One certificate, one number, no exceptions

Every certificate a practising Chartered Accountant signs now needs a UDIN — a Unique Document Identification Number generated from the ICAI portal. This is not new: UDIN has been mandatory for all certificates since 1 February 2019, and for GST and tax audit reports since 1 April 2019. What is striking is how many firms still treat the UDIN as an afterthought — a number generated in a hurry, pasted onto a document, and then recorded nowhere in particular. The certificate goes out; the UDIN evaporates into a portal and a vague memory.

UDIN exists for a good reason. Members' names and signatures were being misused, and forged certificates were circulating in the market. The number ties a specific document to the specific CA who signed it, verifiable by any bank, regulator or authority that receives it. That makes your UDIN record a genuine compliance asset — and, if you manage it carelessly, a genuine exposure.

What 2025 changed, and what 2026 will

The rules around UDIN keep tightening, and two recent moves make a casual approach untenable. From 20 June 2025, generating a UDIN under the 'GST & Tax Audit' or 'Audit & Assurance' categories requires disclosing the auditor's opinion — whether it is unmodified, qualified, adverse, or a disclaimer — along with indicators such as Key Audit Matters, Emphasis of Matter, and material uncertainty on going concern where relevant. PAN details are now mandatory at the point of generation. And from 1 April 2026, the portal will cap each CA at 60 tax-audit UDINs in a financial year, enforced at the system level. Read together, these mean your UDIN record has stopped being a footnote and become live, firm-level operational data you have to be able to see.

  • Every UDIN generated, tied to the client, the engagement and the exact document it belongs to.
  • The ICAI-prescribed window to generate a UDIN after signing, so none is ever missed.
  • Which signed certificates still do not carry a UDIN — the gap that invites an ICAI query.
  • A running count of tax-audit UDINs against the 60 cap, per partner, well before year-end.
  • Any revoked or cancelled UDINs, with the reason, kept on the record.
A UDIN you generated but never recorded is a certificate you cannot account for. Multiply that by a busy season and you have a compliance blind spot, not a practice.

Where the filing tools stop

It is worth being fair to the software you already run. Genius, CompuTax, Winman and Suvit are strong at computing income, preparing returns and filing them, and some will help you push a UDIN as part of that flow. But they think per return and per filing, not per firm. None of them will tell you, across every partner and every client at once, how many tax-audit UDINs the firm has consumed this year, or which signed certificate went out the door without a number attached. That cross-cutting, whole-practice view is a practice-management job, and it is precisely the job a computation engine was never built to do.

Every attestation the firm issues: who signed it, when, for whom, and under which UDIN.
Every attestation the firm issues: who signed it, when, for whom, and under which UDIN.

Getting this wrong is not abstract. ICAI has held that failing to generate a UDIN where required amounts to professional misconduct, and a certificate that cannot be verified is a certificate a bank or authority can simply reject and send back — usually at the exact moment a client's loan or filing depends on it. Add the new tax-audit ceiling, and a firm that is not watching its running count can find, late in the year, that a partner has no headroom left to sign. None of these are dramatic on the day they are set up; they are the quiet failures that surface under deadline pressure, which is the worst time to discover them.

UDIN is really a document-and-audit-trail problem

Strip UDIN back to its essence and it is a knowledge problem: for every attestation the firm issues, do you know who signed it, when, for which client, under what number, with the document itself on file and retrievable? That is the same muscle as a client document vault and a deadline tracker — the muscle of a practice that runs on a system rather than on the memory of whoever generated the number. Treat UDIN as isolated admin and it stays fragile. Treat it as one more thing the practice records by default, and it stops being a worry at all.

Run the practice, not just the returns: the compliance back office of a CA firm.

How BizRevolt keeps UDIN under control

BizRevolt's practice workspace keeps a UDIN register that ties every number to its client, its engagement and the stored document behind it. It flags certificates that were signed but not yet numbered, keeps the generation window in view, and maintains a running, per-partner count of tax-audit UDINs against the 60 ceiling so that April 2026 arrives as a date you planned for rather than a wall you hit. It sits deliberately alongside your filing tool: BizRevolt does not compute returns and has no wish to replace Genius, CompuTax, Winman or Suvit. It makes the practice around those returns — the certificates, the numbers, the deadlines, the documents — defensible.

Pricing is a flat 1,499 rupees a month for a solo professional and 4,999 for a firm — a subscription that complements your computation software rather than competing with it. You keep filing where you already file. What changes is that the UDINs, the certificates and the audit trail behind them stop living in a spreadsheet nobody fully trusts and start living in a system the whole firm can rely on.

If your UDINs are technically all there but scattered across a portal and a partner's memory, that is the exact gap we close. WhatsApp the founder, or call +91 91 0657 4865, and we will show you what a proper UDIN register looks like — usually within about fifteen minutes on a working day.

Image credit: Blogtrepreneur, CC BY 2.0, via Wikimedia Commons.