Audit Trail and Log Review for IS Auditors
Who changed what, and when. Since April 2023 the edit log is the law, not just good practice.
An audit trail is a chronological record that lets you trace a figure in a report back to the transaction that created it, and see every change made along the way: who, what and when. Logs are the raw material: application logs, database logs, operating system and network device logs. Together they are the main detective control in any IT environment.
For Indian auditors this stopped being a best-practice topic in 2023. Companies must now use accounting software with a non-disableable edit log, statutory auditors must report on it, and CERT-In requires organisations to keep logs of their ICT systems. An IS auditor has to know both the legal floor and how to test whether a log can actually be trusted.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Indian Rules on Audit Trails and Logs
Proviso to Rule 3(1), Companies (Accounts) Rules, 2014
Who it binds
Every company using accounting software, for financial years from 1 April 2023
What it requires
Software that records an audit trail of every transaction, an edit log of each change with the date, and an audit trail that cannot be disabled
Rule 11(g), Companies (Audit and Auditors) Rules, 2014
Who it binds
The statutory auditor
What it requires
Report whether the software had the feature, whether it operated throughout the year for all transactions, was not tampered with, and was preserved as required
Section 128(5), Companies Act, 2013 (as applied by ICAI's guide)
Who it binds
The company
What it requires
Books of account kept for at least eight years, so the audit trail is retained for eight years from 1 April 2023 onwards
CERT-In Directions, 28 April 2022
Who it binds
Service providers, intermediaries, data centres, body corporates and government organisations
What it requires
Enable logs of all ICT systems and keep them securely for a rolling 180 days within India; synchronise clocks with NIC or NPL time servers or sources traceable to them
| Rule | Who it binds | What it requires |
|---|---|---|
| Proviso to Rule 3(1), Companies (Accounts) Rules, 2014 | Every company using accounting software, for financial years from 1 April 2023 | Software that records an audit trail of every transaction, an edit log of each change with the date, and an audit trail that cannot be disabled |
| Rule 11(g), Companies (Audit and Auditors) Rules, 2014 | The statutory auditor | Report whether the software had the feature, whether it operated throughout the year for all transactions, was not tampered with, and was preserved as required |
| Section 128(5), Companies Act, 2013 (as applied by ICAI's guide) | The company | Books of account kept for at least eight years, so the audit trail is retained for eight years from 1 April 2023 onwards |
| CERT-In Directions, 28 April 2022 | Service providers, intermediaries, data centres, body corporates and government organisations | Enable logs of all ICT systems and keep them securely for a rolling 180 days within India; synchronise clocks with NIC or NPL time servers or sources traceable to them |
What a Usable Log Records
ICAI's guide lists the minimum; a log missing any of these cannot answer the auditor's question.
- When
- Date and time stamp, from a synchronised clock. Without time sync, logs from the ERP and the database cannot be lined up.
- Who
- A unique user ID. Shared or generic IDs make the trail useless for accountability.
- What
- The data or transaction changed, ideally old and new values, and whether the action succeeded or failed.
- Where
- Application level, database level, or both. ICAI's guide expects database-level logging where needed, to catch direct changes that bypass the application.
How an IS Auditor Reviews Logs
- 1
Map the population
List every system that holds books of account or critical data, including interfaces and databases, not only the main ERP.
- 2
Confirm logging was on all period
Check the configuration and look for gaps in the log sequence or dates that suggest it was switched off.
- 3
Test protection
Who can alter or delete logs, or change the logging setting? Administrators who can do both are a gap. Access to the logs themselves should be restricted and logged.
- 4
Analyse for exceptions
With a CAAT, look for back-dated entries, changes after period close, edits by privileged IDs, activity outside working hours, and failed log-in bursts.
- 5
Check retention and backups
Confirm logs are backed up and kept for the statutory period, and that a restore actually works.
Quick practice on audit concepts. No signup.
A Log Nobody Reviews Is Only Half a Control
Logging is detective only if someone looks. In a bank's core banking system, a daily review of parameter changes by someone independent of the person who made them is what turns the log into a control. When testing, ask for evidence of review, not just evidence that logs exist.
How the DISA Assessment Test Tests This
- check_circleControl classification: audit trails are detective. A question offering "preventive" is a trap.
- check_circleTool matching: ICAI's own Module 1 question asks which tool is most useful when an audit trail is required; the answer is the snapshot technique.
- check_circleShared IDs, missing time sync and admins who can edit logs are the weaknesses scenario questions are built on.
- check_circleExpect questions on what system activity file interrogation looks for: unauthorised access attempts, failed log-ins, changes to master records.
FAQs
What is an audit trail in accounting software?expand_more
A chronological edit log recording each change to the books of account, with who made it, when and what changed. Under the Companies (Accounts) Rules it must cover every transaction and must not be capable of being disabled.
From when is the audit trail mandatory for companies?expand_more
The proviso to Rule 3(1) of the Companies (Accounts) Rules applies for financial years commencing on or after 1 April 2023, after two deferrals.
How long must the audit trail be retained?expand_more
ICAI's implementation guide reads the eight-year requirement for books of account in section 128(5) as applying to the audit trail, from 1 April 2023 onwards.
How long must logs be kept under CERT-In directions?expand_more
The April 2022 directions require logs of all ICT systems to be kept securely for a rolling 180 days, within India.
Next steps
- CAATs & Evidencearrow_forward
- Incident Responsearrow_forward
- IT Actarrow_forward
- ICAI Standardsarrow_forward
Assessment Test format, timed and scored.
