CORAA
Resources · Internal Audit RCM

Internal audit control repository.

A control repository is the source library behind an internal audit RCM. It records the process risk, expected control, test procedure and evidence requirement before the auditor tailors it to the entity, cycle, ERP and approved SOW.

Build RCM in Excel/PDFInternal audit resource hub
Repository structure

The fields worth standardising fields

Keep the repository granular enough to become a workpaper, but not so granular that every entity becomes a copy-paste exercise. These fields allow one library row to become an RCM row, a monitoring rule, an observation and an ATR item.

Process cycle and sub-process
Risk statement and risk rating
Control objective and assertion
Preventive / detective classification
Manual, automated or IT-dependent control type
Control owner and frequency
Test procedure and sample basis
Evidence source and IPE check
Result, exception count and reviewer conclusion
Observation, management response and ATR status
Cycle map

Core controls by internal audit cycle controls

Use this as the first draft of the repository. The internal auditor should then remove irrelevant controls, split broad rows, add entity-specific control owners and map each test to the actual ERP report or source document.

P2P

Procure to Pay

Risks
  • Fictitious or duplicate vendors
  • Purchases without approved PO
  • GRN-invoice mismatch
  • Delayed MSME payments
Controls
  • Vendor creation approval and maker-checker review
  • PO approval against delegation matrix
  • Three-way match before payment
  • MSME ageing and due-date monitoring
Evidence

Vendor master change log, PO approval report, GRN, supplier invoice, payment run and MSME ageing.

O2C

Order to Cash

Risks
  • Unauthorised customer credit
  • Revenue recorded before dispatch/service
  • Credit notes used to suppress collections
  • Receivables ageing not followed up
Controls
  • Credit limit approval and override review
  • Dispatch/service proof matched to invoice
  • Credit note approval and reason-code review
  • Ageing review with collection owner
Evidence

Customer master, credit approval, sales order, dispatch proof, invoice register, credit note register and ageing.

R2R

Record to Report

Risks
  • Unauthorised manual journals
  • Late close adjustments
  • Unreconciled control accounts
  • Unsupported provisions
Controls
  • Journal approval with preparer-reviewer trail
  • Close calendar ownership
  • Balance-sheet reconciliation review
  • Provision basis approval
Evidence

Journal listing, approval workflow, close checklist, reconciliation file, provision workings and reviewer notes.

H2R

Hire to Retire / Payroll

Risks
  • Ghost employees
  • Unauthorised salary changes
  • Attendance-payroll mismatch
  • Incomplete exit recovery
Controls
  • Employee master maker-checker
  • Salary revision approval
  • Attendance exception review
  • Full-and-final checklist and access removal
Evidence

HR master, offer letter, attendance report, payroll register, bank file, PF/ESI challans and exit clearance.

CB

Cash and Bank

Risks
  • Unauthorised bank accounts
  • Stale BRS items
  • Payments outside mandate
  • Petty cash leakage
Controls
  • Bank master approval
  • Monthly BRS ageing review
  • Payment maker-checker and mandate match
  • Petty cash surprise count
Evidence

Bank master, bank statements, BRS, payment approvals, cheque/online mandate and cash count sheet.

INV

Inventory

Risks
  • Unrecorded receipts/issues
  • Stock shrinkage
  • Obsolete stock not provided
  • Valuation errors
Controls
  • GRN matched to purchase records
  • Stock issue authorisation
  • Physical count reconciliation
  • Ageing and NRV review
Evidence

GRN, stock ledger, issue slips, count sheets, variance approval, ageing report and valuation working.

FA

Fixed Assets

Risks
  • Capex booked without approval
  • CWIP not capitalised on time
  • Missing asset tagging
  • Incorrect depreciation
Controls
  • Capex approval against budget
  • CWIP ageing review
  • Physical tagging and verification
  • Depreciation method/useful-life review
Evidence

Capex note, vendor invoice, CWIP register, fixed asset register, physical verification file and depreciation working.

TRE

Treasury

Risks
  • Borrowing covenant breach
  • Unauthorised investments
  • Idle surplus funds
  • Forex exposure not monitored
Controls
  • Loan covenant tracker review
  • Investment approval matrix
  • Cash forecast review
  • Forex exposure register and hedging approval
Evidence

Sanction letters, covenant workings, investment file, bank balances, cash forecast, forex exposure register and board approvals.

SC

Statutory Compliance

Risks
  • GST/TDS/ROC defaults
  • Notices not tracked
  • Compliance ownership unclear
  • Late interest/penalty exposure
Controls
  • Compliance calendar ownership
  • Return-to-ledger reconciliation
  • Notice register review
  • Exception ageing and escalation
Evidence

Compliance calendar, challans, returns, reconciliations, notice register, legal updates and management sign-off.

ITGC

IT General Controls

Risks
  • Inappropriate system access
  • Weak change management
  • Backup failure
  • ERP configuration changes without approval
Controls
  • User access review
  • Privileged access monitoring
  • Change request approval
  • Backup and restoration evidence review
Evidence

User list, role matrix, access review sign-off, change tickets, deployment approval, backup logs and restoration evidence.

Downloads and tools

Turn the repository into workpapers workpapers

Internal Audit RCM Builder

Generate an editable Excel/PDF RCM across core cycles.

Open ->
Internal Audit Risk Scorer

Prioritise the audit universe before building the control repository.

Open ->
Internal Audit Monitoring Rules

Convert recurring controls into exception rules and reviewer conclusions.

Open ->
Internal Audit SOW Generator

Turn the approved repository scope into engagement terms and a data request list.

Open ->
Internal Audit Report Format

Report observations, ratings, management responses and follow-up requirements.

Open ->
Action Taken Report Tracker

Track closure evidence, revised dates, owners and repeat observations.

Open ->
Standards anchor

What makes the repository defensible defensible

Section 138 and Rule 13

Section 138 creates the internal-audit requirement for prescribed companies. Rule 13(2) requires the Audit Committee or Board, in consultation with the internal auditor, to formulate scope, functioning, periodicity and methodology. The repository should therefore connect every control row back to approved scope and cadence.

Open source ->
ICAI Standards on Internal Audit

ICAI's February 2026 Compendium of Standards on Internal Audit applies from 1 April 2026. The repository should support SIA 220/310 planning, SIA 320 evidence, SIA 330 documentation, SIA 350 review, SIA 370 reporting and SIA 390 follow-up.

Open source ->
FAQ

Control repository FAQs questions

What is an internal audit control repository?

An internal audit control repository is the reusable library of process risks, control objectives, control activities, test procedures, evidence requirements and reviewer conclusions used to build engagement-level RCMs.

Is a control repository the same as an RCM?

No. The repository is the reusable source library. The RCM is the engagement-specific extract after the auditor selects cycles, tailors controls, adds entity owners and records testing results.

Which internal audit cycles should be included first?

Most Indian finance-led internal audit plans start with P2P, O2C, R2R, cash and bank, payroll/H2R, inventory, fixed assets, statutory compliance and treasury. ITGC is added wherever ERP controls affect the process evidence.

How does this connect to continuous monitoring?

The repository identifies controls worth testing. Continuous monitoring converts selected controls into recurring rules with population source, rule logic, cadence, exception owner and reviewer conclusion.