Practice notes

When a platform upgrade changes the audit trail

An upgrade can be routine for IT and material for the people who have to explain last quarter’s numbers.

Hands typing at a laptop next to a notebook and coffee

Reporting platforms are upgraded for security patches, vendor support, or a new filing schema. From an audit point of view the question is narrower: did the upgrade change how figures are calculated, stored, or logged, and can last period’s run still be reproduced?

We have seen upgrades that silently recast mapping tables, reset user roles, or archive job logs into a format the current interface cannot search. None of those events are automatically a misstatement. All of them can make the next audit more expensive if nobody recorded what changed.

If you have an upgrade planned between two filing dates, write down the report definitions in force before the change, export a sample of run logs, and keep a copy of the mapping extract. If you want us involved, the right moment is before the cutover, not after the first return from the new version has already gone out.

Our remediation verification engagement exists partly for this situation: a named set of controls or calculations, re-tested on the new version, with a short letter that your board or external auditor can file beside the upgrade note.

More practice notes