Information System Audit
An information system (IS) audit tests whether your IT systems keep data safe, accurate and available, and whether they meet the rules your regulator sets. Banks and NBFCs must run IS audits under the RBI’s cybersecurity and technology risk directions of 31 July 2026, and every company using accounting software must keep an audit trail that cannot be switched off.
What it is
An IS audit is an independent review of the controls around your IT systems. It asks simple questions. Who can log in, and should they? Who changed what, and was it approved? Are backups taken and do they actually restore? Do the numbers coming out of the ERP match what went in?
For banks, NBFCs and other entities the RBI regulates, IS audit sits inside the RBI’s Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued on 31 July 2026. They replaced the Master Direction on IT Governance of 7 November 2023. For companies, the audit trail rule in the Companies (Accounts) Rules, 2014 makes the controls inside accounting software a statutory audit issue. For everyone else, it is a health check that pairs well with your internal audit.
Who it applies to
You are a bank or RBI-regulated NBFC
The RBI issued separate Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 for commercial banks and for NBFCs, among other entity types. The IS audit can be done internally or by an external agency, and larger entities have the board’s audit committee oversee it.
You keep books in accounting software
Every company that keeps its books in software must use one that records an audit trail of every change, which cannot be disabled. The statutory auditor reports on it each year.
You hold customer data
Fintechs, SaaS firms, hospitals and e-commerce sellers handle personal data under the Digital Personal Data Protection Act, 2023 and must report cyber incidents to CERT-In.
Why it matters
Find the gaps before the regulator does
RBI inspections, SEBI cyber audits and statutory auditors now all test IT controls.
Make your books reliable
If anyone can edit last year’s entries or the audit trail is off, your auditor cannot rely on the books. Weak access control is also where most frauds start.
Keep the business running
A backup that does not restore, or one shared admin password, can stop operations for days.
Documents required
Policies and structure
- IT and information security policies
- Board or committee minutes on IT matters
- Previous IS audit or inspection reports
System details
- List of applications, servers and cloud services
- Network diagram
- User lists with access rights for key systems
- Change and incident logs
Vendors and continuity
- Contracts and SLAs with IT vendors
- Backup schedule and restore test records
- Business continuity and disaster recovery plans
What an IS audit covers
| Area | What we test |
|---|---|
| Access control | User creation and removal, shared IDs, admin rights, password rules |
| Change management | Whether software changes are approved, tested and logged |
| Audit trail and logs | Edit logs in accounting software, log retention and review |
| Backup and recovery | Backup frequency, off-site copies, restore tests, DR drills |
| Outsourcing | Vendor contracts, access given to vendors, vendor audit reports |
| Incident handling | How incidents are logged, escalated and reported to CERT-In |
The CERT-In directions of 28 April 2022, issued under Section 70B(6) of the IT Act, 2000, require cyber incidents to be reported within six hours of noticing them. Logs must be kept for a rolling 180 days within India, and system clocks synchronised with the NTP servers of NIC or NPL.
Here is the catch with outsourcing in any information system audit. An NBFC that runs its loan book on vendor-hosted software still owns the risk under the RBI directions, so we review what the vendor can access and what its contract promises.
How it works
Agree the scope with you
We start from your regulator’s requirements and your own risks, and agree which systems, locations and vendors are in scope.
Walk through the systems
We meet the IT team and process owners, collect evidence and understand how data moves from entry to the final reports.
Test the controls on samples
We test samples: leavers who still have access, unapproved changes, backups never restored, audit trail settings. Picture a Faridabad manufacturer whose accountant left last year but whose Tally login still works. It is a common finding, and an easy one to fix.
Report with ratings and actions
Each finding gets a risk rating, the evidence and a practical fix, discussed with management before the report goes to the audit committee or board.
Recheck the high-risk fixes
We recheck the high-risk findings after you fix them, so the next audit or inspection starts clean.
Timelines
RBI-regulated entities
Under the 31 July 2026 NBFC directions, IS audit is done at least once a year, ideally before the statutory audit. Critical systems get a vulnerability assessment every six months and penetration testing every 12 months. DR drills for critical systems are held twice a year.
Incident reporting
Cyber incidents go to CERT-In within six hours of being noticed. RBI-regulated NBFCs also report to the RBI within six hours of detection. Under the DPDP Rules, 2025, a personal data breach is reported to the Data Protection Board with details within 72 hours.
Companies
The audit trail must run all year, and the statutory auditor reports on it every year. Books, including the audit trail, are kept for eight financial years.
What happens if controls fail
Regulatory action
The RBI can penalise regulated entities that breach its directions, and inspection findings go to the board. The 31 July 2026 directions took effect on issue, so older IT governance checklists need updating. SEBI-regulated entities face similar action under their cyber framework.
Data protection penalties
Under the DPDP Act, failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore.
Adverse audit reporting
If the audit trail was disabled or not kept, the statutory auditor must say so under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014. Lenders and investors read that remark.
Frequently asked questions
Is an information system audit mandatory?
It is mandatory for some entities and a sensible check for the rest. Banks and NBFCs must have IS audit under the RBI’s Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, which replaced the 2023 IT governance direction on 31 July 2026. SEBI-regulated entities have cyber audits under their own framework. For other companies, the audit trail rule and DPDP duties make an IS review sensible. We tell you which rules apply to your information system audit before we scope the work.
What is the audit trail requirement for companies?
Since 1 April 2023, every company keeping books in accounting software must use software that records an audit trail of each transaction and every edit, with the date of the change, and the feature cannot be disabled. The statutory auditor reports on this under Rule 11(g) each year. The trail must be kept for eight years like the books. We check your settings and logs before your auditor does.
Who conducts the IS audit for an RBI-regulated NBFC?
The NBFC owns it. Under the RBI’s 31 July 2026 directions, IS audit can be carried out internally or by an external agency, and larger NBFCs have the board’s audit committee oversee it. Responsibility stays with the NBFC. We prepare the evidence, coordinate the review and help you track the fixes; where the work needs a qualified professional’s signature, that professional signs.
How often should an IS audit be done?
For RBI-regulated NBFCs, the 31 July 2026 directions expect IS audit at least once a year, ideally before the statutory audit, with continuous auditing encouraged for critical systems. For other businesses, once a year is a sensible minimum, and again after a major system change such as a new ERP. We help you set a cycle that matches your risks.
Can you do the CERT-In empanelled cyber audit SEBI requires?
No. SEBI’s Cybersecurity and Cyber Resilience Framework of 20 August 2024 needs periodic audits by a CERT-In empanelled IS auditing organisation, and that certifying audit must come from one. What we do is the readiness work: gap review, policies, evidence and fixing findings, so the empanelled auditor’s visit goes smoothly. We coordinate with the empanelled firm you appoint.
Is an IS audit the same as ISO 27001 certification?
No. An IS audit is a review that reports findings to your management or regulator. ISO 27001 certification is a certificate issued by an accredited certification body after it audits your information security management system against the standard. The two overlap a lot. Many businesses use an IS audit as the first step towards ISO 27001.
What does CERT-In require us to do?
Under the CERT-In directions of 28 April 2022, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents within six hours of noticing them. They must keep logs for a rolling 180 days within India and synchronise clocks with NIC or NPL time servers. These three points are easy to check, and we test all of them in our audit.
Is there a government fee for an IS audit?
No. An IS audit is a professional engagement, and no government fee applies. You pay our fee, which depends on the number of systems, locations and vendors in scope. Penetration testing, if you need it, is done by a specialist security firm and quoted separately. We fix the scope with you first, so the quote has no surprises.
What it costs
Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.
No government fee applies to an IS audit.
Ready to begin?
Tell us your regulator and your main systems, and we will propose an IS audit scope that matches both.