CORAA

Contract Management Internal Audit Checklist

Tests the controls around the contract lifecycle — approval authority, renewal tracking, and SLA/penalty compliance — from execution through to expiry or renewal.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Scope
Drafting → approval → execution → renewal/expiry
Key risk
Auto-renewal without review, SLA penalties not invoked
Cross-reference
Related-party contracts → Sec 188 / Ind AS 24 process
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

CONTRACT MANAGEMENT — INTERNAL AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: tests the design and operation of controls across the contract lifecycle — from drafting and approval through execution, renewal and expiry — for the population of active contracts within scope.

Conclusion

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What is the single most common contract-management control gap?
Renewal tracking. Many organisations have a reasonable approval process at the point a contract is first signed, but no systematic alert before expiry — so contracts auto-renew on unfavourable terms, or lapse without a replacement being in place, simply because nobody was tracking the date.
Why test SLA/penalty monitoring separately from contract approval?
A well-approved contract with strong penalty clauses is only valuable if those clauses are actually monitored and invoked. It is common to find contracts where a vendor has repeatedly missed service levels but no penalty was ever claimed, because performance tracking was never operationalised after signature — a separate control point from getting the contract terms right in the first place.
How does this checklist relate to the related-party transactions checklist?
This checklist tests the general contract lifecycle for ALL contracts; the related-party transactions checklist tests the SPECIFIC additional approval and disclosure process (Sec 188, Rule 15(3) thresholds, AOC-2/3CD reporting) that applies only when the counterparty is a related party. A related-party contract should pass both tests, not just the general one.
Related templates

You might also need.

Related Party Transactions Internal Audit Checklist
Free related party transactions internal audit checklist. Tests identification, board approval, Rule 15(3) thr
Vendor Management Internal Audit Checklist
Free vendor management internal audit checklist. Tests vendor onboarding KYC, master data controls, price appr
Standard Operating Procedure (SOP) Review Checklist
Free SOP review checklist for internal audit. Tests SOP existence, approval, version control, communication an