Corporate Accounting and Auditing · Application of Technology in Audit and Audit Trail
Auditor's Responsibilities and Reporting on Audit Trail
Updated 10 October 2026 · Fact-checked
An audit trail is a record of who changed what, and when, in the accounting software. The auditor checks that the company's software has this feature, that it was enabled for the whole year and not tampered with, and then reports on it under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014.
Understand Auditor's Responsibilities and Reporting on Audit Trail
An audit trail (edit log) is a built-in record in accounting software. It captures each transaction or change: what was entered, edited or deleted, who did it, and when. It helps prove that books were not altered without a trace.
Under the Companies (Accounts) Rules, 2014, a company that maintains books of account in electronic mode must use accounting software that has a feature of recording an audit trail of each and every transaction. The feature must create an edit log of each change made in the books, and it must not be disabled. This duty falls on management, not the auditor.
The auditor's duty is to report on whether the company complied. Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 requires the auditor to state, in the report on Other Legal and Regulatory Requirements, whether the company used accounting software with an audit trail feature, whether it operated throughout the year for all transactions, and whether it was tampered with. The rule applies to financial years starting on or after 1 April 2023.
To form a view, the auditor tests both the design and the operation of the controls around the feature. This means checking that the feature exists, that it was switched on all year, that users cannot turn it off or edit the logs, and that the log is preserved as the law requires. The auditor also checks controls at any service organisation that hosts the software.
This is different from CARO 2020. CARO is an order with specified clauses. The audit trail reporting sits under Rule 11(g) as a separate matter in the audit report. Do not mix the two in your answer. The reporting is also not part of the auditor's opinion on the financial statements. It is a legal and regulatory requirement.
Key rules to remember
- Management's duty (Companies (Accounts) Rules, 2014, Rule 3(1))
- Accounting software must record an audit trail of each transaction, create an edit log of each change, and the feature must not be disabled
- This is the company's responsibility. The auditor reports on it but does not own it.
- Auditor's reporting duty (Rule 11(g), Companies (Audit and Auditors) Rules, 2014)
- Report whether (1) software has audit trail feature, (2) it operated throughout the year for all transactions, (3) it was not tampered with, and (4) the trail was preserved as per statutory requirements
- Reported under Other Legal and Regulatory Requirements. Applies from financial years beginning on or after 1 April 2023.
- Reporting outcome
- Clean statement if all conditions are met; otherwise state the exception with specifics
- A gap, such as the feature not enabled for a module or a database, must be stated in the report.
How to solve Auditor's Responsibilities and Reporting on Audit Trail questions
Use this method for any question on the auditor's duties or the report wording on audit trail.
- 1Identify the company's books: are they kept in electronic mode? If books are fully manual, the requirement does not arise.
- 2State management's duty first: software with audit trail, edit log of each change, feature not disabled.
- 3List the auditor's procedures: inquire, inspect software settings, test that the feature was on all year, and test that logs cannot be altered or deleted.
- 4Cover scope: all transactions and all modules, including systems at service organisations and any interfaced software.
- 5Check preservation: the audit trail must be retained as required by law.
- 6Conclude with the report: Rule 11(g) statement under Other Legal and Regulatory Requirements, clean or with the exception described.
- 7Mention documentation of the work and of any management representation obtained.
Quickest way: Four-test memory frame for Rule 11(g)
When to use it: For short notes, MCQs and 14-mark theory answers under time pressure.
- Exists: does the software have the audit trail feature?
- On all year: was it operating throughout the year for all transactions?
- Intact: was it tampered with, and could users disable or edit it?
- Kept: was the trail preserved as the law requires?
- Then say where it is reported: Other Legal and Regulatory Requirements, not CARO.
Common mistakes in Auditor's Responsibilities and Reporting on Audit Trail
Saying the auditor must maintain or enable the audit trail.
Students blur the roles of management and auditor.
Fix: Write that management must maintain it; the auditor tests and reports.
Placing the reporting under a CARO 2020 clause.
Both are in the audit report and both are about compliance.
Fix: Write that it is reported under Rule 11(g), in the report on Other Legal and Regulatory Requirements.
Checking only that the feature exists.
Students treat it as a yes or no question.
Fix: Add that it must have operated throughout the year, for all transactions, and not been tampered with.
Ignoring service organisations and interfaced systems.
Students think only of the main accounting package.
Fix: Mention checking whether the audit trail covers hosted or third-party software that feeds the books.
Giving a clean statement when a module had the feature off.
Students assume the main ledger is enough.
Fix: Report the exception clearly, naming the gap, such as a database level or a period where logging was not active.
Worked examples
Example 1
Mehta Textiles Ltd keeps its books in electronic mode. State the auditor's responsibilities and what the auditor should report on audit trail for the year ended 31 March 2027.
Show the solution
- Books are in electronic mode, so the requirement applies. The financial year begins on or after 1 April 2023 (here 1 April 2026), so Rule 11(g) applies.
- Management's duty: use accounting software that records an audit trail of each transaction, creates an edit log of each change, and does not allow the feature to be disabled.
- Auditor's procedures: inquire of management, inspect the software settings, and test that the feature was enabled all year for all transactions.
- Test controls: check that users cannot switch off the log or alter it, and that access is restricted.
- Check the trail has been preserved as required by law, including for any service organisation.
- Report under Rule 11(g) in the report on Other Legal and Regulatory Requirements: whether the software had the feature, operated throughout the year, and was not tampered with.
Answer: Management maintains the audit trail. The auditor tests design and operation of the controls and reports under Rule 11(g), in Other Legal and Regulatory Requirements, with exceptions if any.
Example 2
During the audit of Kaveri Foods Ltd, the auditor finds that the audit trail feature was not enabled at the database level of the accounting software for the whole year, though it was enabled at the application level. How should the auditor respond in the report?
Show the solution
- The Rule 11(g) condition is that the feature operates throughout the year for all transactions.
- A gap at database level means that changes made directly at that level would not be logged.
- The auditor therefore cannot give a clean statement.
- The auditor should report the exception in the Rule 11(g) paragraph under Other Legal and Regulatory Requirements, naming the gap: the audit trail feature was not enabled at the database level. This reporting does not by itself modify the opinion on the financial statements.
- The auditor should also discuss it with those charged with governance and consider the effect on the audit approach, such as extra procedures on possible direct changes.
Answer: Report the exception in the Rule 11(g) paragraph of Other Legal and Regulatory Requirements, naming the gap: the feature was not enabled at database level. A clean statement would be wrong. This does not itself modify the opinion on the financial statements.
Exam tips
- Write the rule number, Rule 11(g), and name the Companies (Audit and Auditors) Rules, 2014, but do not quote section numbers you are unsure of.
- In MCQs, the usual trap is who is responsible: management maintains, auditor reports.
- Use the four-test frame (exists, on all year, intact, kept) to structure a 14-mark answer.
- Keep CARO 2020 and Rule 11(g) as separate points when a question asks about reporting in the audit report.
- If a case shows a gap, state the exception in the report, not just a recommendation.
Practice questions from Application of Technology in Audit and Audit Trail
- A company's accounting software operated an audit trail from 1 April to 31 December, but the feature was disabled from 1 January to 31 March…
- In the context of the accounting software used by a company, an 'audit trail' (edit log) primarily refers to which of the following?
- Aarav & Co., auditors of Kaveri Retail Ltd., plan to rely on an automated three-way match control in the ERP. Which sequence of actions is m…
- Which of the following is a recognised risk that arises specifically from the increased use of IT in an entity's financial reporting environ…
- During the audit of a company, the auditor finds that the audit trail (edit log) feature was enabled at the application level of the account…
Auditor's Responsibilities and Reporting on Audit Trail: frequently asked questions
Is audit trail reporting part of CARO 2020?
No. It is reported under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, in the report on Other Legal and Regulatory Requirements. CARO 2020 has its own set of clauses.
How does an auditor verify audit trail in Tally or similar software?
The auditor checks that the edit log feature is enabled and was on all year, reviews the settings and user access, and tests that entries can be traced and logs cannot be deleted. The same approach applies to any accounting package.
Who is responsible for keeping the audit trail?
Management is responsible for using software with an audit trail that is not disabled. The auditor is responsible for testing and reporting on it.
From when does the audit trail requirement apply?
The reporting requirement applies to financial years beginning on or after 1 April 2023.