ICAI's ISAS: 11 Information Systems Audit Standards, and a Six-Month Clock Already Running
In February 2026, ICAI's Digital Accounting and Assurance Board (DAAB) published the Compendium of Information Systems Audit Standards (ISAS) — approved by the Council and announced to members on 30 March 2026. ICAI's own framing: this is the first comprehensive, principle-based framework of information systems audit standards issued by any professional accounting body worldwide.
The detail that matters most sits in the compendium's preface: "The Standards shall remain on a recommendatory status for an initial period of six months." Six months from the late-March 2026 release means the recommendatory runway points to roughly the end of September 2026 — and as of July, it is already more than half gone. The compendium does not name the exact switchover date, but the direction is unambiguous: these are written as minimum standards for ICAI members conducting IS audit engagements, not as optional guidance.
The 11 Standards
The compendium is organised in six series, mirroring the structure of the familiar SA series:
| Series | Standard | Title |
|---|---|---|
| 100 — Key Concepts | ISAS 110 | Key Concepts |
| 200 — Engagement Planning | ISAS 210 | Business and Information Systems Context |
| ISAS 220 | Engagement Planning | |
| 300 — Executing Assignments | ISAS 310 | Assignment Execution |
| ISAS 320 | Evidence and Documentation | |
| 400 — Specific Areas | ISAS 410 | Audit of Information Systems Controls |
| ISAS 420 | Use of Automated Tools and Techniques | |
| ISAS 430 | Audit of Digital Personal Data Protection | |
| ISAS 440 | Cybersecurity Audit | |
| 500 — Reporting | ISAS 510 | Reporting Results |
| 600 — Quality Control | ISAS 610 | Quality Management and Continual Improvement |
The standards sit inside a larger framework built on the ICAI Code of Ethics: a governing framework document, nine Basic Principles of information systems audit (independence, due professional care, skills and competence, systematic performance, and so on), the 11 mandatory-track standards above, and a recommendatory layer of Implementation Guides and Technical Guides.
What's Genuinely New Here
KIAMs — Key Information Systems Audit Matters. ISAS 510 requires the IS audit report to communicate the matters of highest significance in the engagement, each carrying a risk rating (Critical / High / Medium / Low). It is a deliberate mirror of the Key Audit Matters construct financial auditors know from SA 701 — imported into a domain whose reports have historically been unstructured findings lists.
A DPDP audit standard. ISAS 430 covers audits of Digital Personal Data Protection — evaluating the controls that protect personal data across its lifecycle. With DPDP Act obligations phasing in through 2026-27, this is the first ICAI standard purpose-built for the engagement type those obligations will generate. If your firm is preparing for that work, our DPDP for CA firms guide covers the compliance side of the same coin.
Rules for auditing with AI and automated tools. ISAS 420 governs the use of Automated Tools and Techniques — explicitly including AI, blockchain analysis, and big-data tooling — and its anchor requirement is reproducibility of results: a tool must produce consistent outcomes under identical conditions before its output can stand as audit evidence. That is the same discipline we've argued for in deterministic, rule-based audit automation: if a procedure can't be re-run to the same answer, it isn't evidence.
Digital evidence treated as volatile. ISAS 320 builds documentation requirements around the "digital artifact lifecycle" — identification, collection, preservation, analysis, secure purging — with reliability anchored in hashing, digital signatures, and timestamps. System logs and metadata age badly; the standard forces the engagement file to capture them in a defensible state.
A quality system with an external check. ISAS 610 mandates a Quality Management and Continual Improvement System for IS audit practices: internal quality reviews on an ongoing basis, an external quality review at least once every three years, and at least 20 CPE hours annually in IS-audit subjects for professionals practising in the space.
Who This Actually Lands On
A common misreading is that ISAS is aimed at startups or fintechs. The real demand driver is regulatory: a substantial volume of IS audit work in India is mandated — RBI's Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (November 2023, effective 1 April 2024) requires banks and NBFCs to maintain an IS audit policy and undergo periodic IS audits, and SEBI's system-audit framework imposes comparable requirements on market intermediaries. That mandated work has until now been performed against a patchwork of regulator terms of reference, ISACA practice, and each firm's own methodology. ISAS gives the ICAI members doing it — typically DISA-qualified — a single professional benchmark, and gives the regulators receiving the reports a stated basis to hold them to.
For statutory auditors who never sign an IS audit report, the compendium still matters at one remove: ITGC and application-control testing inside a financial audit remains governed by SA 315, but the ISAS 410 structure (IT general controls at entity level; application controls split into functional and security controls) is likely to become the reference vocabulary for how Indian firms scope that testing — much as its evidence and reporting constructs echo through audit quality management more broadly.
Frequently Asked Questions
Are the ISAS mandatory right now?
No. The compendium's preface places the standards on recommendatory status for an initial period of six months from release. The compendium is dated February 2026 and was announced to members on 30 March 2026, so that runway points to roughly the end of September 2026. ICAI has not announced the precise date on which they become mandatory — watch for a DAAB announcement.
How many standards are there?
Eleven, across six series: ISAS 110, 210, 220, 310, 320, 410, 420, 430, 440, 510 and 610, plus a governing framework, nine Basic Principles, and recommendatory implementation and technical guidance.
Do ISAS replace the DISA qualification?
No — they are complementary. DISA (ICAI's post-qualification Diploma in Information Systems Audit) is the competence credential; ISAS are the performance standards for the engagements. The Basic Principles expressly cite requisite qualifications such as DISA under skills and competence.
Do ISAS change ITGC testing in a statutory audit?
Not directly — ITGC work inside a financial statement audit continues to be governed by the SAs (principally SA 315). ISAS apply to standalone information systems audit engagements. Expect convergence in vocabulary and working-paper structure over time, not a change in which standard governs the statutory audit.
Verified 23 July 2026 against ICAI's Compendium of Information Systems Audit Standards (icai.org PDF) and the DAAB release announcement of 30 March 2026 (icai.org PDF).