Skip to main content

T Roos | Dynamic Tax and Accounting Firm

IRBA’s Auditor Skill Set Just Got a 2026 Update: Here’s What Changed

Thirteen years is a long time in most professions. In auditing, it’s the gap between the Independent Regulatory Board for Auditors’ (IRBA’s) last competency framework and the current proposed revision — and a lot has happened in that gap. Cloud accounting became normal. ESG and sustainability reporting went from niche to expected. Cybersecurity went from an IT department’s problem to a board-level risk. And South Africa watched several high-profile corporate collapses raise uncomfortable questions about what auditors were actually catching.

IRBA’s answer is a redesigned competency framework — the document that quietly shapes what every registered auditor in the country is trained to know, from university through to practical experience. It’s not light reading, but the direction it signals is worth understanding, whether you’re a client relying on an audit opinion or a firm thinking about where to invest in training.

What a Competency Framework Actually Does

IRBA’s competency framework sets out the core technical knowledge, professional skills, and ethical values required to qualify and practise as a registered auditor in South Africa. It guides everything from university curricula to professional training programmes to what counts as valid practical experience on the road to registration. Change the framework, and eventually you change what every new auditor coming through the pipeline actually knows how to do.

What’s Being Added

The IRBA describes the proposed framework as “future-oriented,” and the expansion is genuinely significant. While the full detail sits in the consultation document, the public materials make clear that the revision is designed to reflect:

  • Sustainability and related reporting developments — as climate-related and broader sustainability disclosures become a standard part of what companies report on, alongside the IRBA’s adoption of international sustainability assurance standards.
  • Technology, data and digital systems — recognising that modern audits increasingly run through digital systems, and that the risks sitting inside those systems are now squarely part of an auditor’s risk landscape.
  • Business, economic and regulatory analysis — a broader commercial and regulatory lens, not just technical accounting knowledge, in an environment the IRBA itself describes as more complex and risk-laden.

The IRBA’s own explanation is blunt about why: the audit environment has become more complex, and auditors are now expected to engage with a far wider range of information, systems, and reporting frameworks than the 2013 framework anticipated

Why Now

It’s hard to separate this update from the year IRBA has had. In 2026, the regulator imposed a lifetime ban and substantial penalties on Sipho Malaba, the lead auditor on the collapsed VBS Mutual Bank, after finding him guilty on multiple charges of improper conduct. Corporate failures like VBS put uncomfortable pressure on the question of what auditors are actually equipped to catch, and a competency framework that hasn’t moved since 2013 is an easy target when that question comes up.

Whether or not this specific framework update is a direct response to any one case, the timing lines up with a broader push to close the gap between what auditors are trained to look for and what’s actually putting South African companies and institutions at risk.

Practical Implications for Firms and Clients

  • This is a pipeline change, not an overnight one. The proposed effective date is 1 April 2027, and the framework mainly shapes training, academic programmes, and how new auditors qualify — not an instant retraining mandate for every registered auditor tomorrow.
  • Firms that invest early have a genuine positioning advantage. A firm already building ESG reporting capability, data analytics skills, and cybersecurity awareness into its practice isn’t starting from scratch when the framework formally lands.
  • Clients should expect audit conversations to widen. Over the next few years, don’t be surprised if your auditor starts asking more pointed questions about your data systems, cyber controls, and sustainability disclosures — not because the audit scope has technically changed overnight, but because the people conducting it are being trained to look at more of it.
  • Training providers and universities have work to do. Because the framework feeds directly into academic and professional training content, expect curriculum updates from accounting bodies and universities well ahead of the 2027 implementation date.

Conclusion

IRBA’s first competency overhaul in over a decade is a signal, not just a document — audit isn’t just about the numbers anymore, and the profession’s own training standards are catching up to that reality. For firms, getting ahead of the sustainability, technology, and data, and broader business and regulatory competencies now is a genuine way to stand out before the April 2027 deadline makes it the baseline everyone else has to meet too.

 

While every reasonable effort is taken to ensure the accuracy and soundness of the contents of this publication, neither the writers of articles nor the publisher will bear any responsibility for the consequences of any actions based on information or recommendations contained herein. Our material is for informational purposes.

We use cookies to improve your experience on our website. By continuing to browse, you agree to our use of cookies
X