Audit trail in a loan management system: what Rule 3(1), RBI's technology directions and your auditor check
What a loan system's audit trail has to show under the Companies Act edit log rule, the auditor's Rule 11(g) report and RBI's 2026 NBFC technology directions.

Since the 2023-24 financial year, Indian companies that keep their books in accounting software must use software that records an audit trail of every transaction, logs each change with its date, and cannot have the trail switched off. The statutory auditor reports on it every year. RBI’s 2026 technology directions add audit trail duties for larger NBFCs. When the loan system holds the loan ledger, the trail may need to start there, and your auditor settles the scope.
If you sign off an NBFC’s books, your statutory auditor now reports every year on the software behind them: whether it kept an edit log, whether that log ran all year for every transaction, whether anyone tampered with it, and whether it was preserved.
For a lender, the income, receivable and provision lines in those books begin as loan events. A disbursal, a repayment, a day’s accrual, a charge, a waiver and a write-off each change the loan ledger before they change the general ledger. If the loan system posts those entries, or holds the ledger they are summarised from, the edit log the auditor asks about is likely to reach into it. A change made in the loan system and then summarised into the general ledger leaves no mark in the general ledger’s own log.
- The edit log is company law. Rule 3(1) has applied to accounting software from the financial year that began on 1 April 2023.
- The auditor reports on it. Rule 11(g) asks whether the trail ran all year, was left untampered and was preserved.
- RBI adds a layer-based duty. Base Layer NBFCs of ₹500 crore and above, and every Middle Layer and larger NBFC other than a Core Investment Company, need audit trails under the 2026 technology directions.
- No separate retention period. The trail follows the books, and the Companies Act keeps books for eight years.
- Corrections are the weak point. The original entry and the fix both have to stay visible, with who made the change and when.
What does Rule 3(1) require of accounting software?
An edit log nobody can switch off. The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014, inserted by G.S.R. 205(E) on 24 March 2021, says that every company using accounting software for its books of account must use software “which has a feature of recording audit trail of each and every transaction, creating an edit log of each change made in books of account along with the date when such changes were made and ensuring that the audit trail cannot be disabled”.
That sentence carries three duties:
- an audit trail of each and every transaction
- an edit log of each change to the books, with the date the change was made
- no way to disable the audit trail
The rule names the change and its date. It does not list the user, the old value or the reason. Rule 3(2) of the same rules, in force since 2014, already required that the information in electronic records “remain complete and unaltered”. Rule 3(1) added the software feature that records whether they did.
When did the duty start, and what does the auditor report?
The software duty was first due for the financial year beginning 1 April 2021. G.S.R. 247(E) of 1 April 2021 moved it to 1 April 2022, and G.S.R. 235(E) of 31 March 2022 moved it again to 1 April 2023. The financial year 2023-24 was the first one it covered.
The auditor’s side sits in Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, inserted by G.S.R. 206(E) on the same day as the software duty. It asks the auditor to state whether the company:
- used accounting software with an audit trail (edit log) feature
- operated that feature throughout the year for all transactions recorded in the software
- left the feature untampered
- preserved the audit trail “as per the statutory requirements for record retention”
G.S.R. 248(E) applied Rule 11(g) to financial years from 1 April 2022, a year before the duty it reports on. The first year in which both applied was the one that began on 1 April 2023.
Is a loan management system accounting software under the rule?
The rules do not define accounting software. What they cover is software a company uses “for maintaining its books of account”. A loan system can hold records that sit inside those books: the loan ledger by borrower, the interest accrued each day, the charges levied and waived, and the entries it posts to the general ledger heads. How each of those posts is set out in loan accounting entries for lenders.
If your loan system does that work, treat its edit log as part of the Rule 3(1) question, and agree the scope with your statutory auditor before the year closes rather than during the audit. If it only sends a daily summary to a separate general ledger, the general ledger’s log will show the summary entry. It cannot show the loan-level changes that produced it.
What do RBI’s technology directions add for NBFCs?
A second set of duties, sized by layer. On 31 July 2026 RBI issued the Reserve Bank of India (Non-Banking Financial Companies - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026. The same day it repealed the earlier IT framework and IT governance instructions as they applied to NBFCs, including the 2023 Master Direction. RBI’s press release describes the new directions as a consolidation of existing instructions on an “as is” basis.
The directions define an audit trail, borrowing from NIST, as “a chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result” (paragraph 4(1)). What each NBFC has to do depends on its layer:
| NBFC layer | What the directions require |
|---|---|
| Base Layer, assets under ₹500 crore (Chapter III) | An IT policy whose systems have maker-checker (paragraph 8(3)). No separate audit trail clause. |
| Base Layer, assets of ₹500 crore and above (Chapter IV) | Audit trails for IT assets that meet business, regulatory and legal needs, serve as forensic evidence and help resolve disputes, and record any unauthorised user activity (paragraph 21(8)). Maker-checker with approval by at least two people (21(6)). Documented authority for changes to key business parameters such as interest rates (21(3)). Audit-mode access for auditors and inspecting authorities (paragraph 57). |
| Middle Layer and above, excluding Core Investment Companies (Chapter V) | Audit logging and audit trails in every application that can access or affect critical or sensitive information (paragraph 109). Trails detailed enough for audits, forensic evidence and dispute resolution, including non-repudiation (110). Regular monitoring of trails and system logs (111). All activity of users with elevated access logged and reviewed (114). |
For a Base Layer NBFC of ₹500 crore and above, the interest rate example in paragraph 21(3) lands on the loan product: a change to a product’s rate needs clearly delegated, documented authority. Chapter V has no matching clause.
Chapter V also reaches past the loan system itself. Paragraph 99 requires a migration policy with audit trails of data migration and sign-offs at each stage. Paragraphs 119 and 120 rule out manual changes to data passing between critical applications and require automated transfers with audit trails.
The same directions go further than the edit log. Role-based access, privileged access supervision, multi-factor authentication and vendor risk are separate clauses in the same framework, and they are usually the bigger gap in a system that already logs every change correctly.
How long should the trail be kept?
Neither text sets a separate period for audit trails. RBI’s directions give none, and the only retention clause on logs is for outsourcing: a Base Layer NBFC of ₹500 crore and above (Chapter IV) that outsources technology must have the service provider retain audit trails and logs of administrative activity, accessible to the NBFC on approved requests (paragraph 62(2)).
The Companies Act gives the anchor. Rule 11(g) asks whether the trail was preserved as per the statutory requirements for record retention, and section 128(5) requires a company to keep its books of account for at least the eight financial years before the current one. Reading the trail as part of the books, eight years is the period to plan for. Rule 3(5) has also required a backup of electronic books on servers physically located in India since 2014, and G.S.R. 624(E), dated 5 August 2022, made that backup daily.
On that reading, this year’s entries in the edit log for a loan closed today stay retrievable for at least eight more financial years, including after the book moves to another system.
What should an edit log in a loan system record?
More than Rule 3(1)‘s minimum, if it is to answer an auditor, an RBI inspector or a borrower’s complaint. For each change:
- the loan, and the entry or field that changed, with its value before and after
- who made the change, or which process or agent did, and who approved it where maker-checker applies
- the date and time of the change, and the effective date where the two differ
- the reason, with a reference to the request, ticket or policy behind it
- for a derived figure such as accrued interest or days past due, the version of the rule that produced it
- for a correction, a link to the entry it corrects, with the original still readable
A loan system built audit-by-design writes these fields as part of each change rather than in a separate log someone has to remember to keep. The interest accrual post walks through the daily accrual behind the interest entries. RBI’s draft data governance guidance would add lineage from capture to report on top of this, as the data governance post sets out.
Where can a loan system’s audit trail break?
At the points where data changes without passing through the application’s own rules:
- Direct database fixes. A script run against the database can change a balance without writing to the application’s log. The trail then shows a new value with no change behind it. For Middle Layer and larger NBFCs, paragraph 114 requires that everything users with elevated access do on the system is logged and reviewed.
- Corrections made by overwriting. An entry corrected in place keeps only the new value, and the edit log has to carry the whole story on its own.
- Back-dated entries. A repayment recorded today with last month’s value date changes past interest and past days past due. A log that stores only one of the two dates loses the other.
- Bulk uploads. A file that changes thousands of accounts needs a record for each account changed, not a single line saying a file was loaded.
- Migration. When a book moves systems, the old trail has to move with it or stay retrievable for the retention period.
- Logging that can be turned off. An administrator setting that pauses the log fails the “cannot be disabled” test outright.
Where should a lender start the edit log?
A finance head who wants to hand the auditor the full history of any loan balance, without a week of log requests, has three places to keep the edit log.
- Rely on the audit trail in the accounting package. It covers what the general ledger records and needs no change to the loan system. Loan-level changes that were summarised before they reached the general ledger are not in it.
- Keep the edit log in the loan system, on every loan event, with corrections added as new entries beside the originals and each general ledger posting pointing back to the loan events behind it. It needs a loan system built that way, or a move to one. After that, the trail the auditor checks and the trail RBI’s directions ask for are one record, and a deterministic ledger lets any balance be re-derived from it. Direct database access still needs its own logging and review.
- Add a database-level change capture tool beside the existing loan system. It catches row changes, direct fixes included. It records what changed in a table, not the loan event or the reason, and it becomes one more store to preserve for eight years.
The second path is the most work up front, and it does not reach backwards. History from before the switch stays in the old system’s log, which has to remain retrievable for the rest of its retention period.
Lokta’s loan management system runs on a double-entry, event-sourced ledger that supports full replay of any book, with maker-checker and a full audit trail at every AUM. The same team wrote Apache Fineract, the open-source lending core, years earlier.
Frequently asked questions
What is the audit trail requirement under Rule 3(1) of the Companies (Accounts) Rules?
Since the financial year that began on 1 April 2023, every company that keeps its books of account in accounting software must use software that records an audit trail of each and every transaction, creates an edit log of each change to the books with the date it was made, and cannot have the audit trail disabled. The proviso was inserted on 24 March 2021 and deferred twice before it took effect. The statutory auditor reports on it each year under Rule 11(g) of the Companies (Audit and Auditors) Rules.
Does the audit trail rule apply to an NBFC's loan management system?
It can. Rule 3(1) covers accounting software used for maintaining the books of account, and the rules do not define accounting software. If the loan system holds the loan ledger, computes accruals and charges, or posts entries that form part of the books, its edit log is part of the question the auditor asks. Where the loan system only sends summaries to a separate general ledger, the general ledger's log cannot show the loan-level changes behind them. Settle the scope with your statutory auditor before the year closes.
How long must an audit trail be kept in India?
Neither the MCA rules nor RBI's NBFC technology directions set a separate period for the audit trail. Rule 11(g) asks the auditor whether the trail was preserved as per the statutory requirements for record retention. For company books, section 128(5) of the Companies Act requires books of account for at least the eight financial years before the current one to be kept, which is the natural period to apply. Where books are kept electronically, a backup must also sit on servers in India, taken daily.
What do RBI's 2026 technology directions say about audit trails for NBFCs?
It depends on the layer. Base Layer NBFCs with assets of ₹500 crore and above must keep audit trails for IT assets that meet business, regulatory and legal needs, serve as forensic evidence and record unauthorised user activity. Middle Layer and larger NBFCs, other than Core Investment Companies, must give every application that can access or affect critical or sensitive information audit logging and audit trails, detailed enough for audits and dispute resolution, and monitor them regularly. Base Layer NBFCs under ₹500 crore must have maker-checker in their IT systems, with no separate audit trail clause.
Sources:
- Ministry of Corporate Affairs, G.S.R. 205(E), Companies (Accounts) Amendment Rules, 2021, 24 March 2021: proviso to Rule 3(1). Deferred by G.S.R. 247(E), 1 April 2021, and G.S.R. 235(E), 31 March 2022.
- Ministry of Corporate Affairs, G.S.R. 206(E), Companies (Audit and Auditors) Amendment Rules, 2021, 24 March 2021: Rule 11(g). Start date set by G.S.R. 248(E), 1 April 2021.
- Ministry of Corporate Affairs, G.S.R. 624(E), Companies (Accounts) Fourth Amendment Rules, 2022, 5 August 2022: Rule 3(5) daily backup.
- Companies Act, 2013, section 128(5).
- RBI, Reserve Bank of India (Non-Banking Financial Companies - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, 31 July 2026: paragraphs 3, 4(1), 8, 21, 57, 62, 99, 109 to 111, 114, 119, 120 and 155.
- RBI, press release on the consolidation of supervisory instructions, 2026-2027/787, and the repeal circular, DoS.CO.PPG.66/11.01.005/2026-27, 31 July 2026.


