CORAA
Resources · Internal Financial Controls

Internal financial controls and ICFR readiness.

IFC readiness is not a year-end evidence chase. Internal audit should help management assess and document entity-level controls, process RCMs, ITGC, financial reporting controls, remediation and committee reporting before the statutory audit pressure arrives.

Open control repositoryOpen ITGC checklist
Downloads

IFC / ICFR readiness pack workbook

Download the Excel/PDF pack for control inventory, readiness layers, test criteria, control areas, deficiency grading, year-end sequence, authority notes and product-reuse fields.

Authority anchors

Use legal anchors without overclaiming anchors

Companies Act 2013

Section 134 requires directors to address internal financial controls in the Directors Responsibility Statement for listed companies, and Section 143 requires auditor reporting on internal financial controls with reference to financial statements.

Companies (Accounts) Rules 2014

Rule 8 reporting reinforces why management needs a documented control framework, ownership, testing evidence and remediation status before year-end reporting.

ICAI guidance and SIAs

Use ICAI guidance on internal financial controls over financial reporting for audit expectations, and internal audit standards for planning, evidence, reporting and follow-up discipline.

COSO-style control framework

Map control environment, risk assessment, control activities, information and communication, and monitoring so IFC does not become only a process-level checklist.

Readiness layers

What internal audit should cover framework

Governance and control environment

Board/Audit Committee oversight, code of conduct, delegation matrix, finance close accountability, competence and disciplinary route.

Risk assessment

Financial reporting risks, fraud risks, change events, new systems, complex estimates, related parties, regulatory exposure and outsourced processes.

Process-level controls

P2P, O2C, R2R, inventory, fixed assets, payroll, treasury and compliance controls mapped to assertions and evidence.

IT general controls

Access, privileged users, SoD, change management, backups, jobs, interfaces, report logic and audit logs supporting process controls.

Information and communication

Reliable MIS, close calendars, policy communication, exception reporting, ownership of master data and evidence retention.

Monitoring and remediation

Control self-assessment, internal audit testing, deficiency grading, action plans, retesting, accepted risk and committee reporting.

Control tests

Readiness questions that matter test

Control objective is clear

Each control should say which financial-reporting risk or assertion it addresses.

Control owner is accountable

The owner should be senior enough to operate or review the control, not merely prepare evidence after audit asks.

Frequency and timing are defined

Daily, monthly, quarterly and year-end controls need clear operating windows and escalation for delays.

Evidence is retained

Approvals, reconciliations, logs, review notes and exception follow-up should be retained in a retrievable format.

IT dependency is visible

Report reliability, access rights, change logs and interface controls should be mapped wherever the process relies on system output.

Deficiency conclusion is consistent

Design gap, operating failure, significant deficiency and material weakness logic should be applied consistently.

Coverage map

Control areas to map areas

Entity-level controls

Board oversight, Audit Committee review, ethics, authority matrix, whistleblower, fraud risk, competence and finance close governance.

P2P and payments

Vendor master, PO approval, GRN, invoice matching, GST/TDS/MSME checks, payment approval, bank controls and exception monitoring.

O2C and revenue

Customer master, credit, pricing, dispatch, billing, GST, collections, credit notes, ageing and cut-off.

R2R and close

Chart of accounts, journal approvals, reconciliations, provisions, estimates, consolidation, financial statement mapping and disclosure controls.

Inventory and fixed assets

GRN, stock counts, ageing, NRV, costing, CWIP, capitalization, tagging, depreciation, disposal and impairment.

Payroll and H2R

Employee master, attendance, payroll changes, statutory deductions, reimbursements, exits, full-and-final and HRMS access.

Treasury and bank

Bank mandates, payment release, borrowings, covenants, investments, forex, bank reconciliation and cash-flow controls.

ITGC and reports

User access, SoD, privileged access, changes, jobs, backups, interfaces, audit logs and report completeness/accuracy.

Deficiency grading

Separate design, operation and severity consistent

Design gap

The control is missing or not capable of preventing/detecting the risk even if operated exactly as written.

Operating failure

The control is designed, but did not operate, operated late, lacked evidence, or was not reviewed by the right person.

Repeat deficiency

Same control, owner, root cause or cycle failed again after prior closure or management action.

Significant deficiency

Control weakness important enough for senior management or Audit Committee attention based on exposure, likelihood and compensating controls.

Material weakness indicator

A deficiency or combination of deficiencies that may create a reasonable possibility of material misstatement not being prevented or detected.

Accepted residual risk

Management/governance accepts a remaining exposure; internal audit documents authority, basis, expiry and reporting route.

Timing

Do the work before year-end year-end

Q1 / planning

Confirm scope, legal applicability, process owners, control framework, prior deficiencies and high-risk cycles.

Q2 / design walkthroughs

Walk through entity-level, process and ITGC controls; update RCMs; identify design gaps before year-end pressure.

Q3 / operating testing

Test operating effectiveness for key controls, report early failures and agree remediation owners/dates.

Q4 / remediation and retesting

Retest remediated controls, evaluate residual deficiencies and prepare management/Audit Committee reporting.

Year-end close

Update deficiency evaluation, accepted-risk register, representation support, auditor coordination and final committee pack.

Product reuse

Reusable product fields fields

ArtifactModuleLikely fields
IFC control libraryControl repositoryControl objective, assertion, owner, frequency, evidence, IT dependency, key/non-key flag.
Deficiency evaluatorObservation workflowDesign vs operating failure, exposure, likelihood, compensating control, repeat flag, severity.
ICFR readiness dashboardInternal Audit command centreCoverage, tests complete, failed controls, repeat deficiencies, remediation ageing, retest status.
Auditor request packEvidence workflowControl evidence, population source, report parameters, sample support, reviewer conclusion and retained file.
Committee reportingGovernance workflowHigh deficiencies, repeat issues, accepted risks, open remediation, management representation support.
Related resources

Use this with RCM, ITGC and remediation next

Internal Audit Control Repository

Use the cycle RCM library as the starting point for IFC control mapping.

ITGC Internal Audit Checklist

Map access, change and report-reliability controls that support financial reporting controls.

Root Cause & Remediation Plan

Convert IFC deficiencies into owner-led, retestable action plans.

Closure Evidence & Retesting Checklist

Do not mark a deficiency remediated until evidence and retesting support closure.

Risk Acceptance & Escalation Register

Track accepted residual risk, authority, compensating controls and committee visibility.

Audit Committee Reporting Pack

Report significant deficiencies, repeat failures, accepted risks and remediation ageing.

FAQ

Common questions answers

What is the difference between IFC and ICFR?

IFC is the broader internal financial controls concept used in Indian company reporting. ICFR focuses on controls over financial reporting: whether controls are designed and operating so financial statements are reliable and material misstatements are prevented or detected.

Should internal audit test IFC before the statutory auditor?

Yes, as a readiness activity. Internal audit can test design, operating evidence, IT dependencies and remediation early, so management is not discovering control failures only during year-end statutory audit.

Can internal audit certify that IFC is effective?

Internal audit can provide an internal assessment based on scope, testing and evidence. Formal statutory reporting responsibility remains with the auditor and management/Board as applicable under the Companies Act framework.

What should an IFC readiness workbook include?

It should include a control inventory, entity-level control checklist, process RCM map, ITGC dependency map, deficiency grading, remediation tracker, retest conclusion, accepted-risk register and committee reporting summary.