Cost and Management Audit · Internal Control and Internal Audit
Standards on Internal Audit and the Engagement Process
Updated 11 October 2026 · Fact-checked
Standards on Internal Audit (SIAs) are professional standards issued by ICAI that set the minimum benchmark for how internal audits are planned, performed and reported. An engagement moves through stages: planning and risk assessment, audit programme, fieldwork and evidence, reporting, and follow-up. In exams, apply each stage to the case given.
Understand Internal Audit Standards and Engagement Process
An internal audit is an independent check of a company's operations, controls and risk management, done for management and the audit committee. It is not the statutory audit of the financial statements. Its aim is to tell the board whether controls work and where they fail.
To keep the quality of this work consistent, the Institute of Chartered Accountants of India issues Standards on Internal Audit (SIAs). They cover areas such as planning, internal controls, risk assessment, evidence, documentation, reporting and using the work of experts. Section 138 of the Companies Act, 2013 requires certain classes of companies to appoint an internal auditor. The internal auditor may be a chartered accountant, a cost accountant or another professional the Board decides. So you must know the standards even though the issuing body is ICAI. Do not recite SIA numbers unless you are sure of them. Describe what each standard requires.
The engagement process follows a logical order. First you understand the entity and agree the scope and terms with those charged with governance. Then you assess risk to decide where to spend effort. You write an audit programme, which is a list of procedures for each area. You carry out fieldwork, collect evidence and record it in working papers. You discuss findings with the auditee, then issue a report. Finally you follow up to check that management has acted.
The key idea is risk-based auditing. You cannot test everything, so you test hardest where the chance and impact of failure are highest. Every stage links to this idea. Planning sets the risk focus, the programme turns it into tests, fieldwork gathers evidence, and the report ranks findings by risk.
A good report is specific. For each finding it states the condition found, the criteria or standard expected, the cause, the effect or risk, the recommendation, and management's response. Follow-up closes the loop. Without it, the audit changes nothing.
Key rules to remember
- Engagement stages
- Understand entity → Risk assessment → Audit plan and programme → Fieldwork and evidence → Reporting → Follow-up
- Use this order as the skeleton for any process question.
- Finding structure
- Condition + Criteria + Cause + Effect + Recommendation + Management response
- Each audit observation should cover all six elements.
- Risk prioritisation
- Risk = Likelihood × Impact
- A guide for ranking areas. Rate both factors on the same scale, such as 1 to 5.
- Appointment of internal auditor
- Section 138: prescribed class of companies must appoint an internal auditor, who may be a chartered accountant, a cost accountant or another professional decided by the Board
- The Board decides the scope, functioning and periodicity, with audit committee input where it exists. Class details come from the Rules.
How to solve Internal Audit Standards and Engagement Process questions
Use this method for any question on SIAs or on the internal audit engagement. Always tie your answer to the case facts.
- 1Read the question and identify which stage or standard it tests: planning, risk, programme, evidence, reporting or follow-up.
- 2State the principle or requirement of the relevant standard in one or two plain sentences.
- 3Link it to the facts. Name the entity, process or risk in the case, such as purchase-to-pay or inventory.
- 4List the specific procedures or actions: what you will inspect, inquire about, observe, recompute or confirm.
- 5Rank by risk. Say which area gets more testing and why.
- 6Close with the output: working paper, report finding, recommendation or follow-up action, and state who it goes to.
Quickest way: Stage-by-stage skeleton
When to use it: Use it when you have under ten minutes for a descriptive question on the engagement process or the audit programme.
- Write the six stages as headings in one line each.
- Under each heading add one point drawn from the case.
- For programme questions use the columns: objective, risk, procedure, sample, evidence, reference.
- Finish with report structure and follow-up in two lines.
Common mistakes in Internal Audit Standards and Engagement Process
Treating internal audit as a smaller statutory audit.
Students know statutory audit better and copy its framing.
Fix: Say internal audit is for management, covers operations and controls, and its scope is set by the Board, not by the Companies Act audit report.
Quoting SIA numbers and titles from memory with errors.
Students try to memorise the full list.
Fix: Describe the requirement in plain words. Give a number only if you are certain it is correct.
Writing a generic programme with no link to risk.
Students list standard procedures without reading the case.
Fix: Start from the risk in the case, then write procedures that address that risk.
Stopping the answer at the report.
Students see reporting as the end of the work.
Fix: Add follow-up: track agreed actions, re-test, and report open items to the audit committee.
Writing findings without cause and effect.
Students describe only what went wrong.
Fix: Use condition, criteria, cause, effect and recommendation for each finding.
Worked examples
Example 1
Sharma Components Ltd, a Pune auto-parts maker, has engaged you as internal auditor for its purchase-to-pay cycle. List the steps you will take in planning and risk assessment.
Show the solution
- Understand the process: walk through requisition, purchase order, goods receipt, invoice matching and payment. Note systems and people involved.
- Review past audit reports, the budget and any changes such as a new ERP or new vendors.
- Identify risks: duplicate payments, fictitious vendors, purchases without approval, price variance from the agreed rate.
- Rate each risk by likelihood and impact. For example, duplicate payments may be medium likelihood and high impact.
- Decide scope, timing, team and sample sizes. Give more testing to high-rated risks.
- Agree scope and timeline with management and the audit committee, and document the plan.
Answer: Understand the process, review history and changes, identify and rate risks, set scope, team and sample sizes by risk, and agree the plan with the audit committee. Document each step.
Example 2
During fieldwork at Kaveri Textiles Ltd you find that 12 of 60 sampled purchase invoices were paid without a goods receipt note. Draft the audit finding and the follow-up approach.
Show the solution
- Condition: 12 of 60 sampled invoices were paid without a goods receipt note, which is 20% of the sample. Compute 12 ÷ 60 = 0.20.
- Criteria: company policy requires a three-way match of purchase order, goods receipt note and invoice before payment.
- Cause: the system allows manual override of the match, and approvals are not reviewed.
- Effect: risk of paying for goods not received, and of overstated payables and inventory. Rate this finding as high risk.
- Recommendation: block payment without a match, restrict override rights and review overrides monthly.
- Management response: record the agreed action, owner and date.
- Follow-up: after the agreed date, re-test a fresh sample, confirm the system change, and report any open item to the audit committee.
Answer: Finding: 20% of the sampled invoices (12 of 60) were paid without a goods receipt note, against the three-way match policy. The cause is the manual override and the effect is a high risk of loss. Recommend a system block and restricted override. Follow up with a re-test and report open items to the audit committee.
Exam tips
- Case-based questions reward answers that use the entity's own facts. Mention the business, process and risk by name.
- For programme questions, present a small table-like list with objective, procedure and evidence for each step.
- Give the order of the engagement stages and end with follow-up. Examiners often look for it.
- Keep Section 138 points accurate: the Board decides scope and periodicity, and the auditor may be a chartered accountant, a cost accountant or another professional.
- For MCQs, remember that internal audit is independent of operations but reports to the board or audit committee, not to the process owner.
Practice questions from Internal Control and Internal Audit
- Consider these statements on the vigil mechanism under Section 177 of the Companies Act, 2013. (i) The mechanism must provide adequate safeg…
- According to the guidance in SA 315 on audit evidence about the control environment, what may the auditor consider regarding the internal au…
- Under Section 177 of the Companies Act, 2013, which of the following is a right of the statutory auditors and key managerial personnel in re…
- Under SA 315 as quoted, in considering audit evidence about the control environment, the auditor may also consider which of the following re…
- Which statement about the vigil mechanism under Section 177 of the Companies Act, 2013 is correct?
Internal Audit Standards and Engagement Process in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Audit Standards and Engagement Process: frequently asked questions
Do I need to memorise all Standards on Internal Audit?
Know the themes: planning, risk assessment, internal controls, evidence, documentation, reporting and use of experts. In the exam, explain what a standard requires and apply it to the case. Give an SIA number only if you are sure of it.
What is the difference between an audit plan and an audit programme?
The plan sets the overall scope, timing, resources and risk focus of the engagement. The programme lists the detailed procedures for each area, with samples and evidence expected.
What should an internal audit report contain?
It should state scope, objectives and period, then each finding with condition, criteria, cause, effect and recommendation, plus management's response. It should also give an overall conclusion and be addressed to the Board or audit committee.
Why is follow-up part of the engagement?
Without follow-up, you do not know if management fixed the problem. You track agreed actions, re-test where needed and report overdue items to those charged with governance.