2.77 lakh IDs missing: CAG flags possible back-end deletions in Assam's financial database

During an Information Technology audit of the Integrated Financial Management System (IFMS) for the Himanta Biswa Sarma government in Assam, the Comptroller and Auditor General (CAG) has discovered alarming irregularities regarding the reliability of the state's financial data.
The CAG's report on the Social, Economic, and General Sectors in Assam for the period ending in March 2024 found gaps in database sequence IDs totaling approximately 2.77 lakh missing records, suggesting possible manual intervention at the back end to delete data.
The audit also found that the system lacked a documented Business Continuity or Disaster Recovery Plan, leaving the state's financial data vulnerable.
What is an Integrated Financial Management System?
IFMS is an integrated financial management system consisting of online budgeting, online budget distribution, re-appropriation, e-ceiling management & online salary bill.
The initiative is intended to make the process of ceiling management and payment releases shorter & more transparent.
To understand the gravity of the finding, the report first explains that every table in the IFMS database includes a specific safeguard: "a data field named 'ID', which is a system generated sequential number to each record in the tables to maintain uniqueness". Because these numbers are generated automatically in order, any missing numbers in the sequence serve as a red flag for auditors.
The CAG's discovery of gaps
When auditors scrutinized these sequences, they found massive holes in the digital trail. The report states: "Audit analysed the sequence of ID columns in four important tables in the database and found that there were 2.77 lakh records (IDs) missing in these tables".
Specifically, the audit identified 2,76,803 missing serial numbers across four critical areas of the financial system:
- Budget Allocation: 1,54,401 missing records.
- Budget Distribution: 90,667 missing records.
- Heads of Account: 31,598 missing records.
- Administrative Approvals: 137 missing records.
To understand the CAG’s findings regarding the missing 2.77 lakh records in plain English, think of the government's financial system as a digital receipt book.
In a standard receipt book, every page is numbered in order (1, 2, 3, 4...). If you open the book and see page 10 followed immediately by page 20, you know someone ripped out pages 11 through 19.
The state’s financial software (called the IFMS) works the same way. Every time a transaction is made -- like distributing a budget or approving a project -- the system automatically gives it a serial number (an "ID"). When auditors checked the "book," they found massive jumps in these numbers. Across four main sections of the system, 2,76,803 serial numbers were simply missing.
ALSO READ | Assam floods leave 80 dead, 2.12 lakh affected; relief operations continue across eight districts
Evidence of Manual Intervention
The report notes that while small gaps can sometimes occur due to system errors or aborted transactions, the scale of these missing IDs suggested something far more deliberate.
Usually, if a transaction is canceled, the system records it. However, these gaps were so large -- one gap alone was over 1 lakh numbers long -- that auditors concluded it wasn't just a computer glitch. Instead, they suspect "manual intervention at the back end".
The CAG report explicitly warns: "The larger gaps indicated possible manual intervention at the back end of the system to delete records". In some instances, the gap in a single sequence was as large as 1,06,845 missing IDs.
In layman's terms: someone likely bypassed the normal "front" screen of the computer (where there are rules and records of who does what) and went directly into the "brain" of the database to delete records.
The "Missing" Logs
The mystery deepened when auditors attempted to verify why these deletions occurred.
To find out who deleted the records and why, auditors asked for the Database Administrator logs. Think of this as a "security camera" or a secret diary that records every single thing a high-level technician does behind the scenes.
The Finance Department did not give these logs to the auditors. Because the "secret diary" was hidden, the auditors said they could not be sure if the state's financial data was honest or reliable
The CAG notes a significant lack of transparency from the Finance Department: "In this regard, the Database Administrator logs were not furnished to Audit. As a result, Audit was unable to derive assurance on the integrity and reliability of data".
When auditors analyzed the general user activity logs that were provided, they found a startling contradiction. Despite the 2.77 lakh missing IDs, the report notes that "no record of occurrence of deletion of entries, approval of entries, etc., were noticed" in those specific logs. This lack of recorded activity for such massive data removal further highlighted the "weakness in timestamp integrity and database control measures".
Why this revelation matters
The missing records weren't just random files; they were in critical areas:
- Budget Allocation: 1.54 lakh missing records.
- Budget Distribution: Over 90,000 missing records.
- Heads of Account: Over 31,000 missing records.
When records of how money is moved and approved are deleted without a trace, it creates a massive risk that unauthorized spending or financial manipulation could be hidden from public view.
Without these digital "serial numbers," it is nearly impossible to track exactly where every rupee went or if the books have been "cooked."
Assam government's response
Following these findings, the Finance Department informed the CAG in August 2024 that it has since "undertaken steps to avoid and monitor data updation without authorisation" and that "audit trails have been enforced for all such users" to prevent future manipulation.
However, the CAG maintained its conclusion that the system had failed to shift the "burden of compliance from individual users to the IFMS application," leaving the state's financial records vulnerable to unauthorized manual changes.