Assurance Service

Internal Audit

Continuous assurance built into how you run the business, not just once a year.

Purpose

Why internal audit matters

Internal audit is an ongoing, independent evaluation of your controls, risk management and governance — designed to catch problems while they're still small and cheap to fix, rather than after year-end when a statutory auditor finds them.

Unlike a statutory audit, internal audit isn't primarily about satisfying an external reporting requirement. It's a management tool: a standing, structured check on whether your processes actually work the way you think they do.

Enquire About Internal Audit
Governing LawCompanies Act, 2013 · Sec 138
Mandatory ForListed cos; large unlisted/private cos
FrequencyQuarterly / half-yearly / continuous
Conducted ByChartered Accountant or firm
Typical DurationOngoing engagement
Key OutputInternal Audit Report each cycle
Requirement & Applicability

Who needs an internal audit

Mandatory for certain classes of companies under the Companies Act, and valuable for many more as a management discipline.

Getting Started

Documents & information we'll need

Having these ready before fieldwork begins keeps things on schedule.

How We Work

Our internal audit process

A risk-based cycle that repeats — so control gaps get caught early, not at year-end.

  1. Step 1: Scoping. Risk-based planning to decide which processes and locations get audited this cycle.
  2. Step 2: Walkthroughs. Sit with process owners to understand how each process actually operates today.
  3. Step 3: Control Testing. Test whether the controls that are supposed to exist actually operate as designed.
  4. Step 4: Sampling. Substantive testing of transaction samples to check for errors and irregularities.
  5. Step 5: Gap Analysis. Identify and rate control gaps by the risk they actually pose to the business.
  6. Step 6: Management Response. Share draft findings, discuss root causes, and agree corrective actions.
  7. Step 7: Report & Follow-up. Issue the final report and track agreed actions through to closure.
What You Receive

Deliverables

01

Internal Audit Report

A clear, prioritised write-up of findings for each cycle, not a wall of exceptions.

02

Risk & Control Matrix

A living document mapping key risks to the controls meant to address them.

03

Management Action Plan

Agreed corrective actions with owners and target dates.

04

Follow-up Tracker

Visibility on whether last cycle's findings actually got closed.

Common Questions

Frequently asked questions

Is internal audit mandatory for my private company?

Only if you cross the turnover or borrowing thresholds under the Companies Act. Below that, it's optional but often still a good idea, especially if you're scaling fast.

How is this different from a statutory audit?

Statutory audit is an annual, externally reported opinion on your financial statements. Internal audit is an ongoing, internally focused review of processes and controls, usually more frequent and much more operational in nature.

Can our statutory auditor also do our internal audit?

Generally no — independence requirements mean the statutory auditor should stay separate from the internal audit function of the same entity.

How often should internal audit run?

It depends on risk. High-risk areas like cash, payroll, or procurement might get reviewed quarterly; lower-risk areas annually. We'll propose a cycle based on your risk profile.

Do you audit specific processes or the whole company?

Both — some clients want full-coverage internal audit, others want us focused on one or two high-risk processes. Scope is agreed upfront.

Ready to put internal audit on a schedule?

Tell us your size and sector, and we'll propose a risk-based audit plan.

Get in Touch
← Back to

Assurance Service

See all audit & assurance offerings — internal, tax, forensic, process, concurrent and compliance audits.