Internal audit and statutory audit both examine a company's financial and control environment, but they are not substitutes for each other. Their objectives, appointment, reporting lines, scope and outputs are different. A company can have a strong statutory audit and still need a much deeper internal-audit programme to identify operational, compliance and control weaknesses during the year.
The legal starting point is the Companies Act, 2013. Section 138 on India Code deals with internal audit for prescribed classes of companies. Section 139 on India Code deals with appointment of the company's statutory auditor.
What is internal audit?
Internal audit is an assurance and advisory activity focused on the organisation's risks, controls, governance and processes. Section 138 requires prescribed classes of companies to appoint an internal auditor to conduct internal audit of the company's functions and activities. The section permits the internal auditor to be a chartered accountant, cost accountant or another professional decided by the Board, subject to the applicable rules.
ICAI's Compendium of Standards on Internal Audit provides the current professional framework. ICAI's February 2026 compendium is stated to be applicable from 1 April 2026. The framework covers subjects such as internal controls, risk management, governance, compliance, management of the internal-audit function, overall planning and individual assignments.
What is statutory audit?
Statutory audit is the audit required by company law. Section 139 governs appointment of auditors, while Chapter X of the Companies Act contains the wider statutory-audit framework. The statutory auditor's work is directed toward the audit and reporting responsibilities imposed by law and the applicable auditing standards.
A key qualification difference is visible in the Act itself. Section 138 allows the internal-auditor role to be filled from a broader set of professionals as permitted by the provision and rules. For the statutory auditor, the Companies Act, 2013 provides in section 141 that a person is eligible for appointment as auditor of a company only if the person is a chartered accountant, with firms subject to the conditions stated in that section.
Internal audit vs statutory audit: the practical differences
- Primary purpose: Internal audit helps evaluate and improve risk management, controls, governance and processes. Statutory audit fulfils an independent external reporting obligation under company law.
- Legal trigger: Section 138 makes internal audit mandatory for prescribed classes of companies. Statutory audit sits within the general company-audit framework under Chapter X, including section 139.
- Who can perform it: Section 138 permits a chartered accountant, cost accountant or other professional as decided by the Board, subject to the rules. Statutory-auditor eligibility is governed by section 141.
- Scope: Internal audit can range across procurement, sales, inventory, payroll, IT, compliance, fraud risks, treasury, operations and other processes depending on the risk-based plan. Statutory audit is driven by the statutory financial-statement audit and reporting framework.
- Frequency: Internal audit is often performed throughout the year through periodic assignments. Statutory audit is anchored to the annual financial-reporting cycle, although audit work can of course be planned and performed before year-end.
- Reporting: Internal-audit observations are ordinarily reported through the governance structure established by the company and Board. The statutory auditor issues reports required under company law to the relevant users of the financial statements.
Why internal audit should not become a duplicate statutory audit
A weak internal-audit plan sometimes repeats financial-statement checking that the statutory auditor will later perform, while leaving major operational risks untouched. That wastes the opportunity created by internal audit.
A better plan starts with the business objectives and risk universe. ICAI's Generic Internal Audit Guides include a Technical Guide on Risk Based Internal Audit and an Internal Audit Checklist. ICAI's 2024 Internal Audit Checklist describes a process-oriented approach based on risk exposure, control effectiveness and data analytics rather than a narrow voucher-checking exercise.
Example: procurement process
Consider a manufacturing company with ₹300 crore of annual purchases. An internal-audit assignment may examine vendor onboarding, conflict-of-interest declarations, purchase-order approvals, price comparisons, three-way matching, duplicate invoices, user-access rights, emergency purchases and data patterns indicating control overrides. The objective is to determine whether procurement risks are identified and controlled effectively.
The statutory auditor may also test purchases because they affect the financial statements. But that testing is performed in the context of the statutory audit objectives. The two teams may use some of the same records, yet their purpose and depth of process review can be very different.
Can the statutory auditor rely on internal-audit work?
The existence of internal audit does not transfer the statutory auditor's responsibility to the internal auditor. The statutory auditor remains responsible for the statutory audit opinion and must perform work required by the applicable auditing framework. In practice, however, a well-designed internal-audit function can improve the control environment, surface issues earlier and provide useful organisational knowledge.
Companies should therefore coordinate calendars and information flows without blurring independence or accountability. Internal audit should not be designed merely to produce files for the statutory auditor.
How management should divide responsibilities
- Define the audit universe: list significant processes, entities, locations, systems and compliance areas.
- Risk-rank the universe: prioritise areas using financial exposure, control history, regulatory sensitivity, change, fraud risk and management concerns.
- Approve a periodic internal-audit plan: allocate internal-audit effort to the highest-value risks rather than repeating identical checks every year.
- Maintain statutory-audit readiness separately: prepare financial statements, reconciliations, schedules and statutory evidence needed for the external audit.
- Create a common issue tracker: where appropriate, track control deficiencies, owners, deadlines and closure evidence across assurance functions without merging their responsibilities.
- Escalate significant findings: establish clear reporting to the Board, audit committee or other appropriate governance forum based on the company's structure and legal requirements.
Common misconceptions
- Internal audit is only checking vouchers: modern internal audit is risk- and control-focused and can cover operational, technology, compliance and governance risks.
- A clean statutory audit means controls are perfect: a statutory audit opinion should not be interpreted as a certification that every process or control is flawless.
- Internal audit removes the need for statutory audit: the two functions arise from different objectives and legal responsibilities.
- The same annual checklist is enough: internal-audit priorities should evolve when the business, systems, regulations or risk profile changes.
Which one should a company prioritise?
If statutory audit is legally required, it is not optional and cannot be replaced by internal audit. The practical decision is therefore not which audit to choose, but how to make each function perform its proper role. For companies required to have internal audit under section 138, both obligations must be addressed. Even where internal audit is not legally mandatory, a growing or complex business may still choose internal audit as a governance and risk-management tool.
Practical takeaway
Statutory audit is an independent legal reporting function; internal audit is a continuing risk, control and governance assurance tool. Management should keep the mandates distinct, coordinate them intelligently and avoid turning internal audit into a duplicate year-end financial audit. The strongest model uses internal audit to find and fix process risks during the year while preserving the statutory auditor's independent responsibility under the Companies Act.