Continuous assurance built into how you run the business, not just once a year.
Internal audit is an ongoing, independent evaluation of your controls, risk management and governance — designed to catch problems while they're still small and cheap to fix, rather than after year-end when a statutory auditor finds them.
Unlike a statutory audit, internal audit isn't primarily about satisfying an external reporting requirement. It's a management tool: a standing, structured check on whether your processes actually work the way you think they do.
Enquire About Internal AuditMandatory for certain classes of companies under the Companies Act, and valuable for many more as a management discipline.
Every listed company, regardless of size, must have an internal audit function under Section 138 of the Companies Act, 2013.
Unlisted public companies with paid-up capital ₹50 crore+, turnover ₹200 crore+, outstanding loans/borrowings ₹100 crore+, or outstanding deposits ₹25 crore+.
Private companies with turnover ₹200 crore+, or outstanding loans/borrowings from banks or financial institutions above ₹100 crore.
Any growing business that wants independent assurance over its controls before a lender, investor, or board asks for it.
Having these ready before fieldwork begins keeps things on schedule.
A risk-based cycle that repeats — so control gaps get caught early, not at year-end.
A clear, prioritised write-up of findings for each cycle, not a wall of exceptions.
A living document mapping key risks to the controls meant to address them.
Agreed corrective actions with owners and target dates.
Visibility on whether last cycle's findings actually got closed.
Only if you cross the turnover or borrowing thresholds under the Companies Act. Below that, it's optional but often still a good idea, especially if you're scaling fast.
Statutory audit is an annual, externally reported opinion on your financial statements. Internal audit is an ongoing, internally focused review of processes and controls, usually more frequent and much more operational in nature.
Generally no — independence requirements mean the statutory auditor should stay separate from the internal audit function of the same entity.
It depends on risk. High-risk areas like cash, payroll, or procurement might get reviewed quarterly; lower-risk areas annually. We'll propose a cycle based on your risk profile.
Both — some clients want full-coverage internal audit, others want us focused on one or two high-risk processes. Scope is agreed upfront.
Tell us your size and sector, and we'll propose a risk-based audit plan.