Skip to Content

Building an Audit Evidence Pack From Odoo

Learn how to organise Odoo access reports, approvals, reconciliations, supporting documents, change records and period-close evidence for audit.
11 min read
October 1, 2026
Odoo Audit & Certification ERP

Overview

An audit request becomes difficult when evidence is scattered across Odoo records, emails, shared folders and individual memories. Finance then spends days locating files, confirming which version was approved and explaining why a record changed. The pressure grows near month-end or year-end when the same people must also close the books.

A well-designed Odoo audit evidence pack changes that experience. It organises evidence around the business event, the control and the reporting period. Instead of sending a large export and hoping it answers the question, the business can provide a controlled set of reports, records and supporting documents that shows what happened, who approved it and how it was reconciled.

This guide explains how finance leaders can build that pack from Odoo. It covers access reports, approvals, reconciliations, change records, attachments and period-close evidence. It does not replace statutory requirements or professional audit advice. Local laws, accounting standards and the auditor’s request determine what evidence is sufficient. The goal is to make routine evidence available, traceable and easier to review.

Current Process

In a weak process, audit preparation starts after the request arrives. Finance exports transactions, asks managers to find approval emails and searches drives for invoices or contracts. IT provides a current user list while operations may provide a spreadsheet that differs from the Odoo posting.

Evidence can then be incomplete, duplicated or taken from the wrong date. A report can show today’s permissions rather than the permissions in place during the period. A supplier bill can lack its purchase order, receipt or approval context.

The issue is not that Odoo lacks records. It is that the evidence has not been designed as a connected story. A finance control is usually supported by several record types. For example, a vendor-payment control may require the supplier bill, approval record, payment details, bank reconciliation result, user access evidence and the supporting document. Each item alone is incomplete.

Start With The Audit Question

Every evidence request has a question behind it: whether only authorised users approved payments, revenue belongs in the correct period or master-data changes were controlled. Define the question before choosing a report.

For each material process, document the trigger, expected control, evidence source, owner, retention location and review frequency. The pack should show what occurred, which rule applied, who performed or approved it and what review confirmed the result.

Common Evidence Gaps

The most common gap is a completed transaction without supporting context. A bill may be posted but its supplier document is missing. A payment may be recorded but the approver’s authority is unclear. A journal entry may be valid but lack a clear explanation for an unusual adjustment.

Another gap is evidence without a defined owner. If a report is generated only when an auditor asks for it, no one confirms that its scope is correct during the year. The same applies to user access. A current list is useful but it does not by itself prove regular review, timely removal of leavers or appropriate segregation of duties.

Finally, teams often save too much without an index. Hundreds of attachments are not an evidence pack. Auditors still need to know which records support the requested sample, how the records relate and whether the file is final. A short index with stable record references is more valuable than an uncontrolled archive.

Target Odoo Workflow

The target workflow makes evidence a normal output of controlled work. It begins when a transaction is created and ends when the period is closed and the relevant reports are retained. The business should avoid a separate shadow process where staff download and rename documents only for audit purposes.

For a supplier invoice, the flow may begin with a purchase order or an approved exception. The supplier bill is entered with the source document attached. The responsible user validates the bill according to the defined approval route. Payment follows the approved process, then the bank activity is reconciled. At close, finance reviews outstanding items, unusual journals and approval exceptions. The evidence pack links each stage through the Odoo document trail and a controlled period folder or repository.

Build A Period Evidence Index

Create one evidence index for each month, quarter or year-end period depending on the review cycle. The index should be concise. It should identify the control, population or report, period, owner, reviewer, storage location, date prepared and status. It can sit in a controlled repository or an Odoo document structure if that suits the organisation’s design.

Do not copy every transaction into the index. Link the report or population that supports the control, then record the sample or exception references when needed. Stable Odoo record identifiers, report dates and attachment links make retrieval faster. If data is exported, retain the query logic, filter choices and generation date so a reviewer can understand the population.

Evidence AreaOdoo Evidence To OrganiseControl QuestionPeriod Owner
User AccessUser list, roles, access review and approved changesDid only appropriate users have access?System owner
Procure To PayPurchase order, bill, approval, payment and attachment trailWas expenditure authorised and supported?Accounts payable owner
Record To ReportJournal-entry support, reconciliation reports and review evidenceAre balances complete, accurate and reviewed?Financial controller
Order To CashSales document, delivery, invoice, credit note and collection statusWas revenue recorded in the right period?Revenue owner
Change ControlConfiguration request, test evidence, approval and release recordWere material changes authorised and tested?Change owner

Assemble The Pack In A Logical Order

Structure the pack in the order that an auditor tests a process: process narrative, stated control, population report, selected transaction evidence, exception analysis and management review. Use names that include the period, process, report and preparation date. If a report is regenerated, retain the reason and point the index to the approved version.

Attachments should remain connected to the Odoo record where practical. Where external documents are required, use a controlled link and record which business document it supports. Do not rely on a personal drive or inbox as the only evidence location.

Connect Approvals To Authority

An approval is only useful evidence if the business can show what was approved and why the approver was authorised. Configure approval rules and user responsibilities to match the approved policy. For material approvals, retain the document state, approver, date, amount, company and any requested exception.

Review delegated authority separately. A temporary delegate, emergency override or unusual price or credit approval may be legitimate. It should have a defined reason, expiry or follow-up review. Without that context, a valid exception can appear to be an uncontrolled bypass.

For high-risk processes, finance should periodically test a sample of approvals from Odoo against the authority matrix. The purpose is not to repeat every approval. It is to confirm that configuration, user access and operational practice still agree. Record the result and corrective action in the period evidence index.

Roles And Controls

An audit-ready pack requires clear ownership. Finance owns financial reporting evidence, the Odoo administrator owns access and release evidence and process owners confirm operational completeness. Internal audit or compliance may independently review selected controls.

The preparer should not be the only approver. An accounts payable analyst can prepare a reconciliation while a controller reviews material unreconciled balances. A system administrator can produce a user-access report while a business owner confirms appropriate access.

RoleCore ResponsibilityEvidence Of Control
Process OwnerDefines the process, exceptions and expected outcomesApproved process narrative and periodic exception review
Evidence PreparerProduces reports, indexes evidence and resolves gapsDated pack with report parameters and record references
Control ReviewerChecks completeness, anomalies and follow-up actionsReview sign-off, comments and tracked actions
Odoo AdministratorMaintains access and controlled technical changesAccess-change record, release evidence and review report
Finance LeaderAccepts period-close evidence and unresolved riskClose checklist, material-issue decision and escalation record

Design Reports For Review Rather Than Volume

Reports should answer a control question. An unfiltered general ledger export may be necessary for a population but it rarely proves that unusual journals were reviewed. Add a focused report or documented review criteria for manual journals, aged unreconciled items, credit notes, write-offs, approvals outside threshold or master-data changes.

Keep the report logic consistent. Record the legal entity, date range, status filters, currency treatment and exclusions. If a reviewer makes a manual adjustment to the population, explain it. A reproducible report is more credible than a spreadsheet that has been rearranged without a record of how it was produced.

Retain Supporting Documents Responsibly

Supporting documents may contain personal data, commercial terms or bank information. Limit access to people who need it, follow the retention schedule and do not keep sensitive documents indefinitely. Identify which documents remain attached to the Odoo record, which sit in a controlled repository and who approves deletion when the retention period ends.

Exceptions

An audit pack should make exceptions visible rather than attempt to hide them. An exception may be a late approval, unmatched bank item, manual journal, missing attachment, emergency access request or failed interface. The important control is that it is identified, owned, investigated and resolved or formally accepted.

Maintain an exception log connected to the period evidence index. Record the exception type, record reference, discovery date, business impact, assigned owner, expected resolution date, current status and final outcome. For material matters, include management’s decision and evidence of follow-up. This gives auditors a clear view of how the business handles issues.

Do not force every exception to close before reporting. Some reconciling items are legitimate and may remain open at period-end. The pack should explain why the item remains open, what evidence supports the balance and when it will be reviewed next. An honest documented exception is stronger than a rushed correction that introduces another error.

Change Records Need Business Context

Odoo configuration, customisation, integration and reporting changes can affect financial controls. A technical ticket by itself may not explain the business impact. Each material change should show the request, reason, affected process, approval, testing, deployment date, rollback plan where appropriate and post-release review.

This matters especially when a change occurs near close. A new approval threshold, altered tax mapping or updated integration can change transaction behaviour. Include the related release evidence in the period pack and assess whether extra reconciliation or sampling is required. The business owner should confirm that the change delivered the intended outcome without weakening the control.

KPIs And Next Steps

Track required close evidence completed by the agreed date, missing-document exceptions, ageing unreconciled items, approval exceptions, access-review completion and audit-request response time. These measures show where the process is becoming fragile. Every adverse trend should lead to a named corrective action.

Before the next audit cycle, run a small evidence rehearsal. Select one process such as procure to pay and ask an independent reviewer to trace a sample from population report to document, approval, payment and reconciliation. Record missing links and fix the process while there is time. This is far more effective than discovering gaps during a formal audit request.

For a finance-control design that connects operating workflows with evidence, Odoo accounting services and the Odoo accounting module can be aligned with Odoo implementation services, Odoo integration services, Odoo migration services, Odoo reporting services and Odoo support services. The practical aim is a control environment where reports, approvals and supporting documents can be retrieved without disrupting the period close.

Frequently Asked Questions

1. What Is An Odoo Audit Evidence Pack?

An Odoo audit evidence pack is an organised set of reports, record references, approvals, reconciliations, supporting documents and review evidence for a defined period. It helps the business answer audit requests efficiently and show how a control operated.

2. Which Odoo Records Should Be Included In Audit Evidence?

Include the records that support the control being tested. These can include user-access reviews, purchase orders, bills, invoices, payments, journal-entry support, reconciliation reports, approval history, attachments and material change records.

3. How Does Odoo Support Approval Evidence?

Odoo records can show the document state, responsible users, dates and related business records. The business should also maintain an authority policy and review unusual approvals or overrides so the approval trail has clear context.

4. How Should Finance Organise Period-Close Evidence In Odoo?

Create a period evidence index with each control, report, owner, reviewer, storage location and status. Link the required Odoo records and retain report filters or generation details. Review the index as part of the close process.

5. What Should Be Done With Missing Documents Or Unreconciled Items?

Record them as exceptions with an owner, impact assessment, target resolution date and current status. A valid item can remain open at period-end when its reason and follow-up are documented. Do not hide or rush the item to closure.

6. Why Are Change Records Important For Odoo Audit Evidence?

Configuration, integration or customisation changes can alter a financial workflow or control. Change evidence should explain the business reason, approval, testing, deployment and any extra review needed after release.

7. How Can A Business Test Its Audit Evidence Pack Before An Audit?

Run an evidence rehearsal. Choose one process and trace a small sample from the population report through the transaction, approval, payment or delivery evidence and reconciliation. Log missing links and improve the workflow before the formal audit begins.

Conclusion

Building an audit evidence pack from Odoo is not a once-a-year file-collection exercise. It is a repeatable control process that links transactions, approvals, reconciliations, changes and supporting documents to the relevant reporting period. When each item has an owner, an index and a review point, audit requests become easier to answer and finance gains stronger visibility before the auditor arrives.

Start with the business questions that matter most. Map the evidence for each critical control, preserve the document trail with the Odoo record, record exceptions honestly and retain proof of review. Then test the pack through a small rehearsal. This approach reduces late searching and helps the organisation demonstrate that its financial controls operate as intended.

Building an Audit Evidence Pack From Odoo
Vishesh Joshi Business Systems Strategist

About the Author

Helps organizations scale operations, improve visibility, and drive growth through process transformation, ERP strategy, and digital execution. Writes about business systems, operational excellence, and technology-led growth.
Book a Consultation

Share this post