Internal Audit Services in India

Internal Audit Services in India

Internal Audit Services in India – Risk, Controls & Compliance

EzyBiz India Consulting LLP provides comprehensive Internal Audit Services in India to Indian companies, foreign-owned subsidiaries, multinational groups, startups, manufacturing businesses, trading companies and service organisations.

Our internal audit approach goes beyond checking accounting transactions. We evaluate business risks, internal controls, operational processes, statutory compliance, financial reporting systems, approval mechanisms and management information to identify weaknesses and recommend practical corrective actions.

Quick Answer: Internal audit is an independent and systematic review of an organisation’s risks, controls, governance and business processes. A modern internal audit examines whether important risks have been identified, whether appropriate controls exist, whether those controls actually operate in practice and whether management is taking timely corrective action when weaknesses are identified.

Internal audit can be statutory where Section 138 of the Companies Act, 2013 applies, or it can be undertaken voluntarily by management, an Audit Committee, the Board or an overseas parent company to strengthen governance and obtain greater visibility over business operations.

Our assignments may cover procurement-to-pay, order-to-cash, payroll, inventory, fixed assets, banking, treasury, GST, TDS, statutory compliance, information systems, maker-checker controls, fraud risks, management reporting and other business processes according to the organisation’s risk profile.

Need Professional Audit and Assurance Support?

Get expert assistance with statutory audit, tax audit, internal audit, certification and other assurance requirements in India.

Speak With Our Audit Experts

What Are Internal Audit Services?

Internal audit provides management and those charged with governance with structured assurance regarding internal controls, risk management and organisational processes.

Unlike a routine transaction-checking exercise, effective internal audit starts with understanding the organisation’s objectives and risks and then evaluates whether the controls designed to manage those risks are adequate and functioning effectively.

Purpose and Objectives of Internal Audit

The principal objective of internal audit is to assist an organisation in improving governance, risk management and internal controls.

Depending upon the agreed scope, internal audit may help:

  • identify significant business and compliance risks;
  • evaluate design and operating effectiveness of internal controls;
  • identify process inefficiencies;
  • review adherence to policies and delegated authorities;
  • identify regulatory and statutory compliance gaps;
  • evaluate reliability of management information;
  • review safeguards over assets;
  • identify areas susceptible to error or fraud;
  • recommend corrective actions; and
  • monitor closure of previously identified weaknesses.

For a wider understanding of the characteristics of the function, see our guide on Characteristics of Internal Audit.

Internal Audit vs Statutory Audit

Internal audit and statutory audit serve different purposes.

Statutory audit primarily examines annual financial statements and fulfils reporting requirements prescribed under applicable law. Internal audit has a broader and more flexible scope covering risks, processes, controls, compliance, operational efficiency and governance.

Internal audit is therefore not intended to duplicate the work of the statutory auditor. Businesses requiring annual financial-statement audit support may refer to our Statutory Audit Services in India.

Section 138 Internal Audit Applicability in India

Section 138 of the Companies Act, 2013 requires prescribed classes of companies to appoint an internal auditor. The detailed applicability criteria are contained in Rule 13 of the Companies (Accounts) Rules, 2014.

The statutory text of Section 138 can be reviewed in the official Companies Act, 2013 published by the Ministry of Corporate Affairs.

Listed Companies

Every listed company is required to appoint an internal auditor under the prescribed framework.

Unlisted Public Companies

An unlisted public company is required to appoint an internal auditor where it satisfies any of the prescribed criteria during the preceding financial year, including:

  • paid-up share capital of ₹50 crore or more;
  • turnover of ₹200 crore or more;
  • outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point during the preceding financial year; or
  • outstanding deposits of ₹25 crore or more at any point during the preceding financial year.

Private Companies

A private company is required to appoint an internal auditor where it has:

  • turnover of ₹200 crore or more during the preceding financial year; or
  • outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point during the preceding financial year.

Companies close to an applicability threshold should review the precise statutory wording and their financial information before determining whether Section 138 applies.

Who Can Be Appointed as Internal Auditor?

Section 138 provides that the internal auditor may be a Chartered Accountant, Cost Accountant or such other professional as may be decided by the Board, subject to the applicable statutory framework.

The internal auditor may be internal to the organisation or externally engaged. Rule 13 also recognises appointment through an individual, partnership firm or body corporate, as applicable.

The Audit Committee or Board, in consultation with the internal auditor, determines the scope, functioning, periodicity and methodology of internal audit.

Scope of Our Internal Audit Services in India

The scope of an internal audit should reflect the organisation’s business model, material risks, geographic spread, transaction volume, regulatory environment and management priorities.

Risk-Based Internal Audit

We use a risk-focused approach to identify areas where control failure could materially affect financial performance, compliance, business continuity, reputation or achievement of organisational objectives.

Rather than allocating equal audit effort to every process, higher-risk areas receive greater attention.

Read our detailed guide on Risk Based Internal Audit.

Process and Operational Audit

Process audits examine how activities are actually performed rather than merely how policies describe them.

Important areas may include procurement, vendor management, sales, customer onboarding, inventory, production, payroll, expenses, banking, collections, fixed assets and other operating cycles.

Compliance and Regulatory Review

Internal audit can review whether appropriate systems exist to identify, assign, monitor and document compliance with applicable legal and regulatory requirements.

This may include Companies Act compliance, GST, TDS, payroll regulations, PF, ESI, FEMA, licences, regulatory filings and industry-specific requirements depending upon applicability.

Our supporting guide explains Compliance with Laws and Regulations in Internal Audit.

Our Internal Audit Methodology

A well-structured internal audit is performed through a planned sequence rather than isolated checking of vouchers and transactions.

Business and Process Understanding

We begin by understanding the organisation’s activities, ownership structure, locations, products or services, systems, organisational structure, accounting environment, regulatory requirements and major business processes.

Discussions with management and process owners help identify how transactions originate, who approves them, how they are recorded and which controls are expected to prevent or detect errors.

Risk Assessment

Key financial, operational, regulatory, technological and fraud-related risks are identified and evaluated.

The assessment considers factors such as financial significance, transaction volume, complexity, regulatory exposure, history of control failures, management concerns and potential impact on business objectives.

Audit Scope and Programme

Once risks are understood, the audit scope defines the processes, entities, locations, period and control areas to be reviewed.

Detailed audit procedures are then designed to address the identified risks and audit objectives.

For the complete methodology, see our Internal Audit Process – Step-by-Step Guide.

Internal Audit Planning and Audit Universe

Effective internal audit begins before fieldwork. An organisation should first determine what can potentially be audited and then prioritise those areas according to risk.

Developing the Audit Universe

The audit universe represents the complete population of potentially auditable entities, departments, functions, processes, systems, projects and locations.

Depending upon the business, the audit universe may include finance, procurement, sales, inventory, manufacturing, HR, payroll, IT, taxation, legal compliance, treasury, customer service, projects and branches.

Annual Internal Audit Plan

The annual or periodic internal audit plan allocates audit resources according to risk and organisational priorities.

Higher-risk activities may be audited more frequently, while lower-risk areas may follow a rotational plan. The plan should remain flexible enough to address emerging risks, significant control failures and major changes in business operations.

Read more about Internal Audit Planning and Risk Assessment.

What Our Internal Audit Actually Tests

A practical internal audit examines both financial information and the underlying processes that generate it. Depending upon the agreed scope, the following areas may be reviewed.

Procurement-to-Pay

The procurement-to-pay review may examine vendor onboarding, quotation comparison, purchase approvals, purchase orders, receipt of goods or services, invoice verification, payment approval, duplicate invoices and related-party vendors.

We also evaluate whether appropriate segregation exists between purchasing, receipt, accounting and payment functions.

Order-to-Cash and Receivables

Order-to-cash testing may include customer onboarding, credit limits, pricing approval, sales orders, dispatch, invoicing, revenue recognition, credit notes, collections and receivable ageing.

Unusual discounts, long-outstanding receivables and deviations from approved credit terms may require particular attention.

Payroll and Employee Expenses

Payroll review can cover employee master controls, attendance inputs, salary processing, new joiners and exits, variable payments, reimbursements, payroll approvals, TDS, PF and ESI where applicable.

Testing may also examine whether payroll changes are supported by appropriate authorisation.

Inventory and Warehousing

Inventory audit procedures may cover inward and outward movements, stock records, physical verification, negative stock, damaged or obsolete items, valuation, inventory adjustments and access controls.

Significant differences between physical stock, ERP records and financial books should be investigated and documented.

Fixed Assets and Capital Expenditure

Fixed-asset review may include capital expenditure approvals, purchase documentation, capitalisation, asset tagging, physical verification, useful lives, depreciation, disposals and reconciliation of the fixed-asset register with the general ledger.

Banking, Treasury and Maker-Checker Controls

Banking review may cover bank reconciliations, payment approvals, authorised signatories, internet-banking rights, maker-checker controls, borrowings, cash management and unusual fund transfers.

Special attention may be required where one employee is able to initiate, approve and account for the same transaction.

GST, TDS and Statutory Compliance

Internal audit may compare accounting records with GST returns, TDS records and other statutory filings to identify unreconciled differences and compliance failures.

Typical areas include differences between books and GSTR-1/GSTR-3B, input-tax-credit reconciliation, reverse charge, TDS deduction and deposit, statutory payment delays and unresolved notices.

Need Professional Audit and Assurance Support?

Get expert assistance with statutory audit, tax audit, internal audit, certification and other assurance requirements in India.

Speak With Our Audit Experts

Internal Controls and Maker-Checker Review

Internal controls should reduce identified risks to an acceptable level without creating unnecessary operational complexity.

Design vs Operating Effectiveness

A control may be well designed but still fail if it is not consistently followed.

Internal audit therefore considers both:

  • Design effectiveness: whether the control is capable of addressing the identified risk; and
  • Operating effectiveness: whether the control was actually performed consistently during the period under review.

For a detailed discussion, see our guide on the Internal Control System in an Organisation.

Segregation of Duties and Authority Matrix

Critical transactions should ordinarily involve appropriate segregation between initiation, verification, approval, custody and accounting.

Internal audit may review delegation-of-authority matrices, financial approval limits, system permissions, override controls and evidence of approvals.

Internal Audit Testing and Data Analytics

Internal audit procedures should be selected according to risk, the nature of the control and availability of reliable data.

Walkthroughs, Sampling and Transaction Testing

Process walkthroughs help auditors understand how transactions flow through the organisation and identify key control points.

Testing may use risk-based samples, random or systematic samples, targeted selections or 100% examination of specific high-risk transaction populations.

Analytical Procedures and Data Analytics

Data analysis can help identify unusual trends, duplicate transactions, abnormal journal entries, missing sequence numbers, repeated payments, dormant vendors, unusual round-sum transactions and other exceptions requiring investigation.

Analytical procedures may also compare financial and non-financial information across periods, locations, products or departments.

See our supporting article on Analytical Procedures in Internal Audit.

Internal Audit Findings and Reporting

An internal audit report should help management understand what was identified, why it matters and what needs to be corrected.

Observation, Risk, Root Cause and Recommendation

A useful audit observation normally explains:

Condition → Criteria → Cause → Risk/Impact → Recommendation

This approach is more useful than merely stating that an error occurred because it connects the audit finding with the underlying business risk and required corrective action.

Management Response and Action Plan

Significant observations should be discussed with responsible process owners before finalisation.

The final report may record:

  • audit observation;
  • risk or potential impact;
  • root cause;
  • recommendation;
  • management response;
  • responsible person;
  • target implementation date; and
  • status of corrective action.

For a detailed reporting framework, read our guide on Internal Audit Reporting.

Corrective Action Tracking and Follow-Up Audit

Identifying a weakness does not by itself improve a control environment. Audit value arises when agreed corrective actions are implemented and sustained.

Monitoring Open Audit Issues

Organisations should maintain a structured tracker of significant observations, responsible persons, management commitments and target closure dates.

Follow-up audit procedures can verify whether corrective actions have actually been implemented and whether the underlying risk has been adequately addressed.

Repeated observations should receive particular attention because they may indicate ineffective remediation or insufficient management accountability.

Outsourced and Co-Sourced Internal Audit

An organisation does not necessarily need to maintain its entire internal audit function internally. Depending upon resources and expertise, it may use an outsourced or co-sourced model.

Outsourced Internal Audit

Under a fully outsourced arrangement, an external internal audit team may assist with risk assessment, annual planning, fieldwork, testing, reporting and follow-up.

This can be particularly useful for businesses that require independent review but do not maintain a dedicated internal audit department.

Co-Sourced Internal Audit

In a co-sourced model, the organisation’s internal team and external specialists work together.

External professionals may provide additional capacity, industry experience, tax and regulatory expertise, data analytics or specialist knowledge for particular assignments.

Read our detailed guide on Outsourcing and Co-Sourcing Internal Audit.

Internal Audit for Foreign-Owned Indian Subsidiaries

Internal audit can be especially valuable for Indian subsidiaries of foreign groups where overseas management does not have daily visibility over local operations.

Local Controls and Group Policies

We can review whether Indian operations follow local delegation-of-authority rules, global policies, group reporting requirements and established approval processes.

Areas may include procurement, employee expenditure, banking, related-party transactions, management reporting and access to financial systems.

Indian Tax, FEMA and Regulatory Compliance

Foreign-owned businesses may require additional review of Indian GST, TDS, Companies Act, FEMA, foreign investment reporting, transfer-pricing processes and intercompany transactions.

Internal audit can help overseas management identify local compliance weaknesses before they result in significant regulatory or financial exposures.

Industry-Focused Internal Audit

The appropriate audit programme depends heavily upon the organisation’s industry and operating model. The same checklist should not be mechanically applied to every business.

Manufacturing and Trading Businesses

Manufacturing and trading audits may focus on procurement, inventory, bill of materials, production, scrap, warehouses, fixed assets, vendor controls, logistics, working capital and statutory compliance.

Service, Technology and Professional Businesses

Service-sector audits may place greater emphasis on customer contracts, revenue recognition, project billing, employee costs, subcontractors, utilisation, information security, receivables and unbilled revenue.

Common Internal Audit Issues We Identify

Our practical audit work frequently identifies issues that arise from weak reconciliations, inadequate documentation or controls that exist on paper but are not consistently followed.

GST, TDS and Books Reconciliation Differences

Common issues can include turnover mismatches between accounting records and GST returns, unreconciled input tax credit, TDS defaults, delayed statutory deposits and differences with tax information statements.

Inventory, Old Balances and Unsupported Entries

Other recurring issues can include negative inventory, unexplained stock adjustments, long-outstanding receivables or payables, unreconciled advances, old suspense balances, unsupported journal entries and inadequately documented provisions.

Weak Approval and Compliance Controls

Audit observations may arise where approvals are obtained informally, payment controls can be bypassed, system access is excessive, statutory deadlines are not centrally monitored or the same person performs incompatible functions.

Many of these weaknesses are preventable through stronger maker-checker controls, reconciliations, responsibility matrices and periodic management review.

See also our guide on Common Pitfalls in Internal Audit.

ICAI Standards, Independence and Audit Documentation

Internal audit quality depends upon appropriate professional competence, objectivity, planning, evidence, documentation, communication and review.

Current ICAI Standards on Internal Audit

The Institute of Chartered Accountants of India maintains a structured Standards on Internal Audit framework covering internal controls, risk management, governance, compliance, planning, evidence, documentation, communication, reporting and related areas.

ICAI’s current Compendium of Standards on Internal Audit, as updated in February 2026, is applicable from 1 April 2026.

Readers may also access ICAI’s Standards on Internal Audit portal.

Internal Audit Charter and Independence

An internal audit charter establishes the function’s purpose, authority, organisational position, responsibilities, reporting relationships and access rights.

The internal auditor should have sufficient organisational independence and access to records, personnel and systems to perform the agreed work objectively.

Our guide on the Internal Audit Charter explains these principles in greater detail.

Audit Evidence and Documentation

Audit conclusions should be supported by appropriate evidence and working papers showing the procedures performed, information examined and conclusions reached.

Good documentation also permits appropriate review of the audit work and provides an audit trail for significant professional judgments.

Read our detailed guides on Internal Audit Documentation and Internal Audit Evidence.

Why Choose EzyBiz India for Internal Audit?

EzyBiz India Consulting LLP combines audit, accounting, taxation, GST, corporate law, regulatory and financial advisory experience to evaluate internal-control issues from both a compliance and business perspective.

Practical, Risk-Focused and Actionable Internal Audit

  • Risk-based methodology: Audit effort is directed towards areas having greater financial, operational and regulatory significance.
  • CA-led approach: Reviews combine accounting knowledge with practical tax and compliance experience.
  • Process understanding: We examine how transactions actually flow rather than relying solely upon written policies.
  • Integrated compliance review: GST, TDS, corporate, payroll and other statutory matters can be considered within the agreed internal audit scope.
  • Data-driven testing: Where reliable electronic data is available, analytics can supplement traditional sampling.
  • Management-focused reporting: Findings are linked with risk, root cause and corrective action.
  • Foreign subsidiary experience: Internal audit can be aligned with the oversight requirements of overseas parent companies.
  • Follow-up approach: Significant unresolved observations can be monitored until appropriate corrective action is implemented.

Our objective is to help management strengthen systems and controls rather than merely produce an audit report containing a list of exceptions.

Need Professional Audit and Assurance Support?

Get expert assistance with statutory audit, tax audit, internal audit, certification and other assurance requirements in India.

Speak With Our Audit Experts

Frequently Asked Questions

Is internal audit compulsory for every company in India?

No. Section 138 read with Rule 13 prescribes specific categories and thresholds for mandatory internal audit. Every listed company is covered, while specified unlisted public and private companies become subject to internal audit when prescribed financial criteria are satisfied.

Companies outside the mandatory thresholds may still voluntarily undertake internal audit as part of their governance and risk-management framework.

Can a private company appoint an internal auditor voluntarily?

Yes. A private company that is not statutorily required to appoint an internal auditor can still establish an internal audit function where management, investors, lenders or an overseas parent require independent review of risks, processes and controls.

What is included in an internal audit?

The scope depends upon the organisation’s risks and objectives. Common areas include procurement, sales, receivables, inventory, payroll, fixed assets, banking, GST, TDS, statutory compliance, IT controls, management reporting and approval processes.

How frequently should internal audit be conducted?

There is no single frequency suitable for every organisation. Audit frequency should reflect risk, transaction volume, regulatory requirements, previous findings and management priorities.

High-risk processes may require quarterly or more frequent review, while lower-risk areas may be examined annually or through a rotational audit plan. For companies governed by Rule 13, the Audit Committee or Board, in consultation with the internal auditor, determines the periodicity and methodology.

What is the difference between internal audit and internal control?

Internal controls are policies, procedures and activities established by management to address business risks. Internal audit independently evaluates whether those controls are appropriately designed and operating effectively.

Management therefore owns and operates internal controls; the internal auditor evaluates them and reports observations and recommendations.

Related Audit and Advisory Services

Need Professional Audit and Assurance Support?

Get expert assistance with statutory audit, tax audit, internal audit, certification and other assurance requirements in India.

Speak With Our Audit Experts

Prepared By:
EzyBiz India Consulting LLP
New Delhi, India

Reviewed By:
Anil Agrawal, Chartered Accountant

Last Updated:
September 2026

Disclaimer:
The information contained on this page is intended for general informational and educational purposes only and should not be construed as accounting, auditing, tax, legal or regulatory advice. Internal audit applicability, scope, methodology and reporting requirements depend upon the legal status, financial parameters, activities, risks and specific circumstances of each organisation. Applicable laws, rules, professional standards and regulatory requirements may change from time to time. Companies should review the latest provisions of the Companies Act, 2013, applicable rules and relevant professional standards and obtain appropriate professional advice before acting upon the information contained on this page. Internal audit does not eliminate business risk and should not be regarded as a guarantee that every error, control failure, fraud or instance of non-compliance will be detected.

Contact Form