CA K Sanjay BhargavChartered Accountant
Open menu

Internal financial controls and IT systems audit

Almost every company is required to maintain internal financial controls; a smaller set must also have the auditor report on them under Section 143(3)(i). Where the accounting runs on a system — and it almost always does — testing those controls means testing the system around them. This work is carried out by a Chartered Accountant who also holds the ICAI’s Diploma in Information Systems Audit (DISA).

Who has to report on IFC

Two obligations get conflated, and separating them is the first useful thing to do:

ProvisionWho it bindsWhat it requires
s.134(5)(e)Directors of a listed companyState in the Directors’ Responsibility Statement that IFC were laid down, are adequate and operated effectively
Rule 8(5)(viii), Companies (Accounts) RulesBoard’s reportDisclose the adequacy of internal financial controls with reference to the financial statements
s.143(3)(i)The statutory auditorReport on whether adequate IFC with reference to financial statements exist, and on their operating effectiveness

The obligation to have controls sits on the company regardless of size. Only the auditor’s separate reporting duty under s.143(3)(i) carries an exemption.

The private-company exemption — and the condition people miss

By the MCA notification dated 13 June 2017, the s.143(3)(i) reporting requirement does not apply to a private company which:

  • is a one person company or a small company; or
  • has turnover less than ₹50 crore as per the latest audited financial statement; or
  • has aggregate borrowings less than ₹25 crore from banks, financial institutions or any body corporate, at any point during the financial year.

These are alternatives, not cumulative conditions — meeting any one is enough. But the exemption carries a proviso that is easy to overlook and expensive to discover late: it is available only to a private company that has not defaulted in filing its financial statements under Section 137 or its annual return under Section 92. A company comfortably under both thresholds that filed its AOC-4 or MGT-7 late can therefore find the exemption unavailable — a link between routine ROC filing discipline and audit scope that is rarely anticipated at the time the filing is missed. If you are working out whether the reporting requirement reaches you at all, this decision tree walks the test limb by limb.

IFC or IFCoFR — the distinction that sets the scope

The two terms are used loosely and mean different things, which matters because they define who is answerable for what.

The Explanation to s.134(5)(e) defines internal financial controls broadly: the policies and procedures for the orderly and efficient conduct of business, adherence to company policies, safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information. That is the board’s responsibility, and it reaches into operations and compliance.

s.143(3)(i), as it now stands, requires the auditor to report on internal financial controls with reference to financial statements — the reporting subset usually called IFCoFR. So the auditor’s report is narrower than the board’s duty. A clean audit report on IFCoFR is not a statement that the company’s controls over operations or legal compliance are adequate, and it should not be read as one.

What an IFC engagement actually involves

  • Scoping — identifying material account balances and the processes that feed them, so effort goes where misstatement risk actually is rather than across every process equally.
  • Process documentation — narratives or flowcharts for each significant cycle: revenue and receivables, procurement and payables, payroll, inventory, fixed assets, treasury, and the financial close.
  • Risk and control matrix (RCM) — for each risk, the control that addresses it, whether it is preventive or detective, manual or automated, and who performs it.
  • Design and implementation assessment — walkthroughs confirming the control as described exists and would address the risk.
  • Operating effectiveness testing — sample-based testing across the period, since a control that worked in March but not the rest of the year is not operating effectively.
  • Deficiency evaluation and remediation — classifying what is found, and setting out what to fix and in what order.

IT general controls — where systems meet the audit

Where accounting is produced by a system, the reliability of the records depends on the controls around that system. These are examined under four heads:

AreaThe question being answered
Access to programs and dataWho can log in, who can post and approve, are privileged and ex-employee accounts controlled, is segregation of duties real or only on paper
Change managementHow changes and customisations are requested, approved, tested and moved to production
Program developmentHow new systems or major modules are implemented and data is migrated
Computer operationsJob scheduling, backups, restoration testing, incident handling

Alongside these sit application controls — the configured checks inside the accounting or ERP system: approval limits, three-way matching, duplicate-invoice blocks, credit limits, and the integrity of system-generated reports relied on during the audit. A recurring finding in smaller companies is an audit trail that can be disabled, or a shared administrator login that makes it impossible to attribute an entry to a person.

Internal audit under Section 138

Separate from IFC reporting, Section 138 with Rule 13 of the Companies (Accounts) Rules 2014 requires an internal audit function for:

CompanyThreshold (any one)
ListedAlways applicable
Unlisted publicPaid-up capital ≥ ₹50 crore · turnover ≥ ₹200 crore · borrowings from banks or public financial institutions > ₹100 crore at any point in the preceding year · outstanding deposits ≥ ₹25 crore
PrivateTurnover ≥ ₹200 crore · borrowings from banks or public financial institutions > ₹100 crore at any point in the preceding year

What’s covered

  • IFC documentation — process narratives, flowcharts and risk and control matrices built from how your business actually runs, not from a template.
  • IFC testing — design, implementation and operating effectiveness testing, with a deficiency register and remediation plan.
  • IT general controls review — access, change management, operations and backup controls around the accounting system.
  • Application and ERP controls review — configuration, approval workflows, segregation of duties and audit-trail integrity in Tally, Zoho, SAP, Oracle, NetSuite or a custom system.
  • Internal audit of IT-dependent processes — scoped reviews under Section 138 where applicable, or voluntarily where management wants assurance.
  • Pre-audit readiness — putting controls and evidence in order before the statutory auditor arrives, so IFC reporting does not become a year-end scramble.

Who this is for

Companies crossing the s.143(3)(i) thresholds for the first time and finding IFC reporting newly in scope; companies whose exemption has lapsed through a late ROC filing; businesses migrating to or upgrading an ERP, where controls need designing into the new system rather than retrofitting; and boards that want an independent view of whether the controls they are certifying actually operate. It sits alongside statutory and internal audit, and assumes the underlying books are in place.

What to send first

Your entity type and shareholding, latest audited turnover and borrowings, the accounting or ERP system in use and roughly how many people use it, and whether your auditor has already raised IFC reporting. From that, what applies to you — and what does not — is set out plainly before any engagement is scoped.

Frequently asked questions

Is IFC applicable to private limited companies?

The obligation to maintain internal financial controls applies to every company. What the exemption removes is the auditor's separate reporting obligation under Section 143(3)(i). Under the MCA notification of 13 June 2017, a private company is outside that reporting requirement if it is a one person company or a small company, or its turnover is less than ₹50 crore as per the latest audited financial statement, or its aggregate borrowings from banks, financial institutions or any body corporate at any point during the financial year are less than ₹25 crore — but only if it has not defaulted in filing its financial statements under Section 137 or its annual return under Section 92.

We are exempt from IFC reporting. Do we still need internal financial controls?

Yes. The exemption is from the auditor's reporting requirement, not from the underlying obligation. The Board's report must still disclose the adequacy of internal financial controls with reference to the financial statements, and directors remain answerable for them. An exempt company with no documented controls is not compliant — it is simply not being separately reported on.

What is the difference between IFC and IFCoFR?

Internal financial controls, as defined in the Explanation to Section 134(5)(e), is the broader concept — orderly and efficient conduct of business, safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information. Section 143(3)(i) narrows the auditor's reporting to controls with reference to financial statements, which is the reporting subset commonly called IFCoFR. The board's responsibility is wider than what the auditor reports on.

When does internal audit become mandatory under Section 138?

Under Rule 13 of the Companies (Accounts) Rules 2014, internal audit applies to every listed company; to unlisted public companies crossing paid-up capital of ₹50 crore, turnover of ₹200 crore, borrowings from banks or public financial institutions above ₹100 crore at any point in the preceding financial year, or outstanding deposits of ₹25 crore; and to private companies with turnover of ₹200 crore or more, or borrowings above ₹100 crore at any point in the preceding financial year.

What are IT general controls and why do auditors ask about them?

IT general controls are the controls around the systems that produce your accounting records — who can access them, how changes to the software are approved and moved to production, how backups and recovery are handled, and how the system is operated day to day. If those are weak, the reports the system produces cannot be relied upon, which is why they are examined as part of controls testing wherever accounting is system-dependent.

Can this be done remotely?

A large part of it can. Documentation review, process walkthroughs by video call, system configuration review and evidence gathering are handled online. Where physical verification or access to on-premise systems is required, that part is planned around your location.

Need internal financial controls documented or tested?

Send a note on your entity type, turnover and the accounting system in use. What actually applies to you — and what does not — is set out before any engagement is scoped.