Skip to Content
Home / Services / Audit & Assurance / Internal Audit & Internal Controls
Audit & Assurance

Internal Audit & Internal Controls

Evaluating internal controls and risk management processes to improve operational efficiency.

Overview

Internal audit is an independent review of an organisation's processes, controls and risk management, carried out for the board and management. Its purpose is to check whether controls are designed well and are working in practice, and to recommend improvements before issues turn into losses.

A good internal audit function looks at how transactions actually flow through the business: who approves, who records, who reconciles, and where the gaps are. It supports the audit committee and strengthens corporate governance.

Who needs this service

Listed companies (mandatory)
Unlisted public companies with paid-up capital of ₹50 crore or more, turnover of ₹200 crore or more, borrowings above ₹100 crore, or deposits of ₹25 crore or more
Private companies with turnover of ₹200 crore or more, or borrowings above ₹100 crore
Growing businesses that want stronger controls before scaling or fundraising
Boards and audit committees seeking independent assurance

Legal and regulatory framework

  • Companies Act, 2013: Section 138 and Rule 13 of the Companies (Accounts) Rules, 2014
  • Section 134(5)(e): directors' responsibility for internal financial controls
  • Section 177: role of the audit committee
  • Standards on Internal Audit issued by the ICAI
  • SEBI (LODR) Regulations, 2015 for listed entities

Scope of services

Process audits

  • Revenue and receivables: order to cash, credit limits, collections
  • Procurement and payables: purchase to pay, vendor onboarding, three-way match
  • Inventory: receipts, issues, physical verification, valuation
  • Payroll: masters, attendance, salary changes, statutory deductions
  • Treasury: banking, payments authorisation, investments

Internal financial controls (IFC)

  • Documentation of risk and control matrices (RCMs)
  • Testing of design and operating effectiveness
  • Support for management's IFC assessment and the statutory auditor's review

Compliance reviews

  • Statutory compliance calendar and filings
  • Delegation of authority and approval matrices
  • Related party transactions and their approvals

Follow-up

  • Action-taken reports on earlier observations
  • Root-cause analysis for repeat findings

How the engagement works

  1. Risk-based planAnnual internal audit plan prioritising high-risk processes, agreed with the audit committee.
  2. Process walkthroughUnderstanding of each process with the people who run it, and mapping of key controls.
  3. TestingSample testing of transactions and controls, with evidence documented.
  4. ReportingObservations rated by risk, with root cause, impact and agreed management action and timeline.
  5. Follow-upTracking of actions to closure and reporting status to the audit committee.

Documents typically required

Organisation chart and delegation of authorityStandard operating procedures and policiesERP access or transaction reports for the periodPrevious internal and statutory audit reportsMinutes of audit committee meetings

Key forms and due dates

ItemTimeline
Appointment of internal auditorBy the Board, for applicable companies, typically at the start of the financial year
Reporting frequencyQuarterly or half-yearly, as agreed with the audit committee

Indicative; subject to amendments and extensions notified by the authorities.

Deliverables

The scope of each engagement is agreed in writing and depends on the nature, size and regulatory requirements of the entity.

Frequently asked questions

Can the statutory auditor also be the internal auditor?

No. Section 144 of the Companies Act, 2013 prohibits the statutory auditor from providing internal audit services to the same company.

Is internal audit useful for companies not required to have one?

Yes. Many growing businesses use internal audit to find leakages, strengthen approvals and prepare for investors or banks.

What are internal financial controls?

Policies and procedures that ensure orderly and efficient conduct of business, safeguarding of assets, prevention and detection of fraud and errors, and accurate and timely financial records.

How are observations rated?

Typically as high, medium or low based on financial impact and likelihood, so management can prioritise action.

This page is for general information only and does not constitute professional advice or solicitation.