Standards on Internal Audit in India – ICAI SIA Guide
Table of Contents:-
Internal audit has evolved from a traditional transaction-checking function into an important assurance and advisory mechanism covering risk management, internal controls, governance, regulatory compliance and operational efficiency.
To establish consistency and quality in internal audit assignments, the Institute of Chartered Accountants of India (ICAI) issues Standards on Internal Audit (SIAs) through its Internal Audit Standards Board.
These standards provide a professional framework for areas such as internal audit principles, engagement terms, planning, risk assessment, evidence, documentation, supervision, communication, reporting and follow-up.
ICAI has published a Compendium of Standards on Internal Audit as on February 2026, applicable from 1 April 2026. Businesses and professionals should therefore refer to the latest framework rather than relying solely upon older SIA numbers and guidance.
Readers can refer directly to the ICAI Internal Audit Standards Board for current standards, technical guides and professional publications.
For professional assistance with implementation, see our Internal Audit Services in India.
What are Standards on Internal Audit?
Standards on Internal Audit provide a structured professional framework for planning, conducting, documenting, supervising and reporting internal audit assignments.
They help establish consistency regarding:
- responsibilities of the internal auditor;
- internal audit objectives;
- terms of engagement;
- planning and risk assessment;
- quality of audit work;
- audit evidence;
- documentation;
- review and supervision;
- communication;
- reporting; and
- monitoring of previous audit issues.
Why Internal Audit Standards are Important
Internal audit standards help ensure that the audit is not conducted merely according to personal preference or an informal checklist.
They provide a structured methodology that helps:
- improve audit quality;
- maintain consistency;
- establish accountability;
- support professional judgment;
- improve documentation;
- strengthen supervision;
- enhance reporting; and
- demonstrate adherence to recognised professional practices.
Who Issues Standards on Internal Audit in India?
The Institute of Chartered Accountants of India issues Standards on Internal Audit through its Internal Audit Standards Board.
The Board develops standards, technical guides, studies, manuals and other professional literature relating to internal auditing. The latest standards and publications can be accessed through the official ICAI Internal Audit Standards Board.
Current ICAI Internal Audit Standards Framework
ICAI periodically revises and reorganises its internal audit standards.
This is important because older articles and professional literature may refer to standards such as SIA 7 – Quality Assurance in Internal Audit and SIA 8 – Terms of Internal Audit Engagement, while the current framework should be read with the latest ICAI Compendium.
ICAI’s February 2026 Compendium became applicable from 1 April 2026.
Basic Principles of Internal Audit
The standards framework starts with the fundamental principles governing internal audit.
These principles support:
- professional competence;
- objectivity;
- appropriate audit methodology;
- sufficient audit evidence;
- professional judgment;
- appropriate communication; and
- quality in performance.
Internal audit should ultimately add value by evaluating and improving governance, risk management and internal controls.
For the basic concepts, read What is Internal Audit?.
Terms of Internal Audit Engagement
One of the important current standards deals with Terms of Internal Audit Engagement.
ICAI’s current SIA 120 addresses the terms of internal audit engagement. Its objectives include documenting the scope of internal audit activity, providing clarity regarding the internal audit arrangement, establishing responsibilities and authorities, defining limitations and specifying reporting timelines.
The engagement terms establish the operating framework within which the internal auditor performs the assignment.
Managing the Internal Audit Function
Where an organisation has an internal audit function, it should be appropriately managed.
Important matters may include:
- audit strategy;
- annual audit planning;
- resources;
- staffing;
- technical competence;
- allocation of assignments;
- supervision;
- quality monitoring; and
- reporting to appropriate governance authorities.
Effective management helps ensure that internal audit resources are directed towards significant organisational risks.
Internal Audit Planning
Internal audit requires structured planning at both the overall function level and individual engagement level.
Planning generally considers:
- business objectives;
- significant risks;
- audit universe;
- previous audit observations;
- management concerns;
- regulatory requirements;
- available resources; and
- changes in the organisation.
For a practical explanation, see our Internal Audit Process.
Quality Assurance in Internal Audit
Quality assurance has historically been an important component of ICAI’s internal audit standards.
The attached older article was largely built around SIA 7 – Quality Assurance in Internal Audit and covered matters such as ethical requirements, human resources, engagement performance, monitoring and internal/external quality review.
ICAI’s 2026 professional education programme specifically covered QSIA 1 & 2, demonstrating the continuing importance of quality standards within the current framework.
Objective of Quality Assurance
The objective of quality assurance is to establish reasonable confidence that internal audit activities are performed in accordance with applicable professional standards and appropriately designed procedures.
A quality framework helps determine whether:
- assignments are properly planned;
- qualified personnel perform the work;
- procedures are appropriately executed;
- evidence supports findings;
- documentation is complete;
- reports are properly reviewed; and
- significant issues are appropriately communicated.
Internal Quality Review
Internal quality review may involve periodic or ongoing evaluation within the internal audit function.
Important areas can include:
- compliance with audit methodology;
- quality of working papers;
- appropriateness of sampling;
- adequacy of evidence;
- review of audit conclusions;
- quality of reports;
- staff supervision; and
- implementation of corrective actions.
The existing page also recognised internal quality review and communication of its results to management as important quality-assurance elements.
External Quality Review
Depending upon applicable professional requirements and the internal audit framework adopted by the organisation, an independent external review may also provide an objective assessment of the quality of the internal audit function.
Such reviews can evaluate:
- independence;
- methodology;
- governance structure;
- documentation;
- competency;
- quality controls;
- stakeholder communication; and
- overall effectiveness.
Responsibility for Quality
Quality is not the responsibility of one reviewer alone.
The person responsible for managing the internal audit function should establish appropriate systems covering:
- assignment planning;
- staff competence;
- supervision;
- review;
- documentation;
- reporting; and
- continuous improvement.
Terms of Internal Audit Engagement
Clearly defined engagement terms are essential because ambiguity at the beginning of an audit can lead to disputes regarding scope, responsibility and reporting.
The existing article also correctly emphasised that the terms should be agreed before commencement of the audit and appropriately documented.
Internal Audit Charter
For an in-house internal audit function, the overall mandate is generally established through an internal audit charter.
The charter may define:
- purpose;
- authority;
- responsibility;
- organisational position;
- reporting relationships;
- access to information;
- independence; and
- broad scope of internal audit.
Read our detailed guide on the Internal Audit Charter.
Engagement Letter
Where an internal audit is outsourced, an engagement letter helps clearly establish the terms agreed between the organisation and the internal auditor.
Typical matters may include:
- audit objectives;
- scope;
- period;
- responsibilities;
- access to records;
- confidentiality;
- deliverables;
- reporting;
- timelines;
- fees;
- limitations; and
- other significant conditions.
ICAI’s current SIA 120 expressly recognises documentation of the scope and the terms of an outsourced internal audit engagement.
Scope of Internal Audit Engagement
The scope should identify precisely what the auditor is expected to examine.
It may specify:
- departments;
- locations;
- processes;
- legal entities;
- periods;
- transactions;
- control areas;
- regulatory matters; and
- exclusions.
A poorly defined scope can result in scope creep, delays and disagreements.
Our guide on Common Pitfalls in Internal Audit explains these risks in detail.
Responsibilities of Management
Management remains responsible for the organisation’s:
- operations;
- accounting records;
- internal controls;
- risk management;
- regulatory compliance; and
- implementation of corrective measures.
Appointment of an internal auditor does not transfer these management responsibilities to the auditor.
Responsibilities of Internal Auditor
The internal auditor is responsible for performing the agreed procedures with appropriate professional competence and care.
Responsibilities may include:
- understanding the business;
- assessing risks;
- planning procedures;
- obtaining audit evidence;
- documenting work;
- reporting significant findings; and
- maintaining professional objectivity.
Risk Management and Internal Controls
Modern internal audit standards place considerable importance on the relationship between internal audit, risk management and internal controls.
Risk-Based Internal Auditing
Internal audit resources should ordinarily be directed towards areas presenting material risks to organisational objectives.
Important risks may include:
- financial risk;
- operational risk;
- compliance risk;
- fraud risk;
- IT risk;
- cybersecurity risk;
- reputational risk; and
- strategic risk.
Read our detailed guide on Risk Based Internal Audit.
Evaluation of Internal Controls
Internal auditors evaluate whether controls are:
- appropriately designed;
- properly implemented; and
- operating effectively.
Controls may include approvals, segregation of duties, reconciliations, access controls, maker-checker controls, supervisory review and automated system controls.
For broader attributes of an effective internal audit function, see Characteristics of Internal Audit.
Conduct of Internal Audit Assignments
The standards also support a structured approach to individual internal audit assignments.
Understanding the Entity
Before performing detailed procedures, the internal auditor should understand:
- business model;
- organisational structure;
- significant processes;
- information systems;
- regulatory environment;
- key personnel; and
- significant risks.
Planning Audit Procedures
The auditor should design procedures that address identified risks and audit objectives.
Procedures may include:
- inquiry;
- observation;
- inspection;
- walkthroughs;
- analytical review;
- transaction testing;
- sampling;
- reconciliations; and
- physical verification.
Internal Audit Evidence
Audit conclusions should be supported by sufficient and appropriate evidence.
Evidence can include:
- invoices;
- contracts;
- management reports;
- accounting records;
- system reports;
- confirmations;
- reconciliations; and
- regulatory records.
Sampling
Where examination of an entire population is impractical, auditors may use appropriate sampling methods.
Sample selection should correspond with:
- audit objective;
- population;
- risk;
- materiality; and
- nature of transactions.
For detailed guidance, read Sampling in Internal Audit.
Internal Audit Documentation
Working papers should demonstrate:
- procedures performed;
- evidence examined;
- samples selected;
- findings identified;
- professional judgments exercised; and
- conclusions reached.
For detailed guidance, see Internal Audit Documentation.
Review and Supervision
Internal audit work should undergo appropriate supervision and review.
The reviewer should consider:
- whether procedures were properly performed;
- whether evidence is sufficient;
- whether findings are supported;
- whether conclusions are reasonable;
- whether documentation is adequate; and
- whether significant matters have been appropriately reported.
Communication and Reporting
Communication is an important part of a successful internal audit.
Communication During the Audit
Important matters should be discussed with relevant process owners during fieldwork.
This helps:
- clarify facts;
- obtain missing evidence;
- understand root causes;
- avoid factual errors; and
- enable timely corrective action.
Internal Audit Report
A structured internal audit observation generally includes:
Observation: What was identified?
Criteria: What should have happened?
Cause: Why did it happen?
Risk/Impact: Why does the issue matter?
Recommendation: What corrective action is required?
Management Response: What action has management agreed?
Timeline: When will the matter be resolved?
Reporting Significant Issues
Material matters may need to be communicated to:
- senior management;
- Audit Committee;
- Board of Directors; or
- others charged with governance,
depending upon the organisational structure and significance of the finding.
Follow-Up of Audit Findings
Internal audit should also monitor previously reported observations.
Findings may be classified as:
- Open;
- Under Implementation;
- Overdue; or
- Closed.
Failure to follow up audit recommendations is one of the common weaknesses that can reduce the effectiveness of internal audit.
Compliance with Laws and Regulations
Internal audit may also evaluate whether appropriate systems exist to ensure compliance with applicable laws and regulations.
Compliance Areas
Depending upon the organisation, these may include:
- Companies Act;
- GST;
- income-tax and TDS;
- FEMA;
- labour laws;
- environmental requirements;
- licences; and
- industry-specific regulations.
For detailed guidance, read Compliance with Laws and Regulations in Internal Audit.
Official corporate regulatory information can also be obtained from the Ministry of Corporate Affairs, tax information from the Income Tax Department, GST information from the GST Portal and foreign exchange regulations from the Reserve Bank of India.
Management Responsibility for Compliance
Internal audit does not replace management’s responsibility for legal and regulatory compliance.
The internal auditor evaluates whether adequate processes and controls have been established to identify, monitor and manage significant compliance risks.
Standards on Internal Audit and Global Internal Audit Standards
Indian organisations may also refer to international professional guidance where appropriate.
The Global Internal Audit Standards issued by The Institute of Internal Auditors provide a global professional framework covering ethics, governance of internal audit, management of the function and performance of internal audit services.
ICAI Standards
For internal audits performed within the ICAI professional framework in India, professionals should refer to the latest standards and pronouncements issued by ICAI.
The ICAI Compendium of Standards on Internal Audit should be referred to for the current consolidated framework. The February 2026 compendium is stated by ICAI to be applicable from 1 April 2026.
Global Standards
The Global Internal Audit Standards can provide additional international context, particularly for multinational organisations and Indian subsidiaries of overseas groups.
Foreign-owned businesses may need to align:
- group internal audit requirements;
- Indian legal requirements;
- ICAI professional standards; and
- global internal audit policies.
Older SIA 7 and SIA 8 – Important Update
This page was previously written around SIA 7 – Quality Assurance in Internal Audit and SIA 8 – Terms of Internal Audit Engagement.
Earlier SIA 7
The earlier SIA 7 primarily addressed quality assurance in internal audit, including internal and external quality reviews. The original attached article also covered responsibilities for quality, monitoring and communication of review results.
Earlier SIA 8
The older article presented SIA 8 as dealing with terms of internal audit engagement and covered matters such as scope, responsibilities, authority, confidentiality, limitations and reporting.
Why the Page Has Been Updated
ICAI has subsequently revised its Standards on Internal Audit framework. The current February 2026 compendium is applicable from 1 April 2026, and ICAI’s 2026 professional programme includes current standards such as SIA 120 – Terms of Internal Audit Engagement along with QSIA 1 & 2 for quality standards.
Accordingly, old SIA references should not be read in isolation without checking the current ICAI framework.
Frequently Asked Questions
What are Standards on Internal Audit?
Standards on Internal Audit are professional standards establishing principles and requirements for planning, performing, documenting, reviewing and reporting internal audit work.
Who issues Standards on Internal Audit in India?
The Institute of Chartered Accountants of India issues Standards on Internal Audit through its Internal Audit Standards Board.
What is the latest ICAI Compendium of Standards on Internal Audit?
ICAI’s website currently lists a Compendium of Standards on Internal Audit as on February 2026, applicable from 1 April 2026.
Is SIA 7 on Quality Assurance still relevant?
SIA 7 forms part of ICAI’s older standards literature. For current professional application, the latest ICAI Compendium and current quality standards should be checked. ICAI’s 2026 education programme specifically covers QSIA 1 & 2.
Which current standard deals with terms of internal audit engagement?
ICAI currently has SIA 120 – Terms of Internal Audit Engagement, which deals with matters such as scope, responsibilities, authority, reporting and other engagement parameters.
Why is an internal audit engagement letter important?
An engagement letter clarifies the audit scope, responsibilities, access, limitations, reporting requirements, timelines and other significant terms before commencement of the engagement.
Is an internal audit charter the same as an engagement letter?
No. An internal audit charter generally establishes the overall mandate and authority of an internal audit function, whereas an engagement letter ordinarily documents specific terms between the organisation and an external internal auditor.
Do Internal Audit Standards cover documentation?
Yes. Internal audit standards address preparation and maintenance of documentation supporting procedures, evidence, findings and conclusions.
Do Internal Audit Standards cover risk management?
Yes. Evaluation of organisational risks and alignment of audit activities with significant risks are important components of modern internal auditing.
Are Internal Audit Standards applicable to foreign-owned Indian companies?
Internal audit standards may be relevant to the internal audit of foreign-owned Indian entities depending upon the engagement, professional framework and applicable requirements. Such companies may additionally need to align with global group internal audit policies.
Related Services & Guides
- Internal Audit Services in India
- Audit and Assurance Services in India
- What is Internal Audit?
- Characteristics of Internal Audit
- Internal Audit Checklist
- Internal Audit Process
- Risk Based Internal Audit
- Internal Audit Documentation
- Sampling in Internal Audit
- Internal Audit Charter
- Compliance with Laws and Regulations in Internal Audit
- Common Pitfalls in Internal Audit
Prepared By
Anil Agrawal, Chartered Accountant
EzyBiz India Consulting LLP, New Delhi
Chartered Accountant with experience in audit, taxation, regulatory compliance, international taxation and business advisory services.
Last Updated
August 2026
Disclaimer
This article is intended for general informational and educational purposes only and should not be treated as legal, audit, accounting, tax or other professional advice. Standards on Internal Audit and related professional guidance may be amended, superseded or reorganised from time to time. Readers should refer to the latest Standards, Compendium and pronouncements issued by ICAI and other applicable professional or regulatory authorities and obtain appropriate professional advice before taking any action.
