Contact Info
What does an ERP audit cover for a Kenyan company?
An ERP audit for a Kenyan company is an independent review of a system the business already depends on. I test whether every invoice and credit note carries its eTIMS status, why M-Pesa receipts sit in suspense, how withholding certificates are tracked, whether depot stock can be trusted and who can do what. It is not a tax or statutory audit, and I deliver it remotely.
Last reviewed by Vikas Saroj
Many Kenyan businesses reach the same uncomfortable point a while after go-live. The ERP is running, but the accounts team spends the first days of each month clearing M-Pesa receipts from a suspense account, a branch still raises some invoices in a separate tool, and directors ask for stock and debtor reports that nobody is fully prepared to sign.
I review live ERP systems remotely for Kenyan companies as an independent consultant. The audit looks at configuration, data and daily practice side by side, then produces findings ranked by their effect on cash, compliance risk and management control. It covers the business system only; it does not replace your external auditor, your tax advisor or any review by KRA.
No vendor or implementer pays me anything, so the findings can say plainly whether a problem lies in the platform, the setup or the way it is used. The engagement runs in English, and any Kiswahili material in the system is checked by your own team.
Each area is tested with your own recent documents and the people who handle them, not with a generic checklist.
I compare the ERP's invoices and credit notes for a sample period with the records your team pulls from eTIMS, to find documents that were never transmitted, failed silently or were issued from another tool.
Unallocated M-Pesa and bank receipts are aged and traced to their cause, from missing account references to Paybill numbers mapped to the wrong entity or branch.
I review how withholding VAT and withholding tax certificates from customers are captured and matched to invoices, and how deductions on supplier payments are recorded, then list questions for your tax advisor.
Stock movements at depots and branches are tested against physical counts and delivery notes, including transactions captured on paper during outages and keyed in afterwards.
Shared branch logins, users who can both create customers and approve credit, supplier bank changes and dormant accounts are reviewed against the authority your directors intended.
Payroll postings, bank statement imports, POS or e-commerce links and reporting tools each need a named owner and visible error alerts, and I set license tiers against what staff genuinely use.
Questions, documents and access
Compare records with reality
Priorities with clear owners
An ERP that is quietly underperforming rarely produces a single dramatic failure. It shows up as recurring effort that everyone has learned to accept. In Kenyan businesses the signals to look for are fairly specific:
Each of these has a cause that can be found and usually fixed through configuration, rules, training or a better-built integration. The audit exists to find those causes, rank them and give your team and your implementer a clear list to work from, following my ERP health check method.
It is worth being clear about scope. This is a review of the business system. It is not a tax audit, it does not replace the work of your external auditor and it does not predict how KRA would view any transaction. Where a finding has a tax angle, I describe what the system does and pass the question to your tax advisor.
For businesses within its scope, eTIMS is how invoice data reaches Kenya Revenue Authority. During an ERP audit, the question is not how eTIMS works in general but whether every relevant document in your system actually went through, and whether the ERP shows that clearly.
I take a sample period and work with your team to compare three lists: the invoices and credit notes in the ERP, the validated documents your staff can retrieve from eTIMS, and any documents issued from other tools such as a POS or a standalone invoicing app. Differences usually fall into a few groups:
For each group I note where it originates in the setup or the connector, and who would fix it. I do not interpret KRA rules or decide what must be transmitted; the findings go to your tax advisor, who confirms the obligations before your implementer changes anything. How eTIMS should be specified in a new system is covered on the ERP business analyst page for Kenya.
Receivables in Kenya combine mobile money, bank transfers and deductions made by customers, and an ERP can handle all three well or turn them into a daily chore. The audit follows the money through each route.
For M-Pesa, I review which Paybill and Till numbers feed which entity or branch, how statements or payment notifications reach the ERP, and what reference customers are asked to enter. Then I take the unallocated list, age it and trace a sample of entries to the reason they failed to match: a phone number instead of an account code, a payment split across invoices, a reversal posted twice or a Paybill mapped to the wrong company. The pattern of causes points to the fix.
For withholding, I look at how certificates received from customers are recorded and linked to the invoices they relate to, and whether the system can show which deductions still lack a certificate. On the payables side I check how withholding on supplier payments is calculated and documented. Treatment and rates are for your tax advisor to confirm; my part is showing where the records are incomplete or disconnected.
Bank receipts in shillings and dollars complete the picture, including how bank statements are imported and how exchange differences on dollar receipts are posted. Many of these fixes are matching rules and configuration, the territory of ERP optimization.
Distribution, manufacturing and retail businesses in Kenya often run depots or branches far from head office, sometimes with patchy connectivity. These sites are where system discipline erodes first, and where the audit spends real time.
On stock, I compare a sample of system quantities with recent counts, then trace the differences through delivery notes, transfers and returns. Typical causes include transfers dispatched but never received in the system, returns booked as new stock, and sales recorded on paper during an outage and keyed in days later with the wrong date. Each one distorts both stock value and margin reports.
On access, branch practice often diverges from head office policy. I check for:
Where a small branch cannot realistically separate every duty, I suggest compensating checks that head office can run. Personal data held in the system is noted so whoever is responsible under Kenya's data protection law can review the arrangements. If depot connectivity is causing deeper operational failures, the ERP rescue page for Kenya covers resilience in more depth.
The remaining areas cover what flows into the ERP and what the company pays for. Payroll in Kenya is commonly processed outside the ERP, in dedicated software or by an outsourced payroll bureau that deals with statutory deductions. I do not review the payroll calculations, but I check the posting interface: whether salaries, deductions and employer costs arrive in the right accounts, departments and entities, and whether someone corrects the journal by hand each month.
Dollar balances get a focused check. I look at how exchange rates are entered and by whom, whether bank accounts, debtors and creditors in dollars are revalued consistently, and whether management reports show currency exposure in a way your accountant accepts.
Licenses are compared with real use, and add-ons or connectors nobody depends on are listed. Commercial decisions stay between you and your vendor.
The report gives directors a short summary of the most important findings, then the full list with cause, business effect, recommended fix and a priority rating. Tax-related observations, such as eTIMS gaps or withholding records, sit in a separate section for your tax advisor. I present the findings in an online session and can stay involved while your implementer works through them.
For wider context, see the Kenya overview, the ERP consultant page for Kenya and the Nairobi page.
Tell me about your business and current systems. I’ll suggest the most sensible first step.
Book a Consultation
Not sure which ERP you need?
Share your business requirements with me and I will help you understand the right process, architecture and platform before implementation.
No. A tax audit is carried out by the tax authority, and the annual audit by your external auditor. My ERP audit looks only at how your business software is configured, the quality of its data, its internal controls, its connections and its reporting. Some findings, such as untransmitted credit notes, have tax implications, and those are described factually for your tax advisor to assess and act on.
I do not need direct access to your KRA accounts, and it is better that I do not have it. Your team retrieves the relevant records for the sample period and shares them, and I compare them with the ERP documents. That keeps credentials with the people responsible for them.
It should not. Findings describe system behavior and its business effect, not personal blame, and many issues come from requirements that were never written down. A clear, ranked list usually helps a small implementer, because it replaces scattered complaints with a defined set of tasks they can plan and price.
Read-only access to the ERP, a handful of exports such as user lists and receipt reports, the eTIMS records for a sample period, and short screen-sharing sessions where finance and branch staff show their normal work. I plan the sessions around month-end so they do not compete with the close.
Every business is different. Share where you are today and what you want to fix, and I’ll tell you honestly whether and how I can help.
Book a Consultation
Book a consultation to talk through your processes, systems and goals. I’ll reply with practical next steps - no obligation.