
DISA 4.0:The Digital Accounting and Assurance Board (DAAB) of the Institute of Chartered Accountants of India (ICAI) has announced the upgrading of the Post Qualification Course on Information Systems Audit from DISA 3.0 to DISA 4.0. The revamped DISA 4.0 ICAI course focuses on building practical audit skills, cybersecurity awareness, and risk management capabilities for Chartered Accountants. As new batches under the older version discontinue, existing DISA 3.0 candidates must understand the DISA 3.0 transition to the 4.0 framework.
The DISA 4.0 course is an upgraded Post Qualification Course (PQC) designed by ICAI to prepare members for complex digital environments. In response to rapid technology changes, cloud computing, and cybersecurity threats, ICAI revised the course structure to focus on hands-on practical application.
The revised ICAI DISA 4.0 curriculum moves beyond basic IT controls to emphasise real-world audit scenarios, data privacy compliance, and system security assessments. It provides members in practice and industry with practical tools to conduct IT risk assessments and internal system audits effectively. Click the button below to download the official notification:
Upgradation of DISA 3.0 to DISA 4.0 ICAI Notification PDF
DISA 4.0 and 3.0 details have been discussed below:
| ICAI DISA 4.0 & 3.0 Overview | ||
| Parameter | DISA 3.0 Framework | DISA 4.0 Framework |
| Conducting Authority | ICAI (Digital Accounting and Assurance Board) | ICAI (Digital Accounting and Assurance Board) |
| Primary Focus | Theoretical & Conceptual Information Systems Audit | Practical Exposure, Cybersecurity & IT Governance |
| Course Fee (New Candidates) | ₹20,000 | ₹25,000 |
| Bridge Class Fee (Upgrade) | Not Applicable | ₹10,000 |
| Refresher Course Fee (Qualified) | Not Applicable | ₹20,000 (DISA+ Refresher) |
| E-Learning Duration | 20 Hours | 15 Hours |
| Live Immersion Sessions | Not Available | 2 Days / 12 Hours |
| Practical Physical Training | 12 Days | 8 Days |
| Official Portal | learning.icai.org / icai.org | learning.icai.org / icai.org |
The DISA 4.0 course structure uses a blended learning model combining self-paced digital modules, interactive online sessions, and physical training:
Self-paced e-Learning (15 Hours): Covers foundational concepts of information technology, system controls, and security standards.
Live Immersion Sessions (2 Days / 12 Hours): Interactive online classes focused on practical concepts, tools, and technical case studies.
Physical Practical Training (8 Days): Classroom training focusing on auditing software, system log analysis, and simulated audit scenarios.
The expanded DISA 4.0 syllabus equips CAs to handle modern technology risks and regulatory demands:
Information Systems Audit & Governance: IT governance frameworks, IT strategy, and alignment with business objectives.
Cybersecurity Audit & Risk Management: Incident response planning, network security controls, and enterprise risk management.
Application Controls & Identity Access: Evaluating automated controls in modern enterprise resource planning (ERP) systems and identity management setups.
Third-Party Risk & Operations: Assessing vendor IT risks, outsourcing controls, and operational continuity strategies.
Business Resilience & Compliance: Data protection laws, Disaster Recovery Planning (DRP), and Business Continuity Planning (BCP).
The course is open exclusively to active members of the Institute of Chartered Accountants of India (ICAI).
Both practising CAs and CAs working in industry who hold a valid ICAI membership number can apply.
Visit the official ICAI Digital Learning Hub (learning.icai.org).
Log in using your registered SSP (Self Service Portal) credentials.
Select DISA 4.0 Registration from the available Post Qualification Courses.
Pick your preferred batch schedule for physical practical training.
Pay the prescribed DISA 4.0 fees online to complete your enrollment.
ICAI has introduced a clear DISA 4.0 transition framework to support candidates currently enrolled in DISA 3.0. The migration paths depend on your current stage in the program:
Path 1: Fresh Candidates
Members joining the program for the first time will enrol directly in DISA 4.0.
Complete 15 hours of e-learning, 12 hours of live immersion, and 8 days of physical practical training.
Candidates who passed the DISA 3.0 Eligibility Test but have not cleared the final Assessment Test (AT) receive a transition window of 2 years or 6 attempts.
They can finish the remaining Assessment Test attempts under the DISA 3.0 framework without paying an additional fee.
After the 2-year window expires, candidates must transition to DISA 4.0.
Candidates who finished DISA 3.0 classroom training but have not cleared the Eligibility Test can select one of two routes:
Option A (Migrate to DISA 4.0): Attend an 8-day practical bridge class, pay a DISA 4.0 upgrade fee of ₹10,000, and take the ET and AT under the DISA 4.0 syllabus.
Option B (Complete DISA 3.0): Continue under the DISA 3.0 track and clear the ET and AT within two years at no extra charge.
Chartered Accountants who already hold the DISA 3.0 qualification can take the optional DISA+ Refresher Course.
This course carries a fee of ₹20,000 and helps qualified members update their skills with modern cybersecurity and practical IT audit tools.
DISA 4.0 Fee structure is given below:
| DISA 4.0 Fee Structure | ||
| Candidate Category | Program Option | Applicable Fee |
| Fresh Applicants | Complete DISA 4.0 Course | ₹25,000 |
| Existing DISA 3.0 (ET Passed) | Finish DISA 3.0 within 2 Years / 6 Attempts | Nil |
| Existing DISA 3.0 (ET Pending) | Option A: Upgrade to DISA 4.0 via Bridge Classes | ₹10,000 |
| Existing DISA 3.0 (ET Pending) | Option B: Complete DISA 3.0 within 2 Years | Nil |
| Qualified DISA Members | Optional DISA+ Refresher Course | ₹20,000 |