All writing
Audit Methodology12 September 20268 min read

Audit Trail Under Rule 11(g): The Year It Starts, and What to Test

Two rules, two dates, and a year in the middle where the clause is not reported at all — plus the software list that decides whether the rest of the work means anything.

In short
  • The company's obligation under the proviso to Rule 3(1) applies from 1 April 2023, while Rule 11(g) speaks of financial years commencing on or after 1 April 2022 — so ICAI's Implementation Guide puts the first year of reporting at financial year 2023-24.
  • The sentence on preservation is reported from the second year, financial year 2024-25, and the trail is kept for eight years because section 128(5) requires books to be preserved that long.
  • Scope is every software whose changes reach the books of account, including databases and systems at a service organisation, where a SOC 2 or SAE 3402 report may be used.
Yellow and green network cables neatly connected in a patch panelPhotograph: Albert Stoynov / Unsplash

Three audit seasons after the audit trail became law, the reporting under Rule 11(g) is still going wrong in the same two places: the year it started, and the software nobody listed.

The two rules, and which one binds whom

They are different rules, in different sets of rules, with different dates.

The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 binds the company:

"Provided that for the financial year commencing on or after the 1st day of April 2023, every company which uses accounting software for maintaining its books of account, shall use only such accounting software which has a feature of recording audit trail of each and every transaction, creating an edit log of each change made in the books of account along with the date when such changes were made and ensuring that the audit trail cannot be disabled."

Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 binds the auditor:

"Whether the company, in respect of financial years commencing on or after the 1st April, 2022, has used such accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility and the same has been operated throughout the year for all transactions recorded in the software and the audit trail feature has not been tampered with and the audit trail has been preserved by the company as per the statutory requirements for record retention."

Read them together and a year falls out of the middle. The reporting rule says financial years commencing on or after 1 April 2022. The company's own obligation was deferred twice and lands on 1 April 2023, the last deferral being the Companies (Accounts) Second Amendment Rules, 2022.

The Implementation Guide says so plainly at paragraph 14: audit reporting is triggered for financial years commencing on or after 1 April 2022, "however, the applicability of the Account Rules will commence on or after April 1, 2023", so for financial year 2022-23 "in absence of compliance requirement for the companies, auditors would not be able to report under Rule 11(g)". Its illustrative wording for that year says exactly that — the proviso applies only with effect from 1 April 2023, so reporting under the clause is not applicable.

Two consequences, both in the Guide's own footnote:

  • Reporting under Rule 11(g) is applicable from financial year 2023-24.
  • The sentence about preservation is relevant from the second year, financial year 2024-25.
An unmodified paragraph that reports on preservation in the first year is reporting on something the Guide does not ask for in that year.

How long the trail is kept

Rule 11(g) says "as per the statutory requirements for record retention" and stops. The Guide fills it in at paragraph 19: section 128(5) of the Companies Act, 2013 requires books of account to be preserved for a minimum of eight years, so the audit trail is retained for a minimum of eight years, from the date the Accounts Rules applied — 1 April 2023 onwards.

Where the position actually lands

Try it

Where the Rule 11(g) reporting lands

Pick the year under audit, then answer each assertion the rule makes.

Does every software used for the books of account have an audit trail (edit log) feature?Paragraph 20 — management identifies the applications, web portals, databases, interfaces and cloud components used to create and maintain the books.
Was it operated throughout the year for all transactions recorded in the software?Paragraph 11 — whether the feature is configurable, and whether it was enabled for the whole period, not only when tested.
Did the audit find no instance of the feature being tampered with?Paragraph 20 — controls over access to the audit trail and its backups, and logs of changes to its configuration.
Has the audit trail been preserved as per the statutory requirements for record retention?Paragraph 19 — section 128(5) requires books to be preserved for at least eight years, so the trail is kept eight years from 1 April 2023.

ICAI, Implementation Guide on Reporting on Audit Trail under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 — paragraphs 11, 14, 19, 20, 30 and 31, and the rules reproduced in it.

The software list is the audit

The commonest failure is not a missing feature. It is a missing system.

Paragraph 20 puts the first responsibility on management: identify the records and transactions that constitute books of account under section 2(13), then identify the software — and the Guide's list of what counts is deliberately wide: applications, web portals, databases, interfaces, data warehouses, data lakes, cloud infrastructure, or any other IT component used for processing or storing data for the books of account.

A company that answers "Tally" has answered for one of them. The billing portal that raises invoices, the payroll system, the warehouse application that books stock movements, the database the whole thing sits on — each is in scope if a change there changes the books.

Paragraph 9 adds the cases people forget: the software may be hosted in India or outside it, on-premise, on cloud, or subscribed to as software as a service, and it may be maintained at a service organisation. Paragraph 22 gives the answer for that last one — the company and the auditor may use the service organisation's own independent auditor's report, such as SOC 2 or SAE 3402, provided it specifically covers maintenance of the audit trail in line with the Act.

What management has to be able to show

Paragraph 20's list, compressed. Management must ensure that the software has the feature; that it captures changes to each and every transaction, including when changes were made, who made them and what was changed; that it is always enabled; that it is enabled at the database level, where applicable, to log direct data changes; that it is protected from modification; that it is retained for the statutory period; and that the controls over it are designed and operating effectively throughout the period of reporting.

To demonstrate that, the Guide expects specific internal controls, and lists five:

  • Controls that the feature has not been disabled or deactivated.
  • Controls that user IDs are assigned to each individual and are not shared.
  • Controls that changes to the audit trail's configuration are authorised, with logs of those changes.
  • Controls that access to the audit trail and its backups is disabled or restricted, with access logs.
  • Controls that periodic backups of the trail are taken and archived for the period specified under section 128.

The second one is the quiet killer. A shared login satisfies "when" and "what" and defeats "who", and an edit log that cannot name a person is evidence of very little.

Testing it in three accounting packages

What follows is each vendor's own published documentation, and the audit question it settles.

TallyPrime. Edit Log is available from Release 2.1. Tally publishes two products: in TallyPrime Edit Log, the feature is always on with no option to disable it; in the regular TallyPrime release, it can be enabled or disabled as needed. That single difference is the first thing to establish, because the proviso to Rule 3(1) requires that the audit trail cannot be disabled. Tally's FAQ says that if the feature is disabled in the regular release, logging of future activity stops while previously captured logs remain, and re-enabling resumes it going forward — which is precisely the gap the rule is aimed at. The log records version numbers, the user who made the change, the date and time, and what changed, shown in a "Differences Between Edit Log Versions" report. Deleted vouchers are logged and can be viewed. Edit logs remain intact after backup and restore, and when a company is split the data persists in both companies, with the split itself recorded in the Activities Affecting Edit Log report. Masters as well as vouchers are covered.

Zoho Books. Its India audit trail page states that the audit trail captures all user and system-generated transactions and that the product does not allow disabling of audit trails. It is part of the Activity reports in the Reports module, and an entry shows when the action was performed, who performed it, the module, and what the action was. Where a record is changed more than once, every version is kept and versions can be compared.

BUSY. Its own FAQ states that where the GSTIN is registered as a company, the audit trail feature is automatically enabled and is compulsory as per MCA guidelines, and the report can be filtered by user and by whether the entry was added, modified or deleted.

Three observations follow for the working paper:

  • Ask which release and which product, not which brand. Two builds of the same software can differ on the only point the rule cares about.
  • Get the evidence for "throughout the year". Enabled on the date of testing is not what Rule 11(g) asks. A configuration screenshot taken in October says nothing about April.
  • Ask about the database. Application-level logging does not capture a change made directly to the tables underneath, which is why paragraph 20 asks for database-level logging where applicable.

The working paper

A blank three-sheet working paper — the software inventory with hosting and enablement, the five controls from paragraph 20 with columns for design and operating effectiveness, and the procedures from paragraphs 19 to 22 with a conclusion line.

Download the audit trail working paper (.xlsx) — free, no sign-up.

Reporting, in the Guide's words

For an unmodified position, the Guide's illustration reads that based on an examination which included test checks, the company has used an accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility, that it has operated throughout the year for all relevant transactions recorded in the software, and that the audit did not come across any instance of the feature being tampered with — with the preservation sentence added from the second year.

Where it does not hold, paragraph 31 is blunt about the register to use: the reporting under this rule requires factual reporting. Not an opinion on whether the gap matters; a statement of what was found — which software, which period, which transactions.

Questions this answers

From which year is reporting under Rule 11(g) applicable?

From financial year 2023-24. Rule 11(g) speaks of financial years commencing on or after 1 April 2022, but the company's own obligation under the proviso to Rule 3(1) applies only from 1 April 2023, so for financial year 2022-23 the Implementation Guide reports the clause as not applicable.

How long must the audit trail be preserved?

A minimum of eight years. Rule 11(g) refers to the statutory requirements for record retention, and section 128(5) of the Companies Act, 2013 requires books of account to be preserved for at least eight years, counted from 1 April 2023 onwards.

Does the audit trail requirement apply to software other than the accounting package?

Yes. The Implementation Guide asks management to identify every application, web portal, database, interface, data warehouse, data lake or cloud component used for creating and maintaining the books of account, whether hosted in India or outside, on-premise, on cloud or as software as a service.

Can the audit trail feature be switched off in TallyPrime?

It depends on the product. Tally's documentation says Edit Log is available from Release 2.1, that in TallyPrime Edit Log the feature is always on with no option to disable it, and that in the regular TallyPrime release it can be enabled or disabled as needed.

What if the accounting software is run by a service provider?

The Implementation Guide says the company and the auditor may consider the service organisation's independent auditor's report, such as SOC 2 or SAE 3402, provided it specifically covers maintenance of the audit trail in line with the Act.