Avinav Verma
Jammu: Jammu and Kashmir’s Integrated Financial Management System (IFMS), conceived to bring financial transactions under a real-time, technology-driven control mechanism, remains plagued by delays, incomplete modules and serious data-security weaknesses, the Comptroller and Auditor General of India (CAG) has observed.
The CAG’s Information Technology Audit of IFMS, included in its Report No. 3 of 2026 tabled Autum session of Jammu and Kashmir Legislative Assembly, found that despite the project being taken up in March 2010, only four of the 12 proposed modules were fully operational as of March 2023.
Four modules were only partially implemented and two had not been implemented, leaving several key financial functions dependent on manual processes.
he audit found that the project was originally scheduled for completion within 14 months of the signing of the MoU in May 2012. Instead, more than a decade later, key components of the system were still incomplete.
Among the financial consequences flagged by the CAG, J&K lost ₹11.88 crore in central assistance after the Detailed Project Report was not revised in accordance with Government of India instructions and prescribed milestones under the treasury computerisation programme were not achieved.
The audit also questioned the handling of infrastructure meant to support the system. Instead of upgrading the State Data Centre for hosting IFMS applications, the applications were hosted on the NIC Mini Data Centre at Jammu without a supporting backup site.
The CAG noted that ₹5.26 crore earmarked for the State Data Centre-related work remained misutilised.
The deficiencies were particularly visible in the Budget Estimation and Management & Allocation System (BEAMS).
The CAG found that reappropriation of funds was being processed through physical files instead of through BEAMS, with the amounts subsequently entered manually into the system at the backend. During 2023-24, ₹220.98 crore was reappropriated, while ₹624.77 crore was reappropriated during 2024-25.
More significantly, of the ₹624.77 crore reappropriated for 2024-25, ₹515.72 crore was approved only after the financial year had closed, during 2025-26. T
he audit said the absence of a system-based tracking and approval mechanism meant IFMS could not ensure that reappropriated funds were made available in time.
The CAG also found that the surrender functionality had not been developed in BEAMS, forcing the process to continue manually.
The audit found another significant discrepancy while comparing JKPaySys and TreasuryNet data.
Of 2,564 non-pension bills test-checked for 2021-22 and 2022-23, 98 bills worth ₹1.67 crore were paid through TreasuryNet but had no corresponding record in the JKPaySys database.
The JKPaySys records for the test-checked bills totalled ₹93.88 crore, against ₹95.55 crore recorded in TreasuryNet.
This was despite a Finance Department circular directing that, after implementation of JKPaySys, only electronic bills should be processed by treasuries from May 1, 2019.
The audit found that 11,534 non-pension bills were manually processed by 317 DDOs in 2021-22, while another 2,281 non-pension bills were manually processed by 158 DDOs in 2022-23.
The CAG rejected the explanation that differences were merely the result of phased implementation or technical issues, pointing instead to shortcomings in integration between IFMS applications.
The audit also detected differences between DDO codes recorded in JKPaySys and those appearing at the TreasuryNet stage.
In one case involving a travelling allowance bill generated by the Zonal Education Officer, Udhampur, the system-generated bill number was manually altered on the physical bill, while the original number was also deleted at the database level.
The CAG linked the incident to the failure of the Government to take over key database administration functions and the non-implementation of a database management policy, observing that these shortcomings had led to tampering with transactions.
The audit raised perhaps its most serious concern over the ability of the system to establish accountability for changes made to financial data.
According to the CAG, IFMS lacked robust logical access controls, effective password-recovery mechanisms and transaction logs. The system did not maintain a complete trail showing who inserted a record and who subsequently modified it.
The audit further found that key administrative functions, including user onboarding and deboarding and management of master data, had not been fully taken over by the J&K Government. Several applications continued to be managed by the NIC-JK Project Management Unit and remained hosted on the NIC Mini Data Centre even after 12 years.
The CAG said continued reliance on the system integrator, developer and support team for sensitive administrative functions posed a security risk, particularly in the absence of transactional or data-modification logs.
The audit also found weaknesses in testing before deployment.
As of March 2024, User Acceptance Testing had not been conducted for IFMS applications except
TreasuryNet, for which testing was conducted in 2011.
The CAG noted that formal UAT documentation was not made available to audit and observed that
frequent additions of modules indicated that applications may have been made live without adequate user acceptance testing.
The report also called for comprehensive business-process re-engineering, stronger validation, role-based access controls and multi-factor authentication, proper password management, transaction audit trails, a disaster-recovery plan with defined recovery objectives, documented UAT and independent STQC certification.
The audit’s findings collectively point to a system that was intended to digitise and strengthen financial governance but, according to the CAG, continued to carry manual processes, fragmented applications and weak accountability mechanisms more than a decade after its implementation began.
