Audit workpaper redaction is the removal of client personal data from engagement documentation. ISA (UK) 230, issued by the FRC, sets the rule. Paragraph 8 requires a file an experienced auditor with no prior connection could follow. Paragraph 9 requires the identifying characteristics of the items tested to be recorded. anonym.plus marks each identifier locally, so the evidence trail stays whole while the personal fields go.
When this applies
A working paper cites sampled employees, signatories, and account holders by name. Paragraph 14 requires the final file to be assembled on a timely basis after the auditor's report, and application material A21 puts that at ordinarily no more than 60 days. You clear personal detail before the binder reaches a reviewer or an FRC inspector.
How anonym.plus handles it
- Open the engagement file in anonym.plus on your device.
- Built-in OCR reads scanned tick-marks and confirmations.
- The app marks names, references, and account numbers.
- Keep tick-mark legends and cross-references intact.
- Replace or black out the confirmed identifiers.
- Save the clean binder locally with no network call.
What you need to provide
- The working paper or binder (PDF, XLSX, DOCX, scan).
- An operator: Replace, Redact, or Mask.
- Optional batch for a binder of many schedules.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | sampled staff R. Ode → [EMPLOYEE] |
| Identifiers | UK_NINO | QQ 12 34 56 C → [NINO] |
| Financial | UK_BANK_NUMBER | supplier acct 0091 → [ACCOUNT] |
| Contact | EMAIL_ADDRESS | r.ode@example.co.uk → [EMAIL] |
| Org | ORGANIZATION | Acme Foods Ltd → [CLIENT] |
| Dates | DATE_TIME | date of birth 1980 → [DOB] |
Compliance achieved
- Aligns with ISA (UK) 230 para. 8, which wants a file an experienced auditor could follow unaided.
- Keeps the identifying characteristics of tested items that ISA (UK) 230 para. 9 requires, such as tick-marks and index references.
- Respects ISA (UK) 230 para. 15: once the final file is assembled, nothing may be deleted before the retention period ends, which ISA (UK) 230 A23 puts at ordinarily five years from the report date.
- Companies Act 2006 s.499 gives the auditor access to the company's books, accounts, and vouchers; redacting a shared copy does not touch that right. Offline work keeps the file inside your practice, with AES-256-GCM at rest.
Anonymise audit workpapers offline — see plans & start free →
Limitations & cautions
ISA (UK) 230 requires the file to support the conclusions reached. Remove personal data, not the evidence behind a sign-off. Paragraph 16 also requires the reason for any change made after assembly to be recorded, with who made it and when. The app marks identifiers; you keep what the standard demands.
Frequently asked questions
Will my cross-references survive the pass?
Yes. Use the allow-list to protect tick-mark codes and index numbers. ISA (UK) 230 para. 9 wants those identifying characteristics on file, so only personal identifiers are marked for removal.
How long must the engagement file be kept?
ISA (UK) 230 para. 15 bars deletion before the retention period ends, and application material A23 puts that period at ordinarily no shorter than five years from the date of the auditor's report. Redacting a copy you share does not shorten it, because the retained file is a separate thing.
Is the engagement file sent anywhere?
No. The desktop app works on your machine with no cloud step. Batch mode handles up to 20 files per local run, with OCR for any scanned schedule.