Skip to main content
Roles: CS Executive, CA Partner - CS Executives conduct the audit and prepare the report. CA Partners finalise and submit the report. The partner signing the secretarial audit report must be a practising Company Secretary.
Upstream dependencies: A CA Engagement must exist for the company client. Board meeting minutes, ROC filing records, and statutory registers for the audit period should be available in the system before the audit begins. Downstream: The submitted secretarial audit report (Form MR-3) is filed with the ROC as an attachment to the company’s MGT-7 annual return. See ROC Filings.

Overview

A CA Secretarial Audit record manages the secretarial audit required under section 204 of the Companies Act, 2013. The audit covers whether the company has complied with the provisions of the Act, applicable SEBI regulations, FEMA, labour laws, environmental laws, and the Secretarial Standards issued by ICSI. The CS Executive conducts the audit area by area using a structured checklist, then prepares the draft report. The CA Partner reviews, finalises, and submits the signed report. Records are named automatically in the format SA-YYYY-##### (for example, SA-2025-00008).
Secretarial Audit list view showing audit records by client, financial year, status, and checklist score

Who needs a secretarial audit

A secretarial audit is mandatory under section 204 for: Private companies are generally exempt unless they are subsidiaries of listed companies. Check the client’s latest financial data against these thresholds at the start of each financial year.

Who uses this feature


Before you start

  • The client must have an active CA Engagement and must meet at least one of the mandatory audit thresholds above.
  • All board meeting records for the audit period should be completed and minutes approved in the system.
  • ROC filing records for the audit period (especially SRN Received status) should be up to date.
  • Statutory registers for the period (Members, Directors, Charges, etc.) should be current.
  • Director KYC (DIR-3 KYC) records for the year should be available.
  • Start the audit at least 60 days before the AGM date to leave time for the company to remedy any gaps before the report is finalised.

Create a secretarial audit record

Path: CA Practice Management → ROC and Company Law → Secretarial Audit → New
  1. Select the Client Engagement for the company.
  2. Select the Financial Year being audited.
  3. Enter the Auditor Name (the name of the practising Company Secretary signing the report).
  4. Set Audit Period From and Audit Period To (usually 1 April to 31 March for the financial year).
  5. Save. The record is created with status Initiated and the auto-name is assigned. The checklist items are populated automatically based on the company type and applicable laws.
New Secretarial Audit form showing Client Engagement, Financial Year, Auditor Name, and Audit Period fields

Work through the audit checklist (CS Executive)

  1. Open the audit record and click Start Audit. The status moves to In Progress.
  2. Open the Secretarial Audit Checklist tab. You will see one row for each compliance area. Work through each row.
  3. For each item, set the Compliant column to Yes, No, or NA (not applicable).
  4. Enter your findings in the Observations column and any additional detail in Remarks.
  5. The Checklist Score at the top of the record updates automatically as you save each row. It shows the percentage of applicable items (excluding NA) marked as Yes.
Secretarial Audit Checklist table showing rows for different compliance areas with Compliant, Observations, and Remarks columns

Checklist coverage

The audit checklist covers the following compliance areas. All applicable items must be completed before moving to draft report.
Secretarial Audit Checklist showing multiple compliance area sections with Yes/No/NA dropdowns and observation text fields

Prepare the draft report (CS Executive)

After completing the checklist:
  1. Review all items marked No. These will become either qualifications or observations in the report.
  2. Enter any formal qualifications in the Qualifications field. A qualification is a matter where the company has not complied and the non-compliance is material enough to be reported as a specific finding in the MR-3 report.
  3. Enter other notable items (complied with but worth flagging) in the Observations field.
  4. Enter suggested improvements in the Recommendations field. Recommendations are advisory and do not form part of the formal MR-3 report, but they are useful to share with the client.
  5. Click Create Draft Report. The status moves to Draft Report.
Secretarial Audit in Draft Report status showing the Qualifications, Observations, and Recommendations fields
Keep the draft report internal until the CA Partner has reviewed it. Do not share it with the client or the company’s management team at this stage, as the partner may need to reclassify items between qualifications and observations.

Finalise and submit the report (CA Partner)

  1. Open the audit record in Draft Report status.
  2. Review the checklist score, the qualifications, the observations, and the recommendations.
  3. If the report needs significant changes, click Rework. The status returns to In Progress and the CS Executive is notified.
  4. If the report is accurate, prepare the signed Form MR-3 outside the system (using the statutory template from the MCA website), attach it to the record using the Report Attachment field.
  5. Click Finalize Report. The status moves to Final Report.
  6. Click Submit Report. The status moves to Submitted.
The submitted report is then attached to the company’s MGT-7 filing. See ROC Filings for instructions on including the report in the MGT-7.
Secretarial Audit in Final Report status showing the Report Attachment field with the signed MR-3 document uploaded

Field guide

Checklist table fields


Workflow journey

Role at each step


Notifications and alerts


Workspace access

Path: CA Practice Management → ROC and Company Law → Secretarial Audit The workspace section shows:
  • Audits in progress for the current financial year (quick list)
  • Audits not yet started for clients who are past the 60-day pre-AGM threshold (number card)
  • Average checklist score across all submitted audits (metric)
  • Audits by status for the year (chart)
CA Practice Management workspace showing the Secretarial Audit section with in-progress audits and clients awaiting audit initiation

Best practices

  • Start the audit at least 60 days before the AGM. The checklist typically surfaces a few compliance gaps. The company needs time to remedy them (for example, filing a missed DIR-3 KYC or updating a statutory register) before the report is finalised. A clean checklist is far easier to report than a set of qualifications.
  • Complete the checklist fully before writing qualifications. The checklist score helps you see the overall picture before you draft findings. Writing qualifications without completing the checklist risks missing areas that should also be qualified, or over-qualifying areas that are actually compliant.
  • Keep the draft report internal until the partner has reviewed it. If the company’s management sees a draft with provisional qualifications that the partner later downgrades to observations, it creates unnecessary alarm and undermines confidence in the process.
  • Never submit without the partner’s digital signature on the MR-3. The report has no legal standing without the practising Company Secretary’s signature and their Certificate of Practice number. The Report Attachment field should contain the fully signed PDF before you click Submit Report.
  • Use the Recommendations field for advisory findings. Items that are technically compliant but handled poorly (for example, minutes circulated late, quorum met by a narrow margin) should go in Recommendations rather than Qualifications. This keeps the formal report focused on actual non-compliance and gives the company a clear action list without inflating the findings.
  • Cross-check the checklist against the statutory registers in the system. The Statutory Registers module records Members (MGT-1), Directors, Charges, and Contracts. Use those records to verify the checklist items for register maintenance rather than relying solely on documents provided by the company.
  • Mark SEBI-related rows as NA for non-listed companies. The checklist includes SEBI rows for comprehensiveness. For private companies and unlisted public companies, mark all SEBI items as NA before calculating the checklist score, so the score reflects only applicable laws.

  • Board Meetings: Meeting records are a key source for the secretarial audit checklist (SS-1, SS-2 compliance, quorum, minutes maintenance)
  • ROC Filings: The submitted MR-3 report is attached to the MGT-7 annual return
  • Client Engagements: Confirms the client’s size thresholds and applicable laws
  • Feature Overview: Full list of modules and how they connect