CORAA
Internal Audit · SIA-aligned

Internal audit that runs on a cadence, not once a year.

One Risk & Control Matrix — process, sub-process, risk, control, test, result — across eight process cycles, tested on a cadence you set during onboarding. Every test, observation, management response and follow-up action rolls up live into a SIA 370 report, instead of being assembled by hand a week before the deadline.

The Risk & Control Matrix

One taxonomy, every control on it.

Every engagement is built on the same structure SIA 220 and SIA 310 already expect: a process cycle breaks into sub-processes, each sub-process carries a rated risk, each risk is met by a control with a named objective, each control has a test, each test has a result, and a failed result can become an observation that flows into the report. CORAA seeds this from a pack library at engagement creation — the auditor’s confirm-or-edit is what makes a row authoritative, not the seed.

Process cycle → sub-process, mapped to how the entity actually operates
Risk, rated High / Medium / Low against that sub-process
Control, typed Preventive or Detective, and Manual / Automated / IT-dependent
Control objective, in the same assertion vocabulary as statutory testing — Existence, Validity, Occurrence, Accuracy, Completeness, Authorisation, Valuation, Compliance
Test, with pre-wired links to real Transaction Scrutiny rules and JE Analysis detectors where one exists — an honest blank where it doesn’t
Result and rating, carried straight into the report’s executive summary
Eight process cycles

Every cycle a business runs on audited, not just booked.

Eight process cycles ship as standard. The cadences below are illustrative starting references, not fixed rules — the actual review frequency for each cycle is calibrated with the internal audit team during onboarding, the same way SIA 310 expects planning to be tailored to the entity rather than templated.

P2P
Procure-to-Pay
Duplicate or fictitious vendors, unapproved purchases, goods paid for but not received.
Weekly review · illustrative
O2C
Order-to-Cash
Unauthorised credit exposure, revenue cut-off manipulation, invoices that don’t reconcile to dispatch.
Weekly review · illustrative
R2R
Record-to-Report
Unauthorised or erroneous journal entries, period-close manipulation, unreconciled control accounts.
Monthly review · illustrative
H2R
Payroll
Ghost employees, unauthorised payroll changes, PF/ESI/PT/TDS default, unrecovered exit dues.
Monthly review · illustrative
INV
Inventory
Stock shrinkage or pilferage, obsolete stock not provided for, GRN-to-stock mismatches.
Monthly review · illustrative
TRE
Treasury
Unauthorised borrowing or investment decisions, covenant breach, idle surplus funds.
Monthly review · illustrative
FA
Fixed Assets
Unauthorised capex, misclassified revenue-vs-capital spend, wrong depreciation basis.
Quarterly review · illustrative
SC
Statutory Compliance
GST/TDS/TCS default, ROC filing gaps, related-party disclosure gaps.
Monthly review · illustrative
Two ways to run it

A dated report, or a live health view.

An entity’s internal audit plan can run either engagement type, or both together — a fieldwork engagement for the dated report a board or audit committee expects, and continuous process monitors for the cycles that benefit from being watched every week instead of every quarter.

Periodic · dated report
Fieldwork engagement
A fixed-period RCM review with observations and a SIA 370 report — Planning → Fieldwork → Reporting → Follow-up → Closed. Weekly, monthly, quarterly, half-yearly or annual, under one internal audit plan (SIA 220 / SIA 310).
Ongoing · live health view
Continuous process monitor
Pick a cycle, scope the controls in and out, set a cadence, start it. Every new transaction keeps testing against the same checklist as it lands — no re-creation needed. A Command Centre rolls up clearance rate, failures, and open actions across every active monitor.
From test to report

Four ratings, one honest scale.

A control test concludes on the same four-point scale the Guidance Note on Audit of Internal Financial Controls uses, so a rating means the same thing whether an audit committee or a statutory auditor is reading it.

Effective
The control operated as designed for the period tested — no exceptions, or immaterial ones with no compensating gap.
Deficiency
A control is missing or doesn’t operate as designed, but is unlikely on its own to allow a material misstatement or loss.
Significant Deficiency
A deficiency, or combination of deficiencies, important enough to merit those charged with governance’s attention — not yet a material weakness, but close.
Material Weakness
A reasonable possibility that a material misstatement or loss won’t be prevented or detected in time. Escalates to the audit committee and, on the statutory side, threatens the Section 143(3)(i) IFC opinion.

Observations carry the five parts SIA 360/370 expect

Condition — what was actually found, with the count or sample size. Criteria — the policy, standard or law the condition falls short of. Cause — the root cause, not just “control failed.” Effect — what could go wrong because of it. Recommendation— the specific fix, addressed to a role. From a failed test, CORAA can draft this structure — condition carries the real counts from the test, the rest is a starting point the auditor edits before creating it. A management response, response owner and agreed action date then carry the observation into the SIA 390 follow-up register, where closure evidence is risk-tiered: High → re-audit procedures, Medium → documentary evidence, Low → written management confirmation.

Reporting

A SIA 370 report, rolled up live.

Every figure in the report — controls tested, observations by rating and status, RCM summary by cycle — is a direct count over the engagement’s own RCM rows and observations, not a document assembled separately at the end. A draft view is available at any point; a final report is gated until a draft has actually been issued to the auditee, the way SIA 370 (3.3) expects. An optional AI-drafted narrative can add an executive-summary reading of those same numbers — it’s marked as a draft the auditor reviews before it goes into the issued report, and flagged stale the moment the underlying RCM or observations change.

One RCM, two audiences

Internal audit under Section 138 of the Companies Act 2013 is mandatory for a defined set of companies (by paid-up capital, turnover, borrowings, or public deposits — check applicability for the entity in question). Separately, Section 143(3)(i) requires the statutory auditor to opine on the adequacy and operating effectiveness of internal financial controls. A control tested for the Section 138 function — its design, its test result, its rating — is the same evidence a statutory auditor needs for the Section 143(3)(i) opinion. CORAA’s RCM engine can carry the additional Guidance Note fields (assertions, key-control flag, IPE reference, test-of-design and test-of-effectiveness results) a statutory ICFR conclusion needs on the same control row, instead of a second team re-documenting it from scratch.

Frequently asked

Before you seed the first RCM.

An RCM is the structured taxonomy an internal audit engagement is built on: process cycle → sub-process → risk (rated High/Medium/Low) → control (preventive or detective, manual/automated/IT-dependent) → control objective → test → result → observation → report. CORAA seeds an entity’s RCM from a library of pre-built controls at engagement creation, then the auditor confirms or edits each row — the seed is a starting point, not the final record; the auditor’s edit always supersedes it.
CORAA’s internal audit module ships eight process cycles as standard — Procure-to-Pay, Order-to-Cash, Record-to-Report, Payroll, Inventory, Treasury, Fixed Assets, and Statutory Compliance — with cadences calibrated to the entity during onboarding rather than fixed in advance. Manufacturing and retail entities get additional cycle-specific controls layered on top (production/BOM controls for manufacturing, POS and marketplace-settlement controls for retail).
A fieldwork engagement is a fixed-period RCM review — Planning → Fieldwork → Reporting → Follow-up → Closed — that produces a dated SIA 370 report, the way a quarterly or annual internal audit visit works today. A continuous process monitor is scoped once per cycle (pick the controls in scope, set a review cadence) and then keeps testing every new transaction against that checklist without being re-created — a live health view rather than a periodic snapshot. An engagement can use either or both; a Command Centre rolls up every active monitor’s clearance rate, failures, and open actions in one place.
The RCM row carries the test result (Effective, Deficiency, Significant Deficiency, or Material Weakness) with the evidence it was based on. From a failed result, CORAA can draft an observation in the condition-criteria-cause-effect-recommendation structure SIA 360/370 expect — the condition carries the real counts from the test, the rest is a starting draft the auditor edits before it’s created. Nothing is recorded as a finding until the auditor explicitly saves it. From there it carries a management response, a response owner, and an agreed action date into the SIA 390 follow-up register.
Yes — the engagement stages, evidence handling and report structure map to the relevant SIAs: SIA 220 (conducting the assignment) and SIA 310 (planning) govern the engagement setup; SIA 320 (evidence) and SIA 330 (documentation) govern what’s recorded on each RCM row, with a preparer/reviewer trail; SIA 350 covers supervision and review; SIA 360, 370 and 390 govern management communication, reporting and follow-up respectively. The ICAI Council has been moving the SIA framework from recommendatory toward mandatory in a phased rollout — check the current applicability schedule for your engagement period rather than assuming full mandatory status.
Internal audit under Section 138 of the Companies Act 2013 is mandatory for a defined set of companies (by paid-up capital, turnover, borrowings, or public deposits — check applicability for the entity in question). Separately, Section 143(3)(i) requires the statutory auditor to opine on the adequacy and operating effectiveness of internal financial controls. Those are two different audiences reading the same underlying evidence: CORAA’s RCM engine supports both, so a control tested for the Section 138 internal audit function can carry the additional Guidance Note fields (assertions, key-control flag, IPE reference, test-of-design and test-of-effectiveness results) the statutory Section 143(3)(i) opinion needs, instead of a second team re-documenting the same control from scratch.
No. Automation runs the tests, pulls the actual transaction population for the period, and surfaces exceptions and pre-wired counts from existing scrutiny rules — the internal auditor still investigates root cause, drafts or edits the observation, and agrees the management response. Every AI-drafted narration or observation is labelled as a draft the auditor reviews and can rewrite; nothing is finalised until the auditor’s own action.
Ready when you are

Internal audit, under a cadence you set.

Start with one process cycle — seed its RCM, run the first control test, and see what a live internal audit engagement actually looks like before committing to all eight.

Start your first engagementSee the statutory-audit AI Modules