Financial Controls
Evaluation of controls over financial reporting, transaction processing, asset safeguarding, and segregation of duties within accounting and finance functions.
Our internal audit engagements, conducted in accordance with IIA Standards, evaluate control design and operating effectiveness across multiple domains.
Evaluation of controls over financial reporting, transaction processing, asset safeguarding, and segregation of duties within accounting and finance functions.
Evaluation of controls within business processes—procurement, inventory, revenue cycle, and other operational areas—assessing design adequacy and operating effectiveness.
Evaluation of adherence to applicable laws, regulations, contractual obligations, and internal policies across relevant areas of your operations.
Evaluation of controls over information systems—access management, change management, data integrity, and IT governance supporting business processes.
Evaluation of board and committee functioning, delegation of authority frameworks, and alignment of organisational practices with documented objectives and policies.
Internal audit services addressing mandatory requirements under Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014.
Internal audit functions as an independent evaluation mechanism—distinct from risk management, which designs and implements risk frameworks.
We assess your organisation's risk landscape to develop an audit plan that directs attention to areas of significant exposure and strategic importance.
We assess your organisation's risk landscape to develop an audit plan that directs attention to areas of significant exposure and strategic importance.
We document processes, identify control objectives, and map key controls through walkthroughs, interviews, and review of relevant policies and procedures.
We document processes, identify control objectives, and map key controls through walkthroughs, interviews, and review of relevant policies and procedures.
We evaluate control design for adequacy and test operating effectiveness through sampling, observation, inquiry, and re-performance of control activities.
We evaluate control design for adequacy and test operating effectiveness through sampling, observation, inquiry, and re-performance of control activities.
We document observations with supporting evidence, assess root causes, and develop recommendations that address identified gaps and weaknesses.
We document observations with supporting evidence, assess root causes, and develop recommendations that address identified gaps and weaknesses.
We present findings to management and the audit committee, obtain management responses, and track implementation status of agreed action items.
We present findings to management and the audit committee, obtain management responses, and track implementation status of agreed action items.
Internal audit is an independent, objective evaluation of how an organisation manages risk, operates its controls, and meets its governance and compliance obligations. It examines areas such as controls over financial reporting, operational processes like procurement and inventory, regulatory compliance, IT general controls, and governance structures. The purpose is to give management and the audit committee an informed view of where controls are working and where gaps need attention, supported by practical recommendations.
No. Under Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014, internal audit is required only for specified classes of companies. Every listed company must appoint an internal auditor. Unlisted public companies and private companies become subject to the requirement once they cross prescribed size thresholds. Companies below those thresholds may still adopt internal audit voluntarily for assurance over their controls.
The thresholds apply by company type, measured against the preceding financial year. A listed company is always covered. An unlisted public company is covered if its turnover is Rs 200 crore or more, or its paid-up share capital is Rs 50 crore or more, or its outstanding loans or borrowings from banks or public financial institutions exceed Rs 100 crore, or its outstanding deposits are Rs 25 crore or more. A private company is covered if its turnover is Rs 200 crore or more, or its outstanding loans or borrowings exceed Rs 100 crore.
No. An LLP is not required to have an internal audit, since Section 138 of the Companies Act applies to companies rather than LLPs. An LLP may still need a statutory audit under the LLP Act, 2008 if its turnover exceeds Rs 40 lakh or its capital contribution exceeds Rs 25 lakh, and a tax audit under Section 44AB [ITA 2025: s. 63], with the report furnished under Rule 6G [ITR 2026: r. 47] in Form 3CA [ITR 2026: Form 26, Part A] or Form 3CB [ITR 2026: Form 26, Part B] together with Form 3CD [ITR 2026: Form 26, Parts C and D]. Many growing LLPs adopt internal audit voluntarily to strengthen controls ahead of lending or expansion.
Under Section 138 and Rule 13, the internal auditor can be a Chartered Accountant, a Cost Accountant, or any other professional the Board considers suitable. The appointee may be an individual, a partnership firm, or a body corporate, and may be either an employee of the company or an external professional. Unlike the statutory auditor, who must be a practising Chartered Accountant, the internal auditor need not be in practice, which gives companies flexibility in how they resource the function.
The internal auditor is appointed by the Board of Directors through a board resolution. Section 138 does not fix a rigid deadline in the way the statutory auditor provisions do, but a company that crosses the applicability thresholds should appoint promptly, ideally before the financial year for which internal audit applies. Rule 13 also contains a transitional proviso under which an existing company that becomes covered by the criteria is required to comply with Section 138 within six months of the commencement of the section. For companies other than private companies, the board resolution is filed with the Registrar in Form MGT-14 within 30 days. Delays can attract penalties, so the appointment is best made without gaps.
No. Section 144 of the Companies Act, 2013 bars the statutory auditor from providing internal audit services to the same company, and to its holding or subsidiary company, whether directly or indirectly. The restriction protects auditor independence, since the statutory auditor should not review controls that the same firm helped design or operate. The two roles must be held by different professionals or firms.
Statutory audit is an externally required examination of the financial statements that produces an independent opinion for shareholders, governed by Section 143 of the Companies Act, 2013. Internal audit is an ongoing, management-facing evaluation of controls, processes, risk, and governance, reporting to the audit committee and the board. Statutory audit looks primarily at the accuracy of the accounts; internal audit looks across operations to improve how the organisation runs and where its risks sit.
Internal Financial Controls are the system of policies and procedures a company puts in place for orderly business conduct, reliable financial reporting, and compliance, referenced in Section 134(5)(e) of the Companies Act, 2013 and reported on by the statutory auditor under Section 143(3)(i). Internal audit is the independent function that tests whether those controls are designed well and operating effectively. In short, IFC is the control framework, and internal audit is one of the mechanisms that evaluates it.
Risk-based internal audit directs audit effort to the areas where the organisation faces the most significant exposure, rather than testing every area equally. The auditor first assesses the risk landscape, identifying where financial, operational, compliance, or technology risks are highest, then builds the audit plan around those priorities. This focuses limited time and resources on what matters most to the business and its objectives.
IT general controls, often called ITGCs, are the controls over the systems that support business processes and financial reporting. An internal audit typically examines access management, meaning who can enter and change data, change management, meaning how system changes are tested and approved, data integrity, and overall IT governance. Weak IT general controls can undermine otherwise sound process controls, which is why they are assessed alongside financial and operational areas.
Many internal audit reports structure each finding around five elements: Criteria, the standard or policy that should be met; Condition, what was actually observed; Cause, why the gap occurred; Consequence, the impact or risk it creates; and Corrective Action, the agreed fix and the owner responsible. This structure keeps findings clear and actionable, helping management understand not just what is wrong, but why it matters and what to do about it.
There is no single statutory frequency. Section 138 leaves the scope, functioning, periodicity, and methodology to be decided by the audit committee, or the board, in consultation with the internal auditor. In practice, many organisations run internal audit on a continuous or quarterly cycle for high-risk areas and less frequently for lower-risk areas, set out in an annual audit plan. The right rhythm depends on the size, complexity, and risk profile of the business.
The internal auditor reports to the audit committee where one exists, and otherwise to the Board of Directors. Reporting at this level keeps the function independent of the operations it reviews, so findings are not filtered by the managers responsible for the areas being audited. The audit committee or board, in consultation with the internal auditor, also sets the scope and approach and tracks how agreed actions are implemented.
The Companies Act does not prescribe a specific penalty for missing the internal audit requirement, so the general penalty under Section 450 applies. The company and every officer in default can face a penalty of Rs 10,000, with a further Rs 1,000 for each day the default continues, subject to a maximum of Rs 2,00,000 for the company and Rs 50,000 for an officer in default. Recent adjudication orders show the Registrar of Companies actively levying these penalties, so timely appointment matters.