CORAA
Resources - Internal Audit FAQ

Internal audit FAQ for India answers.

Practical answers for internal audit teams, CA firms and finance leaders building a Section 138, SIA-aligned internal audit operating model: mandate, SOW, RCM, fieldwork, reporting, ATR, dashboards, continuous monitoring and AI.

Open internal audit hubBrowse downloads
Answer map

Grouped by the audit lifecycle 40 questions

Applicability, mandate and scope

Start here before drafting a SOW, annual plan or checklist.

Planning, audit universe and annual plan

Turn risk themes into auditable units, hours and calendar commitments.

SOW, PBC and fieldwork setup

The quality of fieldwork depends on scope, data and evidence discipline before testing starts.

RCM, controls and sampling

A useful checklist must become testable control work, not just a list of questions.

Reporting, observations and ATR

The report should connect evidence to finding, owner, action and follow-up.

Audit committee, dashboards and maturity

Internal audit should show coverage, blockers, ageing and residual risk clearly.

Continuous monitoring, analytics and AI

Analytics are useful only when the source data, logic and review owner are documented.

Cycle and industry checklists

Use separate workpapers for each major process or industry rather than one generic checklist.

01

Applicability, mandate and scope FAQs

Start here before drafting a SOW, annual plan or checklist.

When is internal audit mandatory in India?

Internal audit is mandatory when a company falls under Section 138 of the Companies Act 2013 and Rule 13 of the Companies (Accounts) Rules. The exact test depends on company type and thresholds for turnover, borrowings, deposits and paid-up share capital, so confirm applicability for the financial year before issuing a mandate.

Check applicability ->
Is internal audit the same as statutory audit?

No. Statutory audit gives an opinion on financial statements. Internal audit reviews governance, risk management, controls, process compliance, operational effectiveness and agreed corrective action. The work can support statutory audit evidence, but it does not replace the statutory auditor's opinion.

See report pack ->
What should an internal audit charter include?

A charter should define purpose, authority, independence, reporting line, scope, unrestricted access to records and people, confidentiality, escalation rights, audit committee reporting and annual review. It should be approved at the right governance level before recurring reviews begin.

Open charter guide ->
What is the difference between charter and SOW?

The charter is the standing mandate for the internal audit function. The SOW is the engagement-specific scope, period, locations, cycles, exclusions, deliverables, timelines, data requests, meetings and management responsibilities for a particular assignment.

Build SOW ->
Can a CA firm provide internal audit services?

Yes, CA firms commonly provide internal audit, co-sourcing and outsourced internal audit support. They still need clear independence boundaries, scope ownership, evidence access, management responsibility, reporting protocol and quality review so internal audit does not become undocumented advisory work.

CA firm internal audit page ->
02

Planning, audit universe and annual plan FAQs

Turn risk themes into auditable units, hours and calendar commitments.

What is an internal audit universe?

An audit universe is the full list of auditable entities, processes, locations, systems and risk themes that internal audit may review. It should map each unit to risk category, owner, inherent risk, control maturity, last review, planned frequency and assurance coverage.

Build audit universe ->
How do you score internal audit risks?

Most teams score impact and likelihood first, then adjust for control maturity, change, fraud sensitivity, regulatory exposure, prior findings, management turnover and assurance already available. The scoring model should rank review priority, not mechanically declare a finding.

Use risk scorer ->
What should an annual internal audit plan include?

A strong annual plan shows auditable units, risk rationale, quarter, scope, location, estimated hours, reviewer, specialist need, dependency, monitoring candidate and audit committee approval. It should leave capacity for investigations, follow-up and emerging risks.

Build annual plan ->
When should an internal audit plan be refreshed mid-year?

Refresh the plan when incidents, regulatory change, cyber events, fraud indicators, major system changes, acquisitions, repeated control failures, high overdue ATR items or dashboard exceptions change the risk profile enough that the approved plan no longer fits reality.

Plan refresh guide ->
How do you avoid overcommitting the internal audit plan?

Convert every review into hours, quarter load, manager/reviewer time, specialist demand, travel, follow-up effort and reporting time. Compare that demand with available capacity before presenting the plan to the audit committee.

Check capacity ->
03

SOW, PBC and fieldwork setup FAQs

The quality of fieldwork depends on scope, data and evidence discipline before testing starts.

What should an internal audit SOW contain?

The SOW should contain objective, period, locations, process cycles, in-scope and out-of-scope areas, deliverables, methodology, timelines, data request protocol, management responsibilities, reporting audience, limitation handling and agreed contacts.

Generate SOW ->
What is a PBC list in internal audit?

PBC means Prepared by Client. It is the data and document request list for the engagement: ERP reports, master data, policies, approvals, reconciliations, contracts, logs, evidence files, explanations and owners. Each item should carry due date, status and escalation route.

Build PBC list ->
What should a walkthrough memo capture?

A walkthrough memo should record process owner, systems used, documents traced from initiation to recording, key controls observed, handoffs, system reports relied on, exceptions noted, design gaps and which RCM rows need testing.

Write walkthrough memo ->
How do you know whether source data is reliable enough for testing?

Before testing, retain extraction parameters, population completeness checks, report owner, system source, date/time of extraction, filters, reconciliations to control totals, field dictionary and evidence that the report can be recreated or independently verified.

Source data readiness ->
When should missing PBC evidence be escalated?

Escalate when a request is overdue, incomplete, inconsistent with source systems, repeatedly deferred, controlled by the same person being reviewed, or likely to create a scope limitation. The escalation trail should show impact on testing and reporting.

Track escalation ->
04

RCM, controls and sampling FAQs

A useful checklist must become testable control work, not just a list of questions.

What is an RCM in internal audit?

RCM means Risk and Control Matrix. It maps each sub-process to risk, control, control owner, frequency, control type, evidence, test procedure, sample basis, result, exception and reviewer conclusion. It is the bridge between process understanding and fieldwork.

Build RCM ->
What is the difference between design effectiveness and operating effectiveness?

Design effectiveness asks whether the control, if performed as described, would prevent or detect the risk. Operating effectiveness asks whether the control actually operated during the period, by the right person, at the right frequency, with evidence.

Design gap register ->
How should internal audit select samples?

Sample selection should start from a complete population and documented risk basis. Consider control frequency, population size, expected deviation, prior exceptions, materiality, high-risk items, random coverage and replacement rules if selected items cannot be tested.

Build sampling plan ->
When is 100% testing better than sampling?

Use full-population testing when the data is reliable, the logic is deterministic and the risk benefits from exception scans: duplicate payments, credit overrides, late journals, stale BRS items, leaver access, negative stock or GST/TDS filing delay.

Monitoring rules ->
What should a fieldwork tracker show?

A fieldwork tracker should show each RCM row, sample count, evidence received, tests completed, exceptions, open queries, blocker owner, reviewer status, report impact and whether the item is ready for observation drafting.

Fieldwork tracker ->
05

Reporting, observations and ATR FAQs

The report should connect evidence to finding, owner, action and follow-up.

What should an internal audit observation include?

A complete observation should include condition, criteria, cause, consequence, risk rating, evidence reference, recommendation, management response, action owner, target date and follow-up requirement. Avoid reporting control opinions that cannot be traced to workpapers.

Build observation report ->
How should internal audit rate findings?

Use consistent criteria for impact, likelihood, recurrence, control weakness, compliance sensitivity and pervasiveness. High ratings usually involve fraud, regulatory exposure, repeated failure, material financial impact, management override or significant control design weakness.

Rate findings ->
What is ATR in internal audit?

ATR means Action Taken Report. It tracks each observation, management response, owner, due date, revised due date, closure evidence, status and follow-up result. It is how the audit report becomes accountable action rather than a static document.

Build ATR tracker ->
What closure evidence is enough to close an audit issue?

Closure evidence should prove the corrective action operated, not just that management agreed. Examples include revised policy, approval log, system configuration, sample retest, reconciliation, screenshot, monitoring report or committee-approved risk acceptance.

Closure checklist ->
When should accepted risk be reported to the audit committee?

Accepted risk should be reported when residual exposure is significant, regulatory, repeated, fraud-sensitive, unsupported by compensating controls, past due, outside management authority or likely to affect annual assurance. Record acceptance authority and expiry date.

Risk acceptance register ->
06

Audit committee, dashboards and maturity FAQs

Internal audit should show coverage, blockers, ageing and residual risk clearly.

What should an audit committee internal audit pack include?

The pack should show plan progress, completed reviews, high observations, overdue ATR ageing, accepted risks, scope limitations, evidence blockers, monitoring exceptions, management attendance, decisions required and private-session matters.

Committee pack ->
Which KPIs should an internal audit dashboard track?

Track plan completion, high-risk coverage, open observations, overdue ATR, repeat findings, average closure days, evidence blockers, monitoring exceptions, issue severity mix, accepted risk, co-source quality and management response ageing.

Dashboard KPIs ->
What is an annual internal audit assurance opinion?

It is the year-end internal audit view on the adequacy of governance, risk management and controls across the areas reviewed, with scope limitations, reliance basis, high residual risks, issue ageing and next-year planning implications.

Annual opinion pack ->
How do you assess internal audit maturity?

Assess mandate, independence, risk-based planning, methodology, workpaper quality, QAIP, reporting, issue follow-up, analytics, AI governance, stakeholder impact, talent and capacity. Then translate gaps into a 30-60-90 day roadmap.

Maturity assessment ->
What is a three lines assurance map?

A three lines map shows which risks are owned by operations, monitored by second-line functions, reviewed by internal audit and covered by external assurance. It reduces duplicate testing and highlights gaps in assurance coverage.

Assurance map ->
07

Continuous monitoring, analytics and AI FAQs

Analytics are useful only when the source data, logic and review owner are documented.

What is continuous monitoring in internal audit?

Continuous monitoring is recurring exception testing over stable source data, such as duplicate vendor bank accounts, credit overrides, late journals, stale BRS items, leaver access or covenant watchlists. Exceptions still need auditor review before becoming findings.

Monitoring rules ->
What is process mining in internal audit?

Process mining uses event logs to reconstruct actual process flows, variants, bottlenecks and control bypasses. It works best when timestamps, user IDs, activity labels, case IDs and extraction completeness are reliable.

Process mining guide ->
How can internal audit use AI without weakening evidence?

Use AI for drafting, summarising, mapping risks and suggesting tests only inside approved boundaries. Retain source data, prompts or assumptions where relevant, reviewer edits, human conclusion and proof that no confidential data was exposed outside policy.

AI strategy template ->
Should internal audit review business AI governance?

Yes where the organisation uses AI in finance, HR, credit, procurement, customer operations or compliance. Internal audit should test inventory, owner accountability, data use, model changes, human review, incidents, vendor controls and monitoring.

AI governance workpaper ->
How does AI-enabled fraud change internal audit testing?

It increases the need for source-evidence skepticism: invoices, contracts, bank details, voice approvals, applicant records, emails and screenshots may be fabricated or manipulated. Test verification routes, independent confirmations, logs and monitoring rules.

AI fraud checklist ->
08

Cycle and industry checklists FAQs

Use separate workpapers for each major process or industry rather than one generic checklist.

Which finance cycles should most internal audit plans cover?

Most plans consider P2P, O2C, R2R, H2R/payroll, cash and bank, inventory, fixed assets, treasury, statutory compliance and ITGC. The final mix depends on risk, size, industry, systems and last review date.

Cycle programmes ->
What does a P2P internal audit checklist cover?

P2P covers vendor onboarding, vendor master changes, purchase requisitions, PO approval, GRN, invoice matching, GST ITC, TDS, MSME ageing, advances, payment release and AP reconciliations.

P2P checklist ->
What does an R2R internal audit checklist cover?

R2R covers GL master, close calendar, manual journals, balance-sheet reconciliations, accruals, provisions, intercompany, reporting packs, tax tie-outs, Schedule III mapping and close-period access.

R2R checklist ->
When do you need an industry-specific internal audit checklist?

Use industry-specific checklists when generic cycles miss key risks: manufacturing BOM and scrap, NBFC NPA/ALM, hospital TPA billing, real-estate RERA collections, hotel POS and OTA, pharma batch records or NGO grants/FCRA.

Industry checklists ->
Are CORAA internal audit resources downloadable?

Yes. The explanatory pages stay open for search and AI answers, while Excel, PDF, Word and working-file downloads are routed through standard CORAA resource forms so auditors can reuse the files and CORAA can capture the resource requested.

Downloads hub ->
Open internal audit hubSee internal audit product