The Audit Trail Requirement for Companies: What Rule 3(1) Demands and What Your Auditor Must Report
A requirement with no size exemption, an eight-year retention period, and a remark that goes on the public record.
The audit trail requirement for companies is one of the few obligations under the Companies Act framework that carries no exemption for size, turnover or class. A two-founder private company in its first year is bound by it on exactly the same terms as a listed group. Any company whose accounts live on a computer is within it, which today means effectively all of them, and it has bound financial years starting on or from 1 April 2023.
What makes it worth a founder's attention is not the rule itself but its enforcement mechanism. Compliance is not assessed by an inspector who may or may not visit. It is assessed by your own statutory auditor, who is separately required to report on it in the audit report, and that report is filed with the Registrar and sits on the public record. A software shortcoming becomes a permanent, publicly visible remark on the company's accounts. This article sets out what the rule requires, who it reaches, what the auditor must say, and how long the records must survive.
01 — The RuleWhat Is the Audit Trail Requirement for Companies Under Rule 3(1)?
The obligation sits in the proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014, made under Section 128 of the Companies Act, 2013 and notified by the Ministry of Corporate Affairs. For financial years commencing on or after 1 April 2023, a company that uses accounting software to maintain its books of account may use only software that carries a specific set of capabilities.
The audit trail requirement for companies rests on three capabilities, stated together in the rule. The software must record an audit trail of each and every transaction. It must create an edit log of each change made in the books of account, along with the date on which that change was made. And it must ensure that the audit trail cannot be disabled. The third of these is what converts the requirement from a feature into a control: a log that an administrator can switch off provides no assurance about the period during which it was off.
A definitional point matters more than it first appears. The rule attaches to software used for books of account, and books of account is itself a defined expression under the Act. Where a company runs several systems, and records falling within that definition are maintained in more than one of them, each such system comes within scope. A billing platform, an inventory system or a payroll application that feeds entries into the ledger is not automatically outside the requirement simply because nobody thinks of it as accounting software. Establishing the full inventory of in-scope systems is the first task in any audit trail services review we carry out.
02 — Who's CoveredWhich Entities Does the Requirement Apply To?
All of them, provided the accounts are kept electronically, and no size threshold applies. The table below sets out the position for the entity types we are most often asked about.
| Entity Type | Covered? | Position |
|---|---|---|
| Private limited company | Yes | No exemption by size, turnover or capital; applies from the first financial year |
| Small company | Yes | The small company relaxations elsewhere in the Act do not extend to this requirement |
| One person company | Yes | Covered on the same terms as any other company |
| Dormant company | Yes | Dormant status affects filing obligations, not the manner of keeping books |
| Section 8 company | Yes | Charitable object makes no difference to the requirement |
| Foreign company | Yes | Covered in respect of books maintained for its Indian operations |
| LLP, firm, proprietorship, trust, society | No | Governed by other statutes; the Companies (Accounts) Rules do not reach them |
The exclusion of limited liability partnerships is genuine and often useful, but it should not be read as permanent planning. A business that converts from an LLP into a private limited company acquires the obligation on conversion, and it acquires it for the software it is already using. Where a conversion is contemplated, the audit under the LLP Act position and the post-conversion position are worth considering together rather than sequentially.
03 — Five TestsWhat Must the Software Actually Do to Comply?
Five tests decide whether software meets the audit trail requirement for companies, and vendor marketing material will rarely answer all five. They are worth putting to a vendor in writing.
- Is the logging a built-in feature of the software itself? A log maintained manually, in a separate register or spreadsheet, does not satisfy the rule regardless of how carefully it is kept.
- Does it capture every change, not merely the creation of entries? The requirement is an edit log of each change made in the books, which means modifications and deletions as well as original entries.
- Is the date of each change recorded? The rule states this expressly, and a log without reliable dating cannot demonstrate when the books were altered.
- Can any user, including an administrator, disable the feature? If the answer is yes, the software does not meet the requirement as drafted, whatever its other capabilities.
- Does the logging extend to changes made directly at the database, bypassing the application? Where the books can be altered by that route, application-level logging alone will not capture it.
Note — Where accounting software is hosted or supported by an external service provider, the company remains responsible for compliance. Management and the auditor may look to an independent assurance report obtained by that provider as evidence about the controls it operates, but the obligation itself does not transfer. This is worth confirming in the contract with any cloud accounting vendor rather than assuming it from a compliance page on their website.
04 — Rule 11(g)What Does Your Auditor Have to Report Under Rule 11(g)?
The reporting obligation sits in Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, introduced by amendment in March 2021 and read with the provision of the Act requiring auditors to report on such other matters as may be prescribed. It sits in the part of the audit report dealing with other legal and regulatory requirements.
The auditor is required to state four things: whether the company used accounting software having the audit trail feature; whether that feature operated throughout the year for all transactions recorded in the software; whether the feature was tampered with; and whether the audit trail has been preserved in accordance with the statutory requirements for record retention. Each is a separate assertion, and a company can satisfy the first and fail the second.
Two consequences follow that founders often do not anticipate. First, the auditor must modify the remark where the requirement is not met even if the financial statements themselves are entirely correct, because the two matters are assessed separately. Second, in the earlier reporting cycles the preservation assertion attracted little scrutiny for the simple reason that there was no prior year of logs to have preserved. That is no longer the case, and preservation is now tested as a matter of course. Where a statutory audit is being planned, the audit under the Companies Act scope should include this well before the year end rather than at fieldwork.
05 — RetentionHow Long Must the Audit Trail Be Preserved?
Eight years, following the retention period prescribed for books of account under Section 128(5) of the Companies Act, 2013. Since the substantive requirement began on 1 April 2023, the retention clock runs from that date, which means the earliest logs now within the period date from the financial year 2023-24.
Retention creates two practical problems that are easy to overlook while a system is running normally. The first is a change of software. A company that migrates from one accounting package to another does not shed its obligation in respect of the earlier period, and the historical logs must remain retrievable for the balance of the eight years even though the system that generated them is no longer in use. The second is subscription lapse. Where logs are held by a cloud provider and the subscription ends, access to those logs may end with it unless an export was taken.
There is a related requirement in the same set of rules that belongs in the same conversation. Where a company keeps its books in electronic mode and maintains a back-up, that back-up is to be kept on servers physically located in India on a daily basis. A company reviewing its audit trail position should confirm the back-up position at the same time, since both are tested from the same underlying facts.
06 — VerificationHow Do You Verify the Audit Trail Requirement for Companies Is Actually Met?
Eight steps. Done before the year end, this is a short exercise. Done during fieldwork, it becomes an argument with the auditor at the least convenient moment.
List every system in which books of account are maintained. Not just the accounting package. Any system holding records within the statutory definition of books of account is in scope, including systems that feed the ledger from elsewhere in the business.
Obtain a written confirmation from each software vendor. Ask specifically whether logging is built in, whether it captures modifications and deletions, whether dates are recorded, and whether any user can disable it.
Test whether the feature can be switched off. Have someone with administrator rights attempt to disable it in a test environment. This is the assertion most often assumed rather than verified.
Check the database layer. Establish whether the books can be altered directly at the database, and if so whether those alterations are logged. Where they are not, the gap needs to be closed or documented.
Confirm the feature was on for the whole year. The auditor must report on operation throughout the year, not on the position at year end. Any interruption needs to be identified and explained now.
Verify the retention arrangement. Confirm that logs from earlier years remain retrievable, including for any system the company has since stopped using, and that the daily back-up sits on servers located in India.
Document what you have done. The auditor will ask for the basis on which management concluded that the requirement was met. A short file recording the tests above answers that question in minutes rather than days.
Raise gaps with the auditor early. Where a gap exists and cannot be closed for the year under audit, discussing it in advance produces a considered position. Discovering it at signing produces a modified report.
07 — ConsequencesWhat Are the Consequences of Not Complying?
Failing the audit trail requirement for companies carries three consequences, and they escalate in a way that is the reverse of what most people expect.
- A modified remark in the audit report. The auditor must state the position under Rule 11(g), and where the requirement was not met the report says so. This is the consequence that is certain to occur.
- A public record. Annual accounts are filed with the Registrar and are accessible to anyone who searches the company. The remark travels with the accounts and is seen by lenders, investors, acquirers and counterparties long afterwards.
- Penalty exposure under Section 128. Contravention of the requirements concerning books of account attracts a fine on the managing director, the whole-time director in charge of finance, the CFO, or any other person charged by the Board with compliance, ranging from fifty thousand rupees up to five lakh rupees.
The order matters. The penalty is the consequence people ask about and the least likely to be the one that costs them. The audit remark is the consequence that is effectively automatic, and because it sits on a public filing it is the one that surfaces in diligence years later, when a company is raising, borrowing or being bought. Where a default has already occurred and needs to be regularised, MCA adjudication and the related remedial routes are available, but they are slower and considerably more expensive than putting the control in place in the first year.
Important — Responsibility for this requirement rests with the management and the Board, not with the auditor. The auditor reports on the position; the Board is obliged to establish it. That distinction matters when a remark appears, because the answer to why it happened cannot be that nobody was told. Selecting compliant software, keeping the feature enabled and preserving the logs are management functions, and boards should record that they have considered them.
08 — BackgroundHow Did the Audit Trail Requirement for Companies Come Into Force?
Indian company law has permitted books of account to be kept in electronic form for many years, and the Companies Act, 2013 carried that forward with conditions about accessibility, retention and back-up. What it did not originally do was say anything about whether the software recorded how the books had been changed. A ledger could be maintained electronically and edited without trace, and nothing in the rules addressed that.
The Ministry of Corporate Affairs closed the gap in March 2021, inserting the requirement into the Companies (Accounts) Rules and, on the same day, inserting the corresponding reporting clause into the audit rules. The original commencement was the financial year beginning 1 April 2021. It was then deferred, and deferred again, before finally taking effect from 1 April 2023, which left a period in which the reporting clause and the substantive obligation carried different dates and a good deal of professional commentary was devoted to reconciling them.
That drafting history explains something still visible today. Because the obligation was postponed twice, a number of companies formed a working assumption that it would be postponed indefinitely, and did not act. It was not postponed again. The requirement has now been in force for three completed financial years, guidance for auditors has been issued and revised, and preservation is being tested in current audits. A company that has still not addressed the audit trail requirement for companies is no longer early; it is several years late, with logs it was obliged to keep and may not have.
FAQFrequently Asked Questions
When did the audit trail requirement become applicable to companies?
For financial years commencing on or after 1 April 2023. The provision was inserted into the Companies (Accounts) Rules, 2014 with an original commencement of 1 April 2021, and the Ministry of Corporate Affairs then deferred it twice before it finally took effect. That confusion is now historical: every financial year from 2023-24 onwards is squarely within the requirement.
Does the audit trail requirement apply to a small company or an LLP?
Any company keeping its accounts on a computer is caught, and neither turnover, capital nor class of company buys an exemption. A one person company, a small company, a dormant company, a Section 8 company and a foreign company are all covered on the same terms as a listed entity. LLPs, partnership firms, sole proprietorships, trusts and societies fall outside the rule entirely, because the obligation arises under the Companies Act framework.
Can we maintain an audit trail manually in a spreadsheet?
No. The requirement is for the recording of changes to be a built-in feature of the accounting software itself. A log maintained by hand, kept in a separate spreadsheet, or compiled periodically by a member of staff does not satisfy the rule, however diligently it is kept — it provides no assurance that changes to the books were captured completely.
Does the audit trail have to operate at database level?
This has been the most contested point in practice. Where changes can be made directly at the database without passing through the application, an application-level log alone will not capture them. In the first cycles of reporting, the absence of database-level logging led auditors to modify their remarks in a number of cases.
How long must the audit trail be preserved?
Eight years, matching the period Section 128(5) of the Companies Act, 2013 prescribes for keeping books of account themselves. Changing accounting software, or ending a subscription, does not end the obligation — historical logs must remain retrievable for the full period even after the system that produced them is no longer in use.
What happens if the auditor reports that the audit trail was not maintained?
The remark appears in the auditor's report under the section dealing with other legal and regulatory requirements, and the auditor is required to make it even where nothing is wrong with the financial statements themselves. Because annual accounts are filed with the Registrar and are publicly accessible, the remark becomes part of the company's permanent record.
Need help confirming your audit trail position?
Beyonte Compliances is a company secretarial practice working with private limited companies, LLPs, one person companies and startups across India. We identify every system in which your books of account are maintained, obtain and assess written confirmations from your software vendors, test whether the feature can be disabled, verify retention, and prepare the documentation your auditor will ask for.
Beyonte Compliances — Company Secretary Practice. ROC, MCA & Corporate Governance, India.