What an audit trail is for
An audit trail is the running record of what happened to a business record: who created it, who changed what, who approved it and when. In lending and funds, it is how you prove that your controls worked, not just that they exist in a policy PDF.
Auditors rarely ask "do you have logs?". They ask things like: who approved this sanction? Was it within their limit? What did the record look like at the moment they approved it? Did anyone touch it afterwards?
What a useful audit trail captures
- Who. The actual person, or the system or service account, that did it.
- On whose behalf. Delegations and proxies, recorded as such.
- What. The action, plus the before and after values.
- When. A reliable timestamp on every step.
- Under which authority. The role, limit or policy that allowed it.
- Context. The version that was reviewed, and the comments, especially on deviations.
What the RBI expects from NBFCs
The RBI’s Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for NBFCs (31 July 2026) define an audit trail as a chronological record that reconstructs the sequence of activities around an operation or event, from inception to result. What they require depends on the NBFC’s layer and size.
- Base layer NBFCs with assets of ₹500 crore and above: audit trails must exist for IT assets, meet business, regulatory and legal requirements, support audits, serve as forensic evidence and help resolve disputes, and record any unauthorised user activity (paragraph 21(8)).
- Middle layer and above: every application or system that can access or affect critical or sensitive information needs audit logging and must provide audit trails (paragraph 109).
- Those trails must be detailed enough for audits, forensic evidence and dispute resolution, including non-repudiation (paragraph 110).
- Audit trails and system logs must be monitored regularly to detect, understand or recover from unauthorised activity or attacks (paragraph 111).
- Data migrations need their own audit trail and sign-offs from business users and application owners at each stage (paragraph 99).
- Where technology is outsourced, the provider must keep audit trails and admin logs and make them available to the NBFC (paragraph 62(2)(i), base layer ₹500 crore and above).
What "tamper-evident" means in plain terms
A tamper-evident log is one where you can’t edit or delete an entry without that change itself showing up. Usually the log is append-only, entries are written as the action happens, and integrity checks make any alteration visible.
Why does it matter? Because a log that an administrator can quietly tidy up isn’t evidence. It’s a claim. Tamper-evidence is what lets you hand the record to an auditor without a knot in your stomach.
The gaps we see most often
- The change is logged, but not who approved it or on what authority.
- Shared logins, which make "who" meaningless.
- Approvals given in email, outside the system that holds the record.
- No record of which version was approved, so later edits are invisible.
- Logs that technically exist but take days to search and export.
Stop preparing for audits
The practical goal is that nobody has to "get ready for audit" anymore. If approvals, committee decisions and changes happen inside a governed workflow, the platform records who, what, when and under which authority as a side effect of people doing their jobs. Pulling evidence for a period then takes minutes.
Averoic records a tamper-evident audit trail on every action, including on-behalf-of and system actions, alongside maker-checker controls and attribute-based access control.
General information for operations and compliance teams, not legal or regulatory advice. RBI references are to the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/461), which apply by layer and asset size.
Works with alternative lenders, AIFs, NBFCs and insurers in India on approvals, maker-checker controls and audit readiness.
See how your own process would run on Averoic — configured, not coded, with maker-checker controls and a tamper-evident audit trail built in.
Frequently asked questions
What should an audit trail include?
Who performed each action, on whose behalf, what changed (before and after), when it happened, under which role or authority, and the version and context of the record, especially for approvals and deviations.
What are the RBI audit trail requirements for NBFCs?
Under the RBI’s 2026 IT and cybersecurity directions for NBFCs, base layer NBFCs of ₹500 crore and above need audit trails that support audit, forensics and dispute resolution and record unauthorised activity (para 21(8)). Middle layer and above NBFCs need audit logging in every system that can access or affect critical or sensitive information, detailed enough for non-repudiation, and regular monitoring of those logs (paras 109 to 111).
What is a tamper-evident audit trail?
An audit log where entries cannot be edited or deleted without the change being detectable, usually append-only, written at the time of the action and protected by integrity checks, so it can be relied on as evidence.
How do you make a business process audit-ready?
Run approvals and changes inside a governed workflow with enforced controls (maker-checker, authority limits, role-based access) that records a tamper-evident audit trail automatically, so evidence for any period can be exported on demand.