Compliance with Laws and Regulations in Internal Audit – SIA 150
Table of Contents:-
Compliance with applicable laws and regulations is an important area of internal audit. Businesses operate within an increasingly complex regulatory environment involving corporate law, taxation, labour regulations, environmental requirements, industry-specific regulations and numerous other compliance obligations.
An effective internal audit therefore goes beyond checking financial transactions. It evaluates whether adequate systems and controls exist to identify applicable legal requirements, assign compliance responsibilities, monitor compliance and report instances of non-compliance.
The Institute of Chartered Accountants of India (ICAI) currently addresses this subject through Standard on Internal Audit (SIA) 150 – Compliance with Laws and Regulations. The current ICAI Standards on Internal Audit list SIA 150 under the 100 Series of Standards on Key Concepts.
Businesses looking to strengthen their compliance and control framework may also refer to our Internal Audit Services in India.
What is Compliance with Laws and Regulations in Internal Audit?
Compliance with laws and regulations in internal audit refers to evaluating whether an organisation has established adequate processes and controls for identifying and complying with legal and regulatory requirements applicable to its activities.
The internal auditor may examine:
- applicable laws and regulations;
- licences and registrations;
- statutory returns;
- regulatory approvals;
- internal compliance policies;
- compliance calendars;
- responsibility matrices;
- supporting documentation;
- instances of non-compliance;
- management’s corrective actions; and
- reporting of significant compliance failures.
The objective is not merely to identify individual violations but also to evaluate whether the organisation has an effective compliance management framework.
SIA 150 – Compliance with Laws and Regulations
ICAI currently lists SIA 150 – Compliance with Laws and Regulations as the applicable Standard on this subject.
The Standard should be considered as part of the broader internal audit framework covering internal controls, risk management, governance and compliance.
For the complete current list, refer to the official ICAI Standards on Internal Audit.
What Happened to SIA 17?
The earlier version of this article was based on SIA 17 – Consideration of Laws and Regulations in an Internal Audit and addressed matters such as management responsibility, internal auditor responsibility, identification of non-compliance and reporting.
The page should now be updated around SIA 150 – Compliance with Laws and Regulations, which appears in ICAI’s current standards framework.
Therefore, businesses and professionals referring to this subject should consult the latest ICAI standards and pronouncements.
Why Legal and Regulatory Compliance Matters in Internal Audit
Non-compliance can expose an organisation to:
- financial penalties;
- interest and additional liabilities;
- cancellation or suspension of licences;
- regulatory proceedings;
- litigation;
- business disruption;
- reputational damage;
- management accountability; and
- weaknesses in corporate governance.
An internal audit can provide management with an independent assessment of whether compliance risks are being identified and appropriately managed.
Responsibility of Management for Compliance
The primary responsibility for ensuring compliance with applicable laws and regulations rests with the organisation and its management.
Management should establish an appropriate compliance framework that includes:
- identification of applicable laws;
- assignment of compliance responsibilities;
- compliance policies and procedures;
- compliance calendar;
- monitoring mechanism;
- appropriate documentation;
- escalation procedures;
- periodic management review; and
- corrective action for identified defaults.
Depending upon the organisation’s size and complexity, responsibilities may also be assigned to legal, finance, tax, HR, secretarial and compliance teams.
Internal audit evaluates these systems but does not replace management’s responsibility for compliance.
Responsibility of the Internal Auditor
The internal auditor’s role is principally to assess whether the organisation has adequate controls for managing compliance risks.
The internal auditor should consider:
- applicable legal and regulatory requirements;
- areas having significant compliance risk;
- effectiveness of compliance controls;
- evidence supporting compliance;
- previous instances of non-compliance;
- regulatory correspondence;
- management representations;
- potential consequences of non-compliance; and
- corrective actions taken by management.
The old page correctly distinguished management’s responsibility from the internal auditor’s role and also highlighted the importance of obtaining sufficient and appropriate internal audit evidence.
For a detailed understanding of audit evidence, refer to our Internal Audit Documentation Guide.
Types of Laws and Regulations Reviewed During Internal Audit
The exact legal framework will depend upon the organisation’s industry, location, ownership structure and business activities.
An internal audit may consider compliance under areas such as:
Corporate and Company Law
Companies may be required to comply with provisions relating to:
- Companies Act, 2013;
- board and shareholder meetings;
- statutory registers;
- ROC filings;
- related-party transactions;
- loans and investments;
- appointment of directors and auditors; and
- maintenance of statutory records.
The official corporate regulatory framework and filings can be accessed through the Ministry of Corporate Affairs.
Income Tax and TDS Compliance
Internal audit may examine:
- TDS deduction;
- TDS payment;
- return filing;
- advance tax;
- income-tax compliance;
- withholding documentation; and
- reconciliation with tax records.
For broader assistance, see our Tax and Regulatory Advisory Services in India.
GST Compliance
Important areas may include:
- GST registration;
- tax invoices;
- input tax credit;
- return filing;
- tax payments;
- reconciliations;
- e-invoicing; and
- e-way bills.
The official source for GST compliance is the GST Portal.
Labour and Employment Compliance
Depending upon applicability, an organisation may need to evaluate compliance relating to:
- employee records;
- wages;
- provident fund;
- employee state insurance;
- gratuity;
- statutory benefits; and
- workplace requirements.
FEMA and Foreign Investment Compliance
Foreign-owned Indian companies may also have regulatory obligations involving:
- foreign direct investment;
- issue or transfer of shares;
- overseas payments;
- foreign currency transactions;
- reporting requirements; and
- RBI/FEMA documentation.
The Reserve Bank of India provides the applicable regulatory framework and directions.
Industry-Specific Regulations
Depending upon the business, additional regulations may apply relating to:
- environmental protection;
- pollution control;
- food safety;
- pharmaceuticals;
- financial services;
- import/export;
- data protection;
- factories;
- fire safety; and
- other sector-specific licences.
The internal auditor should therefore develop the compliance universe according to the actual operations of the organisation.
Understanding the Compliance Universe
Before conducting a compliance-focused internal audit, the auditor should understand the organisation’s compliance universe.
A compliance universe is essentially the complete set of material laws, regulations, licences, approvals and regulatory requirements applicable to an organisation.
The auditor may classify these requirements according to:
- business entity;
- location;
- department;
- regulatory authority;
- frequency;
- compliance owner;
- financial exposure; and
- risk of non-compliance.
This approach helps ensure that significant compliance risks are not omitted from the audit scope.
Risk-Based Approach to Compliance Audit
Not every compliance requirement carries the same level of risk.
Internal auditors should therefore consider factors such as:
- severity of potential penalty;
- financial exposure;
- frequency of compliance;
- history of defaults;
- regulatory scrutiny;
- reputational impact;
- possibility of business interruption; and
- effectiveness of existing controls.
High-risk areas should ordinarily receive greater audit attention.
For the methodology, read our detailed guide on Risk Based Internal Audit.
Internal Audit Procedures for Checking Compliance
Internal audit procedures may include:
Understanding Applicable Regulations
The auditor should identify material laws and regulations relevant to the business and understand how management monitors compliance.
Reviewing the Compliance Register
The auditor may examine whether the organisation maintains an updated compliance register or statutory compliance calendar.
Identifying Compliance Owners
Every important compliance requirement should ideally have an identified responsible person or department.
Testing Compliance
The auditor may verify:
- statutory returns;
- challans;
- certificates;
- licences;
- approvals;
- regulatory correspondence;
- reconciliations; and
- supporting documentation.
Obtaining Audit Evidence
Sufficient and appropriate evidence should support the audit findings.
The procedures and evidence obtained should also be properly recorded in the internal audit working papers. See our guide on Internal Audit Documentation.
Evaluating Exceptions
Where an exception is identified, the auditor should evaluate:
- nature of non-compliance;
- period involved;
- financial impact;
- potential penalty;
- frequency;
- root cause;
- responsible function; and
- corrective action required.
What Should the Internal Auditor Do When Non-Compliance is Identified?
Where actual or suspected non-compliance is identified, the internal auditor should understand the nature and circumstances of the matter and obtain appropriate information to evaluate its potential impact.
Depending upon the significance of the matter, the auditor may:
- perform additional audit procedures;
- obtain further supporting documents;
- discuss the matter with responsible management;
- evaluate financial and operational consequences;
- determine whether the issue is isolated or systemic;
- assess the underlying control weakness;
- consider the need for legal or specialist advice;
- document the findings; and
- appropriately communicate the matter.
The previous page similarly emphasised additional audit procedures and evaluation where non-compliance is identified or suspected.
Reporting Non-Compliance in Internal Audit
Significant instances of non-compliance should be appropriately communicated and reported.
A well-structured internal audit observation should generally contain:
Observation: What non-compliance was identified?
Criteria: Which legal, regulatory or internal requirement applies?
Cause: Why did the non-compliance occur?
Impact/Risk: What is the potential financial, regulatory or operational consequence?
Recommendation: What corrective action should management take?
Management Response: What action has management agreed to take?
Timeline: When will corrective action be completed?
Significant matters may need to be escalated to senior management, the Audit Committee or those charged with governance depending upon their severity.
The original article also specifically recognised reporting non-compliance to those charged with governance.
Examples of Non-Compliance Identified During Internal Audit
Typical examples may include:
- delayed statutory returns;
- TDS not deducted or deposited;
- GST reconciliation differences;
- expired licences;
- non-renewal of registrations;
- non-compliance with employment regulations;
- absence of required environmental approvals;
- inadequate FEMA documentation;
- delayed ROC filings;
- non-compliance with contractual obligations; and
- deficiencies in statutory registers.
These examples demonstrate why compliance review should form part of a comprehensive internal audit programme.
Internal Audit Compliance Checklist
A practical compliance audit checklist may include:
- Have all applicable laws and regulations been identified?
- Is a compliance register maintained?
- Is each compliance assigned to a responsible person?
- Are statutory due dates monitored?
- Are returns filed within prescribed timelines?
- Are statutory payments made on time?
- Are licences and registrations valid?
- Are supporting records maintained?
- Are regulatory notices centrally tracked?
- Are previous defaults followed up?
- Are significant compliance issues reported to management?
- Are corrective actions monitored until closure?
For a broader operational checklist, see our Internal Audit Checklist.
Compliance Review for Foreign-Owned Companies in India
Foreign-owned Indian companies may face an additional layer of regulatory requirements because they have to comply with Indian corporate, tax and employment regulations as well as foreign investment and cross-border transaction requirements.
Areas requiring particular attention may include:
- FEMA and FDI reporting;
- related-party transactions;
- transfer pricing;
- withholding taxes;
- foreign remittances;
- GST;
- Companies Act requirements;
- employment regulations; and
- regulatory filings.
Periodic internal audit can help overseas parent companies obtain greater visibility over the compliance environment of their Indian subsidiaries.
Role of Internal Audit in Strengthening Compliance
Internal audit should not be viewed merely as a mechanism for detecting historical defaults.
A mature internal audit function can help management:
- identify emerging compliance risks;
- strengthen preventive controls;
- establish clear accountability;
- improve compliance monitoring;
- reduce recurring defaults;
- improve documentation;
- identify root causes; and
- monitor corrective action.
This aligns compliance auditing with the wider objectives of governance, risk management and internal control.
For an overview of the complete methodology, see our Internal Audit Process.
Frequently Asked Questions
What is SIA 150?
SIA 150 is the ICAI Standard on Internal Audit dealing with Compliance with Laws and Regulations and forms part of ICAI’s current 100 Series of Standards on Key Concepts.
Is SIA 17 still the current standard?
The current ICAI standards listing identifies SIA 150 – Compliance with Laws and Regulations for this subject. Accordingly, references to the older SIA 17 should be updated when discussing the current standards framework.
Is the internal auditor responsible for ensuring all legal compliances?
Management is primarily responsible for establishing systems and processes to ensure compliance. Internal audit evaluates the design and effectiveness of those processes and identifies material weaknesses or instances of non-compliance.
What is a compliance audit?
A compliance audit evaluates whether an organisation is adhering to applicable laws, regulations, policies and prescribed requirements.
What should an internal auditor do when non-compliance is found?
The auditor should understand the matter, obtain appropriate evidence, evaluate its significance and impact, identify the underlying control weakness and appropriately report the matter.
Should regulatory compliance form part of a risk-based internal audit?
Yes. Compliance risks should be considered while developing the risk universe and audit plan, particularly where non-compliance can result in significant financial, regulatory, operational or reputational consequences.
What records should be maintained for a compliance audit?
Records may include statutory returns, licences, approvals, challans, certificates, regulatory correspondence, compliance registers, reconciliations, supporting evidence and internal audit working papers.
Related Services
- Internal Audit Services in India
- Audit and Assurance Services in India
- What is Internal Audit?
- Internal Audit Checklist
- Internal Audit Process
- Risk Based Internal Audit
- Internal Audit Documentation
- Sampling in Internal Audit
- Internal Audit Charter
Prepared By
Anil Agrawal, Chartered Accountant
EzyBiz India Consulting LLP, New Delhi
Last Updated
August 2026
Disclaimer
Disclaimer: This article is intended solely for general informational and educational purposes and should not be construed as legal, regulatory, tax or professional advice. Laws, regulations and Standards on Internal Audit may be amended from time to time. Readers should refer to the latest applicable legislation, regulatory guidance and pronouncements issued by ICAI and other relevant authorities and obtain appropriate professional advice before taking any action.