Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

Audit in an IT environment: understanding the IT systems, general IT controls and application controls, the audit trail in accounting software, data analytics and what the auditor documents

The auditor must understand the information system and the IT and manual procedures that process transactions (SA 315, paragraph 18). IT helps controls but brings specific risks...

Published
Updated
Reading time
9 min
Views
6
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 9, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

Most books of account now live in software: accounting packages, billing systems, payroll applications and cloud platforms. The auditor still has to reach an opinion on the financial statements, but must first decide how far the computer can be trusted. This article explains how that is done under the Standards on Auditing and what the finance team should prepare. Process maps and control documentation are part of our compliance advisory support.

This article is based on the Standards on Auditing issued by ICAI as in force on 4 October 2026; ICAI may revise standards, so check the current text on icai.org. The standards are explained in our linked posts; the tools and vendor names are deliberately left out because the standards are not tied to any product.

What the standards say

SA 315, paragraph 18, requires the auditor to understand the information system relevant to financial reporting: the significant classes of transactions, the IT and manual procedures by which they are initiated, recorded, processed, corrected and reported, the related records, how non-transaction events are captured, the financial reporting process and the controls over journal entries. Where the risk is such that substantive procedures alone cannot give enough evidence, for example in highly automated routine processing, the auditor must understand the entity's controls (paragraph 30). Our post on SA 315 explains the risk assessment.

The application material A60 describes controls in IT systems as a combination of automated controls (embedded in programs) and manual controls, which may use IT-produced information or monitor IT and handle exceptions. A61 lists what IT does for control: consistent application of rules, accurate large-volume processing, extra analysis, monitoring, a lower chance of controls being circumvented and security-based segregation of duties. A62 lists the risks, including inaccurate processing, unauthorised access and data changes, IT staff with excess privileges, unauthorised changes to master files and programs, failure to make needed changes, inappropriate manual intervention and loss of data.

General IT controls and application controls

LayerWhat it coversWhat the auditor looks at
General IT controlsConditions for systems to work reliably: access to programs and data, program changes, operations and backup, and system development or acquisitionUser access lists and rights, leaver and joiner handling, privileged accounts, change approval and testing records, backup and recovery
Application controlsControls inside a process: validations, approvals, automatic calculations, interfaces between systems, exception reportsSample runs and re-performance, review of configuration, test of the approval workflow, review of interface reconciliation
Manual controls that use IT outputReview of reports, reconciliations, exception follow-upWhether the report used is complete and accurate; evidence of the review
User-developed toolsSpreadsheets feeding reportsVersion control, formula protection, who can change them

The link between the two layers matters. SA 330, paragraph 13, lists, among the factors in deciding whether evidence about controls from earlier audits can still be used, whether the control is manual or automated and the effectiveness of general IT controls. An automated control that worked last year can be assumed to work consistently only if programs and configuration did not change without authority. SA 330, paragraph 8, requires tests of controls where the auditor expects to rely on them, or where substantive procedures alone cannot give sufficient evidence, and paragraph 10 asks how, how consistently and by whom the controls were applied; paragraph 14 allows use of evidence from earlier audits only after establishing that the control has not significantly changed, and requires testing at least once in every third audit if unchanged. See our post on SA 330.

Information produced by the entity

SA 500, paragraph 9, says that when the auditor uses information produced by the entity, the auditor must evaluate whether it is sufficiently reliable, including evidence of accuracy and completeness and whether it is precise and detailed enough. This is where IT reports meet audit evidence: an ageing report, a stock listing or a list of journal entries is only as good as the query that produced it. The auditor may re-run the report, compare it to a control total, or test the parameters. See our post on SA 500.

Audit trail in accounting software

Whether a company must keep an audit trail of changes to its electronic books, and from when, is a legal question answered in our post on electronic books of account and the audit trail; the auditor's reporting on it is covered in our post on rules 11 and 12 of the Audit and Auditors Rules. For the audit, the practical questions are: is the feature enabled for all relevant systems and users, is it active throughout the period, who has rights to alter or disable it, and is it covered by general IT controls. We do not restate the rule here.

Data analytics

Analytics means testing whole populations with queries, not only samples. Common uses are checking journal entries for unusual postings (weekends, round amounts, entries by unexpected users, entries near year end), recomputing depreciation or interest for all assets or loans, matching two populations such as goods received and invoices, finding duplicate payments and testing the ageing of every receivable. Used in this way, analytics support the procedures required by SA 520 and SA 240 for journal entries. The auditor still needs to decide the purpose, check the completeness and accuracy of the data extracted, define the exceptions, and follow them up. A clean analytic result is not proof of correctness if the data was incomplete.

Outsourced processing

Where a service provider hosts or runs the system, SA 402 applies, and the provider's controls report may be used as evidence. See our posts on SA 402 and on SAE 3402, which is the standard under which that report is prepared.

What the auditor documents

The file shows the systems understood and their role in financial reporting, the risks arising from IT, the general IT controls tested and the results, application controls tested, the reliability checks on reports used as evidence, analytics performed with the data source and exceptions, and the response where a control failed (such as extending substantive work). Our post on SA 230 covers audit documentation.

Worked example (illustrative)

Prakash Retail Pvt Ltd, an invented chain, runs billing, inventory and accounts in separate systems with an interface. The auditor maps the flow from store sale to general ledger, and finds the interface posts daily totals automatically. The auditor tests the interface reconciliation for a sample of days, and the user access list shows that a finance executive who prepares journals also has rights to change interface settings. The control is tested and the access conflict is reported. Because the general IT access control is weak, the auditor does not rely on the automated posting control and increases sales substantive testing; the entity removes the access. A full-population query over journal entries finds 14 manual entries posted by a user outside the finance team in the last week of March, with an illustrative total of Rs 62 lakh; they are examined and found to be proper reclassifications, with one reversal needing an explanation.

Documents to keep ready

  • System landscape: list of applications, owners, hosting and interfaces.
  • User access list by role, joiner and leaver records, and privileged access.
  • Change log with approvals and testing evidence.
  • Backup and recovery records.
  • Report parameters for any report given to the auditor, with control totals.
  • Evidence that the audit trail feature is active, and who can change it.
  • Service provider reports for outsourced systems.

Common lapses

  • Shared logins or accounts of staff who have left.
  • Developers or finance users with rights to change production data and programs.
  • Reports given to the auditor without control totals or parameters.
  • Spreadsheets used for key calculations with no version control.
  • Audit trail feature disabled or switched off for some users.

Need help with IT controls and records?

Access lists, change records and a documented system map are the first things the auditor asks for in an IT-heavy audit, and they are easiest to keep up through the year. Our team can help you document processes, controls and reports; see our compliance advisory support.

Key takeaways

  • The auditor must understand how transactions flow through IT and manual procedures (SA 315, paragraph 18).
  • General IT controls underpin reliance on automated controls (SA 330, paragraph 13).
  • Information produced by the entity must be checked for reliability (SA 500, paragraph 9).
  • Analytics test populations but still need data checks and follow-up.
  • Audit trail requirements for company books are covered in the linked posts.

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Audit

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Do small businesses with simple software need an IT audit?

The Standards on Auditing are scaled to the entity; a simple package needs a lighter understanding, but the auditor still checks access and the reliability of reports.

What are general IT controls?

Controls over access, program changes, operations and system acquisition that support the reliable working of applications.

Books written up every week need no heroics at year end.

— TaxClue Accounts & Audit Desk

Audit: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

The Standards on Auditing are scaled to the entity; a simple package needs a lighter understanding, but the auditor still checks access and the reliability of reports.

Controls over access, program changes, operations and system acquisition that support the reliable working of applications.

Only after establishing that it has not significantly changed (SA 330, paragraph 14), and general IT controls are a factor in that decision (paragraph 13).

No standard requires specific tools; analytics are one way to obtain evidence and are used where they suit the risk.

Because the auditor must evaluate whether the information is sufficiently accurate, complete and precise (SA 500, paragraph 9).

Management is responsible for keeping books on software that meets the rule; the linked posts explain the requirement.