Audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Most books of account now live in software: accounting packages, billing systems, payroll applications and cloud platforms. The auditor still has to reach an opinion on the financial statements, but must first decide how far the computer can be trusted. This article explains how that is done under the Standards on Auditing and what the finance team should prepare. Process maps and control documentation are part of our compliance advisory support.
This article is based on the Standards on Auditing issued by ICAI as in force on 4 October 2026; ICAI may revise standards, so check the current text on icai.org. The standards are explained in our linked posts; the tools and vendor names are deliberately left out because the standards are not tied to any product.
The auditor must understand the information system and the IT and manual procedures that process transactions (SA 315, paragraph 18). IT helps controls but brings specific risks: unauthorised access, changes to programs and master data, and inaccurate processing (SA 315, A62). The auditor tests general IT controls because automated application controls can only be relied on if the general controls hold (SA 330, paragraph 13). Reports and data produced by the entity must be checked for reliability (SA 500, paragraph 9). The audit trail rule for company books is only referred to here, through the linked post.
What the standards say
SA 315, paragraph 18, requires the auditor to understand the information system relevant to financial reporting: the significant classes of transactions, the IT and manual procedures by which they are initiated, recorded, processed, corrected and reported, the related records, how non-transaction events are captured, the financial reporting process and the controls over journal entries. Where the risk is such that substantive procedures alone cannot give enough evidence, for example in highly automated routine processing, the auditor must understand the entity's controls (paragraph 30). Our post on SA 315 explains the risk assessment.
The application material A60 describes controls in IT systems as a combination of automated controls (embedded in programs) and manual controls, which may use IT-produced information or monitor IT and handle exceptions. A61 lists what IT does for control: consistent application of rules, accurate large-volume processing, extra analysis, monitoring, a lower chance of controls being circumvented and security-based segregation of duties. A62 lists the risks, including inaccurate processing, unauthorised access and data changes, IT staff with excess privileges, unauthorised changes to master files and programs, failure to make needed changes, inappropriate manual intervention and loss of data.
General IT controls and application controls
| Layer | What it covers | What the auditor looks at |
|---|---|---|
| General IT controls | Conditions for systems to work reliably: access to programs and data, program changes, operations and backup, and system development or acquisition | User access lists and rights, leaver and joiner handling, privileged accounts, change approval and testing records, backup and recovery |
| Application controls | Controls inside a process: validations, approvals, automatic calculations, interfaces between systems, exception reports | Sample runs and re-performance, review of configuration, test of the approval workflow, review of interface reconciliation |
| Manual controls that use IT output | Review of reports, reconciliations, exception follow-up | Whether the report used is complete and accurate; evidence of the review |
| User-developed tools | Spreadsheets feeding reports | Version control, formula protection, who can change them |
The link between the two layers matters. SA 330, paragraph 13, lists, among the factors in deciding whether evidence about controls from earlier audits can still be used, whether the control is manual or automated and the effectiveness of general IT controls. An automated control that worked last year can be assumed to work consistently only if programs and configuration did not change without authority. SA 330, paragraph 8, requires tests of controls where the auditor expects to rely on them, or where substantive procedures alone cannot give sufficient evidence, and paragraph 10 asks how, how consistently and by whom the controls were applied; paragraph 14 allows use of evidence from earlier audits only after establishing that the control has not significantly changed, and requires testing at least once in every third audit if unchanged. See our post on SA 330.
Information produced by the entity
SA 500, paragraph 9, says that when the auditor uses information produced by the entity, the auditor must evaluate whether it is sufficiently reliable, including evidence of accuracy and completeness and whether it is precise and detailed enough. This is where IT reports meet audit evidence: an ageing report, a stock listing or a list of journal entries is only as good as the query that produced it. The auditor may re-run the report, compare it to a control total, or test the parameters. See our post on SA 500.
Audit trail in accounting software
Whether a company must keep an audit trail of changes to its electronic books, and from when, is a legal question answered in our post on electronic books of account and the audit trail; the auditor's reporting on it is covered in our post on rules 11 and 12 of the Audit and Auditors Rules. For the audit, the practical questions are: is the feature enabled for all relevant systems and users, is it active throughout the period, who has rights to alter or disable it, and is it covered by general IT controls. We do not restate the rule here.
Data analytics
Analytics means testing whole populations with queries, not only samples. Common uses are checking journal entries for unusual postings (weekends, round amounts, entries by unexpected users, entries near year end), recomputing depreciation or interest for all assets or loans, matching two populations such as goods received and invoices, finding duplicate payments and testing the ageing of every receivable. Used in this way, analytics support the procedures required by SA 520 and SA 240 for journal entries. The auditor still needs to decide the purpose, check the completeness and accuracy of the data extracted, define the exceptions, and follow them up. A clean analytic result is not proof of correctness if the data was incomplete.
Outsourced processing
Where a service provider hosts or runs the system, SA 402 applies, and the provider's controls report may be used as evidence. See our posts on SA 402 and on SAE 3402, which is the standard under which that report is prepared.
What the auditor documents
The file shows the systems understood and their role in financial reporting, the risks arising from IT, the general IT controls tested and the results, application controls tested, the reliability checks on reports used as evidence, analytics performed with the data source and exceptions, and the response where a control failed (such as extending substantive work). Our post on SA 230 covers audit documentation.
Worked example (illustrative)
Prakash Retail Pvt Ltd, an invented chain, runs billing, inventory and accounts in separate systems with an interface. The auditor maps the flow from store sale to general ledger, and finds the interface posts daily totals automatically. The auditor tests the interface reconciliation for a sample of days, and the user access list shows that a finance executive who prepares journals also has rights to change interface settings. The control is tested and the access conflict is reported. Because the general IT access control is weak, the auditor does not rely on the automated posting control and increases sales substantive testing; the entity removes the access. A full-population query over journal entries finds 14 manual entries posted by a user outside the finance team in the last week of March, with an illustrative total of Rs 62 lakh; they are examined and found to be proper reclassifications, with one reversal needing an explanation.
Documents to keep ready
- System landscape: list of applications, owners, hosting and interfaces.
- User access list by role, joiner and leaver records, and privileged access.
- Change log with approvals and testing evidence.
- Backup and recovery records.
- Report parameters for any report given to the auditor, with control totals.
- Evidence that the audit trail feature is active, and who can change it.
- Service provider reports for outsourced systems.
Common lapses
- Shared logins or accounts of staff who have left.
- Developers or finance users with rights to change production data and programs.
- Reports given to the auditor without control totals or parameters.
- Spreadsheets used for key calculations with no version control.
- Audit trail feature disabled or switched off for some users.
Need help with IT controls and records?
Access lists, change records and a documented system map are the first things the auditor asks for in an IT-heavy audit, and they are easiest to keep up through the year. Our team can help you document processes, controls and reports; see our compliance advisory support.
Key takeaways
- The auditor must understand how transactions flow through IT and manual procedures (SA 315, paragraph 18).
- General IT controls underpin reliance on automated controls (SA 330, paragraph 13).
- Information produced by the entity must be checked for reliability (SA 500, paragraph 9).
- Analytics test populations but still need data checks and follow-up.
- Audit trail requirements for company books are covered in the linked posts.
Read next
- SAE 3402, controls at a service organisation
- Data analysis and digital evidence in forensic work
- SA 330, responses to assessed risks
- SIA 520 and SIA 530, internal audit of IT systems
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
