Choose your language

अपनी भाषा चुनें

KhojKaro
Free Assessment
Companies Act + RBI Compliance

IT Audit & ITGC Assessment for Indian Companies

IT General Controls (ITGC) audit, IT infrastructure assessment, and technology governance review. For banks, corporates, and any company with an IT audit trail requirement under the Companies Act 2013.

60+ IT audits delivered across 8 cities

IT Audit Is Now a Legal Requirement

The Companies Act 2013 (Section 143) requires audit trail for all computerized accounting systems. Rule 11(g) mandates companies to maintain audit trail of every transaction. For banks and NBFCs, RBI mandates IT audit as part of statutory audit. SEBI requires ITGC assessment for listed companies.

MCA
Audit trail mandatory for all companies using accounting software (Section 143)
Companies (Accounts) Rules 2021, Rule 3(1)
RBI
IT audit as component of statutory audit for banks
RBI Guideline on IT Examination
SEBI
ITGC assessment for listed companies and market intermediaries
SEBI Circular CIR/CFD/CMD1/2024

Who Needs IT Audit?

All companies using computerized accounting must maintain audit trail. Listed companies need ITGC assessment as part of statutory audit under SEBI guidelines.

Applies if: You use Tally, SAP, Oracle, or any ERP for accounting

IT audit covers core banking, internet banking, mobile banking, UPI, and all customer-facing digital channels. Part of annual statutory audit.

Applies if: You operate any digital banking channel

Companies Act audit trail requirement applies to all computerized transactions — inventory, billing, GST, payroll. Tally users must enable audit trail.

Applies if: You process invoices, inventory, or payroll digitally

For SOC reporting, client assurance, and internal governance. Covers SDLC controls, change management, access controls, and deployment pipelines.

Applies if: You develop software or provide IT services to clients

IT Audit Deliverables

ITGC Assessment

Evaluation of IT General Controls — access management, change management, computer operations, and program development.

IT Infrastructure Audit

Review of servers, network equipment, endpoints, cloud infrastructure, and data center controls.

Application Controls Review

Testing input/output/processing controls in business applications (ERP, CRM, banking systems).

Audit Trail Compliance Check

Verification that all accounting software maintains proper audit trail as per Companies Act Rule 3(1).

IT Governance Report

Assessment of IT strategy, budget allocation, project management, and technology risk oversight.

Findings & Remediation Plan

Classified findings (Critical/High/Medium/Low) with specific remediation steps and implementation timeline.

IT Audit Pricing

SME
Rs 40,000 - Rs 80,000
Small companies (Tally/basic ERP, single location)
  • ITGC assessment
  • Audit trail compliance check
  • Basic infrastructure review
  • 2-week delivery
Enterprise
Rs 2,00,000 - Rs 5,00,000
Large corporates, banks, listed companies
  • Everything in Mid-Market
  • Multi-location coverage
  • Cloud infrastructure audit
  • SEBI ITGC compliance
  • Board-level presentation
  • Quarterly follow-ups

Structured IT Audit in 2-4 Weeks

Week 1

Scoping & Understanding

Map IT environment, identify critical systems, define audit scope based on regulatory requirements and business risk.

Week 2-3

Testing & Evidence

Perform control testing, walkthrough procedures, sample transactions, review configurations, interview IT team.

Week 3-4

Reporting

Draft findings, discuss with management, finalize report with remediation plan. Deliver in statutory audit format if needed.

2-4 weeks
KhojKaro
5-8 weeks
Others
50% faster delivery

Frequently Asked Questions

IT department audit involves: (1) Review IT policies and governance structure, (2) Assess access controls and user management, (3) Test change management procedures, (4) Evaluate backup and recovery processes, (5) Check network security controls, (6) Verify software licensing compliance, (7) Review incident management, (8) Assess IT staffing and skills.

ITGC (IT General Controls) audit evaluates the foundational controls that support all IT applications. It covers four areas: access to programs and data, program changes, computer operations, and program development. ITGC forms the basis of reliance for financial statement audits.

Yes, indirectly. The Companies Act 2013 Rule 3(1) mandates audit trail for all computerized accounting. Statutory auditors must verify this trail exists and is tamper-proof. For banks and listed companies, IT audit is explicitly mandatory under RBI and SEBI guidelines.

Expect: (1) Document requests (policies, network diagrams, user lists), (2) System walkthroughs with IT team, (3) Sample testing of transactions and access, (4) Configuration reviews of critical systems, (5) Interviews with IT staff and management, (6) A findings report with risk ratings and recommendations.

IT audit costs in India range from Rs 40,000 for small single-location companies to Rs 5,00,000+ for large multi-location enterprises. Factors affecting cost: number of applications, locations, complexity of IT environment, and regulatory requirements. KhojKaro starts at Rs 40,000.

Yes. IT audit does not require a Chartered Accountant. It requires IT audit professionals with CISA, DISA, or equivalent certifications. However, when IT audit is part of statutory financial audit, the CA firm may engage IT auditors as specialists under SA 620 (Using Work of an Expert).

Get Your Free IT Audit Assessment

No obligation. We review your current setup, identify gaps, and tell you exactly what you need — in plain language, not jargon.

WhatsApp Us Now

Or call: +91-8293037387 (Mon-Sat, 9am-7pm)