CS Professional · Internal and Forensic Audit
Internal Controls: formula sheet
Key formulas
- Core objectives of internal control
- Safeguard assets + Reliable records and reporting + Compliance with laws + Operational efficiency + Prevent and detect error and fraud
- Use this as your answer skeleton for any 'objectives' question. Add one line of explanation to each point.
- Level of assurance
- Internal control gives reasonable assurance, not absolute assurance
- Based on SA 315 (A52). Always state this when discussing limitations.
- Internal control vs internal check vs internal audit
- Internal control = whole system; Internal check = division of duties within it; Internal audit = independent review of the system
- Write the three as a comparison with basis, nature, responsibility and purpose.
- Inherent limitations
- Human error + Faulty judgment + Collusion + Management override + Cost-benefit + Changed conditions
- A52 and A54 support error, judgment and design or operating failure. Collusion, override and cost-benefit are standard additions.
- Internal auditor and statutory auditor services
- An auditor appointed under the Act cannot provide internal audit services to the company (section 144(b))
- Useful when linking independence to the internal audit function.
- Five components of COSO
- Control environment + Risk assessment + Control activities + Information and communication + Monitoring activities
- Learn them in this order. Control environment is the foundation; monitoring closes the loop.
- Count of principles
- 5 + 4 + 3 + 3 + 2 = 17
- Control environment 5, risk assessment 4, control activities 3, information and communication 3, monitoring 2.
- Three COSO objectives
- Operations, Reporting, Compliance
- The cube links each objective to all five components.
- Principles: control environment (5)
- Integrity and ethics; board independence and oversight; structure, authority and responsibility; commitment to competence; accountability
- Compare with SA 315 para A76 elements such as integrity, competence, governance participation and HR policies.
- Principles: risk assessment (4)
- Clear objectives; identify and analyse risks; assess fraud risk; identify and assess significant change
- Fraud risk is a named principle. Do not leave it out.
- Principles: control activities (3)
- Select and develop controls; general controls over technology; deploy through policies and procedures
- SA 315 para A95 lists authorisation, performance reviews, information processing, physical controls and segregation of duties.
- Principles: information and communication (3)
- Use relevant quality information; communicate internally; communicate externally
- External communication includes customers, regulators and shareholders.
- Principles: monitoring (2)
- Conduct ongoing and/or separate evaluations; evaluate and communicate deficiencies
- SA 315 para A105 describes monitoring as ongoing activities, separate evaluations, or a combination.
- Preventive control
- Acts BEFORE the event; stops the error or fraud
- Examples: authorisation limits, segregation of duties, passwords. Lower cost of error, but can be bypassed or overridden.
- Detective control
- Acts AFTER the event; finds the error or fraud
- Examples: reconciliations, exception reports, physical stock count, review of variances. It does not stop the error, it reveals it.
- Corrective control
- Acts AFTER detection; fixes the error and prevents recurrence
- Examples: correcting entries, recovering from backup, system patches, disciplinary action.
- Directive control
- Guides behaviour towards the desired outcome
- Examples: policies, manuals, code of conduct, training, written instructions.
- Manual vs automated (SA 315, A59-A65)
- Manual: judgment, unusual items. Automated: high volume, recurring items
- Manual controls can be more easily bypassed or overridden and are more error-prone. IT helps apply predefined rules consistently and reduces the risk that controls are circumvented.
- Entity-level vs process-level
- Entity-level: whole organisation. Process-level: one process or transaction cycle
- Entity-level controls set the control environment. Process-level controls address specific risks of misstatement in a process.
- Definition of internal financial controls
- IFC = policies and procedures for (1) orderly and efficient conduct of business, including adherence to company policies + (2) safeguarding of assets + (3) prevention and detection of frauds and errors + (4) accuracy and completeness of accounting records + (5) timely preparation of reliable financial information
- From the Explanation to Section 134(5)(e). The wording in your answer should follow these five parts.
- Directors' duty on IFC
- Section 134(5)(e): listed company only. Directors had laid down IFC, and the IFC are adequate and were operating effectively.
- Part of the Directors' Responsibility Statement in the Board's report under Section 134(3)(c). Unlisted companies are not covered by clause (e).
- Directors' duty on legal compliance systems
- Section 134(5)(f): all companies. Directors had devised proper systems to ensure compliance with all applicable laws, and the systems were adequate and operating effectively.
- Do not confuse with clause (e). Clause (f) is not limited to listed companies.
- Auditor's reporting duty
- Section 143(3)(i): report whether the company has adequate IFC with reference to financial statements in place, and whether they are operating effectively.
- Exempted classes of companies exist by notification. Mention this in the answer.
- Who signs the Board's report
- Chairperson, if authorised by the Board. Otherwise at least two directors, one of whom is a managing director. If there is one director, that director.
- Section 134(6).
- Penalty for default under Section 134
- Company: ₹3,00,000. Every officer in default: ₹50,000.
- Section 134(8) as substituted in 2020. These are penalties, not imprisonment.
- Design effectiveness test
- Control properly designed ⇔ if operated as prescribed by competent persons, it can prevent or detect material misstatement on a timely basis
- Assess design first. Testing operation of a badly designed control wastes time.
- Operating effectiveness test
- Control operates effectively ⇔ performed as designed, consistently through the period, by an authorised and competent person
- Use inquiry, observation, inspection and re-performance. Inquiry alone is never enough.
- Material weakness
- Deficiency (or combination) with a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
- Look at likelihood and magnitude, not at whether a misstatement actually occurred.
- Severity ranking
- Control deficiency < Significant deficiency < Material weakness
- Significant deficiency is serious enough for governance attention but is less than a material weakness.
- Reporting consequence
- Material weakness → normally adverse opinion on IFC; scope limitation → qualified or disclaimer
- The opinion is on IFC as at the balance sheet date, separate from the financial statement opinion.
- Evaluation sequence
- Document → Walkthrough → Test design → Test operation → Assess deficiency → Report → Follow up
- Use this order in any answer. Do not test controls you have not first understood.
- Deficiency assessment
- Severity = Likelihood of failure × Magnitude of possible impact
- A qualitative judgement, not a numeric calculation. Higher severity means escalation to senior levels.
- Questionnaire reading rule
- "Yes" = control present; "No" = possible weakness
- Design the ICQ so that a No answer always signals a weakness. Each No must still be followed up.
- Section 144 limit
- Statutory auditor cannot provide internal audit services to the company
- Section 144(b) bars an auditor appointed under the Act from rendering internal audit, directly or indirectly, including to its holding or subsidiary company.
- Section 138 appointee
- Internal auditor = chartered accountant, cost accountant or other professional decided by the Board
- Section 138 applies to prescribed classes of companies. The manner and intervals of audit and reporting to the Board are set by rules.
Quick revision
- Internal control is a process that gives reasonable, not absolute, assurance about the achievement of objectives.
- Controls cover operations, reporting and compliance; the safeguarding of assets runs through all three.
- Know the COSO components and map each control example to one of them.
- Preventive controls stop errors, detective controls find them, corrective controls fix them.
- Segregation of duties, authorisation limits and reconciliations are core control techniques.
- Section 138: prescribed classes of companies must appoint an internal auditor who is a chartered accountant, a cost accountant or another professional decided by the Board.
- Section 177: the Audit Committee has at least three directors, with independent directors forming a majority.
- The Audit Committee's terms of reference include evaluation of internal financial controls and risk management systems.
- Section 177 also covers scrutiny of inter-corporate loans and investments and approval of related party transactions.
- The Audit Committee can obtain external professional advice and has full access to company records.
- Section 177(9) and (10): listed and prescribed companies need a vigil mechanism with safeguards against victimisation.
- In an evaluation report, state the weakness, its risk, your recommendation and management's response.
Common mistakes
- Treating internal control, internal check and internal audit as the same thing. Fix: Remember: control is the system, check is a duty-division feature inside it, audit is an independent review of it.
- Saying internal control guarantees there is no fraud or error. Fix: State that it gives only reasonable assurance and cite SA 315 (A52) with the inherent limitations.
- Listing the components in a random order or missing one, usually monitoring. Fix: Learn the sequence as foundation, risk, action, information flow, review. Check that you have five.
- Stating the wrong number of principles under a component, or the wrong total. Fix: Memorise 5-4-3-3-2 and check that it adds to 17.
- Calling a bank reconciliation a preventive control. Fix: Ask when it operates. A reconciliation runs after transactions are recorded, so it is detective.
- Confusing corrective with detective controls. Fix: Detective finds the problem. Corrective repairs it and fixes the cause. Write both words with separate examples.
- Saying that every company's directors must state that IFC are adequate and operating effectively under Section 134(5)(e). Fix: Remember that clause (e) is for a listed company. Clause (f) on compliance systems is for all companies.
- Writing only that controls must be 'adequate' and leaving out 'operating effectively'. Fix: Always write both words for directors and for the auditor. Adequacy is about design. Operating effectiveness is about whether the control worked over the period.
- Treating the Guidance Note as binding law. Fix: Say the Companies Act, 2013 creates the duty, and the ICAI Guidance Note explains how to perform and report the work.
- Relying on inquiry alone to prove operating effectiveness. Fix: Combine inquiry with observation, inspection and re-performance. Inquiry supports but does not prove.
Exam tips
- Always include the phrase 'reasonable assurance' and cite SA 315 (A52) when the question mentions limitations.
- For difference questions, give a table-style comparison in bullet form with at least four bases.
- In case-based questions, name the missing control, the risk and a practical fix. Do not stop at definitions.
- Mention that management is responsible for internal control, and the internal audit and audit committee review it.
- Cite only sections you are certain of: 138, 144(b) and 177(4)(vii) are safe here.
- Write the component name and the principle name for each point. Examiners reward the link between the two.
- In case questions, tag each fact to a component before writing. This keeps the answer structured.
- Mention the SA 315 parallel, with para A57 for the five-component split, when the question refers to audit or the statutory auditor.