Skip to content

CS Professional · Internal and Forensic Audit

Internal Audit: Introduction and Overview: formula sheet

Full chapter guide

Key formulas

IIA definition (key elements)
Internal audit = independent + objective + assurance and consulting activity → evaluates and improves risk management, control and governance
Quote these elements in the answer. Do not replace them with 'checking of accounts'.
Scope of internal audit
Scope = financial + operational + compliance + risk management + governance + IT
Scope is decided by management or the board, so it can vary between entities.
Evolution in stages
Error and fraud detection → compliance and asset protection → control and operational review → risk-based assurance and advice
Use this as a four-point timeline when asked for evolution.
Appointment
Internal auditor: appointed by the Board (on audit committee advice where applicable), where internal audit applies. Statutory auditor: appointed by the members at the general meeting.
Under Section 138 read with Rule 13 of the Companies (Accounts) Rules, 2014, the internal auditor may be a chartered accountant, cost accountant or other professional as the Board decides, or an employee. Internal audit is mandatory only for prescribed classes of companies. Statutory auditor must be a qualified chartered accountant or firm and cannot be an employee.
Objective
Internal audit: improve operations, risk management, controls and governance. Statutory audit: express an opinion on true and fair view of financial statements.
Internal audit is advisory and forward looking; statutory audit is an assurance on past financial results.
Scope
Internal audit: decided by management or the board. Statutory audit: decided by law and auditing standards.
Management cannot restrict the scope of the statutory auditor.
Reporting
Internal audit: report to management, board or audit committee. Statutory audit: report to members.
Statutory report is a public document; internal reports are normally confidential.
Frequency
Internal audit: continuous or periodic through the year. Statutory audit: annual, after the year end.
Internal audit can be done on any period or area as planned.
Independence
Internal auditor: independent of the activity audited, but part of or engaged by the entity. Statutory auditor: independent of the entity and management.
Statutory auditor independence is backed by statutory disqualifications and removal safeguards.
Hierarchy of the three
Internal check ⊂ Internal control; Internal audit evaluates both
Internal check is one part of internal control. Internal audit is an independent review of the whole system.
Ownership test
Control and check = management operates; Audit = independent function reviews
If the person runs the process, it is control or check. If the person tests it independently, it is audit.
Timing test
Check and control = continuous, during the transaction; Audit = periodic, after or sampled
Use this to separate them quickly in a comparison answer.
Core aim
Control = achieve objectives; Check = prevent errors and fraud; Audit = assure and improve
Write the aim in one line for each concept.
Core role
Internal auditor = independent assurance + advisory on risk management, control and governance
Use this one-line definition to open most answers.
Functional and administrative reporting
Functional reporting → audit committee/board; administrative reporting → senior management
This reporting line protects independence. The audit committee typically approves the plan and the scope.
Independence vs objectivity
Independence = organisational status; Objectivity = individual mental attitude
Examiners often ask you to distinguish the two.
Management responsibility
Management owns risk and controls; internal audit evaluates and advises
If the auditor makes management decisions or designs and runs controls, objectivity is impaired.
Financial audit focus
Financial audit = accuracy and reliability of records, existence and valuation of assets
Example: verifying bank reconciliations and stock balances.
Compliance audit focus
Compliance audit = actual practice compared with laws, regulations and internal policies
Example: checking timely statutory dues payment and delegation of authority limits.
Operational audit focus
Operational audit = economy, efficiency and effectiveness of a function
Example: reviewing purchase cycle time and wastage in stores.
Management audit focus
Management audit = quality of planning, decision-making, organisation and control at management level
Broader than a single function; evaluates management performance.
Systems audit focus
Systems audit = IT controls, security, data integrity and system reliability
Example: review of access rights in the ERP.
Risk ranking idea
Audit priority rises with inherent risk and falls with strength of controls
A guiding rule, not a fixed numerical formula.
Section 138(1) - who must appoint
Prescribed class of company → must appoint an internal auditor (CA, cost accountant, other professional, or employee)
The classes are prescribed by Rule 13 of the Companies (Accounts) Rules, 2014.
Rule 13 - classes covered
Every listed company; unlisted public company meeting any prescribed limit; private company meeting any prescribed limit
Limits relate to paid-up share capital, turnover, outstanding loans or borrowings from banks and public financial institutions, and outstanding deposits. Check the exact figures in the official rule text before using them in an answer. The tests are applied to the immediately preceding financial year.
Who can be internal auditor
Chartered accountant | cost accountant | other professional decided by the Board | employee
The statutory auditor of the company cannot be appointed as its internal auditor.
Appointing authority
Board of Directors appoints (on Audit Committee recommendation where one exists)
The Audit Committee or Board decides scope, functioning, periodicity and methodology in consultation with the internal auditor.
Reporting line
Internal auditor → Audit Committee / Board
Under SEBI LODR, the Audit Committee reviews adequacy, structure, coverage and frequency of internal audit, and the internal auditor may report directly to it.
Four stages of an engagement
Planning → Execution (fieldwork) → Reporting → Follow-up
Use this as the skeleton for any process question. Add the activities under each stage.
Series of ICAI Standards on Internal Audit
100 Key concepts | 200 Internal audit management | 300 Conduct of audit assignments (including reporting) | 400 Specialised areas
Learn the four series themes. Confirm the current individual standards from the ICSI study material.
Charter versus engagement letter
Charter = function-level mandate | Engagement letter = assignment-level terms
Examiners often test this difference.
Evidence trail
Objective → Procedure → Evidence → Working paper → Finding → Recommendation
Every finding in a report must trace back through this chain.

Quick revision

  • Internal audit is an independent and objective assurance and advisory activity that adds value and improves operations.
  • Internal audit reviews risk management, control and governance processes.
  • Internal auditors report to management or the audit committee, while the statutory auditor reports to members.
  • External audit looks at the true and fair view of financial statements. Internal audit has a wider scope set by management.
  • Internal control is the system of policies and procedures. Internal audit evaluates that system.
  • Internal check is part of internal control. It divides duties so that one person's work is checked by another.
  • The internal auditor advises on weaknesses but does not take management decisions.
  • Audits can be classified by purpose, such as financial, operational and compliance audits.
  • Section 138 requires certain prescribed companies to appoint an internal auditor. Check the exact classes in the rules.
  • The internal auditor may be an individual or a firm, and the rules set out who is eligible. Verify this in the rules.
  • The engagement process runs from planning to fieldwork, reporting and follow-up.
  • In case answers, always follow this order: provision, facts, conclusion.

Common mistakes

  • Defining internal audit as checking of accounts only. Fix: Include risk management, control, governance and consulting, and say it covers non-financial areas too.
  • Saying the internal auditor makes and enforces decisions. Fix: State that the internal auditor assesses and recommends. Management implements.
  • Saying internal audit is done only by employees. Fix: State that the internal auditor may be an employee or an outside professional, such as a chartered accountant or cost accountant, as the board decides.
  • Saying the statutory auditor reports to the board. Fix: Write that the statutory auditor reports to the members, who appoint the auditor. The internal auditor reports to management or the audit committee.
  • Treating internal check and internal control as the same thing. Fix: Remember that internal check is only one part of internal control, covering division of work. Internal control also includes authorisation limits, physical safeguards, budgets and compliance procedures.
  • Saying the internal auditor is responsible for internal control. Fix: Management owns and operates internal control. The internal auditor evaluates it and recommends improvements.
  • Treating internal audit as only checking accounts and vouchers. Fix: Present the role as covering risk, control and governance, and as both assurance and advisory.
  • Saying the internal auditor is responsible for designing and running internal controls. Fix: State that management owns controls and risk. The auditor evaluates them and recommends improvements.
  • Treating operational audit and compliance audit as the same. Fix: Compliance asks whether rules are followed. Operational asks whether the work is done efficiently and effectively, even if rules are followed.
  • Confusing management audit with operational audit. Fix: Operational audit looks at a function or process. Management audit evaluates management's decisions and overall control.

Exam tips

  • Always quote the IIA definition with its key words; examiners look for independence, objectivity, assurance, consulting and risk management, control and governance.
  • Use bullets with a one-line explanation each. This scores better than a long paragraph.
  • In case-based questions, name the entity and link at least two points to its facts.
  • If asked to distinguish internal audit from other functions, first fix the concept here, then compare on appointment, scope, purpose and reporting.
  • Do not forget the evolution point when a question mentions the 'changing role' or 'modern view'.
  • Answer comparison questions in a pair format, with one short line per side under each heading. This is easy for the examiner to mark.
  • Always include the reliance point: the statutory auditor may use internal audit work, but responsibility for the opinion stays with the statutory auditor.
  • In case questions, first label each task as internal or statutory audit, then give the reason in terms of objective and reporting line.