| 118 Annual Report | 2025-2026 Arohan Financial Services Limited Independent Auditor’s Report of even date on the financial statements of Arohan Financial Services Limited for the year ended March 31, 2026 (cont’d) Information Technology systems and controls The key audit matter How the matter was addressed in our audit Information Technology (IT) systems and controls The Company’s key financial accounting and reporting processes are dependent on the automated controls in information systems. There exists a risk in the IT control environment which could result in the financial accounting and reporting records being misstated. We have identified ‘IT systems and controls’ as a key audit matter considering the high level of automation and the complexity of the IT architecture. Further, it impacts on overall financial reporting process and regulatory expectations on automation. In view of the significance of the matter, we applied the following audit procedures in this area, among others to obtain sufficient audit evidences for scoped in application by involving our IT specialist: 1. Evaluating and testing the design, implementation and operating effectiveness of the significant accounts related to IT applications controls relevant to the accuracy of system computation, and the consistency of data transmission. 2. Evaluating and testing the design, implementation and operating effectiveness of key General IT Controls. This includes controls on Access management, Change management and IT Operations. 3. User access management controls which includes access authentication through password configuration management, granting or modification of user access, creating new users, deactivating user access for exiting users, user access and privileged access examination basis their role and function. 4. Program changes which include changes moved into production environment as per defined procedures and relevant segregation of duties are ensured. 5. IT Operations which includes Job monitoring, scheduling, backup and recovery. 6. We also evaluated the design and the operating effectiveness of relevant key IT dependencies within the business process which included testing automated controls, interfaces and system generated reports, as applicable. 7. Understanding Cybersecurity Risk Management Framework followed by the entity for information assets, including information, applications systems, databases, networks and data storage systems. 8. We communicated with those charged with governance and management, tested combination of compensating controls or remediated controls and / or performed alternate audit procedures, where necessary. Based on procedures performed above, wherever required, we extended our audit procedures over other IT application controls, periodic reconciliations, manual approval processes, tests on identified key changes and additional substantive testing. Independent Auditor’s Report
RkJQdWJsaXNoZXIy NTE5NzY=