Since April 2023, every Indian company using accounting software has been required to keep a functioning audit trail, a running edit log of every transaction and every change made to it. That part isn’t new. What’s new for FY 2025-26 is enforcement. Auditors are now expected to verify not just that the audit trail ran this year, but that last year’s trail was properly preserved too, something largely waved through in the rule’s first year for lack of a prior trail to check.
This blog covers what the audit trail rule actually requires, who it applies to, the specific ways companies end up non-compliant without realizing it, and what it costs to get wrong.
What the Audit Trail Rule Actually Requires
Rule 3(1) of the Companies (Accounts) Rules, 2014 requires that any company using accounting software to maintain its books of account uses software with a functioning audit trail. This can also be called an edit log. In practice, every transaction, and every edit made to that transaction afterward, has to be recorded with:
- A timestamp of when the change was made
- The user ID responsible for the change
- The change itself, what it looked like before and after
The critical detail is that this feature cannot be disabled at any point during the financial year. This feature cannot be switched off temporarily, paused during a system migration, or turned off by an administrator for convenience. If it was disabled for even part of the year, the year isn’t compliant, even if the software itself is fully capable of meeting the requirement.
Who This Audit Trail Actually Applies To
The audit trail requirement isn’t scaled by company size or turnover. It applies to every company using accounting software to maintain its book, no company has exceptions. Larger companies, particularly those above 50 crore rupees in turnover, tend to face more detailed scrutiny in practice, but the underlying legal obligation doesn’t distinguish between a large enterprise and a small private limited company.
If a business assumed this was something only bigger companies needed to worry about, that assumption is worth revisiting now, before an auditor raises it.
Having Software Isn't the Same as Being Compliant
Using genuinely capable, reputable accounting software doesn’t automatically mean a company is compliant. The requirement isn’t about whether the software can maintain an audit trail. It’s about whether that feature was actually running, continuously, for the entire financial year, without interruption.
A few common situations that break compliance even with the right software in place:
- Switching accounting systems mid-year without properly preserving and carrying forward the audit trail from the earlier system
- Disabling the feature briefly during a data migration or system upgrade
- Turning it off temporarily because someone in the finance team didn’t realize what it was for
- Using a cloud or hosted system where the vendor, not the company, controls whether the feature stays enabled, without confirming this directly
Demonstrating compliance generally means being able to show that the feature was functional and enabled throughout, which usually requires designing specific internal controls around it, not just installing the right software and assuming the rest takes care of itself.
The Excel Blind Spot
Standard spreadsheet-based bookkeeping doesn’t have a built-in, non-disableable edit log by design. Anyone can open a spreadsheet and change a number without any record of who changed it, when, or what it looked like before.
Companies that still maintain their primary books of account through Excel, rather than dedicated accounting software, are very likely non-compliant with this rule right now. This is not usually through any intent to avoid the requirement, but simply because the rule’s reach into ordinary spreadsheet-based bookkeeping isn’t always obvious until an auditor points it out.
How Long Companies Have to Keep Audit Trails
Once the audit trail exists, it has to be preserved and retained. Under Section 128(5) of the Companies Act, companies are required to retain books of account for at least eight financial years. The audit trail attached to those books needs to be preserved for the same eight-year window.
This isn’t a separate, unfamiliar retention obligation stacked on top of existing ones. It’s an extension of a retention rule that’s already part of standard practice, just now applied to the edit history as well as the books themselves.
What Audit Trails Non-Compliance Actually Costs
Penalties for non-compliance break down roughly like this:
- 25,000 to 5,00,000 rupees, depending on the nature of the violation
- More serious consequences where the lapse looks intentional or fraudulent rather than an oversight
- A qualification in the statutory audit report itself, since the auditor is specifically required to report on whether the audit trail was enabled and preserved throughout the year
Transfer pricing checks whether these transactions are priced at arm’s length. In simple terms, it asks whether the pricing is fair, as if the transaction happened between two independent parties. Where applicable, the foreign company may need transfer pricing documentation and a report from an accountant. This is especially relevant when there are international related-party transactions.
For most companies, the realistic risk here is a process failure, a feature disabled during a migration, a system switch without proper handover, rather than deliberate wrongdoing, and the penalty structure broadly reflects that distinction. But the audit report consequence matters regardless of intent. A gap here doesn’t stay a private problem between a company and its accounting system. It becomes a qualification in a visible, filed document. The broader statutory audit and CARO (Companies (Auditor’s Report) Order) reporting process this feeds into is covered in more depth elsewhere on this site.
Conclusion
Audit trails have stopped being a box-ticking exercise the moment auditors started actually verifying preservation rather than taking current-year enablement at face value. The fix, for most companies, is a short conversation with whoever manages the accounting software to confirm that the audit trail feature has to run without interruption all year and that any prior year’s trail was to be properly carried forward. That conversation is considerably cheaper to have now than to have for the first time when the auditor asks the question directly.
FAQ'S
An audit trail is a chronological record of every transaction and every change made to it, showing what was changed, who changed it, and when. In Indian accounting software, this typically takes the form of an edit log that captures creation, alteration, and deletion of entries.
Audit trails make it possible to trace exactly how a company’s financial records reached their final form, rather than only seeing the final numbers. This supports internal control, makes fraud and errors easier to detect, and gives auditors a reliable basis for verifying that reported figures haven’t been altered without a record.
The core requirement, under Rule 3(1) of the Companies (Accounts) Rules, 2014, has applied since April 2023. This proviso mandates that companies must use accounting software with a non-disableable audit trail feature. What’s changed for FY 2025-26 is that auditors are now expected to verify preservation of the prior year’s trail as well, not just whether the feature ran during the current year.
To check if the accounting software has an audit trail, ask these three questions: Whether the audit trail feature is enabled and running by default, not something a user has to turn on; Whether it captures the timestamp, user ID, and before-and-after values for every edit; Whether there’s no setting anywhere in the software that lets an administrator disable it. If any of these can be switched off, the software isn’t compliant, regardless of what the vendor’s marketing claims.
No. Rule 3(1) of the Companies (Accounts) Rules, 2014 applies specifically to companies registered under the Companies Act, 2013. LLPs are governed by the Limited Liability Partnership Act and aren’t currently covered by this specific requirement, though LLPs still have their own separate books-of-account and audit obligations under LLP law.




