Digital Evidence explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Most modern frauds leave their trail in emails, accounting software, bank files and mobile data. FAIS 410 and FAIS 420 tell a forensic accountant how to analyse such data and collect digital evidence so that the results can be trusted and, where needed, relied on before a competent authority.
This article is from the ICAI Compendium of Forensic Accounting and Investigation Standards (as on September 2025); mandatory for engagements conducted on or after 1 July 2023. ICAI may revise the standards, so check the current text on icai.org.
FAIS 410 requires a written data analysis plan, careful data preparation, tests that another competent person can reproduce, and safeguards for confidentiality, integrity and preservation. FAIS 420 requires a documented e-discovery process, evidence gathered by people with the right skills, compliance with the laws and data privacy rules on digital evidence, and a reliable chain of custody. Admissibility itself is decided under the law of evidence, not by these standards.
FAIS 410: applying data analysis
The standard applies to any assignment that uses data analysis (DA) to meet its objectives (paragraph 1.4). Its aims are more reliable evidence, consistency across assignments, early identification of anomalies and fraud indicators, and outputs that preserve data integrity and meet the evidentiary needs of competent authorities (paragraph 2.1). It defines a few terms worth knowing: the test of reproducibility (the same tests on the same data set should give the same result when run by another competent person) and the data boundary (restricting source and period of data to what the objectives need).
| Requirement | What the Professional does | Paragraph |
|---|---|---|
| Data analysis plan | Written plan: objectives, assumptions, hypotheses, procedures, sources and boundaries, tools, reporting form | 3.1, 4.1 |
| Pre-processing | Acquire, validate and prepare data; keep integrity and the data boundary; take care over admissibility | 3.2, 4.2 |
| Analysis | Run scripts or models, test reproducibility, repeat with more data if needed | 3.3, 4.3 |
| Preservation | Protect confidentiality, integrity, archival and retrieval for as long as law requires | 3.4, 4.4 |
| Team skills | Team as a whole has DA knowledge and experience | 3.5, 4.5 |
| Governance | Quality review of scripts, validated tools, masking or minimising personal data | 3.6, 4.6 |
The documentation required (paragraph 5.1) is four sets of records: the plan; acquisition and preparation records (file names, metadata, chain of custody, validation results, boundary criteria); the analysis record (the logic, scripts or queries used and a log of procedures); and a note of how the data is preserved. In plain terms, someone else should be able to pick up the file and run the same tests on the same data to get the same answers.
What this means for the accounts team
If you are asked to supply data for a review, expect requests for full extracts rather than summaries, in their original format, with a record of who exported them and when. Keep the originals untouched and give working copies for analysis. Our guidance on electronic books of account, backups and the audit trail explains the record-keeping rules the company's own system must already meet. If your team needs support in setting up such records, see our compliance advisory service.
FAIS 420: evidence gathering in the digital domain
FAIS 420 applies to assignments that depend on gathering digital evidence (paragraph 1.5). Its definitions include the digital chain of custody: the procedures that track the movement of evidence from collection through storage, securing, safeguarding and analysis, recording each person who handled it and the date, time and purpose of each transfer. Another is the digital footprint, such as browsing history or social media activity traceable to a user.
The requirements:
- A documented e-discovery process, stipulating the technical standards and legal requirements to follow (paragraph 3.1).
- An understanding of the information systems environment, so far as it affects the objectives (paragraph 3.2).
- Evidence gathering by people with the skills, expertise and experience to preserve reliability and admissibility (paragraph 3.3).
- Compliance with domestic or, where applicable, international laws on the digital domain and with data privacy laws that restrict e-discovery and custody (paragraph 3.4).
- Forensic tools and techniques, where necessary, to authenticate the evidence, analyse the data and maintain a reliable chain of custody (paragraph 3.5).
The explanatory comments say that the sufficiency of the credentials of the person doing the e-discovery is a matter of judgement and may lead to a temporary technical expert being engaged under FAIS 230 (paragraph 4.3). Documentation must include the process followed and the chain of custody for all evidence, which can be an electronic chain of custody that can be tested independently with logs (paragraphs 5.1 and 5.2).
The standard asks for compliance with the law on digital evidence but does not state it. Admissibility is governed by the law of evidence, and the information technology law and data protection law also bear on collection; take legal advice on those points. For cyber incident reporting and log retention duties, see our guide to the CERT-In Directions of 2022.
How the two standards fit together
FAIS 410 deals with what is done to data once it is in hand; FAIS 420 deals with how digital material is found and secured in the first place. Both lean on FAIS 320 for evidence and documentation and on FAIS 230 for experts, covered in our articles on FAIS 320 to 360 and 510 and FAIS 210 to 310. An auditor testing a client's IT systems works under auditing standards instead; see our article on audit in an IT environment.
Illustrative example
Illustrative: Crestview Retail Pvt Ltd suspects that a regional manager inflated discount credits to a distributor. The forensic accountant prepares a data analysis plan: hypothesis of excess discounts, twenty-four months of invoice and credit note data from the billing system, with the boundary limited to that distributor and region. The IT team exports the data under the accountant's supervision, and a log records the exporter, the time and a checksum of each file. The accountant validates record counts against the trial balance, runs a script that compares discount rates with the approved price list, and saves the script. A second team member re-runs it on the same files and gets the same list of 61 exceptions, which satisfies the reproducibility test. A laptop and phone used by the manager are imaged by a hired digital forensic specialist whose credentials and independence the accountant first checks; the images are sealed, logged and stored. Personal messages unrelated to the case are masked in the working copies.
Common lapses
- Analysing a spreadsheet someone emailed rather than data acquired under supervision.
- No log of who exported, copied or opened the files.
- A script that only its author can run, or that has been overwritten.
- Seizing a personal device or reading private messages without checking the legal basis.
- Using an unvalidated tool or an untested macro to produce the exception list.
Need help with data records for an investigation?
If you expect to be asked for system data or want your accounting records ready for an external review, we can help you check how they are kept and exported through compliance advisory.
Key takeaways
- Prepare a written data analysis plan and keep the data within a defined boundary (FAIS 410, paragraphs 3.1 and 3.2).
- Make analysis reproducible and keep the scripts and logs (FAIS 410, paragraphs 3.3 and 5.1).
- Gather digital evidence under a documented e-discovery process by qualified people (FAIS 420, paragraphs 3.1 and 3.3).
- Record a digital chain of custody for every item (FAIS 420, paragraph 5.2).
- Comply with the laws on digital evidence and data privacy; the standards point to them but do not set them out.
Read next
- FAIS 320 to 360 and 510: evidence, procedures, interviews, testifying and the report
- Fraud risk, red flags and detection techniques
- Audit in an IT environment
- CERT-In Directions of 2022: cyber incident reporting and log retention
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
