Release 22 (September 2026) is the largest change to AuditTrove since it opened. Every item below has its own steps in this edition; the chapter is given in brackets.
| What changed | What it means for you | Chapter |
|---|---|---|
| External confirmations sent from AuditTrove (ISA 505) | Bank, customer, supplier and legal confirmation letters are emailed to the other party from AuditTrove, never through the client. Addresses the client supplied or on a free-mail domain are flagged. The other party replies on a secure public reply page, with the signed letter attached where needed. A second request goes out automatically after 10 days, then a non-response prompt for alternative procedures. A difference can be recorded as a misstatement in one step. | 9 |
| Client authorisation by e-signature | The client's authorisation for the confirmations is signed in the client portal or recorded as given offline. | 9 |
| Excel uploads | The trial balance and analytics populations can be uploaded from .xlsx files, choosing the sheet and the header row. Old .xls files must be saved as .xlsx or CSV first. | 8, 10 |
| Data analytics beyond 250,000 rows | Populations of up to 5 million rows (a whole general ledger) are stored in segments; tests run as background jobs with the same results as before. | 10 |
| Accounting-system connectors | Xero, QuickBooks Online, Sage Business Cloud Accounting and Zoho Books: the client (from the portal) or the engagement partner connects the client's books to the engagement; the trial balance and journal lines are pulled directly. | 4 |
| A fuller BookTrove link | Besides pulling the trial balance and journals, the team can propose adjustments to the client's BookTrove and read the client's decisions back, and send client requests to BookTrove and pull the answers and files. | 15 |
| The ISA for LCE | An audit can follow the International Standard on Auditing for Less Complex Entities: AC-4L applicability paper, a streamlined programme, the ISA for LCE report and letters, and a switch to the ISAs when the entity turns out to be more complex. | 15 |
| Partner review monitoring (ISA 220 (Revised)) | AuditTrove records when the engagement partner reviews each paper and shows coverage of significant risks, significant judgements and key stages, with a flag for a report dated before the partner's review. A firm-wide view feeds quality monitoring. The firm chooses whether gaps warn or block the report. | 13, 19 |
| Engagement quality review read from SQMTrove | When the SQMTrove link is on and an engagement needs an EQR, the report cannot be dated or signed until SQMTrove shows the quality review as completed (ISQM 2.24(b), ISA 220.36). | 4, 13 |
| Malware checks and quarantine | Every upload is checked. Programs and scripts are refused; files with macros, embedded objects or PDF actions are held in quarantine until the firm administrator releases them. Settings → File scanning shows the log. An outside scanner (Cloudmersive) can be added. | 3, 11 |
| Sign in with Microsoft or Google | A firm can let its people sign in with their Microsoft 365 or Google Workspace account, for the firm's own email domains only. Nobody is created this way: the person must already have a login. | 3 |
| SOC 2 and ISO 27001 readiness | Settings → Security & compliance: the audit trail exported with a fingerprint after the seal chain is checked; the quarterly access review of every login; the public trust page with the controls and sub-processors. | 3 |
| Sessions stored as fingerprints | Sign-in sessions are now stored only as fingerprints, so a copy of the database cannot be used to take over a session. When the release was installed everyone was signed out once and signed in again. There is no screen for this change. | 1 |
What the owner sets up. Some features need keys that only TroveUniverse (for sign-in with Microsoft or Google and the platform scanner) or the firm (for the accounting systems) can register. Until they are set, the Settings page shows the feature as not configured and the rest of AuditTrove works as before. The screenshots in this guide show those pages as a firm sees them before the keys are entered.
- Sign in with Microsoft or Google — registered once for the whole service by TroveUniverse (an app in Microsoft Entra ID and an OAuth client in Google Cloud). Each firm then switches the provider on for its own email domains in Settings → Sign-in providers (step 3.1).
- Accounting systems — each firm registers its own app with Xero, Intuit (QuickBooks), Sage or Zoho, using the redirect address and permissions shown in Settings → Accounting systems, and enters the client ID and secret there (step 4.1). QuickBooks production keys need Intuit's app assessment first.
- Outside malware scanner — optional. A firm can enter its own Cloudmersive key in Settings → File scanning; without it AuditTrove's own checks still run (step 3.3).
- Confirmation emails — need email sending to be set up on the service (it is on troveuniverse.com). Without it AuditTrove says "email not configured".
- BookTrove — the client creates an auditor access token in BookTrove with the read, adjust and pbc permissions and gives it to the engagement team (step 15.6).