Skip to main content
Audit & Assurance

Internal Audit Services

Practice01/06

Financial Controls.

Note01
Testing reconciliations, journal controls, segregation of duties and asset safeguarding across finance.
Index06 Practices
01Financial Controls
02Operational Controls
03Compliance Assessment
04IT General Controls
05Governance Structures
06Section 138 Requirements

Internal Audit Scope

Our internal audit engagements, conducted in accordance with IIA Standards, evaluate control design and operating effectiveness across multiple domains.

Financial Controls

Evaluation of controls over financial reporting, transaction processing, asset safeguarding, and segregation of duties within accounting and finance functions.

Operational Controls

Evaluation of controls within business processes—procurement, inventory, revenue cycle, and other operational areas—assessing design adequacy and operating effectiveness.

Compliance Assessment

Evaluation of adherence to applicable laws, regulations, contractual obligations, and internal policies across relevant areas of your operations.

IT General Controls

Evaluation of controls over information systems—access management, change management, data integrity, and IT governance supporting business processes.

Governance Structures

Evaluation of board and committee functioning, delegation of authority frameworks, and alignment of organisational practices with documented objectives and policies.

Section 138 Requirements

Internal audit services addressing mandatory requirements under Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014.

The Role of Internal Audit

Internal audit functions as an independent evaluation mechanism—distinct from risk management, which designs and implements risk frameworks.

  • Independent evaluation of control design and operating effectiveness across functions
  • Identification of control gaps, process weaknesses, and compliance deviations
  • Objective findings reported directly to the audit committee and management
  • Risk-based audit planning directing resources to areas of significant exposure
  • Recommendations for addressing identified issues and observed weaknesses
  • Support for audit committee discharge of oversight responsibilities under the Act

Our Audit Approach

Step 1

Risk-Based Planning

We assess your organisation's risk landscape to develop an audit plan that directs attention to areas of significant exposure and strategic importance.

Step 2

Process Documentation

We document processes, identify control objectives, and map key controls through walkthroughs, interviews, and review of relevant policies and procedures.

Step 3

Control Testing

We evaluate control design for adequacy and test operating effectiveness through sampling, observation, inquiry, and re-performance of control activities.

Step 4

Findings Documentation

We document observations with supporting evidence, assess root causes, and develop recommendations that address identified gaps and weaknesses.

Step 5

Reporting & Follow-up

We present findings to management and the audit committee, obtain management responses, and track implementation status of agreed action items.

Common Questions

  1. What is internal audit, and what does it cover?

    Internal audit is an independent, objective evaluation of how an organisation manages risk, operates its controls, and meets its governance and compliance obligations. It examines areas such as controls over financial reporting, operational processes like procurement and inventory, regulatory compliance, IT general controls, and governance structures. The purpose is to give management and the audit committee an informed view of where controls are working and where gaps need attention, supported by practical recommendations.

  2. Is internal audit mandatory for every company in India?

    No. Under Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014, internal audit is required only for specified classes of companies. Every listed company must appoint an internal auditor. Unlisted public companies and private companies become subject to the requirement once they cross prescribed size thresholds. Companies below those thresholds may still adopt internal audit voluntarily for assurance over their controls.

  3. What turnover and other thresholds make internal audit mandatory?

    The thresholds apply by company type, measured against the preceding financial year. A listed company is always covered. An unlisted public company is covered if its turnover is Rs 200 crore or more, or its paid-up share capital is Rs 50 crore or more, or its outstanding loans or borrowings from banks or public financial institutions exceed Rs 100 crore, or its outstanding deposits are Rs 25 crore or more. A private company is covered if its turnover is Rs 200 crore or more, or its outstanding loans or borrowings exceed Rs 100 crore.

  4. Is internal audit mandatory for an LLP?

    No. An LLP is not required to have an internal audit, since Section 138 of the Companies Act applies to companies rather than LLPs. An LLP may still need a statutory audit under the LLP Act, 2008 if its turnover exceeds Rs 40 lakh or its capital contribution exceeds Rs 25 lakh, and a tax audit under Section 44AB [ITA 2025: s. 63], with the report furnished under Rule 6G [ITR 2026: r. 47] in Form 3CA [ITR 2026: Form 26, Part A] or Form 3CB [ITR 2026: Form 26, Part B] together with Form 3CD [ITR 2026: Form 26, Parts C and D]. Many growing LLPs adopt internal audit voluntarily to strengthen controls ahead of lending or expansion.

  5. Who can be appointed as an internal auditor?

    Under Section 138 and Rule 13, the internal auditor can be a Chartered Accountant, a Cost Accountant, or any other professional the Board considers suitable. The appointee may be an individual, a partnership firm, or a body corporate, and may be either an employee of the company or an external professional. Unlike the statutory auditor, who must be a practising Chartered Accountant, the internal auditor need not be in practice, which gives companies flexibility in how they resource the function.

  6. Is there a time limit for appointing an internal auditor, and how is the appointment made?

    The internal auditor is appointed by the Board of Directors through a board resolution. Section 138 does not fix a rigid deadline in the way the statutory auditor provisions do, but a company that crosses the applicability thresholds should appoint promptly, ideally before the financial year for which internal audit applies. Rule 13 also contains a transitional proviso under which an existing company that becomes covered by the criteria is required to comply with Section 138 within six months of the commencement of the section. For companies other than private companies, the board resolution is filed with the Registrar in Form MGT-14 within 30 days. Delays can attract penalties, so the appointment is best made without gaps.

  7. Can our statutory auditor also carry out our internal audit?

    No. Section 144 of the Companies Act, 2013 bars the statutory auditor from providing internal audit services to the same company, and to its holding or subsidiary company, whether directly or indirectly. The restriction protects auditor independence, since the statutory auditor should not review controls that the same firm helped design or operate. The two roles must be held by different professionals or firms.

  8. What is the difference between internal audit and statutory audit?

    Statutory audit is an externally required examination of the financial statements that produces an independent opinion for shareholders, governed by Section 143 of the Companies Act, 2013. Internal audit is an ongoing, management-facing evaluation of controls, processes, risk, and governance, reporting to the audit committee and the board. Statutory audit looks primarily at the accuracy of the accounts; internal audit looks across operations to improve how the organisation runs and where its risks sit.

  9. What is the difference between internal audit and internal financial controls (IFC)?

    Internal Financial Controls are the system of policies and procedures a company puts in place for orderly business conduct, reliable financial reporting, and compliance, referenced in Section 134(5)(e) of the Companies Act, 2013 and reported on by the statutory auditor under Section 143(3)(i). Internal audit is the independent function that tests whether those controls are designed well and operating effectively. In short, IFC is the control framework, and internal audit is one of the mechanisms that evaluates it.

  10. What is risk-based internal audit?

    Risk-based internal audit directs audit effort to the areas where the organisation faces the most significant exposure, rather than testing every area equally. The auditor first assesses the risk landscape, identifying where financial, operational, compliance, or technology risks are highest, then builds the audit plan around those priorities. This focuses limited time and resources on what matters most to the business and its objectives.

  11. What do IT general controls cover within an internal audit?

    IT general controls, often called ITGCs, are the controls over the systems that support business processes and financial reporting. An internal audit typically examines access management, meaning who can enter and change data, change management, meaning how system changes are tested and approved, data integrity, and overall IT governance. Weak IT general controls can undermine otherwise sound process controls, which is why they are assessed alongside financial and operational areas.

  12. What are the five C's used to frame an internal audit finding?

    Many internal audit reports structure each finding around five elements: Criteria, the standard or policy that should be met; Condition, what was actually observed; Cause, why the gap occurred; Consequence, the impact or risk it creates; and Corrective Action, the agreed fix and the owner responsible. This structure keeps findings clear and actionable, helping management understand not just what is wrong, but why it matters and what to do about it.

  13. How often should internal audit be carried out?

    There is no single statutory frequency. Section 138 leaves the scope, functioning, periodicity, and methodology to be decided by the audit committee, or the board, in consultation with the internal auditor. In practice, many organisations run internal audit on a continuous or quarterly cycle for high-risk areas and less frequently for lower-risk areas, set out in an annual audit plan. The right rhythm depends on the size, complexity, and risk profile of the business.

  14. Who does the internal auditor report to?

    The internal auditor reports to the audit committee where one exists, and otherwise to the Board of Directors. Reporting at this level keeps the function independent of the operations it reviews, so findings are not filtered by the managers responsible for the areas being audited. The audit committee or board, in consultation with the internal auditor, also sets the scope and approach and tracks how agreed actions are implemented.

  15. What happens if a company required to appoint an internal auditor does not?

    The Companies Act does not prescribe a specific penalty for missing the internal audit requirement, so the general penalty under Section 450 applies. The company and every officer in default can face a penalty of Rs 10,000, with a further Rs 1,000 for each day the default continues, subject to a maximum of Rs 2,00,000 for the company and Rs 50,000 for an officer in default. Recent adjudication orders show the Registrar of Companies actively levying these penalties, so timely appointment matters.