| Engagement snapshot | |
|---|---|
| Client archetype | Indian operating subsidiary of a multinational group; logistics and supply-chain services |
| Service line | IS audit: testing of IT general controls (ITGC) |
| Jurisdictions | India (governing; fieldwork) · multinational group (reporting recipient) |
| Engagement model | Fixed-scope ITGC review |
| Duration band | 1–3 months of fieldwork |
| Frameworks | Companies Act, 2013 s.143(3)(i) · ICAI Guidance Note on Audit of IFC over Financial Reporting · Rule 3(1) proviso and Rule 11(g) · ISO/IEC 27001:2022 Annex A |
| Team shape | Partner-led; manager IS audit; senior IS auditor |
What was the challenge?
The subsidiary reported through one SAP ERP and several satellite applications, and the controls beneath them had never been tested as one estate. Section 143(3)(i) of the Companies Act, 2013 requires the statutory auditor to report on the adequacy and operating effectiveness of internal financial controls. IT general controls underpin every automated control and system report.
| Challenge | Operational reality | Business risk |
|---|---|---|
| Mixed application estate | SAP plus several operational and ancillary applications, each administered differently | IT-dependent controls in untested applications cannot support reliance |
| Privileged access | Powerful SAP profiles; database, operating-system and directory administrators | Financial data changed outside approval, without a trace |
| Audit trail (edit log) | The audit trail must not be capable of being disabled; logging may sit in the application but not the database | A modified Rule 11(g) comment in the auditor's report |
| Change path | SAP transports, direct changes and patching follow different routes | An unapproved change alters how transactions post |
| Backup and interfaces | Interfaces feed SAP; restores are rarely rehearsed | Incomplete postings or unrecoverable records |
How did JCSS Indonesia approach it?
JCSS Indonesia, working with the JCSS India team, set scope by financial-reporting relevance and tested every in-scope system against one matrix.
Scope. We selected applications and layers using the general IT control domains of the ICAI Guidance Note. Artefact: system inventory and scoping memo.
Test matrix. We mapped five domains to ISO/IEC 27001:2022 Annex A controls 5.15, 5.18, 8.2, 8.5, 8.15, 8.13 and 8.32. Artefact: the coverage matrix below.
SAP ERP. Test areas: privileged profiles such as SAP_ALL, the segregation-of-duties ruleset, logon parameters (login/min_password_lng, login/fails_to_user_lock), the STMS transport path, SCC4 client settings, table logging (rec/client) and the security audit log (rsau/enable).
Infrastructure. The same domains covered the database, operating system, directory and network perimeter, with log settings compared to the CERT-In Directions of 28 Apr 2022.
Audit trail. We tested operation at application and database level, following the ICAI Implementation Guide on Rule 11(g). Artefact: audit-trail position memo.
Reporting. We classified deficiencies by domain and financial-reporting impact and issued a remediation tracker. JCSS Indonesia issued no opinion on internal financial controls.
Why this approach: a SAP-only review leaves untested the layers where privileged users can bypass application controls. We rejected an ISMS-readiness review: Annex A serves an information security management system, while this scope follows financial reporting.
Which controls were tested on each system?
Each of the five domains was tested on every in-scope layer, as the matrix shows.
| Domain (Annex A) | SAP ERP | Other applications | Database and OS | Directory | Network and perimeter |
|---|---|---|---|---|---|
| Access (5.15, 5.18, 8.2, 8.5) | Users, roles, SAP_ALL, SoD ruleset | User lists, leavers | Privileged DBA and OS accounts | Administrator groups | Administrator and remote access |
| Change (8.32) | STMS path, SCC4 settings | Release approvals | Direct changes, patching | Group-policy changes | Firewall rule changes |
| Operations (8.15) | Security audit log, rec/client | Job and incident monitoring | Database audit trail, log retention | Event logs | Log retention |
| Backup (8.13) | Restore evidence | Backup schedule | Backup and restore | Directory backup | Configuration backup |
| Interface (5.14, partial) | Interface monitoring | Reconciliations | Service accounts | Service accounts | Port and segment rules |
What were the results?
JCSS Indonesia delivered a complete, evidenced ITGC view of the estate on which management and the group reporting team can act.
| Result | What was delivered | Why it matters |
|---|---|---|
| Coverage | Every in-scope layer tested across five domains in one matrix | Tested and excluded areas are visible to any reviewer |
| Privileged access | Privileged accounts and profiles tested at each layer | A direct route to financial data now has evidence |
| Audit trail | Documented position at application and database level | Evidence pack built for the statutory auditor's Rule 11(g) work |
| Remediation | Deficiency register with owners and a sequenced tracker | Management can close gaps before the next reporting cycle |
Which frameworks and regulations applied?
- Companies Act, 2013, s.143(3)(i) and the ICAI Guidance Note on Audit of IFC over Financial Reporting (2015): reporting on internal financial controls; general IT control domains.
- Rule 3(1) proviso, Companies (Accounts) Rules, 2014 (G.S.R. 235(E)): audit trail that cannot be disabled, from FY 2023-24.
- Rule 11(g), Companies (Audit and Auditors) Rules, 2014; ICAI Implementation Guide (Revised 2024): audit-trail reporting.
- ISO/IEC 27001:2022: Annex A control references.
- CERT-In Directions No. 20(3)/2022: rolling 180-day log retention within India.
- SAP documentation: logon parameters, rec/client, STMS.
Key takeaways for CFOs and heads of IT in Indian subsidiaries
- Scope ITGC by financial-reporting relevance across the whole stack, because privileged access and audit trails sit beneath the application.
- Evidence the audit trail at database level as well, since a direct database change reaches the books without touching the application.
- Give reviewers the coverage matrix: a blank cell is a scope statement they must be able to see.
Frequently asked questions
What does an ITGC audit of SAP and other business applications cover in India?
It tests the general controls that every financial application depends on: access, change, operations, backup and interfaces. The ICAI Guidance Note on Audit of Internal Financial Controls over Financial Reporting groups them into access security, system change control, and data-centre and network operations. Each domain applies to the application, database, operating system, directory and network layers.
From which financial year must auditors report on audit trail under Rule 11(g)?
The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 requires an audit trail that cannot be disabled for financial years commencing on or after 01 Apr 2023 (G.S.R. 235(E), 31 Mar 2022). The ICAI Implementation Guide (Revised 2024) therefore treats FY 2023-24 as the first year of reporting under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014.
Must the audit trail be enabled at database level?
Yes, where applicable. The ICAI Implementation Guide states that changes made directly at database level affect the books of account, so the audit trail is required there too. It also cites a minimum eight-year retention under section 128(5) of the Companies Act, 2013.
How long does an ITGC review of an SAP estate take in India?
Duration in India depends on the number of applications, environments and privileged users to be tested. In this engagement, fieldwork ran within a one-to-three-month band across one SAP ERP, several other applications and the supporting infrastructure. Scoping and access provisioning come first; deficiency reporting follows.
