Overview
Internal audit is an independent review of an organisation's processes, controls and risk management, carried out for the board and management. Its purpose is to check whether controls are designed well and are working in practice, and to recommend improvements before issues turn into losses.
A good internal audit function looks at how transactions actually flow through the business: who approves, who records, who reconciles, and where the gaps are. It supports the audit committee and strengthens corporate governance.
Who needs this service
Legal and regulatory framework
- Companies Act, 2013: Section 138 and Rule 13 of the Companies (Accounts) Rules, 2014
- Section 134(5)(e): directors' responsibility for internal financial controls
- Section 177: role of the audit committee
- Standards on Internal Audit issued by the ICAI
- SEBI (LODR) Regulations, 2015 for listed entities
Scope of services
Process audits
- Revenue and receivables: order to cash, credit limits, collections
- Procurement and payables: purchase to pay, vendor onboarding, three-way match
- Inventory: receipts, issues, physical verification, valuation
- Payroll: masters, attendance, salary changes, statutory deductions
- Treasury: banking, payments authorisation, investments
Internal financial controls (IFC)
- Documentation of risk and control matrices (RCMs)
- Testing of design and operating effectiveness
- Support for management's IFC assessment and the statutory auditor's review
Compliance reviews
- Statutory compliance calendar and filings
- Delegation of authority and approval matrices
- Related party transactions and their approvals
Follow-up
- Action-taken reports on earlier observations
- Root-cause analysis for repeat findings
How the engagement works
- Risk-based planAnnual internal audit plan prioritising high-risk processes, agreed with the audit committee.
- Process walkthroughUnderstanding of each process with the people who run it, and mapping of key controls.
- TestingSample testing of transactions and controls, with evidence documented.
- ReportingObservations rated by risk, with root cause, impact and agreed management action and timeline.
- Follow-upTracking of actions to closure and reporting status to the audit committee.
Documents typically required
Key forms and due dates
| Item | Timeline |
|---|---|
| Appointment of internal auditor | By the Board, for applicable companies, typically at the start of the financial year |
| Reporting frequency | Quarterly or half-yearly, as agreed with the audit committee |
Deliverables
- Internal audit plan
- Periodic internal audit reports with risk ratings
- Risk and control matrices (for IFC engagements)
- Action-taken and follow-up reports
The scope of each engagement is agreed in writing and depends on the nature, size and regulatory requirements of the entity.
Frequently asked questions
Can the statutory auditor also be the internal auditor?
No. Section 144 of the Companies Act, 2013 prohibits the statutory auditor from providing internal audit services to the same company.
Is internal audit useful for companies not required to have one?
Yes. Many growing businesses use internal audit to find leakages, strengthen approvals and prepare for investors or banks.
What are internal financial controls?
Policies and procedures that ensure orderly and efficient conduct of business, safeguarding of assets, prevention and detection of fraud and errors, and accurate and timely financial records.
How are observations rated?
Typically as high, medium or low based on financial impact and likelihood, so management can prioritise action.