The proposed introduction of Draft Form 26 under the Income-tax Act, 2025 reflects a calibrated shift in the architecture of tax audit reporting. Where books of account are maintained in electronic form, the audit framework now contemplates disclosure of the IP address of the system, the country of primary data storage, and the location of backup servers.
Regulatory context
This development is not isolated. A comparable regulatory approach is embedded within the Companies Act, 2013. Section 128, read with the applicable Rules, requires companies maintaining books at a place other than the registered office to intimate the Registrar of Companies through Form AOC-5. Additionally, where books are maintained in electronic mode, disclosure of the service provider’s particulars — including IP address and server location — forms part of statutory reporting.
The legislative trajectory is clear: regulatory assurance increasingly encompasses the integrity of systems that generate financial information, not merely the information itself.
I. Regulatory context — why infrastructure disclosure matters
In a digitally integrated business environment, financial data is hosted across cloud infrastructures, managed servers, and distributed architectures. The physical situs of records has evolved into a technological construct.
Infrastructure-level disclosure serves three essential purposes:
- Establishing traceability of accounting data
- Clarifying locus of control and access
- Enhancing regulatory confidence in electronic record maintenance
The tax audit framework’s incorporation of such disclosures represents an alignment with this systemic oversight philosophy.
II. Implications for the audit profession
For Chartered Accountants, the refinement is substantive. The professional inquiry must now extend beyond financial verification to digital governance considerations.
Audit engagement planning and execution will increasingly involve:
- Understanding the client’s hosting and storage architecture
- Evaluating digital access controls and segregation of duties
- Documenting infrastructure disclosures within audit working papers
- Assessing whether system configuration impacts independence perception
Audit assurance, therefore, becomes integrative — linking financial accuracy with system reliability.
III. Independence in the digital environment
Independence must be preserved not only at an organisational level but also at a technological level. Where accounting preparation and audit verification operate within overlapping or insufficiently segregated digital environments, the perception of independence may be diluted. Transparent reporting of IP addresses and server locations introduces structural clarity, reducing ambiguity regarding control and access.
The foundational principle remains unchanged: preparation and verification must remain institutionally distinct, including within shared technological ecosystems.
IV. Conclusion
The audit discourse is evolving. It no longer concludes with the accuracy of balances; it extends to the governance of the infrastructure supporting those balances. Digital Infrastructure Transparency is not an ancillary reporting requirement — it represents a measured progression in regulatory design, strengthening accountability, reinforcing independence, and modernising assurance in a cloud-driven economy.