,

Audit Software vs Excel and SharePoint: When to Switch, and How Big You Need to Be

Every internal audit function starts on spreadsheets, and a meaningful share never leaves them. Gartner’s own research puts adoption of dedicated audit management software at 84 percent of audit functions, based on 259 departments surveyed as of September 2026, which still leaves a real minority of functions of every size running their plan, workpapers and issue tracking through some combination of Excel, SharePoint and Microsoft Teams. That is not automatically a mistake. A one- or two-person shop with a short, low-complexity plan can document a defensible audit in a well-organized spreadsheet, and some of the reasons people give for wanting to switch — better dashboards, an AI feature, a nicer interface — are really requests for a discipline problem to be solved by a subscription instead of a folder structure. The more useful question is not whether spreadsheets are good enough in general. It is at what point, for a function your size running your kind of plan, they stop being good enough for you.

This guide sets out what Excel, SharePoint, Teams and this site’s own free tools can do well for internal audit, the eight signs that reliably mean a function has outgrown them, a sizing table that pairs team size with plan complexity, and a worked hours estimate for a six-person function still running everything by hand. It also gives the cheapest credible paid entry points in the public record, with sources, for functions that decide to switch, and a folder, naming and retention template for functions that decide to stay a while longer. For the fuller shortlist once you are ready to compare named products, see the site’s guide to types of internal audit software and the best internal audit software roundup; for a function of one to five people specifically, the guide to software for small teams goes deeper on real options and prices.

How to read this guide

What this guide is for. A threshold decision, not a product shortlist: whether your internal audit function has outgrown Excel, SharePoint and Teams, and roughly what switching should cost at your size if it has. It is written for a function of any size still running its plan, workpapers and issues by hand, and for a new audit manager or CAE inheriting a spreadsheet-based setup and deciding whether to change it.

Evidence. Research-based: Gartner and IIA survey data, public procurement and pricing records, and vendor documentation. We have not run the paid products named on this page hands-on for this guide.

Last verified. 27 September 2026.

In this guide

What Excel, SharePoint and Teams do well

Dismissing the spreadsheet stack outright gets the incentives backward. It costs nothing beyond what the organization already pays for Microsoft 365, everyone on the audit team and every auditee already knows how to use it, and it carries no vendor renewal, no per-user pricing and no migration risk if the function later changes its mind. For a low-volume plan, SharePoint document libraries genuinely do version history and access control well — the failure mode described later in this guide is usually that a function never turns those features on, not that SharePoint cannot do the job. Four of this site’s own tools exist specifically to close the remaining gaps for free: a risk and control matrix builder, a sampling tool, a self-assessment tool and a time and engagement log, all listed together on the site’s free audit tools page. None of them replace a full platform’s workflow, but together with a disciplined SharePoint setup they cover more ground than most spreadsheet-based functions actually use.

The table below separates what the stack genuinely does well from what it does only with real, ongoing discipline from the team using it.

TaskExcel, SharePoint and TeamsThe catch
Workpaper storage and version historyNative SharePoint document libraries do this wellOnly if version history is turned on and nobody keeps a personal desktop or OneDrive copy
Risk and control matrixA spreadsheet template works at any sizeThe site’s free RCM Workbench adds structure and export without a template to maintain
SamplingExcel formulas handle random and interval samplingThe site’s free sampler removes the formula-error risk on judgment calls
Self-assessment and QAIP checksA checklist workbook worksThe site’s free self-assessment tool structures the same checklist
Time and engagement trackingExcel or Teams Planner both workNeither ages or escalates on its own; myDayLog is a free, purpose-built alternative
Basic analyticsPivot tables, VLOOKUP and Power Query cover most testsStill one person’s formulas, not a reproducible, reviewable script

SharePoint and Teams also carry real governance tools that most functions never turn on. Microsoft Purview retention labels can enforce a fixed retention period on a document library without anyone remembering to apply it by hand, and sensitivity labels can restrict who opens a workpaper outside the audit team without building a separate access system. Teams channels tied to a SharePoint site keep engagement discussion attached to the engagement rather than scattered across email threads that never make it into the file. A function using SharePoint as “just a shared drive” is paying for a governance layer it has switched off; the “stay on Excel well” section later in this guide turns these settings into a checklist.

None of this is a reason to buy software early. The site’s own guides to Excel and data analysis tricks for internal auditors and to Excel versus Google Sheets and Apple Numbers cover the spreadsheet choice itself; assume for the rest of this guide that the spreadsheet is not the problem, and the real question is what the stack around it needs to do that a spreadsheet was never built to do.

Eight signs you have outgrown them

The signals below are not feature envy. Wanting an AI summary or a nicer dashboard is not, by itself, a reason to switch; a function that hits several of the eight signs below usually has an operational problem that a spreadsheet stack cannot fix by being used more carefully.

  • Review evidence goes missing or gets overwritten. Once a workpaper has been saved a dozen times by three people, “who reviewed this, and when” stops having a reliable answer. SharePoint’s native version history helps only if it stays switched on and nobody works from a synced local copy that breaks the chain.
  • Version control breaks down in ordinary use. A function with more than one auditor eventually gets a file named something like “RCM_v3_final_reallyfinal.xlsx,” and the site’s own risk and control matrix template guide exists partly because that pattern is so common.
  • Issue follow-up slips. Nothing in a spreadsheet ages a past-due action plan or escalates it on its own; the site’s guide to tracking issues from basic Excel to AI-enabled practice covers the specific gap, which is also where the Global Internal Audit Standards’ Standard 15.2 on monitoring action plans gets hardest to demonstrate.
  • Committee reporting eats real time every quarter. Rebuilding a status deck from several people’s separate files, by hand, every quarter, is one of the most commonly cited time costs in this program’s research into vendor case studies.
  • An examiner or external quality assessor finds fault with the documentation itself. This is the sharpest version of the first sign: Standard 14.6 on engagement documentation does not care that the underlying testing was sound if the file cannot show who did it, who reviewed it, and when.
  • Turnover creates a knowledge cliff. The one auditor who understood the folder structure leaves, and the map leaves with them; a spreadsheet system is only as organized as the last person who imposed discipline on it.
  • The audit universe and plan live in a file only one person edits with confidence. A rolling, risk-based plan needs updating between cycles, not just once a year; the site’s guide to building an audit universe assumes a system that can hold and update that list, which a static file resists by design.
  • Nobody can answer “how many issues are overdue right now” without rebuilding a report by hand. If that number takes more than a few minutes to produce on any given day, the tracking system, not the issue volume, is the actual problem.

None of these eight signs requires all the others to be present before switching makes sense. Two or three, especially the documentation and follow-up signs together, are usually enough on their own once a function is above the one- or two-person band in the table below. The count is a lens for spotting the pattern, not a scorecard to clear before the decision counts.

How big is big enough: a sizing table

Team size alone does not decide this; what the function actually audits does. The table below pairs four size bands with the plan complexity typical at that size, and a recommendation grounded in the signs above rather than in any vendor’s marketing about who its product is for.

Function sizeTypical annual planExcel and SharePoint verdict
1 to 2 auditors4 to 10 engagements a year, mostly operational or compliance-drivenUsually adequate if the function follows the discipline later in this guide; see the guide to setting up a small internal audit function
3 to 5 auditors8 to 18 engagements, with some concurrent fieldworkWorkable, but this is the size where most functions should at least get a price quote, even if they do not buy yet
6 to 15 auditors15 to 40 engagements, several auditors working concurrently, often with some SOX or regulatory scopeUsually already outgrown: concurrent editing and quarterly committee reporting cost the real hours documented in the next section
16 or more auditors40 or more engagements, typically across multiple locations or business unitsA genuine control gap at this scale: no function this size can show a defensible, function-wide audit trail from spreadsheets alone

Headcount is only half of “audit-plan mix.” The other half is what kind of engagements fill the plan. A six-person function running mostly one-off advisory and operational reviews generates fewer repeatable, evidence-heavy engagements than a six-person function running an annual SOX and ITGC cycle across the same locations every year; the second function repeats the same testing, the same evidence types and the same sign-off pattern often enough that a platform’s templates and control library start paying for themselves noticeably sooner. A plan with several parallel, similar engagements — branch audits at a bank, franchise audits at a retailer — behaves the same way: the more the plan repeats a pattern, the earlier software earns its keep at a given headcount.

One variable moves every row earlier: a SOX program or real examiner scrutiny. Even a one- or two-person function running Sarbanes-Oxley testing, or a bank or credit union under active regulatory attention, should treat software as a near-term decision rather than a someday one, regardless of where it sits in the table above; the site’s guide to audit software versus compliance automation and its types of internal audit software guide both cover why SOX-specific and audit-specific tools are not interchangeable, and getting that category choice right matters as much as the size question does.

The real cost of staying: a worked estimate

Put a number next to the signs above with a worked, illustrative example: MidState Beverage, a three-state drinks distributor with a six-person internal audit function — one director and five auditors — that has never used anything but Excel, SharePoint and Teams. MidState is not a real company, and the hours below are a labeled illustration built from the recurring tasks in the signs section above, not a survey finding; every function should replace them with its own numbers rather than treat them as a benchmark.

Recurring taskHow oftenIllustrative hours for MidState
Rebuilding the quarterly committee packet from several people’s separate filesQuarterly16 hours a quarter, 64 a year
Chasing issue and action-plan status by email because nothing ages automaticallyMonthly6 hours a month, 72 a year
Reconciling overlapping workpaper versions before each of about 12 engagements closesPer engagement3 hours an engagement, 36 a year
Rebuilding the audit universe and rolling risk assessment from memory and last year’s fileAnnually40 hours a year
Onboarding one new auditor with no central system to hand themOnce, this year20 hours, one time

That is roughly 232 hours in a typical year across a six-person team — not a catastrophe on its own, closer to six working weeks spread across five or six people, but a coordination tax that grows with headcount and plan complexity rather than staying flat. Converting hours into dollars needs a real, function-specific blended rate rather than a number invented for this guide; the site’s guide to how much an internal audit actually costs has the method for building that rate from your own function’s compensation.

The same math scales in both directions. A one- or two-person function with four engagements a year will not recognize MidState’s numbers; most of the line items above shrink toward zero at that size, which is exactly why the sizing table above puts that band in the “usually adequate” row. A function closer to Lakeshore Bancorp — the $9 billion regional bank with 212 key controls used elsewhere on this site — would see the opposite: a SOX-scale control population multiplies the workpaper-reconciliation and committee-reporting lines well past MidState’s illustrative 232 hours, which is the practical reason the sizing table moves banks and SOX-heavy companies into a near-term decision regardless of headcount.

Hours are also not the only cost, and probably not the largest one. An examiner citation for documentation gaps, a committee report that has to be restated, or a missed follow-up that becomes a repeat finding costs reputation and, in a regulated function, real regulatory attention that no hourly rate captures. Treat the 232-hour estimate above as the conservative half of the real number, not the whole of it.

The cheapest credible entry points if you switch

For a function that reads the hours above and recognizes its own year, the entry price for real audit software is lower than most people assume, though “lower” still means a real budget line. Every figure below is public, sourced and dated in the table; treat it as evidence of what is possible in the market, not a quote for your organization — the site’s internal audit software pricing guide has the fuller set of figures and how to negotiate them.

OptionWhat it isPrice evidenceSource and date
Stay on the spreadsheet stack, plus this site’s free toolsRCM Workbench, sampler, self-assessment tool and myDayLog$0internalauditguide.com
TeamMate+ Audit Essentials, 2 usersThe smallest paid platform tier found in this program’s research; includes TeamMate Analytics and TeamCloud hosting$6,150.88 a year run rate; $15,630 one-time implementation after a $6,000 discount; the quote’s own stated total with training and expert time added is $26,395.88 in year oneCity of Norman, Oklahoma council quote, 28 February 2025
Onspring, low end of its published rangeA no-code, audit-specific platform priced by user, by product or a hybrid, with some tiers offering unlimited employee users$9,972 a year, the low end of a $9,972 to $55,810 rangeVendr marketplace, viewed 26 September 2026
Power BI Pro, one analytics seatNot audit-specific, but a real query and dashboard layer on top of existing Excel and SharePoint data$14 a user a month, $168 a yearMicrosoft’s published pricing
DataSnipper, Start tierAn Excel add-in that links evidence directly to workpaper cells; quote-gatedAbout $175 a seat a month by a third-party estimate (low confidence), implying roughly $10,500 a year at a reported five-seat minimumSacra, viewed 26 September 2026

TeamMate’s Norman number is the cheapest verified full-platform run rate this program found, and the bundled TeamMate Analytics add-in ships well over 150 built-in tests, with current vendor pages showing as many as 180 to 200; but the one-time implementation figure matters as much as the subscription line, and belongs in a year-one budget alongside it, not left out of it. Onspring’s low end sits in a similar place; its by-product pricing path is worth asking about specifically if the function needs many part-time reviewers rather than a small number of named seats. The two analytics options solve a narrower problem than either platform: if the real pain is testing and evidence-linking rather than the whole planning-to-reporting workflow, a $168-a-year Power BI seat or a DataSnipper add-in can close that specific gap without a platform purchase at all.

Contract terms move the effective price more than the sticker figure suggests. Vendr’s community notes on Onspring mention a flat rate available on two-year deals and in-house implementation running $50 to $75 an hour more than using a partner — the kind of detail that changes a shortlist decision more than a few hundred dollars of list price does. LogicGate takes a different approach worth knowing even though its own median contract, at $53,784 a year per Vendr, is not the cheapest option here: its Internal Audit Management app treats Standard and External users as free, so a function that needs to give many part-time auditees or reviewers access without adding named seats can end up paying for a smaller core user count than the headline contract size suggests.

The $0 row is also worth taking seriously on its own terms rather than as a placeholder. The site’s guide to free internal audit software and its build-versus-buy guide to homegrown Power Apps and Airtable setups both cover paths between plain spreadsheets and a paid platform that this guide does not have room to develop fully. Once a number from any of these paths is worth pursuing, the site’s guide to the business case for audit software covers how to get it approved.

None of this is a recommendation to buy any one of these products; it is evidence that the decision is affordable enough to investigate seriously. Once a real number is on the table, the site’s vendor-neutral RFP method, demo script and due diligence guide cover how to turn a shortlist into a defensible decision rather than a sales conversation.

What the adoption data actually says

Two figures describe the same market from different angles, and the gap between them is the real headline. Gartner’s most recent count puts adoption of dedicated audit management software at 84 percent of the 259 audit departments it surveyed, published 16 September 2026. Read alone, that makes staying on spreadsheets sound like the unusual choice. The same press release adds an important qualifier: in Gartner’s words, “the key challenge is ensuring they’re capturing the level of value they expected” from the investment, and departments on the same platform realize very different value depending on whether they standardize methodology and reduce their reliance on spreadsheets and email.

The IIA’s Vision 2035 survey of 6,506 respondents fills in why: only 40 percent say audit management software is implemented at a high level, and roughly one in three report low or no technology implementation at all, license or no license. A separate IIA Pulse survey of 405 practitioners found 41 percent using generative AI in their audit work in 2025, which tracks with a wider pattern in this program’s research: owning a subscription and running a function well from inside it are two different achievements.

SurveyWhat it measuresFigure
Gartner, September 2026, 259 departmentsHas adopted dedicated audit management software at all84 percent
IIA Vision 2035, 6,506 respondentsSoftware implemented at a high level40 percent
IIA Vision 2035, 6,506 respondentsLow or no technology implementationAbout one in three

Analytics adoption specifically lags even further behind: the same IIA 2025 Pulse survey found only 28 percent of functions at a high or advanced level of data analytics maturity, which is the gap the cheap analytics seats in the previous section are aimed at closing without a full platform purchase. A $168-a-year Power BI seat will not close a 28-point maturity gap by itself; it only removes the cost excuse for not starting.

The practical reading is not that adoption is meaningless; it is that the buying decision only pays off if implementation follows it. The site’s 15 mistakes internal audit teams make when buying software and its guide to implementing audit management software and migrating off Excel both cover the gap between signing a contract and closing it; the site’s guide to evaluating AI in audit software is worth reading before that 41 percent figure becomes a reason to buy anything specific.

How to stay on Excel well

For a function below the threshold in the sizing table, or simply not ready yet, the goal is closing the gap between “we use Excel” and “we use Excel in a way that would survive being questioned,” borrowing the discipline a paid platform would otherwise impose. It is also worth remembering that a spreadsheet-based workpaper system is itself an end-user-computing tool, and the site’s guide to auditing end-user computing and spreadsheet risk lists close to the exact controls an examiner would expect the function to apply to its own system, not only the ones it reviews elsewhere.

The disciplined Excel and SharePoint setup

Folder structure. One SharePoint site per audit year, one folder per engagement, named with a fixed pattern such as engagement ID, process name and fiscal year. No personal OneDrive copies of live workpapers, ever.

File naming and version control. One master workbook per workpaper. Turn on SharePoint version history and use it as the audit trail; retire any filename that ends in “v2” or “final,” since the version number belongs to the system, not the filename.

Review and sign-off. A tracked field for reviewer name and date on every workpaper, not a checkmark; this is the single detail Standard 14.6 tests first.

Retention. An explicit retention period, set per the function’s charter and any applicable regulation, applied through a SharePoint retention label rather than left to one person remembering to delete or keep a file.

Issue tracking. One master issue log, not a copy per engagement, with an owner, a due date and a formula that flags anything past due without anyone checking manually.

Access and backup. A defined access list per engagement, reviewed on a set schedule, kept separate from any single person’s personal drive.

None of this costs anything beyond the discipline to enforce it, and it is close to exactly what a quality assurance and improvement program self-assessment will test first; the site’s free self-assessment tool is built around the same kind of checklist.

Questions about switching from Excel

Does the Global Internal Audit Standards require audit management software?

No. The Standards are technology-neutral. What Standard 14.6 requires is defensible engagement documentation, and what Standard 15.2 requires is tracked monitoring of action plans; a disciplined spreadsheet system can satisfy both at a small enough scale. It gets harder to prove, not impossible, as the function and the plan grow, which is the actual argument for switching, not a Standards requirement to do so.

What is the minimum team size where paid software reliably pays for itself?

Based on the sizing table above, three to five auditors is where most functions should at least get a price quote, and six or more is usually where the hours in the cost-of-staying estimate justify the decision on their own, before any feature comparison enters the conversation. A SOX-heavy or bank plan moves that threshold earlier, sometimes into the one- or two-person band, per the sizing table’s own exception above.

Can SharePoint alone replace audit management software?

It replaces the storage, version history and access-control layer reasonably well. It does not natively do audit-specific work such as an aging issue register, a rolling risk-based plan, or a committee-ready scorecard that nobody has to rebuild by hand; Teams and Planner add task tracking on top, but neither is audit-specific workflow either. The Purview governance features covered earlier in this guide close some of the gap, but not the workflow gap itself.

Is a spreadsheet-based workpaper system itself an audit risk?

Yes, in the same sense as any other end-user-computing tool; see the site’s guide to auditing end-user computing. That is not disqualifying, but it means the function should apply its own EUC controls — version control, access restriction, a named owner — to its own tools, not only to the ones it reviews elsewhere.

We are a small SOX-heavy public company. Does the size threshold still apply?

No. This is the one case where size does not decide it on its own; even a one- or two-person SOX function should treat software as a near-term decision, per the exception noted in the sizing table above.

What is the actual first step if we decide to switch?

Not a demo. Write requirements sized to the plan you actually run first, then use them to run a structured comparison; the site’s vendor-neutral RFP method and demo script cover both steps in order.

internalauditguide.com has no commercial relationship with TeamMate, Onspring, LogicGate, Microsoft, DataSnipper or any other vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.

Sources and verification

New guides & tools by email

Useful so far?

There are 400+ more guides where this came from. Get new guides, templates and free audit tools by email when they ship. No schedule, no filler.

Free. One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

New guides & tools by email

Don’t lose this library.

400+ practitioner-written guides and free tools. Hear when new ones land.

One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading