Internal control evidence redaction is the removal of personal data from screenshots, logs, and approvals kept as proof of governance. Companies Act 2006 s.386(2)(c) requires accounting records sufficient to let the directors ensure the accounts comply with the Act. Controls are how that is achieved in practice. anonym.plus marks each identifier on your device, so the proof of a working safeguard stays while names go.
When this applies
Such proof shows user IDs, approver names, and emails in captured screens. An auditor builds an understanding of the system under ISA (UK) 315 (Revised), then performs tests of controls under ISA (UK) 330 para. 8. You strip the personal fields before the pack reaches an external reviewer.
How anonym.plus handles it
- Open the captured proof in anonym.plus on your device.
- Built-in OCR reads screenshot images and logs.
- The app marks user IDs, approver names, and emails.
- Keep timestamps and reference IDs intact.
- Replace or black out the confirmed identifiers.
- Save the clean files locally.
What you need to provide
- The evidence (PNG, PDF, XLSX, or log file).
- An operator (Redact suits screenshot images).
- Optional batch for many captured screens.
PII & financial identifiers detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | approver Linda Day → [APPROVER] |
| Contact | EMAIL_ADDRESS | l.day@example.co.uk → [EMAIL] |
| Identifiers | NATIONAL_ID | user staff ID → [USER_ID] |
| Identifiers | UK_NINO | shown NI number → [NINO] |
| Dates | DATE_TIME | approved 03/2026 → [DATE] |
| Org | ORGANIZATION | ERP vendor → [SYSTEM] |
Compliance achieved
- Preserves the control proof behind Companies Act 2006 s.386(2)(c) and the true and fair view in CA 2006 s.393.
- Keeps the timestamps and reference IDs an auditor needs for tests of controls under ISA (UK) 330 para. 8.
- Leaves the process understanding required by ISA (UK) 315 (Revised) intact once names go.
- For companies applying the UK Corporate Governance Code 2024, Provision 29 adds a board declaration on material controls for financial years beginning on or after 1 January 2026. Built-in OCR catches on-screen names.
Anonymise control evidence files offline — see plans & start free →
Limitations & cautions
A screenshot can show a unique screen layout or a rare role that hints at one user. Segregation-of-duties proof often needs two distinct approvers, so removing both names can weaken the evidence itself. The app marks visible names and IDs, not every contextual clue. Review captures before you share.
Frequently asked questions
Can it redact a screenshot of an approval screen?
Yes. On-device OCR reads the image, then marks the approver name, ID, or email so you can black it out.
Will reference IDs and timestamps survive?
Yes. Allow-list them. Tests of controls under ISA (UK) 330 para. 8 turn on when and how often a control ran, so only personal identifiers are marked.
Does the UK have an equivalent of a SOX internal-control report?
Not in the same form. Companies Act 2006 s.386 sets the records duty, and Provision 29 of the UK Corporate Governance Code 2024 asks boards that apply the Code for a declaration on material controls, for financial years beginning on or after 1 January 2026. There is no separate statutory attestation regime for every company.