Audit

Accounting Software Audit Trail Under Companies Act: Practical Compliance Checklist

A practical guide for Indian companies and finance teams on accounting software audit trails, system mapping, edit-log controls, common mistakes and auditor reporting under Rule 11(g).

Accounting Software Audit Trail Under Companies Act: Practical Compliance Checklist

Companies that maintain their books of account electronically need to treat the accounting software audit trail as a compliance feature, not merely an IT setting. Section 128 of the Companies Act, 2013 permits books and relevant papers to be kept in electronic mode in the prescribed manner. The Companies (Accounts) Rules, 2014 add a specific requirement for accounting software used to maintain books of account: it must have a feature that records an audit trail of each transaction, creates an edit log of every change made in the books, records when the change was made, and does not allow the audit trail to be disabled.

This is a durable systems-and-controls requirement. Readers can verify the statutory foundation in Section 128 on India Code and consult ICAI's Implementation Guides page.

What does an accounting software audit trail mean?

An audit trail is a chronological record that helps reconstruct what happened to accounting data. In practical terms, when a user creates or changes a transaction, the system should preserve enough information to identify the change rather than simply overwriting the earlier value without trace.

This is different from a normal activity log that only records logins or system events. The compliance focus is on changes to transactions recorded in the books of account. A company should therefore determine which applications actually form part of its books-of-account environment instead of assuming that one log in the main ERP automatically covers every relevant system.

What should the company test?

A useful compliance review begins with the accounting-system landscape. Identify the general ledger and every application or interface that creates, modifies or feeds accounting entries. This can include billing, payroll, inventory, fixed-asset, expense, revenue or other sub-ledgers where they form part of the accounting process.

  • Audit trail is enabled: confirm the relevant feature is active in each applicable accounting application.
  • Changes are captured: test whether edits to transactions leave a trace showing the change and its timing.
  • Users cannot disable the trail: review configuration rights and privileged access rather than relying only on management representation.
  • Logs are retained: ensure the organisation's retention and backup process preserves the audit trail along with the underlying books and records for the required period.
  • Interfaces are understood: where transactions pass between systems, document which system creates the accounting record and where subsequent edits can occur.

Example: an invoice is edited after posting

Suppose a sales invoice is posted for ₹1,00,000 and a user later changes the amount to ₹90,000. A compliant audit-trail design should not merely show the final ₹90,000 balance. The edit history should preserve evidence that the transaction was changed and when the modification occurred. The company's control process should also make it possible to investigate who had authority to make the change and whether the change was properly approved.

The accounting entry may originate in a billing application and flow to the general ledger. In that case, reviewing only the general-ledger audit trail may be insufficient if the editable accounting record exists upstream. The system architecture matters.

Management responsibility versus auditor reporting

Management is responsible for maintaining books of account and complying with the applicable Companies Act and Rules. The statutory auditor's role is not to operate the company's audit-trail feature. Instead, the auditor evaluates the relevant accounting-software environment and reports as required under Rule 11(g).

ICAI's revised guide is particularly useful because it addresses practical questions around the auditor's reporting responsibility. The guide is listed on ICAI's official Implementation Guides publication page, alongside the revised 2024 edition on reporting on audit trail.

Common implementation mistakes

  • Checking only the main ERP: accounting data may be created or changed in another application before reaching the ledger.
  • Confusing backups with edit logs: a database backup can help restore data, but it is not automatically a transaction-level edit trail.
  • Ignoring administrator access: a feature that ordinary users cannot disable may still be vulnerable if privileged users can alter or suppress logs.
  • Testing only at year-end: a feature enabled on the audit date does not by itself establish that it operated throughout the period.
  • No evidence of configuration: screenshots taken once are weaker than documented configuration, access-control and periodic-review evidence.

Practical year-round compliance checklist

  1. Prepare an inventory of software used for maintaining books of account and relevant sub-ledgers.
  2. Map how transactions originate, move between systems and reach the general ledger.
  3. Document the audit-trail or edit-log feature for every relevant system.
  4. Restrict configuration and administrator rights through appropriate access controls.
  5. Perform sample tests during the year to confirm that transaction edits are captured.
  6. Review whether log retention and backups cover the required records.
  7. Preserve evidence of periodic checks, exceptions found and remediation performed.
  8. Discuss system changes, migrations and new applications with the statutory auditor early rather than waiting until year-end.

Why Section 128 still matters

The software requirement sits within the broader obligation to maintain proper books. India Code's current Section 128 page states that every company must prepare and keep books of account and other relevant books and papers and financial statements that give a true and fair view and explain transactions, and expressly permits electronic maintenance in the prescribed manner.

That means audit-trail compliance should be integrated with the company's wider books-and-records controls: access management, retention, backup, change management and documentation of accounting processes.

Practical takeaway

The safest approach is to treat audit trail as a continuous accounting control. Companies should map every relevant accounting system, confirm that transaction edits remain traceable, protect the feature from being disabled, retain the logs and test the setup periodically. Auditors should separately apply the Rule 11(g) reporting requirement using the applicable legal text and ICAI guidance. A year-end screenshot of one ERP setting is not a substitute for evidence that the relevant audit trail operated across the accounting environment.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj