Indirect Tax Laws · Accounts and Records; E-way Bill
Generation and Maintenance of Electronic Records (Rule 57, CGST Rules)
Updated 5 October 2026 · Fact-checked
Rule 57 of the CGST Rules sets conditions for keeping GST records in electronic form. Each record must carry the digital signature of the authorising person, each login must have a unique ID, the data must be safeguarded and backed up, and you must produce it on demand, authenticated, with the means to verify it. Test each fact against these conditions.
Understand Generation and Maintenance of Electronic Records
Section 35 of the CGST Act requires a registered person to keep accounts and records at the principal place of business and at each additional place. The law allows these records to be kept in electronic form. Most businesses use accounting software, so this is the usual case.
Electronic records are easy to alter without a trace. Rule 57 therefore adds controls so that the officer can trust the data. The controls fall in four groups: authentication, traceability, safety of data and availability to the department.
Authentication means the record carries the digital signature of the person who must authenticate it, as understood under the Information Technology Act, 2000. Traceability means every login to the system has a unique ID, so you can tell who generated or changed a record. Safety means safeguards against loss, destruction and unauthorised access, plus proper backups. Availability means that when the proper officer asks, you produce the records, authenticated, in hard copy or electronic form, along with the means to verify them.
Think of it as a test: could an officer open your records, see who made each entry, confirm nothing was tampered with, and recover the data if your system failed? If yes, you comply. Exam questions describe a gap in one of these four areas and ask you to spot it.
Key rules to remember
- Authentication
- Electronic record + digital signature of the person required to authenticate it (IT Act, 2000)
- A plain typed name or an unsigned printout does not meet this condition.
- Unique login ID
- Every login to generate or maintain records = one unique ID, used to identify who generated or maintained the record
- Shared logins break traceability.
- Safeguards and backup
- Proper safeguards against loss or unauthorised access + proper electronic backup of records
- Backup is a compliance condition, not just good practice.
- Production on demand
- Proper officer asks → produce relevant records, duly authenticated, in hard copy or electronic form, with the means to verify them
- Giving the data without the means to verify it is incomplete compliance.
- Legal base
- Section 35 CGST Act allows electronic records; Rule 57 sets the conditions
- Cite both in answers: the section permits, the rule regulates.
How to solve Generation and Maintenance of Electronic Records questions
Use this method for any question on electronic records, whether a short note, a case scenario MCQ or a compliance check.
- 1Identify the person and the records: who is the registered person and what records (accounts, stock, invoices) are kept electronically.
- 2State the legal base: Section 35 allows records in electronic form, and Rule 57 prescribes how they are generated and maintained.
- 3Test authentication: does each record carry the digital signature of the person required to authenticate it?
- 4Test traceability: does each login have a unique ID that identifies who generated or maintained the record?
- 5Test safety: are there safeguards against loss and unauthorised access, and is there a proper electronic backup?
- 6Test availability: can the records be produced on demand, duly authenticated, in hard copy or electronic form, with the means to verify them?
- 7Conclude: name the condition that fails and state that the person has not complied with Rule 57, or that all conditions are met.
- 8Where the question asks for consequences, say in plain words that failure to maintain records as required attracts penalty provisions under the Act, and do not quote a figure you are unsure of.
Quickest way: The four-check scan: Sign, ID, Safe, Show
When to use it: Use it for case-scenario MCQs and for any scenario that describes a business's software or record practice.
- Sign: is there a digital signature on the record?
- ID: does each user have a unique login?
- Safe: are there safeguards and a backup?
- Show: can the records be produced on demand with the means to verify?
- The first check that fails is the answer. If all four pass, the person complies.
Common mistakes in Generation and Maintenance of Electronic Records
Thinking GST records must be kept in paper form at the business premises.
Students remember the place-of-business requirement under Section 35 and forget that electronic form is allowed.
Fix: Remember that electronic form is permitted, subject to Rule 57 conditions.
Treating a scanned signature or typed name as a digital signature.
The words 'signature' and 'authentication' are used loosely.
Fix: Link the digital signature to the Information Technology Act, 2000 and say the record must carry it.
Ignoring the unique login ID condition when staff share one login.
Students focus on signature and backup and treat login controls as an IT detail.
Fix: Remember that the ID must identify who generated or maintained each record, so shared logins fail.
Saying backup is optional or only recommended.
Backup sounds like best practice rather than a legal condition.
Fix: State that proper safeguards and electronic backup are part of the rule.
Producing only a data file when the officer asks for records.
Students think handing over the data is enough.
Fix: Add that the records must be duly authenticated and supplied with the means to verify them, in hard copy or electronic form.
Worked examples
Example 1
Alpha Traders, a registered person, keeps its sales and stock records in accounting software. Three accounts staff use a single common login. Records are digitally signed by the proprietor and backed up regularly. During a visit, the proper officer asks for the records. Advise whether Alpha Traders complies with Rule 57.
Show the solution
- Legal base: Section 35 allows electronic records, and Rule 57 sets the conditions.
- Authentication: records carry the proprietor's digital signature, so this is met.
- Safety: regular backups exist, so this is met.
- Traceability: three users share one login, so the system cannot identify who generated or maintained a record. This fails the unique ID condition.
- Availability: Alpha Traders must produce the records on demand, authenticated, in hard copy or electronic form, with the means to verify them.
Answer: Alpha Traders does not fully comply. The shared login breaches the unique ID requirement of Rule 57. It should give each user a unique login ID, and it must produce the records when the proper officer asks.
Example 2
Beta Ltd keeps its books in electronic form. Entries are made through individual logins and the data is backed up. The finance manager prints records for the officer but does not sign them, and the system generates entries with no digital signature. Identify the lapse under Rule 57.
Show the solution
- Check unique ID: individual logins are used, so this is met.
- Check backup and safeguards: the data is backed up, so this is met.
- Check authentication: each electronic record must carry the digital signature of the person required to authenticate it. Beta Ltd's records carry none.
- Check production on demand: records given to the officer must be duly authenticated, and the unsigned printouts fail this.
- Conclude on the lapse.
Answer: The lapse is the missing digital signature. The records are not authenticated as Rule 57 requires, and the unsigned printouts do not satisfy the duty to produce authenticated records on demand. Beta Ltd should authenticate its records with a digital signature under the Information Technology Act, 2000.
Exam tips
- Case-scenario MCQs usually plant one defect among otherwise correct facts. Run the Sign, ID, Safe, Show scan and find it.
- In written answers, cite Section 35 of the CGST Act and Rule 57 together, and list the conditions as short bullets.
- Always mention the Information Technology Act, 2000 when you discuss digital signature.
- Do not quote sub-rule numbers or penalty amounts unless you are sure. Marks come from stating the conditions correctly and applying them to the facts.
Practice questions from Accounts and Records; E-way Bill
- During a visit, a proper officer asks Kaveri Foods Ltd, which stores its accounts electronically, to produce its records. The finance manage…
- Meera Pharma Ltd stores its accounts in encrypted files using internal short-form codes. On demand, the officer asks for access. Which set o…
- Ritu Exports Ltd receives a demand to produce electronic records. Its accountant says records can be shown only on the company's own screen …
- Who is required to authenticate the records produced on demand in hard copy or in an electronically readable format, under the CGST Rules, 2…
- Ganga Components Ltd's data centre in Chennai is flooded, destroying its servers. It had maintained no off-site electronic back-up, but reta…
Generation and Maintenance of Electronic Records in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Generation and Maintenance of Electronic Records: frequently asked questions
Can a registered person keep GST records only in electronic form?
Yes. Section 35 of the CGST Act allows records in electronic form. Rule 57 then sets the conditions on authentication, login, safeguards, backup and production on demand.
Is a digital signature compulsory for electronic records under GST?
Yes. Each electronic record must carry the digital signature of the person required to authenticate it, in line with the Information Technology Act, 2000.
Why does Rule 57 require a unique login ID?
The ID shows who generated or maintained each record. This makes entries traceable and discourages tampering.
What must I do when the proper officer asks for electronic records?
Produce the relevant records on demand, duly authenticated, in hard copy or electronic form, along with the means to verify them. Handing over raw data alone is not enough.