AS | Ankit Sarawagi|Founder, CFOmatrix·July 2026·11 min read | Capstone SOP |
- Auditors want five things for a transaction: the document, the agreement, the process, the approval and the audit log. Have those and the audit is fast.
- Documentation, not the work, is the gap. Startups do the work; they just never leave a record. Every SOP in this series produces that record as a byproduct.
- Keep the books and backups. Section 128 of the Companies Act expects books of account kept in order, generally for at least eight years, subject to current law.
- Keep the audit trail switched on. The MCA requires accounting software with an edit-log that stays on all year; the auditor checks it.
- Audit readiness is a routine, not a project. A clean monthly close plus current registers and filings means audit is confirmation, not reconstruction.
| 5 Things auditors ask for: document, agreement, process, approval, log | ~8 yrs Books of account retention under Section 128 (subject to current law) | ON Where the MCA audit-trail feature has to stay, all year |
01The Five Things Auditors Always Ask For
Across every audit and due-diligence process, the request boils down to the same five things for any transaction that matters. Not clever questions, not gotchas: just the paper trail that proves the number is real and was handled properly.
“In every audit and every diligence I have been through, they ask for the same things: the document, the agreement, the process, the approval and the audit log. Founders do all the work. They just never write it down, and that is what trips them up.”
Ankit Sarawagi, from working with founders through audits and diligenceThis is the whole point of the SOP cluster. When you run the approval matrix, vendor onboarding, accounts payable and the rest, the five records above are produced as a byproduct of doing the job, not as extra paperwork at year-end. Audit readiness is not a separate workstream; it is what a well-run finance function leaves in its wake.
02Books and Records to Maintain
Section 128 of the Companies Act requires every company to keep books of account and relevant papers that give a true and fair view, in good order, and to retain them for a defined period, generally at least eight financial years (longer if an investigation is ordered). That is the legal floor. The practical goal is wider: keep everything a future auditor, investor or tax officer could reasonably ask for, and keep it where it survives a lost laptop.
| Record | Examples | Keep |
| Books of account | Ledgers, journals, trial balance, financials | ~8 yrs |
| Transaction proof | Sales & purchase invoices, bills, receipts | ~8 yrs |
| Bank records | Statements, reconciliations | ~8 yrs |
| Contracts & agreements | Customer, vendor, lease, employment | Life + buffer |
| Statutory registers | Members, directors, charges, RPTs | Permanent |
| Resolutions & minutes | Board and shareholder resolutions | Permanent |
| Statutory payment proof | GST, TDS, PF, ESI returns and challans | ~8 yrs |
Keep records where they outlive people and hardware. Cloud accounting (Zoho Books, QuickBooks) with regular backups for the books, and a single organised document store, folder-per-vendor, folder-per-customer, for the paper. The failure I see most is not a missing record; it is a real record trapped on an ex-employee’s personal drive or in a WhatsApp thread no one can find.
Registers and resolutions are the ones startups forget, because they are not day-to-day. Related-party transactions in particular need approval and a register entry under Section 188; keep the RPT record current, and hold your policies as the rules behind these records in the CFOmatrix policy library.
03The MCA Audit-Trail Requirement
This is the one control that is now written into law and that the auditor is required to report on. The Ministry of Corporate Affairs requires companies to use accounting software that has an audit-trail (edit-log) feature, to keep that feature switched on through the year, and not to tamper with it. Every entry, edit and deletion is logged with who did it and when.
The auditor checks three things: that the software had the audit-trail feature, that it operated through the year, and that it was not disabled at any point. Switching it off to “clean up” entries is exactly what gets flagged. Turn it on, leave it on, and never edit history outside the tool. The requirement and its dates are subject to current law.
The audit trail is only as useful as the approval that sits beside it. If you approve a spend on Slack or email for speed, capture it back into the tool so the log and the approval live together. That habit runs through the whole series, from payment controls to internal financial controls.
04The Year-Round Audit-Readiness Routine
The difference between a calm audit and a painful one is when the work happens. Do it through the year and the audit is a review. Leave it to the end and it becomes an archaeology project. Here is the contrast.
- Monthly close, finalised and locked
- Bank and key balances reconciled each month
- Registers and filings kept current
- Documents and approvals saved at the moment
- Short quarterly self-review vs checklist
- Rebuilding 12 months from memory
- Chasing counterparties for missing contracts
- Explaining entries no one logged
- Reconciling a year of bank at once
- Surprises the founder learns about late
The engine of all this is the month-end close: reconcile the bank and key balances, review all expenses, finalise the numbers, and the month is behind you for good. Layer on current statutory filings, up-to-date compliance calendar items, and registers maintained as events happen, and by year-end there is nothing left to reconstruct. A short quarterly self-review against your audit checklist surfaces any gap while it is still cheap to fix.
Run a 30-minute quarterly “mock audit” on a handful of random transactions: pick five entries and check that all five records exist for each. If any are missing, you have found a process gap now, not in front of the auditor.
05The Document Checklist Auditors Request
When the audit or diligence begins, the request list is remarkably predictable. Have these organised and ready, and you set the tone: the auditor sees a company in control of its records.
- Trial balance and financial statements
- General ledger and sub-ledgers
- Bank statements and reconciliations
- Fixed-asset register
- Sample sales and purchase invoices
- Contracts and agreements
- Approvals for the sampled items
- Audit-trail / edit-log extract
- GST, TDS, PF, ESI returns and challans
- ROC filings
- Statutory registers
- Board and shareholder resolutions
- Related-party transactions and approvals
- Cap table and ESOP records
- Payroll and salary records
- Key policies and the approval matrix
Get the CFOmatrix Audit-Readiness Checklist: the document request list above plus the year-round routine, as an editable file you can work through each quarter. Tick it off through the year and the annual audit is a formality, not a fire drill.
06Lean Now, When to Add a Step
Audit readiness for a 10-person startup does not look like audit readiness for a 500-person company, and it should not. Keep it right-sized, and add structure only when scale genuinely calls for it.
- One finance owner runs the monthly close
- Cloud accounting with audit trail on
- One organised document store
- Quarterly self-review against the checklist
- A documented close calendar with owners
- Formal ICFR testing above thresholds
- An internal-audit or controls review
- A managed data room for repeat diligence
The lean version is not a lesser version. A clean monthly close, the audit trail left on, and every record saved at the moment of the transaction will carry a startup through a statutory audit and most diligence. The heavier machinery, formal ICFR testing, internal audit, a standing data room, is something you add when the company is large enough to need it, not before.
“The best-run startups are not audit-ready because they prepared for the audit. They are audit-ready because they ran the business well and the records simply exist. That is the whole idea behind these SOPs.”
Ankit Sarawagi, CFOmatrix
|
FAQFrequently Asked Questions
How do I make my startup audit-ready?
Audit readiness is a habit, not a last-month scramble. Close the books every month, reconcile the bank and key balances at each close, keep registers and filings current, and file the proof for every transaction as it happens: the document, the agreement, the approval and the record in your accounting tool, with the audit trail left switched on. If your monthly close is clean, the annual audit is mostly the auditor confirming what you already have. Startups fail audits not for missing work but for doing the work and never documenting it.
What records should a startup keep, and for how long?
Keep your books of account and the supporting records: invoices, bills, bank statements, contracts, board and shareholder resolutions, statutory registers, and proof of GST, TDS, PF and ESI payments. Under Section 128 of the Companies Act, books of account and relevant papers must be kept in good order, generally for at least eight financial years, longer if an investigation is ordered. Keep them so they survive a laptop dying: cloud accounting plus regular backups, and one organised document store. Specific periods and formats are subject to current law.
What is the MCA audit-trail requirement?
The Ministry of Corporate Affairs requires companies to use accounting software that has an audit-trail (edit-log) feature, to keep it switched on through the year, and not to tamper with it. The auditor checks and reports on whether the software had the trail, whether it operated, and whether it was disabled at any point. In practice, use software like Zoho Books or QuickBooks with the audit trail enabled so every entry, edit and deletion is logged with who and when. Do not switch it off. The requirement and its dates are subject to current law.
What do auditors and due-diligence teams actually ask for?
Almost always the same five things per transaction: the document (invoice, bill or statement), the agreement (signed contract or terms), the process (evidence the SOP was followed), the approval (who authorised it), and the audit log (the entry in your software with who and when). On top of that, statutory registers, board and shareholder resolutions, and proof that GST, TDS, PF and ESI were deducted and paid on time. If those exist and are organised, the audit is fast.
How do I avoid a year-end audit scramble?
Move the work into the year. Run a disciplined monthly close so each month is finalised and reconciled while it is fresh, keep registers and statutory filings current as they fall due, and save every document, approval and record at the moment of the transaction. Do a short quarterly self-review against your audit checklist so gaps surface early. When the auditor arrives, you hand over organised records instead of rebuilding a year from memory and chasing missing contracts.
What is an audit trail?
An audit trail is the chronological record of how a transaction moved through your books: who created an entry, who edited or deleted it, when, and what changed. In accounting software it is the edit log; around a transaction it is the wider paper trail of the document, agreement, approval and process behind the entry. It lets an auditor, investor or tax officer verify the numbers are real and were not quietly altered. Under the MCA rule, the audit-trail feature must stay on all year, which is subject to current law.
This is general educational information for founders, current to mid-2026, and is not legal, tax or audit advice. References to Section 128 of the Companies Act, record-retention periods, CARO 2020, ICFR reporting thresholds, Section 188 related-party approvals and the MCA audit-trail requirement are indicative and subject to current law; applicability depends on company type and thresholds. Verify the current position or consult your auditor before acting on a specific matter.
Internal Financial Controls That Actually Matter
Finance SOPs & Controls for Startups: The Full Guide
AS | Founder, CFOmatrix | Finance Strategy & Equity Compliance CFOmatrix is a knowledge platform focused on how finance actually works inside growing companies. This capstone SOP draws on hands-on experience taking founders through audits and diligence: the records auditors ask for, a live audit trail, and a year-round routine that keeps a lean startup audit-ready without big-company bureaucracy. |