Audit Exposes Cracks in J&K’s Digital Financial Firewall Part-I

CAG finds bills generated without budget allocation, altered transaction details, and missing audit trails in system meant to safeguard government spending
Comptroller and Auditor General report flags flaws in Jammu and Kashmir financial system. Image is representational.
Comptroller and Auditor General report flags flaws in Jammu and Kashmir financial system. Image is representational.Photo/AI Generated ChatGPT
Published on: 

(This news article is a three-part series. Part-I is published today.)

SRINAGAR: A computerised financial system created to put tighter controls on Jammu and Kashmir's public money allowed government bills worth more than ₹158 crore to be generated without corresponding budget allocations.

It also contained weaknesses through which critical details of financial transactions could be altered, a Comptroller and Auditor General audit has found.

More disturbingly, auditors examining the Integrated Financial Management System, or IFMS, found instances where information contained in a bill when generated through one government application was different when the same transaction reached another.

The findings raise fundamental questions about the integrity of the electronic architecture through which Jammu and Kashmir controls and records government expenditure.

The Comptroller and Auditor General (CAG) report, recently tabled in the Jammu and Kashmir Assembly, found serious gaps in the government’s financial control system. Safeguards meant to stop unauthorised spending and keep a record of changes to financial data were either missing or not working properly.

In perhaps the most striking finding, auditors discovered that during 2021-22, five Drawing and Disbursing Officers (DDOs) were able to generate bills totalling ₹75.06 crore for 47 schemes despite the absence of proper allocation through BEAMS, the government's Budget Estimation, Allocation and Monitoring System.

The following year, six DDOs similarly generated bills worth ₹83.23 crore covering 51 schemes without proper budget allocation.

The CAG said this demonstrated an "ineffective mechanism" within IFMS to exercise expenditure control and defeated the purpose of an integrated financial system.

As of January 2026, the report records that the government had furnished no specific reply to this finding.

The audit then encountered something potentially more troubling.

JKPaySys is used to prepare bills, while TreasuryNet processes them at the treasury. In an integrated financial system, the information should travel between the two without alteration.

But auditors found two bills generated in JKPaySys for ₹17,090 and ₹25,800 that were subsequently passed in TreasuryNet for ₹17,190 and ₹48,512, respectively.

The CAG described this as clear evidence that bill data was being manipulated at the database level.

The Finance Department attributed the discrepancies to heavy transaction traffic in March and said the problem had subsequently been corrected.

The auditors rejected that explanation.

Modern financial applications, the CAG observed, should maintain data integrity irrespective of transaction volumes. More damagingly for the government's explanation, one of the affected transactions was from January, not March.

The CAG therefore concluded that in the absence of database logs, "the possibility of unauthorised or uncontrolled alteration of bill data" could not be ruled out.

Auditors found another nine transactions during 2021-23 in which the Detailed Head of expenditure recorded in JKPaySys differed from that appearing in TreasuryNet.

They separately detected transactions where scheme codes differed between the two databases.

In another category, the audit found changes in DDO or Accountant General codes. The government's explanation linked these to conversion of codes involving corporations and autonomous bodies.

Again, the CAG rejected the explanation, saying the transactions identified by auditors did not involve such bodies. It said the cases "clearly indicate manipulation" in the codes.

No Footprints After Changing Records

Normally, even where an authorised official changes financial information, an electronic system should record who made the original entry, who changed it and when.

The J&K system did not provide that protection adequately.

The CAG found that although BEAMS, JKPaySys and TreasuryNet had audit-trail tables, they did not maintain a complete transaction history showing who inserted records and who subsequently modified them.

That weakness is particularly significant because auditors had already discovered discrepancies between data travelling through the different applications.

Without the logs, the CAG said it could not determine how many transactions may have been altered.

The Finance Department accepted the observation and said corrective measures would be incorporated in the next version of IFMS.

There was another basic security problem.

A person logged into JKPaySys as a "Checker" could, auditors discovered, click a particular link and acquire "Maker" functions without entering the Maker's password.

The maker-checker principle exists precisely to prevent one official from both creating and approving sensitive financial transactions.

The Department acknowledged the weakness and told auditors that NIC had agreed to correct it.

Comptroller and Auditor General report flags flaws in Jammu and Kashmir financial system. Image is representational.
J&K Economy Grows, But the Exchequer Leans Harder on Delhi: CAG Audit Flags Deepening Fiscal Dependence

System Still Unfinished

IFMS was not a new experiment. Jammu and Kashmir began implementing the project in March 2010. Yet by March 2023, the CAG found that only four of the 12 proposed modules were fully operational.

The project was therefore more than a decade behind full implementation. The consequences were financial as well as technological.

Because the government did not revise its Detailed Project Report according to Government of India instructions and failed to meet prescribed milestones, Jammu and Kashmir lost ₹11.88 crore in central assistance, according to the audit.

Another ₹5.26 crore earmarked for upgrading the State Data Centre remained misutilised, while IFMS applications were instead hosted at NIC's Mini Data Centre in Jammu without the proposed supporting disaster-recovery site.

The CAG found that ₹97.50 lakh had specifically been proposed for a business-continuity and disaster-recovery arrangement.

Yet as of March 2024, there was no separate recovery infrastructure. The government told auditors that regular backups were maintained, and another copy was kept at the Civil Secretariat.

The CAG was unconvinced. It noted that NIC backups were located in the same premises where the applications themselves were hosted. A disaster affecting that location could therefore threaten both the operational system and its fallback.

The audit also exposes the gap between the promise of digitisation and actual government functioning.

The Finance Department had ordered that from May 1, 2019, treasuries would process only electronic bills.

Yet Treasury officials could not retrieve online bills until DDOs physically delivered documents carrying barcodes and supporting papers.

Auditors also found 11,534 non-pension bills manually processed by 317 DDOs during 2021-22 and another 2,281 by 158 DDOs in 2022-23.

The system meant to eliminate manual processing was therefore still dependent upon it.

There were weaknesses even in the database of people and entities receiving government money. Auditors found 24,023 duplicate agencies or beneficiaries in 2021-22. By 2022-23, that number had climbed to 34,188.

The Department's response did not satisfy the CAG, which found instances where the same vendor appeared multiple times with different Goods and Services Tax identification numbers.

The system checked whether a GST number was valid and active but did not automatically retrieve taxpayer details or prevent duplicate vendors from being entered.

Cyber-Security Questions

The report says IFMS was also not certified to the quality and information-security standards envisaged in its project design.

The CAG noted that in May 2025 several J&K government websites, including JKPaySys, were taken down over non-compliance with cyber-security protocols and vulnerability assessment and penetration-testing requirements.

Auditors found neither NIC-J&K nor the government had ensured the prescribed testing and certification. A risk register had not been prepared, while unofficial addresses, including Gmail and dummy email accounts, were also being used.

Taken together, the findings reveal something larger than an unfinished IT project.

Jammu and Kashmir created IFMS to make public spending traceable from budget allocation to bill generation and treasury payment. More than a decade later, the CAG found weaknesses at each of those points.

Comptroller and Auditor General report flags flaws in Jammu and Kashmir financial system. Image is representational.
After touring J&K, CCG flags ‘dangerous drift’ and growing disillusionment
Kashmir Times
kashmirtimes.com