· 3 min read
By Correct Editorial — Compliance Research Desk
Who Should Hold GST and MCA Logins and Challans?
Published on: August 15, 2026
A recurring complaint in Indian founder-CA relationships is simple: the firm registered every portal under its own email and phone, so the director cannot log in to GST, MCA or income tax, and challans appear only after an invoice is cleared. That arrangement is common. It is also a control failure.
Portal logins, OTPs, challans, board resolutions and filed forms are company records. The professional files them. The company owns them. Section 36 of the CGST Act, 2017 requires GST books and related documents to be retained for 72 months from the due date of the annual return. The Companies Act, 2013 treats minutes, registers and ROC filings as records of the company, not of the practising CS.
This guide sets out who should hold credentials, how long evidence must last, what to do when an engagement ends, and how to grant access without giving the keys away.
What Goes Wrong When the Firm Owns the Login?
Three failures show up in diligence and in notices:
- The company cannot file or reply. A notice on GSTIN or a DIN KYC window needs an OTP that lands on a phone the founder does not control.
- Evidence is incomplete. Bank KYC, Series A data rooms and tax audits ask for three years of challans and SRNs. If they live in a practitioner inbox, the pack is late.
- Access is used as leverage. Unpaid professional fees become a reason to withhold records. The company then misses the next due date and pays late fee on top of the invoice dispute.
The opposite design is straightforward: one encrypted store the company controls, with access granted per person and revoked when work ends.
What Must You Keep, and for How Long?
| Record | Why it exists | Typical retention |
|---|---|---|
| GST invoices, 2B, 3B ARN, payment challans | Section 36 CGST Act | 72 months from annual-return due date |
| MCA e-forms, SRNs, fee challans | Companies Act filings and proof of fee | At least 8 years for many registers; keep filing packs with the minutes they support |
| TDS challans and 26Q/24Q acknowledgements | Income-tax audit trail | Align with assessment limitation |
| PF/ESI ECR and challans | EPFO / ESIC inspections | Keep with payroll records for inspection cycles |
| Portal IDs, authorised signatory list | Who can file | Until superseded, then archive |
Store the document and the login that produced it in the same vault. A filing marked complete with no challan is not complete.
How Should Access Be Granted?
- Register GST, MCA and income-tax primary email and mobile on a company-owned mailbox and SIM or virtual number the company can recover
- Issue additional users or authorised signatories to the CA, CS or accountant. Do not transfer the primary ID
- Grant vault access named, time-bound, and revocable
- When the engagement ends, rotate passwords, remove authorised signatories on the portals, and export a full evidence pack to the company
Professionals still need to work. They need access. They do not need exclusive custody.
What Does the Law Expect of Directors?
Directors remain responsible for ROC filings and for books of account even when a firm files the forms. "Our CA had the password" is not a defence to additional fees on AOC-4 or to a GST late fee on GSTR-3B. Assign an internal owner who can log in without calling the firm.
For the annual ROC cycle see Annual Compliance Calendar for Companies (2025-26). For GSTR-3B cost of delay see GSTR-3B Due Date and Late Fee in India.
Correct's vault is built so documents and passwords stay encrypted, access is per person, and if you leave you take everything with you. No records held against an unpaid invoice. Read the product at Correct.
Practical Checklist
- Primary GST and MCA credentials on company identity
- Named additional users for the filing firm
- Challans and ARNs uploaded the day they are generated
- Revocation drill twice a year: who still has access who should not
- Exit pack in the contract: SRNs, challans, working papers, and portal user list
References
- CGST Act, 2017 — Section 36 — Retention of books and records
- Companies Act, 2013 — books, registers and filing — Company records and ROC e-forms
- GST Portal — User management — Additional users and authorised signatory
- MCA21 — V3 user roles — Business user vs professional user
- ICAI — Code of Ethics — Client records and professional conduct
- ICSI — Secretarial standards and records — Minutes and filing custody
Frequently asked questions
- Should my CA firm hold the GST and MCA portal logins?
- The firm may be granted access to file. The company should still own the credentials, the registered email and mobile, and a copy of every challan and acknowledgement. If the engagement ends, access should be revoked and the records should leave with the company, not stay on the firm's drive.
- How long must GST records be kept?
- Section 36 of the CGST Act requires books and related records to be retained for 72 months from the due date of furnishing the annual return for the year. Keep challans, invoices, 2B extracts and ARN letters for that full period.
- What company records must stay with the company under the Companies Act?
- Registers, minutes, financial statements and ROC filing evidence are company records. Directors remain responsible for them even when a practising CS files the e-forms. Copies of AOC-4, MGT-7, SRNs and fee challans should sit in a company-controlled store.
- Can a professional withhold challans until an invoice is paid?
- Statutory records and portal access belong to the company. Holding challans or login OTPs against an unpaid fee leaves the company unable to file, respond to a notice, or prove payment. Separate commercial disputes from custody of evidence.