UDIN, or Unique Document Identification Number, is ICAI's document-authentication mechanism for specified certificates, audit reports and other attestation documents signed by Chartered Accountants in full-time practice. For a practicing CA, the practical question is not simply what UDIN means, but which documents need it, who must generate it, when it should be generated and what happens when a document has more than one signing auditor.
ICAI's current UDIN portal is the operational starting point for generation and verification. ICAI also maintains a current FAQs on UDIN publication through the UDIN Directorate. The framework is intended to help regulators, banks and other stakeholders verify documents associated with practicing Chartered Accountants.
When is UDIN required?
ICAI's published FAQs state that UDIN was made mandatory in phases: for certificates from 1 February 2019, GST and tax audit reports from 1 April 2019, and other audit, assurance and attestation functions from 1 July 2019. In practical terms, a full-time practicing CA signing a professional document should not assume that UDIN applies only to tax-audit reports. The document category and the nature of the signing function need to be checked.
The safest workflow is to identify the document category before signing and then use the relevant category on the UDIN system. This also helps avoid treating a certification assignment and an audit or assurance assignment as interchangeable merely because both involve a CA signature.
Who has to generate the UDIN?
ICAI's UDIN FAQs state that practicing CAs holding a full-time Certificate of Practice are the members who generate UDINs. The signing member is responsible for generating the UDIN; a partner should not generate it on behalf of another partner who actually signed the attestation document.
This distinction matters in firms with centralised compliance teams. Administrative staff may maintain trackers and collect information, but the professional workflow should preserve the link between the signing member and the UDIN generated for that member's document.
Can UDIN be generated before signing?
No. ICAI's published UDIN FAQs state that there is no option to generate a UDIN in advance. The number relates to a document that has been signed, so the signing date and the information used for generation should be final and internally consistent.
A practical control is to make UDIN generation part of the document-release checklist: finalise the document, obtain the authorised signature, generate the UDIN using the correct particulars, place or communicate it as required, and retain evidence in the engagement file.
What is the 60-day rule?
ICAI states that UDIN should be generated while signing the relevant report, certificate or document. Where a member is unable to generate it at that time, ICAI's continuing rule permits generation within 60 days from the date of signing. The Institute's specific announcement aligning the generation period to 60 days also says that where a regulator or stakeholder requires UDIN immediately or within a specified period, that requirement should be followed.
The 60-day period should therefore be treated as a backstop, not a routine target. A firm that waits until day 55 for every document creates avoidable risk if the signing date, category or document particulars later need to be checked.
Example: certificate signed today but UDIN missed
Assume a practicing CA signs a certificate on 10 August but the team discovers on 18 August that UDIN was not generated. The practical response is to generate the UDIN against the actual signing date and document particulars without waiting further, provided the case remains within ICAI's permitted period and no regulator-specific shorter requirement has been breached. The generated UDIN should then be communicated to management or those charged with governance for dissemination to stakeholders, consistent with ICAI's guidance.
What happens in a joint audit?
ICAI's FAQs clarify that in a joint audit, all signing auditors must obtain UDIN separately and mention their UDINs individually on the report signed by them. One auditor's UDIN is therefore not a substitute for the other joint auditor's identification.
For audit teams, the release checklist should contain a separate UDIN status against every signing auditor. This is especially useful when different firms or partners complete their internal sign-off at different times.
Does a generated UDIN expire?
ICAI's published FAQs state that a generated UDIN has no expiry unless it is revoked. That is different from the deadline for generating the number. The 60-day rule concerns when generation must occur; it does not mean that a correctly generated UDIN automatically expires after 60 days.
What about duplicate certificates?
ICAI's FAQs distinguish a duplicate copy from a fresh professional certification. Where a duplicate certificate is issued at the client's request, the FAQ says UDIN is generated once for the original certificate and the same earlier-generated UDIN is mentioned on the duplicate. Teams should therefore avoid creating a second UDIN merely because the client asks for another copy of the same original certificate.
Practical UDIN checklist for CA firms
- Classify the document: identify whether it is a certificate, GST or tax audit report, or another audit, assurance or attestation document.
- Confirm the signing member: the UDIN should be generated by the CA who signs the document.
- Use the actual signing date: do not pre-generate a UDIN for an unsigned document.
- Generate promptly: aim for generation at signing; use the 60-day allowance only where generation could not be completed then.
- Check external deadlines: a regulator, bank or other stakeholder may require UDIN immediately or within a shorter specified period.
- Handle joint audits separately: track a separate UDIN for every signing auditor.
- Retain an engagement-file trail: keep the UDIN, signing date, document version and communication evidence together.
Common mistakes to avoid
- Assuming UDIN applies only to tax audit.
- Allowing one partner to generate UDIN for another signing partner.
- Trying to generate UDIN before the document is signed.
- Confusing the 60-day generation limit with a 60-day validity period.
- Using one joint auditor's UDIN for all signing auditors.
- Generating a fresh UDIN merely for a duplicate copy of the same original certificate.
Practical takeaway
For practicing Chartered Accountants, UDIN is best managed as a signing control rather than an after-the-fact administrative task. Identify whether the document falls within ICAI's mandatory framework, ensure the signing CA generates the number, generate it at signing wherever possible, and treat the 60-day period only as the permitted fallback. ICAI's current UDIN portal and 6th Edition FAQ publication page should be checked when a document presents an unusual or category-specific question.