If your auditor has been asking whether your accounting software has an "audit trail feature" enabled throughout the year, that is not a casual question. Under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 — effective April 1, 2023 — your auditor is legally required to comment on exactly this in every statutory audit report. A gap in audit trail compliance means a qualification in the audit report, and potentially, a letter from your Registrar of Companies.
Most Indian SMBs know they need to maintain books of account. Far fewer understand that since FY 2023-24, how you maintain those books matters just as much as what you record in them. As auditors wrap up FY 2025-26 annual reports this August and September, thousands of companies will discover — too late — that their accounting software was not fully compliant.
Here's everything your business and your CA need to know.
What the Law Actually Requires
The Ministry of Corporate Affairs amended Rule 3(1) of the Companies (Accounts) Rules, 2014 via notification GSR 205(E) dated March 24, 2021. After multiple postponements, the requirement became effective for all companies from April 1, 2023.
In plain language, Rule 3(1) now mandates that:
- 1Every company using accounting software to maintain books of account must use software that has a feature to record an audit trail (edit log) for each and every transaction.
- 2The audit trail must record changes made to the books of account, along with the date of the change and who made it.
- 3The audit trail must not be capable of being disabled — by any user, including the software administrator.
- 4The audit trail, once created, must be preserved for eight years from the end of the financial year to which it relates.
What Your Auditor Must Now Certify
Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 — also effective April 1, 2023 — requires every statutory auditor to state in the audit report whether the company used accounting software with a continuously active audit trail feature, whether that feature was tampered with, and whether the audit trail was preserved as per statutory requirements.
This is not a tick-box exercise. The auditor must investigate, verify, and explicitly report. If the answer to any part of this is "no" or "not verifiable," the audit report carries a qualification or emphasis-of-matter paragraph — a red flag that attracts ROC scrutiny.
Why So Many Companies Are Non-Compliant
Here are the four most common compliance failures seen by CAs across India:
1. The Feature Exists but Was Disabled at Some Point
Many accounting software products — including popular mid-market ERPs and newer cloud platforms — ship with audit trail as an optional feature. If your system administrator turned it off at any point during FY 2025-26, even for a few days to 'clean up' entries, you have a gap.
Even a single day without audit trail means the auditor cannot certify compliance for the entire year. Auditors now routinely check system logs to verify this.
2. Using Desktop Software Without Proper Logging
Older versions of desktop accounting software — and many tools still widely used across India — do not have granular audit trails. They may record which user logged in, but not what specific entries were altered after posting. That's insufficient under MCA Rule 3(1).
3. Excel-Based Books of Account
If your company maintains books of account in Microsoft Excel or Google Sheets, you have no audit trail at all. Every cell can be overwritten without any record of the change. This is non-compliant under Rule 3(1) and raises questions about the reliability of the books themselves.
A company with ₹2 crore turnover maintaining books in Excel faces the same audit qualification as a ₹50 crore company with a flawed ERP — the rule applies to all companies, regardless of size.
4. Partial Implementation Across Modules
Some software enables audit trail for the general ledger but not for inventory, payroll, or subsidiary ledgers. Rule 3(1) requires audit trail for each and every transaction — a partial implementation does not satisfy the requirement.
What a Proper Audit Trail Must Capture
For your accounting software to be compliant, its audit trail must record, at minimum:
- Transaction date: The original date of entry
- Change timestamp: The exact date and time of any modification
- User ID: Which user account made the change
- Before-value: What the entry said before the change
- After-value: What the entry says after the change
- Nature of change: Whether it was an edit, a reversal, or a new entry
A Practical Example
Suppose your accounts team records a purchase entry of ₹8,40,000 from a supplier on April 15, 2026. On April 22, they realise the amount should have been ₹8,04,000 and modify it. A compliant audit trail shows:
- Original entry: ₹8,40,000 — April 15, 2026, by user 'Accounts-Priya'
- Modification: Changed to ₹8,04,000 — April 22, 2026, at 11:34 AM, by user 'Accounts-Manager'
If your software only shows the current value of ₹8,04,000 with no edit history, you are non-compliant.
The Auditor's Verification Process
Your auditor is not taking your word for this. In FY 2025-26 audits, they will typically:
- 1Request access to the software's audit log for a sample of transactions across the year
- 2Test whether the audit trail can be disabled by a typical admin user
- 3Cross-check backup logs to verify the audit trail was continuously active from April 1, 2025
- 4Look for suspicious patterns — such as bulk entries modified within 24 hours of year-end without a documented business reason
If the audit trail was interrupted for a legitimate reason such as a system migration or backup restoration, document it immediately with a board resolution or IT change log. Auditors give weight to documented explanations; unexplained gaps trigger qualifications every time.
What Happens If You Are Non-Compliant
Qualified Audit Report
The most immediate consequence is a qualification in the statutory audit report under Rule 11(g). This goes into your Annual Report, which is a public document filed with the ROC and accessible to banks, lenders, and prospective investors.
ROC Inquiry and Penalties
A qualified audit report increases the probability of ROC scrutiny. Under Section 128(6) of the Companies Act, 2013, if a company fails to comply with requirements related to maintaining books of account, the managing director, whole-time director in charge of finance, CFO, and company secretary can each face:
- Penalty of ₹5 lakh for the first default
- Imprisonment up to one year in cases of wilful non-compliance
Impact on Bank Financing
A qualified audit report is a red flag for banks and NBFCs. If your SMB is applying for a working capital loan or term loan, a qualification related to books-of-account maintenance can delay or derail the credit appraisal process significantly.
Step-by-Step Compliance Checklist
For FY 2025-26 (Immediate Action)
- Ask your accounting software vendor for a written certificate confirming compliance with MCA Rule 3(1) audit trail requirements
- Pull the audit log from your software and verify it covers the period April 1, 2025 to March 31, 2026 continuously — no gaps
- Confirm the audit trail covers ALL modules: general ledger, accounts payable, accounts receivable, inventory, payroll
- If any gap exists, document the business reason with dates in a board note or IT change register
- Ensure backup copies of the audit log are stored separately and can be accessed for the 8-year retention period
- Brief your auditor on your software's audit trail feature before fieldwork begins
For FY 2026-27 (Preventive Controls)
- Configure the audit trail so it cannot be disabled by any user without a secondary alert or approval
- Train accounts staff: never delete posted entries directly — use formal reversal entries only
- Add audit trail status to your monthly IT controls checklist
- If your current software cannot meet these requirements, evaluate a cloud accounting platform where the audit trail is enforced at infrastructure level
Common Mistakes to Avoid
Assuming compliance because the software is cloud-based. Not every cloud tool is built for Indian Companies Act compliance. A basic invoicing platform storing data in the cloud is not automatically a Books-of-Account compliant system with a proper audit trail. Ask for the specific MCA Rule 3(1) compliance certificate.
Relying on the vendor's verbal assurance. Get it in writing. Vendors who cannot issue a written compliance certificate should be replaced before the next financial year begins.
Enabling audit trail only in the last month of the financial year. Enabling it in March 2026 does not make you compliant for FY 2025-26. The trail must be continuous from April 1, 2025.
Thinking this does not apply to your company because turnover is small. MCA Rule 3(1) applies to every company incorporated under the Companies Act, 2013 that uses accounting software — regardless of turnover, paid-up capital, or whether the company is private or public.
Key Takeaways
- Effective from April 1, 2023: All companies using accounting software must maintain a tamper-proof, continuously active audit trail for every transaction.
- Auditors must certify it: Rule 11(g) requires your statutory auditor to explicitly confirm audit trail compliance in the annual audit report — any gap leads to a qualification.
- Four common failure modes: Disabled feature, Excel-based books, desktop software without granular logs, and partial implementation across modules.
- Penalties under Section 128(6): Up to ₹5 lakh per officer and imprisonment for wilful non-compliance.
- Eight-year retention: The audit log must be preserved for eight years — not just the current year.
How corpus Helps
corpus is built from the ground up for Indian Companies Act compliance. Every transaction posted in corpus — from purchase invoices and journal entries to bank reconciliation and credit notes — is recorded with a tamper-proof audit trail that captures the timestamp, user ID, original value, and modified value. The audit trail cannot be disabled by any user, ensuring continuous compliance with MCA Rule 3(1) from the first day of your financial year.
When your auditor requests audit trail evidence for FY 2025-26, corpus generates a date-filtered audit log exportable to PDF or Excel in minutes — replacing what used to be a week-long manual exercise with a single afternoon of clean documentation. Your CA gets verifiable, structured evidence; you get a clean audit report.
If your current accounting software cannot produce an audit trail compliant with MCA Rule 3(1), the time to switch is before FY 2026-27 begins — not after your auditor qualifies the report.
Contributing author at corpus. Expert in Indian accounting compliance, GST, and financial reporting for Chartered Accountants and growing businesses.
Automate your compliance with corpus
AI-powered cloud accounting built for Indian professionals. GST, TDS, payroll, bank reconciliation — all automated. Join the waitlist.
Join the Waitlist