Assurance is worth exactly as much as the independence and the evidence behind it
An audit opinion is a statement that someone with no interest in the answer looked at the evidence and reached a conclusion. Everything that makes assurance valuable follows from that: who may do it, what they may not also sell you, what evidence they must obtain, and what they must say when they cannot obtain it. These pages set out the ten assurance engagements we perform, what triggers each one, and the thresholds and standards that decide whether an obligation applies to you at all.
- Written against the position in September 2026, including the small company threshold change of December 2025, the new Income-tax Act, and the two quality management standards whose effective date was deferred in March 2026.
- Every threshold, section number, standard and date sits in a claims register with its source. Where a notification has been amended by a corrigendum that the usual online sources do not carry, we say so, because we have been caught by exactly that before.
- We are explicit about independence. Several of the engagements described here cannot be performed by the same firm for the same client, and we would rather tell you that at the outset than discover it at a conflict check.
Ten engagements, and what actually triggers each
| Engagement | What triggers it |
|---|---|
| Statutory audit | Every company, without exception on size. Guide 1. |
| Tax audit | Turnover or gross receipts above the statutory threshold, and from tax year 2026-27 also certain low-margin declarations. Guide 2. |
| Internal audit | Statutory for listed companies and for unlisted public and private companies above prescribed thresholds; a management choice for everyone else. Guide 3. |
| Risk-based audit | Not a separate statutory category. It is how a modern internal audit plan is built, and it is mandated as an approach for regulated financial entities. Guide 3. |
| Compliance audit | Contractual, regulatory or board-driven. Common where a group needs assurance that a subsidiary is meeting obligations the statutory audit does not cover. Guide 3. |
| Due diligence | A transaction. No statute governs it, which is exactly why scope has to be written down. Guide 5. |
| Forensic audit | Reason to believe a fraud has been committed, a whistle-blower report, a regulator, a lender, or the statutory fraud reporting duty itself. Guide 4. |
| Information system audit | Mandated for regulated financial entities and for entities regulated by the securities regulator under its cyber resilience framework. Guide 5. |
| Management audit | Board-driven. An assessment of whether management processes achieve what the board intends, rather than of whether the numbers are right. |
| Sustainability assurance | Statutory for listed entities within the reporting glide path, and increasingly contractual for their suppliers. Guide 5, and the sustainability pages. |
What one firm can and cannot do for one client
This is worth stating on the front page rather than in a footnote, because it determines who you should ask for what.
The statutory auditor cannot be the internal auditor
Section 144 of the Companies Act and the Institute's own guidance prevent it. A group that wants one firm across both is asking for something that cannot be provided, and a firm that agrees has a problem.
Building a system and auditing it are incompatible
Where a firm designs or operates a client's financial systems, that firm cannot provide assurance over them. This is the most common conflict in practice because it arises gradually rather than at appointment.
Sustainability assurance has its own, wider bar
The securities regulator bars the provider of core sustainability assurance or assessment, and its associates, from selling products or providing a long list of non-audit services to the entity or its group. It also bars the entity's internal auditor from the role while permitting the statutory auditor. Guide 5 sets out the detail, and it is the reason a firm cannot both build an ESG framework and assure it.
How an assurance engagement runs
1. Establish that we can take it
Independence and conflict checks first, including for engagements the group has with other parts of the firm. If the answer is no, it is better said now.
2. Scope against the actual obligation
Which statute or contract requires this, what it requires to be said, and to whom. For a non-statutory engagement, a written scope with exclusions, because there is no statute to fall back on.
3. Understand the business before testing it
Risk assessment, the control environment, and the areas where a misstatement would actually matter. Testing that starts before this stage tests the wrong things thoroughly.
4. Evidence, and say so when it is not there
The value of the opinion is in the willingness to qualify it. An engagement that cannot produce a qualification is not assurance.
5. Report so that it can be acted on
The formal report says what it must. The management letter says what is actually worth doing, in an order that reflects what matters.
Five guides across the ten engagements
Guides 1 and 2 are the two audits almost every company has. Guide 3 is the one that is a choice for most businesses and a requirement for some. Guide 4 is the one nobody plans for. Guide 5 covers the three engagements that arrive from outside: a buyer, a regulator, or a customer's sustainability team.
Statutory Audit: Appointment, Rotation and What the Report Has to Say
Appointment and rotation, the eligibility bars, resignation, the auditor's report order and the reporting on internal financial controls, including the single most misquoted conjunction in Indian company law.
Tax Audit and the Move to the Income-tax Act 2025
The thresholds for FY 2025-26 under the old Act, what section 63 of the new Act does differently, the change of substance that widens who gets audited, and the consolidated form that replaces three.
Internal Audit, Risk-based Audit and Compliance Audit
When internal audit is a statutory obligation and when it is a management choice, who may hold the role, how a risk-based plan is actually built, and how this sits alongside our governance and internal control work.
Forensic Audit, Fraud Reporting and Investigation
The statutory fraud reporting duty and its two thresholds, the timetable that starts the day a suspicion forms, the standards a forensic engagement is conducted under, and what a forensic engagement is not.
Due Diligence, Information System Audit and ESG Assurance
Three assurance engagements that are not statutory audits: what a buyer's diligence should now cover after two years of legal change, where information system audit is mandated, and the sustainability assurance regime including the independence bar that decides who can do it.
Where the neighbouring work sits
Governance, risk and internal control
Board effectiveness, internal financial controls design, enterprise risk management, technology risk and fraud risk frameworks. Where audit tests controls, that work builds them. See those pages.
Sustainability and governance reporting
Framework design, reporting and disclosure, and the sustainability reporting regime in full. Note the independence bar in guide 5: designing a framework and assuring it are not available from the same firm. See those pages.
Direct taxation
Tax audit sits here, but tax compliance, assessments, litigation and planning sit with the tax practice. See those pages.
Transaction advisory
Financial and tax due diligence on a deal is an advisory engagement to one party, not an assurance engagement, and it runs on a transaction timetable rather than a year end. Guide 5 covers what a 2026 diligence has to reach; the deal-side work sits with that practice. Financial and Tax Due Diligence.
Send an enquiry
Tell us which engagement you are asking about and what prompted it: a year end, a threshold you think you have crossed, a transaction, a regulator, or a reason to believe a fraud has occurred. A partner replies within one business day.
This page is general information, not professional advice. Audit obligations in India turn on thresholds that moved recently and on standards whose effective dates have been deferred more than once. The small company definition changed on 1 December 2025, the Income-tax Act 2025 replaced the 1961 Act on 1 April 2026, two quality management standards were deferred on 31 March 2026, and a revised group audit standard has been proposed but not notified. Whether a particular obligation applies to you depends on your own numbers at your own year end. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else's, without one.