Audit Trail: Practical Approach for Effective Implementation of Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014

Digitalization has taken over the traditional physical system of bookkeeping in electronic form. Most organizations use some or other software to process their accounting information for statutory compliance and internal business decisions. Accounting software offers better organization of data, lower operating costs, fewer human errors, enhanced security, better accessibility, and high processing speed, but at the same time, it offers room for manipulation of data. MCA issued the Companies (Audit and Auditors) Amendment Rules, 2021 on March 24, 2021, which introduced new Rule 11(g) in the Companies (Audit and Auditors) Rules, 2014. Rule 11(g) deals with reporting on the use of accounting software by companies for maintaining their books of account which have the feature of recording audit trail (Edit Log). This casts additional responsibility on the auditors of companies to report compliance with Rule 11(g). This article attempts to describe the management\'s responsibility and the auditor\'s responsibility separately, the need to acquire relevant IT skills by auditors and a practical approach for effective implementation of the audit trail in compliance with Rule 11(g).

By Vitin Kumar, Research Scholar
By Prof. (Dr.) V.K. Singh, Academician

With advancements in computer science and information technology, and global digitalization drive, financial and non-financial information has moved from physical (paper) form to electronic form. Business entities and regulatory bodies are moving towards a digital environment and experiencing technological intervention in accounting and other business information in various ways. Starting from journal entries to final financial statements, the process is either fully automated or semi-processed. Data is further engineered through accounting software by accounting professionals in MS-Excel or other utilities in line with the provision of various statutory and internal business requirements.

Auditing work has changed much in the digital environment and besides critical investigation of various books of account and other relevant records, auditors must be abreast with technical aspects of data manipulation in the IT environment.

Although, auditors exercise rigorous audit procedures, including computer-assisted audit techniques, in line with applicable standards on auditing and other relevant guidelines with a higher degree of automation in accounting. However, there is always a chance that intentionally or unintentionally records have been manipulated. Unusual/malafide alteration of records is fatal to the whole auditing process and it is therefore necessary that the auditor should be in a position to trace the elements of data manipulation to comply with the requirement of the audit trail in a true sense.

On March 24, 2021, the Ministry of Corporate Affairs (MCA) introduced new Rules 11(e), 11(f) and 11(g) in the Companies (Audit and Auditors) Rules, 2014 by the Companies (Audit and Auditors) Amendment Rules, 2021. Rule 11(g) casts responsibility on auditors to report on the use of accounting software by companies for maintaining their books of account which has a feature of recording audit trail.

Audit Trail

Audit Trail (or Edit Log) is a visible trail of evidence enabling one to trace information contained in statements or reports back to the original input source. Audit trails are a chronological record of the changes that have been made to the data like creating new data, updating or deleting data. Records maintained as audit trail may include the following information: when changes were made i.e., date and time (timestamp); who made the change i.e., User Id; what data was changed i.e., data/transaction reference; success/failure.

Coverage of Rule 11(g)

Initially, auditors were required to report on companies\' use of accounting software for maintaining books of account, effective from April 1, 2021. However, owing to technical and other reasons, this requirement was deferred twice, and it was made mandatory from April 1, 2023. This requirement is now applicable prospectively and not retrospectively. It is clear that the auditor is required to assess the appropriateness of the audit trail for prospective financial years only.

Management\'s Responsibility

If a company is using any existing software for maintenance of books of account, which is not having feature of audit trail then necessary modification needs to be made in the software to provide feature of recording audit trail of each and every transaction, creating an edit log of each change made in the books of account along with identity of personnel who made changes, time and date when such changes were made and ensuring that the audit trail cannot be disabled.

  • Identification of software(s) covered under Rule 11(g).
  • Ensuring the functionality of the audit trail feature is appropriately enabled in software used for the maintenance of books of account.
  • Ensuring that the audit trail cannot be disabled.
  • Recording the audit trail for each and every transaction.
  • Edit log (audit trail) of each change made in the books of account along with the timestamp.
  • Capturing identity of person(s) who made such changes.

Auditor\'s Responsibility

Under obligation cast by Rule 11(g), the auditor needs to comment on whether the company is using an accounting software which has a feature of recording audit trails, whether the audit trail feature can be disabled or tampered with, whether it was disabled/tempered during the reported period, whether all transactions recorded in the software covered in the audit trail feature, and whether the audit trail has been preserved by the company as per statutory requirements for record retention (minimum eight years as per section 128(5) of Companies Act 2013).

Practical Approach

As Auditor needs to gather evidence from the IT environment, it is important for them to have an insight of the IT environment. Auditor may involve IT experts/specialists to assist him in the evaluation of management controls and configurations involved in the accounting software with regard to the audit trail. Auditors should obtain written representations in line with SA 580, test the working of audit trail functionalities by altering a record for test purposes and restoring the same on a sample basis, and collaborate with IT specialists. Readers may also refer to the \'Implementation Guide on Reporting on Audit Trail under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 (Revised 2024 Edition)\' issued by the Auditing and Assurance Standards Board of ICAI.

References:
  • Oracle Documentation (https://docs.oracle.com/en/)
  • MCA Amendment Rules 2021 (https://www.mca.gov.in/Ministry/pdf/AuditAuditorsAmendmentRules_24032021.pdf)
  • Implementation Guide on Reporting on Audit Trail under Rule 11(g) (Revised 2024 Edition) (https://resource.cdn.icai.org/78922aasb63149.pdf)
Authors may be reached at vitinktyagi@gmail.com and eboard@icai.in