Most of the content aimed at accounting firms about client communication assumes a single audience: the client. Bookkeepers, tax preparers, and general practice accountants build their workflows around getting documents from a client, doing the work, and delivering something back to that same client. Audit and advisory work doesn't fit that pattern. An audit file has to satisfy an audience that never asked for a single thing during the engagement — a regulator, or a professional body's monitoring team, sometimes years after the report was signed. Advisory work built around a transaction has an entirely different problem: for a few intense weeks, several outside parties who aren't the client at all need controlled access to the firm's most sensitive documents, and then that access has to disappear cleanly. Neither of those requirements has much to do with the file-sharing habits that work fine for a sole trader's annual return.
The File Doesn't Belong to the Firm Once the Report Is Signed
Statutory audit work in the UK is a reserved, regulated activity. A firm can't simply decide to sign audit reports — it has to be registered as a statutory auditor through a Recognised Supervisory Body, most commonly ICAEW, ACCA, or ICAS, and stay in good standing with that body's audit regulations to keep doing the work. Registration is the entry point; ongoing monitoring is where the file itself gets tested. Larger audits — generally those of public interest entities and other major companies — are inspected directly by the FRC's Audit Quality Review team. Every other ICAEW-registered firm is subject to monitoring visits from ICAEW's own Quality Assurance Department. Either way, the reviewer's job is to reconstruct, from the file alone, what judgment was made, on what evidence, and when.
That last word — when — is where ISA 230 puts a genuinely hard deadline on the work, one that has no real equivalent in general bookkeeping or tax practice. The standard requires the auditor to assemble the final audit file on a timely basis after the date of the audit report, and says this is "ordinarily" no more than 60 days. After that point, existing documentation can't be deleted or discarded, and any later additions have to be documented in a way that makes clear what was added, when, why, and by whom. The file then has to be retained for a period ISA 230 describes as ordinarily no shorter than five years from the report date — and many firms retain longer once professional indemnity insurance and limitation-period considerations are factored in.
Put plainly: a working paper an audit team uploaded in March has to be provably the same document eleven months later when a QAD reviewer or an FRC inspector opens the file, and the firm has to be able to show, without reconstructing it from memory, exactly when the final version was locked. A client portal built for gathering tax documents and firing off a few messages during filing season was never asked to do that. A version history that quietly overwrites the previous upload, or a shared drive where anyone with access can edit a file after the fact, is a real problem the moment a reviewer asks a question the file itself is supposed to answer.
Advisory Work Has the Opposite Shape of Risk
Audit risk is about proving nothing changed after a fixed date. Advisory and transaction work — due diligence support, valuations, restructuring, M&A-adjacent workstreams — has almost the opposite problem: a short, intense window in which the number of people who need access expands well beyond the client relationship the firm normally manages. A due diligence exercise typically pulls in the buy-side team, their lawyers, sometimes a separate financial due diligence provider, all of whom need to see specific documents — often unannounced management accounts, cap tables, or projections that can't circulate more broadly than the deal team that's supposed to see them. That's exactly why standalone virtual data rooms exist as a category in the M&A world: the access itself has to be logged, restricted to named individuals, and revocable the moment the deal closes or falls through.
An accounting firm doing advisory work for a client going through a transaction doesn't usually run a separate data room product for every engagement — but it inherits the same underlying requirement in miniature. Whoever the firm shares documents with during that period needs access scoped to that engagement specifically, not the client's entire history with the firm, and that access needs to be cleanly removable when the deal is done. A workspace where "give the buyer's advisers view access to these six documents for three weeks" is a genuine, auditable action — rather than an email attachment nobody can later account for — is doing something meaningfully different from a general client communication tool.
Want to see how this works in practice? Explore Osuria’s client portal
What This Actually Means When Choosing a Workspace
None of this is really about picking a portal with more features than a competitor's. It's about matching the tool to the two things audit and advisory work specifically ask for that ordinary compliance work doesn't: a document trail that can prove it wasn't altered after a fixed date, and access control that can be scoped tightly to a single engagement or deal and switched off cleanly when that engagement ends. A firm running audit or advisory alongside its compliance work is, in effect, running two different risk profiles through the same client relationships, and a workspace that only handles the second one leaves the more consequential half — the part a regulator or a counterparty's lawyers might actually examine — running on email and shared drives instead.
Osuria gives firms a branded client workspace built around exactly that kind of accountability: every document, upload, and access event tied to a specific client and time-stamped as it happens, rather than reconstructed after the fact from an inbox. For engagements where the file itself is the thing that eventually gets reviewed, that structure is the difference between producing an answer in minutes and reconstructing one under pressure.
If your firm's audit or advisory work needs a record that can stand up to more scrutiny than a typical client file, explore the Digital Workspace or start using Osuria to see what a fully documented, engagement-scoped workspace looks like.
Sources: ISA 230 Audit Documentation: A Practical Guide, LearnSignal; Become a registered auditor, ICAEW; Audit Quality Review (overview), FRC; How to prepare for a QAD monitoring visit, ICAEW; Due Diligence Data Rooms: 5 Best Providers in 2026, iDeals