Audit Trail in Zoho Books: What Your Auditor Will Ask For, and How to Produce It



Quick Summary
This article explains the importance of the audit trail feature in Zoho Books, especially for UK companies. It details the legal requirements for accounting software to log all transactions and edits, and how auditors use this information. The guide provides practical steps on generating the necessary reports from Zoho Books, including filtering by date, module, user, and action, and highlights common pitfalls to avoid before an audit.

Three audit seasons in, the audit trail conversation with clients has changed shape. In 2023 it was "does our software have it". Now it is "the auditor wants a report and nobody here has ever opened it". That second problem is the one this note deals with, and it is written around Zoho Books because that is where most of the SME companies we audit or advise now keep their books.

The legal position first, briefly. From FY 2023-24, the proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 restricts every company to accounting software that logs each transaction, keeps an edit log of every change with its date, and cannot have that logging turned off. Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014 then obliges the auditor to state in the report whether the feature existed, ran all year on every transaction, was left untampered, and has been preserved. Zoho Books clears the software test the day the organisation is created. Everything below is about the other words in that sentence: all year, untampered, preserved.

Zoho Books Audit Trail: What Your Auditor Needs

The report the auditor wants

The report is under Reports, then  Activity in the category list on the left, then  Activity Logs & Audit Trail. Nothing needs enabling; it has been recording since day one, on the free plan as much as on the paid ones, and there is no switch for it anywhere in Settings.

A row in the report tells you when, in which module and on which record, what was done, and by whom. Click Customise and you get the five filters that matter:

  • Date range
  • Activity related to: a module such as Invoices, Bills, Journals, Chart of Accounts, or an action such as Bank Feeds or Reconciliation
  • Customer or vendor name
  • User
  • Action: All, Create, Update or Delete

There is also a PII toggle that restricts the report to changes in personal data fields, which matters more for the DPDP Act than for the audit.

For any transaction that has been changed more than once, open it and use  Audit Trail  on the record itself. Zoho Books keeps every version, not just the last one, and lets you compare two of them. Changed fields are shown in yellow, removed data in pink, added data in green. A bill that was created at Rs. 1,18,000, edited to Rs. 1,08,000, and edited again to change the TDS section, shows as three versions with each difference marked. That view answers "who changed what, and when" in one screen, which is exactly the question the rule was written to answer.

Five runs to do before the auditor asks

1. The whole year, all actions: Set the date range to the financial year, Action to All, and export. Note the row count in the working file. This is the base document; the rest are subsets of it.

2. Deletions: Same range, Action = Delete. For most SMEs this is a short list, and it is where the questions come from. A deleted sales invoice with a live IRN, a deleted bank transaction that was later re-entered with a different date, a deleted journal from the month a loan was drawn. Each row should have a one-line reason written against it before the audit starts, not during.

3. Entries created after the close, dated inside the year: Set the date range to run from the day after the books were closed, Action = Create, and look for anything whose transaction date falls within the audited year. A journal created on 28 June for a provision dated 31 March is not wrong in itself. It is wrong if the board saw draft financials in May that did not include it. The log gives the creation date; the ledger only gives the transaction date.

4. Invoices edited after the IRN was generated: Module = Invoices, Action = Update, then check the edited rows against the e-invoice register. The IRN cannot be amended, so any change to value or quantity after generation leaves the books and the portal disagreeing. The correct route was a credit note. The audit trail is not the problem here; it is the thing that exposes the problem.

5. Changes to masters:  Module = Chart of Accounts, and separately Customers and Vendors, Action = Update. A GL account re-mapped in February changes how every transaction since then is classified. A customer's credit terms changed from 30 to 90 days in March, affecting the ageing that the provisioning was based on. These are changes "in the books" even though they are not transactions.

 

Roles and lock dates, which prevent instead of record

The log records. It does not stop anyone. If a user's role permits deleting a bill, the bill goes and the log says so. Two settings turn the trail from a record of what went wrong into a reason it did not.

Users & Roles under Settings. Look at who can delete transactions and who can change transaction dates. In a typical SME the answer should be one or two people, and neither of them should be the person who raises the invoices.

Transaction Locking under Settings. Set the lock date on the day the trial balance goes to the auditor and record that date in the working file. Anything that has to be posted after that date goes through an unlock, which itself appears in the log with the user's name.

The migration gap

A company that moved from Tally to Zoho Books on 1 October has an activity log that starts on 1 October. The opening balances imported that day carry an October creation stamp. Nothing in Zoho Books can say anything about April to September.

For that period, the auditor will ask for the edit log from the old system, and the answer depends on the release that was running and whether the feature was on. The old data and its log have to be kept for eight years under Section 128(5), in a form that can still be opened. A backup file with no licensed copy of the software to read it does not meet that test. Before the old subscription lapses, export the data and the log, and put a licence aside if one is needed to read them.

The same point applies in reverse. If the company ever leaves Zoho Books, export the full Activity Logs report and the organisation data on the last day of use. The eight-year clock does not stop because the subscription did.

What the auditor writes

Where everything above is in order, the Rule 11(g) paragraph in the audit report says that the company used software with an audit trail feature, that it operated throughout the year for all transactions, that the auditor found no instance of tampering, and that the trail has been preserved as required. Where the trail did not exist for part of the year, because of an old release or a spreadsheet on the side, the paragraph has to say so and name the period. Directors are the ones exposed under Section 128(6), with a fine of Rs. 50,000

 

Three questions we get every year

  • Can the log be exported for the auditor rather than giving them a login?  Yes. Run the report with the filters set, use Export As at the top right, and send the file. A view-only user role is the cleaner alternative for a larger audit.
  • Does the free plan record the same log as the paid plans?  Yes. The activity log is not a plan feature.
  • Our accountant uses one login for three staff. Does the log still work?  It records, but it records the login, not the person. The auditor will treat every row under that login as unattributed and will extend testing. Give each person their own user; the cost of an extra seat is smaller than the cost of an extended audit.

The views expressed are the author's own and do not constitute professional advice. Statutory references are as at September 2026. 

The author is the founder of KC Shah & Associates, a Mumbai chartered accountancy firm that implements Zoho Books for SME companies, handles migrations from Tally, and audits companies that have already made the move.


292 Views 1 Likes Comment   Share Audit   Report


About the Author

Practice

CA Karan Shah is the Founder of KC Shah Associates, a Mumbai-based Chartered Accountancy firm serving startups, SMEs and growing businesses across India. He specialises in outsourced accounting, GST and MSME compliance, business valuation and Virtual CFO advisory, with deep hands-on expertise in cloud accounting and Z ... Read more

Comments :

Related Articles


Loading


Popular Articles





CCI Pro

CCI Articles

submit article


Company
ARTICLESHIP 01 October 2026
Articled Assistant

KPSN & Associates LLP

Chennai

CA Inter

View Details
Company
ARTICLESHIP 16 September 2026
Article Assistant

MANUJ SHARMA AND COMPANY

Noida

CA Inter

View Details
Company
22 September 2026
Account Assistant

Chirag P Shah & Co. Chartered Accountant

Pune

B.Com

View Details
Company
ARTICLESHIP 18 September 2026
Industrial Trainee

Twenty Point Nine Five Ventures Private Limited

Noida

CA Inter

View Details
Company
Featured 11 September 2026
Audit Executive

RBSM Corporate Advisors Private Limited

Pune

CA

View Details
Company
30 September 2026
Senior Accounts Executive

Codeboard Technology

Chennai

MBA

View Details
Company
19 September 2026
Finance Manager

Mugdha Art Studio

Hyderabad

CA

View Details
Company
26 September 2026
Chartered Accountant

pushpganga ventures

Pune

CA

View Details