• Logistics and supply-chain services
  • IS audit / ITGC
  • India
  • ISO/IEC 27001:2022

ITGC Evidence for an Indian Subsidiary's SAP and Application Estate

The Indian subsidiary of a multinational logistics and supply-chain services group needed tested IT general controls across one SAP ERP, several operational applications and their infrastructure. JCSS Indonesia tested access, change, operations, backup and interface controls against ISO/IEC 27001:2022 Annex A and Rule 11(g) audit-trail requirements, delivering one evidenced domain-by-application matrix and a remediation tracker.

Engagement snapshot
Client archetypeIndian operating subsidiary of a multinational group; logistics and supply-chain services
Service lineIS audit: testing of IT general controls (ITGC)
JurisdictionsIndia (governing; fieldwork) · multinational group (reporting recipient)
Engagement modelFixed-scope ITGC review
Duration band1–3 months of fieldwork
FrameworksCompanies Act, 2013 s.143(3)(i) · ICAI Guidance Note on Audit of IFC over Financial Reporting · Rule 3(1) proviso and Rule 11(g) · ISO/IEC 27001:2022 Annex A
Team shapePartner-led; manager IS audit; senior IS auditor

What was the challenge?

The subsidiary reported through one SAP ERP and several satellite applications, and the controls beneath them had never been tested as one estate. Section 143(3)(i) of the Companies Act, 2013 requires the statutory auditor to report on the adequacy and operating effectiveness of internal financial controls. IT general controls underpin every automated control and system report.

ChallengeOperational realityBusiness risk
Mixed application estateSAP plus several operational and ancillary applications, each administered differentlyIT-dependent controls in untested applications cannot support reliance
Privileged accessPowerful SAP profiles; database, operating-system and directory administratorsFinancial data changed outside approval, without a trace
Audit trail (edit log)The audit trail must not be capable of being disabled; logging may sit in the application but not the databaseA modified Rule 11(g) comment in the auditor's report
Change pathSAP transports, direct changes and patching follow different routesAn unapproved change alters how transactions post
Backup and interfacesInterfaces feed SAP; restores are rarely rehearsedIncomplete postings or unrecoverable records

How did JCSS Indonesia approach it?

JCSS Indonesia, working with the JCSS India team, set scope by financial-reporting relevance and tested every in-scope system against one matrix.

  1. Scope. We selected applications and layers using the general IT control domains of the ICAI Guidance Note. Artefact: system inventory and scoping memo.

  2. Test matrix. We mapped five domains to ISO/IEC 27001:2022 Annex A controls 5.15, 5.18, 8.2, 8.5, 8.15, 8.13 and 8.32. Artefact: the coverage matrix below.

  3. SAP ERP. Test areas: privileged profiles such as SAP_ALL, the segregation-of-duties ruleset, logon parameters (login/min_password_lng, login/fails_to_user_lock), the STMS transport path, SCC4 client settings, table logging (rec/client) and the security audit log (rsau/enable).

  4. Infrastructure. The same domains covered the database, operating system, directory and network perimeter, with log settings compared to the CERT-In Directions of 28 Apr 2022.

  5. Audit trail. We tested operation at application and database level, following the ICAI Implementation Guide on Rule 11(g). Artefact: audit-trail position memo.

  6. Reporting. We classified deficiencies by domain and financial-reporting impact and issued a remediation tracker. JCSS Indonesia issued no opinion on internal financial controls.

Why this approach: a SAP-only review leaves untested the layers where privileged users can bypass application controls. We rejected an ISMS-readiness review: Annex A serves an information security management system, while this scope follows financial reporting.

Which controls were tested on each system?

Each of the five domains was tested on every in-scope layer, as the matrix shows.

Domain (Annex A)SAP ERPOther applicationsDatabase and OSDirectoryNetwork and perimeter
Access (5.15, 5.18, 8.2, 8.5)Users, roles, SAP_ALL, SoD rulesetUser lists, leaversPrivileged DBA and OS accountsAdministrator groupsAdministrator and remote access
Change (8.32)STMS path, SCC4 settingsRelease approvalsDirect changes, patchingGroup-policy changesFirewall rule changes
Operations (8.15)Security audit log, rec/clientJob and incident monitoringDatabase audit trail, log retentionEvent logsLog retention
Backup (8.13)Restore evidenceBackup scheduleBackup and restoreDirectory backupConfiguration backup
Interface (5.14, partial)Interface monitoringReconciliationsService accountsService accountsPort and segment rules

What were the results?

JCSS Indonesia delivered a complete, evidenced ITGC view of the estate on which management and the group reporting team can act.

ResultWhat was deliveredWhy it matters
CoverageEvery in-scope layer tested across five domains in one matrixTested and excluded areas are visible to any reviewer
Privileged accessPrivileged accounts and profiles tested at each layerA direct route to financial data now has evidence
Audit trailDocumented position at application and database levelEvidence pack built for the statutory auditor's Rule 11(g) work
RemediationDeficiency register with owners and a sequenced trackerManagement can close gaps before the next reporting cycle

Which frameworks and regulations applied?

Key takeaways for CFOs and heads of IT in Indian subsidiaries

  • Scope ITGC by financial-reporting relevance across the whole stack, because privileged access and audit trails sit beneath the application.
  • Evidence the audit trail at database level as well, since a direct database change reaches the books without touching the application.
  • Give reviewers the coverage matrix: a blank cell is a scope statement they must be able to see.

Frequently asked questions

What does an ITGC audit of SAP and other business applications cover in India?

It tests the general controls that every financial application depends on: access, change, operations, backup and interfaces. The ICAI Guidance Note on Audit of Internal Financial Controls over Financial Reporting groups them into access security, system change control, and data-centre and network operations. Each domain applies to the application, database, operating system, directory and network layers.

From which financial year must auditors report on audit trail under Rule 11(g)?

The proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 requires an audit trail that cannot be disabled for financial years commencing on or after 01 Apr 2023 (G.S.R. 235(E), 31 Mar 2022). The ICAI Implementation Guide (Revised 2024) therefore treats FY 2023-24 as the first year of reporting under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014.

Must the audit trail be enabled at database level?

Yes, where applicable. The ICAI Implementation Guide states that changes made directly at database level affect the books of account, so the audit trail is required there too. It also cites a minimum eight-year retention under section 128(5) of the Companies Act, 2013.

How long does an ITGC review of an SAP estate take in India?

Duration in India depends on the number of applications, environments and privileged users to be tested. In this engagement, fieldwork ran within a one-to-three-month band across one SAP ERP, several other applications and the supporting infrastructure. Scoping and access provisioning come first; deficiency reporting follows.

How this case study was prepared: client details are anonymised and the narrative is based on the engagement record. Regulations are described as in force at 02 Oct 2026; this page is not legal or tax advice.

Last reviewed: 02 Oct 2026. Reviewed by: Managing Partner.