Guide for firmsSoftware migration
Accounting software migration for firms: a five-gate plan from pilot to cutover
Move a small cohort first, reconcile it account by account, prove the originals can still be found, and expand only through agreed decisions.

Short answerHow should an accounting firm migrate its accounting software?
Migrate an accounting firm's software in gates, not in one weekend. Agree what moves and what is archived, map accounts and tax codes, import a small pilot cohort, reconcile it account by account and check that a reviewer can still find the original documents. Then rebuild access, approve cutover with a fallback, and keep old records retrievable for their retention period: ten years for a Malta company's accounting records.
Key takeaways
- Migrate in five gates: scope, mapping, a reconciled pilot, access, then cutover with a fallback.
- Reconcile account by account and test retrieval. Matching totals can hide a lost document.
- Keep old records retrievable for their full period: ten years for a Malta company's accounting records, at least six for VAT records.
- Under ISA 230, closed audit files must not be deleted before their retention period ends, which is ordinarily at least five years from the auditor's report.
- Get client data back from the old supplier in a readable format before you confirm deletion.
01What should an accounting firm move, and what should it archive?
Start with an inventory, not an export. List the client companies in scope, the financial periods and every kind of record the team uses: opening balances, transaction history, sales and purchase documents, bank data, open invoices, fixed asset registers, VAT and payroll records, previous working papers and client due diligence files. For each one, decide whether it moves into the new platform, stays in an archive the team can still search, or both.
A trial balance is not the whole firm. It can be enough to start a client's books on the new platform, but a reviewer answering a question next year may need the invoice behind a posting, the reconciliation that explained a difference or the correspondence that closed a query. Decide where each of those will live before anything is imported.
Then name the source of truth for each period. During testing the old system usually stays the book of record. Agree who may post adjustments, how changes made after the first export are captured, and the date from which the new platform takes over. Without that decision, two systems that each look internally consistent can drift apart because different people kept updating them.
| Record | Usual decision | Why it matters |
|---|---|---|
| Opening balances at the cut-over date | Move | The new books start from them. Reconcile them account by account, not only in total. |
| Open items: unpaid invoices and unreconciled bank lines | Move | The team works on them next week, so the ageing must match the old system. |
| Prior-year transactions | Move or archive, client by client | Useful for comparatives and queries. Decide per client how many years are worth importing. |
| Source documents and attachments | Archive at least; move if the links to postings survive | A posting without its document is hard to review. |
| Closed audit files and working papers | Archive, read-only | They must not be deleted, or changed without a documented reason, before their retention period ends. |
| Client due diligence (KYC) records | Move current clients; archive ended relationships | The firm keeps them for a set period after a relationship ends. |
| Users, roles and client portal access | Rebuild, do not copy | A role in the old system may not mean the same thing in the new one. |
From the old system to the new one in five gates
Each gate has an owner and evidence. A cohort moves on only when its gate has passed, so problems surface on four clients rather than forty.
-
01
Scope
List clients, periods and record types. Decide what moves, what is archived and which system is the book of record.
Read this step: Scope -
02
Map
Map accounts, tax codes, contacts and documents, and start an index of where every record will live.
Read this step: Map -
03
Pilot
Import a small cohort, reconcile it account by account and check that a reviewer can find the originals.
Read this step: Pilot -
04
People
Rebuild roles, rehearse the client workflow and agree the exit terms with the old supplier.
Read this step: People -
05
Cut over
Approve cutover with a named owner and a fallback, then make the old system read-only.
Read this step: Cut over
The gate plan further down turns these steps into criteria you can tick, with an owner for each gate.
02How long must old records stay retrievable after a migration?
The archive is not optional, and the duties behind it belong to different people. Some are your clients' duties, which you help them meet because you keep their books. Others are the firm's own. A migration plan should map each record type to the longest period that applies and keep it retrievable, in a form someone can open and read, until that period ends.
For a company in Malta, the Companies Act requires accounting records to be kept for ten years; where they are kept in a bound or unified form, the ten years run from the last entry (Cap. 386, article 163(5)). The same article requires the records to be open to inspection by the company's officers at all times. VAT records must be kept for at least six years from the end of the year they relate to; where a return is filed late or corrected, the six years run from the late filing or the correction request (Cap. 406, article 48(4)). The VAT Act also requires invoices to be stored in the original form in which they were sent or made available, paper or electronic (Eleventh Schedule, paragraph 1(2)). A converted copy is not the original.
The firm's own records have their own rules. Malta's anti-money laundering regulations cover auditors, external accountants and tax advisers. They require customer due diligence records, and the supporting records needed to reconstruct transactions, to be kept for five years from the end of the business relationship. The period can be extended, up to a maximum of ten years, only where a thorough assessment of necessity and proportionality concludes that the extension is necessary for the Financial Intelligence Analysis Unit, supervisory authorities or law enforcement to prevent, detect, analyse or investigate money laundering or terrorist financing (S.L. 373.01, regulation 13(2)). From 10 July 2027, the EU Anti-Money Laundering Regulation (EU) 2024/1624 applies directly to auditors, external accountants and tax advisers, and its Article 77 then governs how long these records are kept (Articles 3, 77 and 90).
Audit firms carry one more duty. ISQM 1, the IAASB's quality management standard, says the retention period for engagements under the ISAs is ordinarily no shorter than five years from the date of the engagement report (paragraph A85); ISA 230 says the same of the auditor's report (paragraph A23). ISA 230 forbids deleting or discarding audit documentation of any nature after the final file is assembled and before its retention period ends (paragraph 15). ISQM 1 adds that keeping documentation can mean managing the custody, integrity, accessibility or retrievability of the data and the related technology (paragraph A84). That is the migration risk in one sentence: a closed audit file that only opens in software you no longer licence is not retrievable. In Malta, compliance with generally accepted auditing standards means adherence to the IAASB's International Standards on Auditing, its quality control standards and other related standards, as issued from time to time and as far as they are relevant to the statutory audit (S.L. 281.02, regulations 2 and 4). Check whether a longer retention period applies to your firm.
| Records | Whose duty | Retention rule | Source |
|---|---|---|---|
| A company's accounting records | The company; its accountant helps it comply | Ten years; for records in bound or unified form, from the last entry | Companies Act (Cap. 386), art. 163(5) |
| VAT records, documents and accounts | The taxable person | At least six years from the end of the year they relate to, or from a late return or correction request | VAT Act (Cap. 406), art. 48(4) |
| Invoices | The taxable person | Stored in the original form, paper or electronic, for the VAT period above | VAT Act (Cap. 406), Eleventh Schedule, para. 1(2) |
| Wage sheets and records of tax deducted at source | The employer or other payer who deducts the tax | At least nine years after the transactions are completed | Income Tax Management Act (Cap. 372), art. 23(12) |
| Customer due diligence and supporting transaction records | The firm, as a subject person | Five years from the end of the relationship; up to ten only where a thorough assessment finds it necessary for the authorities to prevent, detect, analyse or investigate money laundering or terrorist financing | S.L. 373.01, regulation 13(1) and (2) |
| Audit engagement files | The audit firm | Ordinarily no shorter than five years from the date of the auditor's report; no deletion before the period ends | ISQM 1, para. A85; ISA 230, para. 15 |
| Client personal data held by the old supplier | The supplier, as your processor | Deleted or returned, at your choice, when the service ends; copies kept only where the law requires | GDPR, Article 28(3)(g) |
03How do you map accounts, tax codes and documents before importing?
Map before you import. Write down how each source item lands in the new platform: the chart of accounts, VAT and other tax codes, customer and supplier records, dimensions such as departments or projects, currencies and fixed asset categories. Ask the supplier which fields import directly, which need configuration and which need manual work. Test unusual and inactive codes as well as the common ones.
Decide how you will handle duplicates, unsupported fields and missing documents, and record each decision. Keep the mapping in a form a preparer and a reviewer can both read, with an owner and a date. If you serve clients under different reporting frameworks or tax rules, validate each group's workflow rather than assuming one clean import covers everyone.
Build a retained-record index alongside the mapping. For each client and period, list what moved, what was archived, where it now sits and in what format. At the end of the pilot you reconcile this index as well as the balances. A document that was meant to move but did not is a migration error, even when every total agrees.
- Source code or field, target code or field, and the rule that links them.
- Tax codes checked against the rates and treatments each client actually uses.
- How inactive accounts, duplicates and unsupported fields are treated.
- Which attachments move, and whether their links to postings survive.
- Who prepared the mapping, who approved it and when.
04How do you test and reconcile a pilot cohort?
Choose a small cohort that contains the record types you actually handle. A simple trading company is a sensible first case. Add a client with several bank accounts, foreign currency, payroll or a more complex ledger when those features matter to your practice. Keep the pilot small enough that one named person can own every exception.
Reconcile at more than one level. Agree the imported trial balance to the source account by account at the cut-over date. Then check the balances behind it: bank, aged receivables, aged payables, the VAT control account and any other control accounts in scope. Log every difference with its cause, the correction and who approved it. Matching headline totals can hide a supplier posted to the wrong account or a tax code mapped to the wrong rate.
Then test retrieval, because that is where migrations fail quietly. ICAEW's audit monitoring insights, published on 29 June 2026, report that some of the smallest audit firms failed to manage the move from paper audit files to new audit software, and original documentation was lost or missing. That is UK monitoring by ICAEW's Quality Assurance Department, not a Malta finding, but the risk it describes comes with any software change. Its head of audit put it plainly: 'Disciplined change management is critical'. In your pilot, ask a reviewer who did not run the import to start from a balance in the new platform and find the original document, its version and the explanation that went with it. Matching totals is not the same as matching records. A migration is finished when a reviewer can find the original.
| Check | Compare | Passes when |
|---|---|---|
| Trial balance | Imported balances with the source at the cut-over date, account by account | Every account agrees, or each difference is explained and approved |
| Bank | Imported balance and open items with the bank statement | The balance agrees and every open item has carried over |
| Receivables and payables | Aged lists by customer and supplier with the source ageing | Individual balances and ageing bands agree |
| VAT and other control accounts | Control balances with the source and the last return; sample postings with the tax code mapping | Balances agree and sample postings land on the right code |
| Documents | The retained-record index with what is actually in the new platform or the archive | Every listed document is where the index says it is |
| Retrieval | A reviewer starts from a balance and looks for the original, its version and the explanation | Found without help from the person who ran the import |
Matching totals is not the same as matching records. A migration is finished when a reviewer can find the original.
05How do you move staff, clients and permissions?
Rebuild access rather than copying it. Set up sample roles and confirm that each person sees the right companies and can do only their own steps: preparers prepare, reviewers review, partners sign. Check who can export data, who can delete it and who can reopen a closed period. Then run an ordinary request, upload, preparation, review and correction from start to finish on a pilot client.
Tell clients what changes, when, and what stays the same. A short message should say where to upload records from which date, what happens to anything sent the old way, and whom to contact. Tell staff which work continues in the old system, which moves, and the date old access becomes read-only. Train on the team's real workflow rather than a tour of menus.
Settle the exit from the old supplier at the same time. Where it processes client personal data for you, the GDPR requires a contract or other binding legal act, and it must let you choose whether the supplier deletes or returns the data when the service ends (Article 28(3)(g)). Ask for the return first, in formats you can open without its software, check it against your record index and only then confirm deletion.
06When is a firm ready to cut over, and what is the fallback?
Approve cutover when the pilot's exceptions are resolved to the responsible person's satisfaction, not because a licence renewal is due. Agree the final export, any remaining import and the final reconciliation. Record who approved cutover and who may pause the rollout if a material issue appears.
Pick a cut-over point that keeps periods clean. A month end, quarter end or VAT period end avoids splitting a period across two systems. Busy filing weeks are a poor time to switch, because the people who must review the exceptions have the least time.
Define the fallback before you need it: which records are preserved, which system would resume posting and how changes made in between would be reconciled. Then give the old system's editable life an end date. Two editable ledgers kept open indefinitely create a reconciliation problem of their own. After that date, keep the old data read-only and retrievable for its retention period, or exported to formats you can open without the old software.
| Approach | How it works | Suits | Watch out for |
|---|---|---|---|
| All at once | Every client moves on one date | Small firms with few, similar clients and simple ledgers | Every mapping error surfaces at the same time, often in a busy week |
| Cohort by cohort | A pilot group moves first; the rest follow in planned waves | Firms with mixed clients, payroll, foreign currency or audit work | Two systems run side by side for a while, so record which client is where |
| Parallel run | Both systems are updated for a period and compared | Firms that need evidence before trusting the new figures | Double keying, and drift if the comparison is not done promptly |
07What should you ask Vacei, or any supplier, about migration?
Vacei's published pages say that ledgers are migrated from a firm's current software or Excel, prior year included, that its team helps set up the firm and train its people, and that the firm's data stays exportable in full, at any time, in open formats. Its pricing page lists onboarding and training for the firm's team, with firm pricing on request.
Turn those statements into questions for your proposal. Which source systems and file formats are covered? Does 'prior year' mean balances, transactions or documents as well? Are attachments, working papers and client due diligence files included, or only ledgers? Who reconciles the import: your team, the supplier or both? Which open formats does the export use, and does it include documents? Ask for the answers in writing, with scope, responsibilities, timing and fees agreed for your practice.
Prepare your record inventory before you talk to any supplier; the gate plan below gives you the list. It records which decisions are ready; it does not set a migration deadline or promise that every record can move automatically. Vacei's firm demo is a 30-minute walkthrough: you tell Vacei what you plan to move, and the demo uses sample data to show the relevant workflow.
Plan your migration in five gates
Tick each criterion you can evidence today and name an owner for each gate. A gate passes only when every criterion in it is ticked. The result shows your current gate and what is still missing.
How the result is worked out
A gate passes only when every one of its criteria is ticked; there is no partial pass. The current gate is the first gate, in the order listed, that has not passed.
Ticks are your own record of where things stand. Nothing is checked, verified or approved by this page.
Common questions
How long does an accounting software migration take for a firm?
It depends on the number of clients, how much history you move, how clean the source data is and how many exceptions the pilot finds. Published guides quote anything from a few days to several months. Plan by gates instead: a cohort moves when its gate criteria are met, not on a date fixed in advance.
Can a trial balance be enough for a migration?
For a narrow scope, such as starting a client's books on the new platform from a clean cut-over date, it can be. It does not carry transaction history, documents or the explanations behind balances. If you do not move those, keep them retrievable in an archive for their retention period.
Do we need to move every historical transaction?
Move what the team needs for current work and queries, and archive the rest in a form you can search and open without the old software. Check any storage conditions attached to a record type: in Malta, for example, invoices must be kept in the original form in which they were sent or made available.
Do we need to keep the old software licence after migrating?
Only if it is the only way to open records you must keep. Export closed files and archives to formats you can read without it, check the export against your record index and keep it for the retention period. For audit files, ISQM 1 notes that retention can involve the related technology as well as the data.
Should the whole firm switch at once?
Small firms with a few similar clients sometimes do. Most firms learn more from a pilot cohort first, because it shows mapping, access and review problems before they affect every client. The table in section 06 compares the three approaches.
What happens to client data left with the old supplier?
Where the supplier processes personal data for you, the GDPR requires its contract to let you choose deletion or return when the service ends, with copies kept only where the law requires. Ask for the return first, check it against your record index, then confirm deletion in writing.
Who should sign off the migration?
Name one owner for each gate, plus one person who approves cutover and can pause it. In an audit firm, involve whoever is responsible for quality management in how closed engagement files are preserved, because ISQM 1 treats keeping that documentation as part of the firm's system.
Does a completed gate plan mean the migration worked?
It means the criteria you set were ticked. The evidence behind each tick, such as the reconciliations, the record index and the retrieval tests, is what shows the migration worked. Keep that evidence with the migration record.
How this guide was prepared
Method and limits
This guide sets out a gated plan for moving an accounting or audit firm's client work to new software. Each legal or standards statement names the provision, and the sources list links to the official text with the date we checked it. The ISA 230 link is the IAASB handbook page, which asks for a login before download. Malta law is cited as consolidated on legislation.mt on 6 October 2026, and EU law as in force on that date. ICAEW's findings are UK monitoring observations, used as context.
The retention table is a planning aid, not legal advice. It shows the retention rule for common record types. Other rules can apply to particular records or clients, and some duties belong to your clients rather than to the firm.
The gates tool records what you say you can evidence. It does not inspect data, test an import or decide whether you comply with any law or standard. Statements about Vacei describe its published pages; they are not test results.
Related Vacei pages: How firms move onto Vacei · What firms get, including migration · About Vacei · Pricing for firms.
Who prepared it
- Author
- A4 Team
- Published
- 6 October 2026
- Last substantive update
- 6 October 2026
- Sources checked
- 6 October 2026
Sources
- Malta Companies Act (Cap. 386), article 163 (consolidated to Act I of 2026)legislation.mt · checked 6 October 2026
- Malta VAT Act (Cap. 406), article 48 and Eleventh Schedulelegislation.mt · checked 6 October 2026
- Malta Income Tax Management Act (Cap. 372), article 23(12)legislation.mt · checked 6 October 2026
- Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01), regulations 2 and 13legislation.mt · checked 6 October 2026
- Accountancy Profession (Accounting and Auditing Standards) Regulations (S.L. 281.02), regulations 2 and 4legislation.mt · checked 6 October 2026
- IAASB: ISQM 1, Quality Management for Firms (final pronouncement, December 2020), paragraphs 13, 31(f) and A83 to A85iaasb.org · checked 6 October 2026
- IAASB: 2025 Handbook, Volume 1, ISA 230 Audit Documentation, paragraphs 14 to 16 and A23iaasb.org · published 17 September 2025 · checked 6 October 2026
- EUR-Lex: Regulation (EU) 2016/679 (GDPR), Article 28eur-lex.europa.eu · published 4 May 2016 · checked 6 October 2026
- EUR-Lex: Regulation (EU) 2024/1624 (EU Anti-Money Laundering Regulation), Articles 3, 77 and 90eur-lex.europa.eu · published 19 June 2024 · checked 6 October 2026
- ICAEW: Audit monitoring insights 2026: themes, risks and what good looks likeicaew.com · published 29 June 2026 · checked 6 October 2026
- Vacei: about, migration and exportvacei.com · checked 6 October 2026
- Vacei: how firms move onto Vaceivacei.com · checked 6 October 2026
- Vacei: pricing for firmsvacei.com · checked 6 October 2026
- Vacei: book a firm demovacei.com · checked 6 October 2026
Talk through your migration in a Vacei firm demo
Start with a 30-minute walkthrough. Tell Vacei what you plan to move, such as how many clients, which periods and which record types; the demo uses sample data to show the relevant workflow. Ask which formats, periods and documents the migration covers.