Last reviewed: 27 August 2026. As statutory audits for FY 2025-26 run up to AGM season, one finding keeps recurring across small and mid-size companies we look at: the accounting software is right, the numbers are right, but the audit trail was switched off for part of the year, or nobody can show the auditor it operated continuously. Rule 3(1) of the Companies (Accounts) Rules, 2014 has been mandatory since FY 2023-24 and every statutory auditor must now comment on it under Rule 11(g) — yet most founders and even many in-house accountants have never actually opened the setting. This guide sets out what the rule requires, what your auditor is checking, and a practical checklist to close the gaps before sign-off.
Rule 3(1) vs Rule 11(g) — two different obligations, one finding
These are commonly discussed as one thing, but they sit in two different Rules and land on two different people.
| Rule 3(1), Companies (Accounts) Rules, 2014 | Rule 11(g), Companies (Audit and Auditors) Rules, 2014 | |
|---|---|---|
| Who it binds | The company (in practice, the person maintaining the books — CFO/finance head/accountant) | The statutory auditor |
| What it requires | Use accounting software with a feature that records an audit trail of every transaction and creates an edit log of every change, with the date of the change, and the feature cannot be disabled | State in the audit report whether the company used such software, whether the audit trail operated throughout the year for all transactions, and whether it has been preserved per the statutory retention requirement |
| Effective from | Books of account maintained for FY 2023-24 onward (financial years commencing on or after 1 April 2023) | Reporting from FY 2023-24; the preservation limb became a standard part of the reporting from FY 2024-25 onward |
| What breach looks like in practice | Software with the feature switched off, an admin login that can toggle it, or bulk historical edits with no log | A qualified remark, an "Emphasis of Matter" paragraph, or an outright statement that the requirement was not met |
How we got to a mandatory rule — two deferrals before it stuck
| Milestone | What happened |
|---|---|
| Companies (Accounts) Amendment Rules, 2021 | Audit trail feature first notified as a requirement, originally to apply from 1 April 2021 |
| First deferral | MCA pushed the effective date out by a year, to 1 April 2022, citing the time software vendors needed to build the feature into their products |
| Second deferral | Pushed again to 1 April 2023 for the same reason — wide industry representation that ERP and accounting-software vendors were not ready |
| FY 2023-24 | Finally mandatory. Rule 11(g) auditor reporting kicks in for financial statements of this year onward |
| FY 2024-25 onward | Auditor reporting matures to also cover the preservation limb as a standard line, not a one-off note |
The two-deferral history matters practically: a lot of the working assumptions accountants formed in 2021-22 ("this got postponed again, we'll deal with it later") are now three years out of date. Three full audit cycles have gone by since the rule actually bit.
What the audit trail must actually do
| Requirement | Plain-English test |
|---|---|
| Records an audit trail of every transaction | Every voucher entry, invoice, journal or ledger posting is logged — not just year-end adjustments |
| Creates an edit log of every change, with date | If someone opens a posted voucher and edits an amount, date or narration, the software keeps the original and the change, dated |
| Cannot be disabled | No settings menu, admin role or configuration flag lets any user — including the company itself — switch the logging off. If it can be turned off, the software does not meet the requirement even if it is normally left on |
Two situations we see repeatedly
Worked example 1 — the "admin can disable it" gap. A trading company runs Tally Prime with the edit-log feature enabled for daily use. During the audit, the statutory auditor asks the IT-admin user to demonstrate the setting and finds that the same login that does day-to-day entries also has the rights to turn audit-trail logging off from Tally's configuration screen. Nothing was actually disabled during the year, but the capability to disable it existed — and Rule 3(1) requires that the feature "cannot be disabled," not merely that it wasn't. The auditor records this as a Rule 11(g) exception even though the books themselves are accurate. The fix is administrative, not technical: restrict configuration-level access to a role the routine data-entry user does not hold, and document that restriction.
Worked example 2 — the mid-year migration gap. A services company moves from an older desktop accounting package to Zoho Books in October, mid-way through the financial year, to get GST e-invoicing integration. The new system's audit trail is complete from October onward. But six months of transactions sat only in the old package, whose audit trail was never exported or preserved once the subscription lapsed. The auditor cannot verify audit trail continuity for April-September, and reports accordingly. The lesson: any mid-year software change needs a documented migration plan that exports and archives the old system's audit trail before access is lost, not after.
Preservation — how long the trail has to survive
Rule 3(1) itself does not spell out a separate retention period for the audit trail. The consistent practitioner reading, which lines up with ICAI's implementation material, is that the audit trail is part of the books of account and therefore inherits the Section 128(5) minimum: not less than eight financial years from the end of the relevant financial year, or longer where the company is under investigation and the Central Government has directed a longer retention. In practice this means: do not let an accounting-software subscription lapse, and do not let a migration wipe out the old system's data, until you have exported and archived the audit trail alongside the books it belongs to.
Who is covered — and who genuinely is not
- Covered: every company incorporated under the Companies Act, 2013 that uses accounting software — private limited, public limited, One Person Companies, Section 8 (not-for-profit) companies, and Nidhis. There is no turnover, paid-up capital or company-size carve-out.
- Not covered today: LLPs under the LLP Act, 2008, and unregistered partnership firms or proprietorships. Neither the LLP Act nor its Rules currently carry an equivalent mandate, though a firm relying on its books for a bank loan, a GST assessment or a tax audit is well served by adopting the same discipline voluntarily.
- Grey zone: a company still doing part of its bookkeeping in Excel and importing summarised entries into the compliant software. The imported entries carry an audit trail; the Excel workings that fed them generally do not. Auditors are increasingly asking to see the source workbook's version history as supporting evidence, not just the software's log.
Compliance checklist before your FY 2025-26 audit closes
| Check | Why it matters |
|---|---|
| Confirm with your software vendor, in writing, that the audit trail feature exists and cannot be disabled from any user role | This is the exact wording your auditor will ask for; a vendor confirmation letter is standard supporting documentation now |
| Review admin/configuration-level access and remove the ability to toggle logging from day-to-day user roles | Closes the "capability to disable" gap even where nothing was actually switched off (Worked example 1) |
| If you changed accounting software during the year, export and archive the old system's audit trail before the subscription lapses | Preserves continuity across the migration date (Worked example 2) |
| Check whether any part of the books still lives in Excel or a manual register and route it into the compliant system, or retain full version history for the workbook | Closes the grey-zone gap auditors are increasingly probing |
| Retain audit trail data for at least eight financial years, in a format you can still open | Software changes and license lapses are the most common reason older audit trail data becomes unreadable |
| Flag this as a standing item in your monthly closing checklist, not a once-a-year audit-season scramble | Rule 11(g) reporting is now permanent, not a one-time transition item |
Not sure your current setup would pass this test, or planning a software migration this year? Our Bookkeeping & Accounting team runs a one-time audit-trail readiness review alongside your regular books, and we coordinate directly with your statutory auditor so the Rule 11(g) paragraph in this year's report is clean.
Frequently asked questions
Does the audit trail rule apply to LLPs, partnership firms or proprietorships?
No. Rule 3(1) of the Companies (Accounts) Rules, 2014 applies only to companies registered under the Companies Act, 2013 — private limited, public limited, One Person Companies, Section 8 companies and Nidhis. LLPs (governed by the LLP Act, 2008), partnership firms and proprietorships have no equivalent statutory mandate today, though the same edit-log discipline is good practice for anyone relying on their books for a bank facility or a tax audit.
We use Tally Prime / Zoho Books / Busy — is the software automatically compliant?
The software vendor can build the audit trail feature, but compliance depends on how you configure and use it. Most mainstream Indian accounting software (recent Tally Prime, Zoho Books, Busy, QuickBooks India editions) has the capability, but if the edit-log module is left switched off, if a super-admin login can disable it, or if the company works partly out of a spreadsheet that reconciles into the software after the fact, the audit trail is not actually operating the way Rule 3(1) requires — and your auditor will say so.
What does the auditor actually check under Rule 11(g)?
Three things: whether the software used to maintain books had the audit trail feature enabled, whether it operated throughout the financial year for all relevant transactions, and whether the audit trail has been preserved as per the statutory retention requirement. Where any of these is not fully met, the auditor's report must say so explicitly rather than stay silent — this shows up as an "Emphasis of Matter" or a qualified remark under Rule 11(g), which is now a routine reading item for banks and investors reviewing your financials.
Is there a specific penalty for not having an audit trail?
There is no standalone penalty section titled "audit trail" — it sits inside the broader books-of-account requirement under Section 128. Where the managing director, the whole-time director in charge of finance, the CFO, or the officer the Board has charged with this duty fails to ensure compliance, Section 128(6) exposes that individual to a fine of not less than ₹50,000 extending up to ₹5,00,000, with imprisonment up to one year in serious cases. The bigger practical cost for most MSMEs is the qualified audit report itself, not the fine.
How long do we have to preserve the audit trail?
The Rules do not prescribe a separate number for the audit trail specifically, so the safe practitioner position — and the one ICAI's implementation material points to — is to preserve it alongside the underlying books of account for the Section 128(5) minimum: not less than eight financial years from the end of the relevant year (longer if a specific investigation under the Act requires it).
We migrated accounting software mid-year — does the audit trail break?
It can, and this is one of the most common findings. If you moved from one system to another partway through the year, the auditor needs the trail to be continuous and unbroken across the migration, with both systems' logs preserved and reconciled. Plan any mid-year software change with your accountant so the cut-over date, opening balances and historical audit trail are documented before the old system is retired.
Does this apply to a small private company below a turnover threshold?
There is no turnover or paid-up-capital threshold for the audit trail requirement — it applies to every company using accounting software to maintain its books, regardless of size. A small private company preparing abridged financials under the small-company rules still has to meet Rule 3(1); the only relief small companies get elsewhere in the Act (rotation of auditors, cash-flow statement, CARO applicability) does not extend to this rule.
We review your accounting software configuration, close the admin-access and migration gaps auditors flag most often, and coordinate with your statutory auditor so the Rule 11(g) paragraph reads clean. If your company is also due for ROC annual filings this AGM season, it is worth handling both together.
Bookkeeping & Accounting ROC Filing Services Talk to usThis article explains the audit trail requirement under Rule 3(1) of the Companies (Accounts) Rules, 2014 and Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 as in force as of 27 August 2026, and is general guidance, not advice on your specific facts — consult us before you rely on it for a filing or an audit response.