All insights

State Modernisation

Legacy System Audit Before Any AI Project

· 9 minute read

An agent on an unaudited twenty-year system will inherit every silent batch job and unnamed owner. Do the legacy audit first. The model can wait.

A state department asked for an agent on top of the existing application. The existing application was a 2004 Oracle form, a 2012 web wrapper, a night batch that recomputed demand, a shared database user called APP, and two officers who still knew why a flag named TEMP2 must never be 7. Nobody wrote that down. The vendor connected a retrieval layer to a reporting view that was twelve hours stale. Citizens received fluent answers about yesterday's demand.

This cluster is state modernisation. The first honest step is not a model. It is an audit of what you already run: who owns it, what it writes, when it batches, which identity it trusts, which fields are personal or land-critical, and which jobs will fight an agent at 02:00.

This checklist is for state CIOs, SDC leads, NIC coordinators and departmental system owners. It is written on 17 August 2026. It is not an STQC audit and not legal advice. It is the minimum you should attach before any agent work order.

Inventory what you actually have

Name the legal system of record. Not the dashboard. The table or register that a court would ask for. If two systems both claim a citizen's demand, you do not have a legacy system. You have a dispute. List runtimes: OS, database, app server, job scheduler, report engine, SMS gateway, payment, document store. Versions, last patch, who may patch, who still has the installer.

List identities: AD / LDAP / Aadhaar-based login / department code / shared password on a sticky note. An agent cannot be cleaner than the shared APP user it inherits. List batch jobs and their windows. An agent that reads at 10:00 and a batch that overwrites at 02:00 will gaslight every officer.

Minimum inventory rows. If a row is unknown, the agent project is premature.
RowAskFail the kickoff if
System of recordWhich table/register a court getsTwo answers from two wings
OwnerNamed post, not NIC / vendor / weOwner is a firm that exited
IdentityHow a user is unique; shared accountsProduction used via a common password
Write pathWhich roles can mutate the recordNobody can list the roles
Batch / CDCJobs, windows, lag of viewsReporting view age unknown
Personal / land-critical fieldsClassification, maskingEverything is in one schema called DATA
LogsApp, DB, admin; CERT-In 180-day floorLogging is on the vendor SIEM
Exit artefactsSchema, jobs, licence keys, sourceSource is missing and vendor is gone

Read paths you can live with

Prefer a read replica, a documented view, or an API the owner will support. Do not point an agent at the OLTP table just for the pilot. Pilots become production at 11 p.m. on a Saturday. Measure lag. If the replica is six hours behind, the agent's disclaimer must say so, or the agent must not answer time-critical questions (demand paid, mutation status, exam fee). Character encodings in old Indian systems are archaeology. A view that mojibakes khatauni text will make the agent fluent and wrong. Sample Indic fields before you promise retrieval quality.

Write paths you must not invent

If the legacy app has no API for a mutation, the agent does not get to SQL-update its way to glory. That is how you skip validations, stamps and court-defensible numbers. If the only write path is a form, the agent drafts and the officer uses the form. Wrapping is the next article. The audit's job is to say, in writing, that no safe write API exists. Payment, demand, mutation, FIR, marks, pension — default deny. The audit should print those names so a later enthusiast cannot just add a tool.

People and paper

Find the two officers who know TEMP2. Record them on video if you must. Knowledge that lives in one retirement is a single point of failure no model can retrieve. Find the manuals that the app no longer matches. The agent must not retrieve a 2011 circular as if it were live. The audit tags live versus archival. Find the vendor still on AMC, if any. An agent project that does not include that vendor's change window will be blamed for the next batch failure whether or not it caused it.

  • Photograph the deployment diagram as it is, not as the 2016 PPT claimed.
  • Export a data dictionary even if it is incomplete. Date the gaps.
  • List every integration that already breaks when DNS or the state WAN blips.
  • Note which environments still contain production PII (most staging systems do).
  • Note licence constraints that forbid a second reader process.

Two rooms you can walk into

The audit was the project. The agent was optional.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note.

We already have an IT audit / ISO / STQC.

Those are useful and differently shaped. This checklist is about whether an agent can read without lying and write without skipping a validation. Attach them. Do not substitute them.

The vendor will discover this during implementation.

Then you are paying discovery at production risk. Pay discovery as an audit with a stop gate.

Documentation will take a year.

A two-week minimum inventory is enough to know whether to stop. Perfect dictionaries are a later luxury.

This is only a chatbot on circulars.

Then the audit is shorter: you still need a live-versus-archival tag and a place that is not the OLTP. If the chatbot will also just check status, you are back to the full list.

A ten-day legacy audit that can stop the project

If day ten says stop, you saved the year. Write that as a success in the file.

  1. Days 1–2: name the system of record, owner, identities, and whether staging has production PII.
  2. Days 3–4: list batch jobs, view lag, and every write role. Print the default-deny list.
  3. Days 5–6: sample Indic fields, personal-data classes, and two court-defensible extracts.
  4. Days 7–8: interview the TEMP2 officers; record live versus archival circulars.
  5. Days 9–10: gate note — read path allowed / disallowed; write path none; agent project go / no-go.

How this shows up in the file

Subject: Legacy system audit — precondition for any agent. System of record named. Owner named. Identity defects listed. Reporting lag in hours. Write API for agent use: none. Default-deny writes listed. Live circular pack tagged. Staging PII yes or no. Recommendation: go on a replica, stop for reconciliation, or stop until owner exists. This audit is not an STQC certificate.

What we will and will not claim

Prcept AI will not wrap an agent around a register two wings still fight over. We will sit through the ten-day audit, on-prem, and accept a no-go. A model on a disputed table is not modernisation. It is a fluent argument.

This article is informational field guidance for Indian universities and public institutions, not legal, procurement, audit or engineering advice. Confirm against the live Gazette, GFR, state financial rules, GeM terms, UGC text, GIGW, DPDP commencement, departmental manual and your counsel before you file it.

How to sequence this in a state, not a slide

“Legacy System Audit Before Any AI Project” is a department problem. A P1 CIO/CTO should name the legacy system, the officer who owns the file, and the citizen charter clock before buying “legacy system audit government AI”.

An agent on an unaudited twenty-year system will inherit every silent batch job and unnamed owner. Do the legacy audit first. The model can wait. Do not invent league tables of states. Read tenders and policies. Election Model Code of Conduct can freeze a rollout. NIC is a partner, not a villain. SDC readiness is GPU, power, ops and egress — not a logo.

  • Audit the legacy store first.
  • Keep mutation and money as officer actions.
  • Map SLAs to the citizen charter.
  • Budget change requests after go-live.

Close this loop before the next CAB

Put “Legacy System Audit Before Any AI Project” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “legacy system audit government AI” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Do we need a legacy audit if the agent will only read circulars?
A lighter one: live-versus-archival tagging and a store that is not the OLTP. If anyone says also check application status, run the full checklist.
Is this the same as a CERT-In or STQC audit?
No. CERT-In directions shape logs and incidents. STQC shapes certain quality certifications. This checklist asks whether an agent will lie or skip a validation. Do all that apply; do not merge them.
What if the original vendor has vanished?
That is an audit finding. You may still put a read replica in front of a well-understood extract. You may not invent writes. Budget a maintainability project separately.
How long should the audit take?
A go/no-go inventory can take ten working days if owners are in the room. A full data dictionary can take months. Do not block the first on the second, and do not skip the first.
Who signs the audit?
The system owner and the CIO or SDC lead. The AI vendor may help list questions. They do not certify their own runway.

Sources