
The first statutory audit is a step change. Not because the numbers get harder, but because for the first time someone independent asks you to evidence what you have been asserting.
Most growing companies do not fail this because their controls are bad. They fail because their controls are informal — real in practice, invisible in evidence.
Audit requirements under the Corporations Act depend on entity type, size and ownership — and the thresholds change. Foreign-controlled entities and companies with certain shareholder structures can have obligations that surprise founders.
Your auditor or company secretary should confirm your position against the current thresholds. Do not assume, and do not rely on a figure you read somewhere — including here.
Separately, investors frequently require audited accounts contractually well before the law does.
Segregation of duties. The person who creates a supplier should not be the person who approves the payment to them. In a five-person finance team this is genuinely hard, and auditors know that — what they want is either separation or a documented compensating control, such as review of a payments report by someone outside the process.
Approval authority. A documented delegation of authority: who can approve what, to what value. It has to exist in writing and be enforced by the system, not just understood.
Period close controls. Periods locked after close. Journals reviewed and approved before posting. A clear trail of who did what and when.
Access controls. Role-based permissions that reflect actual job function, reviewed periodically, with joiners and leavers processed promptly. A former employee's active login is a finding.
Reconciliation controls. Balance sheet reconciliations prepared, reviewed and signed by different people, with the review evidenced rather than assumed.
Here is the pattern we see constantly. A company genuinely does review journals — the financial controller looks at every one. But the review happens by looking at a screen, and nothing records that it happened.
From the auditor's perspective, an unevidenced control did not occur. Not because they doubt you, but because they cannot test it.
This is why system-enforced controls matter more than policy documents. When approval is a workflow step, the evidence is a by-product of doing the work. When approval is a conversation, the evidence has to be manufactured afterwards — usually the week the auditors arrive.
If your first audit is within twelve months, in priority order:
Not perfection. Auditors work with growing companies constantly and understand resource constraints.
What they value is a finance team that knows where its own weaknesses are, has documented them, and has a plan. A known and mitigated control gap is a conversation. An unknown one discovered during fieldwork is a finding, and it raises questions about everything else.
Tell your auditor about the messy bit before they find it. It changes the entire tone of the engagement.
Everything above is also what you need for a due diligence, a debt facility, or a SOC 2 process. Building it once for the audit means it is already in place when a term sheet arrives with a two-week diligence window.
We configure control frameworks as part of implementation — approval workflows, period locks, role-based permissions and reconciliation processes that produce evidence automatically.
If you have an audit coming and are not confident the controls will evidence themselves, that is a good six-months-ahead conversation.