CORAA
CORAA University / Continuous audit

Internal audit monitoring rules

Build a practical exception-rule library for recurring internal audit: duplicate payments, leaver access, stale BRS items, aged reconciliations, GST/TDS delays, covenant watchlists and other monitoring tests.

Select monitoring cycles
15 monitoring rules
CycleRuleData sourceException logicCadenceOwner
Procure to PayDuplicate vendor bank accountsVendor masterSame bank account used by more than one active vendor, excluding approved group/vendor relationships.WeeklyProcurement finance
Procure to PayDuplicate invoice riskPurchase invoice registerSame vendor plus invoice number, invoice date and amount repeated, or same amount/date with similar invoice reference.WeeklyAccounts payable
Procure to PayMSME ageing breachVendor master and open payable ageingMSME vendors unpaid beyond agreed 15/45-day terms or missing MSME classification evidence.WeeklyAccounts payable
Order to CashCredit-limit overrideCustomer master, sales orders and override logInvoices or dispatches released where exposure exceeded approved limit without documented approval.WeeklySales finance
Order to CashLong-outstanding receivablesDebtors ageing and collection trackerBalances beyond threshold ageing with no recent collection note, dispute tag or approved legal escalation.WeeklyReceivables
Record to ReportLate manual journalsGL journal dumpManual journals posted after close deadline, on weekends, by senior users, or without attachment/reference.Monthly closeControllership
Record to ReportAged reconciling itemsBalance-sheet reconciliation trackerReconciling items older than policy threshold or repeated for more than two closes.Monthly closeControllership
Cash and BankStale BRS itemsBank reconciliationOpen bank or book reconciling items older than policy threshold, split by receipts/payments/bank charges.MonthlyTreasury operations
H2R and PayrollPayroll to leaver matchPayroll register and exit listSalary, reimbursement or statutory contribution processed after last working day without FNF approval.MonthlyPayroll
H2R and PayrollBank account reuseEmployee masterSame salary bank account mapped to more than one active employee without approved family/exception note.MonthlyPayroll
Statutory ComplianceGST/TDS filing delayCompliance calendar, returns and challansReturn or payment completed after statutory due date, or reconciliation not reviewed before filing.MonthlyTax
TreasuryCovenant watchlistLoan agreements, covenant tracker and MISCovenant ratio approaching breach threshold, actual breach or missing lender reporting evidence.MonthlyTreasury
TreasuryUnauthorised bank guarantee/LCBG/LC register and bank statementsGuarantee, LC or charge created without approval, limit availability check or register update.MonthlyTreasury
ITGC and AccessLeaver access activeHR exit list and user access extractSeparated employee retains ERP, bank portal, email, VPN or privileged application access after exit date.WeeklyIT
ITGC and AccessPrivileged user activityAdmin user list and activity logsPrivileged user changes master data, approvals or configuration without ticket and independent review.WeeklyIT

Build the underlying RCM or open the monitoring rules guide.

How it works

Continuous monitoring converts repeatable audit procedures into periodic exception rules. It is strongest for complete-population checks such as duplicates, ageing, overdue reconciliations, access conflicts and filing delays.

The output should not be treated as automatic audit evidence. Exceptions need threshold tuning, false-positive review, evidence retention, owner assignment and follow-up before they become internal audit observations.

Worked example

A finance team wants monthly internal audit monitoring for P2P, statutory compliance, treasury and ITGC.

Inputs
Cycles selectedP2P, Statutory Compliance, Treasury, ITGC
ExportExcel exception-rule workbook
Output
RulesDuplicate invoice, MSME ageing, filing delay, covenant watchlist, leaver access and privileged-user activity

Common mistakes

No threshold tuning
A rule without materiality, ageing or exception thresholds creates noise and is abandoned quickly.
No owner for review
Every exception rule needs a reviewer and action owner; otherwise it is only a report.
No evidence retention
Monitoring exceptions should preserve the population, logic, reviewer conclusion and closure evidence.

Frequently asked questions

What are internal audit monitoring rules?+
They are repeatable exception tests applied to ERP, payroll, bank, tax or compliance data to identify transactions or balances that need review.
Is continuous monitoring the same as internal audit?+
No. Continuous monitoring supports internal audit by identifying exceptions, but fieldwork, evidence evaluation, observation rating and reporting still require auditor judgement.
Which processes are best for monitoring?+
P2P, O2C, R2R, Cash and Bank, Payroll, Statutory Compliance, Treasury and ITGC are strong candidates because they produce structured recurring data.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditCurrent SIA framework includes planning, evidence, documentation, reporting and follow-up standards.
MCA
Companies (Accounts) Rules, 2014 - Rule 13Rule 13(2) anchors periodicity and methodology for internal audit.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit RCM builderInternal audit risk scorerInternal audit resources
Share this tool
Last reviewed: 2026-08-27 · For informational purposes only — not professional advice.