Summary: The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 requires every company using accounting software for maintaining its books of account to use software that records an audit trail of each transaction, creates an edit log of every change with the date of change and does not permit the audit-trail feature to be disabled. Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 requires the statutory auditor to report on whether the feature existed, operated throughout the year for relevant transactions, was not tampered with and was preserved as required by law. The article explains the applicable provisions, their effective dates and notification history, including the daily India-based back-up and service-provider disclosure requirements under Rule 3(5) and Rule 3(6). It discusses how audit trails operate in cloud and desktop accounting systems, the evidence auditors should retain, vendor assurance reports, Activity Logs, user roles and migration issues. Three worked examples address migration between accounting systems, post-e-invoice invoice modification and journals created after year-end with earlier transaction dates. The article also sets out an illustrative Rule 11(g) audit-report paragraph, consequences of non-compliance, a practical compliance framework and frequently asked questions concerning Excel ledgers, LLPs, software migration, cloud servers, preservation, master-data changes and audit evidence. The conclusion emphasises that FY 2025-26 compliance depends less on obtaining new software and more on preserving historical logs, controlling migration, maintaining India-based backups, setting transaction locks, reviewing deletion logs and identifying every system in which any part of the books was maintained.
- Introduction
- Key Takeaways at a Glance
- Which Provision Applies
- How the Rule Reached Its Present Form
- The Statutory Text
- Where the Trail Lives in Practice, and What It Actually Records
- Evidencing a Cloud Product: What Goes in the Audit File
- Worked Examples
- Example 1: Migration from a Desktop Package to a Cloud Package During the Year
- Example 2: Invoice Edited After E-Invoicing
- Example 3: Journal Created After Close, Dated Within the Year
- The Auditor's Paragraph
- Consequences of Non-Compliance
- Practical Compliance Framework
- Frequently Asked Questions
- 1. The Company Keeps Its Ledgers in Excel. Is It Caught?
- 2. Does the Rule Apply to an LLP or a Partnership?
- 3. The Company Changed Software During the Year. What Does the Auditor Report?
- 4. How Does an Auditor Conclude That a Cloud Product "Cannot Be Disabled" and "Was Not Tampered With" When the Auditor Cannot See the Vendor's Servers?
- 5. The Books Are on a Foreign Cloud. Is Rule 3(5) Met?
- 6. The Cloud Subscription Was Cancelled Two Years After Migration to Another Product. Is the Old Trail Still "Preserved"?
- 7. Must the Log Capture Changes to Masters, Such as a Customer's Credit Terms or a GL Mapping?
- Conclusion
- Sources & References
Introduction
The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 requires every company that maintains its books of account in accounting software to use only software which records an audit trail of each transaction, creates an edit log of every change made in the books along with the date of the change, and does not allow that feature to be disabled. It applies to financial years commencing on or after 1 April 2023. Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 requires the statutory auditor to report on whether this has actually happened.
Audit reports for FY 2025-26 being signed this month are the third set to carry a Rule 11(g) paragraph. By now the questions from clients have changed. Nobody asks what an audit trail is. They ask whether a mid-year migration from Tally breaks the trail, whether a company that keeps its ledgers in Excel is caught, and what has to be preserved when a cloud subscription lapses. This article takes those questions in turn. Where a product’s behaviour matters, the description is of the cloud and desktop packages most SME companies in our practice use; the tests are the same for any software.
Key Takeaways at a Glance
- The requirement is on the company, not the auditor, and it has three limbs: audit trail of every transaction, edit log with date of change, and no ability to switch it off (proviso to Rule 3(1), Companies (Accounts) Rules, 2014).
- It applies to every company using accounting software. There is no carve-out for small companies, OPCs or Section 8 companies. LLPs and proprietorships are outside this rule, but not outside Rule 56(15) of the CGST Rules, which has required an edit/delete log for electronic records since 1 July 2017.
- The auditor must report on five points under Rule 11(g): software has the feature; it operated throughout the year; for all transactions; it was not tampered with; and it has been preserved as per statutory retention requirements.
- The trail is part of the books, so Section 128(5) requires it to be kept for at least eight financial years. That obligation survives a change of software or cancellation of a subscription.
- Rule 3(5) requires a daily back-up on servers physically located in India and Rule 3(6) requires annual intimation to the Registrar of the service provider’s details when books are kept on a third-party server. The Companies (Accounts) Fourth Amendment Rules, 2022 introduced these changes.
- In current cloud accounting packages the log is a standard report that is on by default, cannot be turned off, records creates, edits and deletions with user and timestamp, and shows old and new values side by side. The compliance risk is rarely the product. It is the period before a migration, the spreadsheet on the side, and the log nobody exported.
Which Provision Applies
| Requirement | Provision | Who is covered | Effective from |
|---|---|---|---|
| Software must record audit trail, keep an edit log, and be non-disableable | Proviso to Rule 3(1), Companies (Accounts) Rules, 2014 | Every company using accounting software¹ | FY commencing on or after 1 April 2023 |
| Auditor to report on audit trail | Rule 11(g), Companies (Audit and Auditors) Rules, 2014 | Statutory auditor of every company | Reporting from FY 2023-24² |
| Daily back-up on servers in India | Rule 3(5), Companies (Accounts) Rules, 2014 | Companies keeping books in electronic mode | 5 August 2022 |
| Annual intimation of service provider and person in control in India | Rule 3(6), Companies (Accounts) Rules, 2014 | Companies whose books are on a third-party or cloud server | With the annual financial statement filing |
| Preserve books, including the trail, for eight years | Section 128(5), Companies Act, 2013 | Every company | Ongoing |
| Log of every entry edited or deleted in electronic records | Rule 56(15), CGST Rules, 2017 | Every registered person, regardless of constitution | 1 July 2017 |
| Electronic books, daily India back-up, seven-year retention | Draft Rule 46(8) and 46(9), Income-tax Rules, 2026, read with Section 62, Income Tax Act, 2025 | Specified professions and businesses above the Section 62 thresholds | Draft only at the time of writing³ |
¹ “Every company” means every company. Small company status, OPC status or Section 8 registration does not exempt the entity. A company that maintains books manually, or only in spreadsheets with no accounting software, is discussed at FAQ 1.
² Rule 11(g) as inserted referred to financial years commencing on or after 1 April 2022, while the Accounts Rules requirement was deferred to 1 April 2023. ICAI’s Implementation Guide aligns the reporting with the Accounts Rules date, so the first reporting year was FY 2023-24.
³ CBDT released the draft Income-tax Rules, 2026 on 7 February 2026. Confirm the final notification before relying on the rule number or the retention period.
How the Rule Reached Its Present Form
The provision was inserted, deferred twice and then supplemented with the back-up rule. The sequence matters when a client asks why their software vendor “said it was postponed”.
| Notification | Date | What it did |
|---|---|---|
| G.S.R. 205(E) | 24 March 2021 | Inserted the proviso to Rule 3(1); applicable from FY commencing 1 April 2021 |
| G.S.R. 206(E) | 24 March 2021 | Inserted Rule 11(g) in the Companies (Audit and Auditors) Rules |
| G.S.R. 247(E) | 1 April 2021 | Deferred the Rule 3(1) proviso to 1 April 2022 |
| G.S.R. 248(E) | 1 April 2021 | Deferred Rule 11(g) reporting to FY commencing 1 April 2022 |
| G.S.R. 235(E) | 31 March 2022 | Deferred the Rule 3(1) proviso to 1 April 2023 |
| G.S.R. 624(E) | 5 August 2022 | Inserted the daily India back-up requirement in Rule 3(5) and the “person in control in India” disclosure in Rule 3(6) |
The Statutory Text
The proviso to Rule 3(1) reads:
“Provided that for the financial year commencing on or after the 1st day of April, 2023, every company which uses accounting software for maintaining its books of account, shall use only such accounting software which has a feature of recording audit trail of each and every transaction, creating an edit log of each change made in books of account along with the date when such changes were made and ensuring that the audit trail cannot be disabled.”
Three limbs, and all three must be satisfied. Software that logs edits but allows an administrator to pause logging fails the third limb. Software that logs only deletions and not modifications fails the second. The rule does not define “accounting software”, and it does not say the audit trail must record the user who made the change. In practice every auditor asks for the user, and every reasonable product records it, but the statutory minimum is the date.
Rule 11(g) turns this into a reporting obligation. The auditor’s report must state whether the company has used accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility, whether the same has been operated throughout the year for all transactions recorded in the software, whether the audit trail feature has been tampered with, and whether the audit trail has been preserved by the company as per the statutory requirements for record retention.
The last limb is the one that gets less attention than it deserves. “Preserved as per statutory requirements” ties back to Section 128(5), which requires the books of account relating to at least eight preceding financial years to be kept in good order, together with the vouchers. ICAI’s position, and ours, is that the audit trail forms part of the books and therefore carries the same eight-year retention. A company that switched from one product to another in 2024 and let the old subscription lapse without exporting the log has a preservation problem it may not discover until an inquiry under Chapter XIV.
Where the Trail Lives in Practice, and What It Actually Records
Clients often assume the auditor wants a document called “audit trail”. What the auditor wants is the log, filtered sensibly, and the ability to reproduce that filter during the audit.
In the cloud packages the log is a standard report under the Reports menu. Zoho Books is the one we see most often and the description that follows is of that product; the others behave similarly. It is available on every plan including the free one, it is switched on from the day the organisation is created, and there is no setting anywhere in the product to switch it off. That disposes of the third limb of Rule 3(1) without further inquiry. Desktop packages are different. The edit-log feature exists only in particular releases, and on some of them it has to be enabled, which is why an old release left running is the most common way a company fails the rule without knowing it.
The report can be filtered by:
- Date range
- Activity related to a module (Invoices, Bills, Journals, Chart of Accounts, Bank Feeds, Reconciliation and so on)
- Customer or vendor name, for sales and purchase activity
- User
- Action: All, Create, Update or Delete
- PII fields only, for changes to personally identifiable information
Each line carries the timestamp, the module and record affected, the action and the user who performed it. For any record that has been edited more than once, the audit trail view shows every version and lets you compare two of them. Changed values are highlighted in yellow, removed data in pink and added data in green. Deletions are logged as deletions; the record disappears from the ledger but not from the trail. The report can be exported and printed from the top-right of the screen.
Two things the log does not do, and which the auditor has to cover elsewhere. It does not by itself prove that the person logged in as “accounts@” was the accounts executive and not the director using her credentials; that is a user-access control question, and the answer lies in the roles and permissions set-up and, for larger clients, in login history. And it does not stop anyone from doing anything. If a user has permission to delete a bill, the bill will be deleted and the log will record it. Prevention is a matter of role design and transaction locking, both of which sit under Settings, not under Reports.
Evidencing a Cloud Product: What Goes in the Audit File
For software installed on the client’s own server, the auditor can look at the configuration. For a cloud product the auditor cannot inspect the vendor’s database, and ICAI’s Implementation Guide (revised 2024 edition) accepts that the auditor may consider the service organisation reporting framework, that is SA 402 and the vendor’s SOC or SAE 3402 reports, in forming a view.
Our working-paper set for a cloud-accounting client in FY 2025-26 has looked like this:
1. Screenshot of the organisation’s creation date and current plan, to establish the software was in use from the start of the year (or the migration date, see Example 1).
2. The vendor’s published SOC 2 Type II and ISO 27001 documentation for the period, filed as service-organisation evidence for the “cannot be disabled” and “not tampered with” limbs.
3. The Activity Logs report run for the full financial year with Action = All, exported, with the row count noted.
4. The same report filtered to Action = Delete, reviewed line by line for transactions dated within the year. This is short for most SMEs and it is where the interesting findings are.
5. The report filtered to Date range = after year-end, Action = Create, then checked for any transaction dated inside the audited year (see Example 3).
6. A sample of ten to fifteen edited transactions traced through the version comparison, with the reason for each edit obtained from the client.
7. Users and Roles print-out, with a note on who can delete and who can change transaction dates.
8. Management representation on the software used, the period used, and confirmation that no other accounting software or spreadsheets were used to maintain any part of the books.
That last representation is worth a specific sentence in the letter. The most common failure we have seen is not a product without a trail. It is a company running two systems, one with a trail and one without.
Worked Examples
Example 1: Migration from a Desktop Package to a Cloud Package During the Year
ABC Trading Private Limited kept its books in a desktop package through 30 September 2025 and moved to a cloud package on 1 October 2025. Closing balances as at 30 September were imported as opening balances. The new system’s activity log therefore begins on 1 October 2025; every imported balance carries an October creation stamp. It cannot evidence anything about April to September. The auditor has to look at the old system’s edit log for the first six months. If the release in use had the edit log feature and it was active, the auditor can report without modification, naming both products. If the release did not have the feature, or the feature was not enabled, the report has to say so for that period. The old system’s data and its edit log must be preserved for eight years in a form the company can still open; a backup file with no licensed copy of the software to read it is not, in our view, “preserved”.
Example 2: Invoice Edited After E-Invoicing
On 14 November 2025 the company raises INV-0231 for Rs. 4,72,000 and generates the IRN. On 2 December 2025 the accounts executive edits the invoice to reduce the quantity, and the value falls to Rs. 4,13,000. The audit trail shows both versions, the user, the timestamp and the changed lines. The IRN cannot be amended, so the books now disagree with the e-invoice portal by Rs. 59,000. The correct route was a credit note. This is a finding about the company’s controls, not about its compliance with Rule 3(1); the trail did exactly what the rule requires, which is to make the edit visible. The auditor’s response is to extend testing on post-IRN edits and to recommend that invoice editing after IRN generation be removed from the executive’s role.
Example 3: Journal Created After Close, Dated Within the Year
The company closed FY 2025-26 on 15 April 2026. On 28 June 2026 a journal dated 31 March 2026 is created for a provision of Rs. 8,50,000. The transaction date says March; the log says June. Run the activity report for 16 April 2026 onwards, Action = Create, and scan for any transaction dated on or before 31 March 2026. Each one needs an explanation and, usually, a look at whether the draft financial statements given to the board in May already reflected it. Every current package has a transaction-locking or period-close setting that prevents exactly this; we set the lock date on the day the trial balance is handed to the auditor, and record that date in the working papers.
The Auditor’s Paragraph
Where all five limbs are satisfied, the paragraph under “Report on Other Legal and Regulatory Requirements” reads along these lines:
Based on our examination, which included test checks, the Company has used accounting software for maintaining its books of account which has a feature of recording audit trail (edit log) facility and the same has operated throughout the year for all relevant transactions recorded in the software. Further, during the course of our audit we did not come across any instance of the audit trail feature being tampered with. Additionally, the audit trail has been preserved by the Company as per the statutory requirements for record retention.
For Example 1 with a non-compliant release in the first half, the paragraph has to be modified to name both products and state the period for which the feature was not available or not enabled. Do not soften it into “substantially throughout the year”. The rule says “throughout the year”, and the reader of the report is entitled to know which months are not covered.
Consequences of Non-Compliance
Section 128(6) places the liability on the managing director, the whole-time director in charge of finance, the Chief Financial Officer, or any other person charged by the Board with compliance, and prescribes a fine of not less than Rs. 50,000 which may extend to Rs. 5,00,000. The auditor’s exposure is separate: an unqualified Rule 11(g) paragraph over books that had no trail for part of the year is a deficient audit report, with the usual consequences under Section 147 and, for listed and other NFRA-covered entities, under the NFRA Rules.
The larger practical consequence is evidentiary. In an assessment or an investigation, a company that cannot produce a log of who changed what and when is a company whose books are easier to disbelieve.
Practical Compliance Framework
1. Identify every place the books are kept. Accounting software, payroll software that posts to the ledger, inventory software, and any spreadsheet that holds a ledger rather than a working. Each one is either inside the rule or has to be justified as outside it.
2. Confirm the trail is on for the whole year, in every system, for every user. This is the point most often missed. The rule is satisfied by the software in use on every day of the year, not by the software in use on 31 March. A migration date is a compliance boundary.
3. Restrict, then log. Set roles so that deletion and back-dating are limited to one or two people, and set the transaction lock date at every close. The log then becomes short enough to actually read.
4. File the vendor’s assurance reports each year. For a cloud product, the current SOC 2 Type II and ISO 27001 documents. Their coverage period should span the financial year.
5. Meet Rule 3(5) and 3(6). Confirm with the vendor where the data is hosted (the larger vendors now host Indian organisations in Indian data centres, which addresses the location question) and take and document a periodic full export as the company’s own back-up. Disclose the service provider and the person in control of the books in India in the annual filing.
6. Plan the eight-year preservation before changing software. Export the complete activity log and the full data set on the last day of use, in a readable format, and record where it is kept. If the old product needs a licence to open its files, keep one.
Frequently Asked Questions
1. The Company Keeps Its Ledgers in Excel. Is It Caught?
The rule applies to a company “which uses accounting software for maintaining its books of account”. A spreadsheet in which the ledger is actually maintained is, in substance, the accounting software, and it has no audit trail. ICAI’s guide treats this as a case for modified reporting rather than as an exemption. The practical advice is to move the books into a product that logs, and to report honestly on the period before the move.
2. Does the Rule Apply to an LLP or a Partnership?
Not under the Companies (Accounts) Rules. But every GST-registered person, of any constitution, has been required since 1 July 2017 under Rule 56(15) of the CGST Rules to maintain a log of every entry edited or deleted in electronically kept records. The draft Income-tax Rules, 2026 extend a similar electronic-records regime to persons covered by Section 62 of the Income Tax Act, 2025. The direction is clear even where the company law rule does not yet bite.
3. The Company Changed Software During the Year. What Does the Auditor Report?
Both products, with the period each was used, and a separate conclusion on each of the five limbs for each product. See Example 1. The migration date is disclosed, not hidden inside a single sentence.
4. How Does an Auditor Conclude That a Cloud Product “Cannot Be Disabled” and “Was Not Tampered With” When the Auditor Cannot See the Vendor’s Servers?
Through the product’s own behaviour (there is no off switch to find), the vendor’s service-organisation reports under SA 402, and the auditor’s own testing of the log against known transactions. The absence of a setting is itself evidence; the SOC report speaks to the vendor’s controls over the log; the test of details speaks to whether the log is complete for this organisation.
5. The Books Are on a Foreign Cloud. Is Rule 3(5) Met?
Rule 3(5) requires the back-up to be kept on servers physically located in India on a daily basis, whether or not the primary data is in India. A vendor whose primary servers are outside India needs to give the company a daily India-located back-up, or the company has to take one. Where the vendor hosts Indian organisations in India, the location question is answered, but we still recommend a documented periodic export in the company’s own custody.
6. The Cloud Subscription Was Cancelled Two Years After Migration to Another Product. Is the Old Trail Still “Preserved”?
Only if it was exported before cancellation. Section 128(5) requires eight years. A subscription that has lapsed and a log that was never exported is a preservation failure that will surface in the Rule 11(g) paragraph of the year it is discovered.
7. Must the Log Capture Changes to Masters, Such as a Customer’s Credit Terms or a GL Mapping?
The rule speaks of “each change made in books of account”. A change to a master that alters how transactions are recorded or classified is, in our reading, a change in the books, and the conservative course is to ensure it is logged. The cloud packages log changes to contacts, items, the chart of accounts and settings in the same activity report, so the question rarely needs to be argued for them. For software that logs only transactions, raise it with the client before the audit rather than in the report.
Conclusion
Three financial years of Rule 11(g) reporting (FY 2023-24, FY 2024-25 and FY 2025-26) have settled most of the early arguments. The software question is largely answered: any current cloud product, and any current release of the mainstream desktop products, records a trail that cannot be switched off. What remains unsettled in practice is everything around the software. Whether the trail existed for the whole year and not just on the day of the audit. Whether the log from the product that was abandoned in a migration is still readable, and will be in 2032. Whether the company has a daily India-located back-up it can point to, and has told the Registrar who controls the books. Whether anyone has actually read the deletion log.
Those are the points on which reports for FY 2025-26 will be modified, and on which directors will be asked questions under Section 128(6). None of them need a new product. They need a migration checklist that treats the old system’s log as a record to be preserved, a lock date that is set and recorded at every close, a deletion review that is part of the audit programme rather than an afterthought, and a management representation that names every system in which any part of the books was kept. For a company on any current cloud package the log itself takes ten minutes to run. Reading it, and acting on what it shows, is the part that still requires a chartered accountant.
Sources & References
| # | Reference |
|---|---|
| 1 | Companies (Accounts) Rules, 2014, Rule 3, as amended |
| 2 | Companies (Audit and Auditors) Rules, 2014, Rule 11(g) |
| 3 | Notifications G.S.R. 205(E) and 206(E) of 24 March 2021; G.S.R. 247(E) and 248(E) of 1 April 2021; G.S.R. 235(E) of 31 March 2022; G.S.R. 624(E) of 5 August 2022 |
| 4 | Companies Act, 2013, Section 128 |
| 5 | ICAI, Implementation Guide on Reporting on Audit Trail under Rule 11(g) (Revised 2024 Edition) |
| 6 | CGST Rules, 2017, Rule 56(15); CGST Act, 2017, Section 36 |
| 7 | Income Tax Act, 2025, Section 62; draft Income-tax Rules, 2026, Rule 46 |
*****
Disclaimer: This article is for general information and does not constitute professional advice. Statutory provisions, notification numbers and product features are stated as understood at the date of writing and may change; the draft Income-tax Rules, 2026 in particular should be checked against the final notification. Readers should verify the current position before acting.
About the Author: CA Karan Shah is the founder of KC Shah & Associates, a Mumbai-based chartered accountancy firm working with startups and SMEs on outsourced accounting, GST and MSME compliance, business valuation and Virtual CFO advisory. The firm implements cloud accounting for companies moving off desktop packages, and audits companies that have already made the move.






