What Is System Audit? A Practical Guide for Internal Auditors and CAs


A system audit, in the context of India, refers to a detailed examination and assessment of an employer's systems, techniques, and controls to make sure their effectiveness, compliance with applicable legal guidelines and guidelines, and identity of regions for improvement. It entails assessing diverse aspects of the machine, such as hardware and software program configurations, information security and integrity, user get right of entry to controls, backup and recuperation techniques, and adherence to applicable requirements and tips.

You are doing an internal audit at a small NBFC. Interest income ties perfectly with the ledger. Everything matches. Then you ask one question: who feeds the interest rate into the loan software?

Turns out the branch manager can edit that field himself. No approval. No log.

Your numbers were right. The system was not. That gap is exactly where system audit starts.

What Is System Audit? Simple Meaning

A system audit is an independent check of the software, IT processes and controls that a business runs on. It is also called an information system audit or IS audit.

A financial audit asks: are these numbers correct? A system audit asks: can this system be trusted to produce correct numbers every single time, even when nobody is watching?Think of it like this. A financial auditor tastes the food. A system auditor inspects the kitchen.

Why System Audit Is a Big Deal in India Right Now

Three reasons, and all three are recent.

1. RBI has made it compulsory for payment companies. Payment aggregators must get an annual system audit done by a CERT-In empanelled auditor. Separately, RBI's 2018 data localisation directive requires a System Audit Report (SAR) confirming that payment data is stored only in India. That report has to be approved by the board before it goes to RBI.

2. SEBI's CSCRF framework. Introduced in August 2024, it covers almost everyone in the securities market — exchanges, depositories, brokers, AMCs, RTAs, portfolio managers. Entities are slotted into five categories, and depending on the category, a cyber audit is required annually or half-yearly, again only from CERT-In empanelled auditors.

3. The audit trail rule under the Companies Act. Companies using accounting software must keep the edit log feature switched on, recording every change with date and user. Auditors now have to comment on it. That single rule turned a technical setting into an audit reporting matter.

What Does a System Auditor Actually Check?

This is the part most articles skip. Here is the real checklist.

Who has access

The most common finding in India, and the easiest to test. Pull the user list from the ERP and match it with the HR exit list.

Real example: 

An articled assistant who left a manufacturing company eight months ago still had an active Tally login with rights to create vendor masters. Nobody removed it because IT was never told about the exit.

Also check segregation of duties. If the same person can create a vendor, raise a purchase order and approve the payment, you do not have a control — you have a hope.

How changes are made to the software

Someone wanted the invoice discount logic changed. Who approved it? Was it tested before going live? Was it pushed on a Friday night straight into the live system?

Real example: A retail company changed its discount module and, by mistake, allowed manual override of the discount percentage. Three months of revenue leakage before anyone noticed.

Whether data can be quietly changed

Can someone backdate an entry? Can an invoice be deleted without a trace? Is the edit log switched on, or was it turned off because it was "slowing the system down"?

Backup and business continuity

Almost every company takes backups. Very few ever test whether the backup actually restores. Ask for the date of the last restoration test. The silence is usually your finding.

Data moving between systems

Payroll data flowing from the HR software to Tally. Sales data flowing from the app to the ERP.

Real example: An NBFC rounded interest to two decimals in one system and three in another. Two paise per account, across 2.4 lakh loan accounts, every month. Small number, ugly reconciliation.

The System Audit Process, Step by Step

  1. Understand the business — what systems are used, and what genuinely matters if it breaks.
  2. Scope and risk assessment — you cannot audit everything. Pick the systems that touch money, customer data or regulatory reporting.
  3. Walkthrough — sit with the user and watch one transaction travel end to end.
  4. Test the controls — sample checks, re-performance, observation, and system-generated reports.
  5. Document findings with root cause — not "access control weak", but why it was weak.
  6. Report and get management response — every finding needs an owner and a date.
  7. Follow-up — an unclosed finding is not a finding, it is a note.
  8. How Can a CA Get Into System Audit?

  • DISA — ICAI's post-qualification course in Information Systems Audit, open to members. It is the standard route for practising CAs, and it helps in bank audit empanelment.
  • CISA — ISACA's global certification. Wider recognition, and accessible to a broader group.
  • Start inside statutory audit. If you are in articleship, ask to be put on ITGC testing. That is the real entry door and it costs you nothing.
One honest point students should know: CERT-In empanelment is given to organisations, not individuals. So a CA firm cannot sign an RBI or SEBI mandated system audit report unless it is empanelled. DISA and CISA build your skill and open internal audit, IT risk advisory and bank audit work — they do not by themselves make you eligible for those specific regulatory reports.

Mistakes Juniors Make in Their First System Audit

  • Taking a screenshot as evidence without checking the date and username on it.
  • Reading the IT policy and testing the policy instead of testing what people actually do.
  • Writing a finding with no business impact. "Password policy not enforced" means nothing. "17 users share one admin password that can post journal entries" gets acted upon.
Quick FAQs

Is system audit only for banks and IT companies? No. Any business running on software has system risk. The mandate is heaviest in BFSI, but the work exists everywhere.

Do I need to know coding? No. You need to understand controls, ask sharp questions and read system reports. Excel skill helps far more than coding.

Can a fresher do system audit? Yes, as part of a team. Most people start with user access testing and grow from there.

CA Tushar Makkar
Author - Auditing in real life | Consulting in India, US, Europe and Middle East | Content creator | Ex-PwC | CA AIR 47 Nov' 17 | YouTuber 60k+ | Expertise in manage accounts and Audit.

Bridging Textbooks & Corporate Worlds |Exclusive Special offer | ENROLL NOW