Internal audit in 2026 has the same legal basis it had before: Section 138 of the Companies Act still decides who must appoint an internal auditor, and the audit committee or Board still sets the scope. What has changed is around it: the standards have been reissued and renumbered, audit committees ask for more than a list of observations, full-population testing is practical where the data exists, AI tools are in everyday use, and personal data now carries legal duties of its own.
This guide sets out each change in plain words and ends with a checklist for this quarter. It is for heads of internal audit, in-house internal auditors and CA firms doing internal audit engagements in FY 2026-27.
If you want the working files first, start here:
| Need | Use this |
|---|---|
| This year's risk areas to consider for the plan | Internal audit priority risk areas 2026 |
| The annual plan, scored and ready for approval | Annual Plan Generator |
| What the audit committee should receive each quarter | Audit committee reporting pack |
| A written rule for AI use in the function | Internal Audit AI Strategy Template |
1. The standards picture
ICAI's Standards on Internal Audit: two numbering sets
Indian internal audit runs on the Standards on Internal Audit (SIA) issued by ICAI's Internal Audit Standards Board. There are now two sets in circulation, and anyone citing an SIA number needs to know which one is meant.
The earlier set, as compiled in the October 2022 compendium, has nineteen standards numbered in a 100 to 500 series. The ones most often quoted are SIA 220 on overall planning, SIA 310 on assignment planning, SIA 320 on evidence, SIA 330 on documentation, SIA 350 on review and supervision, SIA 370 (Reporting Results) and SIA 390 (Monitoring and Reporting of Prior Audit Issues). Five older standards sit alongside under their original numbers, including SIA 5 (Sampling) and SIA 11 (Consideration of Fraud in an Internal Audit).
The revised set, issued by the Board during 2025-26 and compiled in its February 2026 compendium, has two quality standards (QSIA 1 and QSIA 2) and SIAs in three series: 100 for core concepts and principles, 200 for audit execution, and 300 for reporting. ICAI lists that compendium as applicable from 1 April 2026, so this is the current set.
The numbers overlap, and the titles do not:
| Number | Title in the earlier set | Title in the revised set |
|---|---|---|
| SIA 110 | Nature of Assurance | Basic Principles of Internal Audit |
| SIA 230 | Objectives of Internal Audit | Internal Audit Evidence |
| SIA 310 | Planning the Internal Audit Assignment | Presentation and Communication of Internal Audit Report |
| SIA 320 | Internal Audit Evidence | Issuing Assurance Reports |
| SIA 330 | Internal Audit Documentation | Special Purpose Reports |
So "SIA 320" in a methodology note written in 2023 means evidence, and in the revised list it means assurance reports.
Three cautions.
- We have verified the titles of the revised set, not its text. For what a revised standard requires, read the ICAI Internal Audit Standards Board compendium.
- The revised set applies from 1 April 2026, but "applicable" is not the same as "mandatory". ICAI's Internal Audit Standards Board lists the February 2026 compendium on its compendium page as applicable from 1 April 2026 (checked on 1 October 2026). That page does not say whether the standards are mandatory or recommendatory, and the Board's annual report described the revised standards as recommendatory at present. So do not write "mandatory" in a report, charter or engagement letter on the strength of the date alone.
- Do not confuse SIA with ISAS. ICAI's Information Systems Audit Standards come from a different board. See ICAI ISAS explained.
What to do: write the standard's title and the compendium edition next to every SIA number in your methodology and report templates, and state that the audit was conducted in accordance with the SIAs only if you can substantiate it. The methodology map is a place to record which edition you follow.
The IIA's Global Internal Audit Standards
The Institute of Internal Auditors replaced its International Professional Practices Framework with the Global Internal Audit Standards, effective 9 January 2025. Several documents became one, arranged in five domains: Purpose of Internal Auditing; Ethics and Professionalism; Governing the Internal Audit Function; Managing the Internal Audit Function; and Performing Internal Audit Services. Under these are fifteen principles and fifty-two standards. The IIA also issues Topical Requirements under the new structure; check the IIA's site for the current list.
These are not Indian law. They bind functions that have committed to them, usually through the internal audit charter. If your charter says the function follows the IIA standards, it should now refer to the Global Internal Audit Standards. The internal audit charter guide covers the wording, and the IIA's 2020 Three Lines Model is set out in the three lines assurance map.
2. What the audit committee now expects
The committee's legal role is unchanged. Under Rule 13 of the Companies (Accounts) Rules, 2014, the audit committee or Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of internal audit. Under Section 177 it may call for the auditors' comments on internal control systems. For listed entities, the SEBI listing regulations add that the committee reviews the adequacy of the internal audit function, including its structure, staffing and the seniority of its head, and reviews internal audit reports on control weaknesses. The statutory auditor, under CARO 2020, reports whether the internal audit system is commensurate with the company's size and business.
What has shifted is what a good committee asks for within that role:
- A coverage statement. What was audited, what was not, and by what method.
- Cause, not only instances. Why the control failed, and whether one cause sits behind several findings.
- Closure with evidence. Whether "closed" items were validated by internal audit or only reported closed by management.
- Technology and AI. What tools the function uses, on what data, and who reviews the output.
- Regular reporting. A periodic report on all internal audit activity, normally quarterly, in addition to each assignment report.
The questions a committee can put are in audit committee questions for internal audit.
3. Every transaction instead of a sample, where the data allows
The default used to be a sample, because checking everything by hand was impossible. Where transactions sit in Tally or an ERP and export cleanly, a defined test can now run across all of them: duplicates, approvals above limit, payments after a bank-detail change.
A test on data covers only what can be written as a rule. A reconciliation that was signed but not done, an override by a senior person and a contract awarded without quotations leave little or no trail, and those still need inspection, inquiry and judgment. Full coverage of transactions is not full coverage of risk.
The earlier SIA 320 on evidence leaves the technique for gathering it outside its scope, and sampling has its own standard, SIA 5. The choice is the auditor's, and it should be documented.
A coverage statement makes the choice visible. An illustrative one for a procure-to-pay audit:
| Area | Method | Population | Covered |
|---|---|---|---|
| Duplicate vendor invoices | Defined test on every invoice | 18,400 invoices | All |
| Payments after change of vendor bank details | Defined test on every payment | 212 changes | All |
| Purchase orders approved within delegated limits | Defined test where approval is recorded in the system; sample for manual approvals | 6,300 orders | 5,100 in full; 25 of 1,200 manual approvals sampled |
| Quotation and tendering for contracts above limit | Inspection of each file | 14 contracts | All |
If the approved plan assumed sampling and you move to full-population tests, tell the committee: methodology is theirs to settle. More in continuous internal audit and full-population testing and internal audit vs continuous monitoring vs MIS.
4. AI assistance and its limits
Internal auditors now use chat assistants such as ChatGPT and Claude to draft RCMs, walkthrough questions, observations and committee summaries. That saves drafting time. The tools do not test a population, they can invent a section number or a threshold, and nothing they write is evidence.
Two things follow for 2026. The function needs a short written rule on permitted uses, data that never goes in and review of AI-assisted work. And the working paper should show where AI assisted and what was verified. The revised SIA list includes a standard titled "Use of Tools"; we have not verified its text, so check the compendium.
Reviewing how the rest of the company uses AI is a separate job; for that, see the AI governance internal audit workpaper and the AI-enabled fraud checklist.
The detail is in three companion guides: AI in internal audit 2026, ChatGPT for internal audit and Claude for internal audit. The governance side is in the internal audit AI strategy guide.
5. Regulated sectors carry a stricter layer
For a bank, an NBFC, a broker or an insurer, the Companies Act is the floor. RBI, SEBI and IRDAI each set a more specific framework and revise it more often. Treat what follows as orientation and read the current direction or circular before relying on it.
Banks, NBFCs and urban co-operative banks. The Reserve Bank of India has required risk-based internal audit in scheduled commercial banks (other than regional rural banks) since 2002. In 2021 it extended the framework to all deposit-taking NBFCs, to non-deposit-taking NBFCs (including core investment companies) with asset size of ₹5,000 crore and above, and to primary urban co-operative banks with asset size of ₹500 crore and above. The framework expects periodic risk assessment of each auditable unit, a plan approved by the Audit Committee of the Board (or the Board, where there is no such committee), and a function with independence, authority and competent resources. RBI has continued to reissue and consolidate these requirements, so confirm the current direction for your category of entity. Concurrent audit in banks, which examines transactions at selected branches close to the time they happen, is a separate exercise and does not replace it. For NBFCs, see our note on the NBFC Internal Audit Function Directions 2026 and the NBFC internal audit checklist.
Market intermediaries. SEBI sets internal audit requirements by type of intermediary. Stock brokers and clearing members have a half-yearly internal audit by an independent practising chartered accountant, company secretary or cost accountant, and the report goes on to the stock exchange with management's comments. Research analysts and investment advisers have an annual compliance audit. Market infrastructure institutions have an annual internal audit across their functions. Frequencies and eligibility are amended from time to time; check the current master circular.
Listed companies generally. The obligation to have an internal auditor comes from the Companies Act. The SEBI listing regulations deal with the audit committee's oversight of that function, not with a separate mandate.
6. Data protection
Internal audit files hold payroll, customer lists and vendor bank details. Under the Digital Personal Data Protection Act, 2023 and its rules, whoever decides why and how personal data is used carries duties for its security and retention, and remains responsible when a vendor or a tool processes it. The obligations are being phased in, with dates set out in DPDP for CA firms.
For the function:
- Take less. A duplicate-payment test does not need a vendor's PAN.
- Hold it properly. Know where audit data sits, who can open it and when it is deleted.
- Add it to the plan. How the company itself handles personal data is an auditable area. The data governance and master data controls guide is a starting point.
What to do this quarter
- Write the standard title and compendium edition beside every SIA number in your methodology, report template and engagement letters, after checking the current status on the ICAI compendium page.
- If your charter refers to the IIA's framework, update the reference to the Global Internal Audit Standards.
- Add a coverage statement to the next report: what was tested in full, what was sampled, what was not covered.
- Pick one process with clean data and run three defined tests from the monitoring rules library across every transaction. Reconcile the data first.
- Put a one-page AI rule in place, tell the committee what it says, and record AI assistance in working papers.
- Separate "closed by management" from "closure validated by internal audit" in the ATR tracker.
- For a regulated entity, confirm the current RBI, SEBI or IRDAI text that applies and the date of the version relied on.
- Review what personal data the audit team requests and holds, and cut what is not needed.
- Refresh the plan against this year's risk areas with the dynamic risk assessment guide.
Every item on this list can be done with the free files linked above; teams that want testing, observations and follow-up in one system can look at CORAA's internal audit product.
Internal audit in 2026 FAQ
What has changed in internal audit in 2026?
The law on who must appoint an internal auditor has not changed. The standards have (a revised ICAI SIA set and the IIA's Global Internal Audit Standards), along with audit committee expectations, the practicality of testing every transaction, routine use of AI for drafting, and data protection duties.
Are the new Standards on Internal Audit mandatory in 2026?
ICAI's Internal Audit Standards Board lists the revised standards, in its February 2026 compendium, as applicable from 1 April 2026 (compendium page checked on 1 October 2026). That page does not say whether they are mandatory or recommendatory, and the Board's annual report described them as recommendatory at present. Treat them as the current set, and check with ICAI before describing them as mandatory in a report.
Is internal audit mandatory for all companies in FY 2026-27?
No. It is required for every listed company, for unlisted public companies crossing any of the paid-up capital, turnover, borrowing or deposit limits in Rule 13, and for private companies crossing the turnover or borrowing limits. The applicability checker runs the test.
Will AI replace internal audit?
No. AI drafts documents and makes full-population testing practical, but it does not hold walkthroughs, establish cause, judge an explanation or take responsibility for a conclusion. The work shifts towards design, cause and the areas with no data trail.
Related CORAA resources
- AI in internal audit 2026: the stage-by-stage guide
- ChatGPT for internal audit: prompts, uses and limits
- Claude for internal audit: Projects, prompts and workflow
- Internal audit priority risk areas 2026
- Internal audit report format: observations, ATR and audit committee reporting
Sources
- Companies Act, 2013 — Sections 138 and 177, Ministry of Corporate Affairs
- Companies (Accounts) Rules, 2014 — Rule 13, on the classes of companies required to appoint an internal auditor and on scope, functioning, periodicity and methodology
- ICAI Internal Audit Standards Board — Compendium of Standards on Internal Audit
- The Institute of Internal Auditors — Global Internal Audit Standards