1 of 26

�Audit Trail �- where corporates and auditors need to focus

CA (Dr.) Sanjeev Singhal

Page 1

6 May 2023

Presentation title

2 of 26

Index

    • Introduction and key changes

    • Requirements under Companies Act, 2013

    • Key management and board considerations

    • Key auditors considerations

    • Interplay between management requirements and auditors reporting responsibilities

    • Illustrative reporting

    • Next steps for companies and the auditors

Audit trail

Page 2

3 of 26

Audit trail: What has changed?

  • Maintaining audit trails is an integral part of any complex IT system like SAP, Oracle, etc. It exists even today, and organizations use it because it is mission critical for certain applications.
    • For e.g., a bill of material application or a payroll application may have detailed audit trails due to the criticality of the applications.
  • Sometimes, certain regulators may require an audit trail to be maintained e.g., the Good Manufacturing Practices (GmP) requirements applicable overseas in the Pharma sector needs audit trail for certain data.
  • The change is that w.e.f April 1, 2023 onwards each and every company, irrespective of size and complexity, would need an audit trail to be maintained throughout the year
  • IT systems can differ from, for e.g., a large automobile company which has a complex system of products, vendors, labor contractors, taxes, etc.
    • Companies, which earlier had a choice of deciding what type of IT systems to use depending on its needs and also a choice on deciding the type of data which they needed an audit trail for, now have limited choices.

Audit trail

Page 3

4 of 26

Requirements under the Companies Act, 2013

From FY beginning 1 April 2023, company which uses accounting software for maintaining its books of account, should use only such accounting software which has:

  • Feature of recording audit trail of each and every transaction
  • Creating an edit log of each change made in the books of account along with the date when such changes were made
  • Ensuring that the audit trail cannot be disabled

Maintenance of electronic records by companies–

Rule 3 of Companies (Accounts) Rules, 2014

From FY beginning 1 April 2022, auditors’ report to state whether the company, has used such accounting software for maintaining its books of account which has:

  • Feature of recording audit trail (edit log) facility
  • Same has been operated throughout the year for all transactions recorded in the software
  • Audit trail feature has not been tampered with
  • Audit trail has been preserved by the company as per the statutory requirements for record retention

Matters to be included in Auditors Report

Rule 11(g) of Companies (Audit and Auditors) Rules, 2014

Management responsibilities and auditor reporting requirements not entirely similar

Audit trail

Page 4

5 of 26

ICAI’s implementation guide

Implementation Guide issued by ICAI deals with key implementation challenges

  • Requirements (management and auditors) apply prospectively i.e. from FY beginning 1 April 2023
  • Applies to all companies under 2013 Act including section 8 company/ foreign company
  • Relevant for consolidated financial statements – components outside India not covered

Audit trail (Edit log) is a visible trail of evidence enabling one to trace information contained in statements or reports back to the original input source.

Audit trails are a chronological record of the changes that have been made to the data. Any change to data including creating new data, updating or deleting data that must be recorded.

Accounting Software is a computer program or system that enables recording, maintenance and reporting of books of account and relevant ecosystem applicable to business requirements.

The functionality of such accounting software differs from product to product. Every organization today employs multiple software for accounting, its operations and other requirements like consolidation, collection of data.

Books of account as per Section 2(13) of the 2013 Act includes records maintained in respect of:

  • All sums of money received and expended by a company and matters in relation to which the receipts and expenditure take place;
  • All sales and purchases of goods and services by the company;
  • Assets and liabilities of the company; and
  • Items of cost as prescribed under section 148 (i.e Cost Records)

Key definitions from the Implementation Guide

Audit trail

Page 5

6 of 26

What constitutes books of account

  • “Books of account” has been defined under Section 2(13) of the 2013 Act; it is a very broad definition which encompasses every record maintained in respect of financial statements
  • Any software that maintains records or transactions that fall under the definition of books of account will be considered as accounting software for maintenance of audit trail
  • The requirements of audit trail are applicable to the extent a company maintains its records in electronic form by using an accounting software
  • Amendments made to Rule 3 regarding access to books of account and daily back up in a physical server located in India
    • accessible at all times
    • Back up on a physical server in India, if the books of account are maintained on a system (server / cloud infrastructure) outside India
    • Back up on a daily basis

Audit trail

Page 6

7 of 26

Common situations / examples

  • Company X has a standalone software for raising sales invoices and recording sales
  • On a monthly basis - a consolidated entry is posted into the general ledger of the company

Sales software should have the audit trail feature since sales invoices fall within the definition of

books of account under 2013 Act

Company X maintains its entire set of books of account on a manual basis

  • Requirement of maintaining audit trail not applicable
  • Same would need to be reported as statement of fact by the auditor

Company X has outsourced payroll and accounts payable processing

  • The service provider should have adequate controls for maintenance of Audit Trail
  • Audit trail reporting will cover software used by service providers

Audit trail

Page 7

8 of 26

Key implementation challenges

Difficulties in amending accounting software maintained at group level (outside India)

Information maintained in MS Excel e.g. consolidation adjustments, current/ deferred tax computations, fixed asset register

Definition of change for audit log - need for a clear definition of what would be considered ‘change’ while recording the edit logs

Ability of companies to invest in such software systems and cost of maintaining audit trail

Implementation challenges for small and medium sized businesses - with relatively limited number of transactions per year, generating and maintaining this ‘audit log over 8years implies a huge quantum of generated data. 

Audit trail

Page 8

9 of 26

Key considerations for management (1/2)

  • Management and Board of Directors primarily responsible for ensuring selection of the appropriate accounting software for ensuring compliance with applicable laws and regulations

  • Accounting software may be hosted and maintained in India/ outside India, may be on-premise, on cloud or subscribed to as Software as a Service (SaaS) software

  • Books of account can also be maintained at a service organisation – e.g. outsourced payroll processing with a shared service centre and the shared service centre may use its own software to process payroll for the company

  • Identify records and transactions that constitute books of account under 2013 Act

  • Any software used to maintain records/ transactions that fall under the definition of books of account (under 2013 Act) is covered e.g. web-portals, databases, cloud infrastructure, used for processing and/ storing data for creation and maintenance of books of account

  • Ensure such software have audit trail feature

  • Ensure that audit trail captures changes to each and every transaction:
    • When changes were made, Who made those changes, What data was changed

Audit trail

Page 9

10 of 26

Key considerations for management (2/2)

  • Ensure that audit trail is appropriately protected from any modification;

  • Ensure that controls over maintenance and monitoring of audit trail and its feature are designed and operating effectively throughout period of reporting. Specific internal controls (predominantly IT Controls) could include:
  • Controls to ensure that the audit trail feature has not been disabled or deactivated
  • Controls to ensure that User IDs are assigned to each individual and that User IDs are not shared
  • Controls to ensure that changes to the configurations of the audit trail are authorized and logs of such changes are maintained
  • Restricting access to the administrators and monitoring changes to configurations that may impact the audit trail
  • Controls to ensure that access to the audit trail (and backups) is disabled or restricted and access logs, whenever the audit trails have been accessed, are maintained
  • Controls to ensure that periodic backups of the audit trails are taken

  • Retain audit trail for a minimum period of 8 years i.e., effective 1 April 2023

Audit trail

Page 10

11 of 26

Key considerations for Board of directors

Board of directors have an important role to play; board to take on record:

  • Policies and procedures as laid down by the management in respect of assertion and conclusion on the adequacy and operating effectiveness of audit trails
  • Deficiencies, significant deficiencies and material weaknesses identified by the management, internal auditors, and the auditor

Audit trail

Page 11

12 of 26

Key considerations for auditors: Audit procedures (1/4)

  • Any software that maintains records or transactions that fall under the definition of books of account as per 2013 Act will be considered as accounting software for this purpose
  • Unlike reporting on ICFR - auditor is required to report that the audit trail feature has “operated throughout the year for all transactions recorded in the accounting software
  • While verifying accounting software used in maintaining the “books of account” – auditor should consider:
  • Software configuration that controls enabling/ disabling of the audit trail. Also assess if audit trail was enabled throughout the year
  • Access to configurations
  • Any changes to the audit trail configuration during the financial year and also from the date of financial statements but before the date of auditor’s report
  • Periodic review mechanism implemented and operated by management for any changes to the audit trail configuration
  • Completeness and accuracy of audit trail or edit logs that are generated through the software functionalities or directly recorded in the underlying database i.e., whether it captures the user ID that made the change, the date and time of change and what fields were changed by reviewing the reports or trails generated, on a test basis, to capture the required information or when the audit trail feature was disabled, etc.
  • Any testing management has performed to assess the completeness and accuracy of the audit trail

Audit trail

Page 12

13 of 26

Key considerations for auditors: Audit procedures (2/4)

  • Assess management’s identification of records and transactions where audit trail needs to be captured
  • Verify on a test basis, whether the audit trail has been configured and enabled for the identified accounting software.
  • Inquire with the management on how they evaluated changes that are required for the maintenance of audit trail as part of changes or upgrades to the accounting software
  • Consider involvement of IT specialists/ experts to assist in evaluation of management controls and configurations in the accounting software with regard to audit trail (where applicable)
  • Evaluate management’s policies in this regard and test controls to determine whether the feature of audit trails have been implemented and operating effectively throughout the reporting period.
  • Inquire with management to understand the procedures implemented by the company to preserve the records as per the statutory record retention period. The auditor may review, on a sample basis, the audit trail records maintained by management for each applicable year and evaluate management controls for maintenance of such records without any alteration and retrievability of logs maintained for the required period of retention
  • Consider that report under SOC 2/ SAE 3402 covers audit trail requirements – (where supported by service providers)

Audit trail

Page 13

14 of 26

Key considerations for auditors: Audit documentation (3/4)

  • Auditor may document the work performed on audit trail such that it provides:

    • a sufficient and appropriate record of basis for auditor’s reporting under Rule 11(g); and

    • evidence that audit was planned and performed in accordance with this Implementation Guide, applicable Standards on Auditing and applicable legal and regulatory requirements.

  • Comply with requirements of SA 230, “Audit Documentation” to the extent applicable.

Audit trail

Page 14

15 of 26

Key considerations for auditors: Management representations (4/4)

  • Acknowledging management's responsibility for establishing and maintaining adequate controls for identifying, maintaining, controlling, and monitoring of audit trails on a consistent basis.

  • Stating that management has performed an evaluation and assessed the adequacy and effectiveness of the company's procedures for complying to the requirements prescribed for audit trails.

  • Stating management's conclusion, as set forth in its assessment, about the adequacy and effectiveness of the company's procedures w.r.t. audit trails.

  • Stating that management has disclosed to the auditor all deficiencies in the design or operation of controls maintained for audit trails identified as part of management's evaluation.

  • Describing instances where identification of fraud, if any, resulting in a material misstatement to the company's financial statements is identified while reviewing and testing the samples related to the disablement of audit trail facility of the accounting software.

  • Stating whether control deficiencies identified and communicated to the audit committee in relation to audit trail during previous engagements have been resolved, and specifically identifying any deficiency that have not been resolved.

Audit trail

Page 15

16 of 26

Interplay between management responsibility and auditors reporting requirements�

  • For the purpose of auditor reporting ‘All transactions recorded in the software’ would refer to all transactions that result in change to the books of account. For example
    • Creation of a user in the accounting software is a transaction in the software but not a change in books of account (Not covered in auditors reporting requirements)
    • Adding a new journal entry or changing an existing journal entry will be a change made in books of (Covered in auditors reporting requirements)
  • Auditor expected to check audit trail for transactions which result in a change to the books of account
  • Requirement of accounting software having feature of audit trail has been prescribed only in the context of books of account
  • Evidenced by the fact that as stated in Accounts Rule - accounting software should be capable of creating an edit log of ‘each change made in books of account

Management responsibility under Accounts Rules

  • Auditor reporting responsibility in respect audit trail in accounting software has been prescribed for ‘all transactions recorded in the software

Auditor responsibility under Auditors Rules

Audit trail

Page 16

17 of 26

Special consideration: Fraud scenarios�

  • Auditor may come across a scenario where occurrence of an error/ fraud could not be established due to lack of maintenance, availability/ retrievability of audit trails
  • In evaluating the severity of a deficiency for such instances specifically in cases of fraud, the auditor should primarily consider two factors:
    • Likelihood that the deficiency will result in a material misstatement
    • Magnitude of such an outcome.
  • This scenario would, in essence, call for performing an assessment of risk of material misstatement due to fraud and would consider both qualitative and quantitative factors in assessing a deficiency or combination of deficiencies as a significant deficiency or material weakness.
  • It would accordingly require application of professional judgement while linking the reporting against Rule 11(g) and section 143(12) of the Act/ clause (x) of CARO 2020 (as the case may be).

Audit trail

Page 17

18 of 26

Special consideration: Impact on ICFR reporting

  • Section 143(3)(i) of the 2013 Act, where applicable, requires the auditor to state in his audit report whether the company has adequate internal financial controls with reference to financial statements in place and the operating effectiveness of such controls.
  • ICAI has issued Guidance Note in this regard
  • Guidance Note uses expression ‘audit trail’ – but does not entail any detailed audit procedures
  • Mere non-availability of audit trail does not necessarily imply failure or material weakness in the operating effectiveness of ICFR
  • Where the feature of audit trail has not operated throughout the year, the auditor may need to appropriately modify his comment while reporting on audit trail depending upon the further testing/examination as may be required to conclude the wider impact on the reporting implication e.g. a where ICFR opinion is modified due to inability of management to rely on the automated controls the auditor may report as follows:

The company has used an accounting software for maintaining its books of account however for the reasons stated in [refer the reporting of ICFR] management is unable to rely on automated controls related to financial reporting in the accounting software and consequently we are unable to comment on audit trail requirements of the said software as envisaged under Rule 11(g)

Audit trail

Page 18

19 of 26

Auditors reporting: FY 2022-2023

Illustrative reporting - section ‘Report on Other Legal and Regulatory Requirements’:

As proviso to rule 3(1) of the Companies (Accounts) Rules, 2014 is applicable for the company only w.e.f. April 1, 2023, reporting under this clause is not applicable

  • In FY 2022-23 management has not been mandated to use the accounting software with requisite audit trail facility
  • Auditor reporting exists for FY 2022-23
  • Auditor should make a factual statement stating that the management responsibility is not applicable in the current year

Audit trail

Page 19

20 of 26

Auditors reporting: Unmodified reporting in FY 2023-2024 (standalone)

Illustrative reporting - section ‘Report on Other Legal and Regulatory Requirements’:

Based on our examination which included test checks, the company has used an accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility and the same has operated throughout the year for all relevant transactions recorded in the software. Further, during the course of our audit we did not come across any instance of audit trail feature being tampered with.

[*Additionally, the audit trail has been preserved by the company as per the statutory requirements for record retention.]

*This reporting would be relevant from the second year. In the first year of applicability, this sentence would not be reported upon.

Audit trail

Page 20

21 of 26

Auditors reporting: Unmodified reporting in FY 2023-2024 (consolidated)

Illustrative reporting - section ‘Report on Other Legal and Regulatory Requirements’:

Based on our examination which included test checks and that performed by the respective auditors of the subsidiaries, associates and joint ventures/joint operations which are companies incorporated in India whose financial statements have been audited under the Act, the company, subsidiaries, associates and joint ventures/joint operations have used an accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility and the same has operated throughout the year for all relevant transactions recorded in the software. Further, during the course of our audit we did not come across any instance of audit trail feature being tampered with.

[*Additionally, the audit trail has been preserved by the company as per the statutory requirements for record retention.]

*This reporting would be relevant from the second year. In the first year of applicability, this sentence would not be reported upon.

Audit trail

Page 21

22 of 26

Auditors reporting: Modified reporting in FY 2023-2024 (standalone)

Illustrative reporting - section ‘Report on Other Legal and Regulatory Requirements’:

[Fixed asset software did not have audit trail]

Based on our examination, the company, has used accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility except in respect of maintenance of fixed asset records wherein the accounting software did not have the audit trail feature enabled throughout the year. Further, the audit trail facility has been operating throughout the year for all relevant transactions recorded in the software except for the instances reported below…... Further, during the course of our audit we did not come across any instance of audit trail feature being tampered with.

Audit trail

Page 22

23 of 26

Auditors reporting: Modified reporting in FY 2023-2024 (consolidated)

Illustrative reporting - section ‘Report on Other Legal and Regulatory Requirements’:

Based on our examination, which included test checks, and that performed by the respective auditors of the subsidiaries, associates and joint ventures/ joint operations which are companies incorporated in India whose financial statements have been audited under the Act, except for the instances mentioned below, the company, subsidiaries, associates and joint ventures/ joint operations have used an accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility and the same has operated throughout the year for all relevant transactions recorded in the software. Further, during the course of our audit, we and respective auditors of the above referred subsidiaries, associates and joint ventures/ joint operations did not come across any instance of audit trail feature being tampered with. [*Additionally, the audit trail has been preserved by the Holding Company and above referred subsidiaries, associates and joint ventures/joint operations as per the statutory requirements for record retention.]

*This reporting would be relevant from the second year. In the first year of applicability, this sentence would not be reported upon.

Instances of accounting software for maintaining its books of account which did not had a feature of recording audit trail (edit log) facility and the same was not operated throughout the year for all relevant transactions recorded in the software

In respect of […] of subsidiaries

[No of instances without mentioning name of the Components]

Instances of audit trail feature being tampered with

Instances of non-preservation of the audit trail

Audit trail

Page 23

24 of 26

Next steps for companies

  • Take an inventory of software in use by the company during the year
  • Identify the processes which are relevant from a financial statement perspective
  • Identify critical elements in each of the processes for which IT logs changes/ trail may be required
  • Discuss the data requirement with the software vendors and the possibility and cost of generating and maintaining data
  • For outsourced processes, communicate with the service providers, re-set expectations, modify contracts
  • Discuss the approach for compliance with the MCA requirements with the Board/Audit Committee and the auditors
  • Identify areas/processes/elements in the processes for which trail is not possible/not feasible etc.
  • Assess reporting implications, both in the financial statements and in the auditor’s report
  • Assess compliance with laws and regulations in case of exceptions, response in Directors Report
  • Enabling audit trails may not be a simple task for companies which use simple accounting software, which typically don't have an audit trail functionality
  • Companies may have to effect significant changes to their existent software or implement a different software altogether.

Audit trail

Page 24

25 of 26

Next steps for auditors

  • Understand the business, how it operates, use of technology and the capability of the technology to have any audit trail
  • For key processes, understand risks and controls – manual or IT
  • Involve appropriate expert on the audit team possessing appropriate IT audit skills and understanding of the company software
  • If any audit firm does not have this expertise within the firm, external experts can be involved as per SA620 “Using the work of an Auditors Expert”. The audit firm should understand the competency of the expert, objectivity, ensuring ethics compliance and documenting these aspects on the workpaper file
  • Early planning for this new reporting requirement and communication with auditee and where required Those Charged With Governance (TCWG) – this can also be accomplished with the closing of the March 2023 audits
  • Where Audit Trail is ineffective, assess the impact on ICFR and identification and testing of alternate controls
  • Planning and timely communication to obtain reports from service providers for outsourced processes
  • Assess impact on reporting including NOCLAR – audit report and ICFR
  • Timely communication to management and TCGW for potential report modification

Audit trail

Page 25

26 of 26

Thank you

Audit trail

Page 26