CORAA
Blog/Internal Audit

Audit Committee Questions to Ask Internal Audit (2026): 17 Questions and What a Good Answer Sounds Like

Audit committee questions to ask internal audit in 2026: seventeen questions on plan and coverage, independence, findings and closure, fraud and data, and the use of technology and AI — each with what a good answer and a weak answer sound like, and the audit committee's role under Indian law.

CCORAA Team1 October 202610 min read

The most useful audit committee questions to ask internal audit are about five things: what the plan covers and leaves out, how independent the function really is, whether findings get closed, how fraud and data are handled, and how technology and AI are being used. A good answer in each area is specific — a number, a name, a date. A weak one is a general reassurance.

This guide gives seventeen questions for an audit committee member or independent director to put to the head of internal audit in FY 2026-27. It starts with the committee's footing in law, because that is what gives the questions their weight.

If you want the working file rather than the explanation, start here:

Need Use this
What the internal audit papers for a committee meeting should contain Internal Audit Audit Committee Reporting Pack
A tracker of observations, management responses, owners and ageing Internal Audit ATR Tracker
Management's own scored check of finance controls, to compare with internal audit's view Finance Controls Health Check
Whether the company is required to have an internal auditor at all Internal Audit Applicability Checker

The audit committee's role in internal audit in India

Three provisions matter.

Section 177 of the Companies Act, 2013 requires the Board of every listed company, and of prescribed classes of public companies, to constitute an audit committee. The prescribed classes are public companies with paid-up share capital of ₹10 crore or more, turnover of ₹100 crore or more, or aggregate outstanding loans, borrowings, debentures or deposits exceeding ₹50 crore. Among its functions, the committee may call for the auditors' comments on internal control systems, review the scope of audit, discuss issues with the internal and statutory auditors and management, and has full access to the company's records to investigate a matter.

Section 138, with Rule 13 of the Companies (Accounts) Rules, 2014, requires prescribed classes of companies to appoint an internal auditor. Rule 13 also says who sets the terms: the audit committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit. The plan is therefore the committee's document, not management's. Section 138 has no rotation or cooling-off clause for the internal auditor of the kind that applies to the statutory auditor, and the internal auditor may be an employee or an outside firm — which makes the committee's oversight the main protection of independence.

For listed entities, Regulation 18 of the SEBI (LODR) Regulations, 2015 sets the committee's composition: at least three directors, at least two-thirds of them independent, all financially literate and at least one with accounting or financial management expertise, chaired by an independent director. The committee must meet at least four times a year, with no more than 120 days between meetings. The role it refers to, in Part C of Schedule II, includes reviewing the adequacy of the internal audit function — its structure, staffing and the seniority of the person heading it — reviewing internal audit reports on internal control weaknesses, and reviewing the appointment, removal and remuneration of the chief internal auditor. Check the current text of the regulations before quoting them in board papers.

None of these prescribes a list of questions. What follows is practice, not law.

Plan and coverage

# Question A good answer sounds like A weak answer sounds like
1 What did this year's plan leave out, and why? A named list of processes, entities and locations not covered, with the reason for each and the year each was last audited "The plan is risk-based and covers all key areas"
2 What has changed in the business since we approved the plan, and has the plan changed with it? Specific events — a new ERP, an acquisition, a new line of business — and the reviews added, deferred or dropped as a result, brought to the committee for approval "The plan is on track"
3 How much of the plan is complete, and what was deferred at whose request? Reviews completed, in progress and deferred, with who asked for each deferral A completion percentage with nothing behind it
4 Which subsidiaries, branches and outsourced activities have not been visited in the last three years? A list. In a group, coverage shown by entity, not only by process "We cover the group on a rotational basis"

Independence and resourcing

# Question A good answer sounds like A weak answer sounds like
5 Who decides your appraisal, pay and budget — and who could remove you? A clear line to the committee on appointment, removal and remuneration, with the administrative line to management described honestly "I report to the CFO, but it has never been a problem"
6 Has anyone restricted your scope, delayed access to records or people, or asked you to soften a finding this year? Either a plain "no", or the instances — what was withheld, by whom, and what was done instead Hesitation, or "nothing significant"
7 Does the team have the skills for this plan? What did you buy in, and what could you not cover? The areas where the team is thin — IT, tax, treasury, data — who was brought in, and what remains uncovered "The team is adequately staffed"

Questions 5 and 6 are best asked in a private session without management present. If the committee does not hold one at least once a year, that is the first thing to fix.

Findings and closure

# Question A good answer sounds like A weak answer sounds like
8 Which findings this period are repeats, and why did the earlier fix not hold? A count of repeat findings, the process and owner for each, and the reason — the fix was never made, or it treated the symptom "Some observations are recurring in nature"
9 How many agreed actions are overdue, how old is the oldest, and whose are they? Overdue actions by age band and by owner, with original and revised dates shown side by side A total of open points with no ageing
10 When an action is marked closed, what did you check? High-rated items re-tested, with evidence seen; lower items closed on documents; the number reopened after testing "Management confirmed closure"
11 Where has management accepted a risk rather than fix it, and who signed that off? A short list, each with the person who accepted it, their authority to do so, and a review date "Management has noted the observation"

Fraud and data

# Question A good answer sounds like A weak answer sounds like
12 What suspected fraud or misconduct came to your notice this year — including through the whistle-blower channel — and how did each end? A number, a one-line description of each, the outcome, and the control change that followed "No material frauds were reported"
13 Where could a senior person override a control, and how would we find out? Specific points — manual journals, vendor creation, payment release, credit notes — and the review that covers each "Controls are in place and operating"
14 For which areas did you test every transaction, and for which a sample? How do you know the data was complete? Areas tested in full and those sampled, with the reason; how the extract was agreed to the books before testing "We use data analytics extensively"

Use of technology and AI

# Question A good answer sounds like A weak answer sounds like
15 Where does management run its own ongoing checks on transactions, and how do you rely on them? Which exceptions management monitors, who owns closure, and what internal audit did to test the rules, the data and the closures before relying on them "Management has a dashboard"
16 Is the internal audit team using AI tools? For what, and who reviews the output? Named uses — drafting, summarising, structuring working papers — with a reviewer for every output, and a plain statement that the auditor remains responsible for evidence and conclusions "We are exploring AI", or "AI does our testing"
17 What company, customer or employee data goes into those tools, and who approved that? A written rule on what may be uploaded, the tool's data-use and retention settings checked, and no personal or confidential data in consumer tools without authority "The team uses whatever is convenient"

On question 16: general AI tools draft, summarise and structure well, but they do not test a population and they can state things that are wrong with confidence. Be more worried by an internal auditor who claims too much for them than by one who uses them cautiously. See the internal audit AI strategy guide.

Question 15 matters because management's monitoring and internal audit are different things; the difference is explained in internal audit vs continuous monitoring vs MIS.

What a good answer looks like on paper

Questions 8 to 10 should not need to be asked aloud; the answer should be in the pre-read. An illustrative closure summary for one quarter:

Rating Open at start Raised Closed and re-tested Open at end Of which overdue Oldest overdue Repeat findings
High 4 2 3 3 1 75 days 1
Medium 11 6 7 10 4 140 days 2
Low 9 5 8 6 2 60 days 0
Total 24 13 18 19 7 3

With this in front of it, the committee can go straight to what matters: the high-rated item 75 days overdue, the medium item at 140 days, and the three repeats. The ATR tracker produces the underlying list.

How to use the questions

  • Pick five, not seventeen. Choose the ones the pre-read does not already answer.
  • Ask for the list, not the assurance. "Which entities?" gets a better answer than "Are all entities covered?"
  • Ask the same question of two people. Put question 6 to the head of internal audit privately, and ask the CFO whether internal audit had everything it asked for.
  • Compare views. Where management's own health check scores an area as strong and internal audit rates it weak, ask both to explain the gap.
  • Minute the answer and the follow-up, with an owner and a date, and look at it first at the next meeting.

Audit committee and internal audit FAQ

What questions should an audit committee ask internal audit in 2026?

Ask what the plan leaves out, whether anyone restricted the auditor's access, which findings are repeats, how many agreed actions are overdue and how closure was verified, what fraud came to notice, and how the team uses data and AI. In each case ask for the list, the owner and the date rather than a general assurance.

What is the role of the audit committee in internal audit in India?

Under Rule 13 of the Companies (Accounts) Rules, 2014, the audit committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit. Under Section 177 the committee may call for auditors' comments on internal control systems and discuss issues with the internal auditor. For listed entities, SEBI's listing regulations add review of the function's adequacy and of internal audit reports.

Does the internal auditor report to the audit committee or to management?

The internal auditor reports on the results of the audit to the audit committee or Board, which sets its scope. Day-to-day administration often sits with management. For listed entities, the listing regulations provide that the internal auditor may report directly to the audit committee, and that the committee reviews the appointment, removal and remuneration of the chief internal auditor.

How often should the audit committee meet the internal auditor?

For a listed entity the committee must meet at least four times a year with no more than 120 days between meetings, and internal audit is normally on each agenda. Other companies set their own frequency. A private session with the head of internal audit, without management, at least once a year is good practice.

Which companies must have an audit committee?

Every listed company, and public companies with paid-up share capital of ₹10 crore or more, turnover of ₹100 crore or more, or aggregate outstanding loans, borrowings, debentures or deposits exceeding ₹50 crore. Where there is no audit committee, the Board performs the role in relation to internal audit under Rule 13.

Sources

  • Companies Act, 2013 — Sections 138 and 177, Ministry of Corporate Affairs
  • Companies (Accounts) Rules, 2014 — Rule 13; Companies (Meetings of Board and its Powers) Rules, 2014, for the classes of companies required to constitute an audit committee
  • SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 — Regulation 18 and Part C of Schedule II; verify the current text on sebi.gov.in before relying on it
Topics
audit committee questions to ask internal auditaudit committee role in internal audit Indiaaudit committee questions 2026questions for head of internal auditindependent director internal audit questionsaudit committee internal audit oversightSection 177 audit committee internal audit
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free