CORAA
Companies Act · Rule 11(g) · Since FY 2023-24· लॉग

Audit trail reporting: the five things you actually test.

Every company audit report now states whether the accounting software kept an edit log all year, untampered and preserved. Three seasons in, review boards have seen every flavour of vague wording — here is the test battery behind an answer you can defend, the Tally reality, and how to report the gaps.

The five-point test

1

The feature exists — at every layer that stores the books

Confirm the accounting software has an edit log recording each change: what changed, when, and (ideally) by whom. The ICAI Implementation Guide pushes past the application screen: if the books live in a database that administrators can edit directly, the trail question extends to that layer too.

2

It ran throughout the year, for all transactions

Not from the date the client noticed the rule — from day one of the financial year, across every company/entity file in the software. Inspect configuration history or vendor logs for any window where the feature was off; a mid-year gap is a reportable fact.

3

It cannot be — and was not — tampered with

Test whether the edit log itself can be edited, purged or disabled by users, and inspect for signs it was. Management enquiry alone is not evidence; look at the configuration, user rights over the feature, and (for hosted software) the vendor’s controls report.

4

It is preserved for the retention period

Books of account carry an eight-year retention under Sec 128(5); the audit trail rides with them. Year-one logs must still be producible years later — backup and archival practice is part of the test.

5

The finding is reported as a fact, precisely

Rule 11(g) asks for a statement, not an opinion: which software, whether the feature operated throughout, whether tampering was noted, whether preservation holds. Where there are gaps, say exactly what and when — vague comfort language is what review boards flag.

Anchors: proviso to Rule 3(1), Companies (Accounts) Rules 2014 (the company’s duty, FYs from 1 April 2023) · Rule 11(g), Companies (Audit and Auditors) Rules 2014 (the reporting duty) · ICAI Implementation Guide (Revised 2024) · Sec 128(5) retention and penalty (₹50,000–₹5,00,000). Facts verified 18 July 2026.

Free downloads · Evidence the statement

Put the trail test in the file

The Rule 11(g) sentence in the report should trace to working papers: the software inventory, the configuration evidence, the tamper tests and the conclusion. These two anchor it in the file.

Audit file index (SA 230) →JE testing working paper →

CORAA reads the full voucher population from Tally — alteration patterns, period-end spikes and round-sum entries surface as exceptions with drill-down to the voucher — see transactional scrutiny or start free: your first audit is on us.

Audit trail, frequently asked

What does Rule 11(g) require the auditor to report?

For financial years beginning on or after 1 April 2023, the auditor’s report must state whether the company used accounting software with an audit trail (edit log) feature, whether that feature operated throughout the year for all transactions recorded in the software, whether the audit trail was tampered with, and whether it has been preserved as per statutory record-retention requirements. The company-side obligation sits in the proviso to Rule 3(1) of the Companies (Accounts) Rules 2014.

Does Tally have the required edit log?

Yes — Tally ships an Edit Log capability (and a dedicated Edit Log release) that records created/altered/deleted vouchers and masters with timestamps. The audit questions remain: was the edit-log version in use for the whole year, could users disable it, and were company data files migrated or recreated mid-year (which can break trail continuity)? Verify in the client’s actual data, not the brochure.

What if the audit trail was disabled for part of the year?

Report the fact precisely: the feature did not operate throughout the year, specifying the period or transactions affected where determinable. Rule 11(g) reporting is factual — a gap does not automatically modify the opinion, but it may feed the books-of-account reporting under Sec 143(3)(b) and the company faces Sec 128(5) exposure (fine of ₹50,000 to ₹5,00,000).

Does the rule apply to software hosted outside India or to SaaS accounting tools?

Yes — the obligation follows the books, not the server. For SaaS or vendor-managed software where the auditor cannot directly test the trail, the Implementation Guide points to vendor evidence such as independent controls reports (e.g. SOC reports) covering the audit-trail feature, plus the auditor’s own tests on what is observable.

Does the audit trail requirement apply to LLPs or firms?

No — the Rule 3(1) proviso and Rule 11(g) flow from the Companies Act 2013 and apply to companies. LLPs, partnership firms and proprietorships are outside it, though their auditors may still evaluate edit logs as ordinary evidence about the reliability of the books.

Where is the authoritative guidance?

ICAI’s Implementation Guide on Reporting on Audit Trail under Rule 11(g) (Revised 2024 edition) — including its FAQ section covering practical situations: multiple software, mid-year migrations, database-level trails, and reliance on service-organisation reports. Read it alongside the MCA notifications amending the Companies (Accounts) Rules and (Audit and Auditors) Rules.