Audit Trail - Requirements & Responsibilities
"Audit Trail/Edit log" is the new buzzword that draws the attention of the management from a compliance perspective and of the auditors from reporting perspectives. These requirements emanate from the rules issued by the Ministry of Corporate Affairs under the Companies Act, 2013. This article is an attempt to break down the legal requirements and responsibilities from the perspective of management and the auditor.
Audit Trail
It is a chronological record of the changes that have been made to the data that captures any change to a record, including:
- who made the change
- when it was made
- what fields were changed
Simply, any change to data, including creating new data, updating, or deleting data, must be recorded.
Management Perspective
Statutory Requirement
Proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 requires that for the financial year commencing on or after the 1st day of April 2023, every company that uses an accounting software for maintaining its books of account, shall use only such accounting software which has a feature of:
- recording an audit trail of each and every transaction,
- creating an edit log of each change made in the books of account, along with the date when such changes were made, and
- ensuring that the audit trail cannot be disabled.
Applicability
From the above, it is clear that every company (OPC/Section 8/Private/Public/foreign company) that uses an accounting software shall use such accounting software that has the capabilities to comply with the requirements of Rule 3 of the Companies (Accounts) Rules, 2014.
The said rule is applicable only in case of accounting data maintained with the aid of an accounting software, i.e., working records that are maintained electronically but not through an accounting software do not require the audit trail. For example, fixed asset register, paysheets, calculations maintained in excel without the aid of any accounting software will not be under the purview of Rule 3(1) of Companies (Accounts) Rule, 2014. However, the entries passed in the accounting software, which are resultant of the above excel workings, will be under the purview.
The audit trail functionality is only applicable for the books of accounts as defined in Section 2(13) of the Act. Therefore, the maintenance of an audit trail is not applicable to the "books and papers" and "books or papers" as defined in Section 2(12) of the Act, which includes deeds, writings, documents, minutes, and registers maintained on paper or in electronic form.
Audit trail functionality is required even in cases where the accounting software does not allow the users to make any modifications subsequent to the entry posting.
Management's Responsibility
The responsibility of the management includes:
Determining the Books of Accounts
All the books of accounts that are maintained in an accounting software require the maintenance of an audit trail. Hence, it is of utmost importance to determine the books of accounts that the company intends to maintain/ maintain in the accounting software. The records maintained manually do not require the maintenance of an audit trail even though they are maintained electronically in excel. Only the changes made to books of accounts requires audit trail in accordance with the proviso to Rule 3(1) and not all the changes in the accounting software. For instance, creation/deletion of a user to the accounting software or changes to ESG data are the changes made to the accounting software and not to the books of accounts.
Section 2(13) defines the books of accounts as records maintained in respect of (i) all sums of money received and expended by a company and matters in relation to which the receipts and expenditure take place; (ii) all sales and purchases of goods and services by the company; (iii) the assets and liabilities of the company; and (iv) the items of cost as may be prescribed under Section 148 in the case of a company which belongs to any class of companies specified under that section.
Selection of Accounting Software
The management should maintain its accounting records in an accounting software that is empowered to provide the entity with an audit trail feature for all transactions made in the books of accounts. This feature should be capable enough to maintain a record of 1. change made (i.e., creation, modification, or deletion of a record), 2. when the change is made (i.e., time stamp of the change), 3. who made the change (i.e., user ID), 4. what data was changed (i.e., the transaction reference).
The selected software, having the feature of an audit trail, should also be able to generate a report of the said trail when required.
The requirement of an audit trail is applicable irrespective of the fact that the accounting software is maintained by an in-house team of accounts or outsourced to a third-party service provider. Hence, it is the responsibility of the management to evaluate whether the third-party service provider maintains the company's records on a platform that is capable of capturing an audit trail as required.
Retention
An Audit Trail will form part of the books of accounts required to be maintained in accordance with Section 128 of the Companies Act, 2013 and hence it has to be retained for a period of not less than eight financial years, immediately preceding a financial year or such higher period as may be prescribed by the central government in case of investigation under Chapter XIV of the Act.
Non-Compliance
According to Section 128(6), non-compliance may lead to a fine which shall not be less than fifty thousand rupees, but which may extend to five lakh rupees.
Challenges
Challenges majorly include:
- Cost of storage as such a huge record of data repository can be built only with enlarged storage capacities.
- Time invested in structuring the audit trail reports and run time efficiencies in a real environment may take a hit due to backend tracking of all changes.
- Effective and efficient controls need to be designed, implemented and maintained in order to comply with the new regulations.
- Daily backup will be an additional burden in view of the new audit trail requirement.
Auditor Perspective
Statutory Requirement
Section 143(3)(j) of the Companies Act, 2013, read with Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 requires the audit reports issued for the financial year commencing on or after April 01, 2022, and shall include views or comments of the auditor on whether:
- the accounting software for maintaining its books of account, which has a feature of recording audit trail (edit log) facility, and
- the same has been operated throughout the year
- for all transactions recorded in the software, and
- the audit trail feature has not been tampered with and
- it has been preserved as per the statutory requirements for record retention.
However, proviso to Rule 3(1) of Companies (Accounts) Rules, 2014 requires the maintenance of an Accounting Software which commences from April 01, 2023, creating an impediment for the auditor's ability to report on the said software from the financial year commencing on or after April 01, 2022. Hence, the reporting requirement under Rule 11(g) stands deferred to the financial year commencing on or after April 01, 2023.
Applicability
Section 143(3)(j) of the Companies Act, 2013 read with Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 is applicable for the audit of all class of companies that maintains the Books of Accounts as specified in Section 128 of the Companies Act, 2013 with the aid of an Accounting Software for the financial year commencing on or after April 01, 2023.
As the Section 129 extends the requirement of the Act to both standalone and consolidated financial statements on a par basis, the reporting on an audit trail is also mutatis mutandis applicable to both standalone and consolidated financial statements. However, the said reporting is not applicable for the components if the components included in the consolidated financials are an entity incorporated under statutes other than the Companies Act, 2013 (such as firm, LLP, etc.,) or those entities incorporated in a jurisdiction outside India where there is no similar accounting/reporting obligation cast. In such cases, the auditor of the parent company in his report on consolidated financial statements needs to report such fact of non-applicability on such components included.
The reporting under this Rule is only applicable in case of audit reports issued in accordance with the Companies Act, 2013 where the "Report on other legal and regulatory" is included. Hence, it is not applicable for audit reports or limited review reports issued in accordance with SEBI Regulations or other special-purpose reports issued in accordance with other statutes.
Audit Procedures
Understand
Auditors need to:
- understand the books of accounts maintained and management's assessment of those books of accounts that are maintained in an accounting software from those that are maintained manually, accounting software used by the Company, whether the accounting function has been maintained internally or outsourced to a third-party service provider,
- identify the risks and controls implemented by the management,
- assess the risks identified and plan appropriate responses in order to address the audit risk through control and substantive testing.
Risks may include, but are not limited to:
- Risk of audit trail may be disabled on a need basis.
- Unauthorized access to the audit trail report.
- Changes to audit trail functionality/configuration is not authorized/ log of those changes is not maintained.
- The audit trail may not cover the total period under consideration/ all transactions in the books of accounts.
- Audit trail may not be retained for the period as stated in Section 128 of the Companies Act, 2013.
- Changes may be made at data base level without the aid of the accounting application and the trail present may not capture the same.
- Other accounting software-specific risks.
Use of Experts
It may be appropriate for the auditors to seek expert support considering the complexity of the accounting software. Auditor may involve the experts in the field of information technology to assist in obtaining a reasonable assurance about:
- the use by the management of an appropriate accounting software that is aided with an audit trail feature,
- audit trail has been operative throughout the year under consideration for audit for all transactions in the books of accounts at the application and database level,
- the trail is not compromised/tampered/disabled, and
- the audit trail has been retained.
Auditors need to carefully consider and determine the nature of the experts used. If the experts are specialized in the field of auditing, they will be covered under the definition of audit team and accordingly apply the requirements of SA 220 - Quality Control for an Audit of Financial Statements, and if the experts are specialized in the fields other than auditing i.e., only in information technology, they will be covered under the definition of auditors expert and accordingly apply the requirements of SA 620 - Using the Work of Auditors Expert.
The auditor has the sole responsibility for the audit opinion expressed, and that responsibility is not reduced by the auditor's use of the work of an auditor's expert; hence, he is responsible for concluding that the work of that expert is adequate for his purposes, and he may accept that expert's findings or conclusions in the expert's field as appropriate audit evidence.
Materiality
As the requirement of maintaining an audit trail is applicable for each and every transaction made in the books of account throughout the year, the materiality threshold is not applicable for evaluation, as it is a factual reporting.
Controls & Substantive Testing Plans
Based on the understanding of accounting software, risk, and control environment, auditors need to develop a plan to test the compliance by combining control and substantive procedures. The list provided includes some of the possible testing methods:
- Evaluate the controls implemented by the management to prevent unauthorised access, modifications to the audit trail, and those controls to ensure the audit trail captures all modifications to all transactions throughout the year.
- Inquiry with the system administrator about the customizations made to audit trail configurations where ERPs are customized in accordance with business requirements.
- Test and check the transactions for evidence of operating effectiveness of the audit trail feature throughout the year under consideration for audit for all modifications to the books of accounts.
- Check the configuration settings to identify whether the audit trail feature can be turned off/disabled at any time. In such scenarios, obtain the edit log of configuration settings to check the instances.
- Test the audit trail in the test environment by editing and deleting some sample transactions rather than making edits on the main/real environments.
- Verify the edit logs of the databases to ensure no direct modifications are made on the raw data.
Auditors may use the results of the above procedures as corroborative audit evidence to confirm some other findings and may also use the above results to perform substantive analytics, which may reveal any structured misstatements/anomalies that may reduce the auditor's detection risk.
Service Organisation
In case where the accounting function has been outsourced to a third-party service provider who maintains the books of accounts of the entity using its own accounting software, the audit trail requirements extend to the third party's accounting software as well. In such scenarios, auditor may consider using independent auditor's report on service organisation (For Example, SOC 1/ SOC 2/SAE 3402) for compliance with audit trail requirement, and accordingly comply with SA 402 "Audit Considerations Relating to an Entity Using a Service Organization" or SAE 3402, "Assurance Reports on Controls at a Service Organization".
| Accounting Software | Records maintained | Maintained Inhouse or Outsourced | Independent auditor's report (in case outsourced) | Hosting location | Data base | Operating system | Audit trail Enabled | Retention of Audit trail available for previous periods | |
|---|---|---|---|---|---|---|---|---|---|
| Application | Database | ||||||||
Documentation
Auditor documentation should include the understanding obtained, procedures performed, conclusions reached, details w.r.t consultation or expert involvement, SOC-2/SAE 3402 reports on controls at a service organization, and other considerations of SA 402 (if applicable), and a written representation obtained from the management.
In addition to the above, an auditor may also resort to the illustrative table provided above for documentation of audit evidence w.r.t the audit trail and its retention.
Reporting
The auditors' views or comments w.r.t the audit trail need to be reported under the "Report on other legal and regulatory requirements" section of the audit report issued in accordance with SA 700 (Revised), "Forming an Opinion and Reporting on Financial Statements" or SA 705 (Revised), "Modifications to the Opinion in the Independent Auditor's Report".
In case of any modification in the reporting as per the requirement of Rule 11(g), the auditor needs to check the said implications on the reporting of the following, as the requirement of maintaining an audit trail falls under the ambit of Section 128, which deals with "Books of Accounts to be kept by the Company".
- Section 143(3)(b) of the Act, requires the auditor to report on - whether, in his opinion, proper books of account as required by law have been kept by the company so far as appears from his examination of those books and proper returns adequate for the purposes of his audit have been received from branches not visited by him.
- Section 143(3)(h) of the Act requires the auditor to report on any qualification, reservation, or adverse remark relating to the maintenance of accounts and other matters connected therewith.
In case of modification to Rule 11(g) on account of lapse of internal controls (design deficiencies or operation inefficiencies), the auditor needs to consider the said impact on the Report on the Internal Financial Controls with reference to the Financial Statements issued in accordance with Section 143(3)(i).
For modifications in specific scenarios, auditors may recourse to para 30 and 31 of the Implementation Guide on Reporting on Audit Trail issued by the Institute.
Conclusion
The new requirements do not prevent the management from deleting or modifying any books of accounts, whereas it requires the management to have a log of all details of subsequent modifications/deletions, which enables the management, auditor or other regulators to identify any structured/unstructured anomalies that may lead to the identification of material misstatements or other irregularities/contraventions.