Due Diligence, Information System Audit and ESG Assurance
Three engagements that are not statutory audits and do not arrive on a year end. They arrive because a buyer, a regulator or a customer asked. Each has moved substantially in the last two years: due diligence because the underlying law changed, information system audit because two regulators issued new frameworks, and sustainability assurance because the securities regulator softened the requirement and then extended it to everyone.
- What a 2026 due diligence has to cover that a 2024 one did not
- Where information system audit is actually mandated
- The sustainability assurance regime and its glide path
- The independence bar that decides who can provide it
No statute, which is why scope matters
Nothing governs the scope of a due diligence exercise, so everything depends on what was agreed. What has changed is the checklist, because the law underneath a target moved in several places at once between November 2025 and April 2026.
How a diligence is scoped, staffed and run on a live deal is transaction work rather than assurance work, and it sits with our transaction advisory practice: see Financial and Tax Due Diligence. What follows here is the assurance reading of the same exercise, which is what a target's own numbers have to survive. The distinction is not only presentational. Diligence for a buyer is an advisory engagement to that buyer; it is not assurance, it gives no opinion, and it does not put the firm in the position an auditor occupies.
| Area | What a 2026 diligence has to look at |
|---|---|
| Employment and payroll | The four Labour Codes commenced on 21 November 2025, replacing the definition of wages and repealing a large number of central Acts. A target's employment cost base, gratuity accrual and compliance position all changed on that date, and state rules are uneven. See our payroll pages. |
| Direct tax | Two Acts are live. Historic exposure is 1961 Act exposure and forward positions are 2025 Act positions. Warranties and indemnities have to be labelled by year and by Act or they will not do what was intended. |
| Audit history | The small company definition changed on 1 December 2025. The absence of an auditor's report order paragraph or an internal financial controls opinion in a target's FY 2025-26 accounts may be a change in law rather than an omission. Do not read it as a red flag without checking. |
| Records and systems | Audit trail compliance since FY 2023-24, and daily backup on servers physically located in India. A target hosting its ledger abroad without an Indian backup has an issue that will not be visible from the financial statements. |
| Sustainability reporting | Whether the target is inside the reporting glide path, and whether its value chain obligations touch the acquirer. |
| Company law pipeline | A bill amending the Companies Act was introduced in March 2026 and reported on by a joint committee in August 2026. It is not law and must not be diligenced as if it were, but it belongs in a forward-looking section. |
Where it is mandated
Outside regulated sectors, an information system audit is a management or contractual choice. Inside them it is a requirement with a named policy owner.
Banking and non-banking financial companies
The banking regulator's master direction on information technology governance, risk, controls and assurance practices, dated 7 November 2023 and effective from 1 April 2024, applies to commercial banks including small finance banks, payments banks and foreign banks, to non-banking financial companies in the top, upper and middle layers, to credit information companies and to all India financial institutions. It requires an information systems audit policy approved by the audit committee of the board and reviewed at least annually, and risk-based audit planning. Continuous auditing for critical systems is permitted and encouraged rather than required: the direction says regulated entities may consider it wherever possible. The function must have appropriately skilled personnel, with external resources permitted where the skills are not available internally, although responsibility and accountability stay inside the internal audit function.
Securities market entities
The securities regulator's cybersecurity and cyber resilience framework, issued on 20 August 2024 and clarified and amended since, applies to regulated entities in five graded categories with proportionate obligations: vulnerability assessment and penetration testing, cyber audit by empanelled auditors, security operations centre arrangements, certification for the top tiers, and incident reporting. The implementation dates have passed. The deadline was 30 June 2025 for market infrastructure institutions, KYC registration agencies and qualified registrars and share transfer agents, and 31 August 2025 for all other regulated entities under the extension of 30 June 2025. The technical clarifications of 28 August 2025 modified particular controls but granted no further general extension. A cyber incident must still be reported by email within six hours and through the regulator's cyber incident reporting portal within twenty-four hours, with updates through to closure. Both clocks were reconfirmed on 24 August 2026 when the portal was aligned to the Financial Stability Board's reporting format.
Insurance
The current instrument is the insurance regulator's Information and Cyber Security Guidelines 2026, version 2.0, issued by circular of 6 April 2026 and applicable from FY 2026-27 to insurers, insurance intermediaries and the Insurance Information Bureau of India. They replace the 2023 guidelines. Two requirements are commonly collapsed into one and should not be: a cybersecurity assurance audit is required annually, and vulnerability assessment and penetration testing is required separately at least once every six months. The testing does not discharge the audit. For an insurer, the annual audit report with the board's comments goes to the regulator within 90 days of the financial year end or 30 days of the audit being completed, whichever is earlier.
The glide path, and what changed in 2025
Listed entities within scope report against a prescribed sustainability format, and a defined subset of that report, the core, is subject to third-party verification on a phased basis.
| Financial year | Entities in scope for core verification |
|---|---|
| FY 2023-24 | Top 150 listed entities by market capitalisation |
| FY 2024-25 | Top 250 |
| FY 2025-26 | Top 500 |
| FY 2026-27 | Top 1,000. The first year the full reporting population is captured, and the year now in progress. |
Source: the securities regulator's master circular of 30 January 2026, read directly on 18 August 2026.
Two 2025 changes matter to anyone scoping this work. First, the requirement for the sustainability report core is now assessment or assurance, rather than reasonable assurance alone. Where assessment is chosen it must be conducted in accordance with the assessment standards developed by the industry standards forum in consultation with the regulator. A great deal of published material still says reasonable assurance is mandatory; it is not, for the core. Keep this tied to the core rather than read across to every form of sustainability assurance. Second, value chain obligations were softened: value chain disclosure is voluntary for the top 250 from FY 2025-26, and assessment or assurance of it is voluntary from FY 2026-27, with a value chain partner redefined as one individually comprising two per cent or more of purchases or sales and an option to cap coverage at seventy-five per cent cumulatively.
Who may provide it, and the bar that catches advisory firms
The provider need not be a chartered accountant, but the board must satisfy itself of its sustainability expertise. The statutory auditor may provide it. The entity's internal auditor may not. And the provider or any of its associates must not sell products or provide non-audit, non-assurance or non-assessment services to the entity or its group, including consulting, risk management, project management, investment advisory, outsourced financial services, actuarial services, accounting and bookkeeping, and the design or implementation of information systems. Tax audit, system audit, tax filing and third-party certifications are permitted where the entity judges there is no conflict. The practical consequence is direct: a firm cannot both build a client's sustainability framework and assure it. Our framework and reporting work sits on the sustainability pages and the two are not available together.
On standards, the acceptable set includes the international assurance standard, the international sustainability assurance standard, and the Institute's own sustainability assurance standard, with the industry forum standards used for assessment. The Institute issued its general requirements standard for sustainability assurance engagements as an exposure draft on 20 May 2026, with comments closing on 19 June 2026, and it had not been finalised as at 16 September 2026. So a 2026 assurance engagement letter should cite the Institute's assurance standard on sustainability information as the umbrella standard, adding its greenhouse gas statements standard where the engagement covers emissions information. The umbrella standard has been mandatory for assurance reports covering periods ending on or after 31 March 2024. An assessment engagement is different and its letter should cite the regulator's framework and the industry forum's assessment standards instead, not the assurance standards.
One correction worth making explicitly, because it appears throughout published material: the climate disclosure task force was disbanded on 12 October 2023 and its recommendations now live inside the international sustainability standard. Any engagement scoped against 'the task force framework' as a current body is scoped against something that no longer exists.
Where to go next
Audit and Assurance Services
Back to the main page: the full range of engagements, how we work, and how to reach us.
Statutory Audit: Appointment, Rotation and What the Report Has to Say
Appointment and rotation, the eligibility bars, resignation, the auditor's report order and the reporting on internal financial controls, including the single most misquoted conjunction in Indian company law.
Tax Audit and the Move to the Income-tax Act 2025
The thresholds for FY 2025-26 under the old Act, what section 63 of the new Act does differently, the change of substance that widens who gets audited, and the consolidated form that replaces three.
Internal Audit, Risk-based Audit and Compliance Audit
When internal audit is a statutory obligation and when it is a management choice, who may hold the role, how a risk-based plan is actually built, and how this sits alongside our governance and internal control work.
Forensic Audit, Fraud Reporting and Investigation
The statutory fraud reporting duty and its two thresholds, the timetable that starts the day a suspicion forms, the standards a forensic engagement is conducted under, and what a forensic engagement is not.
Send an enquiry
For a transaction, tell us the target and the timetable. For a regulator-driven engagement, tell us which regulator and which category you fall into, because the obligations are graded and the answer changes with the tier.
Position as at 15 September 2026. Reviewed every six months.
This page is general information, not professional advice. Audit obligations in India turn on thresholds that moved recently and on standards whose effective dates have been deferred more than once. The small company definition changed on 1 December 2025, the Income-tax Act 2025 replaced the 1961 Act on 1 April 2026, two quality management standards were deferred on 31 March 2026, and a revised group audit standard has been proposed but not notified. Whether a particular obligation applies to you depends on your own numbers at your own year end. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else's, without one.