Internal and Forensic Audit · Special Points relating to Internal Audit in various Entities
Internal Audit in Insurance Companies: Scope and IRDAI Expectations
Updated 11 October 2026 · Fact-checked
Internal audit in an insurance company is an independent, risk-based review of underwriting, premium, claims, reinsurance, investments, IT and compliance. Under IRDAI's corporate governance and related guidelines, it reports to the Audit Committee. To answer a question, name the area, the risk, the checks, the evidence and the report.
Understand Internal Audit in Insurance Companies
An insurer sells promises. It collects premium today and pays claims later, often years later. So its main risks are wrong pricing, weak underwriting, false or inflated claims, poor reinsurance cover and bad investments. Internal audit tests whether controls handle these risks.
Insurance is regulated by the IRDAI (Insurance Regulatory and Development Authority of India). IRDAI's governance and risk management guidelines expect an insurer to have an internal audit function that is independent of operations, has a board-approved audit policy and plan, and reports to the Audit Committee of the Board. Check the exact circular wording in your study material for the latest version.
The internal auditor does not decide pricing or settle claims. The auditor checks that management follows its approved policies, IRDAI rules and the Insurance Act, and that records are accurate and complete.
The usual scope covers these areas:
- Underwriting and premium: risk selection, rate and product compliance, premium collection and receipt, agent and intermediary commission, premium in advance and outstanding, lapsed or cancelled policies.
- Claims: intimation, registration, survey and investigation, reserving, approval limits, settlement, recovery from salvage and subrogation, repudiation, and fraud indicators.
- Reinsurance: treaty and facultative cessions, correct share ceded, timely recovery from reinsurers, credit exposure to reinsurers and accounts reconciliation.
- Investments: compliance with the approved investment policy and IRDAI investment norms, approval and limits, custody of securities, valuation, income accrual and segregation of policyholders' and shareholders' funds.
- Other areas: actuarial data inputs, IT and cyber controls, policyholder grievances, AML/KYC, outsourcing, solvency and regulatory returns.
A good audit is risk-based. High-value claims, large reinsurance recoveries and unusual investment trades get more attention than routine items.
Key rules to remember
- Net premium retained
- Net premium = Gross premium − Premium ceded to reinsurers
- Use it to check that cessions under reinsurance treaties are correctly booked.
- Claims ratio (incurred)
- Incurred claims ratio = Net claims incurred ÷ Net earned premium × 100
- A sudden change is an analytical red flag that points to reserving or claims-processing problems.
- Reporting line
- Internal audit → Audit Committee of the Board
- Independence from operations is the key principle. Administrative line to the CEO is acceptable; functional line is to the Audit Committee.
- Audit cycle for any area
- Risk → Control → Test → Evidence → Finding → Recommendation
- Use this chain to structure every written answer.
How to solve Internal Audit in Insurance Companies questions
Use the same frame for any question on internal audit of an insurer. Case-based questions reward structure.
- 1Identify the area asked: premium, claims, reinsurance, investments, or the overall function.
- 2State the regulatory background in one or two lines: IRDAI expectations and Audit Committee oversight.
- 3List the key risks in that area using the facts given, such as fraud, delay, leakage or non-compliance.
- 4Write the controls the auditor expects to see: approvals, limits, segregation of duties, reconciliations, system checks.
- 5Give the audit procedures: what to test, which documents to inspect, sample basis and analytical review.
- 6Apply the facts of the case and spot the lapse, naming the specific control that failed.
- 7Conclude with the finding, the risk impact and a practical recommendation, and say it is reported to the Audit Committee.
Quickest way: Area, Risk, Test, Report
When to use it: When time is short and you need a full answer in a few lines.
- Write the area in one line.
- List 3 risks and 3 matching controls in bullets.
- Add 3 audit tests with the document or data used.
- End with the finding and the recommendation to the Audit Committee.
Common mistakes in Internal Audit in Insurance Companies
Treating internal audit as the statutory audit of the insurer's accounts.
Both look at financial records, so the purposes get mixed.
Fix: Say that internal audit is a continuous, risk-based review for management and the Audit Committee, covering controls and compliance, not an opinion on financial statements.
Discussing only premium and claims and leaving out reinsurance and investments.
Premium and claims feel more familiar.
Fix: Cover all four named areas whenever the question asks for scope, even if briefly.
Saying the internal auditor approves or settles claims.
Students confuse review with operational responsibility.
Fix: The auditor tests whether claims were processed per policy, delegation limits and regulations. Management decides claims.
Giving generic controls with no insurance content.
Students reuse answers from other entity types.
Fix: Use insurance terms: survey report, reserve, treaty, cession, salvage, subrogation, policyholders' funds.
Quoting an IRDAI circular number or section that you are unsure about.
Students try to look precise.
Fix: Refer to 'IRDAI guidelines' and the Insurance Act in general terms unless you are certain of the reference.
Stopping at the finding without a recommendation or reporting line.
Time runs out.
Fix: Always close with the recommendation, management response and follow-up reporting to the Audit Committee.
Worked examples
Example 1
The internal auditor of a general insurer, Suraksha General Insurance Ltd, is reviewing motor claims. She finds that several large claims were settled by an officer above his approval limit, and surveyor reports were missing in some files. Explain the audit approach and conclusion.
Show the solution
- Area: claims audit under the risk-based plan approved by the Audit Committee.
- Risks: unauthorised settlement, inflated or fraudulent claims, payment without verification, wrong reserving.
- Expected controls: a delegation of authority matrix, mandatory surveyor report above a threshold, system block on settlement beyond limits, maker-checker review.
- Procedures: select large claims by value, match approval against the delegation matrix, inspect survey reports, policy validity and premium receipt, compare paid amount to the surveyor's assessment, and check reserves.
- Findings: settlements beyond authority show breach of delegation control. Missing surveyor reports mean payment without adequate evidence.
- Recommendation: ratify or recover as appropriate, enforce system limits, make the report mandatory before approval, and expand sampling to other officers and branches.
Answer: The auditor should report both lapses as control breaches in claims processing, rate the risk as high, recommend system-enforced limits and mandatory survey reports, and report to the Audit Committee with follow-up on corrective action.
Example 2
An insurer's gross premium for a year is ₹500 crore and premium ceded under reinsurance treaties as per books is ₹80 crore. The treaty terms say 20% of gross premium is to be ceded. What should the auditor conclude and do?
Show the solution
- Expected cession = 20% × ₹500 crore = ₹100 crore.
- Booked cession = ₹80 crore.
- Difference = ₹100 crore − ₹80 crore = ₹20 crore under-ceded.
- Net premium retained as per books = ₹500 crore − ₹80 crore = ₹420 crore. Expected = ₹500 crore − ₹100 crore = ₹400 crore.
- The insurer has retained ₹20 crore more risk than the treaty intends, or the cession is understated in the books.
- Audit procedures: check treaty terms, premium bordereaux, any exclusions or cancelled policies that explain the gap, and reinsurer statements of account.
Answer: Cession is under-booked by ₹20 crore, so net premium is overstated by ₹20 crore unless a valid explanation is found. The auditor should investigate, report the gap, and recommend correction and a periodic reconciliation with reinsurers.
Exam tips
- Structure answers by the four areas: premium, claims, reinsurance, investments, and add IT and compliance if marks allow.
- Always mention independence and reporting to the Audit Committee.
- In case questions, name the exact control that failed, such as delegation limits or reconciliation, before giving recommendations.
- Show small calculations clearly, like cession checks, and state the effect on net premium.
- Avoid unsure circular numbers. Say 'as per IRDAI guidelines' and focus on the substance.
Practice questions from Special Points relating to Internal Audit in various Entities
- While auditing a municipal corporation's works department, the internal auditor notices that several small payments to one contractor are ea…
- Suraksha Life Insurance Ltd's internal audit team is reviewing the underwriting function. A sample of proposal forms shows that several high…
- Sahyadri Bank Ltd. has a large network of branches. Its internal audit head wants the audit plan to direct more audit hours to branches hand…
- While auditing the claims department of Bharat General Insurance Ltd, the internal auditor notices that one surveyor has been appointed for …
- An internal auditor is reviewing premium collection at Navjeevan Insurance Ltd, which collects premiums through agents and also via online p…
Internal Audit in Insurance Companies in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Audit in Insurance Companies: frequently asked questions
Is internal audit mandatory for insurance companies in India?
Yes, IRDAI's governance and risk management guidelines require insurers to maintain an internal audit function. It must be independent and report to the Audit Committee. Companies Act provisions on internal audit may also apply to insurers that are companies of the prescribed class.
What are the main areas covered in internal audit of a general insurer?
They are underwriting and premium, claims, reinsurance, investments, IT systems, regulatory compliance and grievance handling. The audit plan is set on risk, so high-value and high-risk areas get more coverage.
How is internal audit of claims different from underwriting audit?
Underwriting audit checks risk selection, pricing compliance and premium collection. Claims audit checks intimation, survey, approval limits, reserving, settlement and fraud signs. Both test controls, but at different stages of the policy life.
How should I answer a CS Professional case question on this topic?
Name the area, list risks and controls, apply the facts to find the lapse, and conclude with a recommendation and reporting to the Audit Committee. Keep each part short and tied to the case.