build a documented retention schedule, standardise your ERP export routine, preserve system logs, and assemble an indexed evidence pack before fieldwork begins. Doing so shortens audits, reduces queries and protects you in any later review. For tailored guidance on audit methodology, ERP and cloud evidence, and building a compliant retention framework, specialist advisory support can help you translate these principles into working policies. Explore ERP audit readiness, Ghana Legal Guide 2026 and the Global Law Experts Audit & Assurance directory for further reading, or contact a qualified adviser for advice on your specific circumstances.

This guide reflects professional audit-advisory best practice and interpretation of standards. It is general information for finance teams and audit committees, not legal advice. Confirm current statutory requirements with the relevant regulator or a qualified professional.

Need Expert Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Richard Dwumor at RDK Consulting Services, a member of the Global Law Experts network.

Sources

  1. International Auditing and Assurance Standards Board (IAASB), ISA 230 Audit Documentation
  2. International Federation of Accountants (IFAC)
  3. Institute of Chartered Accountants, Ghana (ICAG)
  4. Ghana Revenue Authority (GRA)
  5. Ghana Audit Service
  6. Bank of Ghana
  7. Data Protection Commission, Ghana

FAQs

What is the minimum time I must keep financial records in Ghana?
Statutory minimums vary by regulator. Tax records supporting returns are generally kept for the period required by the Ghana Revenue Authority (commonly at least six years), and accounting records must be maintained under the accounting-records duty in the Companies Act, 2019 (Act 992). Recommended practice for audit defence and quality reviews is 7 to 10 years for core records and system logs. Confirm the current requirement with the GRA and your auditor.
Yes, provided the scans are complete, legible, linked to their provenance and retained under a documented chain-of-custody. Prefer PDF/A with a metadata manifest, and keep paper originals where statute or the transaction type requires them. This aligns with ISA documentation principles and ICAG local practice.
System-generated evidence is data exported from your ERP or cloud accounting platform, transaction extracts, change logs, access logs and batch reports, that includes transaction IDs, timestamps and user IDs. It meets the audit evidence requirements Ghana auditors apply when accompanied by documented controls proving authenticity and an unbroken audit trail, consistent with IAASB/ICAG expectations.
Use the built-in export function, export the full period with all key fields, and provide both raw files (CSV/XLSX or JSON) and a human-readable PDF report. Include the reconciliation to the trial balance, record the export timestamp and user ID in a manifest, and apply file hashing where available.
No, not until statutory retention has been met. Payroll records must be retained for the applicable tax and labour-compliance period, and because they contain personal data they must also be handled under Data Protection Act, 2012 (Act 843) requirements. Delete only through a logged, secure process once the retention period expires.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Audit Evidence Requirements in Ghana (2026): What Businesses Must Keep

Send welcome message

Custom Message