Skip to main content

Accounting-Software Audit Trail Rule: Edit Log, Backups and Statutory Auditor Checklist

The accounting-software audit-trail rule is about whether every transaction-level change can be traced, not whether the company owns a popular ERP. Covered.

CA Nikhil Gupta · CA Divyanshu Sengar

The accounting-software audit-trail rule is about whether every transaction-level change can be traced, not whether the company owns a popular ERP. Covered companies must use accounting software with an edit-log feature, ensure the trail is not disabled and retain it in accordance with record-keeping requirements. The statutory auditor then reports on the company’s compliance.

Accounting-Software Audit Trail Rule: Edit Log, Backups and Statutory Auditor Checklist

At a glance

First move

Map every system that creates or changes accounting records.

Main trap

Buying compliant software but leaving the audit-trail feature disabled.

Keep

Accounting-system inventory and configuration screenshots/export

Rules

Control
Companies using accounting software must use software with an audit-trail/edit-log feature meeting the Companies (Accounts) Rules requirement.
The feature should operate throughout the year and preserve edit history rather than being switched on only during audit.
Statutory auditors have a corresponding reporting responsibility regarding the audit-trail requirement.

The Companies (Accounts) Rules require prescribed accounting software to record an audit trail of each transaction, creating an edit log for changes and preserving the date of modification.

The audit-trail feature should not be disabled during the year; administrator access that can silently switch logging off creates a control gap.

The rule applies to accounting books maintained electronically, including relevant feeder systems/interfaces where accounting entries can be created or altered.

Migration to a new ERP should preserve historical logs and opening-balance traceability; a clean go-live database is not enough if prior-year evidence disappears.

Backups should protect both accounting data and audit logs. Restore testing is necessary because a backup that cannot be read does not satisfy operational resilience.

User IDs should be individual and role-based. Shared administrator credentials make it difficult to identify who changed a transaction.

The statutory auditor needs evidence to report whether the company used compliant software throughout the year and whether the audit trail was preserved.

Audit trail compliance is about the software configuration and the evidence that it stayed enabled

The Companies (Accounts) Rules require a company using accounting software to use software with an audit-trail/edit-log feature that records each change, captures the date and ensures the audit trail cannot be disabled. The control is not satisfied merely because the ERP product has an optional log module; the company must show that the feature was actually enabled and operated for all relevant transactions throughout the year.

Scope is broader than the general ledger. If transactions originate in billing, inventory, payroll or other systems and flow into the books, management should map whether the accounting record can be altered before or after posting and where the edit history is preserved. Spreadsheet uploads and manual journal interfaces are frequent weak points.

Backups matter because an edit log that exists only on the same vulnerable server may not be reliable evidence. The company should align audit-trail retention with the statutory books-and-records preservation period and test that the log can be restored/read after system upgrades, migrations or vendor changes.

The statutory auditor’s reporting obligation is separate from management’s system design. Management should give the auditor a system inventory, configuration evidence, exception log and sample export. An auditor finding that the feature was disabled for part of the year cannot be cured by turning it on just before the audit.

SituationHow to handle it
ERP has edit-log function but administrator switched it off for two monthsCompliance gap exists for that period; preserve incident evidence and remediation rather than claiming full-year operation.
Sales system feeds accounting software through daily interfaceMap edit history on both the source/interface and accounting layer to determine where transaction changes can occur.
Company migrates to a new ERP mid-yearRetain readable old-system logs and document opening-balance/migration controls in addition to new-system configuration.

Worked example 1

A company’s ERP records edits, but the finance administrator can disable logging and did so for three weeks during year-end cleanup. The company cannot cure that historical gap merely by turning the feature back on before the audit. Management should document the incident, identify transactions changed during the period, preserve alternative evidence, remediate access controls and discuss the reporting implication with the statutory auditor.

Worked example 2

A company’s ERP records journal edits, but the administrator discovers that the audit-log database was excluded from backups for six months. Finance should not describe the control as fully robust merely because screen history is currently visible. It should preserve the available log, remediate backup settings, test restoration, document the affected period and give the auditor the full chronology for reporting under the audit-trail clause.

Mistakes

  • Buying compliant software but leaving the audit-trail feature disabled.
  • Testing only the general ledger and ignoring feeder systems or upload interfaces.
  • Deleting or overwriting logs during an ERP migration.
  • Assuming year-end screenshots prove that the feature operated throughout the year.

Action steps

  1. Map every system that creates or changes accounting records.
  2. Verify edit-log functionality is enabled and cannot be casually disabled.
  3. Test user/admin changes and journal reversals.
  4. Include audit logs in backup and retention controls.
  5. Preserve migration/upgrade evidence.
  6. Provide the statutory auditor with year-long control evidence and exceptions.

Documents

FAQs

Is an ERP automatically compliant because it has an audit-log feature?

No. The feature must be configured, operated and preserved as required; an unused option is not enough.

Can the audit trail be switched off temporarily?

The rule expects the audit trail not to be disabled. Any period of disablement creates a compliance and audit-reporting issue.

Do feeder systems matter?

Yes, if they create or modify accounting data before it reaches the general ledger. The company should map the full transaction path.

What should be retained after an ERP migration?

Readable historical logs, migration controls, access/configuration evidence and proof that the audit trail continued across the change.

Sources

Educational reference. Verify current official sources and facts.