Skip to content

CS Professional · Internal and Forensic Audit

Internal Controls: formula sheet

Full chapter guide

Key formulas

Core objectives of internal control
Safeguard assets + Reliable records and reporting + Compliance with laws + Operational efficiency + Prevent and detect error and fraud
Use this as your answer skeleton for any 'objectives' question. Add one line of explanation to each point.
Level of assurance
Internal control gives reasonable assurance, not absolute assurance
Based on SA 315 (A52). Always state this when discussing limitations.
Internal control vs internal check vs internal audit
Internal control = whole system; Internal check = division of duties within it; Internal audit = independent review of the system
Write the three as a comparison with basis, nature, responsibility and purpose.
Inherent limitations
Human error + Faulty judgment + Collusion + Management override + Cost-benefit + Changed conditions
A52 and A54 support error, judgment and design or operating failure. Collusion, override and cost-benefit are standard additions.
Internal auditor and statutory auditor services
An auditor appointed under the Act cannot provide internal audit services to the company (section 144(b))
Useful when linking independence to the internal audit function.
Five components of COSO
Control environment + Risk assessment + Control activities + Information and communication + Monitoring activities
Learn them in this order. Control environment is the foundation; monitoring closes the loop.
Count of principles
5 + 4 + 3 + 3 + 2 = 17
Control environment 5, risk assessment 4, control activities 3, information and communication 3, monitoring 2.
Three COSO objectives
Operations, Reporting, Compliance
The cube links each objective to all five components.
Principles: control environment (5)
Integrity and ethics; board independence and oversight; structure, authority and responsibility; commitment to competence; accountability
Compare with SA 315 para A76 elements such as integrity, competence, governance participation and HR policies.
Principles: risk assessment (4)
Clear objectives; identify and analyse risks; assess fraud risk; identify and assess significant change
Fraud risk is a named principle. Do not leave it out.
Principles: control activities (3)
Select and develop controls; general controls over technology; deploy through policies and procedures
SA 315 para A95 lists authorisation, performance reviews, information processing, physical controls and segregation of duties.
Principles: information and communication (3)
Use relevant quality information; communicate internally; communicate externally
External communication includes customers, regulators and shareholders.
Principles: monitoring (2)
Conduct ongoing and/or separate evaluations; evaluate and communicate deficiencies
SA 315 para A105 describes monitoring as ongoing activities, separate evaluations, or a combination.
Preventive control
Acts BEFORE the event; stops the error or fraud
Examples: authorisation limits, segregation of duties, passwords. Lower cost of error, but can be bypassed or overridden.
Detective control
Acts AFTER the event; finds the error or fraud
Examples: reconciliations, exception reports, physical stock count, review of variances. It does not stop the error, it reveals it.
Corrective control
Acts AFTER detection; fixes the error and prevents recurrence
Examples: correcting entries, recovering from backup, system patches, disciplinary action.
Directive control
Guides behaviour towards the desired outcome
Examples: policies, manuals, code of conduct, training, written instructions.
Manual vs automated (SA 315, A59-A65)
Manual: judgment, unusual items. Automated: high volume, recurring items
Manual controls can be more easily bypassed or overridden and are more error-prone. IT helps apply predefined rules consistently and reduces the risk that controls are circumvented.
Entity-level vs process-level
Entity-level: whole organisation. Process-level: one process or transaction cycle
Entity-level controls set the control environment. Process-level controls address specific risks of misstatement in a process.
Definition of internal financial controls
IFC = policies and procedures for (1) orderly and efficient conduct of business, including adherence to company policies + (2) safeguarding of assets + (3) prevention and detection of frauds and errors + (4) accuracy and completeness of accounting records + (5) timely preparation of reliable financial information
From the Explanation to Section 134(5)(e). The wording in your answer should follow these five parts.
Directors' duty on IFC
Section 134(5)(e): listed company only. Directors had laid down IFC, and the IFC are adequate and were operating effectively.
Part of the Directors' Responsibility Statement in the Board's report under Section 134(3)(c). Unlisted companies are not covered by clause (e).
Directors' duty on legal compliance systems
Section 134(5)(f): all companies. Directors had devised proper systems to ensure compliance with all applicable laws, and the systems were adequate and operating effectively.
Do not confuse with clause (e). Clause (f) is not limited to listed companies.
Auditor's reporting duty
Section 143(3)(i): report whether the company has adequate IFC with reference to financial statements in place, and whether they are operating effectively.
Exempted classes of companies exist by notification. Mention this in the answer.
Who signs the Board's report
Chairperson, if authorised by the Board. Otherwise at least two directors, one of whom is a managing director. If there is one director, that director.
Section 134(6).
Penalty for default under Section 134
Company: ₹3,00,000. Every officer in default: ₹50,000.
Section 134(8) as substituted in 2020. These are penalties, not imprisonment.
Design effectiveness test
Control properly designed ⇔ if operated as prescribed by competent persons, it can prevent or detect material misstatement on a timely basis
Assess design first. Testing operation of a badly designed control wastes time.
Operating effectiveness test
Control operates effectively ⇔ performed as designed, consistently through the period, by an authorised and competent person
Use inquiry, observation, inspection and re-performance. Inquiry alone is never enough.
Material weakness
Deficiency (or combination) with a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
Look at likelihood and magnitude, not at whether a misstatement actually occurred.
Severity ranking
Control deficiency < Significant deficiency < Material weakness
Significant deficiency is serious enough for governance attention but is less than a material weakness.
Reporting consequence
Material weakness → normally adverse opinion on IFC; scope limitation → qualified or disclaimer
The opinion is on IFC as at the balance sheet date, separate from the financial statement opinion.
Evaluation sequence
Document → Walkthrough → Test design → Test operation → Assess deficiency → Report → Follow up
Use this order in any answer. Do not test controls you have not first understood.
Deficiency assessment
Severity = Likelihood of failure × Magnitude of possible impact
A qualitative judgement, not a numeric calculation. Higher severity means escalation to senior levels.
Questionnaire reading rule
"Yes" = control present; "No" = possible weakness
Design the ICQ so that a No answer always signals a weakness. Each No must still be followed up.
Section 144 limit
Statutory auditor cannot provide internal audit services to the company
Section 144(b) bars an auditor appointed under the Act from rendering internal audit, directly or indirectly, including to its holding or subsidiary company.
Section 138 appointee
Internal auditor = chartered accountant, cost accountant or other professional decided by the Board
Section 138 applies to prescribed classes of companies. The manner and intervals of audit and reporting to the Board are set by rules.

Quick revision

  • Internal control is a process that gives reasonable, not absolute, assurance about the achievement of objectives.
  • Controls cover operations, reporting and compliance; the safeguarding of assets runs through all three.
  • Know the COSO components and map each control example to one of them.
  • Preventive controls stop errors, detective controls find them, corrective controls fix them.
  • Segregation of duties, authorisation limits and reconciliations are core control techniques.
  • Section 138: prescribed classes of companies must appoint an internal auditor who is a chartered accountant, a cost accountant or another professional decided by the Board.
  • Section 177: the Audit Committee has at least three directors, with independent directors forming a majority.
  • The Audit Committee's terms of reference include evaluation of internal financial controls and risk management systems.
  • Section 177 also covers scrutiny of inter-corporate loans and investments and approval of related party transactions.
  • The Audit Committee can obtain external professional advice and has full access to company records.
  • Section 177(9) and (10): listed and prescribed companies need a vigil mechanism with safeguards against victimisation.
  • In an evaluation report, state the weakness, its risk, your recommendation and management's response.

Common mistakes

  • Treating internal control, internal check and internal audit as the same thing. Fix: Remember: control is the system, check is a duty-division feature inside it, audit is an independent review of it.
  • Saying internal control guarantees there is no fraud or error. Fix: State that it gives only reasonable assurance and cite SA 315 (A52) with the inherent limitations.
  • Listing the components in a random order or missing one, usually monitoring. Fix: Learn the sequence as foundation, risk, action, information flow, review. Check that you have five.
  • Stating the wrong number of principles under a component, or the wrong total. Fix: Memorise 5-4-3-3-2 and check that it adds to 17.
  • Calling a bank reconciliation a preventive control. Fix: Ask when it operates. A reconciliation runs after transactions are recorded, so it is detective.
  • Confusing corrective with detective controls. Fix: Detective finds the problem. Corrective repairs it and fixes the cause. Write both words with separate examples.
  • Saying that every company's directors must state that IFC are adequate and operating effectively under Section 134(5)(e). Fix: Remember that clause (e) is for a listed company. Clause (f) on compliance systems is for all companies.
  • Writing only that controls must be 'adequate' and leaving out 'operating effectively'. Fix: Always write both words for directors and for the auditor. Adequacy is about design. Operating effectiveness is about whether the control worked over the period.
  • Treating the Guidance Note as binding law. Fix: Say the Companies Act, 2013 creates the duty, and the ICAI Guidance Note explains how to perform and report the work.
  • Relying on inquiry alone to prove operating effectiveness. Fix: Combine inquiry with observation, inspection and re-performance. Inquiry supports but does not prove.

Exam tips

  • Always include the phrase 'reasonable assurance' and cite SA 315 (A52) when the question mentions limitations.
  • For difference questions, give a table-style comparison in bullet form with at least four bases.
  • In case-based questions, name the missing control, the risk and a practical fix. Do not stop at definitions.
  • Mention that management is responsible for internal control, and the internal audit and audit committee review it.
  • Cite only sections you are certain of: 138, 144(b) and 177(4)(vii) are safe here.
  • Write the component name and the principle name for each point. Examiners reward the link between the two.
  • In case questions, tag each fact to a component before writing. This keeps the answer structured.
  • Mention the SA 315 parallel, with para A57 for the five-component split, when the question refers to audit or the statutory auditor.