Audit Workpaper Redaction with anonym.plus

Clear client personal data from a working paper before the engagement file moves.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Audit workpaper redaction is the removal of client personal data from engagement documentation. ISA (UK) 230, issued by the FRC, sets the rule. Paragraph 8 requires a file an experienced auditor with no prior connection could follow. Paragraph 9 requires the identifying characteristics of the items tested to be recorded. anonym.plus marks each identifier locally, so the evidence trail stays whole while the personal fields go.

When this applies

A working paper cites sampled employees, signatories, and account holders by name. Paragraph 14 requires the final file to be assembled on a timely basis after the auditor's report, and application material A21 puts that at ordinarily no more than 60 days. You clear personal detail before the binder reaches a reviewer or an FRC inspector.

How anonym.plus handles it

  1. Open the engagement file in anonym.plus on your device.
  2. Built-in OCR reads scanned tick-marks and confirmations.
  3. The app marks names, references, and account numbers.
  4. Keep tick-mark legends and cross-references intact.
  5. Replace or black out the confirmed identifiers.
  6. Save the clean binder locally with no network call.

What you need to provide

PII & financial identifiers detected

Categoryanonym.plus entity typeExample
NamesPERSONsampled staff R. Ode → [EMPLOYEE]
IdentifiersUK_NINOQQ 12 34 56 C → [NINO]
FinancialUK_BANK_NUMBERsupplier acct 0091 → [ACCOUNT]
ContactEMAIL_ADDRESSr.ode@example.co.uk → [EMAIL]
OrgORGANIZATIONAcme Foods Ltd → [CLIENT]
DatesDATE_TIMEdate of birth 1980 → [DOB]

Compliance achieved

Anonymise audit workpapers offline — see plans & start free →

Limitations & cautions

ISA (UK) 230 requires the file to support the conclusions reached. Remove personal data, not the evidence behind a sign-off. Paragraph 16 also requires the reason for any change made after assembly to be recorded, with who made it and when. The app marks identifiers; you keep what the standard demands.

Frequently asked questions

Will my cross-references survive the pass?

Yes. Use the allow-list to protect tick-mark codes and index numbers. ISA (UK) 230 para. 9 wants those identifying characteristics on file, so only personal identifiers are marked for removal.

How long must the engagement file be kept?

ISA (UK) 230 para. 15 bars deletion before the retention period ends, and application material A23 puts that period at ordinarily no shorter than five years from the date of the auditor's report. Redacting a copy you share does not shorten it, because the retained file is a separate thing.

Is the engagement file sent anywhere?

No. The desktop app works on your machine with no cloud step. Batch mode handles up to 20 files per local run, with OCR for any scanned schedule.