Internal Audit Checklist

Table of Contents:-

Internal Audit Checklist for Companies in India

An internal audit checklist provides a structured framework for reviewing an organisation’s internal controls, risk management, governance, statutory compliance and operational processes.

Unlike a statutory audit, internal audit is not restricted to examination of financial statements. Its scope may extend to procurement, sales, inventory, payroll, taxation, information systems, regulatory compliance, fraud risks, delegation of authority and operational efficiency.

A properly designed internal audit helps management identify control weaknesses, improve processes, reduce financial and operational risks and strengthen governance.

Companies looking to establish or outsource their internal audit function can also refer to our Internal Audit Services in India.

What Is an Internal Audit?

Internal audit is an independent and systematic review of an organisation’s activities, processes and controls.

Its purpose is to evaluate whether:

  • internal controls are appropriately designed and operating effectively;
  • business processes follow approved policies;
  • significant risks are identified and managed;
  • statutory and regulatory requirements are being complied with;
  • assets and resources are adequately safeguarded;
  • financial and operational information is reliable;
  • fraud and misuse risks are appropriately controlled; and
  • opportunities exist to improve efficiency.

The scope should be designed according to the company’s industry, size, risk profile, organisational structure and management requirements.

The ICAI Internal Audit Standards Board publishes Standards on Internal Audit (SIAs), technical guides and other internal-audit guidance that can be considered while designing and conducting internal audit assignments.

Applicability of Internal Audit Under Companies Act, 2013

Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014 requires prescribed classes of companies to appoint an internal auditor.

Broadly, the requirement covers:

Listed Companies

Every listed company is required to appoint an internal auditor.

Certain Unlisted Public Companies

An unlisted public company is required to appoint an internal auditor where it meets any of the prescribed thresholds relating to:

  • paid-up share capital;
  • turnover;
  • outstanding loans or borrowings from banks or public financial institutions; or
  • outstanding deposits.

Certain Private Companies

Specified private companies are also required to appoint an internal auditor where prescribed thresholds relating to turnover or outstanding loans/borrowings are met.

Applicability should be checked based on the latest provisions and the company’s actual financial position before making an appointment.

Who Can Be Appointed as an Internal Auditor?

Under Section 138 of the Companies Act, the internal auditor may be a Chartered Accountant, Cost Accountant or such other professional as may be decided by the Board.

The internal auditor may also be an internal employee or an external professional, subject to the applicable legal requirements and the company’s governance framework.

Accordingly, companies may maintain an in-house internal audit function or engage an independent external professional or firm.

Businesses considering an outsourced model can learn more about our Internal Audit Services in India.

Key Areas Covered by an Internal Audit Checklist

There cannot be one universal checklist applicable to every business. The internal audit plan should be risk-based and customised.

However, the following areas commonly form part of an internal audit programme.

1. Governance and Internal Control Environment

Review whether:

  • an appropriate organisational structure has been documented;
  • roles and responsibilities are clearly defined;
  • authority and reporting lines are established;
  • policies and SOPs have been approved and communicated;
  • adequate segregation of duties exists;
  • maker-checker controls are implemented for critical transactions;
  • conflicts of interest are appropriately identified;
  • significant exceptions are escalated to management;
  • previous internal audit findings are tracked until closure; and
  • management periodically reviews the effectiveness of internal controls.

2. Delegation of Authority and Approval Matrix

The internal auditor should examine whether the company maintains a documented authority matrix covering areas such as:

  • purchases;
  • expenses;
  • contracts;
  • capital expenditure;
  • payments;
  • credit notes;
  • discounts;
  • employee reimbursements;
  • vendor creation;
  • customer credit limits;
  • journal entries; and
  • bank transactions.

Sample transactions should be tested to determine whether approvals are within prescribed authority limits.

3. Statutory and Regulatory Compliance

The internal audit should evaluate whether the company has an effective mechanism to identify and monitor laws and regulations applicable to its business.

A compliance checklist may include:

  • Companies Act compliances;
  • Income-tax compliances;
  • TDS;
  • GST;
  • PF and ESI;
  • labour law compliances;
  • FEMA requirements for foreign-owned companies;
  • industry-specific licences;
  • environmental or safety requirements, where applicable; and
  • contractual and regulatory reporting obligations.

A compliance calendar with responsibility and due dates should ideally be maintained.

4. Income-Tax and TDS Compliance

Internal audit procedures may include checking:

  • timely filing of income-tax returns and applicable forms;
  • advance tax and self-assessment tax;
  • TDS deduction at applicable rates;
  • timely deposit of TDS;
  • timely filing of TDS statements;
  • TDS certificates;
  • reconciliation of TDS returns with books;
  • Form 26AS/AIS reconciliation;
  • payments to non-residents and applicable withholding-tax requirements;
  • Form 15CA/15CB requirements, where applicable;
  • specified cash transactions; and
  • tax-related provisions and contingent liabilities.

The official Income Tax e-Filing Portal should be referred to for current tax filings and related compliance requirements.

5. GST Compliance

The GST portion of the internal audit checklist may cover:

  • GST registration details;
  • tax invoices;
  • correct classification and applicable tax rate;
  • reconciliation of turnover with books;
  • reconciliation of GSTR-1 and GSTR-3B;
  • input tax credit reconciliation;
  • eligibility of input tax credit;
  • reverse charge transactions;
  • debit and credit notes;
  • e-invoicing, where applicable;
  • e-way bills, where applicable;
  • export documentation and LUT;
  • GST payments;
  • interest and late fees;
  • vendor compliance affecting input tax credit; and
  • year-end GST reconciliations.

Companies may refer to the official GST Portal for current GST compliance requirements.

6. Purchase and Procurement

Procurement is an important internal audit area because weaknesses can result in excessive costs, unauthorised purchases, duplicate payments and fraud.

Purchase Documentation

Check availability and adequacy of:

  • purchase requisitions;
  • approved vendor master;
  • quotations/tenders;
  • comparative statements;
  • purchase orders;
  • contracts;
  • vendor invoices;
  • goods receipt notes/material receipt notes;
  • gate-entry records;
  • quality inspection reports;
  • transport documents;
  • import documentation, where applicable; and
  • purchase register.

Procurement Controls

Verify whether:

  • purchases are initiated through authorised requisitions;
  • appropriate quotations are obtained;
  • comparative analysis is documented;
  • deviations from the lowest quotation are approved;
  • purchase orders are properly authorised;
  • amendments to purchase orders are controlled;
  • goods received are compared with purchase orders;
  • quantity and quality are verified;
  • duplicate invoices are prevented;
  • related-party purchases are separately identified;
  • vendor master creation/modification is controlled; and
  • capital purchases are not incorrectly charged as revenue expenditure.

7. Vendor Management and Accounts Payable

Review:

  • vendor onboarding and KYC;
  • vendor master changes;
  • duplicate vendors;
  • related-party vendors;
  • purchase order–invoice–goods receipt matching;
  • ageing of creditors;
  • old and disputed balances;
  • debit balances;
  • vendor advances;
  • balance confirmations;
  • MSME identification and payment monitoring;
  • credit/debit notes; and
  • duplicate or unusual payments.

Particular attention should be given to changes in vendor bank details and payments made immediately after such changes.

8. Sales and Revenue

The internal audit checklist for sales may include:

  • approved sales policy;
  • customer master controls;
  • sales orders;
  • pricing;
  • discounts;
  • delivery documents;
  • invoices;
  • credit notes;
  • sales returns;
  • revenue recognition;
  • year-end cut-off;
  • unbilled revenue;
  • advances from customers;
  • GST treatment; and
  • reconciliation between sales records and financial accounts.

Sequential control over invoices, credit notes and delivery documents should also be examined.

9. Customer Credit Assessment

Review whether:

  • a formal credit policy exists;
  • customer creditworthiness is assessed before granting credit;
  • credit limits are approved;
  • overrides require appropriate approval;
  • credit limits are periodically reviewed;
  • overdue customers are monitored;
  • blocked customers cannot transact without approval; and
  • exceptions are reported to management.

10. Trade Receivables and Collection

Review:

  • debtor ageing;
  • overdue receivables;
  • customer confirmations;
  • subsequent collections;
  • disputed balances;
  • credit notes;
  • write-offs;
  • bad-debt provisions;
  • expected credit losses, where applicable;
  • collection follow-up procedures; and
  • reconciliation with the general ledger.

Material overdue accounts should be analysed for reasons, recovery status and management action.

11. Inventory and Stores

Internal audit procedures may cover:

  • physical verification;
  • perpetual inventory records;
  • inventory ageing;
  • slow-moving inventory;
  • obsolete inventory;
  • valuation;
  • stock adjustments;
  • goods in transit;
  • stock with third parties;
  • scrap;
  • damaged goods;
  • access to warehouses;
  • goods receipt and issue controls; and
  • reconciliation of physical inventory with books.

Unexpected or recurring stock differences should be investigated.

12. Cash and Bank

Review controls over:

  • cash receipts;
  • cash payments;
  • petty cash;
  • physical cash verification;
  • bank reconciliations;
  • cheque controls;
  • online banking access;
  • bank signatories;
  • maker-checker controls;
  • dormant bank accounts;
  • fixed deposits;
  • unusual transfers; and
  • changes in beneficiary bank details.

Bank reconciliations should be prepared regularly and old unreconciled items investigated.

13. Payroll and Human Resources

Internal audit may review:

  • employee master;
  • appointment documents;
  • salary structure;
  • attendance;
  • leave;
  • payroll processing;
  • salary revisions;
  • incentives and bonuses;
  • overtime;
  • reimbursements;
  • PF/ESI deductions;
  • TDS on salary;
  • employee advances;
  • resigned employees;
  • full and final settlements;
  • ghost employees; and
  • payroll-bank reconciliation.

Changes to employee bank accounts and salary masters should require appropriate authorisation.

14. Fixed Assets

The fixed asset checklist may include:

  • fixed asset register;
  • purchase approvals;
  • invoices;
  • capitalisation;
  • asset identification/tagging;
  • physical verification;
  • asset location;
  • depreciation;
  • impairment indicators;
  • repairs versus capital expenditure;
  • transfers;
  • disposal approvals;
  • sale proceeds; and
  • reconciliation with the general ledger.

15. Expenses and Employee Reimbursements

Review whether:

  • expenses are business-related;
  • adequate supporting documents exist;
  • approval limits are followed;
  • duplicate claims are prevented;
  • personal expenses are identified;
  • GST input tax credit is correctly considered;
  • TDS requirements are complied with;
  • employee reimbursements follow company policy; and
  • unusual expenses are investigated.

16. Loans and Borrowings

Check:

  • sanction letters and agreements;
  • utilisation of borrowed funds;
  • interest calculation;
  • repayment schedule;
  • compliance with covenants;
  • security and charges;
  • defaults;
  • related-party borrowings;
  • TDS on applicable interest; and
  • appropriate accounting classification.

17. Related Party Transactions

Internal audit should identify related parties and examine whether transactions:

  • are appropriately authorised;
  • comply with applicable company policies and legal requirements;
  • are supported by agreements;
  • are recorded accurately;
  • are appropriately disclosed; and
  • are conducted on appropriate commercial terms.

18. Information Technology and User Access Controls

Modern internal audit should also consider technology risks.

Review:

  • user access rights;
  • privileged/administrator access;
  • password controls;
  • access of resigned employees;
  • maker-checker configurations;
  • audit logs;
  • system changes;
  • data backup;
  • disaster recovery;
  • cybersecurity controls; and
  • access to accounting and banking systems.

19. Fraud Risk and Unusual Transactions

Internal audit should remain alert to red flags such as:

  • duplicate payments;
  • unusual journal entries;
  • transactions on holidays;
  • payments immediately below approval limits;
  • related-party transactions not disclosed;
  • unusual cash transactions;
  • frequent vendor bank-detail changes;
  • unsupported expenses;
  • excessive credit notes;
  • inventory shortages; and
  • transactions lacking proper authorisation.

Any suspected fraud or control override should be escalated according to the company’s governance framework.

20. Financial Reporting and Reconciliations

Key reconciliations may include:

  • bank reconciliation;
  • debtors;
  • creditors;
  • inventory;
  • fixed assets;
  • GST;
  • TDS;
  • payroll;
  • inter-company balances;
  • related parties;
  • loans;
  • statutory liabilities; and
  • revenue with operational records.

Old reconciliation differences should not simply be carried forward without investigation.

21. Legal and Contractual Compliance

Review:

  • significant contracts;
  • lease agreements;
  • customer/vendor agreements;
  • pending litigation;
  • legal notices;
  • licences;
  • registrations;
  • insurance;
  • contractual obligations; and
  • contingent liabilities.

The company should maintain a mechanism to monitor expiry and renewal dates of important licences, agreements and insurance policies.

22. Internal Audit Documentation

The internal auditor should maintain adequate documentation supporting the procedures performed, evidence obtained and conclusions reached.

Documentation may include:

  • internal audit plan;
  • scope document;
  • risk assessment;
  • process narratives;
  • control matrices;
  • walkthroughs;
  • sample selection;
  • working papers;
  • supporting evidence;
  • management explanations;
  • observations;
  • management responses;
  • final reports; and
  • follow-up status.

ICAI’s current Standards on Internal Audit include specific standards dealing with internal controls, risk management, governance, compliance with laws, planning, evidence, documentation, reporting and monitoring of prior audit issues.

Refer to the ICAI Standards on Internal Audit for professional guidance.

23. Internal Audit Reporting

An effective internal audit report should clearly communicate:

  • audit scope;
  • procedures performed;
  • observations;
  • risk implications;
  • root causes;
  • recommendations;
  • management responses;
  • responsible persons; and
  • target completion dates.

Observations may also be categorised according to risk level—for example, high, medium and low—to help management prioritise corrective action.

24. Follow-Up of Previous Audit Observations

Internal audit should not end with issuance of the report.

A structured follow-up process should verify:

  • whether management accepted the observation;
  • corrective action proposed;
  • person responsible;
  • target completion date;
  • present status;
  • supporting evidence of closure; and
  • reasons for overdue actions.

Repeated findings should be specifically highlighted to senior management or those charged with governance.

Risk-Based Internal Audit Approach

Rather than giving equal attention to every transaction or process, companies increasingly use a risk-based approach.

Higher attention may be given to areas involving:

  • high financial value;
  • regulatory exposure;
  • fraud risk;
  • management judgement;
  • significant system changes;
  • related-party transactions;
  • weak historical controls;
  • repeated audit findings; or
  • rapidly changing business processes.

ICAI also publishes guidance and technical literature dealing with risk-based internal audit and industry-specific internal audit practices.

Internal Audit Checklist for Foreign-Owned Companies in India

Foreign subsidiaries and other foreign-owned businesses operating in India may require additional internal audit attention because local operations must often comply with both Indian requirements and global group policies.

Important areas can include:

  • inter-company transactions;
  • transfer pricing documentation;
  • FEMA compliance;
  • overseas payments;
  • related-party transactions;
  • management/service fees;
  • royalty payments;
  • foreign currency transactions;
  • group reporting;
  • delegation of authority;
  • global procurement policies; and
  • reconciliation between local and group accounting systems.

An effective internal audit can therefore serve as an important governance mechanism between the Indian management team and overseas headquarters.

Benefits of Using an Internal Audit Checklist

A structured checklist helps ensure that significant areas are not overlooked during an internal audit.

Major benefits include:

  • consistent audit coverage;
  • improved internal controls;
  • early identification of compliance gaps;
  • better risk management;
  • reduced fraud exposure;
  • improved operational efficiency;
  • better documentation;
  • accountability for corrective actions; and
  • stronger corporate governance.

However, a checklist should support—not replace—the professional judgement of the internal auditor.

Frequently Asked Questions

What is an internal audit checklist?

An internal audit checklist is a structured list of processes, controls, risks and compliance areas to be examined during an internal audit.

Is internal audit compulsory for every company in India?

No. Section 138 of the Companies Act, 2013 read with the applicable rules prescribes internal audit requirements for specified classes of companies. Other companies may voluntarily conduct internal audits as a governance and risk-management measure.

Who can be appointed as an internal auditor?

Subject to applicable provisions, an internal auditor may be a Chartered Accountant, Cost Accountant or such other professional as may be decided by the Board. The internal auditor may be an employee or an external professional, depending upon the company’s circumstances and applicable requirements.

What areas should an internal audit checklist cover?

Depending on the business, it may cover governance, finance, procurement, sales, inventory, payroll, taxes, statutory compliance, IT systems, fixed assets, related parties, fraud risks and operational controls.

How often should an internal audit be conducted?

The frequency should depend on the organisation’s size, risks, regulatory requirements and internal audit plan. High-risk processes may require more frequent review than lower-risk areas.

What is the difference between internal audit and statutory audit?

Internal audit focuses primarily on risk management, internal controls, governance, compliance and operational improvement. Statutory audit is an independent examination required under law and focuses on expressing an audit opinion on financial statements and fulfilling prescribed reporting responsibilities.

For statutory audit assistance, refer to our Statutory Audit Services in India.

Can internal audit be outsourced?

Yes, depending on the company’s circumstances and applicable legal requirements, the internal audit function may be outsourced to external professionals. Outsourcing can provide specialised expertise and greater independence from day-to-day operational functions.

Learn more about our Internal Audit Services in India.

Are ICAI Standards on Internal Audit relevant?

ICAI has developed Standards on Internal Audit covering areas including internal controls, risk management, governance, compliance, planning, evidence, documentation and reporting. Internal audit professionals should consider the applicable professional framework while conducting engagements.

Internal Audit Services in India

EzyBiz India Consulting LLP assists Indian and foreign-owned companies with internal audit, risk assessment, internal control reviews, process audits and compliance reviews.

Our approach focuses not merely on identifying exceptions but also on understanding root causes and recommending practical improvements to strengthen controls and business processes.

For professional assistance, visit our Internal Audit Services in India or explore our broader Audit and Assurance Services in India.

Related Services

Prepared By: EzyBiz India Consulting LLP
Reviewed By: Anil Agrawal, Chartered Accountant
Last Updated: August 2026

Disclaimer: This internal audit checklist is intended for general informational purposes and provides an illustrative framework only. The scope and procedures of an internal audit should be determined based on the organisation’s nature, size, industry, risk profile, applicable laws, internal policies and specific engagement objectives. Professional advice should be obtained based on the facts and circumstances of each case.

     3. Compliance of Accounting Standard and Standard on Auditing

    • AS 1 Disclosure of Accounting Policies.
    • AS 2 Valuation of Inventories.
    • AS 11 The Effects of Changes in Foreign Exchange Rates.
    • AS 12 Accounting for Government Grants.
    • AS 18 Related Party Disclosures.
    • SA 230 Audit Documentation.
    • SA 240 The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements.
    • SA 330 The Auditor’s Responses to Assessed Risks.
    • SA 550 Related Parties.
    • SA 265 Communicating Deficiencies in Internal Control to Those Charged with Governance and Management.
    • SIA 18 Related Parties.

    4. Credit Assessment

    • Check credit policy and adherence of Credit Policy and report deviations, if any.
    • Whether credit worthiness of all new credit customers has been evaluated and documented for approval.
    • Whether overrides to the credit rules has been approved in accordance with the authority levels if any.
    • Whether credit assessments for all the major customers has been updated at least once in a year.
    • Check that no delivery order has been generated by the system if the customers had trade debts exceeding their credit terms/ limits and require pre-approval before the orders are processed.

    5. Sales Dispatch

    • Check sales policy and report deviations, if any. Policies and procedures for credit and collections management should be clearly documented.
    • Whether pre-shipment inspection has been carried and material has been dispatched as per invoice and contract.
    • Status of pending overdue sales order, reason and financial implication, if any.
    • Whether cancellation of sale order are properly approved by competent authority.
    • Sales Return Approval for taking sale return, receipt and inspection of returned goods and issue of credit note, etc.
    • Sales return reason, analysis and comment on sales return material lying in stock and the gain/ loss on resale of returned material.
    • On time performance trend and any loss caused due to delay in delivery.
    • Comment on avoidable/ controllable expenses, such as, air freight, demurrage, discount etc.,
    • Process of appointment of agents/ sub-agents/ broker, renewal of agreement and payment of commission to agents as per agreement and as defined in sales policy.
    • In case of non-payment by customer, whether the same has been recovered from agent’s commission. Whether commission payable has been reconciled with respective agents.
    • There should be sequential control over all Invoices, Credit Notes, Delivery Orders and Goods Returned Note.

    6. Reconciliation

    • Debtors ageing report should be reconciled with general ledger.
    • Taking independent confirmations for customer’s account balance with third parties.
    • Overall reconciliation
      • Raw materials
      • Finished goods
      • Billing
      • Debtors
      • Realizations
      • Write-offs.

   Purchase and Procurement

    1. Documents

    • Purchase / service policy of the entity
    • Purchase order/ service contracts
    • Original invoice
    • E-way bills
    • Lorry documents for freight payment and for TDS, if applicable
    • Gate-entry record
    • Material receipt note showing actual quantity.
    • Purchase register
    • Custom clearance and receipt for payment of custom duty, in case of import etc.

   2. Legal Compliance

    • Payment of state/ local entrance fees or availability of proper document showing exemption for such payment.
    • Payment of custom duty and custom clearance of imported material.
    • Deduction and payment of TDS on freight on purchases and services.
    • Payment of GST on the goods purchased from unregistered dealer.
    • In case of purchase from related party at arm’s length price, not contravene Companies Act, 2013.
    • The procurement price is reasonable Income Tax Act, if purchase is made from sister concern.
    • Government notifications and guidelines regarding compulsory purchases from Micro, Small and Medium Enterprises.

   3. Authorisation Matrix

    • Requisition for purchase of store material/ service contracts authorized properly.
    • Opening of tender or quotations signed by proper person.
    • Comparative chart of technical and financial biddings approved by top level.
    • Purchase order or service contracts including amendments or modifications.
    • Inward entry at company gate.
    • Quality check and its approval or satisfactory report from user.
    • Material receipt note by authorized person.
    • Approval of rates, in case purchase order is not raised.
    • Issue of debit or credit note for return or rejection of material singed by proper authority.

   4. Compliance of Accounting Standard and Standard on Auditing

    • AS 1 Disclosure of Accounting Policies.
    • AS 2 Valuation of Inventories.
    • AS 11 The Effects of Changes in Foreign Exchange Rates.
    • AS 18 Related Party Disclosures.
    • SA 550 Related Parties.
    • SIA 18 Related Parties. 

   5. Procedures & Controls

    • The company has clear and comprehensive procurement policy or service contract whether purchases or services are centralised department or purchases or services are made from approved authorities.
    • Internal purchase requisition is properly validated and authorized by proper person.
    • The internal requisition clearly mentions the specification and quantity of material or service to be procured and also the supply date.
    • Purchases and procurement of services are based on competitive quotations as received from two or more suppliers.
    • Whether comparative quotation analysis sheet drawn before purchases are authorized.
    • If lowest quotation is not accepted, whether the purchases has been approved by senior official.
    • Whether purchase or service orders are pre numbered and strict control exists over unused forms.
    • Whether list of pending purchase or service order is complied by appropriate department, at least once in every quarter.
    • Whether quotations are called as per company’s policy from the registered vendors only.
    • Whether quotations are opened and registered and a comparative chart is prepared and authorized.
    • Purchase or service order is given to lowest bidder subject to satisfaction of all other conditions.
    • One copy of each purchase order or service order should be made available to store and accounts department.
    • Material is supplied as per purchase order and material receipt note is prepared after quantity and quality checks and authorization.
    • Service is executed as per service order.

   6. Transaction Recording

  • Raw materials have been recorded as ‘Raw Material’ and stores and spares have been recorded as ‘Consumables’ and service has been recorded to ‘Direct Expenses’.
  • Procurement for capital expenditure is not recorded as revenue expenditure.
  • The value of purchase or service is recorded net of GST and VAT credit, if claimed.
  • All the related expenditure, such as toll tax, freight, etc. is included as part of purchase.
  • TDS, if applicable, should not be charged to purchase or service.