Audit trails for record changes.
1. Meaning of Audit Trail for Record Changes
An audit trail for record changes is a chronological and secure history showing how a record has been created, modified, approved, deleted, or otherwise acted upon.
In simple terms, an audit trail answers:
- Who changed the record?
- What was changed?
- When was it changed?
- What was the original value?
- What is the new value?
- Why was the change made?
- Who approved the change, where approval is required?
- Was the change made through an authorised account?
- Can the original information still be reconstructed?
For example, if an HR system originally records an employee's salary as ₹30,000 and someone changes it to ₹40,000, the audit trail should ideally show:
Employee ID → Original salary ₹30,000 → New salary ₹40,000 → User ID → Date/time → Reason → Approval → System record.
The purpose is not merely to record that a change occurred. The objective is to preserve integrity, accountability, traceability and reliability of the record.
Indian judicial decisions concerning electronic records repeatedly emphasise authenticity and protection against alteration or tampering.
2. Why Audit Trails Are Important
Audit trails are particularly important where records may affect:
- employee salary;
- attendance;
- leave;
- performance ratings;
- disciplinary proceedings;
- recruitment decisions;
- promotions;
- termination;
- payroll;
- statutory compliance;
- financial transactions;
- customer records;
- medical or benefits records;
- contracts;
- approvals;
- investigations;
- litigation.
Without an audit trail, an organisation may have difficulty proving whether a record represents the original information or a subsequently altered version.
A properly designed audit trail therefore functions as a form of digital accountability mechanism.
3. Essential Elements of an Audit Trail
A good audit trail should normally contain the following information:
| Element | Purpose |
|---|---|
| Unique record ID | Identifies the affected record |
| User ID | Identifies who made the change |
| Date and time | Establishes when the change occurred |
| Original value | Preserves the previous information |
| New value | Shows the amended information |
| Field changed | Identifies precisely what was modified |
| Reason for change | Explains why modification occurred |
| Approval information | Establishes supervisory authorisation |
| IP/device information | May help establish source of access |
| Transaction ID | Connects related system activities |
| System-generated timestamp | Prevents reliance solely on user-entered dates |
| Deletion information | Shows whether and when information was deleted |
| Failed access attempts | Helps detect unauthorised activity |
A useful audit trail therefore creates a complete chain of custody for data.
4. Audit Trail and Record Integrity
Record integrity means that the record remains:
- complete;
- accurate;
- reliable;
- traceable;
- protected against unauthorised alteration.
An audit trail should therefore preferably be:
- automatically generated;
- access-controlled;
- time-stamped;
- protected from ordinary users;
- resistant to alteration;
- backed up;
- periodically reviewed;
- retained for the required period.
The ICAI has described an audit trail as a chronological record capturing changes, including who made the change, when it was made and what fields were changed.
5. Audit Trail Should Not Be Editable by Ordinary Users
One of the most important principles is separation between the operational record and its audit history.
For example, an HR administrator may be permitted to correct an employee's designation, but should not be permitted to erase the audit entry showing that the designation was changed.
Otherwise, an employee could potentially:
- change a record;
- change the audit log;
- delete evidence of the change;
- claim that the altered record was original.
Therefore, audit logs should ideally have stronger access restrictions than ordinary business records.
Indian regulatory requirements for accounting software specifically require audit-trail functionality and an edit log of changes, with safeguards against disabling the audit trail.
6. Audit Trails Under Indian Corporate Law
A particularly important statutory requirement arises under the Companies (Accounts) Rules, 2014.
For companies using accounting software for maintaining books of account, the applicable requirement includes software capable of:
- recording an audit trail of each transaction;
- creating an edit log of each change;
- recording the date of changes; and
- ensuring that the audit trail cannot be disabled.
The electronic records are also required to remain complete and unaltered.
Thus, for corporate accounting records, audit trails are not merely a recommended internal-control practice; they can form part of the organisation's statutory compliance framework.
7. Audit Trail and Electronic Evidence
Audit trails become particularly significant during litigation.
Suppose an employee alleges:
"My attendance record was changed after I complained about my manager."
If the organisation produces only the current attendance record, the employee may question whether it was subsequently modified.
An audit trail could demonstrate:
- original attendance entry;
- date of original entry;
- user who entered it;
- subsequent modification;
- date and time of modification;
- reason for modification;
- approving authority.
This can substantially improve the evidentiary reliability of the record.
The Supreme Court has repeatedly recognised that electronic records are particularly susceptible to tampering, alteration, transposition and excision, making authenticity and reliability important considerations.
8. Audit Trail in HR and Employment Records
For HR systems, audit trails are particularly useful for:
Recruitment
Recording:
- candidate score;
- interview assessment;
- changes in ranking;
- selection decision;
- approval;
- modification of recruitment data.
Attendance
Recording:
- original attendance;
- correction;
- person making correction;
- reason for correction;
- approval.
Payroll
Recording:
- salary changes;
- deductions;
- incentives;
- overtime;
- arrears;
- bank-account modifications.
Disciplinary proceedings
Recording:
- complaint;
- inquiry documents;
- notices;
- evidence uploads;
- findings;
- approvals;
- disciplinary orders.
Leave
Recording:
- leave application;
- approval;
- rejection;
- subsequent modification;
- cancellation.
This becomes especially important where an employment dispute later reaches a labour authority, tribunal or court.
9. Audit Trail and Tampering
There are two different concepts:
A. Legitimate correction
An authorised employee discovers that an employee's date of joining was incorrectly entered.
The system changes:
01-06-2026 → 01-07-2026
The audit trail records:
User: HR001
Date/time: 05-07-2026, 11:32 AM
Original: 01-06-2026
Revised: 01-07-2026
Reason: Correction based on appointment letter
Approved by: HR Manager
This is a controlled correction.
B. Unauthorised alteration
An employee's performance rating was originally "Excellent", but someone subsequently changes it to "Poor" without authorisation and without preserving the original record.
This raises serious concerns about:
- data integrity;
- procedural fairness;
- authenticity;
- possible manipulation;
- evidentiary reliability.
10. Six Important Case Laws
1. Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473
Principle
The Supreme Court laid down important principles concerning the admissibility of electronic records.
The Court emphasised the statutory requirements governing electronic evidence and recognised the particular susceptibility of electronic records to alteration and tampering.
Relevance to audit trails
An audit trail helps establish:
- source of the record;
- authenticity;
- continuity;
- reliability;
- absence or detection of unauthorised alteration.
Therefore, where an electronic record is relied upon in litigation, a properly maintained audit history can become highly important in establishing its credibility.
2. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1
This is one of the most important Indian decisions concerning electronic evidence.
The Supreme Court reaffirmed the principles in Anvar P.V. and dealt extensively with proof of electronic records.
The Court recognised that electronic records are susceptible to tampering and alteration and emphasised safeguards relating to their authenticity.
Relevance to audit trails
The judgment demonstrates why organisations should preserve reliable system-generated evidence showing:
- who created a record;
- who modified it;
- when modification occurred;
- how the electronic record was maintained.
A properly preserved audit trail can support the organisation's claim that its electronic records are genuine and traceable.
3. Tomaso Bruno v. State of Uttar Pradesh, (2015) 7 SCC 178
The Supreme Court considered the importance of scientific and electronic evidence, including CCTV footage.
The Court stressed the relevance of electronic evidence and observed that technological evidence can assist in establishing facts.
Relevance to audit trails
The principle is highly relevant to modern organisations because important events are increasingly recorded electronically.
Examples include:
- CCTV systems;
- access-control systems;
- HR databases;
- email systems;
- payroll software;
- ERP systems.
Where such systems generate records, organisations should preserve them in a manner that permits verification of their authenticity.
4. Shafhi Mohammad v. State of Himachal Pradesh, (2018)
The Supreme Court considered issues relating to electronic evidence and authenticity.
The decision discussed safeguards against tampering and recognised that electronic evidence should be assessed with attention to authenticity and reliability.
However, its approach regarding Section 65B certification was subsequently reconsidered and overruled on that point by the larger Bench in Arjun Panditrao Khotkar.
Relevance to audit trails
The case is useful for understanding the broader judicial concern that electronic evidence must be capable of being authenticated.
For audit purposes, this means an organisation should not merely maintain the latest version of a record; it should preserve information demonstrating how the record came into existence and how it was subsequently modified.
5. State (NCT of Delhi) v. Navjot Sandhu @ Afsan Guru, (2005) 11 SCC 600
This case involved extensive consideration of electronic records, including telephone-related electronic evidence.
Although later developments in the law altered aspects of the approach to admissibility of electronic records, the case remains historically important in the development of Indian electronic-evidence jurisprudence.
Relevance to audit trails
It illustrates the growing importance of electronically generated records in judicial proceedings.
For organisations, the lesson is that system-generated records should be capable of being traced to:
- their source;
- the relevant system;
- the relevant transaction;
- the relevant period;
- the person or process responsible.
6. Sonu @ Amar v. State of Haryana, (2017) 8 SCC 570
The Supreme Court considered objections concerning electronic records and the procedural requirements governing their proof.
The decision also discussed the importance of raising objections concerning the mode of proof at the appropriate stage.
Relevance to audit trails
For organisations, the broader lesson is the importance of maintaining electronic records in a manner that permits their authenticity and method of creation to be demonstrated when challenged.
An audit trail can provide important supporting evidence concerning the history of a record.
11. Additional Case Law: Tukaram S. Dighole v. Manikrao Shivaji Kokate, (2010) 4 SCC 329
The Supreme Court recognised that modern technological devices can be used as evidence but also acknowledged their susceptibility to tampering. The Court emphasised that authenticity and accuracy must be carefully assessed.
Audit relevance
This principle directly supports the need for controls such as:
- immutable logs;
- access restrictions;
- timestamps;
- authentication;
- preservation of original values;
- independent review.
12. Audit Trail and Burden of Proving Authenticity
An audit trail does not automatically make every electronic record legally conclusive.
Rather, it helps establish a credible evidentiary history.
A court may consider:
- whether the system was reliable;
- who controlled the system;
- whether records could be altered;
- whether alterations were logged;
- whether access was restricted;
- whether the record was preserved properly;
- whether there is evidence of manipulation.
Therefore, an organisation should never assume:
"The computer generated it, so it must be correct."
Instead, it should be able to demonstrate:
"This is the record, this is how it was created, this is who changed it, this is when it was changed, this is why it was changed, and the system preserved the history of that change."
13. Audit Trail Controls
An effective audit system should implement the following controls.
1. Unique user accounts
Employees should not share login credentials.
2. Role-based access
Users should only be able to modify records necessary for their functions.
3. Automatic timestamps
The system should automatically record date and time.
4. Original-value preservation
The previous value should not simply disappear after modification.
5. Change-value preservation
The revised value should be recorded.
6. Reason-for-change requirement
For sensitive records, the user should be required to provide a reason.
7. Approval controls
High-risk changes should require independent approval.
8. Immutable audit logs
Ordinary users should not be able to edit or delete audit history.
9. Periodic audit-log review
Internal audit should identify unusual modifications.
10. Backup and retention
Audit logs should be retained for an appropriate period and protected from loss.
14. Red Flags During an Audit
An auditor should investigate situations such as:
- audit trail is disabled;
- users share passwords;
- administrator can delete audit logs;
- records are modified without reasons;
- large numbers of changes occur immediately before an audit;
- employee records are changed after a dispute begins;
- timestamps appear inconsistent;
- original values cannot be retrieved;
- audit logs contain gaps;
- terminated employees continue to access the system;
- one person creates and approves the same change;
- unusual changes occur outside normal working hours;
- multiple records are changed simultaneously without a documented business reason.
These may indicate weak internal controls or potential manipulation.
15. Example: HR Record Change
Suppose an employee's disciplinary record originally states:
"Warning issued – 10 August."
Later, the record is changed to:
"Final warning issued – 10 August."
A robust audit trail should show:
| Item | Audit information |
|---|---|
| Record | Employee disciplinary record |
| Original | Warning |
| Revised | Final warning |
| User | HR Manager ID |
| Date/time | 15 August, 3:25 PM |
| Reason | Correction following management review |
| Approval | Head HR |
| Supporting document | Management order |
| Audit-log status | Non-editable |
If the employee subsequently challenges the disciplinary action, this audit history can help demonstrate when and why the change occurred.
16. Difference Between Audit Trail and Change Log
The terms are sometimes used interchangeably, but they can have different practical meanings.
Change Log
Usually records modifications to a particular record.
Audit Trail
A broader chronological history capable of showing the sequence of activities surrounding records or transactions.
For example:
Change log:
Salary changed ₹30,000 → ₹35,000.
Audit trail:
HR executive accessed employee record → salary field changed → approval request generated → manager approved → payroll recalculated → payslip generated.
Thus, an audit trail can provide a much more complete reconstruction of an event.
17. Importance for Internal Audit
During an internal audit, the auditor should ask:
- Does the system automatically maintain audit trails?
- Can audit trails be disabled?
- Who can access audit logs?
- Can administrators modify audit logs?
- Are original values preserved?
- Are changed values preserved?
- Are date and time automatically recorded?
- Is the identity of the user recorded?
- Are changes supported by reasons?
- Are high-risk changes independently approved?
- Are audit logs regularly reviewed?
- Are suspicious changes investigated?
- Are logs backed up?
- Are retention requirements followed?
- Can the organisation reproduce the complete history of an important record?
18. Legal Significance
The legal importance of audit trails can be summarised through four principles:
Authenticity
Can the organisation demonstrate that the record is genuine?
Integrity
Can it demonstrate that the record was not improperly altered?
Accountability
Can it identify who performed an action?
Traceability
Can the complete history of the record be reconstructed?
These principles are particularly important because the Supreme Court has recognised the vulnerability of electronic records to alteration and has developed safeguards concerning their authenticity and proof.
19. Best-Practice Audit Trail Model
A strong model can be represented as:
Create → Authenticate → Record → Modify → Log → Approve → Review → Preserve
Every significant modification should leave a permanent evidentiary footprint.
For high-risk HR or corporate records, the ideal model is:
Original record + authorised modification + reason + timestamp + user identity + approval + immutable audit log + retention
This creates a defensible record-management system.
20. Conclusion
Audit trails for record changes are a fundamental component of modern record governance and internal control. They allow an organisation to reconstruct the history of a record and determine whether a modification was legitimate or unauthorised.
For HR and employment-related systems, audit trails are particularly valuable for attendance, payroll, recruitment, disciplinary records, performance assessments, leave, promotions and termination records.
Indian law increasingly recognises the importance of reliable electronic records. The Supreme Court's decisions in Anvar P.V., Arjun Panditrao Khotkar, Tomaso Bruno, Shafhi Mohammad, Navjot Sandhu, Sonu @ Amar and Tukaram S. Dighole collectively demonstrate the importance of authenticity, reliability, traceability and safeguards against tampering in electronic records.
Therefore, an organisation should treat an audit trail not simply as a technical log, but as an accountability and evidence mechanism capable of demonstrating the complete history of important records.

comments