IT General Controls (ITGC) audit, IT infrastructure assessment, and technology governance review. For banks, corporates, and any company with an IT audit trail requirement under the Companies Act 2013.
60+ IT audits delivered across 8 cities
The Companies Act 2013 (Section 143) requires audit trail for all computerized accounting systems. Rule 11(g) mandates companies to maintain audit trail of every transaction. For banks and NBFCs, RBI mandates IT audit as part of statutory audit. SEBI requires ITGC assessment for listed companies.
All companies using computerized accounting must maintain audit trail. Listed companies need ITGC assessment as part of statutory audit under SEBI guidelines.
IT audit covers core banking, internet banking, mobile banking, UPI, and all customer-facing digital channels. Part of annual statutory audit.
Companies Act audit trail requirement applies to all computerized transactions — inventory, billing, GST, payroll. Tally users must enable audit trail.
For SOC reporting, client assurance, and internal governance. Covers SDLC controls, change management, access controls, and deployment pipelines.
Evaluation of IT General Controls — access management, change management, computer operations, and program development.
Review of servers, network equipment, endpoints, cloud infrastructure, and data center controls.
Testing input/output/processing controls in business applications (ERP, CRM, banking systems).
Verification that all accounting software maintains proper audit trail as per Companies Act Rule 3(1).
Assessment of IT strategy, budget allocation, project management, and technology risk oversight.
Classified findings (Critical/High/Medium/Low) with specific remediation steps and implementation timeline.
Map IT environment, identify critical systems, define audit scope based on regulatory requirements and business risk.
Perform control testing, walkthrough procedures, sample transactions, review configurations, interview IT team.
Draft findings, discuss with management, finalize report with remediation plan. Deliver in statutory audit format if needed.
Government and corporate hub. Many NBFCs headquartered in Noida/Gurgaon. Strong fintech ecosystem in Delhi NCR.
| Company | Specialty | IT Audit Focus |
|---|---|---|
| ASC Group | EDP, IS, IT audit | Multi-city |
| Enterslice | Compliance consulting | Multi-city |
| CyberIntelsys | IT audit, VAPT | Mid-market |
| TCSA | Full-stack security | Enterprise |
| KhojKaro | IT Audit-first | Specialized + Affordable |
Competition level in Delhi: Medium-High. Most providers here focus on general cybersecurity or enterprise clients. No dedicated affordable IT Audit specialist exists.
IT department audit involves: (1) Review IT policies and governance structure, (2) Assess access controls and user management, (3) Test change management procedures, (4) Evaluate backup and recovery processes, (5) Check network security controls, (6) Verify software licensing compliance, (7) Review incident management, (8) Assess IT staffing and skills.
ITGC (IT General Controls) audit evaluates the foundational controls that support all IT applications. It covers four areas: access to programs and data, program changes, computer operations, and program development. ITGC forms the basis of reliance for financial statement audits.
Yes, indirectly. The Companies Act 2013 Rule 3(1) mandates audit trail for all computerized accounting. Statutory auditors must verify this trail exists and is tamper-proof. For banks and listed companies, IT audit is explicitly mandatory under RBI and SEBI guidelines.
Expect: (1) Document requests (policies, network diagrams, user lists), (2) System walkthroughs with IT team, (3) Sample testing of transactions and access, (4) Configuration reviews of critical systems, (5) Interviews with IT staff and management, (6) A findings report with risk ratings and recommendations.
IT audit costs in India range from Rs 40,000 for small single-location companies to Rs 5,00,000+ for large multi-location enterprises. Factors affecting cost: number of applications, locations, complexity of IT environment, and regulatory requirements. KhojKaro starts at Rs 40,000.
Yes. IT audit does not require a Chartered Accountant. It requires IT audit professionals with CISA, DISA, or equivalent certifications. However, when IT audit is part of statutory financial audit, the CA firm may engage IT auditors as specialists under SA 620 (Using Work of an Expert).
No obligation. We review your current setup, identify gaps, and tell you exactly what you need — in plain language, not jargon.
WhatsApp Us NowOr call: +91-8293037387 (Mon-Sat, 9am-7pm)