Contact Info
Which parts of an Indian company's ERP does an audit review?
An ERP audit is a system health review, not a statutory or tax audit. For an Indian company I compare the live configuration with how plants, branches and accounts actually work, prepare GSTIN, e-invoice, e-way bill and TDS setup questions for your chartered accountant, and check payroll links, access rights, connected tools, parallel Excel files and license use. You receive a ranked findings report, delivered remotely.
Last reviewed by Vikas Saroj
Many Indian businesses reach the same point some time after go-live. The system posts invoices and generates IRNs, yet the accounts team still rebuilds the GST working in Excel, stores keep a parallel register and the promoter asks for figures that nobody will sign off without a manual check. An ERP audit finds out why.
What gets reviewed is the software and the habits around it. Statutory, tax and internal audits of your books are separate exercises, and your chartered accountant and external auditor remain responsible for them. I hand them a clear list of setup questions; they decide on treatment.
I am based in India and run the review remotely, with plant or branch visits only by arrangement.
Each area produces evidence, not opinions: screenshots, sample transactions and user walkthroughs that show what the system is really doing.
How sales, purchase, stores, production and accounts run at head office compared with plants, depots and branches, and where each location has drifted into its own way of using the same system.
Registrations, place-of-supply logic, HSN and SAC on items, TDS sections on vendors and document numbering, listed as questions with sample entries so your chartered accountant can confirm or correct them.
How IRN generation, cancellation and e-way bill creation actually flow through the GST service provider or connector, what happens when a call fails, and who notices the failure.
Whether salary, PF, ESI and professional tax figures reach the ledger correctly from the payroll tool or provider, and how differences are found before the books are closed.
Who can create, approve and amend documents, how back-dated changes are controlled, and whether the edit history your auditor expects is switched on and kept, for your auditor to confirm.
Which MIS reports management trusts, which are rebuilt in Excel, how many paid users actually log in, and where duplicate parties or items distort the numbers.
Agree what the review must answer
Look at the system and its users
Rank findings and agree owners
The word audit carries a specific meaning in Indian business. Your statutory auditor signs off the financial statements, a tax auditor may report under the income tax law, and some companies also run an internal audit function. An ERP audit is none of these. It looks at the software, its configuration and the habits that have grown around it, and asks whether the system supports the business as it runs today.
That distinction matters for two reasons. First, my report carries no view on your accounts or tax position; those judgments stay with your chartered accountant and auditors. Second, the review is most useful when it feeds them. A finding such as "interstate stock transfers between two GSTINs are booked as journal entries rather than as tax invoices" is a system observation. Whether that treatment is correct is a question for your CA, and I write it up that way, with sample documents attached.
Typical triggers for the review include a new CFO who wants to know what was inherited, a promoter preparing for investors or a bank review, plans to add a plant or a new state registration, and a growing sense that people work around the ERP rather than in it. If the project never reached a stable go-live, the ERP rescue page for India describes a different engagement.
Indian indirect tax touches almost every ERP master and document. During the review I trace a sample of real transactions from each GSTIN and note how the system handled them. I do not decide whether the tax is right. I list what the system did, so your chartered accountant can confirm it quickly.
Points I typically examine include:
Each point becomes a line in a separate CA question log, so tax decisions and system fixes never get mixed up.
An Indian group often runs more than one legal entity, several state registrations under each one and a mix of plants, depots and sales offices. Over time, these locations tend to use the ERP differently. One branch raises sales orders first while another invoices directly; one plant books production daily while another catches up at month end. Each habit looks harmless locally and causes trouble when figures are combined.
I review how the structure is modeled: companies, branches, cost centers, warehouses and the way stock transfers, job work and intercompany sales are recorded. I look for warning signs such as stock transfers that never get received at the other end, intercompany balances that do not agree, or a branch whose stock is adjusted every month to match a physical count.
Where your group plans to add a new entity, plant or state, this part of the review shows whether the current design can take it without duplicating masters or splitting reports. Findings here often point to multi-company design fixes rather than new software. The aim is a structure that a new finance head or auditor can understand from the system itself, without needing the person who set it up to explain the shortcuts.
Access rights in many Indian ERPs grow informally. An accountant gets administrator rights during go-live and keeps them. A plant user shares a login with the night shift. A senior manager can create a vendor, raise a purchase order, approve it and release payment without a second person involved.
I export the user and role list, compare it with the people who actually work in each function and test a sample of sensitive actions. The checks usually cover:
Indian rules on accounting software and audit trails apply to many companies, and your statutory auditor will have a view on what your setup must show. I do not give a compliance opinion on those rules. I describe what the system records today, so your auditor and CA can tell you whether anything needs to change.
Few Indian ERPs run alone. Payroll often sits with a separate tool or provider, GST compliance passes through a connector, and sales may come from a CRM, a dealer app or an ecommerce channel. Data can slip through the gaps at any of those hand-offs.
I list every integration, what it sends, how often and what happens when it fails. For payroll, I check that salary, PF, ESI and professional tax journals reach the right ledgers and cost centers and that someone reconciles them each month. For bank feeds and dealer or channel orders, I check for duplicates and gaps.
I also build an inventory of side spreadsheets: the outstanding sheet the collections team trusts more than the ledger, the production plan kept outside the system, the MIS pack assembled from exports. Each one is a missed requirement, and the inventory tells you which reports leadership does not trust and why.
Finally, I compare paid user licenses and modules with actual logins and usage. Unused seats and modules are common after a rushed rollout. The findings report ranks everything by business impact, separates quick fixes from deeper redesign and marks which items your partner, your CA or your own team should own. For the method in general terms, see my ERP health check service, and for follow-up work the ERP optimization page.
Tell me about your business and current systems. I’ll suggest the most sensible first step.
Book a Consultation
Not sure which ERP you need?
Share your business requirements with me and I will help you understand the right process, architecture and platform before implementation.
No. Your statutory auditor reports on the financial statements and your chartered accountant handles tax questions. An ERP audit reviews how the software is configured and used. It can make their work easier by documenting how transactions flow, but it does not replace them, and I do not sign anything on their behalf.
I will tell you exactly what the system does: which tax templates apply, how place of supply is derived and what happens to e-invoices and e-way bills. Whether that treatment is right is for your chartered accountant to confirm. I give them a short question log with sample documents so their review is quick.
Read-only access is usually enough, ideally a dedicated user so activity is traceable. Where the platform allows, a copy of the live system works well. I also ask for exports of user roles and sample transactions, and I never change configuration during the review unless you ask me to.
No. Findings describe what the system does, why it matters and what would fix it. Plenty of gaps trace back to a deadline-driven go-live, or to a business that kept evolving after the partner handed over. The report is written so your partner can act on it, and it can be shared with them as it stands.
The review is designed to be remote: users share their screens, walk through real tasks and send short recordings of steps that are hard to show live. If a site visit would genuinely add something, such as seeing a stores process in person, it can be planned by arrangement.
Every business is different. Share where you are today and what you want to fix, and I’ll tell you honestly whether and how I can help.
Book a Consultation
Book a consultation to talk through your processes, systems and goals. I’ll reply with practical next steps - no obligation.