Practical answers for internal audit teams, CA firms and finance leaders building a Section 138, SIA-aligned internal audit operating model: mandate, SOW, RCM, fieldwork, reporting, ATR, dashboards, continuous monitoring and AI.
Start here before drafting a SOW, annual plan or checklist.
Turn risk themes into auditable units, hours and calendar commitments.
The quality of fieldwork depends on scope, data and evidence discipline before testing starts.
A useful checklist must become testable control work, not just a list of questions.
The report should connect evidence to finding, owner, action and follow-up.
Internal audit should show coverage, blockers, ageing and residual risk clearly.
Analytics are useful only when the source data, logic and review owner are documented.
Use separate workpapers for each major process or industry rather than one generic checklist.
Start here before drafting a SOW, annual plan or checklist.
Internal audit is mandatory when a company falls under Section 138 of the Companies Act 2013 and Rule 13 of the Companies (Accounts) Rules. The exact test depends on company type and thresholds for turnover, borrowings, deposits and paid-up share capital, so confirm applicability for the financial year before issuing a mandate.
Check applicability ->No. Statutory audit gives an opinion on financial statements. Internal audit reviews governance, risk management, controls, process compliance, operational effectiveness and agreed corrective action. The work can support statutory audit evidence, but it does not replace the statutory auditor's opinion.
See report pack ->A charter should define purpose, authority, independence, reporting line, scope, unrestricted access to records and people, confidentiality, escalation rights, audit committee reporting and annual review. It should be approved at the right governance level before recurring reviews begin.
Open charter guide ->The charter is the standing mandate for the internal audit function. The SOW is the engagement-specific scope, period, locations, cycles, exclusions, deliverables, timelines, data requests, meetings and management responsibilities for a particular assignment.
Build SOW ->Yes, CA firms commonly provide internal audit, co-sourcing and outsourced internal audit support. They still need clear independence boundaries, scope ownership, evidence access, management responsibility, reporting protocol and quality review so internal audit does not become undocumented advisory work.
CA firm internal audit page ->Turn risk themes into auditable units, hours and calendar commitments.
An audit universe is the full list of auditable entities, processes, locations, systems and risk themes that internal audit may review. It should map each unit to risk category, owner, inherent risk, control maturity, last review, planned frequency and assurance coverage.
Build audit universe ->Most teams score impact and likelihood first, then adjust for control maturity, change, fraud sensitivity, regulatory exposure, prior findings, management turnover and assurance already available. The scoring model should rank review priority, not mechanically declare a finding.
Use risk scorer ->A strong annual plan shows auditable units, risk rationale, quarter, scope, location, estimated hours, reviewer, specialist need, dependency, monitoring candidate and audit committee approval. It should leave capacity for investigations, follow-up and emerging risks.
Build annual plan ->Refresh the plan when incidents, regulatory change, cyber events, fraud indicators, major system changes, acquisitions, repeated control failures, high overdue ATR items or dashboard exceptions change the risk profile enough that the approved plan no longer fits reality.
Plan refresh guide ->Convert every review into hours, quarter load, manager/reviewer time, specialist demand, travel, follow-up effort and reporting time. Compare that demand with available capacity before presenting the plan to the audit committee.
Check capacity ->The quality of fieldwork depends on scope, data and evidence discipline before testing starts.
The SOW should contain objective, period, locations, process cycles, in-scope and out-of-scope areas, deliverables, methodology, timelines, data request protocol, management responsibilities, reporting audience, limitation handling and agreed contacts.
Generate SOW ->PBC means Prepared by Client. It is the data and document request list for the engagement: ERP reports, master data, policies, approvals, reconciliations, contracts, logs, evidence files, explanations and owners. Each item should carry due date, status and escalation route.
Build PBC list ->A walkthrough memo should record process owner, systems used, documents traced from initiation to recording, key controls observed, handoffs, system reports relied on, exceptions noted, design gaps and which RCM rows need testing.
Write walkthrough memo ->Before testing, retain extraction parameters, population completeness checks, report owner, system source, date/time of extraction, filters, reconciliations to control totals, field dictionary and evidence that the report can be recreated or independently verified.
Source data readiness ->Escalate when a request is overdue, incomplete, inconsistent with source systems, repeatedly deferred, controlled by the same person being reviewed, or likely to create a scope limitation. The escalation trail should show impact on testing and reporting.
Track escalation ->A useful checklist must become testable control work, not just a list of questions.
RCM means Risk and Control Matrix. It maps each sub-process to risk, control, control owner, frequency, control type, evidence, test procedure, sample basis, result, exception and reviewer conclusion. It is the bridge between process understanding and fieldwork.
Build RCM ->Design effectiveness asks whether the control, if performed as described, would prevent or detect the risk. Operating effectiveness asks whether the control actually operated during the period, by the right person, at the right frequency, with evidence.
Design gap register ->Sample selection should start from a complete population and documented risk basis. Consider control frequency, population size, expected deviation, prior exceptions, materiality, high-risk items, random coverage and replacement rules if selected items cannot be tested.
Build sampling plan ->Use full-population testing when the data is reliable, the logic is deterministic and the risk benefits from exception scans: duplicate payments, credit overrides, late journals, stale BRS items, leaver access, negative stock or GST/TDS filing delay.
Monitoring rules ->A fieldwork tracker should show each RCM row, sample count, evidence received, tests completed, exceptions, open queries, blocker owner, reviewer status, report impact and whether the item is ready for observation drafting.
Fieldwork tracker ->The report should connect evidence to finding, owner, action and follow-up.
A complete observation should include condition, criteria, cause, consequence, risk rating, evidence reference, recommendation, management response, action owner, target date and follow-up requirement. Avoid reporting control opinions that cannot be traced to workpapers.
Build observation report ->Use consistent criteria for impact, likelihood, recurrence, control weakness, compliance sensitivity and pervasiveness. High ratings usually involve fraud, regulatory exposure, repeated failure, material financial impact, management override or significant control design weakness.
Rate findings ->ATR means Action Taken Report. It tracks each observation, management response, owner, due date, revised due date, closure evidence, status and follow-up result. It is how the audit report becomes accountable action rather than a static document.
Build ATR tracker ->Closure evidence should prove the corrective action operated, not just that management agreed. Examples include revised policy, approval log, system configuration, sample retest, reconciliation, screenshot, monitoring report or committee-approved risk acceptance.
Closure checklist ->Accepted risk should be reported when residual exposure is significant, regulatory, repeated, fraud-sensitive, unsupported by compensating controls, past due, outside management authority or likely to affect annual assurance. Record acceptance authority and expiry date.
Risk acceptance register ->Internal audit should show coverage, blockers, ageing and residual risk clearly.
The pack should show plan progress, completed reviews, high observations, overdue ATR ageing, accepted risks, scope limitations, evidence blockers, monitoring exceptions, management attendance, decisions required and private-session matters.
Committee pack ->Track plan completion, high-risk coverage, open observations, overdue ATR, repeat findings, average closure days, evidence blockers, monitoring exceptions, issue severity mix, accepted risk, co-source quality and management response ageing.
Dashboard KPIs ->It is the year-end internal audit view on the adequacy of governance, risk management and controls across the areas reviewed, with scope limitations, reliance basis, high residual risks, issue ageing and next-year planning implications.
Annual opinion pack ->Assess mandate, independence, risk-based planning, methodology, workpaper quality, QAIP, reporting, issue follow-up, analytics, AI governance, stakeholder impact, talent and capacity. Then translate gaps into a 30-60-90 day roadmap.
Maturity assessment ->A three lines map shows which risks are owned by operations, monitored by second-line functions, reviewed by internal audit and covered by external assurance. It reduces duplicate testing and highlights gaps in assurance coverage.
Assurance map ->Analytics are useful only when the source data, logic and review owner are documented.
Continuous monitoring is recurring exception testing over stable source data, such as duplicate vendor bank accounts, credit overrides, late journals, stale BRS items, leaver access or covenant watchlists. Exceptions still need auditor review before becoming findings.
Monitoring rules ->Process mining uses event logs to reconstruct actual process flows, variants, bottlenecks and control bypasses. It works best when timestamps, user IDs, activity labels, case IDs and extraction completeness are reliable.
Process mining guide ->Use AI for drafting, summarising, mapping risks and suggesting tests only inside approved boundaries. Retain source data, prompts or assumptions where relevant, reviewer edits, human conclusion and proof that no confidential data was exposed outside policy.
AI strategy template ->Yes where the organisation uses AI in finance, HR, credit, procurement, customer operations or compliance. Internal audit should test inventory, owner accountability, data use, model changes, human review, incidents, vendor controls and monitoring.
AI governance workpaper ->It increases the need for source-evidence skepticism: invoices, contracts, bank details, voice approvals, applicant records, emails and screenshots may be fabricated or manipulated. Test verification routes, independent confirmations, logs and monitoring rules.
AI fraud checklist ->Use separate workpapers for each major process or industry rather than one generic checklist.
Most plans consider P2P, O2C, R2R, H2R/payroll, cash and bank, inventory, fixed assets, treasury, statutory compliance and ITGC. The final mix depends on risk, size, industry, systems and last review date.
Cycle programmes ->P2P covers vendor onboarding, vendor master changes, purchase requisitions, PO approval, GRN, invoice matching, GST ITC, TDS, MSME ageing, advances, payment release and AP reconciliations.
P2P checklist ->R2R covers GL master, close calendar, manual journals, balance-sheet reconciliations, accruals, provisions, intercompany, reporting packs, tax tie-outs, Schedule III mapping and close-period access.
R2R checklist ->Use industry-specific checklists when generic cycles miss key risks: manufacturing BOM and scrap, NBFC NPA/ALM, hospital TPA billing, real-estate RERA collections, hotel POS and OTA, pharma batch records or NGO grants/FCRA.
Industry checklists ->Yes. The explanatory pages stay open for search and AI answers, while Excel, PDF, Word and working-file downloads are routed through standard CORAA resource forms so auditors can reuse the files and CORAA can capture the resource requested.
Downloads hub ->