The chain that produces your accounts is an audit object
Your financial statements do not come out of a hand-kept ledger: they come out of an application chain — ERP, interfaces, consolidation tools — whose reliability conditions that of the accounts. The international auditing standards have made it explicit: ISA 315 requires an understanding of the information systems underlying the accounts, ISA 330 requires responses tailored to the identified risks. That is exactly the portion we carry, in co-engagement with statutory auditors, for OHADA entities — consistent with the profession’s AUDCIF directives.
Our angle is singular: we audit systems we know from the inside. The ERPs whose application controls we test are the ones we deploy elsewhere — we know where configurations give way. And our auditors work on HOLOS, the ISA audit platform we built: ISA 300 engagement plans, structured files, multi-standard general report. Where the audit reveals weaknesses to fix over time, the natural continuation is a hardening and compliance programme.
Three moments justify the engagement: before an ERP go-live, to secure controls at design time rather than in remediation; after a migration, to verify data integrity and the preservation of audit trails; and as an annual recurring engagement, integrated into the statutory audit cycle.