Audit Trail Requirements for E-commerce Books
Audit trail has two meanings for a marketplace seller's books, and conflating them causes trouble. The first is the regulatory one: under the Companies (Accounts) Rules, companies must use accounting software with an audit trail, an edit log of every change to books, a requirement that has applied to companies since April 2023. The second is the practical one auditors care about just as much: can every voucher in the books be traced back to the marketplace report row that justifies it? E-commerce clients stress both meanings harder than most businesses, because their books are generated from bulk files rather than individual documents. This article covers what to put in place for each.
The edit log requirement, briefly
For clients that are companies, the accounting software must record an audit trail of each transaction, capture every change with a date stamp, and not allow the edit log to be disabled. TallyPrime ships with an edit log capability aligned to this requirement. Two practice points follow: confirm the edit log is actually enabled on each company client's data, and check applicability for each client with the current rules, since the requirement targets companies rather than proprietorships, and rules evolve. Nothing in this article is a substitute for reading the current notification; treat that as a standing item on your compliance checklist.
The evidence trail: the audit question that actually bites
When an auditor, or a tax officer, or next year's incoming accountant, looks at a sales voucher for an Amazon order, the question is simple: where did this number come from? For manually keyed books, the answer is often a spreadsheet that no longer exists in the version that was used. A defensible evidence trail for marketplace books means:
- Source files are preserved exactly as downloaded, named and dated, for every report used to generate entries.
- Every voucher links to its source rows, so a settlement entry can be traced to the specific settlement report lines behind it.
- Transformations are reproducible. Given the same file, the same vouchers result. Ad hoc spreadsheet edits break this property silently.
- Human decisions are recorded. When someone resolves an exception or approves a batch, the who, when and why are captured.
This is the design principle behind TallySutra's import pipeline: vouchers are generated from stored report files, each voucher carries its source linkage, and approvals are recorded, so the answer to where did this come from is a click rather than a reconstruction. The approach is described further in evidence-backed accounting for marketplace sellers.
Where marketplace books commonly fail an audit review
| Weakness | Why it happens | Mitigation |
|---|---|---|
| Sales booked net of fees | Entries keyed from bank credits | Book gross sales and fees separately from marketplace reports |
| Unsupported consolidated entries | One monthly journal with no working preserved | Preserve source files and per-order or per-settlement detail |
| Duplicated imports | The same report processed twice | Duplicate-safe imports that recognise already-processed rows |
| Untraceable corrections | Figures edited directly in vouchers | Corrections via documented entries; edit log enabled |
Building the trail into the workflow
An evidence trail bolted on at year-end is a reconstruction project. Built into the monthly workflow, it is nearly free. The routine: reports are collected and stored on a schedule, imports run from those stored files, settlement reconciliation flags anything that does not tie out, exceptions are resolved with notes, and a reviewer approves batches before they post to TallyPrime. Each step leaves a record as a by-product of doing the work. The review step deserves emphasis, because an approval log showing that a senior looked at vouchers before posting is itself audit evidence of internal control; the mechanics are covered in reviewing marketplace vouchers before posting.
What to tell clients
Sellers rarely resist this discipline once it is framed correctly: the same trail that satisfies an auditor is what wins fee disputes with marketplaces and answers GST notices quickly, because the order-level evidence is already organised. Set the expectation at onboarding that source reports are a deliverable from the client, not a favour. For how TallySutra stores files and handles client data in this workflow, see the security page; for the workspace where the approval records live, see the CA tools. A short quarterly self-check keeps all of this honest: pick three vouchers at random across clients, trace each back to its source rows, and time the exercise. If any trace takes more than a few minutes, the trail has a gap worth fixing before an auditor finds it for you.
Frequently asked questions
Does the audit trail (edit log) rule apply to all my e-commerce clients?
The requirement under the Companies (Accounts) Rules applies to companies. Many marketplace sellers are proprietorships or partnerships, so check each client's constitution and confirm applicability against the current rules rather than assuming either way.
Is TallyPrime's edit log enough by itself?
It satisfies the software capability side for companies when enabled, but it only records changes inside Tally. The evidence trail from marketplace report to voucher, source files, linkage and approvals, must come from the workflow that generates the entries.
How long should marketplace source reports be retained?
At least as long as books of account must be preserved for the client, and practically for as long as any assessment or dispute could reference them. Store them named, dated and unmodified alongside the books they support.
TallySutra turns Amazon, Flipkart and Meesho reports into reconciled, reviewed TallyPrime vouchers — duplicate-safe, with every rupee traceable to its source row.
Book a 30-minute demo