1. Identify the records and transactions that constitute books of account.

  2. Identify the software used for processing and or storing data for creation and maintenance of books of account.

  3. Ensure such software have the audit trail feature.

  4. Ensure that the audit trail captures changes to each and every transaction of books of account i.e. When Changes were made, Who made those changes, what data was changed.

  5. Ensure that the audit trail feature is always enabled (not disabled) including at the database level (if applicable).

  6. Ensure that the audit trail is appropriately protected from any modification.

  7. Ensure that the audit trail is retained as per statutory requirements for record retention – eight years.

  8. Ensure that controls over maintenance and monitoring of audit trail and its feature are designed and operating effectively throughout the period of reporting.

  9. Ensures that the administrative access to the audit trail is restricted to authorized representatives.