Internal Audit, Risk-based Audit and Compliance Audit
Internal audit is a statutory obligation for some companies and a management choice for everyone else, and the two are run quite differently. The statutory version has to exist. The chosen version has to earn its budget, which means it has to be risk-based, and risk-based means something more specific than looking at what worries people.
- When internal audit is statutory, and who may hold the role
- How the auditor's report order reaches companies that are not caught
- Building a risk-based plan that is actually risk-based
- Compliance audit, and where it differs
Section 138 and rule 13
| Company | Internal audit required where |
|---|---|
| Every listed company | Always |
| Unlisted public company | Any one of four alternative tests, measured on the preceding financial year: paid-up share capital of ₹50 crore or more, or turnover of ₹200 crore or more, or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point during that year, or outstanding deposits of ₹25 crore or more at any point during that year |
| Private company | Turnover of ₹200 crore or more, or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point during the preceding financial year |
| Small company and one person company | Not caught |
Two drafting points decide more borderline cases than the figures do. The tests are alternatives, joined by 'or', so one is enough. And the words 'at any point during the preceding financial year' attach only to the borrowing and deposit limbs, not to all four: capital and turnover are measured for the preceding year rather than at a moment within it. Borrowings must exceed ₹100 crore, so exactly ₹100 crore does not trigger that limb, while deposits of exactly ₹25 crore do trigger theirs.
The internal auditor may be a chartered accountant, a cost accountant or another professional the board decides on, and may be an employee or an external appointee. A chartered accountant or cost accountant appointed to the role need not be in practice or hold a certificate of practice. That is wider than most people assume, but it is not unlimited: an employee must still fall within one of the professional categories the board accepts, and the board has to determine that person's suitability for the function. What is not permitted is for the company's statutory auditor to be its internal auditor, which section 144 prohibits outright.
Why companies outside section 138 still get asked
Two mechanisms bring internal audit into companies that section 138 does not touch.
The first is clause 3(xiv) of the auditor's report order, which requires the statutory auditor to report on whether an internal audit system commensurate with the size and nature of the business exists, and whether internal audit reports were considered. Where the order applies, a company with no internal audit at all invites a reporting comment even though no statute required it to have one.
The second is sector regulation, and the instruments changed in 2026. The banking regulator's current Internal Audit Function Directions, issued on 31 July 2026, require a risk-based internal audit framework for commercial banks and prescribe corresponding frameworks for applicable non-banking financial companies and for urban cooperative banks. They replace the two 2021 circulars, which are now on the regulator's withdrawn list.
The non-banking financial company framework covers every deposit-taking company and housing finance company irrespective of size, and non-deposit-taking companies and housing finance companies with assets of ₹5,000 crore or more. Describing the obligation as reaching only 'larger' non-banking financial companies is wrong, and it is wrong in the direction that lets a small deposit-taking company assume it is outside. The urban cooperative bank directions now apply to urban cooperative banks generally, rather than to those above an asset threshold.
For anyone tracing the history rather than the current obligation, the earlier instruments were the circular of 7 January 2021 for scheduled commercial banks other than regional rural banks, which supplemented the original 2002 mandate, and the circular of 3 February 2021 for non-banking financial companies and urban cooperative banks, extended to housing finance companies on 11 June 2021.
What the phrase should mean
A risk-based plan is not a plan that covers risky things. It is a plan whose coverage, depth and frequency are derived from an assessment that can be shown to somebody. The difference is whether you can answer the question of why you are not looking at something.
1. Build the universe
Every auditable entity: process, location, system, subsidiary, third party. If it is not on the list it cannot be consciously excluded, only forgotten.
2. Assess each on impact and likelihood
Against defined criteria, with the assessment written down and dated. The written record is what makes the plan defensible a year later.
3. Factor in control reliance
Inherent risk moderated by whether controls exist and work. A high inherent risk with strong tested controls can rationally be visited less often than a moderate one with none.
4. Set coverage, depth and frequency
Not everything annually. A defensible plan visits the highest-rated areas each year and rotates the rest on a stated cycle.
5. Keep the plan live
A plan fixed in April and delivered unchanged in March was not risk-based, because the risks moved and it did not.
The output that matters is not the report count. It is whether the audit committee can say what the organisation's principal risks are, whether coverage matched them, and what was consciously not covered.
A different question
A compliance audit asks whether the organisation is doing what a specific set of obligations requires, rather than whether the numbers are right or the controls work. It is not a statutory category and its value depends entirely on the scope being written down: which obligations, over which period, at which locations, and what level of assurance is being given.
Where it earns its place is at the boundaries: a group assuring itself about a subsidiary, a licensor about a licensee, a buyer about a target before completion, or a board about an area the statutory audit does not reach. Labour, environmental, data protection and sector-licensing obligations are the usual subjects, and all four have moved substantially since 2024.
Testing controls against building them
The independence line, again
Internal audit tests whether controls work. Designing and implementing those controls is a different engagement, covered on our governance, risk and internal control pages. One firm can do both for one client only with care, and cannot do either alongside being the statutory auditor. We will say which combination is available before an engagement letter is drafted rather than after.
Where to go next
Audit and Assurance Services
Back to the main page: the full range of engagements, how we work, and how to reach us.
Statutory Audit: Appointment, Rotation and What the Report Has to Say
Appointment and rotation, the eligibility bars, resignation, the auditor's report order and the reporting on internal financial controls, including the single most misquoted conjunction in Indian company law.
Tax Audit and the Move to the Income-tax Act 2025
The thresholds for FY 2025-26 under the old Act, what section 63 of the new Act does differently, the change of substance that widens who gets audited, and the consolidated form that replaces three.
Forensic Audit, Fraud Reporting and Investigation
The statutory fraud reporting duty and its two thresholds, the timetable that starts the day a suspicion forms, the standards a forensic engagement is conducted under, and what a forensic engagement is not.
Due Diligence, Information System Audit and ESG Assurance
Three assurance engagements that are not statutory audits: what a buyer's diligence should now cover after two years of legal change, where information system audit is mandated, and the sustainability assurance regime including the independence bar that decides who can do it.
Send an enquiry
If you have an internal audit function and cannot easily explain how this year's plan was arrived at, that is usually the most useful place to start.
Position as at 15 September 2026. Reviewed every six months.
This page is general information, not professional advice. Audit obligations in India turn on thresholds that moved recently and on standards whose effective dates have been deferred more than once. The small company definition changed on 1 December 2025, the Income-tax Act 2025 replaced the 1961 Act on 1 April 2026, two quality management standards were deferred on 31 March 2026, and a revised group audit standard has been proposed but not notified. Whether a particular obligation applies to you depends on your own numbers at your own year end. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else's, without one.