NISM Professor

Audit trail

Also written Audit trail (SIA report)

The traceable record of the data, decisions and stakeholders behind a Social Impact Report — required as a component of the report itself, and needed to retrieve primary data when the assessor checks it.

In plain language

A Social Impact Report makes claims about lives changed and communities helped. Those claims have to be traceable back to real evidence and real decisions, or they are just assertions. The audit trail is what makes that tracing possible.

The workbook names it as a required component of the Social Impact Assessment report itself: "An audit trail for decision-making, including which stakeholders, outcomes or indicators were included and which were not, and a rationale for each of these decisions."

How it works

Audit trail shows up in the workbook in two related but distinct ways:

  1. As a report component (Chapter 7). The SIA report must include an audit trail explaining which stakeholders, outcomes or indicators were included — and which were excluded — with a rationale for each decision. This is not simply a data log; it is a documented account of the choices the assessment made and why.
  2. As a property of the underlying data (Chapter 5). Primary data — collected first-hand through interviews, questionnaires, focus group discussions and surveys — must be "maintained in a form that can be retrieved by the impact assessor during audit trail." In other words, the audit trail is only as good as the underlying evidence being retrievable when the assessor goes looking for it.

The workbook also flags where an audit trail becomes difficult to maintain: for certain hard-to-reach stakeholder groups — its own examples are adult learners and nomads — traceability is described as a genuine challenge, and "primary evidence/audit trail for such groups will be an impediment." This is not a footnote detail; it is one of the workbook's named challenges in capturing social and economic impact.

Together, these give the audit trail two jobs: it documents why the assessment scoped itself the way it did (which stakeholders and indicators were in or out), and it ensures the evidence behind whatever was included can actually be produced and checked later.

A worked example

A Social Impact Assessor reviewing the Niwas housing repair project (1,265 families in Mumbai's slums) builds the audit trail for the assessment in two parts.

Decision trail. The assessor documents: direct beneficiaries, the Swagruha project team, local contractors, local suppliers and the local government office were all included as stakeholders consulted, with the rationale that each had first-hand knowledge of implementation or impact. A fifth potential stakeholder group — nearby residents not enrolled in the project — was excluded, with the rationale recorded that they were outside the project's direct beneficiary scope. Both the inclusion and the exclusion, and the reasoning for each, go into the audit trail.

Evidence trail. For the 15% sample of direct beneficiaries personally interviewed, the assessor retains the interview schedules, questionnaires and raw responses in a form that can be pulled up again later — so that, if a funder or the Social Stock Exchange later asks "how was the 75% improved-toilet-facilities figure derived?", the underlying primary data can actually be retrieved and checked, not just re-asserted.

Had the project instead tried to survey a genuinely hard-to-reach population — say, seasonal migrant labourers who move between sites — the workbook's own warning applies: building a reliable audit trail for that group would itself be "an impediment," and the assessor would need to document that limitation honestly rather than claim a traceability the data cannot support.

Why NISM asks about it

Chapter 7 (Social Impact Assessment Reporting), in the components-of-the-SIA-report passage, lists the audit trail as a required element covering stakeholder, outcome and indicator inclusion/exclusion decisions; Chapter 5 (Social Impact Assessment and Social Impact Assessors) ties audit trail to the retrievability of primary data, and separately flags it as a challenge for hard-to-reach stakeholder groups. Expect a question on what an audit trail must document as a report component, and a question on which stakeholder groups the workbook names as posing an audit trail challenge.

Common exam traps

  • The audit trail documents inclusion AND exclusion decisions, with reasons for both — a report that only explains what was covered, without explaining what was deliberately left out and why, is missing half of what the workbook requires.
  • Audit trail is a named, required component of the SIA report itself (Chapter 7), not merely a back-office record-keeping practice — leaving it out of the report is a reporting gap, not just an internal process failure.
  • Primary data must be retrievable "during audit trail" — the workbook ties audit trail directly to whether the underlying interview, survey and questionnaire data can actually be produced later, not just whether it was collected once.
  • Adult learners and nomads are the workbook's own named examples of hard-to-trace stakeholder groups — a scenario question describing a mobile or itinerant population is likely pointing at this audit trail challenge.
  • Do not confuse this with the desk review of secondary documents (annual reports, project documents, photographs) — those are sources of evidence the assessor examines; the audit trail is the documented record of decisions and the retrievability of the evidence itself.

Check yourself

  1. 1.Which of the following is a required component of an SIA report as listed in the workbook?

    1. a)A record only of the stakeholders and indicators that showed positive results
    2. b)An audit trail of which stakeholders, outcomes or indicators were included and excluded, with a rationale for each decision
    3. c)A full copy of every completed survey questionnaire
    4. d)A guarantee of future impact signed by the board
    Show the answer

    Answer: (b) An audit trail of which stakeholders, outcomes or indicators were included and excluded, with a rationale for each decision

    The workbook lists an audit trail for decision-making — which stakeholders, outcomes or indicators were included and which were not, and a rationale for each.

    Option A contradicts the rule that negative impacts must also be reported. Option C would break the rule that the report be as short as possible. Option D is not a component the workbook mentions.

Where this is taught

Free preparation for NISM Series XXI-A

Related terms

← All terms
Something look wrong? Report it